Stacklok
Also known as: ToolHive, Stacklok Enterprise, vMCP
Self-hosted platform for running and governing what agents reach: MCP servers in isolated containers, an identity-aware tool gateway and an AI gateway for model routing, budgets, screening and audit, on Kubernetes.
Stacklok gives enterprises a self-hosted way to run and govern the tools and models their AI agents use. It is built on ToolHive, an Apache 2.0 open source platform that runs each MCP server in an isolated container with its own permissions and secrets, available as a desktop app, CLI and Kubernetes operator, with a Registry Server for MCP servers, agent skills and plugins and a Virtual MCP Server that aggregates several backends behind one endpoint with tool filtering.
Stacklok Enterprise adds two gateways that bookend an agent. The Connector Gateway is an identity-aware endpoint for tool calls: administrators register MCP servers as connectors, grant them to directory groups and let the gateway broker credentials, so every call carries the identity of the person behind it, and a usage view shows traffic by connector and tool.
The AI Gateway is the same idea for models: connect OpenAI, Anthropic, Bedrock, Azure OpenAI, Vertex AI or any OpenAI-compatible provider, route model names with weighting, failover and retries, cap spend per user or group in dollars, screen prompts for injection and scan for card and personal data, and forward structured audit events to a SIEM. An Enterprise Manager enforces policies across clients, and authorization is expressed as Kubernetes custom resources mapping identity-provider groups to MCP roles.
Everything runs in the customer's own cluster, installed as one Helm chart, including air-gapped, and Stacklok's Security Center states the company neither hosts nor processes customer data; the distribution carries Sigstore signatures, SLSA provenance and SBOMs. Stacklok governs what agents may reach and records what they did; it does not run agent workflows, hold agent memory or index the customer's documents. ToolHive is free; Stacklok Enterprise is an annual subscription quoted through sales.
Vendor details
Canonical URL
https://stacklok.com
Category
Agent infrastructure
Subcategory
Enterprise MCP runtime and governance
Funding status
Independent; per its homepage, backed by Accel, Bain Capital Ventures and Madrona, led by CEO Craig McLuckie and CTO Joe Beda, and a charter member of the Agentic AI Foundation.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Runs any MCP server in an isolated container, with a curated registry of vetted servers and agent skills, and a Connector Gateway that brokers each connector's credentials per user. Identity through Okta and Microsoft Entra ID with SCIM provisioning; model providers OpenAI, Anthropic, AWS Bedrock, Azure OpenAI, Google Vertex AI and OpenAI-compatible endpoints through the AI Gateway; OpenTelemetry and SIEM forwarding for traces and audit events; Kubernetes operator, CLI, desktop app and GitHub Actions.
In practice
A platform team runs vetted MCP servers as Kubernetes pods with least privilege, so existing NetworkPolicy and GitOps rules govern agents like any other workload
A security team maps ServiceAccounts and OIDC claims to MCP permissions and traces every tool call via OpenTelemetry into Splunk for audit
An enterprise curates a signed, version pinned registry of trusted MCP servers so developers install from an internal catalog instead of random GitHub repos
Sources & related URLs
Agentic Index coverage score
8.0 / 14 capabilities · 57%
| Integrations & Tool Calling | Full |
|---|---|
|
Every tool call carries the identity of the person who made it. Administrators register MCP servers as connectors in the Connector Gateway, an identity aware endpoint for MCP tool calls, and grant them to directory groups, and the gateway brokers each connector's credentials on the caller's behalf. ToolHive runs each MCP server in an isolated container with its own permissions and secrets, and a Virtual MCP Server aggregates backends into one endpoint with tool filtering for a given agent. Together they form an authenticated action framework. Sourcedocs.stacklok.com/connector-gatewayread 2026-09-22 |
|
| Workflow Orchestration | Not documented |
|
A Virtual MCP Server aggregates backend MCP servers behind one endpoint with static backend selection, tool filtering and renaming, and the Connector Gateway exposes a group-scoped toolset; both route a call to the right server rather than running work. Stacklok's documented platform runs no workflow or agent loop of its own, and no sequencing, branching or retries across deterministic workflow steps and autonomous agent steps are documented. Sourcedocs.stacklok.com/connector-gatewayread 2026-09-22 |
|
| Knowledge Grounding & RAG | Not documented |
|
The vMCP optimizer searches tool descriptions to surface only relevant tools per request and cut token use, and the registry catalogs MCP servers and skills; neither is a retrieval structure over the customer's own knowledge. No maintained index, graph or embeddings layer over the customer's documents is documented. Sourcedocs.stacklok.com/toolhive/guides-vmcp/optimizerread 2026-09-22 |
|
| Human Oversight & Guardrails | Partial |
|
Stacklok constrains what an agent may do rather than putting a person in the loop: administrators decide which MCP servers are registered as connectors and which directory groups may use them, Enterprise Manager policies can block servers that are not in the approved registry, authorization policies limit each role's tools, and the AI Gateway screens prompts for injection and scans requests and responses for card and personal data. These are constraints the customer controls; no mechanism where a person reviews, approves or validates an agent action before it commits is documented. Sourcedocs.stacklok.com/connector-gatewayread 2026-09-22 |
