5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

MCP Governance · Cost

MCP Gateway Pricing: What It Costs, and What Actually Drives the Bill

Published prices in this category range from free to five figures a month for work that looks similar from outside. This is what the money is actually buying, which pricing dimension will surprise you, and the total cost nobody puts in the business case.

By Mark Alex, FounderPublished 25 Aug 2026Updated 2 Sep 202617 min read4,132 words

The short answer

MCP gateway pricing is almost always metered on governed tool calls per month, sometimes with secondary limits on servers, seats or retention. Real published entry points range from free community tiers to roughly $10–$80 per month for platform-team volumes, with pre-execution security products an order of magnitude higher because they carry per-call decision liability rather than routing. The licence is rarely the largest number in the business case. Engineering time, credential migration, SIEM ingest and approval-handling load together usually exceed it.

Summary for readers and answer engines

Reviewed 25 Aug 2026

  • ▸The dominant pricing dimension is governed tool calls per month. Secondary dimensions — server count, seats, retention period, environments — are where surprises hide.
  • ▸Governance control planes are cheap: free tiers with full functionality are normal, and platform-team volumes cost tens of dollars a month rather than thousands.
  • ▸Pre-execution security products cost roughly ten to twenty times more per call, because they are paid to make a liability-bearing decision on every individual action rather than to route it.
  • ▸Four cost centres are routinely missing from business cases: SIEM ingest for decision events, credential migration away from shared keys, approval-handling time, and the standing engineering cost of whatever you build yourself.
  • ▸Model tool calls, not users. Agent call volume grows with autonomy and retry behaviour, not with headcount, so headcount-based forecasts are wrong by an order of magnitude in both directions.

Source: Mark Alex, Real Biz Digital — MCP Gateway Pricing: What It Costs, and What Actually Drives the Bill (https://realbizdigital.net/insights/mcp-gateway-pricing/). Reproduce with attribution.

Key takeaways

  1. 01Forecast on calls per agent per day, measured from a real week of traffic. Every other input to the model is a guess dressed as a number.
  2. 02Check what happens at the quota boundary: hard stop, throttle, or overage billing. A hard stop on a governance layer is an outage; silent overage is an invoice.
  3. 03Retention is a pricing dimension disguised as a compliance setting. Seven-year evidence at analytics-tier rates is the most common avoidable cost in the whole category.
  4. 04Free tiers in this market are unusually capable. Community tiers frequently include the full policy engine, registry and audit, gated only on volume.
  5. 05Price the approval workflow in human minutes. Twenty approvals a day at four minutes each is a third of a person, and it does not appear on any invoice.
  6. 06Never compare a governance control plane’s per-call price with a pre-execution firewall’s. They are paid for different risks; the ratio is meaningful, not anomalous.
Part of the clusterMCP Governance →

Quick answers

One-line answers to the questions this page is most often asked. Each is expanded further down, and each is written to be quoted on its own.

How much does an MCP gateway cost?
Governance control planes commonly start free and run from roughly $10 to $80 per month for platform-team call volumes. Pre-execution AI security products start around $149 per month and reach four figures at enterprise decision volumes.
What is the standard pricing unit?
Governed tool calls per month. Secondary limits appear on servers, seats, retention window and number of environments.
Why are security products so much more expensive per call?
They carry decision liability: each call is inspected, classified and permitted or refused pre-execution, with evidence produced. A routing decision is cheap; an accountable one is not.
What is the biggest hidden cost?
Engineering time, whether it goes into building a governance layer or operating someone else’s. SIEM ingest for decision events is the usual runner-up.
How do I forecast call volume?
Measure one real week per agent, then multiply by planned agents and add headroom for retries. Do not forecast from employee headcount, which correlates with nothing here.
Is a free tier viable in production?
For a single team with modest volume, frequently yes — free tiers in this category often include the whole feature set with a call quota. The constraint is volume, not capability.
What should I negotiate?
Retention terms, overage behaviour and the definition of a billable call — particularly whether denied calls, shadow evaluations and tools/list polling count.

Five pricing dimensions, and which one bites

Almost every product in this category meters the same primary unit. The differences that produce unexpected invoices are all in the secondary limits.

