# ContextForge: IBM's gateway for the moment every tool became an MCP server

> ContextForge is IBM's Apache-2.0 registry and proxy that federates Model Context Protocol servers, A2A agents and REST or gRPC APIs behind one endpoint, with centralized governance, discovery and observability. It virtualizes legacy services as MCP tools, ships 40 plus plugins including a guardrail family, traces through OpenTelemetry with LLM specific metrics, and runs from PyPI or Docker up to multi-cluster Kubernetes with Redis backed federation.

**IBM/mcp-context-forge** — An AI Gateway, registry, and proxy that sits in front of any MCP, A2A, or REST/gRPC APIs, exposing a unified endpoint with centralized discovery, guardrails and management. Optimizes Agent & Tool calling, and supports plugins.

- Repository: https://github.com/IBM/mcp-context-forge
- Website: https://ibm.github.io/mcp-context-forge/
- Stars: 4,529 · Forks: 887
- Language: Python
- License: Apache-2.0
- Published: 2026-08-08 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/ibm-mcp-context-forge

## One endpoint over three protocol worlds

ContextForge is an open source registry and proxy that federates tools, agents and APIs into one clean endpoint for AI clients, and the three gateways it names cover the current protocol landscape. The Tools Gateway handles MCP, REST, gRPC-to-MCP translation and TOON compression. The Agent Gateway speaks the A2A protocol with OpenAI-compatible and Anthropic agent routing. The API Gateway brings classic concerns to REST services, rate limiting, auth, retries and reverse proxying. The whole runs as a fully compliant MCP server, lets you pin the MCP protocol version such as 2025-11-25, and exposes a single unified interface over diverse backends, deployable via PyPI as mcp-contextforge-gateway or as a container, scaling to multi-cluster Kubernetes with Redis backed federation and caching.

## Legacy APIs, virtualized as MCP tools

The virtualization story wraps non-MCP services as virtual MCP servers. For REST, a tool adapter adapts endpoints into tools with automatic JSON Schema extraction, support for headers, tokens and custom auth, and retry, timeout and rate-limit policies attached per tool. For gRPC, translation runs via the server reflection protocol, with automatic service discovery and method introspection, so a gRPC backend becomes callable MCP surface without hand writing bindings. Tools, prompts and resources register with minimal configuration, and the result is that legacy APIs join the same registry, discovery and governance as native MCP servers, which is the difference between adopting agents incrementally and rewriting the estate.

## Three registries: prompts, resources, tools

Federated content lands in three registries with distinct machinery. Prompts are Jinja2 templates with multimodal support and rollback and versioning, so prompt engineering gets change control. Resources are URI-based with MIME detection, caching and SSE updates for live changes. Tools are native or adapted, with input validation and concurrency controls, the safety rails around whatever a client invokes. Transports span HTTP, JSON-RPC, WebSocket, SSE with configurable keepalive and Streamable HTTP, with stdio available for server-side use, so the same registry serves browser clients, agent runtimes and local tooling without protocol forks.

## Guardrail plugins with pointed names

The plugin system counts 40 plus extensions for additional transports, protocols and integrations, and the pinned package list in pyproject.toml names the security family explicitly, cpex-pii-filter, cpex-secrets-detection, cpex-sql-sanitizer, cpex-encoded-exfil-detection, cpex-rate-limiter, cpex-retry-with-backoff, cpex-output-length-guard and cpex-url-reputation. Read together they describe the actual risks of routing agent traffic, exfiltration through encoded payloads, secrets leaking into tool calls, SQL assembled from model output, runaway output length. Authentication supports Basic, JWT and custom schemes with user-scoped OAuth tokens, and the X-Upstream-Authorization header passes credentials upstream unconditionally when configured, the piece that lets central auth coexist with per-backend credentials.

