Try Bifrost Enterprise free for 14 days.
Request access
[ MCP GATEWAY ]
[ ENTERPRISE READY: VPC | ON-PREM | AIR-GAPPED ]

MCP Gateway for Secure,
Governed Access to Every MCP Server

One enterprise gateway that gives your teams secure access to every MCP server, with per-user authentication, and a log of every tool call.

[ PERFORMANCE AT A GLANCE ]

11µs
Internal Overhead
Ultra-low latency at high throughput
50%+
Token Savings
With Code Mode vs classic MCP
40%
Faster Execution
Code Mode execution pipeline
10,000+
Model Support
LLM models supported

[ TRUSTED BY TEAMS BUILDING WITH BIFROST ]

[ ARCHITECTURE ]

How Bifrost Connects Your Agents to MCP Servers

Bifrost acts as both an MCP client (connecting to external tool servers) and an MCP server (exposing tools to external clients like Claude Desktop) through a single deployment.

MCP Client

Bifrost connects to your external MCP servers - filesystem tools, web search, databases, custom APIs, and discovers their capabilities automatically.

  • Connect local or remote servers over STDIO, HTTP or SSE
  • Tools are discovered when a server is added and refreshed automatically
  • Health status for every server, with the reason when one fails
  • Six ways to authenticate, from shared keys to per-user sign-in
  • No tools exposed from a server until you allow them

MCP Server

Bifrost exposes all connected tools through a single gateway URL. MCP clients like Claude Desktop connect to Bifrost and access everything.

  • One endpoint for every tool, over Streamable HTTP or SSE
  • Claude Desktop, Claude Code and Cursor sign in through the browser, with no keys in config files
  • Each client sees only the tools its key allows
  • Virtual MCPs give each team its own curated tool endpoint
Your Application
Chat completions API
Bifrost Gateway
MCP Client + Server
MCP Servers
Filesystem, DB, APIs

[ CORE CAPABILITIES ]

Everything you need to run MCP tools at enterprise scale

Connect, authenticate, control, and log every MCP tool call from one gateway, and cut the token cost of large tool catalogs with Code Mode.

Approve every MCP tool call before it runs

  • Treat tool calls from the model as suggestions until your app approves them
  • Execute approved calls through a separate API request
  • Let Agent Mode auto-run only the tools you list
  • Keep sensitive tools behind approval in multi-step tasks
Tool execution docs →SUGGESTED → APPROVED → EXECUTED

Authenticate every MCP server and every user

  • Connect servers with OAuth 2.0, shared headers, or no auth for local tools
  • Let each user connect with their own account through per-user OAuth or headers
  • Pass the caller's identity token upstream with token exchange
  • Sign in Claude Desktop, Claude Code and Cursor through the browser with OAuth 2.1
  • Re-authenticate or revoke any user's connection in MCP Sessions
MCP authentication docs →6 AUTH TYPES · PER-USER SIGN-IN

Cut MCP token costs by up to 92% with Code Mode

  • Replace hundreds of tool definitions with four meta-tools
  • Load tool schemas on demand, not in every request
  • Let the model write short scripts that call tools in a sandbox
  • Keep a 100% task pass rate at 508 tools across 16 servers
Code Mode docs →75.1M → 5.4M INPUT TOKENS AT 508 TOOLS

Give each team only the MCP tools it needs

  • Allow tools one by one, not just whole servers
  • Bundle tools from several servers into a Virtual MCP with its own URL
  • Attach tool access to virtual keys per user, team or customer
  • Grant tool access by role with access profiles (Enterprise)
Virtual MCPs docs →ONE URL PER TEAM · ONLY APPROVED TOOLS

Log and track the cost of every MCP tool call

  • Record every tool call in the same logs as your LLM requests
  • Track tool cost and call volume over time
  • See which tools your teams call most
MCP logs docs →TOOL CALLS · COST · TOP TOOLS

[ HOW IT WORKS ]

Set up your MCP gateway in three steps

The default tool calling pattern is stateless with explicit execution. No unintended API calls, no accidental data modifications, full audit trail of every operation.

