Developer Tools · Security

Secure MCP Gateway

enkryptai/secure-mcp-gateway

Featured Blog Post: Learn how the Secure MCP Gateway prevents top attacks and vulnerabilities in our latest blog.

Install

pip install secure-mcp-gateway

Client configuration

{
  "mcpServers": {
    "Enkrypt Secure MCP Gateway": {
      "command": "docker",
      "args": [
        "run",
        "--rm",
        "-i",
        "-e",
        "MCP_TRANSPORT=stdio",
        "-v",
        "C:\\Users\\<user>\\.enkrypt\\docker:/app/.enkrypt/docker",
        "-e",
        "ENKRYPT_GATEWAY_KEY",
        "-e",
        "ENKRYPT_PROJECT_ID",
        "-e",
        "ENKRYPT_USER_ID",
        "secure-mcp-gateway"
      ],
      "env": {
        "ENKRYPT_GATEWAY_KEY": "<ENKRYPT_GATEWAY_KEY>",
        "ENKRYPT_PROJECT_ID": "<ENKRYPT_PROJECT_ID>",
        "ENKRYPT_USER_ID": "<ENKRYPT_USER_ID>"
      }
    }
  }
}

Environment variables

ENKRYPT_GATEWAY_KEYENKRYPT_PROJECT_IDENKRYPT_USER_IDENKRYPT_APIKEYENKRYPT_MCP_GATEWAYMCP_HTTP_MODE
Category
Developer Tools, Security
Updated
Oct 6, 2026

Features

  • Authentication: We use Unique Key to authenticate with the Gateway. We also use Enkrypt API Key if you want to protect your MCPs with Enkrypt Guardrails. Additionally, a secure admin_apikey…

  • Ease of use: You can configure all your MCP servers either locally in enkrypt_mcp_config.json or — better yet for teams and production — in Enkrypt cloud (run secure-mcp-gateway generate-config…

  • Dynamic Tool Discovery: The Gateway discovers tools from the MCP servers dynamically and makes them available to the MCP client

  • Restrict Tool Invocation: If you don't want all tools to be accessible of a an MCP server, you can restrict them by explicitly mentioning the tools in the Gateway config so that only the allowed…

  • Caching: We cache the user gateway config and tools discovered from various MCP servers locally or in an external cache server like KeyDB if configured to improve performance

  • Guardrails: You can configure guardrails for each MCP server in Enkrypt both on input side (before sending the request to the MCP server) and output side (after receiving the response from the MCP…

  • Logging: We log every request and response from the Gateway locally in your MCP logs and also forward them to Enkrypt (Coming soon) for monitoring. This enables you to see all the calls made in your…

  • Sandbox Isolation: MCP servers can be launched inside isolated sandbox environments (Docker, Podman, or microVMs) so that a compromised or malicious server cannot access the host filesystem, network,…

  • MCP Config is an array of MCP servers like mcp_server_1, mcp_server_2, mcp_server_3 etc.

  • User is a user of the gateway with unique email and ID

Tools (6)

  • local_apikey

    The cloud enkrypt_config.api_key is not accepted as an admin credential (would silently widen the trust boundary).

  • enkrypt

    The cloud enkrypt_config.api_key is also accepted as an admin credential.

  • Windows

    USERPROFILE%\.enkrypt\enkrypt_mcp_config.json

  • macOS/Linux

    enkrypt/enkrypt_mcp_config.json

  • admin_apikey

    (root-level): Used for all administrative operations (user management, project management, etc.)

  • apikeys

    (in the apikeys section): Used for gateway access by users

Details on this page are taken from the project's README. Open README

Supported clients

Clients mentioned in this server's README:

View all
Claude Desktop logo

Claude Desktop

Desktop · Freemium · Proprietary

Anthropic's official Claude AI desktop application. Supports MCP servers to extend functionality.

WindowsMacOS
Cursor logo

Cursor

Desktop · Freemium · Proprietary

The first agentic IDE. The Cursor editor truly merges how developers and AI work together, delivering a magical coding experience.

WindowsMacOSLinux

Related MCP servers

More servers
Playwright logo

Playwright

microsoft/playwright

72.2k

Playwright is a framework for web automation and testing. It drives Chromium, Firefox, and WebKit with a single API — in your tests, in your scripts, and as a tool for AI agents.

Developer Tools
repomix logo

repomix

yamadashy/repomix

15.2k

Repomix is a tool that packs a codebase into an AI-friendly format, supporting local and remote repository processing and providing code compression, security checks and multiple output formats.

Developer Tools
UI-TARS-desktop logo

UI-TARS-desktop

bytedance/UI-TARS-desktop

12.9k

TARS is ByteDance's multimodal AI agent stack, shipping two projects: Agent TARS (a CLI and Web UI agent built on MCP) and UI-TARS-desktop (a desktop GUI agent).

Developer Tools
blender logo

blender

ahujasid/blender-mcp

10.6k

formerly blender-mcp — the PyPI package is now mcp-for-blender. Existing setups keep working; no config change is required. Read more.

Developer Tools
Playwright Browser Automation logo

Playwright Browser Automation

microsoft/playwright-mcp

9.2k

A Model Context Protocol (MCP) server that provides browser automation capabilities using Playwright. This server enables LLMs to interact with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models.

Developer Tools
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Developer Tools