# MCP Gateway (/docs/ai/components/mcp-gateway)



## Component Category [#component-category]

AI tools / MCP traffic gateway

## Component Description [#component-description]

The MCP Gateway is the single entry point through which every Model Context Protocol call passes. It authenticates the caller, confirms the target server belongs to their organization, exchanges the caller's platform credential for the User Credential they linked, applies the server's tool allowlist, and forwards the request over Streamable HTTP.

It runs as its own workload with its own address, separate from the `BSQAI API`. MCP sessions stay open for the life of the client connection, and isolating them keeps long-lived streams from competing with chat traffic.

Managed Servers are run by MCP Lifecycle Operator, which reconciles `MCPServer` custom resources in the `mcp.x-k8s.io/v1alpha1` API group. The BSQAI API records an administrator's intent as a custom resource; the operator creates the workload and reports readiness back. Remote Servers involve no operator because the platform runs nothing for them.

## Why It Is Used [#why-it-is-used]

In BullSequana AI, MCP Gateway gives an organization one governed surface for tool access. Administrators decide which MCP Servers exist and which of their tools may be called, while each user authenticates to the system behind a server with their own credential. No platform token reaches a third-party system, and no user's credential is used on another user's request.

## Learn More [#learn-more]

* [Model Context Protocol specification](https://modelcontextprotocol.io/)
* [Model Context Protocol on GitHub](https://github.com/modelcontextprotocol)

## Deployment notes [#deployment-notes]

The Gateway runs as a separate workload in the BSQAI API release. Its internal address carries platform chat and Agent traffic. Its separately configured public address is advertised to external MCP clients through `gateway_url`. Route timeouts are unbounded because a Streamable HTTP session can remain open for the life of the client connection.

User Credentials are encrypted at rest with a deployment-held key derived separately per user and per server. OAuth linking requires a browser return address; without one, users can link only pasted credentials.

See [Connect tools with MCP](/docs/ai/mcp) for administration and usage guidance.

## Interacts With [#interacts-with]

* `BSQAI API`, which stores MCP Server records, tool allowlists, and credentials.
* `MCP Lifecycle Operator`, which reconciles Managed Server workloads.
* `AI Web Portal`, where administrators manage servers and users link credentials.
* `Keycloak`, which authenticates the calling user and identifies the active tenant.
* `PostgreSQL`, which stores server records, allowlists, and encrypted User Credentials.
* `External MCP clients`, which connect to individual server URLs through the public Gateway.
