Docker MCP Gateway

Docker’s official gateway for bundling and controlling container-isolated MCP servers for AI clients.

Description

Docker MCP Gateway is Docker’s open-source, client-facing gateway implementation for the Model Context Protocol. It is neither just an SDK nor one domain-specific tool: an AI client connects to a gateway that starts registered MCP servers, aggregates their tools, routes requests, and controls credential access. The direct product link leads to Docker’s official documentation, while source and technical details are available in the linked GitHub repository. This makes the gateway particularly useful for teams using more than one MCP server without configuring every connection, container runtime, and secret separately in Claude Code, Codex, or Cursor.

A gateway instead of uncoordinated individual servers

Individual MCP servers are quick to install, but become difficult to manage at scale: every client configuration carries its own commands, tokens, images, and permissions. Docker MCP Gateway provides an intermediary layer. Docker says it manages server lifecycle, routing, credentials, and access control. A client commonly connects locally through stdio using docker mcp gateway run; the gateway then exposes the selected tools of the underlying servers. SSE and Streamable HTTP are also supported for networked cases. Docker documents operation through Docker Desktop with MCP Toolkit, as a docker mcp CLI plugin on Docker Engine, or through Docker Compose.

Containers, permissions, and secrets

The operational boundary is the practical value. According to the documentation, MCP servers run in isolated containers with restricted privileges, resource settings, and network controls. Host environment variables are not passed through by default. Secrets are scoped to one declaring server instead of being distributed to every container. --block-secrets is enabled by default and scans tool arguments and responses for secret-like values. This is a guardrail, not a promise that every secret will be detected: credentials should still be least-privilege and supplied only to the server that needs them.

For HTTP transports, the security documentation says the gateway requires a Bearer token by default, configured or generated through MCP_GATEWAY_AUTH_TOKEN. --allow-unauthenticated removes that boundary and is not a sensible default for reachable production endpoints. The health endpoint intentionally remains unauthenticated. Network egress is not globally blocked automatically either; users needing restrictions must deliberately configure blocking or allowlist options. Third-party images outside Docker’s signing namespaces do not receive the same signature verification as official images.

Clients and common uses

Docker explicitly documents integration with Claude Code, OpenAI Codex, and Cursor. A team can centrally activate a documentation server, database server, and cloud server while the agent still sees one MCP endpoint. That reduces duplicated configuration, but does not make permissions safer than the underlying servers and tokens allow. It is most useful for development teams standardizing agent workstations or operating several MCP servers through Docker Desktop and Compose.

License, version, and GitHub stars

The repository is MIT licensed. On 2026-09-07, GitHub’s API reported 1,556 stars; that point-in-time count is not evidence of security or quality. The newest tag was v0.43.3, while GitHub did not provide a separate latest-release record. The gateway itself is open source. Costs can arise from Docker products, infrastructure, or services used behind the gateway; their official provider terms apply.

Who benefits most

The gateway pays off when multiple MCP servers must be distributed repeatedly, containerized, and bounded clearly across coding clients. For one trusted local server, the additional layer is often unnecessary. Start with a small read-only toolset, inspect images and logs, then expand access only after a traceable test. That keeps the gateway an operational simplification rather than a new uncontrolled collection point for access.

Requirements

Docker Desktop with MCP Toolkit or Docker Engine/Compose plus an MCP client.

Installation instructions

Enable Docker MCP Toolkit or run the gateway with Docker Compose. Connect the client through docker mcp gateway run and initially enable only approved read-only servers.

docker mcp gateway run

Authentication

Stdio runs locally. HTTP requires a Bearer token by default.

Required access permissions

Permissions derive from connected servers, secrets, mounts, and network rules.

Transmitted or stored data

Tool calls are routed to connected servers. Docker documents metadata logging by default, but no blanket data-residency guarantee.

Security risks

Unreviewed images, broad tokens, mounts, or network access enlarge the attack surface. Never expose HTTP unintentionally without authentication.

License and costs

License
MIT
Cost
free

The gateway is MIT licensed. See the respective providers for infrastructure, Docker offering, and connected-service terms.

Alternatives

Not recorded yet.

At a glance

Provider
Docker
Status
Official server
Deployment
Local and remote
Current version
0.43.3
GitHub stars
1,586
Last reviewed
07.09.2026

Repository and documentation

Categories

Supported clients