Key facts

  • ▸Ask explicitly whether a denied call is billable. Policies that deny a lot are doing their job, and paying premium rates to be told no is a poor incentive structure.
  • ▸Ask whether tools/list and health polling count. Discovery traffic can be a surprisingly large fraction of total calls in a chatty estate.
  • ▸Ask whether shadow evaluations are billed. If they are, you are being charged to test policy safely, which discourages the single most valuable practice in the category.
DimensionHow it is meteredWhere it bites
Governed tool callsPer month, tieredRetry storms and polling. A misconfigured agent can double monthly volume in an afternoon
Server or connector countPer registered MCP serverEstates that onboard many small internal servers rather than a few large ones
SeatsPer human user with console accessApproval workflows, which need many occasional approvers rather than few daily ones
RetentionDays or years of decision historyRegulated workloads. Seven-year retention at hot-tier rates is the classic avoidable cost
EnvironmentsPer deployment or regionAnyone honouring data residency, or running a genuine staging estate

Those three questions take a minute to ask and routinely change the effective price by tens of percent.

What the category actually charges

Published prices, stated as of 2 September 2026, for the products we can quote authoritatively — our own. The pattern generalises: governance control planes are inexpensive, execution automation is inexpensive, and pre-execution security decisions are not.

$0.00032per governed call at Gateway Business tier
$0.002per decision at Vault Business tier
6×the ratio between the two — decision liability, not margin
$0entry price for a full-featured governance control plane
ProductJob it is paid forEntryTop published tier
Barzel Central GatewayEstate governance: inventory, policy, routing, risk, approvals, evidenceFree — 1,000 calls/mo, full feature set$149/mo — 250,000 calls/mo
BarzelVaultPre-execution action decisions with hash-chained proofFree — 10,000 decisions$3,999/mo — 5,000,000 decisions
BarzelOpsGoverned execution across HubSpot, Xero, Gmail, Drive, SlackFree tier$199/mo — unlimited calls
Barzel FinOps AtlasCost attribution and unit economics for AI estatesFree — 500 calls/mo$799/mo — 50,000 calls/mo
Barzel Scripture IntelligencePublic reference server for client testingFree, unmetered—

The six-fold ratio between a governance decision and a pre-execution security decision is the most useful number on this page. If a vendor charges control-plane rates for liability-bearing pre-execution enforcement, ask what the decision actually inspects.

The four costs missing from most business cases

These are ordered by how often they are omitted. Together they usually exceed the licence line by a comfortable margin, which is why licence-only comparisons mislead.

Cost 01

SIEM ingest for decision events

Every governed call can produce a security event, and SIEM licensing is per gigabyte. Twenty agents at twelve thousand calls a day is roughly ten gigabytes a month with summarised arguments, and four times that with raw ones.

Mitigate by summarising arguments, sampling routine allows, and using a two-tier retention split. Never sample denials or approvals — that is the signal you are paying to collect.

Cost 02

Credential migration

Moving from shared API keys to per-user OAuth is the single highest-value governance change and it is engineering work, not configuration. Budget two to six weeks per awkward upstream system.

This cost is incurred whether you buy or build, so it belongs in the baseline rather than in the comparison. Leaving it out makes every option look cheaper than it is.

Cost 03

Approval-handling time

Human approval is a control that spends human minutes. Twenty requests a day at four minutes each is roughly a third of a full-time person, permanently, and it is invisible on every invoice.

Model it explicitly, then reduce it deliberately: risk classes rather than blanket approval, transform outcomes instead of denials, and per-agent ceilings that make routine cases unnecessary to review.

Cost 04

Your own engineering, forever

Whatever you build, you operate. A governance component in the critical path needs on-call, upgrades, schema migrations and a person who understands it when the original author leaves.

Two to three engineers permanently is the realistic figure for a credible in-house control plane. At category prices, that is the decisive term in build-versus-buy and it is usually left out.

Total cost of ownership, worked for three estate sizes

Figures below are annualised, in US dollars, using our published prices for the licence line and conservative UK/US blended engineering costs elsewhere. They are illustrative arithmetic, not a quotation — but the shape holds across every estate we have modelled.

Key facts

  • ▸Credential migration is a one-off, but in year one it is the second-largest line in the small estate and it is almost always omitted from business cases entirely.
  • ▸Approval-handling time grows with autonomy, not with server count. Estates that add agents faster than they refine risk classes see this line grow fastest.
  • ▸The large estate spends more on SIEM ingest than on both governance and security licences combined. That is a design choice, and it is adjustable.

The number that matters

licence_share = licence / total_cost_of_ownership Across all three sizes: 0% to 6.5% Engineering + human time share: 73% to 88%

If licence price is under seven percent of your total, negotiating it hard while ignoring approval load and engineering time is optimising the wrong variable by an order of magnitude.

