One enterprise gateway that gives your teams secure access to every MCP server, with per-user authentication, and a log of every tool call.
[ PERFORMANCE AT A GLANCE ]
[ TRUSTED BY TEAMS BUILDING WITH BIFROST ]
[ ARCHITECTURE ]
Bifrost acts as both an MCP client (connecting to external tool servers) and an MCP server (exposing tools to external clients like Claude Desktop) through a single deployment.
Bifrost connects to your external MCP servers - filesystem tools, web search, databases, custom APIs, and discovers their capabilities automatically.
Bifrost exposes all connected tools through a single gateway URL. MCP clients like Claude Desktop connect to Bifrost and access everything.
[ CORE CAPABILITIES ]
Connect, authenticate, control, and log every MCP tool call from one gateway, and cut the token cost of large tool catalogs with Code Mode.
[ HOW IT WORKS ]
The default tool calling pattern is stateless with explicit execution. No unintended API calls, no accidental data modifications, full audit trail of every operation.
Connect Bifrost to any MCP-compliant server. Bifrost auto-discovers available tools and their schemas at startup.
Your app sends a standard chat completion request. Bifrost injects discovered MCP tools into the request automatically.
When the LLM suggests a tool call, your app decides whether to execute it. Bifrost handles the MCP protocol and returns results.
[ CODE MODE ]
The more MCP servers you connect, the more tokens each request spends on tool definitions. Code Mode removes that overhead and loads tools only when needed.
| MCP setup | Input tokens | Estimated cost | Task pass rate |
|---|---|---|---|
| 96 tools, 6 servers | 19.9M → 8.3M (−58%) | $104 → $46 | 100% → 100% |
| 251 tools, 11 servers | 35.7M → 5.5M (−85%) | $180 → $30 | 98.5% → 100% |
| 508 tools, 16 servers | 75.1M → 5.4M (−93%) | $377 → $29 | 100% → 100% |
NoteAround 40% faster execution in large MCP deployments. Recommended once you connect 3 or more MCP servers.
[ MCP GOVERNANCE ]
Decide which MCP tools each user, team and customer can reach, enforce it on every request, and keep those rules in sync with your identity provider.
[ SECURITY-FIRST DESIGN ]
By default, Bifrost does NOT automatically execute tool calls. All tool execution requires explicit API calls from your application, ensuring human oversight for every operation.
Tool calls from LLMs are suggestions only. Execution requires a separate API call from your application.
Filter tools per-request, per-client, or per-virtual-key. Blacklist dangerous tools globally.
Agent Mode with auto-execution must be explicitly configured. Specify exactly which tools are allowed.
Each API call is independent. Your app controls conversation state with full audit trails at every step.
[ SECURITY ]
[ TRANSPORT PROTOCOLS ]
Local process execution via stdin/stdout.
Local toolsRemote MCP servers via HTTP requests.
MicroservicesPersistent streaming for real-time data.
Live data[ USE CASES ]
Connect AI coding agents to filesystem tools, databases, and deployment pipelines. Bifrost handles tool injection transparently with full audit trails for every operation.
Deploy in healthcare, finance, or government with explicit approval workflows, PII redaction, and tamper-evident audit logs for SOC 2 and HIPAA compliance.
Coordinate filesystem operations, database queries, and API calls in a single request using Code Mode. Reduce token waste and latency when using 3+ MCP servers.
Supervised infrastructure actions and deployments with role-based tool access. Only approved tools execute, with complete visibility into every automated step.
Manage tool access across teams with virtual keys and per-key tool filtering. Set different tool policies for development, staging, and production environments.
Expose your entire tool ecosystem through a single Bifrost gateway URL. Claude Desktop and other MCP clients connect once and discover all available tools automatically.
[ WHY BIFROST ]
11µs overhead at 5,000 requests per second
Stateless architecture with explicit approval
Code Mode: 50% fewer tokens, 40% faster execution
Dual role: MCP Client and MCP Server
Built-in OAuth 2.0 with automatic token refresh
Production-proven at millions of requests/day
Complete audit trails and OpenTelemetry export
Open source (Apache 2.0) with enterprise support
Go-native with zero Python GIL bottleneck
[ WHAT'S NEXT ]
Continue with governance, guardrails, MCP, and the rest of the resource library.
[ BIFROST FEATURES ]
Everything you need to run AI in production, from free open source to enterprise-grade features.
01 Governance
SAML support for SSO and Role-based access control and policy enforcement for team collaboration.
02 Adaptive Load Balancing
Automatically optimizes traffic distribution across provider keys and models based on real-time performance metrics.
03 Cluster Mode
High availability deployment with automatic failover and load balancing. Peer-to-peer clustering where every instance is equal.
04 Alerts
Real-time notifications for budget limits, failures, and performance issues on Email, Slack, PagerDuty, Teams, Webhook and more.
05 Log Exports
Export and analyze request logs, traces, and telemetry data from Bifrost with enterprise-grade data export capabilities for compliance, monitoring, and analytics.
06 Audit Logs
Comprehensive logging and audit trails for compliance and debugging.
07 Vault Support
Secure API key management with HashiCorp Vault, AWS Secrets Manager, Google Secret Manager, and Azure Key Vault integration.
08 VPC Deployment
Deploy Bifrost within your private cloud infrastructure with VPC isolation, custom networking, and enhanced security controls.
09 Guardrails
Automatically detect and block unsafe model outputs with real-time policy enforcement and content moderation across all agents.
[ SHIP RELIABLE AI ]
Change just one line of code. Works with OpenAI, Anthropic, Vercel AI SDK, LangChain, and more.
[ FAQ ]
An MCP (Model Context Protocol) gateway connects AI models to external tools like filesystems, databases, and APIs. Without a gateway, each AI client needs individual tool configurations. Bifrost centralizes tool management, adds security controls, and provides audit trails for every tool execution.
No. By default, Bifrost treats tool calls from LLMs as suggestions only. Your application must explicitly approve and trigger execution via a separate API call. This security-first design prevents unintended actions. Agent Mode with auto-execution is available but requires explicit opt-in configuration.
An MCP gateway solves the problem of runaway tool-calling that can overload internal systems or hit provider API limits. The main objective is to regulate resource consumption while maintaining a smooth developer experience.
Key features for resource management include:
Code Mode replaces traditional tool calling with AI-generated Python code that orchestrates multiple tools in a single round-trip. Instead of sending 100+ tool schemas in every request, Code Mode uses four meta-tools for on-demand schema loading. This cuts token usage by 50%+ and reduces LLM calls by 3-4x.
Bifrost supports all three MCP transport types: STDIO for local process execution, HTTP for remote MCP servers, and SSE (Server-Sent Events) for real-time streaming connections. OAuth 2.0 authentication with automatic token refresh is built in.
Yes. Bifrost acts as both an MCP client (connecting to external tool servers) and an MCP server (exposing tools to clients). Claude Desktop and other MCP-compatible clients can connect to a single Bifrost gateway URL to discover and use all registered tools.
Virtual keys are scoped credentials for each consumer of your MCP gateway: a user, team, or customer integration. Each key defines which tools it may call at the tool level, not just per server, so customer-facing agents cannot reach internal admin tooling. See AI governance for how keys, budgets, and policies are assigned.
A Virtual MCP server is a curated toolkit your agents see at the gateway, built from MCP Tool Groups. Each group is a named collection of tools from one or more backend MCP servers. Define a group once, attach it to virtual keys, teams, or customers, and Bifrost resolves allowed tools in memory at request time without duplicates.