Skip to main content

Connector Gateway

Stacklok Enterprise

The Connector Gateway is a component of Stacklok Enterprise.

Learn more about Stacklok Enterprise.

The Connector Gateway provides an identity-aware endpoint for MCP tool calls. It evaluates each connector's policy to expose the connectors available to each caller and brokers connector credentials on their behalf.

It is the counterpart to the AI Gateway. The AI Gateway governs the models your agents can call; the Connector Gateway governs the tools they can use.

Where to start​

How it works​

A connector is an MCP server registered with the gateway. Every user points their MCP client at the same gateway endpoint and signs in with their corporate identity. The gateway then serves that user only the connectors they're granted and connected to.

On each request, the gateway asks the Enterprise Manager who the caller is and which connectors their connector policies allow. For each tool call, it attaches the credential that the connector's authentication type defines and forwards the call to the connector's backend.

Two roles share the work:

  • Administrators register connectors, configure how the gateway authenticates to each backend, and grant connectors to directory groups. See Manage connectors.
  • Users connect their MCP client to the gateway endpoint, connect to the connectors they're granted, and choose which tools stay on. A connector that acts as the user asks them to sign in to its provider once, when they connect. The console guides users through these steps. See Support users' connector access.

What you administer​

The console groups Connector Gateway administration under Connectors:

Console areaWhat you do there
ConnectorsRegister connectors, configure connector authentication, and grant access through policies
Identity ProvidersRegister the connector identity providers that OAuth and token exchange connectors authenticate against
Managed SecretsStore the API keys, tokens, and client secrets that connectors and identity providers reference
Tool UsageReview tool calls by connector and tool

Outside the console, you configure tool call recording, telemetry, and audit logs in the platform's Helm values.

Connector Gateway and vMCP​

The Connector Gateway and a Virtual MCP Server (vMCP) both aggregate MCP servers behind one endpoint. They differ in who decides what each caller sees.

Connector GatewayvMCP
Built forPeople using their own MCP clientsApplications and agents with a predefined toolset
Who picks the toolsAdministrators grant connectors in the console; each user connects to the ones they wantA fixed set of backends in the VirtualMCPServer configuration
AuthorizationA per-connector policy evaluated for each userCedar policies on the vMCP, plus ToolhiveAuthorizationPolicy on MCPServer backends
Tool filteringEach user turns off the tools they don't wantAdministrators filter and rename tools for every caller

In structured mode, connector policies grant access to directory groups, which are separate from the OpenID Connect (OIDC) claim groups that cluster authorization policies match. A Cedar-mode connector policy can also match claims in the caller's token. See Directory groups and OIDC claim groups.

You can run the Connector Gateway and multiple vMCP instances in the same cluster.

Prerequisites​

Next steps​