Spike: agentgateway as MCP Aggregation Layer¶
Purpose¶
agentgateway is an open-source MCP proxy/gateway that can multiplex many MCP backends behind a single endpoint. This spike evaluates whether agentgateway can replace the embedded FastMCP aggregator in the AF MCP Platform.
The broker architecture is invariant regardless of this spike's outcome.
The /v1 contract, credential brokering, authorization, and audit subsystems
are unchanged either way. The only question is whether agentgateway is a viable
aggregation frontend.
Acceptance Test¶
The spike passes if and only if agentgateway satisfies all of the following:
Does agentgateway expose an
ext_authz/ext_prochook (or equivalent interceptor mechanism) that: 1. fires on everytools/callinvocation, 2. receives the tool name, tool arguments, and calling identity (principal), 3. can block the call (return an error to the client) before the backend receives it, and 4. supports server-side credential injection — i.e., the hook or a downstream filter can modify the outbound request to the backend (e.g., add/replace an Authorization header) without the LLM client ever seeing the credential?
All four conditions must be met. A "maybe with a workaround" is a Fail.
Test Procedure¶
- Deploy agentgateway (latest stable) in a test namespace with two stub MCP backends.
- Configure a test interceptor (Envoy
ext_procfilter, Lua filter, or agentgateway's native plugin API — whatever it exposes). - Issue a
tools/callfrom a test MCP client with a known identity. - Observe whether the interceptor fires, receives the expected fields, and can return a synthetic error.
- Implement a minimal credential injector: intercept the outbound call to the
backend and replace the
Authorizationheader with a fake brokered token. Verify the backend receives the injected token and the client never sees it.
Outcome Recording¶
Update this section after the spike is run.
Result: [ ] Pass / [ ] Fail¶
Date tested: agentgateway version: Tester:
Findings: (Describe what was observed for each of the four acceptance criteria.)
Decision: - Pass → agentgateway is eligible as a future replacement for the embedded FastMCP aggregator. Add a Phase N task to the roadmap to evaluate migration cost. - Fail → agentgateway is excluded from the architecture. The embedded FastMCP aggregator remains. Do not re-open this question without a concrete upstream issue or PR that addresses the gap.
Architecture Invariance¶
Regardless of outcome, the following are unchanged:
POST /v1/authorize+POST /v1/credentialare the broker's per-call interface for the aggregation layer.- The FastMCP aggregator (or agentgateway) calls the broker; it does not hold credentials or make authorization decisions.
- The
CredentialCacheand all four broker subsystems remain in the broker process. - The Helm chart structure, Flux GitOps workflow, and Kubernetes manifests are unchanged.
The aggregation layer is the only component this spike affects.