<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Anthony Max</title>
    <description>The latest articles on DEV Community by Anthony Max (@anthonymax).</description>
    <link>https://dev.to/anthonymax</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg</url>
      <title>DEV Community: Anthony Max</title>
      <link>https://dev.to/anthonymax</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/anthonymax"/>
    <language>en</language>
    <item>
      <title>[Boost]</title>
      <dc:creator>Anthony Max</dc:creator>
      <pubDate>Wed, 02 Sep 2026 21:35:07 +0000</pubDate>
      <link>https://dev.to/anthonymax/-dd9</link>
      <guid>https://dev.to/anthonymax/-dd9</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/anthonymax/12-open-source-gems-to-become-the-ultimate-developer-671" class="crayons-story__hidden-navigation-link"&gt;12 Open Source Gems To Become The Ultimate Developer 🔥&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/anthonymax" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" alt="anthonymax profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/anthonymax" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Anthony Max
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Anthony Max
                &lt;a href="/++"&gt;&lt;img alt="Subscriber" class="subscription-icon" src="https://assets.dev.to/assets/subscription-icon-805dfa7ac7dd660f07ed8d654877270825b07a92a03841aa99a1093bd00431b2.png"&gt;&lt;/a&gt;
                
              
              &lt;div id="story-author-preview-content-4558943" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/anthonymax" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Anthony Max&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/anthonymax/12-open-source-gems-to-become-the-ultimate-developer-671" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Sep 2&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/anthonymax/12-open-source-gems-to-become-the-ultimate-developer-671" id="article-link-4558943"&gt;
          12 Open Source Gems To Become The Ultimate Developer 🔥
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/opensource"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;opensource&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/webdev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;webdev&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/javascript"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;javascript&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/programming"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;programming&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/anthonymax/12-open-source-gems-to-become-the-ultimate-developer-671" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/exploding-head-daceb38d627e6ae9b730f36a1e390fca556a4289d5a41abb2c35068ad3e2c4b5.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/multi-unicorn-b44d6f8c23cdd00964192bedc38af3e82463978aa611b4365bd33a0f1f4f3e97.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;106&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/anthonymax/12-open-source-gems-to-become-the-ultimate-developer-671#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              5&lt;span class="hidden s:inline"&gt;&amp;nbsp;comments&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            5 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>12 Open Source Gems To Become The Ultimate Developer 🔥</title>
      <dc:creator>Anthony Max</dc:creator>
      <pubDate>Wed, 02 Sep 2026 21:33:23 +0000</pubDate>
      <link>https://dev.to/anthonymax/12-open-source-gems-to-become-the-ultimate-developer-671</link>
      <guid>https://dev.to/anthonymax/12-open-source-gems-to-become-the-ultimate-developer-671</guid>
      <description>&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;It's been a while since I've done a collection (maybe month ago), but today let's look at 12 new and not-so-new projects that can really help you in development.&lt;/p&gt;

&lt;p&gt;They touch on different areas of development, but we will mainly talk about web development.&lt;/p&gt;

&lt;p&gt;If there's a project worth adding to the next collection, feel free to write about it in the comments, and maybe it will be included.&lt;/p&gt;




&lt;h2&gt;
  
  
  1. 🤖 &lt;a href="https://openworklabs.com" rel="noopener noreferrer"&gt;OpenWork&lt;/a&gt; - The open source Claude Cowork alternative.
&lt;/h2&gt;

&lt;p&gt;And we will continue, of course, with AI projects. This tool will allow you to work in one convenient interface with many popular LLMs.&lt;/p&gt;

&lt;p&gt;OpenWork is the desktop app that lets you use 50+ LLMs.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9rolfu6xh0mlpxcwmz1c.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9rolfu6xh0mlpxcwmz1c.png" alt="OpenWork" width="800" height="344"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/different-ai/openwork" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;💎 Check out the OpenWork repository ☆&lt;/a&gt;
&lt;/p&gt;




&lt;h2&gt;
  
  
  2. 💻 &lt;a href="https://t3.codes" rel="noopener noreferrer"&gt;T3 Code&lt;/a&gt; - The open-source control plane for coding agents.
&lt;/h2&gt;

&lt;p&gt;If you know a YouTuber like Theo, then you should know this project. It's an OpenCode alternative that lets you work with AI in an easy-to-use chat interface.&lt;/p&gt;

&lt;p&gt;It enables control of the agents on your machine with a best-in-class mobile app (iOS, Android), web app and Electron-based desktop app.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fam5o873hf3m68dpzcpk0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fam5o873hf3m68dpzcpk0.png" alt="T3 Code" width="800" height="422"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/pingdotgg/t3code" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;💎 Check out the T3 Code repository ☆&lt;/a&gt;
&lt;/p&gt;




&lt;h2&gt;
  
  
  3. ⚙️ &lt;a href="https://summarize.sh" rel="noopener noreferrer"&gt;Summarize&lt;/a&gt; - Point at any URL or file. Get the gist.
&lt;/h2&gt;

&lt;p&gt;The first project is a small tool for extracting short info of content. Summarize was created by one of the creators of the well-known OpenClaw.&lt;/p&gt;

&lt;p&gt;Fast summaries from URLs, files, and media.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwjfl5g1fun6z23gsizr1.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwjfl5g1fun6z23gsizr1.png" alt="Summarize" width="788" height="603"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/steipete/summarize" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;💎 Check out the Summarize repository ☆&lt;/a&gt;
&lt;/p&gt;




&lt;h2&gt;
  
  
  4. 👾 &lt;a href="https://godotengine.org" rel="noopener noreferrer"&gt;Godot&lt;/a&gt; - Free and open source 2D and 3D game engine
&lt;/h2&gt;

&lt;p&gt;A &lt;strong&gt;truly legendary&lt;/strong&gt; engine like Unity or Unreal Engine for games. If you are a game developer, you should know this project. From pet projects for the university to multi-million dollar games - it gives it all.&lt;/p&gt;

&lt;p&gt;Godot Engine is a feature-packed, cross-platform game engine to create 2D and 3D games from a unified interface. It provides a comprehensive set of common tools, so that users can focus on making games without having to reinvent the wheel.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fo0p605tp4vayjbuu5q3v.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fo0p605tp4vayjbuu5q3v.webp" alt="Godot" width="800" height="392"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/godotengine/godot" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;💎 Check out the Godot repository ☆&lt;/a&gt;
&lt;/p&gt;




&lt;h2&gt;
  
  
  5. 💎 &lt;a href="https://reactbits.dev" rel="noopener noreferrer"&gt;React Bits&lt;/a&gt; - An open source collection of animated, interactive &amp;amp; fully customizable React components.
&lt;/h2&gt;

&lt;p&gt;An excellent collection of components no worse than shad/cn, which will allow you to create a modern design for your website. By the way, hello to David :)&lt;/p&gt;

&lt;p&gt;The largest &amp;amp; most creative library of animated React components.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvc05giiu23h09tyqp9aw.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvc05giiu23h09tyqp9aw.png" alt="React Bits" width="800" height="384"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/DavidHDev/react-bits" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;💎 Check out the React Bits repository ☆&lt;/a&gt;
&lt;/p&gt;




&lt;h2&gt;
  
  
  6. 🎬 &lt;a href="https://remotion.dev" rel="noopener noreferrer"&gt;Remotion&lt;/a&gt; - Make videos programmatically.
&lt;/h2&gt;

&lt;p&gt;If you would like to make it possible to create videos on your website by writing just one prompt, then this tool is perfect for you.&lt;/p&gt;

&lt;p&gt;Create real MP4 videos with React. Use coding agents, build apps and render in bulk.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flj2hk9l6hsk4otd6cvq2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flj2hk9l6hsk4otd6cvq2.png" alt="Remotion" width="800" height="324"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/remotion-dev/remotion" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;💎 Check out the Remotion repository ☆&lt;/a&gt;
&lt;/p&gt;




&lt;h2&gt;
  
  
  7. 🐈‍⬛ &lt;a href="https://nestjs.com" rel="noopener noreferrer"&gt;Nest.js&lt;/a&gt; - A progressive Node.js framework for building efficient, scalable, and enterprise-grade server-side applications
&lt;/h2&gt;

&lt;p&gt;If you’ve ever wished Express had a bit more structure, Nest.js is the upgrade you’ve been looking for. It brings TypeScript, OOP, and a modular architecture to Node.js development.&lt;/p&gt;

&lt;p&gt;Nest is a framework for building efficient, scalable Node.js server-side applications. It uses modern JavaScript, is built with TypeScript (preserves compatibility with pure JavaScript) and combines elements of OOP (Object Oriented Programming), FP (Functional Programming), and FRP (Functional Reactive Programming).&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Flqc9zhc1cq0jrbx4w0mb.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Flqc9zhc1cq0jrbx4w0mb.webp" alt="Nest.js" width="800" height="385"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/vercel/turborepo" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;💎 Check out the  Nest.js repository ☆&lt;/a&gt;
&lt;/p&gt;




&lt;h2&gt;
  
  
  8. ⚙️ &lt;a href="https://gitmcp.io" rel="noopener noreferrer"&gt;GitMCP&lt;/a&gt; -  free, open-source, remote MCP server for any GitHub project
&lt;/h2&gt;

&lt;p&gt;The following project is a server implementing the MCP protocol that connects LLM directly to a GitHub repository.&lt;/p&gt;

&lt;p&gt;GitMCP is a free, open-source, remote Model Context Protocol (MCP) server that transforms any GitHub project (repositories or GitHub pages) into a documentation hub.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fkgwpcb3cgzn7a2advy6v.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fkgwpcb3cgzn7a2advy6v.png" alt="Tool 5" width="800" height="382"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/idosal/git-mcp" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;💎 Check out the  GitMCP repository ☆&lt;/a&gt;
&lt;/p&gt;




&lt;h2&gt;
  
  
  9. 🧩 &lt;a href="https://json-render.dev" rel="noopener noreferrer"&gt;json-render&lt;/a&gt; - The Generative UI framework.
&lt;/h2&gt;

&lt;p&gt;The next tool from Vercel allows you to create user interfaces literally from a json object.&lt;/p&gt;

