Barzel · Routing & Control
Barzel Central Gateway: the AI governance control plane
One control layer for increasingly intelligent systems.
Barzel Central Gateway provides centralized infrastructure for managing AI capabilities, resources, routing, policies, approvals and access across AI-powered environments.
Illustrative interface. Capabilities are registered once, then routed and governed centrally instead of per client.
Definition
Barzel Central Gateway is an MCP gateway and AI control plane that centralizes how AI capabilities, resources, routing, policies and access are managed.
The problem
AI capability sprawl
Teams stand up their own MCP servers, tools and credentials. Every client connects directly to every server, permissions live in scattered configuration files, and nobody has a single view of which AI capabilities exist or who can reach them.
The more useful agents become, the faster that sprawl grows — and the harder it becomes to change a policy in one place.
The approach
One entry point, centrally governed
Capabilities are registered with the gateway, which resolves what a client is asking for, applies policy, brokers access and routes the request to the right resource. Governance is defined once and enforced consistently.
Pair it with BarzelVault when the requested operation itself needs evaluation before execution.
Capabilities
What Barzel Central Gateway is designed to do
Capability management
Register AI capabilities and resources once, then manage them as a governed catalogue rather than per-project configuration.
MCP routing
Direct requests from AI clients to the correct server or resource without hard-wiring each connection.
Policy management
Define access and usage rules centrally, so a change applies everywhere instead of in a dozen places.
Secure AI access
Broker credentials and scopes at the gateway rather than distributing secrets to every agent and client.
Resource governance
See which capabilities exist, who may use them and under what conditions — the inventory question answered in one place.
AI orchestration
Coordinate access across multiple servers and services so multi-step agent work runs through one controlled path.
How it works
Request, resolve, authorize, route
Step 01
A client requests a capability
An AI client or agent asks the gateway for a tool or resource rather than connecting directly.
Step 02
The registry resolves it
The gateway identifies which registered server or resource can satisfy the request.
Step 03
Policy authorizes access
Central rules decide whether this client, in this context, may use that capability — and with which scope.
Step 04
The request is routed
Traffic reaches the resource through a single controlled path that can be observed and changed centrally.
Use cases
- Managing MCP servers at scaleBring many team-owned servers under one governed entry point.
- Centralized AI access controlDecide once which agents may reach which systems, and revoke in one place.
- Credential containmentKeep secrets at the gateway instead of embedding them in agent configurations.
- Multi-team platformOffer AI capabilities to product teams as a governed internal service.
Who it is for
- Platform and infrastructure teams running AI for several product teams
- Engineering leaders consolidating MCP servers and internal tools
- Security teams that need one place to grant and revoke AI access
Technical context
The gateway sits between AI clients and Model Context Protocol servers, APIs and internal services. It is the routing and access layer of the Barzel ecosystem, and pairs with Barzel FinOps Atlas for the financial view of AI usage.
Shipping today
Barzel Central Gateway, running in public
Barzel Central Gateway is published and callable now. These are screenshots of the live listing and documentation, not mockups. See the listing ↗
Barzel Central Gateway listed on the MCPize marketplace with a free Community tier at 1,000 calls per month and paid Starter, Team and Business plans.
Barzel Central Gateway enterprise use cases: registering and inventorying MCP servers, building an MCP capability graph, route recommendation, identity-aware policy evaluation, tool risk scoring, workflow simulation and SIEM-ready evidence packs.
Published surface
Six enforcement outcomes
- denial
- redaction
- human approval
- quorum requirement
- budget control
- per-user OAuth/OIDC
Plans
| Plan | Price | Included usage |
|---|---|---|
| Community | Free | 1,000 calls/mo |
| Starter | $10/mo | 10,000 calls/mo |
| Team | $79/mo | 100,000 calls/mo |
| Business | $149/mo | 250,000 calls/mo |
Prices as published on the marketplace listing, 2 September 2026. Check the listing for current tiers.
FAQ
Questions people ask first
What is an MCP gateway?
A central entry point in front of multiple Model Context Protocol servers and tools. Rather than every AI client connecting to every server, requests pass through the gateway, which resolves capabilities, applies policy and controls access.
MCP gateway vs MCP server — what is the difference?
A server exposes tools or resources. A gateway sits in front of many servers and governs discovery, routing and access across them.
How does it relate to BarzelVault?
The gateway decides where a request may go. BarzelVault decides whether the action itself may happen. Together they cover access and execution.