OAuth 2.1 for remote MCP

Put OAuth in front of any MCP server.

Paste your existing MCP URL. Get a protected gateway URL for Claude, Cursor, ChatGPT, and every standards-based MCP client.

No credit card No code changes
New gateway
Edge online
Streamable HTTP
Enter the URL of an existing remote MCP server
Protected endpoint ready OAuth 2.1 · PKCE required
2.4s
https://acme.gatekey.dev/mcp

One secure URL for every MCP client

Claude Cursor ChatGPT Custom clients
From open to protected

Your secure MCP endpoint.
Before the coffee is ready.

Keep your server exactly where it is. Gatekey adds authentication and access control at the edge, without an SDK, sidecar, or rewrite.

01

Paste your MCP URL

Point us at any self-hosted Streamable HTTP endpoint reachable over HTTPS.

02

Choose who gets access

Enable identity providers and allowlist users, organizations, or email domains.

03

Share the protected URL

Use one standards-based gateway URL in Claude, Cursor, ChatGPT, or your own client.

Simple by design

A security layer.
Nothing more.

Gatekey is a transparent Cloudflare-based proxy between your MCP clients and your existing server. It handles identity at the edge, then forwards MCP traffic to your origin.

  • Your tools stay on your serverNo hosted MCP runtime and no tool execution.
  • Your protocol stays intactStreamable HTTP requests and responses pass through.
  • Your code stays untouchedNo auth library or MCP server changes required.
AUTH BOUNDARY
Claude
Cursor
</> Client
Gatekey edge OAuth · policy · limits
PKCEDCRJWT
Your MCP server Your cloud · Your VPC
UNCHANGED
Gatekey managed Customer managed
The gateway essentials

Everything between
public and protected.

Production-ready access controls for remote MCP, with a setup your team can understand at a glance.

OAuth 2.1, correctly wired

PKCE, Dynamic Client Registration, token validation, and standards-based discovery. All handled for every endpoint.

Your identities, your rules

GitHub, Google, or your enterprise identity provider. Allow access by user, team, or verified domain.

Ship under your domain

Use a Gatekey URL out of the box, or connect a custom hostname for a fully branded endpoint.

Control without guesswork

Set rate limits, inspect authentication events, and trace access across users and clients from one compact dashboard.

Rate limits Audit logs Origin tokens
MCP-native

Built for the protocol.
Invisible in the path.

The gateway preserves Streamable HTTP semantics while enforcing authentication before a request ever reaches your origin.

Explore the technical details
live request
POST /mcp 34 ms
authorization: Bearer ••••••••••••
content-type: application/json
mcp-session-id: 8f2a••••••

{
  "jsonrpc": "2.0",
  "method": "tools/call"
}
Authenticated at edge Forwarded to origin
Simple pricing

Secure your first endpoint free.

Start small. Upgrade when your gateway becomes part of production.

Sandbox

For testing your first protected MCP endpoint.

€0for testing
Start testing
  • 1 MCP gateway
  • GitHub & Google login
  • 3 allowed users
  • 3-day audit log
Scale

For SaaS products with advanced identity needs.

Let’s talk
Contact us
  • Unlimited gateways
  • Enterprise SSO
  • Organization policies
  • Extended log retention
  • Priority support

All plans include OAuth 2.1, PKCE, Dynamic Client Registration, and encrypted transport. Prices are indicative B2B prices and exclude VAT.

Questions, answered

Good to know
before you connect.

Still evaluating your setup?

Talk to an engineer

No. Your MCP server and tools remain on your infrastructure. Gatekey is the authentication and policy proxy in front of your existing Streamable HTTP endpoint.

No. Add your current MCP URL, configure who may connect, and use the new gateway URL in your MCP client. An optional service token can protect the connection from Gatekey to your origin.

Gatekey is designed for standards-based remote MCP clients that support OAuth, including Claude, Cursor, ChatGPT, and custom clients using the MCP authorization flow.

Users authenticate with GitHub, Google, or your enterprise provider. You can then allowlist specific identities and email domains, with every authentication event recorded in the audit log.

Yes. Starter and Scale gateways can be published under a custom hostname such as mcp.yourcompany.com, with TLS handled automatically.

Ready when your server is

OAuth for your MCP server.
Minutes from now.

Join the early access list and be first to protect your endpoint.