Annualised total cost of ownership by estate size
Cost lineSmall: 5 servers, 3 agentsMid: 25 servers, 12 agentsLarge: 80 servers, 40 agents
Governance licence$0 (Community)$948 (Team)$1,788 (Business)
Pre-execution security licence— (not yet needed)$2,388 (Team)$9,588 (Business)
SIEM ingest for decision events~$600~$4,800~$18,000
Credential migration, one-off~$12,000~$30,000~$70,000
Approval handling (human minutes)~$6,000~$22,000~$60,000
Platform engineering to operate0.2 FTE ~$28,0000.5 FTE ~$70,0001.5 FTE ~$210,000
Year-one total~$46,600~$130,100~$369,400
Licence share of total0%2.6%3.1%

Two corollaries. First, buy rather than build unless you have a constraint no vendor satisfies. Second, spend your optimisation effort on ingest design and approval-rate reduction, where the money actually is.

How to forecast call volume without guessing

Volume forecasts in this category are usually wrong because they are anchored to the wrong quantity. Agent call volume is driven by autonomy, tool-chain length and retry behaviour — not by how many people work at your company.

  • 01Measure a real week before modelling anything. One instrumented agent for seven days beats any analogy to another company’s estate.
  • 02Count discovery traffic separately. tools/list polling and health checks can be a large share of total calls and are usually cheap to reduce.
  • 03Model retries explicitly. A retry factor of 1.15 is normal; a badly configured agent against a flaky upstream reaches 3 and turns a modest bill into a surprising one.
  • 04Add a step change for every new agent, not a percentage. Agents arrive discretely and each one lands with its own baseline.
  • 05Re-forecast quarterly. Autonomy increases, chains lengthen, and last quarter’s calls-per-run is already stale.
  • 06Set a budget alert at seventy percent of tier, not at a hundred. The point of the alert is to give you a week to act.

Monthly governed calls

calls/mo = agents × runs_per_agent_per_day × calls_per_run × 30 × (1 + retry_factor) example: 12 agents × 40 runs × 22 calls × 30 × 1.15 ≈ 364,000/mo

Measure calls_per_run and retry_factor from one real week. Those two numbers are where every forecast goes wrong, and they are the two you can observe cheaply.

Six questions to ask before you sign

  • 01What exactly is a billable call? Denied calls, shadow evaluations, discovery polling and health checks either count or they do not, and the difference is frequently tens of percent.
  • 02What happens at the quota boundary? Hard stop, throttle, or overage at what rate. A hard stop on a governance layer means agents fail; silent overage means an invoice you did not model.
  • 03What is the retention default, and what does extending it cost? Seven years of evidence at hot-tier pricing is the most common avoidable cost in the category.
  • 04Is the price per environment? Staging, a second region and a data-residency deployment can triple a licence that looked simple.
  • 05What is included in the free or entry tier — feature-gated or volume-gated? Volume-gated entry tiers let you evaluate genuinely; feature-gated ones only let you evaluate the marketing.
  • 06What is the renewal mechanism? Automatic tier escalation on overage, indexed uplifts and multi-year commitments all belong in the model, not in a surprise next August.

Controlling spend once it is running

Cost governance for an agent estate is a live control problem, not an annual budgeting exercise, because a single deployment can change monthly volume materially within hours.

Per-agent call ceilings

A hard monthly ceiling per agent, enforced at the decision point. The first time a retry loop hits it, the ceiling pays for itself several times over.

Tool-class budgets

Budget by consequence rather than by team: expensive or high-risk tool classes get their own ceiling, so a cheap loop cannot consume the allowance for consequential work.

Ingest tiering

Route routine allow decisions to a low-cost log tier and keep decisions, approvals and transforms in the analytics tier. Frequently the largest single saving available.

Discovery reduction

Cache tools/list and reduce polling frequency. Cheap engineering, immediate volume reduction, and it also reduces context cost on the model side.

Cost per outcome, not per call

Track spend against completed business outcomes. A tool that costs twice as much per call but halves retries is cheaper, and per-call reporting hides that.

Quarterly re-forecast

Re-derive calls-per-run and retry factor every quarter. Both drift upward as autonomy increases, and both are early warnings.

Barzel FinOps Atlas exists for the last two of those, and it starts at a free sandbox tier — attribution of AI spend to agents, tools and outcomes, with forecasting and budget guardrails on top.