|
| Security, Identity & Governance | Full |
|
The access surface is deep: identity providers (Okta, Microsoft Entra ID) with SCIM provisioning, directory users, groups and subgroups, virtual API keys bound to a user's identity, enterprise authorization expressed as fleet-wide MCP roles in RBAC custom resources with namespace-level delegation, Cedar policies on MCP servers, and connector credentials stored encrypted at rest in the directory. The distribution itself carries Sigstore signatures, SLSA provenance and SBOMs the customer can verify. No third party attestation of Stacklok's own operations is published; its Security Center says none applies to a self hosted product that holds no customer data. Sourcestacklok.com/security-centerread 2026-09-22 |
|
| Observability & Auditability | Full |
|
The AI Gateway records structured audit events for model requests, detections and key actions and forwards them to the customer's SIEM, the Connector Gateway's tool usage view shows traffic by time range, connector and tool, and an Enterprise Manager telemetry policy enforces OpenTelemetry settings across Stacklok clients so tool calls are traced into the customer's own stack. A customer can inspect what an agent sent and received, keep audit events apart from traces, and export both to its own tools. Sourcedocs.stacklok.com/ai-gateway/forward-audit-logsread 2026-09-22 |
|
| Memory & State Persistence | Not documented |
|
Memory sits outside what Stacklok does. It runs and governs MCP servers, skills and model traffic, and none of its documented components (the ToolHive runtime, Registry Server, vMCP, Connector Gateway, AI Gateway and Enterprise Manager) persists an agent's state or a user's context across runs. Sourcedocs.stacklok.com/toolhiveread 2026-09-22 |
|
| Deployment & Data Residency | Full |
|
Everything runs inside the customer's own infrastructure. Stacklok Enterprise deploys as a single umbrella Helm chart into the customer's Kubernetes cluster, with distributed deployments across clusters and an air gapped install that mirrors the chart from a private registry, and the Security Center states that Stacklok neither hosts nor processes customer data. Sourcedocs.stacklok.com/platformread 2026-09-22 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Agent skills ship with ToolHive: reusable bundles of tools, permissions and secrets that a buyer browses in a registry and installs into its AI clients, builds from a local folder as an OCI artifact, and publishes, lists or deletes through the Registry Server's admin API, with CLI and desktop UI paths for installing, distributing and managing them. Sourcedocs.stacklok.com/toolhive/guides-registryread 2026-09-22 |
|
| Triggers & Channel Coverage | Not documented |
|
Work reaches an agent through Stacklok when a client or agent calls a tool or a model: ToolHive runs the servers, the gateways broker the calls, and both are invoked by the caller. No schedule, event, webhook or inbound queue that starts an agent run is documented. Nothing wakes an agent without a person or client initiating the work. Sourcedocs.stacklok.com/toolhiveread 2026-09-22 |
|
| Model Flexibility & Routing | Full |
|
Customers and admins decide which model serves a request. The AI Gateway is a self hosted control point between AI clients and model providers: the customer connects OpenAI, Anthropic, AWS Bedrock, Azure OpenAI, Google Vertex AI and OpenAI compatible providers, then maps model names onto them with a default route, weighted load balancing, priority failover, retries and timeouts, declared as AIGateway and AIPolicy resources. Sourcedocs.stacklok.com/ai-gatewayread 2026-09-22 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
Builders get an Apache 2.0 open source platform in ToolHive, with a CLI, desktop UI and Kubernetes operator, and a Registry Server implementing the MCP registry API for servers, skills and plugins. Stacklok Enterprise publishes a REST API reference for the Enterprise Manager, Connector Gateway and AI Gateway, custom resource definitions for authorization, and a management API for budgets, so the platform itself carries a documented API and SDK surface. Sourcedocs.stacklok.com/toolhiveread 2026-09-22 |
|
| Testing, Debugging & Optimization | Partial |
|
Before an MCP server goes to production, ToolHive's CLI can test and validate it, and the registry applies review criteria before a server is listed. That validates a deployment rather than evaluating a change: no scored test cases, pass rate or judge verdict that gives a readable, comparable result is documented. Sourcedocs.stacklok.com/toolhive/guides-cli/test-mcp-serversread 2026-09-22 |
|
| Browser & Computer Use | Not documented |
|
The product governs and runs MCP servers and model traffic, and drives no interface itself. No browser, desktop or remote computer session operated for an agent is documented, and no headless fetch or third party browsing engine is wired in. Sourcedocs.stacklok.com/toolhiveread 2026-09-22 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Stacklok has introduced an integration with Anthropic MCP Tunnels to securely connect Claude to internal systems behind corporate firewalls. In this architecture, Stacklok serves as the critical Model Context Protocol management layer that complements Anthropic's tunneling capabilities.
