MCP gateway vs MCP control plane: what the words mean
Support wants Zendesk inside Claude. Finance wants NetSuite inside ChatGPT. You have a week to pick something, and four different product shapes are sold under overlapping words. MCP gateway vs MCP control plane is the axis that sorts them. A gateway forwards calls to MCP servers that other people run. A control plane is the server, and it makes the access decision itself.
MCP (Model Context Protocol) is the standard way an AI assistant calls tools in other apps
All four shapes can end up putting Zendesk in Claude for one support agent. They differ on who runs the servers, who authors the connectors, how many addresses your users have to handle, and who gets paged when a token expires. Sort the vendor into a shape first. Feature lists compared across two shapes tell you almost nothing.
Shape one: a proxy in front of MCP servers you already run
This shape assumes the servers exist and that your team runs them. The product adds one policy point, one place to watch traffic, and one address for agents to dial. It removes nothing from your infrastructure.
Lunar.dev describes MCPX as a self-hosted enterprise MCP gateway that sits between agents and the MCP servers, APIs and LLM providers they use, with an open-source version on GitHub (lunar.dev, checked September 2026). Boomi announced its intent to acquire Lunar.dev on 2026-05-13 and has since completed it (boomi.com, checked September 2026).
The reader this fits runs platform engineering at a company that already operates MCP servers, often several, written by different teams. The gateway gives that reader one choke point instead of five. The trade-off is that the servers stay yours. Uptime, credential rotation, upstream API changes and version upgrades are still your on-call rotation. A central policy point does not shrink that bill, and the bill is the reason most companies leave this shape. The arithmetic is worked through in the cost of running MCP servers yourself.
Shape two: a hosted catalog of servers and connectors somebody else publishes
Here the vendor hosts the MCP surface and a broad catalog, and you connect accounts to it. You run no servers. What you inherit is somebody else's list, and the list is the product.
MintMCP describes a hosted MCP gateway that hosts its MCPs and manages credentials, with hosted connectors and a large server catalog (mintmcp.com, checked September 2026). Composio Connect is an MCP server at https://connect.composio.dev/mcp that gives an agent access to 1000+ apps through a small set of meta-tools, with OAuth links approved in the browser (docs.composio.dev, checked September 2026). OAuth here means the sign-in flow where a user approves access without handing over a password. Composio's MCP Gateway page says each team gets its own MCP endpoint, SSO authenticated (composio.dev, checked September 2026). An endpoint is one URL that answers requests, so the address model in that description is per team rather than per company.
Composio's enterprise page describes permissions set per user and per role down to the individual action, logging of every tool call including denied calls, and SSO over SAML and OIDC (composio.dev/enterprise, checked September 2026). Governance exists in this shape. The questions worth asking are who authors and maintains each item in the catalog, and how many addresses your admins end up managing. A fuller side by side sits in the Composio comparison.
Shape three: an API platform that grew an MCP mode
These are API management products that added MCP support to an existing gateway. They are built for a company whose most valuable tools are its own internal APIs.
Tyk is an API management platform whose MCP Gateway proxies and governs remote MCP servers and can generate an MCP proxy from a managed REST API, with core MCP features in the open-source Tyk Gateway (tyk.io, checked September 2026). Zuplo is an API gateway platform that also ships an MCP Gateway federating MCP servers behind one OAuth-protected gateway (zuplo.com, checked September 2026). Kong AI Gateway supports MCP through AI MCP Server entities, exposing APIs as MCP tools (developer.konghq.com, checked September 2026).
The reader this fits already runs one of these platforms in production. Your billing API and your internal search service are already behind it, with auth and rate limits configured. Turning those into MCP tools is a config change rather than a purchase. The trade-off is scope. MCP is a mode on the product, not the product. The third-party SaaS accounts your finance and support teams live in are not in the platform, and connecting them stays your project.
Shape four: a control plane that is the MCP server
Elaichi is this shape. Every SaaS account the company uses is connected once, and the tools those accounts expose are served through one organization-wide MCP endpoint: POST /mcp, standard MCP over Streamable HTTP, JSON-RPC 2.0, stateless, behind OAuth. There are no per-toolbox URLs and no embedded tokens. Claude, ChatGPT, Cursor and the Elaichi Agent are pointed at the same address and sign in. Each of the first three can be configured through its own admin console, so adding a client is not a per-user project.
Elaichi authors, maintains and serves 450+ connectors from its own infrastructure. It is not a list of servers other people run, and your company runs no MCP servers.
Access resolves in three separate layers. Roles are about 38 action strings grouped into personas, with exactly one role per member. Sharing is a grant of view, use or edit on a resource, and a member sees only what they own or what was shared with them. Restrictions decide which connectors and which individual tools a target may reach, targeted at a role or a user, where A rule on a user replaces the role rules for that user rather than adding to them Enforcement runs at browse, connect, advertise and execute, plus a final check on the fully substituted outbound URL against the same resolver.
Timing is worth stating precisely. A role or restriction change takes effect within about two minutes. Grant revocation, member removal and suspension are effective on the next call, because the revocation flag is re-read on every single call.
The trade-offs are real. The two plans are Gold and Black, with a 14-day trial.; Gold is $15 per user per month or $120 per user per year, with a 14-day trial, no credit card to start. Checkout does collect a card, and it sets the paid trial to the remaining days rather than granting a fresh 14, so it is one continuous trial rather than two (see pricing). The apac region is a placement hint. It is not a hard residency zone, while eu and us are hard residency. Organization deletion tears down the workspace but has no path to purge the organization's log tenant, and it returns that residue by name.
Which shape fits which reader
| Shape | You run MCP servers | Connectors come from | Address model | Built for |
|---|---|---|---|---|
| Proxy in front of your servers | Yes | Your own teams | One gateway over many servers | Platform engineering with servers already live |
| Hosted catalog | No | The vendor's catalog and listed servers | Often per team or per user | Developers who need breadth this quarter |
| API platform with MCP | Your APIs, not MCP servers | Your own REST APIs | The gateway you already run | Companies whose key tools are internal APIs |
| Control plane | No | The vendor authors them | One organization-wide endpoint | IT and operations rolling out to support, finance, sales, legal |
Read the rows across, not down. A company with six internal services and no SaaS sprawl belongs in row three, and no amount of governance in row four changes that.
How do you tell which shape a vendor is selling?
Open the vendor's quickstart, not the homepage, and answer four questions. The quickstart shows the address model and the setup burden in the first screen, which is where the shapes separate.
- Count the addresses in the setup instructions. One per company, one per team, or one per member.
- Find out who wrote the connector for the app you care about most. The vendor, a community, or you.
- Ask what happens to a leaver's access, and who has to act. Elaichi refuses removal until personal connections referenced by a toolbox entry are transferred or deleted.
- Ask how long a permission change takes to apply, and get the number.
When none of the four is worth buying
Two people, one app, and an assistant with a native connector for it do not need any of these products. Turn the connector on in the client's admin console and revisit the question when a second app or a fifth person arrives. The trigger conditions are listed in the case for waiting.
One thing no shape sells you is protection from prompt injection on the server surface. The prompt-injection write gate lives in the Elaichi agent window and does not apply to a raw tool call. What does hold on the endpoint is RBAC per operation, the forbidden classification, output redaction, OAuth scope limits and full audit logging. RBAC means permissions attached to a role rather than to a person.
If the shape you want is the fourth one, the connector catalog shows what is already authored, and the team pages show the rollout order per department. Other head-to-heads live in the comparisons category.