Step 01

Register MCP servers

Connect Bifrost to any MCP-compliant server. Bifrost auto-discovers available tools and their schemas at startup.

Terminal
1$# bifrost config
2$mcp_servers:
3$ - name: filesystem
4$ transport: stdio
5$ command: npx @modelcontextprotocol/server-filesystem
Step 02

Send a chat request

Your app sends a standard chat completion request. Bifrost injects discovered MCP tools into the request automatically.

Terminal
1$curl http://localhost:8080/v1/chat/completions \
2$ -H "Content-Type: application/json" \
3$ -d '{"model": "claude-sonnet", "messages": [...]}'
Step 03

Execute tool calls

When the LLM suggests a tool call, your app decides whether to execute it. Bifrost handles the MCP protocol and returns results.

Terminal
1$# tool call returned in response
2$# your app approves → Bifrost executes
3$# full audit trail logged automatically
No automatic execution: Tool calls from LLMs are suggestions, your app decides what runs.
Full audit trail: Every tool suggestion, approval, and execution is logged with metadata.
Stateless design: Each API call is independent, your app controls conversation state entirely.

[ CODE MODE ]

How MCP Code Mode cuts token costs

The more MCP servers you connect, the more tokens each request spends on tool definitions. Code Mode removes that overhead and loads tools only when needed.

Replace hundreds of tool definitions with four meta-tools
Load a tool's schema only when the model needs it
Run multi-step tool work in one sandboxed script
Use Code Mode for large servers and direct tools for small ones, together
MCP setupInput tokensEstimated costTask pass rate
96 tools, 6 servers19.9M → 8.3M (−58%)$104 → $46100% → 100%
251 tools, 11 servers35.7M → 5.5M (−85%)$180 → $3098.5% → 100%
508 tools, 16 servers75.1M → 5.4M (−93%)$377 → $29100% → 100%

NoteAround 40% faster execution in large MCP deployments. Recommended once you connect 3 or more MCP servers.

[ MCP GOVERNANCE ]

Govern MCP tool access across your organization

Decide which MCP tools each user, team and customer can reach, enforce it on every request, and keep those rules in sync with your identity provider.

Scope MCP tools per virtual key

  • Allow tools one by one, all tools from a server, or none
  • Block every tool by default until a key is granted access
  • Narrow access per request with headers, which can never widen it
  • Reject inactive or expired keys at tool execution
MCP tool filtering docs →DENY BY DEFAULT · TOOL-LEVEL ALLOW-LISTS

Give each team a curated Virtual MCP

  • Bundle tools from several servers behind one URL at /mcp/<slug>
  • Attach each Virtual MCP to the keys that should reach it
  • Keep endpoint URLs stable so connected clients never break
  • Switch a Virtual MCP off without deleting it
Virtual MCPs docs →ONE URL PER TEAM · ONLY APPROVED TOOLS

Grant MCP access by role with access profiles (new, Enterprise)

  • Define MCP access once and apply it to everyone in a role
  • Assign profiles by hand, by role, or from identity provider attributes
  • Issue each user a locked key they can't edit to widen access
  • Push MCP-only changes to every user without touching budgets
  • Bring keys that members create under the same policy
Access profiles docs →ROLE → PROFILE → LOCKED KEY

Keep credentials and policy changes accountable (new, Enterprise)

  • Rotate managed keys on a schedule, with a grace period for callers
  • Record every access profile change with a full snapshot history
  • Limit which Virtual MCPs each admin can see and manage
  • Sync users and groups from Okta, Entra, Keycloak or Google Workspace
Advanced governance docs →AUTO-ROTATION · VERSIONED POLICY

Govern MCP servers on employee machines (new, AI Gateway + Bifrost Edge, alpha)

  • See every MCP server configured in supported AI apps across your fleet
  • Allow or deny each server, and enforce the decision on the device
Edge MCP governance docs →FLEET MCP INVENTORY · ALPHA

[ SECURITY-FIRST DESIGN ]

STDIO, HTTP, and SSE Support

By default, Bifrost does NOT automatically execute tool calls. All tool execution requires explicit API calls from your application, ensuring human oversight for every operation.