&lt;p&gt;Predefined components and actions for safe, predictable output.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fn2uhw36wj9l3q6i5m7lx.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fn2uhw36wj9l3q6i5m7lx.png" alt="json-render" width="799" height="363"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/vercel-labs/json-render" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;💎 Check out the json-render repository ☆&lt;/a&gt;
&lt;/p&gt;




&lt;h2&gt;
  
  
  10. 🔀 &lt;a href="https://flowiseai.com" rel="noopener noreferrer"&gt;Flowise&lt;/a&gt; - Build AI Agents, Visually.
&lt;/h2&gt;

&lt;p&gt;If you've ever worked with Scratch, then you may be familiar with a slightly similar interface. This project will allow you to create AI agent workflow in a practical builder.&lt;/p&gt;

&lt;p&gt;Open source agentic systems development platform.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fiukjnmqqbtg65fq1nwrx.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fiukjnmqqbtg65fq1nwrx.png" alt="Flowise" width="799" height="384"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/FlowiseAI/Flowise" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;💎 Check out the Flowise repository ☆&lt;/a&gt;
&lt;/p&gt;




&lt;h2&gt;
  
  
  11. 🍎 &lt;a href="https://ml-explore.github.io/mlx/build/html/index.html" rel="noopener noreferrer"&gt;MLX&lt;/a&gt; - An array framework for Apple silicon
&lt;/h2&gt;

&lt;p&gt;An excellent framework from Apple that will allow you to teach your MacBook, iMac and other devices to solve many necessary tasks for business and more.&lt;/p&gt;

&lt;p&gt;MLX is designed by machine learning researchers for machine learning researchers. The framework is intended to be user-friendly, but still efficient to train and deploy models. The design of the framework itself is also conceptually simple.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fqocsx1v4v4eooanp13sn.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fqocsx1v4v4eooanp13sn.webp" alt="Gem 9" width="800" height="387"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/ml-explore/mlx" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;💎 Check out the  MLX repository ☆&lt;/a&gt;
&lt;/p&gt;




&lt;h2&gt;
  
  
  12. 🔤 &lt;a href="https://chenglou.me/pretext" rel="noopener noreferrer"&gt;Pretext&lt;/a&gt; - Fast, accurate &amp;amp; comprehensive text measurement &amp;amp; layout.
&lt;/h2&gt;

&lt;p&gt;Well, the last project, no, not an AI project, but a small javascript library for working with fonts and text at all.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;prepared&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;prepare&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;textareaValue&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;16px Inter&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="na"&gt;whiteSpace&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;pre-wrap&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt; &lt;span class="p"&gt;})&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;height&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;layout&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;prepared&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;textareaWidth&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;20&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Pretext side-steps the need for DOM measurements (e.g. getBoundingClientRect, offsetHeight), which trigger layout reflow, one of the most expensive operations in the browser. It implements its own text measurement logic, using the browsers' own font engine as ground truth (very AI-friendly iteration method).&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fltsrstsfj2j2we3je12q.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fltsrstsfj2j2we3je12q.png" alt="Pretext" width="787" height="588"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/chenglou/pretext" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;💎 Check out the  Pretext repository ☆&lt;/a&gt;
&lt;/p&gt;




&lt;h2&gt;
  
  
  🖋️ Conclusion
&lt;/h2&gt;

&lt;p&gt;In this article, I have reviewed only a small part of the volume of projects that are important and even necessary for every developer to know. It is clear that, well, let's say, there are hundreds of such projects today, and maybe more. But I hope you have discovered something new, and if not, at least remembered that there is.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Thank you very much for reading this article ❤️!&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;What other projects do you know that are not so popular, but also useful? It will be interesting to find out in the comments!&lt;/em&gt;&lt;/p&gt;

</description>
      <category>opensource</category>
      <category>webdev</category>
      <category>javascript</category>
      <category>programming</category>
    </item>
    <item>
      <title>[Boost]</title>
      <dc:creator>Anthony Max</dc:creator>
      <pubDate>Sun, 23 Aug 2026 10:25:47 +0000</pubDate>
      <link>https://dev.to/anthonymax/-34j0</link>
      <guid>https://dev.to/anthonymax/-34j0</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-solutions-providers-alternatives-and-cost-34kc" class="crayons-story__hidden-navigation-link"&gt;Enterprise MCP Gateway Solutions: Providers, Alternatives, and Cost 💎&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/anthonymax" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" alt="anthonymax profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/anthonymax" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Anthony Max
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Anthony Max
                &lt;a href="/++"&gt;&lt;img alt="Subscriber" class="subscription-icon" src="https://assets.dev.to/assets/subscription-icon-805dfa7ac7dd660f07ed8d654877270825b07a92a03841aa99a1093bd00431b2.png"&gt;&lt;/a&gt;
                
              
              &lt;div id="story-author-preview-content-4446316" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/anthonymax" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Anthony Max&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-solutions-providers-alternatives-and-cost-34kc" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Aug 20&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-solutions-providers-alternatives-and-cost-34kc" id="article-link-4446316"&gt;
          Enterprise MCP Gateway Solutions: Providers, Alternatives, and Cost 💎
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/webdev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;webdev&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/programming"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;programming&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/opensource"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;opensource&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-solutions-providers-alternatives-and-cost-34kc" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/exploding-head-daceb38d627e6ae9b730f36a1e390fca556a4289d5a41abb2c35068ad3e2c4b5.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/multi-unicorn-b44d6f8c23cdd00964192bedc38af3e82463978aa611b4365bd33a0f1f4f3e97.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;49&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-solutions-providers-alternatives-and-cost-34kc#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              10&lt;span class="hidden s:inline"&gt;&amp;nbsp;comments&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            13 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>Must read</title>
      <dc:creator>Anthony Max</dc:creator>
      <pubDate>Fri, 21 Aug 2026 07:54:22 +0000</pubDate>
      <link>https://dev.to/anthonymax/must-read-34o6</link>
      <guid>https://dev.to/anthonymax/must-read-34o6</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-solutions-providers-alternatives-and-cost-34kc" class="crayons-story__hidden-navigation-link"&gt;Enterprise MCP Gateway Solutions: Providers, Alternatives, and Cost 💎&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/anthonymax" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" alt="anthonymax profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/anthonymax" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Anthony Max
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Anthony Max
                &lt;a href="/++"&gt;&lt;img alt="Subscriber" class="subscription-icon" src="https://assets.dev.to/assets/subscription-icon-805dfa7ac7dd660f07ed8d654877270825b07a92a03841aa99a1093bd00431b2.png"&gt;&lt;/a&gt;
                
              
              &lt;div id="story-author-preview-content-4446316" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/anthonymax" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Anthony Max&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-solutions-providers-alternatives-and-cost-34kc" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Aug 20&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-solutions-providers-alternatives-and-cost-34kc" id="article-link-4446316"&gt;
          Enterprise MCP Gateway Solutions: Providers, Alternatives, and Cost 💎
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/webdev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;webdev&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/programming"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;programming&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/opensource"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;opensource&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-solutions-providers-alternatives-and-cost-34kc" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/exploding-head-daceb38d627e6ae9b730f36a1e390fca556a4289d5a41abb2c35068ad3e2c4b5.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/multi-unicorn-b44d6f8c23cdd00964192bedc38af3e82463978aa611b4365bd33a0f1f4f3e97.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;49&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-solutions-providers-alternatives-and-cost-34kc#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              10&lt;span class="hidden s:inline"&gt;&amp;nbsp;comments&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            13 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>Enterprise MCP Gateway Solutions: Providers, Alternatives, and Cost 💎</title>
      <dc:creator>Anthony Max</dc:creator>
      <pubDate>Thu, 20 Aug 2026 15:58:20 +0000</pubDate>
      <link>https://dev.to/anthonymax/enterprise-mcp-gateway-solutions-providers-alternatives-and-cost-34kc</link>
      <guid>https://dev.to/anthonymax/enterprise-mcp-gateway-solutions-providers-alternatives-and-cost-34kc</guid>
      <description>&lt;p&gt;Your company uses six different AI providers. OpenAI for ChatGPT, Anthropic for Claude and Groq for speed critical inference.&lt;/p&gt;

&lt;p&gt;Each one has different API formats. Different authentication models. Different rate limits and costs. Different failure modes.&lt;/p&gt;

&lt;p&gt;Your application code has to know about all of them. Your security team has to audit requests across all of them. Your finance team has to track costs across all of them. Your compliance team has to ensure governance across all of them.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/maximhq/bifrost" rel="noopener noreferrer"&gt;Bifrost Gateway&lt;/a&gt; solves this by doing what HTTP gateways have done for decades: &lt;strong&gt;centralizing control&lt;/strong&gt;. But for AI.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhppwjyjtyjpmm1dlx7c1.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhppwjyjtyjpmm1dlx7c1.png" alt="Enterprise" width="800" height="281"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  👀 What is an MCP gateway?
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Model Context Protocol (MCP)&lt;/strong&gt; is an open standard that lets AI models discover and execute external tools at runtime filesystems, web search, databases, ticketing systems, and custom business logic instead of being limited to text generation.&lt;/p&gt;

&lt;p&gt;An &lt;strong&gt;MCP gateway&lt;/strong&gt; sits between your applications (or external MCP clients like Claude Desktop and Cursor) and the upstream MCP servers. Instead of each client maintaining its own connections, credentials, and tool lists, the gateway:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Aggregates&lt;/strong&gt; tools from multiple MCP servers into one registry&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Applies governance&lt;/strong&gt;: authentication, tool filtering, budgets, and rate limits&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exposes a single endpoint&lt;/strong&gt; that external MCP clients can connect to&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In Bifrost, this pattern is implemented in two complementary roles:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Role&lt;/th&gt;
&lt;th&gt;What it does&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;MCP Client&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Connects to external MCP servers via STDIO, HTTP, or SSE&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;MCP Server (Gateway)&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Exposes aggregated tools at &lt;code&gt;/mcp&lt;/code&gt; for Claude Desktop, Cursor, and other MCP-compatible clients&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Bifrost is both an &lt;strong&gt;AI gateway&lt;/strong&gt; (routing LLM traffic to 20+ providers) and an &lt;strong&gt;MCP gateway&lt;/strong&gt; (connecting to and exposing tool servers). The open-source gateway covers virtual keys, budgets, rate limits, routing, and MCP tool filtering. &lt;strong&gt;Bifrost Enterprise&lt;/strong&gt; adds RBAC, SSO, audit logs, MCP Tool Groups, guardrails, clustering, and in-VPC deployment options.&lt;/p&gt;