Bears on: Integrations
View sourceStacklok released ToolHive v0.41.0, introducing support for the stateless MCP 2026-07-28 specification revision. The update enables the platform to negotiate and bridge legacy session-based and new stateless clients, while adding an RFC 8693 OAuth 2.0 token exchange grant handler for agentic authorization.
Bears on: MCP / tool calling / API
View sourceStacklok added support for Enterprise-Managed Authorization (EMA) to ToolHive, its open-source Model Context Protocol (MCP) project. This allows identity providers to centrally grant and manage server access, ensuring every tool call carries the real identity of the user who initiated the action.
Bears on: Security / enterprise
View sourcePricing
Open source ToolHive free; Stacklok Enterprise quoted through sales
Annual Stacklok Enterprise subscription; open source core free
What is public
What each edition includes is public: the docs publish a Community versus Enterprise capability comparison. No price is published anywhere on the estate.
Billing mechanics
Free open source core; Stacklok Enterprise licensed as an annual subscription quoted through sales, deployed by the customer into its own cluster.
Cost watchouts
The governance layer is the paid part: the AI Gateway, Connector Gateway, Enterprise Manager, SCIM and directory services, the versioned and attested distribution and SLA support are Enterprise. Because it is self-hosted, the customer also runs and pays for the Kubernetes infrastructure the platform and every MCP server sit on.
Variable cost rationale
Enterprise is an annual subscription rather than usage metered, and the free open source core absorbs experimentation, so cost is predictable within a subscription term; connectors and services are the main additive levers.
Additional watchouts
Evaluate on the free open source core, but production governance features (IdP, hardened images, audit, gateways) require the paid annual subscription.
Sales call required
Yes, required for paid access
Free / trial
ToolHive is free and open source (Apache 2.0); no Enterprise trial is published
Key ambiguities
No figure, unit or tier structure is published for Stacklok Enterprise; stacklok.com/pricing does not exist and the docs route to a demo.
Missing data
Enterprise subscription rates, connector licensing rates, services rates.
Related vendors
- AgentOps — Agent observability and debugging platform: open source SDKs trace…
- Agno — Python agent framework and AgentOS runtime (formerly Phidata) for…
- AIsa — Resource and payment gateway for AI agents: one key to 110+ models…
- AlphaBitCore — AI control plane for regulated financial firms: one gateway enforces…
- Anchor Browser — Cloud hosted browser infrastructure that lets AI agents operate real…
- Apify — Cloud platform and marketplace of more than 73,000 ready-to-run…
Alternatives to Stacklok
The closest documented capability profiles to Stacklok among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Arcade7.5 / 14Fuller documented coverage on Testing, Debugging & OptimizationStacklok vs Arcade →
- Portkey7.5 / 14Fuller documented coverage on Testing, Debugging & Optimization
- AIsa6.0 / 14A lighter documented profile than Stacklok
- Arize AI9.0 / 14Adds documented Triggers & Channel Coverage
- Metorial8.0 / 14Adds documented Triggers & Channel Coverage
- Clawvisor6.5 / 14Fuller documented coverage on Human Oversight & Guardrails
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded