5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

Barzel · Routing & Control

Barzel Central Gateway: the AI governance control plane

One control layer for increasingly intelligent systems.

Barzel Central Gateway provides centralized infrastructure for managing AI capabilities, resources, routing, policies, approvals and access across AI-powered environments.

Capability registry Routing
crm.toolspolicy: read-only
billing.mcpapproval required
warehouse.queryscoped: analytics
infra.adminrestricted

Illustrative interface. Capabilities are registered once, then routed and governed centrally instead of per client.

Definition

Barzel Central Gateway is an MCP gateway and AI control plane that centralizes how AI capabilities, resources, routing, policies and access are managed.

The problem

AI capability sprawl

Teams stand up their own MCP servers, tools and credentials. Every client connects directly to every server, permissions live in scattered configuration files, and nobody has a single view of which AI capabilities exist or who can reach them.

The more useful agents become, the faster that sprawl grows — and the harder it becomes to change a policy in one place.

The approach

One entry point, centrally governed

Capabilities are registered with the gateway, which resolves what a client is asking for, applies policy, brokers access and routes the request to the right resource. Governance is defined once and enforced consistently.

Pair it with BarzelVault when the requested operation itself needs evaluation before execution.

Capabilities

What Barzel Central Gateway is designed to do

Capability management

Register AI capabilities and resources once, then manage them as a governed catalogue rather than per-project configuration.

MCP routing

Direct requests from AI clients to the correct server or resource without hard-wiring each connection.

Policy management

Define access and usage rules centrally, so a change applies everywhere instead of in a dozen places.

Secure AI access

Broker credentials and scopes at the gateway rather than distributing secrets to every agent and client.

Resource governance

See which capabilities exist, who may use them and under what conditions — the inventory question answered in one place.

AI orchestration

Coordinate access across multiple servers and services so multi-step agent work runs through one controlled path.

How it works

Request, resolve, authorize, route

  1. Step 01

    A client requests a capability

    An AI client or agent asks the gateway for a tool or resource rather than connecting directly.

  2. Step 02

    The registry resolves it

    The gateway identifies which registered server or resource can satisfy the request.

  3. Step 03

    Policy authorizes access

    Central rules decide whether this client, in this context, may use that capability — and with which scope.

  4. Step 04

    The request is routed

    Traffic reaches the resource through a single controlled path that can be observed and changed centrally.

Use cases

  • Managing MCP servers at scaleBring many team-owned servers under one governed entry point.
  • Centralized AI access controlDecide once which agents may reach which systems, and revoke in one place.
  • Credential containmentKeep secrets at the gateway instead of embedding them in agent configurations.
  • Multi-team platformOffer AI capabilities to product teams as a governed internal service.

Who it is for

  • Platform and infrastructure teams running AI for several product teams
  • Engineering leaders consolidating MCP servers and internal tools
  • Security teams that need one place to grant and revoke AI access

Technical context

The gateway sits between AI clients and Model Context Protocol servers, APIs and internal services. It is the routing and access layer of the Barzel ecosystem, and pairs with Barzel FinOps Atlas for the financial view of AI usage.

Shipping today

Barzel Central Gateway, running in public

Barzel Central Gateway is published and callable now. These are screenshots of the live listing and documentation, not mockups. See the listing ↗

Live on the marketplace A free Community tier at 1,000 calls a month, then $10 to $79.
Identity-aware, zero-trust routing Policy evaluates identity, role, department, environment, region, PII presence and credential mode before execution.

Published surface

Free tier 1,000 calls/mo
Policy inputs 10 dimensions
Enforcement outcomes 6 classes
Evidence output SIEM-ready packs
Call success rate 100%
Transport MCP over HTTP

Six enforcement outcomes

  • denial
  • redaction
  • human approval
  • quorum requirement
  • budget control
  • per-user OAuth/OIDC

Plans

Plan Price Included usage
Community Free 1,000 calls/mo
Starter $10/mo 10,000 calls/mo
Team $79/mo 100,000 calls/mo
Business $149/mo 250,000 calls/mo

Prices as published on the marketplace listing, 2 September 2026. Check the listing for current tiers.

FAQ

Questions people ask first

What is an MCP gateway?

A central entry point in front of multiple Model Context Protocol servers and tools. Rather than every AI client connecting to every server, requests pass through the gateway, which resolves capabilities, applies policy and controls access.

MCP gateway vs MCP server — what is the difference?

A server exposes tools or resources. A gateway sits in front of many servers and governs discovery, routing and access across them.

How does it relate to BarzelVault?

The gateway decides where a request may go. BarzelVault decides whether the action itself may happen. Together they cover access and execution.