Explicit execution

Tool calls from LLMs are suggestions only. Execution requires a separate API call from your application.

Granular control

Filter tools per-request, per-client, or per-virtual-key. Blacklist dangerous tools globally.

Opt-in auto-execution

Agent Mode with auto-execution must be explicitly configured. Specify exactly which tools are allowed.

Stateless design

Each API call is independent. Your app controls conversation state with full audit trails at every step.

[ SECURITY ]

MCP security controls at the gateway

Block tools by default and open them deliberately

  • Keep tool calls as suggestions until your app approves them
  • Auto-run only the tools you name in Agent Mode
  • Expose no tools from a server or key until you allow them
  • Refuse MCP servers on private networks until dashboard auth is on
Tool execution docs →NOTHING RUNS UNTIL APPROVED

Screen tool calls with MCP guardrails (Enterprise)

  • Inspect, redact or block tool arguments before a tool runs
  • Inspect, redact or block tool results before they reach the model
  • Enforce plain-language policies with an LLM judge
  • Target rules by MCP server, tool, virtual key, team or user
Guardrails docs →BEFORE CALL · AFTER RESULT

Protect every credential

  • Store MCP server credentials encrypted at rest
  • Let callers reach servers as themselves with token exchange, with nothing stored
  • Sign in MCP clients with OAuth 2.1 and short-lived tokens
  • Revoke any user's MCP connection from one screen
MCP authentication docs →ENCRYPTED · SHORT-LIVED · REVOCABLE

[ TRANSPORT PROTOCOLS ]

What You Can Build

STDIO

Local process execution via stdin/stdout.

Local tools
  • Filesystem operations
  • Code search
  • Dev scripts

HTTP

Remote MCP servers via HTTP requests.

Microservices
  • Database tools
  • Internal APIs
  • Authentication

SSE

Persistent streaming for real-time data.

Live data
  • Monitoring
  • Live dashboards
  • Streaming

[ USE CASES ]

Deployment Options

Agentic coding pipelines

Connect AI coding agents to filesystem tools, databases, and deployment pipelines. Bifrost handles tool injection transparently with full audit trails for every operation.

Regulated enterprise environments

Deploy in healthcare, finance, or government with explicit approval workflows, PII redaction, and tamper-evident audit logs for SOC 2 and HIPAA compliance.

Multi-tool orchestration

Coordinate filesystem operations, database queries, and API calls in a single request using Code Mode. Reduce token waste and latency when using 3+ MCP servers.

DevOps & infrastructure automation

Supervised infrastructure actions and deployments with role-based tool access. Only approved tools execute, with complete visibility into every automated step.

Centralized tool governance

Manage tool access across teams with virtual keys and per-key tool filtering. Set different tool policies for development, staging, and production environments.

Claude Desktop & MCP clients

Expose your entire tool ecosystem through a single Bifrost gateway URL. Claude Desktop and other MCP clients connect once and discover all available tools automatically.

[ WHY BIFROST ]

The Fastest Open-Source MCP Gateway

11µs overhead at 5,000 requests per second

Stateless architecture with explicit approval

Code Mode: 50% fewer tokens, 40% faster execution

Dual role: MCP Client and MCP Server

Built-in OAuth 2.0 with automatic token refresh

Production-proven at millions of requests/day

Complete audit trails and OpenTelemetry export

Open source (Apache 2.0) with enterprise support

Go-native with zero Python GIL bottleneck

Build production AI agents with Bifrost

Get enterprise-grade MCP gateway performance with explicit security controls, Code Mode for token efficiency, and a single gateway URL for your entire tool ecosystem.

Read the MCP Gateway Deep Dive

Virtual keys, MCP Tool Groups, Code Mode benchmarks, and how production teams govern tool access while cutting context cost at scale.

[ BIFROST FEATURES ]

Open Source & Enterprise

Everything you need to run AI in production, from free open source to enterprise-grade features.

01 Governance

SAML support for SSO and Role-based access control and policy enforcement for team collaboration.