Next step

Start on the free tier and measure your own volume

A thousand governed calls a month with the full policy engine, registry, routing and audit costs nothing. That is enough to measure your real calls-per-run and retry factor, which are the two numbers every cost model depends on.

Caveats on every number here

We publish prices for our own products and can therefore quote them exactly. Everything else on this page is arithmetic and observation, and both deserve scrutiny.

  • 01Engineering and approval-time figures use blended costs that will not match your organisation. Substitute your own rates; the ratios are the durable part, not the absolute numbers.
  • 02Vendor pricing in this category changes frequently, and our own listing is authoritative over anything written here. Verify before you build a business case on it.
  • 03The TCO model assumes you keep decision evidence and run human approval. An estate that does neither is cheaper and less governed, which is a legitimate choice as long as it is made deliberately.

Frequently asked questions

How much does an MCP gateway cost?

Governance control planes commonly start with a free tier and run from roughly ten to eighty dollars a month at platform-team call volumes. Pre-execution AI security products start near $149 a month and reach four figures at enterprise decision volumes, because they carry per-call decision liability rather than routing.

What is the standard MCP gateway pricing unit?

Governed tool calls per month is the primary unit almost everywhere. Secondary limits appear on registered server count, console seats, decision retention period and number of environments — and those secondary dimensions are where unexpected costs originate.

Why do MCP security products cost more per call than gateways?

Because they are paid to make a liability-bearing decision about each individual action before it executes, including argument inspection, data classification and evidence generation. A routing or registry decision is cheap to compute and carries no direct consequence; a pre-execution refusal does.

What costs are usually missing from an MCP business case?

Four: SIEM ingest for decision events, credential migration away from shared API keys, human time spent handling approvals, and the standing engineering cost of operating whatever you build. In our modelling these together account for seventy to ninety percent of total cost of ownership.

How do I forecast MCP tool-call volume?

Measure one real week from one instrumented agent, then multiply agents by runs per day, calls per run, thirty days and a retry factor. Calls per run and retry factor are the two inputs that make or break the forecast, and both are cheap to observe and impossible to guess.

Are free MCP gateway tiers usable in production?

Often, for a single team at modest volume. Free tiers in this category are commonly volume-gated rather than feature-gated — Barzel Central Gateway’s Community tier includes the full policy engine, registry, routing and audit with a thousand calls a month.

What should I negotiate on an MCP governance contract?

The definition of a billable call, behaviour at the quota boundary, retention pricing, whether the price is per environment, and the renewal mechanism. Licence rate itself is usually the least consequential of the five.

How much SIEM cost does agent telemetry add?

Twenty agents making twelve thousand calls a day generates roughly ten gigabytes a month with summarised arguments, or about forty-three with raw arguments retained. At typical SIEM pricing that difference alone can exceed the governance licence several times over.

Is it cheaper to build an MCP gateway in house?

Almost never. The first cut takes a few engineer-weeks, but the standing cost is two to three engineers permanently for on-call, upgrades, schema migrations and institutional knowledge — far exceeding licence costs that sit in the tens of dollars per month range.

How do I control MCP spend once it is running?

Per-agent monthly call ceilings enforced at the decision point, budgets by tool class rather than by team, ingest tiering for telemetry, reduced discovery polling, and reporting on cost per completed outcome rather than cost per call.

Does a denied tool call count as a billable call?

It depends on the vendor, and it is worth asking explicitly. A policy set doing its job denies a meaningful fraction of calls, and paying premium rates to be refused creates an incentive structure that works against good governance.

How often should I re-forecast agent call volume?

Quarterly. Calls per run and retry factor both drift upward as autonomy increases and tool chains lengthen, so a forecast built on last quarter’s numbers understates by more than teams expect.

Glossary

Governed tool call
One MCP tool invocation that passed through the governance layer and received a decision, whether allowed, denied or transformed.
Metering dimension
The quantity a vendor bills against: calls, servers, seats, retention or environments.
Overage behaviour
What happens when a quota is exceeded — hard stop, throttle, or additional billing.
Retention tiering
Splitting decision history between a queryable short-term tier and a cheaper long-term immutable tier.
Retry factor
The multiplier applied to modelled call volume to account for automatic retries; commonly 1.1–1.2, and far higher in unhealthy estates.
Licence share
Licence cost divided by total cost of ownership; typically under ten percent for governance platforms.
Cost per outcome
Total spend divided by completed business outcomes rather than by call, which is the only metric that rewards reducing retries.
Call ceiling
A hard per-agent monthly volume limit enforced at the decision point, containing runaway loops.
Discovery traffic
tools/list and health-check calls, which consume quota and context without performing work.
Standing engineering cost
The permanent headcount required to operate a component after it is delivered.

