MCP Gateway

Authenticated entry point for Model Context Protocol traffic.

Agentic Friendly

Component Category

AI tools / MCP traffic gateway

Component Description

The MCP Gateway is the single entry point through which every Model Context Protocol call passes. It authenticates the caller, confirms the target server belongs to their organization, exchanges the caller's platform credential for the User Credential they linked, applies the server's tool allowlist, and forwards the request over Streamable HTTP.

It runs as its own workload with its own address, separate from the BSQAI API. MCP sessions stay open for the life of the client connection, and isolating them keeps long-lived streams from competing with chat traffic.

Managed Servers are run by MCP Lifecycle Operator, which reconciles MCPServer custom resources in the mcp.x-k8s.io/v1alpha1 API group. The BSQAI API records an administrator's intent as a custom resource; the operator creates the workload and reports readiness back. Remote Servers involve no operator because the platform runs nothing for them.

Why It Is Used

In BullSequana AI, MCP Gateway gives an organization one governed surface for tool access. Administrators decide which MCP Servers exist and which of their tools may be called, while each user authenticates to the system behind a server with their own credential. No platform token reaches a third-party system, and no user's credential is used on another user's request.

Learn More

Deployment notes

The Gateway runs as a separate workload in the BSQAI API release. Its internal address carries platform chat and Agent traffic. Its separately configured public address is advertised to external MCP clients through gateway_url. Route timeouts are unbounded because a Streamable HTTP session can remain open for the life of the client connection.

User Credentials are encrypted at rest with a deployment-held key derived separately per user and per server. OAuth linking requires a browser return address; without one, users can link only pasted credentials.

See Connect tools with MCP for administration and usage guidance.

Interacts With

  • BSQAI API, which stores MCP Server records, tool allowlists, and credentials.
  • MCP Lifecycle Operator, which reconciles Managed Server workloads.
  • AI Web Portal, where administrators manage servers and users link credentials.
  • Keycloak, which authenticates the calling user and identifies the active tenant.
  • PostgreSQL, which stores server records, allowlists, and encrypted User Credentials.
  • External MCP clients, which connect to individual server URLs through the public Gateway.

On this page