Lian MCP Gateway is a dynamic MCP server and policy engine. It learns your systems, exposes them as tools over API or upstream MCP, and enforces exactly who is allowed to do what — with a full audit trail of every call.
Lian MCP Gateway — product demo
Connects agents to the tools they already run
HOW IT WORKS
No hardcoded tools. You teach the gateway your systems once, and every agent gets them — scoped to their identity.
Pick a ready MCP server from the catalog, let the AI build a bridge in a chat, or map a REST endpoint. Credentials stay on the app, never exposed.
Federate identity via OAuth or SAML (Google Workspace, Azure AD). Grant per-group, per-app — or down to a single tool. A no-grant app stays public.
Agents connect to /mcp/{app}. They see only the tools they're allowed to run — and every call is logged with the exact arguments.
WHY A GATEWAY
A single server that fronts many target systems. A path segment selects the app — one connection, your whole stack.
Expose a product's REST API or proxy an upstream MCP — uniformly. Fill the gaps an upstream MCP leaves with the product's own API.
Group → app grants, nullable down to a single tool. Unauthorized tools vanish from tools/list; blocked calls return a clean error.
One row per call — allowed and denied: who, which app/tool, the LLM's exact arguments, the decision and the outcome. Nothing happens off the record.
OAuth + SAML federation. Per-user upstream tokens stored AES-256-GCM encrypted, enrolled right in the login flow — works even in ChatGPT.
Chat with the LLM to design a bridge, import an OpenAPI spec, or warm a catalog server. Every new tool is a proposal you approve before it goes live.
UNDER THE HOOD
# one endpoint, the app is in the path POST /mcp/jenkins Authorization: Bearer <federated-token> { "method": "tools/call", "params": { "name": "last_build", "arguments": { "job": "deploy" } } } # gateway: check group → app → tool, # inject the right credential, call upstream, # write the audit row, return the result.
STEP-BY-STEP GUIDE
Everything happens in the admin console — the left sidebar is your map: Dashboard · Apps · MCP Management · Access control · Authentication · Audit · Logs · Settings.
Do this first. The AI features (Build-with-AI chat and the Tool Builder) call a model, so they do nothing until you add an API key under Settings. No key → the chat and "build tools" buttons return an error. Add it once and every AI feature lights up.
The gateway is model-agnostic — bring your own Anthropic or OpenAI key. It's stored encrypted and never returned by the API (you only ever see "stored").
An "app" is any system you want agents to reach. Three ways in — all end up as an MCP server with its tools imported into the registry.
Describe the system in plain language. The AI picks a strategy — reuse a published npx/uvx MCP package, or write a small Node bridge — and asks for whatever credentials it needs.
The gateway is its own OAuth Authorization Server for MCP clients (Claude, Cursor, ChatGPT) and federates the actual login to your OIDC provider or SAML IdP (Google Workspace, Azure AD).
Each app has a credential mode. In gateway mode the gateway uses one stored token for everyone. In user mode each caller acts as themselves upstream — and this screen collects their token during the normal login.
RBAC is group-based and goes all the way down to a single tool. Groups come from the IdP assertion or can be assigned by hand.
| User | App · Tool | Args | Decision |
|---|---|---|---|
| dana@lian | jenkins · trigger_build | {job:"deploy"} | allow |
| omer@lian | github · delete_repo | {repo:"core"} | deny |
| dana@lian | redash · run_query | {id:42} | allow |
Give your MCP client one URL. It logs in once and sees every app it's allowed to use; each app's tools are namespaced <app>__<tool>.
RUN IT YOURSELF
A single self-contained image runs everything — the Go gateway, the admin console, and the npx/node/python3 runtimes for local bridges. The only thing you bring is a MySQL database (or let the full stack bundle one).
# the image is on Docker Hub docker pull avnersib/mcp-gateway docker run -d --name mcp-gateway \ --env-file .env -p 8120:8120 \ -v mcpgw-data:/app/data \ avnersib/mcp-gateway # .env → MCPGW_DB_*, MCPGW_BASE_URL, MCPGW_ADMIN_USER/PASS # console → http://<host>:8120/ · MCP → /mcp/
# 1. create the database (once) CREATE DATABASE mcpgw CHARACTER SET utf8mb4; GRANT ALL ON mcpgw.* TO 'mcpgw'@'%' IDENTIFIED BY '…'; # 2. configure cp .env.example .env # set DB_*, BASE_URL, ADMIN_* # 3. run docker compose up -d --build # console → http://<host>:8120/ · MCP → /mcp/
# build the whole project from scratch cp .env.full.example .env # set MCPGW_DOMAIN + DB / root / admin passwords docker compose -f docker-compose.full.yml up -d --build # starts: db (mysql:8.4) + gateway (:8120) # tables auto-created on first boot
TLS: the container serves plain HTTP on :8120. Terminate TLS with nginx / Caddy / Traefik / a cloud LB and forward to it. Set MCPGW_BASE_URL to your public HTTPS URL — it's the OAuth issuer and what redirect URIs are built from. For the long-lived MCP stream use proxy_buffering off; proxy_read_timeout 3600s;.
READY WHEN YOU ARE
Connect the first app in minutes. Scope it, audit it, and never wonder what your agents did again.
Open the admin consoleOPEN SOURCE
Free to use, copy, modify and distribute — in your own products, commercial or not.
MIT License Copyright (c) 2026 Avner Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.