mcpgw pricing

$599/mo flat. Unlimited gateway instances.

Three tiers. Real numbers. No "contact sales" until Enterprise. We never charge per call.

Community
Solo, non-prod, teams under 10 seats.
$0
Get a license
Full gateway functionality
60-day self-issued JWT, automated rotation
All policy actions (deny / redact / rate_limit)
Datadog OTLP export, JSONL audit
Audit shipping to S3, GCS, Kafka, webhook
GitHub Issues for support — no SLA
most chosen
Team
Production at small-to-mid teams. Flat rate.
$599 / month
Start trial
Everything in Community
90-day JWT with automated rotation
Unlimited gateway instances under one license
Email + Slack support, business-hours SLA
Private repo access for early-look features
No call-volume cap — flat rate
$5,990 / year (one month free)
Enterprise
Regulated industries, custom SLA.
from $48,000 / year
Talk to sales
Everything in Team, plus:
Custom SLA (1h P1 response)
HIPAA / SOC 2 BAA available
Air-gapped deploy + offline issuance
Multi-tenant license partitioning
Quarterly security review + SLSA L3 attestation
Net-30 / 60 PO accepted

Compare plans.

Feature Community Team Enterprise
Gateway binary (full functionality)
Policy: deny / redact / rate_limit / default_action
Inbound API-key auth (Argon2id)
Native TLS + mTLS
Datadog OTLP/HTTP export
Audit shipping (S3 / GCS / Kafka / webhook)
License JWT lifetime 60 days 90 days custom
Gateway instances per license 1 unlimited unlimited
Production use under 10 seats
Support channel GitHub Issues Email + Slack Named, 24/7
SLA business-hours 1h P1 response
HIPAA / SOC 2 BAA
Air-gapped + offline issuance
SLSA L3 attestation + quarterly security review
Net-30 / 60 PO terms

Frequently asked questions.

Why $599 flat instead of per-instance or per-call?
Per-instance billing punishes good architecture (separate gateways for blast-radius isolation, per-region failover, dev/staging splits). Per-call billing requires us to see your traffic — we don't. Flat rate aligns price with operational value, not deployment shape.
Is the binary really free?
Yes. The mcpgw source is BSL-1.1 — source-available, with a non-production-or-under-threshold restriction that converts to Apache 2.0 four years after each release. Read the source, modify it, run it locally. The Community-tier JWT is free, automated, and self-service.
What happens if my license expires?
mcpgw stays up for 30 days past exp (the grace window) with a warning every minute. After that, /readyz returns 503 and /mcp returns 503 license_invalid. /healthz stays green so you can renew without an emergency restart.
Do you charge per call?
No. Flat rate per Team license. We don't see your call volume because nothing reports it back to us — there is no analytics ping, no update check, no live revocation API.
Can I run mcpgw across multiple regions on Team?
Yes. Team is unlimited gateway instances under one license subject. Multi-region is included. Multi-tenant license partitioning (separate licenses per business unit) is Enterprise.
When does Team stop being enough?
When you need a custom SLA (sub-business-day P1 response), HIPAA/SOC 2 BAAs, dedicated security review, multi-tenant license partitioning, or net-30/60 PO terms. That's Enterprise — from $48,000/year.
Will the price go up?
Probably. v1.0 launch pricing is conservative. Annual subscribers at $5,990 are price-protected for the term — even if list price rises to $799/$999 in subsequent quarters.
What if mcpgw.dev disappears?
Existing JWTs continue to verify until exp + grace_days. Issued binaries continue to run. The repository is on GitHub. We commit to a minimum 12-month wind-down for paid customers, including either continued JWT issuance or a published private key for self-issuance.

Ready to see every MCP call?

10 minutes from docker pull to first traced span. No credit card.