agentgateway

Linux Foundation

Open Source

Rust proxy for agent traffic that governs MCP, A2A and LLM calls with CEL-based RBAC, budgets and guardrails; runs standalone or on Kubernetes.

Curated by Tiberiu ArvaVerified

Apache 2.0Version 1.5.0Released 2026-08-27

Strengths

  • MCP, A2A and LLM in one proxy
  • CEL policy engine for fine-grained RBAC
  • Kubernetes Gateway API controller built in

Practitioner note

A strong vendor-neutral pick for Kubernetes platform teams that want one policy point for agent tool calls and LLM traffic. It moves quickly and v1.5.0 had breaking changes (e.g. JWT issuer/audience now required), so read the release notes before upgrading.

Governance posture

Reviewed 2026-09-30
YesData residency

Self-hosted binary or Kubernetes deployment; operator controls placement.

Source
YesDeployment model

Standalone binary/Docker or Kubernetes with a built-in control plane and Gateway API. (self-hosted)

Source
PartialAudit logging

Access logs (incl. token timing), distributed traces and a UI logs view; no dedicated audit-log product.

Source
N/ASOC 2

Self-hosted OSS; SOC 2 applies to the operator's infrastructure, not the package.

N/AISO 27001

Self-hosted OSS; ISO 27001 applies to the operator's ISMS, not the package.

N/AISO 42001

Self-hosted OSS; ISO 42001 applies to the deploying organisation.

N/AEU AI Act

Network proxy component, not an AI system placed on the market; obligations rest with the deployer. (role: not-applicable)

YesLicense risk

Apache 2.0 — permissive, OSI-approved; Linux Foundation project. (low)

Source

EU AI Act obligations

Risk tier: Not applicable · as of 2026-08-23

Source-backed information mapped from agentgateway's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.

Change history

Source-backed and auto-detected events for this tool, newest first.

  1. Release

    agentgateway 1.5.0 added API-key-scoped LLM budgets, native Gemini APIs, and guardrails on tool calls, with breaking JWT and token-count changes.

    Release v1.5.0 · agentgateway/agentgateway

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.