&lt;h2&gt;
  
  
  ⚙️ How does an MCP gateway work?
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Connection layer
&lt;/h3&gt;

&lt;p&gt;Each upstream MCP server is registered as an &lt;strong&gt;MCP client&lt;/strong&gt; in Bifrost. Three connection protocols are supported:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Type&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;th&gt;Best for&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;STDIO&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Spawns a subprocess, communicates via stdin/stdout&lt;/td&gt;
&lt;td&gt;Local tools, CLI utilities, scripts&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;HTTP&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Sends requests to an HTTP endpoint&lt;/td&gt;
&lt;td&gt;Remote APIs, microservices, cloud functions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;SSE&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Server-Sent Events for persistent connections&lt;/td&gt;
&lt;td&gt;Real-time data, streaming tools&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Authentication is configured separately via a top-level &lt;code&gt;auth_type&lt;/code&gt; on each client: &lt;code&gt;none&lt;/code&gt;, &lt;code&gt;headers&lt;/code&gt;, &lt;code&gt;oauth&lt;/code&gt;, &lt;code&gt;per_user_oauth&lt;/code&gt;, or &lt;code&gt;per_user_headers&lt;/code&gt;. OAuth auth types apply only to HTTP and SSE connections.&lt;/p&gt;

&lt;h3&gt;
  
  
  Gateway endpoints
&lt;/h3&gt;

&lt;p&gt;When Bifrost acts as an MCP server, external clients connect to:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Endpoint&lt;/th&gt;
&lt;th&gt;Method&lt;/th&gt;
&lt;th&gt;Purpose&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;/mcp&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;POST&lt;/td&gt;
&lt;td&gt;JSON-RPC 2.0 for tool discovery and execution&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;/mcp&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;GET&lt;/td&gt;
&lt;td&gt;Server-Sent Events for persistent connections&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Clients configure their MCP host to point at &lt;code&gt;http://your-bifrost-gateway/mcp&lt;/code&gt;, optionally with a virtual key in the &lt;code&gt;Authorization&lt;/code&gt;, &lt;code&gt;x-bf-vk&lt;/code&gt;, &lt;code&gt;x-api-key&lt;/code&gt;, or &lt;code&gt;x-goog-api-key&lt;/code&gt; header.&lt;/p&gt;

&lt;h3&gt;
  
  
  Tool discovery and execution
&lt;/h3&gt;

&lt;p&gt;Tools are discovered when a client connects and refreshed on a configurable sync interval (default 10 minutes). Each tool follows the prefixed naming convention &lt;code&gt;clientName-toolName&lt;/code&gt; (for example, &lt;code&gt;filesystem-read_file&lt;/code&gt;).&lt;/p&gt;

&lt;p&gt;There are two distinct execution models:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. LLM Gateway path (inference + tools)&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;When your application calls &lt;code&gt;/v1/chat/completions&lt;/code&gt;, Bifrost does &lt;strong&gt;not&lt;/strong&gt; automatically execute tool calls. The default flow is stateless and explicit:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;1. POST /v1/chat/completions   → LLM returns tool call suggestions (NOT executed)
2. Your app reviews tool calls → Apply security rules, get user approval if needed
3. POST /v1/mcp/tool/execute   → Execute approved tool calls explicitly
4. POST /v1/chat/completions   → Continue the conversation with tool results
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;2. Pure MCP Gateway path (Claude Desktop, Cursor, etc.)&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;When external MCP clients connect directly to &lt;code&gt;/mcp&lt;/code&gt;, Bifrost exposes tools over the MCP protocol. The &lt;strong&gt;host application&lt;/strong&gt; (not Bifrost) runs the agent loop and decides whether each &lt;code&gt;tools/call&lt;/code&gt; requires user confirmation. Bifrost's &lt;code&gt;tools_to_auto_execute&lt;/code&gt; setting only applies in Agent Mode when Bifrost is also running the LLM loop, because it is ignored in pure gateway mode.&lt;/p&gt;

&lt;h3&gt;
  
  
  Three levels of tool filtering
&lt;/h3&gt;

&lt;p&gt;A tool must pass all applicable filters to be available:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Client config&lt;/strong&gt;: &lt;code&gt;tools_to_execute&lt;/code&gt; on each MCP client (baseline)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Request headers&lt;/strong&gt;: &lt;code&gt;x-bf-mcp-include-clients&lt;/code&gt; and &lt;code&gt;x-bf-mcp-include-tools&lt;/code&gt; per request&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Virtual key config&lt;/strong&gt;: &lt;code&gt;mcp_configs&lt;/code&gt; array (takes precedence over request headers)&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Deny-by-default for virtual keys:&lt;/strong&gt; when a virtual key has no &lt;code&gt;mcp_configs&lt;/code&gt;, &lt;strong&gt;no MCP tools are available&lt;/strong&gt;. Clients not listed in &lt;code&gt;mcp_configs&lt;/code&gt; are implicitly blocked.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-X&lt;/span&gt; POST http://localhost:8080/api/governance/virtual-keys &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"Content-Type: application/json"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s1"&gt;'{
    "name": "staging-key",
    "mcp_configs": [
      {
        "mcp_client_name": "staging_database",
        "tools_to_execute": ["query"]
      }
    ]
  }'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Enterprise: MCP Tool Groups
&lt;/h3&gt;

&lt;p&gt;In Bifrost Enterprise, &lt;strong&gt;Tool Groups&lt;/strong&gt; are reusable bundles of MCP tools attachable to virtual keys, teams, customers, users, providers, or API keys. At request time, Bifrost inspects the request context and exposes only the union of tools from matching groups. This adds a policy layer above per-key configuration for organizations with many teams and use cases.&lt;/p&gt;

&lt;h3&gt;
  
  
  Health and resilience
&lt;/h3&gt;

&lt;p&gt;Bifrost monitors connected MCP clients with configurable health checks (default: ping every 10 seconds, 5-second timeout, 5 consecutive failures before marking unstable). HTTP/SSE clients reconnect make-before-break; STDIO clients reconnect close-first. Automatic exponential backoff handles transient failures.&lt;/p&gt;




&lt;h2&gt;
  
  
  🔎 What to evaluate in an MCP gateway
&lt;/h2&gt;

&lt;p&gt;When comparing enterprise MCP gateway solutions, these criteria map directly to what production deployments require:&lt;/p&gt;

&lt;h3&gt;
  
  
  1. Security posture
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Question&lt;/th&gt;
&lt;th&gt;Bifrost answer (per docs)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Are tool calls executed automatically?&lt;/td&gt;
&lt;td&gt;No by default. Explicit &lt;code&gt;/v1/mcp/tool/execute&lt;/code&gt; required on the LLM path&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Is access deny-by-default?&lt;/td&gt;
&lt;td&gt;Yes. Virtual keys with no &lt;code&gt;mcp_configs&lt;/code&gt; get zero tools&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Can you limit tools per team/environment?&lt;/td&gt;
&lt;td&gt;Yes. Via virtual key &lt;code&gt;mcp_configs&lt;/code&gt;, request headers, and Enterprise MCP Tool Groups&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Is per-user upstream identity supported?&lt;/td&gt;
&lt;td&gt;Yes. &lt;code&gt;per_user_oauth&lt;/code&gt; and &lt;code&gt;per_user_headers&lt;/code&gt; with lazy auth&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  2. Authentication and identity
&lt;/h3&gt;

&lt;p&gt;Evaluate whether the gateway supports both &lt;strong&gt;server-level auth&lt;/strong&gt; (one shared credential for the team) and &lt;strong&gt;per-user auth&lt;/strong&gt; (each end-user connects under their own account). Bifrost supports five auth types, with OAuth limited to HTTP/SSE and implementing Authorization Code flow only (no client-credentials mode).&lt;/p&gt;

&lt;p&gt;For enterprise SSO, Bifrost Enterprise provides &lt;strong&gt;User Provisioning over OIDC&lt;/strong&gt; (Okta, Microsoft Entra, etc) with role mapping from IdP groups, app roles, or custom claims, synchronized on each session.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Runtime vs administrative governance
&lt;/h3&gt;

&lt;p&gt;This distinction matters: &lt;strong&gt;RBAC in Bifrost Enterprise governs the administrative surface&lt;/strong&gt; (who can edit MCP configs, read logs, configure guardrails) not which tools an agent executes at runtime. Runtime access is controlled by virtual keys, tool filtering, and MCP Tool Groups.&lt;/p&gt;

&lt;p&gt;RBAC permissions are &lt;strong&gt;Resource × Operation&lt;/strong&gt; pairs (for example, &lt;code&gt;MCPGateway:Update&lt;/code&gt;, &lt;code&gt;AuditLogs:View&lt;/code&gt;). Three system roles ship: Admin (42 permissions), Developer (27), Viewer (14).&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Observability and compliance
&lt;/h3&gt;

&lt;p&gt;Look for request logging, MCP execution logs, and audit trails for configuration changes. Bifrost Enterprise provides:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Audit Logs&lt;/strong&gt;: signed, filterable administrative event trails with export to JSON, JSON Lines, or Syslog&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Log Exports&lt;/strong&gt;: automated export of request logs to S3, GCS, BigQuery, and other data lakes&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Guardrails&lt;/strong&gt;: PII detection, secrets detection, content safety, and custom regex on LLM traffic and MCP tool executions&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  5. Cost control at scale
&lt;/h3&gt;

&lt;p&gt;Connecting many MCP servers inflates token usage because classic MCP injects every tool definition on every model turn. Bifrost &lt;strong&gt;Code Mode&lt;/strong&gt; addresses this by having the AI write Python to orchestrate tools in a sandbox rather than exposing hundreds of tool definitions directly. In Bifrost benchmarks with 508 tools across 16 servers, Code Mode reduced input tokens by &lt;strong&gt;92.8%&lt;/strong&gt; and estimated cost by &lt;strong&gt;92.2%&lt;/strong&gt; (from $377 to $29 per benchmark round) while maintaining a 100% pass rate.&lt;/p&gt;

&lt;p&gt;Virtual keys also provide independent &lt;strong&gt;budgets&lt;/strong&gt; and &lt;strong&gt;rate limits&lt;/strong&gt; for cost management at the key, team, and customer level.&lt;/p&gt;

