# agentgateway: Rust Proxy for MCP and A2A Agent Communication

> agentgateway is an open-source proxy built in Rust that provides security, observability, and governance for AI agent traffic across LLM providers, MCP tool servers, and agent-to-agent communication using the A2A protocol. It is a Linux Foundation project and deploys either as a standalone binary or on Kubernetes.

**agentgateway/agentgateway** — Next Generation Agentic Proxy for AI Agents and MCP servers

- Repository: https://github.com/agentgateway/agentgateway
- Website: https://agentgateway.dev
- Stars: 5,080 · Forks: 891
- Language: Rust
- License: Apache-2.0
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/agentgateway-agentgateway

## What Problem agentgateway Solves

As AI applications grow from a single LLM call into fleets of agents calling tools and talking to each other, the concerns that a traditional API gateway handles, including authentication, rate limiting, content filtering, and distributed tracing, become equally relevant to agent traffic. agentgateway addresses this by sitting between agents and their downstream targets, whether those targets are LLM providers, MCP tool servers, or other agents. Rather than requiring each agent to implement these concerns independently, the gateway centralises them. The README describes it as providing 'drop-in security, observability, and governance for agent-to-LLM, agent-to-tool, and agent-to-agent communication across any framework and environment.' It is a Linux Foundation project, which means the governance and intellectual property framework is separate from any single vendor. The project is written in Rust, with the controller component using Go, as visible in the workspace Cargo.toml and go.mod files in the repository.

## Three Gateway Modes and How They Differ

The README organises agentgateway's capabilities into three distinct gateway types. The LLM Gateway routes traffic to major providers, including OpenAI, Anthropic, Gemini, and AWS Bedrock, through a unified OpenAI-compatible API. It adds budget and spend controls, prompt enrichment, load balancing, and failover on top of that routing layer. The MCP Gateway handles connections between LLMs and tools or external data sources. It supports stdio, HTTP, SSE, and Streamable HTTP transports, alongside OpenAPI integration and OAuth authentication. The A2A Gateway handles agent-to-agent communication using Google's A2A protocol, with capability discovery and modality negotiation. Each gateway type is independent; an operator can deploy agentgateway purely as an LLM gateway and ignore A2A entirely, or combine all three depending on the architecture. A fourth component, Inference Routing, handles routing to self-hosted models on Kubernetes using extensions to the Kubernetes Inference Gateway, with routing decisions based on GPU utilisation, KV cache state, LoRA adapters, and queue depth.

## Security, Guardrails, and Observability Capabilities

The README lists several layers of security that agentgateway provides. Authentication supports JWT, API keys, and OAuth. Authorisation uses fine-grained role-based access control implemented with the CEL (Common Expression Language) policy engine, which allows writing precise policies as expressions rather than a fixed permission model. Rate limiting and TLS are also listed. For content filtering, the README describes a multi-layered guardrails system that supports regex filtering, OpenAI moderation, AWS Bedrock Guardrails, Google Model Armor, and custom webhooks. Each guardrail method covers a different scenario: regex is fast and deterministic, while a webhook allows routing filtering decisions to an arbitrary external service. Observability uses OpenTelemetry for metrics, logs, and tracing, making agentgateway compatible with observability stacks that already collect OTLP data. The repository includes a built-in web UI for exploring agent-to-agent and agent-to-tool connections.

## Building and Deploying agentgateway

The Makefile in the repository shows two primary build paths. For a standard Docker image:

```bash
make docker
```

For a statically linked musl build:

```bash
make docker-musl
```

The Cargo.toml requires Rust edition 2024 and sets `rust-version = "1.90"`. The Dockerfile uses `rust:1.98.0-trixie` as the builder image, compiles the UI with Node 24.17.0, and produces a minimal Debian-based runtime image. Kubernetes deployment uses the built-in controller and the Kubernetes Gateway API, with documentation at agentgateway.dev/docs/kubernetes/latest. The standalone path uses flat YAML configuration without the Kubernetes controller, described at agentgateway.dev/docs/standalone/latest. The repository also provides a Tiltfile for development-loop deployments and a set of example directories covering LLM telemetry, MCP authentication, MCP authorisation, semantic routing, and prompt guard scenarios, which give concrete starting points for each gateway type.

