Gateway RegistryBLOCK
Enterprise-ready MCP Gateway & Registry that centralizes AI development tools with secure OAuth authentication, dynamic tool discovery, and unified access for both autonomous AI agents and AI coding assistants. Transform scattered MCP server chaos into governed, auditable tool access with Keycloak/E
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Unified Agent & MCP Server Registry – Gateway for AI Development Tools
[](https://github.com/agentic-community/mcp-gateway-registry/stargazers) [](https://github.com/agentic-community/mcp-gateway-registry/network) [](LICENSE) [](https://github.com/agentic-community/mcp-gateway-registry/releases)
Get Running Now | Docs | Executive Brief | Slide Deck | Demo Videos | AWS Workshop | Community
The MCP Gateway & Registry is a single, governed control plane for every AI asset in your organization, from MCP servers and AI agents to skills and any custom asset your teams build. It is open source, licensed under Apache 2.0, and runs on Kubernetes (Amazon EKS), fully managed serverless (Amazon ECS), or Docker Compose (Amazon EC2).
It began as a gateway and registry for the [Model Context Protocol (MCP)](https://modelcontextprotocol.io/introdu
d5525b8f8615OBSERVED · 2026-09-27Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-gateway-registry-infra --env A2A_SCANNER_LLM_API_KEY=${A2A_SCANNER_LLM_API_KEY} --env AGENT_BEARER_TOKEN=${AGENT_BEARER_TOKEN} --env AGENT_TOKEN=${AGENT_TOKEN} --env AI_DEFENSE_API_KEY=${AI_DEFENSE_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"mcp-gateway-registry-infra": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"A2A_SCANNER_LLM_API_KEY": "${A2A_SCANNER_LLM_API_KEY}",
"AGENT_BEARER_TOKEN": "${AGENT_BEARER_TOKEN}",
"AGENT_TOKEN": "${AGENT_TOKEN}",
"AI_DEFENSE_API_KEY": "${AI_DEFENSE_API_KEY}"
}
}
}
}Exposed tools (9)
7 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Gadget | read | A custom type |
admins | read | Admin group |
current_time_by_timezone | read | |
currenttime-users | read | Users with access to currenttime server |
ds1 | read | |
mcp_command | read | Call MCP gateway commands (ping, list, call, init). |
read_docs | read | Search and read documentation files from the docs folder. Use this when users ask questions about the project, features, setup, configuration, or troubleshooting. |
registry_task | write | Run service management, imports, user management, or diagnostics tasks. |
shell_command | write | Run a read-only diagnostic command. Only a fixed allowlist of inspection binaries |
Trust audit
BLOCKgrade F · trust 19/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (16 observation(s))
- Network
- declared (15 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
# GITHUB_APP_PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----\n...\n-----END RSA PRIVATE KEY-----"
# github_app_private_key = "-----BEGIN RSA PRIVATE KEY-----\\n...\\n-----END RSA PRIVATE KEY-----"
Send the MCP `initialize` request and capture the response headers (for the session ID) and body (for server info).
**Authentication:** with `REGISTRY_URL` and `KEYCLOAK_URL` exported, `register` fetches the JWT it needs dynamically (this is the same flow the README's post-deployment registration uses). **Do not re
After login the browser lands on `https://<cloudfront>/login?error=oauth2_callback_failed`. The auth-server logs (`/ecs/<name>-auth-server`) show its server-side token exchange returning **401** on `P
parsed = yaml.load(raw) as Record<string, any> | null;
SSH_KEY="${SSH_KEY:-$HOME/.ssh/id_ed25519}"# AWS credentials are OPT-IN. Mounting the whole ~/.aws directory into an
SSH_KEY="${SSH_KEY:-~/.ssh/id_ed25519}"The cloud metadata address (169.254.169.254) is never permitted by either
# unless you allowlist them here. The cloud metadata address (169.254.169.254)
# workload-credential endpoints: EC2 IMDS (169.254.169.254, fd00:ec2::254),
"GATEWAY_GENERIC_TLS_VERIFY=false — the generic hop will NOT verify "
./generate_creds.sh -a keycloak -k https://kc.example.com
# MONGODB_CONNECTION_STRING=mongodb://admin:admin@mongodb:27017/mcp_registry?authMechanism=SCRAM-SHA-256&authSource=admin&retryWrites=false
# Read from .env by init-keycloak.sh in Phase 10; see the generation block above.
content = open('.env').read()open('.env', 'w').write(content)content = open('.env').read()open('.env', 'w').write(content)metrics.db
test.db
# Check if admin password is set
# Check if admin password is set
# Check if admin password is set
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
d5525b8f8615full audit observations/trust-audit/mcp-server/agentic-community__gateway-registry.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-27 | d5525b8f8615 | BLOCK | F | 19 | first audit |
Questions
What is the Gateway Registry MCP server?
Enterprise-ready MCP Gateway & Registry that centralizes AI development tools with secure OAuth authentication, dynamic tool discovery, and unified access for both autonomous AI agents and AI coding assistants. Transform scattered MCP server chaos into governed, auditable tool access with Keycloak/E
What tools does Gateway Registry expose?
9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Gateway Registry safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (19/100) and found 20 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Gateway Registry need?
It reads A2A_SCANNER_LLM_API_KEY, AGENT_BEARER_TOKEN, AGENT_TOKEN, AI_DEFENSE_API_KEY, ANS_API_KEY, ANS_API_SECRET, ANTHROPIC_API_KEY, API_KEY_HASH_ALGORITHM, ASOR_ACCESS_TOKEN, ASOR_CLIENT_SECRET, AUTH0_AUDIENCE and AUTH0_CLIENT_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Gateway Registry run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-gateway-registry-infra at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (d5525b8f8615), read on 2026-09-27. The repository is watched and re-audited when it changes.