&lt;h3&gt;
  
  
  6. Deployment model
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Deployment&lt;/th&gt;
&lt;th&gt;When to use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Open-source gateway&lt;/strong&gt; (&lt;code&gt;npx -y @maximhq/bifrost&lt;/code&gt;)&lt;/td&gt;
&lt;td&gt;Local dev, single-node production, full MCP + LLM gateway&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Enterprise clustered&lt;/strong&gt; (3+ pods, PostgreSQL)&lt;/td&gt;
&lt;td&gt;HA production with SSO, audit, guardrails&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;In-VPC&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Private-network deployment with no public traffic&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Bifrost Edge&lt;/strong&gt; (alpha)&lt;/td&gt;
&lt;td&gt;Endpoint governance — routes AI and MCP traffic from every laptop through your Bifrost without per-app reconfiguration&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  📊 Alternatives to a dedicated MCP gateway (and their trade-offs)
&lt;/h2&gt;

&lt;p&gt;As MCP adoption moves from local experiments to production, several vendors now offer gateway layers. Each with a different center of gravity. The table below summarizes how the major options compare at a glance; the sections that follow go deeper on each one.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Capability&lt;/th&gt;
&lt;th&gt;Bifrost&lt;/th&gt;
&lt;th&gt;Docker MCP Gateway&lt;/th&gt;
&lt;th&gt;Microsoft&lt;/th&gt;
&lt;th&gt;AWS AgentCore Gateway&lt;/th&gt;
&lt;th&gt;Kong MCP Gateway&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Primary role&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Unified LLM + MCP + Agents gateway&lt;/td&gt;
&lt;td&gt;Container-native MCP orchestration&lt;/td&gt;
&lt;td&gt;K8s MCP proxy + Azure API Management&lt;/td&gt;
&lt;td&gt;Managed MCP gateway on Bedrock&lt;/td&gt;
&lt;td&gt;API gateway with MCP plugins&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;MCP client + server&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Client/proxy&lt;/td&gt;
&lt;td&gt;Yes (proxy + lifecycle)&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Yes (proxy + REST→MCP conversion)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;LLM provider routing&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Yes (20+ providers)&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;td&gt;Bedrock-centric&lt;/td&gt;
&lt;td&gt;Via separate AI Gateway plugins&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Tool filtering / governance&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Virtual keys, &lt;code&gt;mcp_configs&lt;/code&gt;, MCP Tool Groups&lt;/td&gt;
&lt;td&gt;Profiles, interceptors&lt;/td&gt;
&lt;td&gt;RBAC, APIM policies&lt;/td&gt;
&lt;td&gt;Gateway targets, semantic search&lt;/td&gt;
&lt;td&gt;OAuth 2.1 + per-tool ACLs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;OAuth for MCP servers&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Yes (Authorization Code, PKCE, DCR)&lt;/td&gt;
&lt;td&gt;Yes (built-in OAuth flows)&lt;/td&gt;
&lt;td&gt;Yes (Entra ID)&lt;/td&gt;
&lt;td&gt;Yes (IAM + OAuth inbound)&lt;/td&gt;
&lt;td&gt;Yes (OAuth 2.1 via AI MCP OAuth2 plugin)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Enterprise audit / RBAC&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Yes (Enterprise tier)&lt;/td&gt;
&lt;td&gt;Logging + call tracing&lt;/td&gt;
&lt;td&gt;Entra RBAC + APIM governance&lt;/td&gt;
&lt;td&gt;CloudTrail / IAM&lt;/td&gt;
&lt;td&gt;Enterprise-only, Konnect analytics&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Open-source option&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Yes (full gateway)&lt;/td&gt;
&lt;td&gt;Yes (MIT)&lt;/td&gt;
&lt;td&gt;Yes (K8s gateway OSS)&lt;/td&gt;
&lt;td&gt;Managed AWS service&lt;/td&gt;
&lt;td&gt;Gateway OSS; MCP plugins enterprise&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Deployment&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Binary, Docker, K8s, in-VPC&lt;/td&gt;
&lt;td&gt;Docker Desktop / Docker Engine&lt;/td&gt;
&lt;td&gt;AKS + Azure APIM&lt;/td&gt;
&lt;td&gt;AWS managed&lt;/td&gt;
&lt;td&gt;Kong Gateway / Konnect&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  1. Bifrost
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://docs.getbifrost.ai" rel="noopener noreferrer"&gt;Bifrost&lt;/a&gt; is the open-source, high-performance AI gateway built in Go by Maxim AI. It leads this comparison for teams that need &lt;strong&gt;LLM routing, MCP aggregation, and agent governance in one self-hosted platform&lt;/strong&gt;, not an MCP-only proxy sitting beside a separate LLM gateway.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;MCP connectivity.&lt;/strong&gt; Bifrost acts as both MCP client and MCP server. It &lt;a href="https://docs.getbifrost.ai/mcp/connecting-to-servers" rel="noopener noreferrer"&gt;connects outward to any MCP server&lt;/a&gt; you register (STDIO, HTTP, or SSE) and &lt;a href="https://docs.getbifrost.ai/mcp/gateway" rel="noopener noreferrer"&gt;exposes aggregated tools at &lt;code&gt;/mcp&lt;/code&gt;&lt;/a&gt; for Claude Desktop, Cursor, and other MCP-compatible clients. Five auth types cover the full spectrum: &lt;code&gt;none&lt;/code&gt;, &lt;code&gt;headers&lt;/code&gt;, &lt;code&gt;oauth&lt;/code&gt;, &lt;code&gt;per_user_oauth&lt;/code&gt;, and &lt;code&gt;per_user_headers&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Security by default.&lt;/strong&gt; On the LLM path, Bifrost does not auto-execute tool calls. Your application must explicitly call &lt;code&gt;POST /v1/mcp/tool/execute&lt;/code&gt;. Virtual keys enforce deny-by-default: a key with no &lt;code&gt;mcp_configs&lt;/code&gt; gets zero MCP tools. Three stacked filter levels (client config, request headers, virtual key config) control which tools each caller sees.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Governance and cost control.&lt;/strong&gt; Open-source Bifrost covers virtual keys, budgets, rate limits, routing, and MCP tool filtering. &lt;a href="https://docs.getbifrost.ai/mcp/code-mode" rel="noopener noreferrer"&gt;Code Mode&lt;/a&gt; reduces input token usage by up to &lt;strong&gt;92.8%&lt;/strong&gt; and estimated cost by &lt;strong&gt;92.2%&lt;/strong&gt; when orchestrating many MCP servers, the model writes Python to call tools in a sandbox instead of round-tripping every tool definition through the context window. &lt;a href="https://docs.getbifrost.ai/mcp/agent-mode" rel="noopener noreferrer"&gt;Agent Mode&lt;/a&gt; adds opt-in autonomous execution for tools explicitly marked in &lt;code&gt;tools_to_auto_execute&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Enterprise tier.&lt;/strong&gt; &lt;a href="https://docs.getbifrost.ai/enterprise/overview" rel="noopener noreferrer"&gt;Bifrost Enterprise&lt;/a&gt; adds RBAC (Resource × Operation permissions), SSO via OIDC (Okta, Entra, Keycloak, etc), HMAC-signed audit logs, MCP Tool Groups, guardrails (PII, secrets, content safety), clustering, adaptive load balancing, and in-VPC deployment. Enterprise is a strict superset of OSS. Same &lt;code&gt;config.json&lt;/code&gt; schema, no re-integration.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Performance.&lt;/strong&gt; Bifrost adds roughly &lt;strong&gt;11 µs&lt;/strong&gt; of overhead per request at 5,000 RPS in sustained &lt;a href="https://docs.getbifrost.ai/benchmarking/getting-started" rel="noopener noreferrer"&gt;benchmarks&lt;/a&gt;, making it suitable for latency-sensitive production workloads.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Organizations running mission-critical AI workloads that need a single gateway for LLM traffic, MCP tool access, and agent execution with enterprise-grade governance, air-gapped or in-VPC deployment, and ultra-low latency. Start free with &lt;code&gt;npx -y @maximhq/bifrost&lt;/code&gt;; add Enterprise when SSO, audit logs, and administrative RBAC are required.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Docker MCP Gateway
&lt;/h3&gt;

&lt;p&gt;Docker MCP Gateway is Docker's open-source (MIT) solution for orchestrating MCP servers as &lt;strong&gt;isolated Docker containers&lt;/strong&gt;. It acts as a centralized proxy: AI clients connect to the Gateway once, and the Gateway manages server lifecycle, credential injection, and routing across servers grouped in profiles.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; Strong container isolation (restricted privileges, network sandboxing, resource limits), built-in OAuth flows, secrets management via Docker Desktop, dynamic tool discovery, and call-tracing interceptors (secret scanning, signature verification). Integrates natively with Docker Desktop's MCP Toolkit for a low-friction local developer experience.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trade-offs vs Bifrost:&lt;/strong&gt; Docker MCP Gateway is MCP-focused, it does not route LLM traffic across providers, enforce virtual-key budgets, or offer Code Mode token savings. Cross-team organizational governance (RBAC, SSO, audit logs) requires additional tooling on top. Best suited for container-native teams already standardized on Docker rather than organizations needing a unified AI + MCP control plane.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Teams invested in the Docker ecosystem who want to package, run, and secure MCP servers as containers from local development toward production.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Microsoft MCP Gateway (Azure)
&lt;/h3&gt;

&lt;p&gt;Microsoft offers two complementary paths for MCP at enterprise scale.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Open-source MCP Gateway&lt;/strong&gt; is a Kubernetes-native reverse proxy and management layer for MCP servers on AKS. It provides session-aware stateful routing, MCP server lifecycle management (deploy, update, delete), and integration with &lt;strong&gt;Azure Entra ID&lt;/strong&gt; for bearer-token authentication. A separate Tool Gateway handles dynamic tool routing behind the proxy.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Azure API Management&lt;/strong&gt; adds enterprise governance: expose REST APIs as MCP servers, govern existing MCP endpoints, apply rate-limiting and content-safety policies, and discover servers through Azure API Center. The AI Gateway tier supports MCP-specific features through a dedicated release channel.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; Deep Azure and Entra ID integration, K8s-native scaling, REST-to-MCP exposure without rewriting APIs, and a mature API-management policy engine.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trade-offs vs Bifrost:&lt;/strong&gt; Microsoft's stack is Azure-centric and split across multiple services (AKS gateway + APIM + API Center). It does not unify LLM provider routing with MCP governance in a single binary. Per-tool token-cost optimization (Code Mode) and sub-microsecond LLM gateway overhead are not part of this offering.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Enterprises already on Azure and Kubernetes who want MCP server lifecycle management and API Management-style policy enforcement within the Microsoft cloud ecosystem.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. AWS AgentCore Gateway
&lt;/h3&gt;