Standards and entities referenced

Every named framework on this page resolves to a public definition. If you are checking our claims, start here rather than with us.

Sources and further reading

Primary specifications and standards this article relies on. Where a claim is our own operating judgement rather than something a standard states, the text says so.

  1. 01 · FinOps FoundationFinOps Framework ↗Inform, optimise, operate — the phases capacity and cost planning map onto.
  2. 02 · FinOps FoundationFOCUS — FinOps Open Cost and Usage Specification ↗Open schema for normalising cost and usage data across providers.
  3. 03 · WikipediaTotal cost of ownership ↗Why licence price is the smallest term in a governance build-versus-buy decision.
  4. 04 · MCP projectModel Context Protocol — specification ↗Normative source for tool schemas, capability negotiation and the authorization model.
  5. 05 · WikipediaLittle’s Law and queueing fundamentals ↗Arrival rate, concurrency and latency — the arithmetic behind capacity planning.
  6. 06 · GoogleGoogle SRE — Service Level Objectives ↗Why an estate needs objectives and error budgets, not just dashboards.
  7. 07 · OpenTelemetryOpenTelemetry — GenAI semantic conventions ↗Emerging standard attribute names for model and tool-call telemetry.
  8. 08 · Center for Internet SecurityCIS Critical Security Controls ↗Control 1 and 2 — inventory of assets and software — restated here for MCP servers and tools.

Last reviewed 2 September 2026 by Mark Alex. External links open in a new tab; we do not control their content.

Cite this article

Alex, M. (2026). MCP Gateway Pricing: What It Costs, and What Actually Drives the Bill. Real Biz Digital. https://realbizdigital.net/insights/mcp-gateway-pricing/

Try the mechanics on a live server

To watch a real tools/list response, and see how much surface one server exposes, before you point a client at anything that governs production — Barzel Scripture Intelligence is free and public at scripture-intelligence-server.mcpize.run: no signup, no key, 54 tools. Setup is in the reference.

Buy it on the marketplace

Barzel Central Gateway is this layer, sold as a running product

Twenty-five tools covering identity-aware policy, tool routing, risk scoring, approvals, routebooks, workflow simulation and SIEM evidence. Ten policy inputs, six enforcement outcomes, per-user OAuth/OIDC. The Community tier is free, so an evaluation costs an afternoon rather than a purchase order.

PlanPriceIncludedRight for
CommunityFree1,000 tool calls/mo · full policy engine, registry, routing, auditEvaluating the estate, or one team proving the path works
Starter$10/mo10,000 calls/mo · everything in CommunityOne or two production agents against a handful of servers
Team$79/mo100,000 calls/mo · routebooks, simulation, change impactA platform team governing an estate of 5–20 servers
Business$149/mo250,000 calls/mo · estate-wide evidence exportMulti-team governance with SIEM obligations

Sold on the MCPize marketplace · prices as listed 2 Sep 2026 · the listing is authoritative

The five Barzel servers, and which problem each one is sold for

One estate rarely needs all five. This is the honest mapping, so you buy the layer your problem actually lives in.

ServerSold forEntry priceWhere it sits
Barzel Central GatewayKnowing and governing the estate: inventory, registry, routing, risk scoring, approvals, evidenceFree, then $10–$149/moControl plane — decides what may be reached, and by whom
BarzelVaultStopping a specific dangerous action before it executes, with proof afterwards$199–$3,999/moDecision point — evaluates the individual call before execution
BarzelOpsRunning real business workflows across HubSpot, Xero, Gmail, Drive and Slack under approvalFree, then $19–$199/moExecution layer — does the work the policy allowed
Barzel FinOps AtlasAttributing AI spend to agents, tools and outcomes, then forecasting and capping itFree, then $29–$799/moEconomics layer — what the estate costs per outcome
Barzel Scripture IntelligenceA free, credential-free public MCP server to test clients and inspect real protocol trafficFree, unmetered, no signupReference implementation — safe place to learn the protocol

Written by

Mark Alex

Founder of Real Biz Digital and architect of the Barzel ecosystem — five MCP servers published and callable in public. Software developer, technology entrepreneur and mechatronics engineer, working across AI agent governance, MCP security, AI infrastructure, FinOps and intelligent operations.