Back to vendors
S

Stacklok

Also known as: ToolHive, Stacklok Enterprise, vMCP

Visit site
Entry priceOpen source ToolHive free; Stacklok Enterprise quoted through salesFull pricing detail

Self-hosted platform for running and governing what agents reach: MCP servers in isolated containers, an identity-aware tool gateway and an AI gateway for model routing, budgets, screening and audit, on Kubernetes.

Stacklok gives enterprises a self-hosted way to run and govern the tools and models their AI agents use. It is built on ToolHive, an Apache 2.0 open source platform that runs each MCP server in an isolated container with its own permissions and secrets, available as a desktop app, CLI and Kubernetes operator, with a Registry Server for MCP servers, agent skills and plugins and a Virtual MCP Server that aggregates several backends behind one endpoint with tool filtering.

Stacklok Enterprise adds two gateways that bookend an agent. The Connector Gateway is an identity-aware endpoint for tool calls: administrators register MCP servers as connectors, grant them to directory groups and let the gateway broker credentials, so every call carries the identity of the person behind it, and a usage view shows traffic by connector and tool.

The AI Gateway is the same idea for models: connect OpenAI, Anthropic, Bedrock, Azure OpenAI, Vertex AI or any OpenAI-compatible provider, route model names with weighting, failover and retries, cap spend per user or group in dollars, screen prompts for injection and scan for card and personal data, and forward structured audit events to a SIEM. An Enterprise Manager enforces policies across clients, and authorization is expressed as Kubernetes custom resources mapping identity-provider groups to MCP roles.

Everything runs in the customer's own cluster, installed as one Helm chart, including air-gapped, and Stacklok's Security Center states the company neither hosts nor processes customer data; the distribution carries Sigstore signatures, SLSA provenance and SBOMs. Stacklok governs what agents may reach and records what they did; it does not run agent workflows, hold agent memory or index the customer's documents. ToolHive is free; Stacklok Enterprise is an annual subscription quoted through sales.

Vendor details

Canonical URL

https://stacklok.com

Category

Agent infrastructure

Subcategory

Enterprise MCP runtime and governance

Funding status

Independent; per its homepage, backed by Accel, Bain Capital Ventures and Madrona, led by CEO Craig McLuckie and CTO Joe Beda, and a charter member of the Agentic AI Foundation.

Company status

independent

Use cases & customers

Primary use cases

Running MCP servers securely in productionGoverning agent tool access at enterprise scaleCurating a trusted internal MCP registryLLM budget and model governance via AI GatewayReducing MCP token usage via semantic tool search

Target customers

Platform and infrastructure teamsSecurity and compliance teams in regulated industriesEnterprises deploying MCP and AI agents in production

Deployment options

Self-hosted (VPC)On-premKubernetes (self-managed)Air-gapped

Integrations

Runs any MCP server in an isolated container, with a curated registry of vetted servers and agent skills, and a Connector Gateway that brokers each connector's credentials per user. Identity through Okta and Microsoft Entra ID with SCIM provisioning; model providers OpenAI, Anthropic, AWS Bedrock, Azure OpenAI, Google Vertex AI and OpenAI-compatible endpoints through the AI Gateway; OpenTelemetry and SIEM forwarding for traces and audit events; Kubernetes operator, CLI, desktop app and GitHub Actions.

In practice

A platform team runs vetted MCP servers as Kubernetes pods with least privilege, so existing NetworkPolicy and GitOps rules govern agents like any other workload

A security team maps ServiceAccounts and OIDC claims to MCP permissions and traces every tool call via OpenTelemetry into Splunk for audit

An enterprise curates a signed, version pinned registry of trusted MCP servers so developers install from an internal catalog instead of random GitHub repos

Agentic Index coverage score

8.0 / 14 capabilities · 57%

Integrations & Tool Calling Full

Every tool call carries the identity of the person who made it. Administrators register MCP servers as connectors in the Connector Gateway, an identity aware endpoint for MCP tool calls, and grant them to directory groups, and the gateway brokers each connector's credentials on the caller's behalf. ToolHive runs each MCP server in an isolated container with its own permissions and secrets, and a Virtual MCP Server aggregates backends into one endpoint with tool filtering for a given agent. Together they form an authenticated action framework.