&lt;p&gt;Amazon Bedrock AgentCore Gateway is AWS's managed MCP gateway for connecting agents to tools hosted on AWS services and external MCP servers. It supports multiple MCP protocol versions (including &lt;code&gt;2026-07-28&lt;/code&gt; stateless tool calls), &lt;strong&gt;semantic search&lt;/strong&gt; across tool catalogs, and inbound authentication via IAM and OAuth.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; Fully managed. No gateway pods to size or patch. Native IAM SigV4 for AWS-hosted MCP targets. Semantic search helps agents find the right tool when catalogs grow large. Tight integration with Bedrock agent runtimes and the broader AgentCore platform.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trade-offs vs Bifrost:&lt;/strong&gt; AgentCore Gateway is an AWS managed service with Bedrock-centric positioning, not a self-hosted, provider-agnostic LLM gateway. Pricing follows AWS consumption models rather than a free open-source tier. Virtual-key-style budgets, Code Mode orchestration, and air-gapped on-prem deployment are outside this product's scope.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Teams building agent workloads on Amazon Bedrock who want a managed MCP aggregation layer without operating their own gateway infrastructure.&lt;/p&gt;

&lt;h3&gt;
  
  
  5. Kong MCP Gateway
&lt;/h3&gt;

&lt;p&gt;Kong MCP Gateway extends Kong's AI Gateway (v3.12+) with MCP-specific plugins. The AI MCP Proxy plugin acts as a protocol bridge. Converting REST APIs into MCP tools (&lt;code&gt;conversion-only&lt;/code&gt; / &lt;code&gt;listener&lt;/code&gt; modes) or proxying upstream MCP servers in passthrough mode. The AI MCP OAuth2 plugin implements OAuth 2.1 per the MCP authorization spec, mapping token claims to per-tool ACLs.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Strengths:&lt;/strong&gt; Leverages Kong's proven API-gateway patterns, rate limiting, observability, developer portal, service catalog. Can federate multiple team-owned MCP servers behind one aggregated endpoint with centralized OAuth. REST-to-MCP conversion lets existing Kong-managed APIs become agent tools without new MCP server code.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trade-offs vs Bifrost:&lt;/strong&gt; MCP Gateway capabilities are &lt;strong&gt;enterprise-only paid plugins&lt;/strong&gt; on Kong Gateway or Konnect. Not available in the open-source Kong edition. Kong does not natively route LLM traffic across 20+ providers or offer Code Mode token reduction. Configuration spans Services, Routes, Consumers, and plugin modes rather than a unified MCP + LLM config surface.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Organizations already running Kong API Gateway who want to add MCP aggregation, OAuth 2.1 enforcement, and REST-to-MCP conversion to their existing API-management stack.&lt;/p&gt;




&lt;h2&gt;
  
  
  💻 What implementing an MCP gateway costs
&lt;/h2&gt;

&lt;p&gt;Costs fall into three buckets: &lt;strong&gt;software licensing&lt;/strong&gt;, &lt;strong&gt;infrastructure&lt;/strong&gt;, and &lt;strong&gt;operational/token savings&lt;/strong&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  Software licensing
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tier&lt;/th&gt;
&lt;th&gt;Cost (per docs)&lt;/th&gt;
&lt;th&gt;What you get&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Open-source Bifrost&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Free&lt;/td&gt;
&lt;td&gt;LLM gateway, MCP client + server, virtual keys, budgets, rate limits, routing, MCP tool filtering, Code Mode, observability&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Bifrost Enterprise&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;14-day free trial (no credit card); contact sales for pricing&lt;/td&gt;
&lt;td&gt;Everything in OSS plus RBAC, SSO, audit logs, MCP Tool Groups, guardrails, clustering, adaptive load balancing, in-VPC deployment, log exports&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Bifrost Enterprise is a strict superset of the open-source gateway. Same &lt;code&gt;config.json&lt;/code&gt; schema, no re-integration required.&lt;/p&gt;

&lt;h3&gt;
  
  
  Infrastructure (Enterprise production baseline)
&lt;/h3&gt;

&lt;p&gt;The &lt;a href="https://docs.getbifrost.ai/enterprise/moving-from-oss/sizing" rel="noopener noreferrer"&gt;Enterprise sizing guide&lt;/a&gt; recommends:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Gateway pods&lt;/strong&gt;&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Setting&lt;/th&gt;
&lt;th&gt;Recommended&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Pod count&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;3 minimum&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;vCPU per pod&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;4&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;RAM per pod&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;16 GB&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;PostgreSQL&lt;/strong&gt;&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Configuration&lt;/th&gt;
&lt;th&gt;vCPU&lt;/th&gt;
&lt;th&gt;RAM&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Default (logs in PostgreSQL)&lt;/td&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;24 GB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;With object storage for large logs&lt;/td&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;16 GB&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Object storage (S3, GCS) for log payloads reduces PostgreSQL write pressure and improves dashboard log-read latency. Audit log archival to object storage is configured separately under &lt;code&gt;audit_logs.object_storage&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;For a single-node or development deployment, the open-source gateway runs locally with:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx &lt;span class="nt"&gt;-y&lt;/span&gt; @maximhq/bifrost
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;No minimum hardware is specified for OSS. Production Enterprise sizing above is the documented baseline for HA.&lt;/p&gt;

&lt;h3&gt;
  
  
  Token and inference cost savings
&lt;/h3&gt;

&lt;p&gt;The largest ongoing cost for MCP-heavy workloads is often &lt;strong&gt;LLM token usage&lt;/strong&gt;, not gateway infrastructure. Two Bifrost features directly reduce this:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Code Mode&lt;/strong&gt; (recommended when using 3+ MCP servers):&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Up to &lt;strong&gt;92.8%&lt;/strong&gt; fewer input tokens vs classic MCP at scale&lt;/li&gt;
&lt;li&gt;Up to &lt;strong&gt;92.2%&lt;/strong&gt; lower estimated inference cost&lt;/li&gt;
&lt;li&gt;Benchmark: 508 tools / 16 servers — $377 → $29 per round, 75.1M → 5.4M input tokens&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Governance features that reduce waste:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Virtual key budgets&lt;/strong&gt; — dollar limits with configurable reset periods&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rate limits&lt;/strong&gt; — token and request throttling per virtual key&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Semantic caching&lt;/strong&gt; — reduces cost and latency for similar queries (open-source feature)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tool filtering&lt;/strong&gt; — expose only the tools a team needs, reducing context size even in classic MCP mode&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Total cost framing
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Scenario&lt;/th&gt;
&lt;th&gt;Typical cost drivers&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Single team, OSS, local/dev&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;$0 software + existing hardware; main cost is LLM API usage&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Production OSS, single node&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Compute for one gateway instance + PostgreSQL (if used) + LLM API usage&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Enterprise HA (3 pods + PG + object storage)&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Enterprise license + ~3 × (4 vCPU / 16 GB) + PostgreSQL 8 vCPU / 16–24 GB + object storage + LLM API usage&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Enterprise + Edge (alpha)&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Above + endpoint agent rollout (contact for alpha access)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The gateway itself adds minimal latency. Bifrost benchmarks show &lt;strong&gt;11 µs&lt;/strong&gt; overhead per request at 5,000 RPS on the LLM routing path. The economic case for an MCP gateway is primarily &lt;strong&gt;governance&lt;/strong&gt; (preventing unauthorized tool access) and &lt;strong&gt;token efficiency&lt;/strong&gt; (Code Mode and filtering at scale), not raw infrastructure savings.&lt;/p&gt;




&lt;h2&gt;
  
  
  🖋️ Conclusion
&lt;/h2&gt;

&lt;p&gt;An MCP gateway turns a collection of developer tool connections into an organization-wide control plane. Without one, every agent on every laptop can connect to production systems with no central policy, no audit trail, and no cost visibility.&lt;/p&gt;

&lt;p&gt;Bifrost provides this as both an open-source AI + MCP gateway and an Enterprise tier for organizations that need RBAC, audit-grade logging, guardrails, and high-availability deployment.&lt;/p&gt;




&lt;h2&gt;
  
  
  🔗 Resources:
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Bifrost GitHub&lt;/strong&gt;: &lt;a href="https://github.com/maximhq/bifrost" rel="noopener noreferrer"&gt;https://github.com/maximhq/bifrost&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Bifrost Docs&lt;/strong&gt;: &lt;a href="https://docs.getbifrost.ai" rel="noopener noreferrer"&gt;https://docs.getbifrost.ai&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Bifrost CLI&lt;/strong&gt;: &lt;code&gt;npx -y @maximhq/bifrost-cli&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Thanks for reading this article! ❤️&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;I'd love to hear your thoughts on this mode in the comments!&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>webdev</category>
      <category>programming</category>
      <category>opensource</category>
    </item>
    <item>
      <title>[Boost]</title>
      <dc:creator>Anthony Max</dc:creator>
      <pubDate>Sat, 15 Aug 2026 07:31:51 +0000</pubDate>
      <link>https://dev.to/anthonymax/-3937</link>
      <guid>https://dev.to/anthonymax/-3937</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca" class="crayons-story__hidden-navigation-link"&gt;APIMart: Discounted AI API Aggregator for GPT-5, Sora 2 💎&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/anthonymax" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" alt="anthonymax profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/anthonymax" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Anthony Max
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Anthony Max
                &lt;a href="/++"&gt;&lt;img alt="Subscriber" class="subscription-icon" src="https://assets.dev.to/assets/subscription-icon-805dfa7ac7dd660f07ed8d654877270825b07a92a03841aa99a1093bd00431b2.png"&gt;&lt;/a&gt;
                
