Agentomy MCP Gateway
OfficialClick on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Agentomy MCP GatewayDeny any tool call that would modify production data"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Agentomy MCP Gateway
Governs any stdio MCP server by sitting between the agent and the server. Every
tools/call is checked against your policy before it reaches the server. A refusal is
answered by the gateway and never forwarded, so the side effect does not happen.
Nothing about the upstream server changes. It is not patched, not forked, and never learns it is being governed.
Why interpose instead of observe
A sidecar that watches MCP traffic and reports on it produces a record of the things it failed to stop. Sitting on the wire is what turns a report into a refusal.
Related MCP server: jamjet-policy
Install and run
# Instead of launching the MCP server directly:
# my-mcp-server --flag
# launch it through the gateway:
AGENTOMY_ENDPOINT=https://your-agentomy \
AGENTOMY_API_KEY=... \
agentomy-mcp-gateway -- my-mcp-server --flagIn an agent's MCP configuration, replace the server's command and args:
{
"mcpServers": {
"dev-tools": {
"command": "agentomy-mcp-gateway",
"args": ["--", "the-original-command", "--its", "--flags"],
"env": { "AGENTOMY_ENDPOINT": "https://your-agentomy", "AGENTOMY_API_KEY": "..." }
}
}
}That is the whole integration. One config change, per agent, by the operator.
Variable | Required | Meaning |
| yes | Platform base URL |
| no | Bearer token |
| no | Identity on the decision, default |
| no | Decision timeout, default |
What it does to the protocol
Message | Behaviour |
| Forwarded unchanged |
| Not forwarded. JSON-RPC error |
| Dropped. A notification must never be answered, so the call is stopped and the reply withheld |
Everything else | Forwarded unchanged |
Upstream to agent | Forwarded verbatim. Results are not rewritten |
Requests are adjudicated in arrival order. Deciding concurrently would let a later call reach the server before an earlier one was resolved, which is a reordering bug that only shows up under load.
Fail-closed, and what that costs you
Every failure path denies:
Condition | Reason returned |
Endpoint unreachable |
|
Decision timed out |
|
Non-2xx response |
|
Body not JSON, or no boolean |
|
Fleet halted |
|
Policy refused |
|
The honest trade: if the platform is down, governed tools stop working. That is the correct behaviour for a governance component and it is a real availability coupling. Run the platform accordingly.
The reasons are distinct on purpose. An operator seeing governance_unreachable has an
outage; one seeing policy_denied has a policy question. Collapsing them into "denied"
would make the two indistinguishable at exactly the moment the difference matters.
A missing authorized field denies rather than being read for truthiness, because a
truthiness check turns any unexpected payload, including an error object, into an allow.
What it does not do
It governs actions, not discovery. tools/list passes through. Narrowing what an agent
may see while leaving what it may do ungoverned would be theatre in the wrong place.
It does not rewrite results. The gateway adjudicates requests; making it edit responses would turn it into a participant in the conversation rather than a gate on it.
It does not inspect arguments semantically. Policy receives the tool name and the argument keys, not the values. Argument-level policy is a platform concern and sending full argument values to a decision endpoint would put file contents and shell commands into a second system.
Licence
Apache-2.0.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityBmaintenanceGovernance proxy for MCP servers. Wraps any MCP server with policy evaluation, human approval workflows, and hash-chain audit trails. Supports stdio and Streamable HTTP transports.11012Apache 2.0

jamjet-policyofficial
AlicenseAqualityBmaintenanceDrop-in stdio interceptor that gates MCP tools/call requests through a YAML policy (block / require_approval / audit / budget cap) before they reach the real server. The same policy file is reused by @jamjet/claude-code-hook and @jamjet/openai-guardrail, so one rule set covers Claude Desktop, Cursor, OpenAI Agents, and custom clients.32Apache 2.0- Flicense-qualityCmaintenanceWraps your existing MCP servers and checks each tool call against policy and live state before it runs. Allow, block, or require a refresh, with a reason the agent can act on.5
- Alicense-qualityBmaintenanceA least-privilege enforcement proxy for MCP servers. It sits between MCP clients and upstream servers, enforcing tool policies, hiding denied tools, requiring human approval for risky actions, and providing a structured audit trail.MIT
Related MCP Connectors
Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
A paid remote MCP for OpenAI Codex agent coordination MCP, built to return verdicts, receipts, usage
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/getagentomy/mcp-gateway'
If you have feedback or need assistance with the MCP directory API, please join our Discord server