hub hero bg 1

Docker MCP Enterprise Gateway

One secure gateway for all your tools

Connect your agents to the MCP servers you approve. Policy governs every call, credentials stay in your secret store, and every decision is recorded.
mcp hero
なぜ今?

Agents need access. Enterprises need control.

One registry for container images, hardened content, large-language models, MCP servers, and more. Published, versioned, and verifiable in the same place.
Docker MCP Enterprise Gateway sits between your agents and your MCP servers. It authenticates the user, decides which servers and tools they can reach, applies policy to each call, supplies the credentials, and records the result.
mcp why now
ガバナンス

Say what agents can do. Prove what they did.

Approve servers, scope tools to groups, write rules for each call, and revoke any of it organization-wide.
mcp governance
Every decision recorded with the identity that made the call and the rule that fired.

サーバ

Approve what the organization can reach. Unvetted servers are denied by default.

ツール

Expose only the tools a group needs, not the whole catalog a server ships.

ポリシー

Allow and deny by server, tool, transport, and call, evaluated before anything runs.

Revocation

Cut off a server or a tool and every session picks it up on the next call.

監査

A structured event per evaluation, tied to user and agent, streamed to your SIEM.

mcp hero bg a
mcp hero governance focus
How it connects

One enforcement point, whatever the server is.

Hosted services, containerized servers, and the servers your teams build all route through the same identity, policy, and audit checks. Containerized servers run isolated.
mcp hero bg a
mcp hero how it connects focus
Catalog and workflow

Add a server once.
Publish it to those that need it.

Developers connect their client once. The servers they see, the tools exposed, and the credentials behind them are managed centrally. No tickets, no config files.

Dynamic MCP keeps large catalogs affordable
A big catalog can consume an agent’s context before it does any useful work. With Dynamic MCP, the agent discovers and invokes tools as it needs them, so catalog growth stops taxing every request.
mcp catalog workflow 1

Approve once, publish by group

The groups you scope it to pick it up on their next session.

mcp catalog workflow 2

Connect the client once

One endpoint per client. Catalog and policy changes land without anyone reconfiguring anything.

mcp catalog workflow 3

Containerized servers run isolated

Each one in its own container, separated from the machine it was launched from.

mcp catalog workflow 4

Credentials stay in your store

Supplied when a tool runs, never distributed through client config files.

Docker を選ぶ理由

We already run the servers you are trying to govern.

Governing MCP means controlling how servers are packaged, distributed, and executed. That is what Docker does.

We package and distribute MCP servers

We publish and version the servers your developers want, in registries you already trust.

We control how they execute

Isolated execution on the runtime you already run in production.

One control point across every source

Remote, internal, and Docker-packaged servers enforce the same identity, policy, and audit rules.

The same model covers the agent itself

Tools called from Docker Sandboxes and third-party clients follow one policy model, not two.

エンタープライズ対応

Plugs into the systems you already trust.

No second identity system, no second console, no new place for secrets to live.
mcp enterprise ready

SSO and identity

Sign in through your provider. Policy follows the groups you already manage.

Audit and SIEM

Structured events per tool call, in the pipeline your security team already watches.

シークレット

Credentials are read at call time from the store that already holds them.

ポリシー

Write rules in the gateway, or delegate to the policy engine you already run.

Catalogs and registries

Publish private catalogs from registries you already operate, internal servers included.

配備

Deploy it where your compliance team already said yes.

本日発売

Managed in your cloud

Docker-operated, inside your own account or VPC. Data and traffic stay in your environment.

本日発売

Air-gapped appliance

Private Kubernetes with no outbound connection. Catalogs, server images, and policy load from inside your network.

近日公開

Docker-managed cloud

Multi-tenant, operated by Docker. Governed MCP without running the infrastructure.

How it fits

Control agent execution. Control agent tool use. Audit both.

Two enforcement points, one record. Use either on its own, or run both under central policy.
In production

Already governing MCP in production.

Thousands of developers

Multiple agent harnesses

Global semiconductor manufacturer

Replaced separate MCP configurations across several coding agents with one approved catalog for thousands of developers. Its platform team scopes access by identity group and revokes it organization-wide without redistributing anything.

Thousands of developers

Multiple agent harnesses

Consumer social platform

With hundreds of millions of monthly users, it retired a homegrown MCP proxy for a governed gateway: identity-bound policy, a record of every tool call, and internal servers reaching agents without handing credentials to developers.

よくある質問

What does the gateway actually do on each call?

It authenticates the user through your identity provider, resolves which servers and tools that user’s groups can reach, evaluates policy for the specific call, injects the credentials the call needs, routes it to the server, and records the decision.

Which clients can connect?

Clients that speak MCP, including Claude Code, Cursor, VS Code, Codex, ChatGPT Enterprise, and agents your teams build in house.

What kinds of servers can I connect?

Remote services over HTTP or SSE, containerized servers, and the internal servers your own teams build. Containerized servers run isolated in their own containers.

Where do credentials live?

In your approved secret store. The gateway supplies them when a tool runs, so long-lived credentials are not distributed through client configuration files.

Can it run fully air-gapped?

Yes. Catalogs, server images, and policy load from inside your network with no outbound connection.

How does this relate to Docker Sandboxes?

Sandboxes governs the environment an agent runs in. The gateway governs which servers and tools it can call. Either works alone, and many customers run both.

What is Dynamic MCP?

A way of exposing tools so the agent discovers and invokes what it needs instead of loading every definition up front, which keeps context usage flat as the catalog grows.

Give agents access. Keep control of every call.

Run governed MCP in your cloud, fully air-gapped, or in Docker’s cloud when it lands.