What "elaichi ai vs mintmcp mcp gateway" actually decides
Somebody in support has already pointed Claude at a Zendesk account using their own token. Finance wants the same for its billing system. You are choosing where that traffic lands before it spreads further.
The search people type at this point is elaichi ai vs mintmcp mcp gateway. Both options are hosted, so neither decision is about racking servers. The fork is narrower than the category talk suggests. It comes down to where the connectors are authored, how many addresses a rollout needs, and what the record can prove afterwards.
MCP (Model Context Protocol) is the standard way an AI assistant calls tools in other apps
Elaichi is a governed MCP control plane. Every SaaS account is connected once, and the tools those accounts expose are served through one organization-wide MCP endpoint, POST /mcp. An endpoint here is a single HTTPS address a client talks to. Claude, ChatGPT, Cursor and any other MCP client point at that address and sign in with OAuth, the browser flow that hands a client a token without showing it your password.
Where do the connectors come from?
| Axis | Elaichi | MintMCP |
|---|---|---|
| Hosted vs proxy over your servers | Hosted; Elaichi is the MCP server on its own infrastructure | Hosted gateway; site says it "hosts our MCPs and manages credentials" |
| Connector authorship | Vendor-authored (450+); custom connectors from JSON config | Large catalog of hosted MCP servers, better breadth for a niche app this week |
| Updates | Review surface separates new tools, safe updates, config diffs, conflicts and upstream removals | Not documented publicly; ask before signing |
| Per-org audit | Append-only log; export to Datadog, with Splunk HEC and Sentinel accepted | Not documented publicly; ask before signing |
| Tool-list unification | One organization-wide endpoint at POST /mcp behind OAuth | Not documented publicly; ask before signing |
| Cost model | Seats: $15 per user per month on Gold, 14-day trial | Not documented publicly; ask before signing |
This is the first real fork. Elaichi authors, maintains and serves its connectors from its own infrastructure. There are 450+ of them, and companies do not run MCP servers to use them. Elaichi does not wrap a registry of servers other people publish.
MintMCP's own site describes a hosted MCP gateway that "hosts our MCPs and manages credentials", with hosted connectors and a large server catalog (mintmcp.com, checked September 2026).
The trade-off runs both ways. A large catalog of third-party servers covers a long tail faster than any single vendor can author. Authored connectors give you a tool surface that is one party's responsibility, including tool names, argument schemas and the operation each tool maps to. If the app you need is niche and you need it next week, breadth wins. If your problem is that nobody can say what the agent may call, authorship wins.
Elaichi also takes custom connectors from JSON config. You can fork a public connector and pull upstream changes through a review surface that separates new tools, safe updates, config diffs, conflicts and upstream removals. Conflicts and destructive removals stay unchecked by default.
How many addresses does a company-wide rollout need?
One, with Elaichi. There are no per-toolbox URLs and no embedded tokens, and no MCP server to create, list or revoke per user. The address is fixed, and the grant is what varies between people. A grant is the OAuth authorization a client holds after a member signs in.
That shape matters for the three clients companies actually use. Claude, ChatGPT and Cursor each take one URL in their own admin console. Adding a fourth MCP client is the same work again, not a fork.
Sharing is separate from the address. A member sees only what they own or what was explicitly shared with them, and no organization-level permission silently widens that listing. Owners and admins included.
The alternative shapes are recognizable: a per-team endpoint, a per-member server inside an automation account, or a gateway you run in front of servers you run. Each carries a different operations bill. Per-user addresses move the joiner and leaver problem into the client instead of your directory. The arithmetic of hosting shapes is worked through in what self-hosted MCP servers really cost.
Ask any hosted gateway vendor a plain question. How many URLs exist once 200 people are onboarded, and who revokes one.
What counts as a credential in each model?
With Elaichi, not the URL. POST /mcp is one public address behind OAuth, and holding it grants nothing. Connector credentials never live in Elaichi. A separate credential service holds per-account secrets, encrypted with AES-256-GCM at rest, and owns refresh. A failed refresh marks the connection needs_reauth rather than failing quietly.
A connect URL is not a credential either. It is a one-time session that carries no token, which is why it is safe to return over MCP. Reading back an account's configuration returns public values plus secret_paths, the list of dot-paths that were encrypted, carrying none of their values.
An organization can supply its own OAuth app per connector. That is gated on connector:manage rather than connection:manage, so everyone who can delete a connection does not silently gain the ability to repoint the organization's OAuth app. Per-org envelope encryption with a customer-managed key in AWS KMS is available.