Sourcedocs.stacklok.com/connector-gatewayread 2026-09-22

Workflow Orchestration Not documented

A Virtual MCP Server aggregates backend MCP servers behind one endpoint with static backend selection, tool filtering and renaming, and the Connector Gateway exposes a group-scoped toolset; both route a call to the right server rather than running work. Stacklok's documented platform runs no workflow or agent loop of its own, and no sequencing, branching or retries across deterministic workflow steps and autonomous agent steps are documented.

Sourcedocs.stacklok.com/connector-gatewayread 2026-09-22

Knowledge Grounding & RAG Not documented

The vMCP optimizer searches tool descriptions to surface only relevant tools per request and cut token use, and the registry catalogs MCP servers and skills; neither is a retrieval structure over the customer's own knowledge. No maintained index, graph or embeddings layer over the customer's documents is documented.

Sourcedocs.stacklok.com/toolhive/guides-vmcp/optimizerread 2026-09-22

Human Oversight & Guardrails Partial

Stacklok constrains what an agent may do rather than putting a person in the loop: administrators decide which MCP servers are registered as connectors and which directory groups may use them, Enterprise Manager policies can block servers that are not in the approved registry, authorization policies limit each role's tools, and the AI Gateway screens prompts for injection and scans requests and responses for card and personal data. These are constraints the customer controls; no mechanism where a person reviews, approves or validates an agent action before it commits is documented.

Sourcedocs.stacklok.com/connector-gatewayread 2026-09-22

Security, Identity & Governance Full

The access surface is deep: identity providers (Okta, Microsoft Entra ID) with SCIM provisioning, directory users, groups and subgroups, virtual API keys bound to a user's identity, enterprise authorization expressed as fleet-wide MCP roles in RBAC custom resources with namespace-level delegation, Cedar policies on MCP servers, and connector credentials stored encrypted at rest in the directory.

The distribution itself carries Sigstore signatures, SLSA provenance and SBOMs the customer can verify. No third party attestation of Stacklok's own operations is published; its Security Center says none applies to a self hosted product that holds no customer data.

Sourcestacklok.com/security-centerread 2026-09-22

Observability & Auditability Full

The AI Gateway records structured audit events for model requests, detections and key actions and forwards them to the customer's SIEM, the Connector Gateway's tool usage view shows traffic by time range, connector and tool, and an Enterprise Manager telemetry policy enforces OpenTelemetry settings across Stacklok clients so tool calls are traced into the customer's own stack. A customer can inspect what an agent sent and received, keep audit events apart from traces, and export both to its own tools.

Sourcedocs.stacklok.com/ai-gateway/forward-audit-logsread 2026-09-22

Memory & State Persistence Not documented

Memory sits outside what Stacklok does. It runs and governs MCP servers, skills and model traffic, and none of its documented components (the ToolHive runtime, Registry Server, vMCP, Connector Gateway, AI Gateway and Enterprise Manager) persists an agent's state or a user's context across runs.

Sourcedocs.stacklok.com/toolhiveread 2026-09-22

Deployment & Data Residency Full

Everything runs inside the customer's own infrastructure. Stacklok Enterprise deploys as a single umbrella Helm chart into the customer's Kubernetes cluster, with distributed deployments across clusters and an air gapped install that mirrors the chart from a private registry, and the Security Center states that Stacklok neither hosts nor processes customer data.

Sourcedocs.stacklok.com/platformread 2026-09-22

Prebuilt Agents, Templates & Packs Full

Agent skills ship with ToolHive: reusable bundles of tools, permissions and secrets that a buyer browses in a registry and installs into its AI clients, builds from a local folder as an OCI artifact, and publishes, lists or deletes through the Registry Server's admin API, with CLI and desktop UI paths for installing, distributing and managing them.

Sourcedocs.stacklok.com/toolhive/guides-registryread 2026-09-22

Triggers & Channel Coverage Not documented

Work reaches an agent through Stacklok when a client or agent calls a tool or a model: ToolHive runs the servers, the gateways broker the calls, and both are invoked by the caller. No schedule, event, webhook or inbound queue that starts an agent run is documented. Nothing wakes an agent without a person or client initiating the work.

Sourcedocs.stacklok.com/toolhiveread 2026-09-22

Model Flexibility & Routing Full

Customers and admins decide which model serves a request. The AI Gateway is a self hosted control point between AI clients and model providers: the customer connects OpenAI, Anthropic, AWS Bedrock, Azure OpenAI, Google Vertex AI and OpenAI compatible providers, then maps model names onto them with a default route, weighted load balancing, priority failover, retries and timeouts, declared as AIGateway and AIPolicy resources.

