Runtime authorization & controls
Docker MCP Gateway
MIT-licensed gateway from Docker that acts as a proxy between MCP clients and MCP servers, running each catalogued local server in an isolated container with restricted privileges, network access and resources, injecting credentials centrally and applying per-profile tool allowlists. It provides no semantic inspection of prompts or tool arguments.
open_source · generally available · Research snapshot 2026-09-06
Visit the official product source ↗Where it fits
Runtime authorization & controls · Observability & traceability
Useful conversation with: Developer platform lead, Application security engineer, DevOps engineer.
Ask for a demonstration
Show me the MCP Gateway running two catalogue servers in isolated containers with a profile tool allowlist that hides one tool, plus the call trace for a blocked request.
Capabilities and evidence
Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.
Documented by provider
MCP servers run in isolated Docker containers with restricted privileges, network access and resource usage, with the gateway acting as a centralised proxy managing lifecycle, routing and authentication.
Limit: Documentation does not quantify isolation guarantees against container escape or cover remote third-party MCP servers.
Source s1 · Source s2
Documented by provider
Tool allowlists are managed in profiles, and individual tools on a server can be enabled or disabled, determining which servers and tools clients can reach.
Limit: Allowlists are static configuration; no runtime policy evaluation on call arguments is documented.
Source s2
Documented by provider
The gateway injects required credentials before forwarding requests and provides logging and call-tracing for AI tool activity.
Limit: Log retention, export and SIEM integration are not documented on the fetched pages.
Source s1 · Source s2
Limitations to discuss
- No prompt or content inspection
- No human approval workflow documented
Sources
- MCP Gateway - Docker Docs · Docker, Inc. · official docs
Access date reported by researcher: 2026-09-06 - docker mcp CLI plugin / MCP Gateway · Docker (GitHub) · official repository
Access date reported by researcher: 2026-09-06
Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.
Suggest a correction