Where a gateway manages credentials on your behalf, three questions settle the comparison. Which service holds the secret, who can read it back, and can you bring your own OAuth app.
What can you prove after the agent acted?
Elaichi writes one entry per tool-call attempt, succeeded or failed, and both name the account actually reached. That comes from the execution rather than the intent, because the first question after an unexpected change is which of two connected workspaces the agent wrote to.
actor_kind is a field, not an inference. Its values include user, system, scim, api_token and ai_assistant, recorded at the point of action. Each record carries the operation, the tool, the connection, the classification, whether it was approved, the outcome and an error code. Argument names and counts are logged. Argument values never are.
An audit log here means that append-only, organization-visible trail. It is newest-first, cursor-paginated and filterable by free text, category, actor, action kind and time. It is eventually consistent, so a row may take a moment to appear. Export forwards to your own destination: Datadog is implemented, while Splunk HEC and Microsoft Sentinel are accepted but not yet delivering.
The read-only Auditor seat is free. A compliance reviewer does not cost a license.
What the "github mcp" searches are really asking
Two different questions hide behind the searches elaichi ai github mcp and mintmcp github mcp. One asks whether the code is public and self-hostable. The other asks whether an agent can reach your repositories.
On the first, Elaichi is the MCP server rather than a proxy in front of servers you already run, and it is served from Elaichi's own infrastructure. If you want code you can read and host yourself, that is a different product shape. Lunar.dev describes a self-hosted enterprise MCP gateway with an open-source version on GitHub (lunar.dev, checked September 2026). Whether MintMCP publishes gateway code, and which servers in its catalog are its own, is a question to put to MintMCP rather than something to infer.
On the second, developer tools sit in the same catalog as everything else and are governed the same way. Check the connector catalog for the specific app. A restriction decides which connectors and which individual tools a target may reach, and the targets are role or user only. Blocks match a tool's advertised name or its pinned operation. Allows match the pinned operation only, because a tool's name can be changed by whoever edits the connector's documentation. Why blocks and allows match on different things follows that through.
Where MintMCP is the better buy
When the requirement is breadth of third-party servers, a hosted gateway with a large server catalog gets you there sooner. MintMCP's own site describes hosted connectors and a large catalog of servers (mintmcp.com, checked September 2026). If you need one unusual server this month, an authored catalog of 450+ connectors either has it or it does not.
Two other cases point away from Elaichi. If data must stay in an jurisdiction contract in APAC, Elaichi's apac region is a placement hint only. It is best-effort and not a residency guarantee. The eu and us regions are hard residency, compute and storage both. And if you already run MCP servers you intend to keep, a proxy in front of them fits your estate better than a control plane that replaces them.
Questions to put to MintMCP before you sign
Get the answers from the vendor, not from a comparison page. These five change a rollout.
- How many gateway URLs exist for 200 members, and who can revoke one.
- Where connector secrets are held, who can read them back, and whether we can supply our own OAuth app.
- What the billing unit is: seats, tool calls, or servers.
- Which servers in the catalog are authored by you, and which are third party.
- What happens to a member's access the day they leave our directory.
Elaichi's answers to the same list: one URL; a separate credential service with bring-your-own OAuth app and customer-managed keys; seats at $15 per user per month or $120 per user per year, with a 14-day trial, on the pricing page; every connector authored by Elaichi or by you; and removal revoking every live grant in the same transaction as the membership change.
Timing is worth stating precisely. Role and restriction changes take effect within about two minutes, on MCP, console and REST alike. Grant revocation, member removal and suspension are effective on the next call.
The case for buying neither this quarter
Five people, two connected apps and one client is not a governance problem yet. A shared account and a written rule can hold for a while. Buy a control plane when you cannot answer who reached what, or when removing somebody takes more than one action. The threshold test for a gateway lists the signals.
One limitation belongs in the decision. The prompt-injection write gate lives in the Elaichi agent window and does not apply to a raw tool call. What does hold on the endpoint is RBAC per operation, the forbidden classification, output redaction, OAuth scope limits and full audit logging. RBAC means role-based access control, and here a member holds exactly one role.
Organization deletion has a gap worth naming too. It tears down the workspace but has no path to purge the organization's log tenant, and it returns that residue by name instead of reporting a clean sweep.
To see this against a real team rather than in the abstract, the team rollout guides cover twelve of them. Elaichi next to a tool-call platform is the same comparison against a different shape, and residency details sit on the security page.