## How agentgateway Compares to a Standard API Gateway

A traditional API gateway such as Kong handles HTTP traffic: routing, authentication, rate limiting, and transformation at the HTTP level. agentgateway shares some of those concerns but is built around AI-native protocols. MCP, which defines how LLMs discover and call tools, and A2A, which handles inter-agent communication, are not HTTP REST patterns; they carry their own framing, transport options, and capability negotiation. An API gateway that does not understand MCP cannot inspect or route individual tool calls within an MCP stream, cannot enforce per-tool rate limits, and cannot perform modality negotiation for A2A tasks. agentgateway operates at the protocol level for both MCP and A2A rather than treating them as opaque HTTP payloads. This distinction is meaningful for teams whose agents call a large number of tools or whose architecture involves multiple cooperating agents, but it is irrelevant for simpler setups that only need to route HTTP calls to an LLM API.

## Limitations and Deployment Complexity

The repository is actively developed, with the most recent release being v1.6.0-alpha.2 on 2026-09-22. The alpha label on the current major version is a concrete signal that the API and configuration format are not yet stable. Teams that adopt agentgateway now may face configuration changes when v1.6.0 reaches a stable release. The Kubernetes deployment path, which combines the built-in controller with the Kubernetes Gateway API, adds operational complexity that small teams or individuals running a few agents will not want. The standalone path with flat YAML is simpler but still requires running a separate process that all agent traffic must pass through. The go.mod file lists a Go 1.27 requirement for the controller component, which is the go.mod used for the Kubernetes controller side of the codebase. Server-side OTLP export for the main server is listed in the README as unavailable pending a runtime integration, meaning OpenTelemetry tracing for the server itself is not yet complete despite being available for connectors.

## Licence and Community

agentgateway is licensed under Apache-2.0, which permits commercial use, modification, and redistribution without requiring derived works to use the same licence. As a Linux Foundation project, the governance structure is defined in CHARTER.md and CODE_OF_CONDUCT.md in the repository. The project holds regular community meetings with a published calendar and posts recordings to Google Drive. The repository includes a CONTRIBUTION.md with contributing instructions, and the CODEOWNERS file identifies maintainers by component. The last push to the repository was on 2026-09-15.

## Conclusion

agentgateway fits teams deploying AI agents in production who need auth, rate limiting, guardrails, and observability without wiring those concerns into every agent individually. It is the right choice when the target environment is Kubernetes or when the operator needs fine-grained RBAC with a CEL policy engine. Teams running a single agent for personal use will find the operational overhead of a gateway unnecessary. Before adopting, check the release cadence: v1.6.0 is still in alpha as of the releases listed, and the Kubernetes controller path carries more moving parts than the standalone flat-yaml deployment.

## FAQ

### What does an agent gateway do?

An agent gateway sits between AI agents and their downstream targets, including LLM providers, MCP tool servers, and other agents, to enforce security policies, rate limits, content filters, and observability in a centralised place rather than in each agent separately. agentgateway specifically adds auth, RBAC with a CEL policy engine, OpenTelemetry, and multi-layer guardrails.

### What are the key differences between agentgateway and kgateway?

The README does not describe kgateway directly, so a complete comparison is not possible from the available material. agentgateway is built around AI-native protocols (MCP and A2A) and adds inference routing, content guardrails, and agent-to-agent governance. It is a Linux Foundation project deployed as a standalone binary or on Kubernetes.

### What is agentgateway?

agentgateway is an open-source Rust proxy for AI agent traffic. It handles LLM routing, MCP tool connections, and A2A agent-to-agent communication, adding authentication, fine-grained RBAC, rate limiting, content guardrails, and OpenTelemetry observability across all three channels. It is a Linux Foundation project.

### How does agentgateway compare to an API gateway?

A standard API gateway operates at the HTTP level and cannot inspect MCP tool calls or A2A capability negotiation within a stream. agentgateway understands those AI-native protocols and can enforce per-tool rate limits or per-modality A2A policies that an HTTP-level gateway would treat as opaque payload.

## Sources

- [agentgateway/agentgateway on GitHub](https://github.com/agentgateway/agentgateway)
- [License: Apache-2.0](https://github.com/agentgateway/agentgateway/blob/main/LICENSE)
- [Project website](https://agentgateway.dev)
- [README](https://github.com/agentgateway/agentgateway/blob/main/README.md)
- [Releases](https://github.com/agentgateway/agentgateway/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/agentgateway-agentgateway