Sourcedocs.stacklok.com/ai-gatewayread 2026-09-22

APIs, SDKs & MCP Extensibility Full

Builders get an Apache 2.0 open source platform in ToolHive, with a CLI, desktop UI and Kubernetes operator, and a Registry Server implementing the MCP registry API for servers, skills and plugins. Stacklok Enterprise publishes a REST API reference for the Enterprise Manager, Connector Gateway and AI Gateway, custom resource definitions for authorization, and a management API for budgets, so the platform itself carries a documented API and SDK surface.

Sourcedocs.stacklok.com/toolhiveread 2026-09-22

Testing, Debugging & Optimization Partial

Before an MCP server goes to production, ToolHive's CLI can test and validate it, and the registry applies review criteria before a server is listed. That validates a deployment rather than evaluating a change: no scored test cases, pass rate or judge verdict that gives a readable, comparable result is documented.

Sourcedocs.stacklok.com/toolhive/guides-cli/test-mcp-serversread 2026-09-22

Browser & Computer Use Not documented

The product governs and runs MCP servers and model traffic, and drives no interface itself. No browser, desktop or remote computer session operated for an agent is documented, and no headless fetch or third party browsing engine is wired in.

Sourcedocs.stacklok.com/toolhiveread 2026-09-22

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-08-04·IntegrationsVerified

Stacklok has introduced an integration with Anthropic MCP Tunnels to securely connect Claude to internal systems behind corporate firewalls. In this architecture, Stacklok serves as the critical Model Context Protocol management layer that complements Anthropic's tunneling capabilities.

Bears on: Integrations

View source
2026-07-28·MCP / tool calling / APIVerified

Stacklok released ToolHive v0.41.0, introducing support for the stateless MCP 2026-07-28 specification revision. The update enables the platform to negotiate and bridge legacy session-based and new stateless clients, while adding an RFC 8693 OAuth 2.0 token exchange grant handler for agentic authorization.

Bears on: MCP / tool calling / API

View source
2026-07-06·Security / enterpriseVerified

Stacklok added support for Enterprise-Managed Authorization (EMA) to ToolHive, its open-source Model Context Protocol (MCP) project. This allows identity providers to centrally grant and manage server access, ensuring every tool call carries the real identity of the user who initiated the action.

Bears on: Security / enterprise

View source
View all 3 changes for Stacklok →Tracked since Jul 2026 · Verified from public vendor sources

Pricing

Open source ToolHive free; Stacklok Enterprise quoted through sales

Annual Stacklok Enterprise subscription; open source core free

Free tier

What is public

What each edition includes is public: the docs publish a Community versus Enterprise capability comparison. No price is published anywhere on the estate.

Billing mechanics

Free open source core; Stacklok Enterprise licensed as an annual subscription quoted through sales, deployed by the customer into its own cluster.

Cost watchouts

The governance layer is the paid part: the AI Gateway, Connector Gateway, Enterprise Manager, SCIM and directory services, the versioned and attested distribution and SLA support are Enterprise. Because it is self-hosted, the customer also runs and pays for the Kubernetes infrastructure the platform and every MCP server sit on.

Variable cost rationale

Enterprise is an annual subscription rather than usage metered, and the free open source core absorbs experimentation, so cost is predictable within a subscription term; connectors and services are the main additive levers.

Additional watchouts

Evaluate on the free open source core, but production governance features (IdP, hardened images, audit, gateways) require the paid annual subscription.

Sales call required

Yes, required for paid access

Free / trial

ToolHive is free and open source (Apache 2.0); no Enterprise trial is published

Key ambiguities

No figure, unit or tier structure is published for Stacklok Enterprise; stacklok.com/pricing does not exist and the docs route to a demo.

Missing data

Enterprise subscription rates, connector licensing rates, services rates.

Agentic Index verified 2026-09-22

Alternatives to Stacklok

The closest documented capability profiles to Stacklok among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Arcade7.5 / 14Fuller documented coverage on Testing, Debugging & OptimizationStacklok vs Arcade →
  • Portkey7.5 / 14Fuller documented coverage on Testing, Debugging & Optimization
  • AIsa6.0 / 14A lighter documented profile than Stacklok
  • Arize AI9.0 / 14Adds documented Triggers & Channel Coverage
  • Metorial8.0 / 14Adds documented Triggers & Channel Coverage
  • Clawvisor6.5 / 14Fuller documented coverage on Human Oversight & Guardrails

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.