Gateway Integrations
What's an MCP Gateway?
An MCP gateway sits between AI agents and the MCP servers or APIs they call. Agents connect to the gateway instead of to each server, and the gateway checks every request, routes it to the right server with the right credential, and applies limits and logging in one place.
See MCP Gateways for how it works with Descope, and MCP Gateway Use Cases for when you'd run one.
If you already run a gateway, or want to use one from a vendor, Descope can be its identity provider. The gateway validates Descope-issued tokens, and Descope handles login, consent, client registration, and policies. How that setup works end to end, including token exchange for downstream services, is on MCP Gateways.
Configuring Any Gateway
Any gateway that verifies RS256 JWTs from a JWKS and checks iss and aud can sit in front of your MCP servers with Descope as the authorization server. Model the gateway as an MCP Server Resource so CIMD/DCR, consent, and agent inventory stay in the Hub.
Point it at:
- JWKS:
__BaseURL__/__ProjectID__/.well-known/jwks.json(OIDC endpoints) - Issuer: the MCP Server Issuer URL from Usage Samples
- Audience: the gateway Resource URL
- Scopes: the MCP Server scopes you defined for the gateway, read from the token's
scopeclaim
Scopes are what let the gateway do more than a yes/no check. The token only carries the scopes the user consented to and policy allowed, so the gateway can require mcp:read on one route or tool and a write scope on another.
Most of the gateways below can match on scope directly, for example Portkey's claimValues, Kong consumer ACLs, or an APIM validate-jwt required claim.
Note
To check a user's current roles and permissions instead of what was in the token when it was issued, you can introspect the access token with the /userinfo endpoint.
MCP-Aware Gateways
These gateways terminate MCP, or proxy it to HTTP, and can use Descope as the IdP.
| Gateway | How to use Descope as its IdP |
|---|---|
| Azure AI Gateway | Use the generic validate-jwt policy against Descope's JWKS, not Entra's validate-azure-ad-token from Microsoft's MCP samples. See Descope JWTs with APIM. |
| Kong AI Gateway | Set the AI MCP OAuth2 plugin's jwks_endpoint to Descope's JWKS. The plugin can also swap the inbound token before calling upstream. See Authenticating Kong Gateway with Descope. |
| Portkey | Validates the Descope JWT and forwards claims to downstream MCP servers. See Descope + Portkey. |
| Golf.dev | Enforces Descope roles and scopes per MCP method and tool. See Descope + Golf.dev. |
| agentgateway | Calls Descope as the policy decision point on each request. See Locking Down Your Own Agents' Traffic. |
| TrueFoundry | Point its identity-provider JWT check at Descope's issuer and JWKS. |
| LiteLLM | Set JWT_PUBLIC_KEY_URL to Descope's JWKS, and optionally JWT_ISSUER and JWT_AUDIENCE. |
General API gateways that validate JWTs before forwarding MCP to a backend work the same way.
See AWS API Gateway, GCP API Gateway, or Google Apigee for more information.