02 Adaptive Load Balancing

Automatically optimizes traffic distribution across provider keys and models based on real-time performance metrics.

03 Cluster Mode

High availability deployment with automatic failover and load balancing. Peer-to-peer clustering where every instance is equal.

04 Alerts

Real-time notifications for budget limits, failures, and performance issues on Email, Slack, PagerDuty, Teams, Webhook and more.

05 Log Exports

Export and analyze request logs, traces, and telemetry data from Bifrost with enterprise-grade data export capabilities for compliance, monitoring, and analytics.

06 Audit Logs

Comprehensive logging and audit trails for compliance and debugging.

07 Vault Support

Secure API key management with HashiCorp Vault, AWS Secrets Manager, Google Secret Manager, and Azure Key Vault integration.

08 VPC Deployment

Deploy Bifrost within your private cloud infrastructure with VPC isolation, custom networking, and enhanced security controls.

09 Guardrails

Automatically detect and block unsafe model outputs with real-time policy enforcement and content moderation across all agents.

[ SHIP RELIABLE AI ]

Try Bifrost Enterprise with a 14-day Free Trial

[quick setup]

Drop-in replacement for any AI SDK

Change just one line of code. Works with OpenAI, Anthropic, Vercel AI SDK, LangChain, and more.

1import os
2from anthropic import Anthropic
3
4anthropic = Anthropic(
5 api_key=os.environ.get("ANTHROPIC_API_KEY"),
6 base_url="https://<bifrost_url>/anthropic",
7)
8
9message = anthropic.messages.create(
10 model="claude-3-5-sonnet-20241022",
11 max_tokens=1024,
12 messages=[
13 {"role": "user", "content": "Hello, Claude"}
14 ]
15)
Drop in once, run everywhere.

[ FAQ ]

Frequently Asked Questions

An MCP (Model Context Protocol) gateway connects AI models to external tools like filesystems, databases, and APIs. Without a gateway, each AI client needs individual tool configurations. Bifrost centralizes tool management, adds security controls, and provides audit trails for every tool execution.

No. By default, Bifrost treats tool calls from LLMs as suggestions only. Your application must explicitly approve and trigger execution via a separate API call. This security-first design prevents unintended actions. Agent Mode with auto-execution is available but requires explicit opt-in configuration.

An MCP gateway solves the problem of runaway tool-calling that can overload internal systems or hit provider API limits. The main objective is to regulate resource consumption while maintaining a smooth developer experience.

Key features for resource management include:

  • Token & Request Budgeting: Set hard limits on tool calls per team to prevent backend system overloads and control costs.
  • Automated Failover: Reroute traffic to secondary servers or models if an MCP connection times out or fails.
  • Scale-Ready Architecture: Built to handle thousands of tool-calls concurrently without degrading performance or reliability.

Code Mode replaces traditional tool calling with AI-generated Python code that orchestrates multiple tools in a single round-trip. Instead of sending 100+ tool schemas in every request, Code Mode uses four meta-tools for on-demand schema loading. This cuts token usage by 50%+ and reduces LLM calls by 3-4x.

Bifrost supports all three MCP transport types: STDIO for local process execution, HTTP for remote MCP servers, and SSE (Server-Sent Events) for real-time streaming connections. OAuth 2.0 authentication with automatic token refresh is built in.

Yes. Bifrost acts as both an MCP client (connecting to external tool servers) and an MCP server (exposing tools to clients). Claude Desktop and other MCP-compatible clients can connect to a single Bifrost gateway URL to discover and use all registered tools.

Virtual keys are scoped credentials for each consumer of your MCP gateway: a user, team, or customer integration. Each key defines which tools it may call at the tool level, not just per server, so customer-facing agents cannot reach internal admin tooling. See AI governance for how keys, budgets, and policies are assigned.

A Virtual MCP server is a curated toolkit your agents see at the gateway, built from MCP Tool Groups. Each group is a named collection of tools from one or more backend MCP servers. Define a group once, attach it to virtual keys, teams, or customers, and Bifrost resolves allowed tools in memory at request time without duplicates.