## An Admin UI built for airgapped networks

The administration surface is deliberately old-school in construction, HTMX 2.0.3 bundled with Alpine.js rather than a heavy JavaScript application, providing real-time management, configuration and log monitoring, with the log viewer offering filtering, search and export. The notable deployment claim is airgapped support, the UI works without internet access because everything is bundled, which matters for the regulated environments a governance gateway naturally serves. The developer experience numbers are stated plainly, 7,000 plus tests, Makefile targets, live reload and pre-commit hooks, with the frontend toolchain, Vite, Tailwind, Vitest, held to devDependencies and built into the package during packaging.

## Tracing with LLM-shaped metrics

Observability is OpenTelemetry native and vendor agnostic, with OTLP support and backends including Phoenix, billed as LLM-focused, plus Jaeger, Zipkin, Tempo, DataDog and New Relic. Distributed tracing spans federated gateways and services, with automatic instrumentation of tools, prompts, resources and gateway operations, so a request crossing three federated services stays one trace. The metric model has an LLM-specific layer, token usage, costs and model performance, the numbers agent infrastructure actually bills and tunes by. The claim of zero-overhead when disabled with graceful degradation addresses the usual objection to always-on instrumentation, and dedicated compose overlays exist for Phoenix and Langfuse setups.

## Three languages, two mandatory secrets, nine compose profiles

The repository is polyglot by design, Python and FastAPI for the gateway, a Rust workspace with edition 2024 and the rmcp crate for sample servers, and a JavaScript toolchain for the web UI. Deployment posture is strict about two environment variables, JWT_SECRET_KEY and AUTH_ENCRYPTION_SECRET are required in every environment including local development, and the gateway will not start without them. The compose file organizes operations into profiles, a default stack of gateway, Postgres, Redis and Nginx, plus opt-in profiles for SSO with Keycloak, monitoring with Prometheus, Grafana and Loki, testing with Locust and an A2A echo agent, resilience, benchmark, TLS, the MCP Inspector and the web UI. Releases move quickly, v1.0.10 on 2026-09-07, a pagination patch on 2026-09-21 and v1.0.11 on 2026-09-28, with the last push on 2026-09-25.

## Conclusion

Deploy ContextForge when an organization's agents need one governed front door over a growing sprawl of MCP servers, A2A agents and plain REST services, since the federation, translation and guardrail layers exist precisely for that sprawl. Skip it for a single MCP server with one consumer, where a gateway is architecture without a problem. Before deploying, set JWT_SECRET_KEY and AUTH_ENCRYPTION_SECRET, the gateway refuses to start without them even in local development, choose the compose profile matching the stack, and review the guardrail plugins against your data policies since secrets detection, PII filtering and SQL sanitization are opt-in capabilities, not defaults you can assume.

## FAQ

### What is MCP context forge?

ContextForge, IBM's mcp-context-forge, is an Apache-2.0 registry and proxy that federates Model Context Protocol servers, A2A agents and REST or gRPC APIs into one endpoint with centralized governance, discovery and observability. It runs as a fully compliant MCP server, translates gRPC and REST into MCP tools, and supports 40 plus plugins.

### How do you deploy ContextForge?

Install from PyPI as mcp-contextforge-gateway or run the container image, setting JWT_SECRET_KEY and AUTH_ENCRYPTION_SECRET, which are required in every environment or the gateway will not start. Docker Compose profiles add SSO, monitoring, testing and TLS stacks, and Kubernetes deployments scale with Redis-backed federation and caching.

### What plugins does ContextForge provide?

More than 40 plugins extend transports, protocols and integrations. The pinned security family includes PII filtering, secrets detection, an SQL sanitizer, encoded exfiltration detection, a rate limiter, retry with backoff, an output length guard and URL reputation checks.

## Sources

- [Official documentation](https://ibm.github.io/mcp-context-forge/)
- [Official README](https://github.com/IBM/mcp-context-forge#readme)
- [Project repository](https://github.com/IBM/mcp-context-forge)
- [Release notes](https://github.com/IBM/mcp-context-forge/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/ibm-mcp-context-forge