              
              &lt;div id="story-author-preview-content-4390127" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/anthonymax" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Anthony Max&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Aug 14&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca" id="article-link-4390127"&gt;
          APIMart: Discounted AI API Aggregator for GPT-5, Sora 2 💎
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/webdev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;webdev&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/programming"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;programming&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/api"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;api&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/exploding-head-daceb38d627e6ae9b730f36a1e390fca556a4289d5a41abb2c35068ad3e2c4b5.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/multi-unicorn-b44d6f8c23cdd00964192bedc38af3e82463978aa611b4365bd33a0f1f4f3e97.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;43&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              3&lt;span class="hidden s:inline"&gt;&amp;nbsp;comments&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            3 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>[Boost]</title>
      <dc:creator>Anthony Max</dc:creator>
      <pubDate>Fri, 14 Aug 2026 17:39:40 +0000</pubDate>
      <link>https://dev.to/anthonymax/-2f2j</link>
      <guid>https://dev.to/anthonymax/-2f2j</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca" class="crayons-story__hidden-navigation-link"&gt;APIMart: Discounted AI API Aggregator for GPT-5, Sora 2 💎&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/anthonymax" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" alt="anthonymax profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/anthonymax" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Anthony Max
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Anthony Max
                &lt;a href="/++"&gt;&lt;img alt="Subscriber" class="subscription-icon" src="https://assets.dev.to/assets/subscription-icon-805dfa7ac7dd660f07ed8d654877270825b07a92a03841aa99a1093bd00431b2.png"&gt;&lt;/a&gt;
                
              
              &lt;div id="story-author-preview-content-4390127" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/anthonymax" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Anthony Max&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Aug 14&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca" id="article-link-4390127"&gt;
          APIMart: Discounted AI API Aggregator for GPT-5, Sora 2 💎
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/webdev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;webdev&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/programming"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;programming&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/api"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;api&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/exploding-head-daceb38d627e6ae9b730f36a1e390fca556a4289d5a41abb2c35068ad3e2c4b5.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/multi-unicorn-b44d6f8c23cdd00964192bedc38af3e82463978aa611b4365bd33a0f1f4f3e97.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;43&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              3&lt;span class="hidden s:inline"&gt;&amp;nbsp;comments&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            3 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>Interesting article</title>
      <dc:creator>Anthony Max</dc:creator>
      <pubDate>Fri, 14 Aug 2026 15:14:25 +0000</pubDate>
      <link>https://dev.to/anthonymax/interesting-article-5641</link>
      <guid>https://dev.to/anthonymax/interesting-article-5641</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca" class="crayons-story__hidden-navigation-link"&gt;APIMart: Discounted AI API Aggregator for GPT-5, Sora 2 💎&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/anthonymax" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" alt="anthonymax profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/anthonymax" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Anthony Max
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Anthony Max
                &lt;a href="/++"&gt;&lt;img alt="Subscriber" class="subscription-icon" src="https://assets.dev.to/assets/subscription-icon-805dfa7ac7dd660f07ed8d654877270825b07a92a03841aa99a1093bd00431b2.png"&gt;&lt;/a&gt;
                
              
              &lt;div id="story-author-preview-content-4390127" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/anthonymax" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Anthony Max&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Aug 14&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca" id="article-link-4390127"&gt;
          APIMart: Discounted AI API Aggregator for GPT-5, Sora 2 💎
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/webdev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;webdev&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/programming"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;programming&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/api"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;api&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/exploding-head-daceb38d627e6ae9b730f36a1e390fca556a4289d5a41abb2c35068ad3e2c4b5.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/multi-unicorn-b44d6f8c23cdd00964192bedc38af3e82463978aa611b4365bd33a0f1f4f3e97.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;43&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              3&lt;span class="hidden s:inline"&gt;&amp;nbsp;comments&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            3 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>APIMart: Discounted AI API Aggregator for GPT-5, Sora 2 💎</title>
      <dc:creator>Anthony Max</dc:creator>
      <pubDate>Fri, 14 Aug 2026 13:35:12 +0000</pubDate>
      <link>https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca</link>
      <guid>https://dev.to/anthonymax/apimart-discounted-ai-api-aggregator-for-gpt-5-sora-2-bca</guid>
      <description>&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;Today, there are numerous AI models, and it's important for businesses to be able to work with them easily and, most importantly, profitably.&lt;/p&gt;

&lt;p&gt;Every entrepreneur who runs their own service wants to pay as little as possible for AI tokens and have a personal account with all the keys to the LLM providers' APIs.&lt;/p&gt;

&lt;p&gt;Today I would like to introduce you to a site called APIMart, which will help you and your business with this.&lt;/p&gt;

&lt;p&gt;Well, let's get started! 🏎️&lt;/p&gt;




&lt;h2&gt;
  
  
  👀 What is APIMart?
&lt;/h2&gt;

&lt;p&gt;I would say this: if you are looking for a place to buy cheap access to many popular API providers, then this service will help you with that.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftcr1jow2m88xbtdc91dy.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftcr1jow2m88xbtdc91dy.png" alt="intro"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Use one OpenAI-compatible API to reach leading global models across text, image, video, and multimodal workloads. APIMart unifies keys, billing, monitoring, and production access so teams can ship AI features faster at a lower operating cost.&lt;/p&gt;




&lt;h2&gt;
  
  
  ⚙️ How to use it?
&lt;/h2&gt;

&lt;p&gt;First of all, when working with APIMart, it's important to understand that it's a user-friendly API. Let's try creating our first connection to an AI model.&lt;/p&gt;

&lt;p&gt;To do this, you will need to &lt;a href="https://apimart.ai/register?aff=yScTCM" rel="noopener noreferrer"&gt;register&lt;/a&gt; on the website:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fo7qnye2jgepnl1fftv2o.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fo7qnye2jgepnl1fftv2o.png" alt="register"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;It won't take more than 5 minutes. Next, let's go to your personal account. Let's say I want to create an image.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzh0al2siruo5k9996byw.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzh0al2siruo5k9996byw.png" alt="personal account"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;By clicking the "Create an API Key" button, I can create my first key that I can use. It's worth noting that you can only specify the API key group and name. Advanced settings are optional.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F52lr9ntom3zmuhvvz402.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F52lr9ntom3zmuhvvz402.png" alt="API Key"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After creating an API key, you can select the model to use for image generation. I'll be using &lt;code&gt;gpt-image-2&lt;/code&gt; from OpenAI, but you can choose any model that suits your pricing and needs.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fkv2o6f48qr5bg07ame4c.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fkv2o6f48qr5bg07ame4c.png" alt="gpt-image-2"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;It's also worth noting that you can use the free tariff for the model to see if it's right for you.&lt;/p&gt;

&lt;h2&gt;
  
  
  📚 Documentation
&lt;/h2&gt;

&lt;p&gt;After we've set up our API key, we can now use the model via the API. There's a tab on the model page for this. Clicking on it will take us to the documentation page.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1tiv6pdckp6wddoh4cwv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1tiv6pdckp6wddoh4cwv.png" alt="documentation"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;There's a lot written here about how to use the model, but if anything is missing, the documentation is actively updated.&lt;/p&gt;

&lt;p&gt;To access the API, let's try typing the following line in the terminal:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# model can be "gpt-image-2", or the compatible alias "gpt-image-2-ext"&lt;/span&gt;
curl &lt;span class="nt"&gt;--request&lt;/span&gt; POST &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--url&lt;/span&gt; https://api.apimart.ai/v1/images/generations &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--header&lt;/span&gt; &lt;span class="s1"&gt;'Authorization: Bearer &amp;lt;token&amp;gt;'&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--header&lt;/span&gt; &lt;span class="s1"&gt;'Content-Type: application/json'&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--data&lt;/span&gt; &lt;span class="s1"&gt;'{
    "model": "gpt-image-2",
    "prompt": "Make an image for the article",
    "n": 1,
    "size": "16:9",
    "resolution": "2k"
  }'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If everything is configured correctly, we'll get the generated image.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;url&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;https://api.apimart.ai/v1/images/generations&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;payload&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="na"&gt;model&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;gpt-image-2&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;prompt&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;Make an image for the article&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;n&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;size&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;16:9&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;resolution&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;2k&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;headers&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;Authorization&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;Bearer &amp;lt;token&amp;gt;&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;Content-Type&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;application/json&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;

&lt;span class="nf"&gt;fetch&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;url&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="na"&gt;method&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;POST&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;headers&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;headers&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;body&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;JSON&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;stringify&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;})&lt;/span&gt;
  &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;then&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;response&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;response&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;json&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
  &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;then&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;data&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
  &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="k"&gt;catch&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;error&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;error&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Error:&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;error&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It's worth noting that the API can be accessed from any programming language that supports HTTP requests. So, for example, here's what it would look like using JavaScript.&lt;/p&gt;




&lt;h2&gt;
  
  
  💬 Feedback
&lt;/h2&gt;

&lt;p&gt;If you have questions about the site's operation or want to learn about new features, you can always find them in the community's official project channels:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsml3yslzpsoeyhh4fy26.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsml3yslzpsoeyhh4fy26.png" alt="social links"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Or write directly in the form on the website, which is also convenient:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F96o2nfy18gfsk2fr5jkw.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F96o2nfy18gfsk2fr5jkw.png" alt="form"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  🖋️ Conclusion
&lt;/h2&gt;

&lt;p&gt;APIMart is a great solution for entrepreneurs and companies looking to optimize their AI service costs and simplify their workflow across various models. Instead of managing multiple API keys from different providers, you get a single, convenient interface with your personal account.&lt;/p&gt;




&lt;h2&gt;
  
  
  🔗 Resources:
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;APIMart site&lt;/strong&gt;: &lt;a href="https://apimart.ai/register?aff=yScTCM" rel="noopener noreferrer"&gt;https://apimart.ai/register?aff=yScTCM&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Thanks for reading this article! ❤️&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;I'd love to hear your thoughts on this mode in the comments!&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>webdev</category>
      <category>programming</category>
      <category>api</category>
    </item>
    <item>
      <title>[Boost]</title>
      <dc:creator>Anthony Max</dc:creator>
      <pubDate>Thu, 06 Aug 2026 21:56:32 +0000</pubDate>
      <link>https://dev.to/anthonymax/-m02</link>
      <guid>https://dev.to/anthonymax/-m02</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-with-built-in-security-oauth-20-rbac-and-tool-access-control-68n" class="crayons-story__hidden-navigation-link"&gt;Enterprise MCP Gateway with Built-In Security: OAuth 2.0, RBAC, and Tool Access Control&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/anthonymax" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" alt="anthonymax profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/anthonymax" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Anthony Max
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Anthony Max
                &lt;a href="/++"&gt;&lt;img alt="Subscriber" class="subscription-icon" src="https://assets.dev.to/assets/subscription-icon-805dfa7ac7dd660f07ed8d654877270825b07a92a03841aa99a1093bd00431b2.png"&gt;&lt;/a&gt;
              
