According to Help Net Security, Tuskira has released AI Agent Gateway as an open-source tool that sits between AI agents and the MCP tool servers and model providers they call. It runs in your own environment and does not require a Tuskira account. The design addresses a common setup where model API keys and MCP credentials are copied into each agent's config on laptops and CI runners, leaving them exposed if any file is compromised.
The gateway works by having agents register it as their MCP server and send a gateway key plus profile name with each request. The key is tied to a tenant and role, and the gateway checks whether that profile may use the requested tool before pulling the real credential from an encrypted store and attaching it to the outgoing call. Denied calls are logged and never reach the backend. The same gateway can handle model traffic by changing an SDK's base URL, and it records token usage and estimated cost.
The source flags two defaults to review. A key with no profile attached lets the caller choose its own profile in a request header, so unbound keys should be bound to a profile. The demo stack also stores LLM request and response bodies up to 1 MiB each for display, and that storage can be disabled with one setting. The shipped Docker Compose file allows outbound connections to the host and loopback for local testing; Tuskira's instruction is to remove those on anything shared. Outside those exceptions, the gateway refuses private and loopback addresses by default and always blocks cloud metadata addresses.