              &lt;div id="story-author-preview-content-4311404" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/anthonymax" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Anthony Max&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-with-built-in-security-oauth-20-rbac-and-tool-access-control-68n" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Aug 5&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-with-built-in-security-oauth-20-rbac-and-tool-access-control-68n" id="article-link-4311404"&gt;
          Enterprise MCP Gateway with Built-In Security: OAuth 2.0, RBAC, and Tool Access Control
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/webdev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;webdev&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/programming"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;programming&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/opensource"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;opensource&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-with-built-in-security-oauth-20-rbac-and-tool-access-control-68n" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/exploding-head-daceb38d627e6ae9b730f36a1e390fca556a4289d5a41abb2c35068ad3e2c4b5.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/multi-unicorn-b44d6f8c23cdd00964192bedc38af3e82463978aa611b4365bd33a0f1f4f3e97.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;51&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-with-built-in-security-oauth-20-rbac-and-tool-access-control-68n#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              13&lt;span class="hidden s:inline"&gt;&amp;nbsp;comments&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            8 min read
          &lt;/small&gt;
            
              &lt;span class="bm-initial crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
              &lt;span class="bm-success crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
            
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>[Boost]</title>
      <dc:creator>Anthony Max</dc:creator>
      <pubDate>Wed, 05 Aug 2026 21:38:18 +0000</pubDate>
      <link>https://dev.to/anthonymax/-28h6</link>
      <guid>https://dev.to/anthonymax/-28h6</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-with-built-in-security-oauth-20-rbac-and-tool-access-control-68n" class="crayons-story__hidden-navigation-link"&gt;Enterprise MCP Gateway with Built-In Security: OAuth 2.0, RBAC, and Tool Access Control&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/anthonymax" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" alt="anthonymax profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/anthonymax" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Anthony Max
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Anthony Max
                &lt;a href="/++"&gt;&lt;img alt="Subscriber" class="subscription-icon" src="https://assets.dev.to/assets/subscription-icon-805dfa7ac7dd660f07ed8d654877270825b07a92a03841aa99a1093bd00431b2.png"&gt;&lt;/a&gt;
              
              &lt;div id="story-author-preview-content-4311404" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/anthonymax" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2103048%2F716988a5-9c51-49bf-acef-191bc6dd2fee.jpeg" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Anthony Max&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-with-built-in-security-oauth-20-rbac-and-tool-access-control-68n" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Aug 5&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-with-built-in-security-oauth-20-rbac-and-tool-access-control-68n" id="article-link-4311404"&gt;
          Enterprise MCP Gateway with Built-In Security: OAuth 2.0, RBAC, and Tool Access Control
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/webdev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;webdev&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/programming"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;programming&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/opensource"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;opensource&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-with-built-in-security-oauth-20-rbac-and-tool-access-control-68n" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/exploding-head-daceb38d627e6ae9b730f36a1e390fca556a4289d5a41abb2c35068ad3e2c4b5.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/multi-unicorn-b44d6f8c23cdd00964192bedc38af3e82463978aa611b4365bd33a0f1f4f3e97.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;51&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/anthonymax/enterprise-mcp-gateway-with-built-in-security-oauth-20-rbac-and-tool-access-control-68n#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              13&lt;span class="hidden s:inline"&gt;&amp;nbsp;comments&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            8 min read
          &lt;/small&gt;
            
              &lt;span class="bm-initial crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
              &lt;span class="bm-success crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
            
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>Enterprise MCP Gateway with Built-In Security: OAuth 2.0, RBAC, and Tool Access Control</title>
      <dc:creator>Anthony Max</dc:creator>
      <pubDate>Wed, 05 Aug 2026 19:41:55 +0000</pubDate>
      <link>https://dev.to/anthonymax/enterprise-mcp-gateway-with-built-in-security-oauth-20-rbac-and-tool-access-control-68n</link>
      <guid>https://dev.to/anthonymax/enterprise-mcp-gateway-with-built-in-security-oauth-20-rbac-and-tool-access-control-68n</guid>
      <description>&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;MCP servers are powerful, but they can provide access to production systems if anyone on the team can connect and run tools without guardrails.&lt;/p&gt;

&lt;p&gt;Imagine a new hire testing the app on their laptop and accidentally granting an MCP server access to the production database. Without governance, that is a realistic path to data leakage.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://github.com/maximhq/bifrost.git" rel="noopener noreferrer"&gt;Bifrost&lt;/a&gt; addresses this with three layers:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Human-in-the-loop execution&lt;/strong&gt; — Bifrost does not auto-execute tool calls. The LLM only &lt;em&gt;suggests&lt;/em&gt; tools; your application reviews them and explicitly calls &lt;code&gt;POST /v1/mcp/tool/execute&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Deny-by-default tool filtering&lt;/strong&gt; — A virtual key with no &lt;code&gt;mcp_configs&lt;/code&gt; gets zero MCP tools. Unlisted clients are implicitly blocked.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Governance&lt;/strong&gt; (optional) — RBAC, SSO, audit logs, and MCP Tool Groups control who can configure the gateway and review administrative activity.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Bifrost covers virtual keys, budgets, rate limits, routing, and MCP tool filtering, RBAC, SSO, audit logs, and MCP Tool.&lt;/p&gt;




&lt;h2&gt;
  
  
  🔧 Using MCP server
&lt;/h2&gt;

&lt;p&gt;First, let's open the app and set up the MCP server. To do this, I'll enter the following line in the terminal:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx &lt;span class="nt"&gt;-y&lt;/span&gt; @maximhq/bifrost
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;After that, you will see the following interface (similar, depending on the version):&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0sp0jm5kl6xf18gawppa.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0sp0jm5kl6xf18gawppa.png" alt="interface" width="799" height="385"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Go to the "MCP Library" tab and you will see a huge list of pre-configured MCP servers that you can use in your projects.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fclqzoxedzsd65w9ba5a2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fclqzoxedzsd65w9ba5a2.png" alt="MCP Library" width="799" height="385"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;If you want to set up your own MCP server, go to &lt;strong&gt;MCP Gateway&lt;/strong&gt; and click &lt;strong&gt;New MCP Server&lt;/strong&gt;:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8sq3c1b29mi9rf6pfs42.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8sq3c1b29mi9rf6pfs42.png" alt="mcp settings" width="799" height="385"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Here you can specify the connection URL, auth type, tool allowlists, and other settings including &lt;strong&gt;Code Mode&lt;/strong&gt;, which can significantly reduce token usage when orchestrating many MCP servers.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/maximhq/bifrost" class="crayons-btn crayons-btn--primary" rel="noopener noreferrer"&gt;💎 Star Bifrost ☆&lt;/a&gt;
&lt;/p&gt;




&lt;h2&gt;
  
  
  ⚙️ Human-in-the-loop tool
&lt;/h2&gt;

&lt;p&gt;This is the most important security property for the scenario in the introduction.&lt;/p&gt;

&lt;p&gt;When an LLM returns tool calls, &lt;strong&gt;Bifrost does not automatically execute them&lt;/strong&gt;. Tool calls are suggestions only. Your application must explicitly approve and execute each one:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;1. POST /v1/chat/completions   → LLM returns tool call suggestions (NOT executed)
2. Your app reviews tool calls → Apply security rules, get user approval if needed
3. POST /v1/mcp/tool/execute   → Execute approved tool calls explicitly
4. POST /v1/chat/completions   → Continue the conversation with tool results
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Example execution call:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-X&lt;/span&gt; POST http://localhost:8080/v1/mcp/tool/execute &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"Content-Type: application/json"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s1"&gt;'{
    "id": "call_xyz789",
    "type": "function",
    "function": {
      "name": "database_query",
      "arguments": "{\"sql\": \"SELECT 1\"}"
    }
  }'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;So even if a new hire's agent &lt;em&gt;requests&lt;/em&gt; a dangerous database operation, nothing happens until your application deliberately executes it. Combined with deny-by-default virtual key filtering (below), this is Bifrost's real three-layer answer to accidental production access.&lt;/p&gt;

&lt;p&gt;You can opt into autonomous execution for specific tools via &lt;strong&gt;Agent Mode&lt;/strong&gt;, but that must be explicitly configured, it is not the default.&lt;/p&gt;




&lt;h2&gt;
  
  
  💻 MCP authentication
&lt;/h2&gt;

&lt;p&gt;Authentication is declared on the MCP client itself as a top-level &lt;code&gt;auth_type&lt;/code&gt; field, posted to &lt;code&gt;/api/mcp/client&lt;/code&gt;. There is no nested &lt;code&gt;auth&lt;/code&gt; object.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;code&gt;auth_type&lt;/code&gt;&lt;/th&gt;
&lt;th&gt;Who authenticates&lt;/th&gt;
&lt;th&gt;When to use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;none&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;td&gt;Public MCP servers, local STDIO tools&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;headers&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Admin, once&lt;/td&gt;
&lt;td&gt;Shared API keys, bearer tokens, custom headers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;oauth&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Admin, once&lt;/td&gt;
&lt;td&gt;Shared third-party service the whole team uses&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;per_user_oauth&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Each end-user, lazily&lt;/td&gt;
&lt;td&gt;Per-user services like Notion, GitHub, Sentry&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;per_user_headers&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Each end-user, lazily&lt;/td&gt;
&lt;td&gt;Per-user API keys, signed tokens&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;OAuth (&lt;code&gt;oauth&lt;/code&gt; and &lt;code&gt;per_user_oauth&lt;/code&gt;) is only valid for &lt;strong&gt;HTTP&lt;/strong&gt; and &lt;strong&gt;SSE&lt;/strong&gt; connections. Bifrost implements the &lt;strong&gt;Authorization Code&lt;/strong&gt; flow, there is no client-credentials / service-account mode.&lt;/p&gt;

&lt;h3&gt;
  
  
  1. No auth (development only)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"name"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"local-tools"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"connection_type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"stdio"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"stdio_config"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"command"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"npx"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"args"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"-y"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"@anthropic/mcp-filesystem"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"auth_type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"none"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"tools_to_execute"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"read_file"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"list_directory"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  2. Static headers (shared API keys)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-X&lt;/span&gt; POST http://localhost:8080/api/mcp/client &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"Content-Type: application/json"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s1"&gt;'{
    "name": "web_search",
    "connection_type": "http",
    "connection_string": "https://mcp.example.com/mcp",
    "auth_type": "headers",
    "headers": {
      "Authorization": "Bearer your-api-key",
      "X-Tenant-ID": "acme-corp"
    },
    "tools_to_execute": ["*"]
  }'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  3. Server-level OAuth (admin authorizes once)
&lt;/h3&gt;

&lt;p&gt;The admin authenticates once during setup. Every subsequent request to that MCP server uses the same stored token, regardless of which caller hit Bifrost.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-X&lt;/span&gt; POST http://localhost:8080/api/mcp/client &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"Content-Type: application/json"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s1"&gt;'{
    "name": "authenticated_service",
    "connection_type": "http",
    "connection_string": "https://api.example.com/mcp",
    "auth_type": "oauth",
    "oauth_config": {
      "client_id": "your-client-id",
      "client_secret": "your-client-secret",
      "authorize_url": "https://auth.example.com/oauth/authorize",
      "token_url": "https://auth.example.com/oauth/token",
      "scopes": ["mcp:read", "mcp:write"]
    },
    "tools_to_execute": ["*"]
  }'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The &lt;code&gt;oauth_config&lt;/code&gt; object accepts &lt;code&gt;client_id&lt;/code&gt;, &lt;code&gt;client_secret&lt;/code&gt;, &lt;code&gt;authorize_url&lt;/code&gt;, &lt;code&gt;token_url&lt;/code&gt;, &lt;code&gt;scopes&lt;/code&gt;, or &lt;code&gt;registration_url&lt;/code&gt; / &lt;code&gt;server_url&lt;/code&gt; for Dynamic Client Registration. After the admin completes the authorize step, finalize with &lt;code&gt;POST /api/mcp/client/{id}/complete-oauth&lt;/code&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Per-user OAuth (each user authenticates themselves)
&lt;/h3&gt;

&lt;p&gt;Use &lt;code&gt;auth_type: "per_user_oauth"&lt;/code&gt; when each end-user must connect under their own account. Bifrost stores one OAuth token per &lt;code&gt;(identity, mcp_client)&lt;/code&gt; and reuses it on later calls. Identity is required via virtual key, signed-in SSO user, or &lt;code&gt;x-bf-mcp-session-id&lt;/code&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  5. Per-user headers (legacy / custom per-user keys)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-X&lt;/span&gt; POST http://localhost:8080/api/mcp/client &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"Content-Type: application/json"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s1"&gt;'{
    "name": "acme_api",
    "connection_type": "http",
    "connection_string": "https://api.acme.example.com/mcp",
    "auth_type": "per_user_headers",
    "per_user_header_keys": ["X-API-Key", "X-Tenant-ID"],
    "tools_to_execute": ["*"]
  }'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Identity matters:&lt;/strong&gt; With &lt;code&gt;auth_type: "oauth"&lt;/code&gt; or &lt;code&gt;auth_type: "headers"&lt;/code&gt;, all callers share the same upstream credential. Bifrost does not attach a per-user identity to MCP requests. To know exactly &lt;em&gt;who&lt;/em&gt; performed an action upstream, use &lt;code&gt;per_user_oauth&lt;/code&gt; or &lt;code&gt;per_user_headers&lt;/code&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  💻 Runtime tool access control (Virtual Keys)
&lt;/h2&gt;

&lt;p&gt;RBAC does &lt;strong&gt;not&lt;/strong&gt; govern which MCP tools an agent can invoke at runtime. That is controlled by &lt;strong&gt;virtual keys&lt;/strong&gt; and three stacked levels of tool filtering:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Client config&lt;/strong&gt; — &lt;code&gt;tools_to_execute&lt;/code&gt; on each MCP client (baseline)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Request headers&lt;/strong&gt; — &lt;code&gt;x-bf-mcp-include-clients&lt;/code&gt; and &lt;code&gt;x-bf-mcp-include-tools&lt;/code&gt; per request&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Virtual key config&lt;/strong&gt; — &lt;code&gt;mcp_configs&lt;/code&gt; array (takes precedence over request headers)&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Deny-by-default
&lt;/h3&gt;

&lt;p&gt;This is built-in behavior, not a config setting: &lt;strong&gt;a virtual key with no &lt;code&gt;mcp_configs&lt;/code&gt; gets zero MCP tools&lt;/strong&gt;, and clients not listed in &lt;code&gt;mcp_configs&lt;/code&gt; are implicitly blocked.&lt;/p&gt;

&lt;h3&gt;
  
  
  Virtual key configuration
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-X&lt;/span&gt; POST http://localhost:8080/api/governance/virtual-keys &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"Content-Type: application/json"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s1"&gt;'{
    "name": "new-dev-key",
    "mcp_configs": [
      {
        "mcp_client_name": "internal_api",
        "tools_to_execute": ["search", "get_article"]
      },
      {
        "mcp_client_name": "staging_database",
        "tools_to_execute": ["query"]
      }
    ]
  }'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;code&gt;tools_to_execute&lt;/code&gt;&lt;/th&gt;
&lt;th&gt;Result&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;["*"]&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;All tools from this client&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;["a", "b"]&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Only specified tools&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;[]&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;No tools from this client&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Client not in &lt;code&gt;mcp_configs&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;All tools blocked from that client&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;This is where you enforce patterns like "backend devs can hit staging APIs but not production databases" by giving different virtual keys different &lt;code&gt;mcp_configs&lt;/code&gt;, not by RBAC permission strings.&lt;/p&gt;

&lt;h3&gt;
  
  
  Per-request narrowing
&lt;/h3&gt;

&lt;p&gt;For one-off restrictions within a virtual key's allowlist:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-X&lt;/span&gt; POST http://localhost:8080/v1/chat/completions &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"Authorization: Bearer vk_new_dev"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"x-bf-mcp-include-tools: staging_database-query"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s1"&gt;'...'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Note: when a virtual key has &lt;code&gt;mcp_configs&lt;/code&gt;, it auto-generates &lt;code&gt;x-bf-mcp-include-tools&lt;/code&gt; and overrides any manually sent header.&lt;/p&gt;

&lt;p&gt;Bifrost does not parse SQL or block operations like &lt;code&gt;DELETE&lt;/code&gt; / &lt;code&gt;DROP&lt;/code&gt; at the query level. Restrict access by allowing only specific tool names (for example, a read-only &lt;code&gt;query&lt;/code&gt; tool instead of an &lt;code&gt;execute&lt;/code&gt; tool).&lt;/p&gt;




&lt;h2&gt;
  
  
  🔎 RBAC — administrative access
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Bifrost&lt;/strong&gt; provides Role-Based Access Control for the &lt;strong&gt;administrative surface&lt;/strong&gt; who can edit MCP gateway configs, read logs, configure guardrails, manage virtual keys, and so on. RBAC is &lt;strong&gt;not&lt;/strong&gt; runtime authorization for agents invoking MCP tools.&lt;/p&gt;

&lt;p&gt;Permissions are &lt;strong&gt;Resource × Operation&lt;/strong&gt; pairs, not permission strings like &lt;code&gt;mcp:tool:invoke&lt;/code&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  System roles
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Role&lt;/th&gt;
&lt;th&gt;Permissions&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Admin&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;42&lt;/td&gt;
&lt;td&gt;Full access to all resources and operations&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Developer&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;27&lt;/td&gt;
&lt;td&gt;CRUD on technical resources, view access to logs and cluster&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Viewer&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;14&lt;/td&gt;
&lt;td&gt;Read-only access to all resources&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;You can also create custom roles (for example, an Auditor role with &lt;code&gt;AuditLogs:View&lt;/code&gt; and &lt;code&gt;Logs:View&lt;/code&gt; only).&lt;/p&gt;

&lt;h3&gt;
  
  
  Protected resources include
&lt;/h3&gt;

&lt;p&gt;&lt;code&gt;Logs&lt;/code&gt;, &lt;code&gt;VirtualKeys&lt;/code&gt;, &lt;code&gt;MCPGateway&lt;/code&gt;, &lt;code&gt;MCPToolGroups&lt;/code&gt;, &lt;code&gt;MCPLogs&lt;/code&gt;, &lt;code&gt;GuardrailsConfig&lt;/code&gt;, &lt;code&gt;AuditLogs&lt;/code&gt;, &lt;code&gt;Cluster&lt;/code&gt;, and others.&lt;/p&gt;

&lt;h3&gt;
  
  
  Operations include
&lt;/h3&gt;

&lt;p&gt;&lt;code&gt;View&lt;/code&gt;, &lt;code&gt;Create&lt;/code&gt;, &lt;code&gt;Update&lt;/code&gt;, &lt;code&gt;Delete&lt;/code&gt;, &lt;code&gt;Download&lt;/code&gt;, &lt;code&gt;Reveal&lt;/code&gt;, and inference operations.&lt;/p&gt;

&lt;p&gt;Example: a custom Auditor role might grant &lt;code&gt;AuditLogs:View&lt;/code&gt; and &lt;code&gt;AuditLogs:Download&lt;/code&gt;, but not &lt;code&gt;MCPGateway:Update&lt;/code&gt;. That controls who can &lt;em&gt;configure&lt;/em&gt; the gateway in the dashboard, not which tools an agent executes at runtime.&lt;/p&gt;

&lt;p&gt;Roles and permissions are managed via &lt;strong&gt;Governance → Roles &amp;amp; Permissions&lt;/strong&gt; in the dashboard or the &lt;code&gt;/api/roles&lt;/code&gt; endpoints:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-X&lt;/span&gt; GET http://localhost:8080/api/roles/&lt;span class="o"&gt;{&lt;/span&gt;role_id&lt;span class="o"&gt;}&lt;/span&gt;/permissions &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"Authorization: Bearer &amp;lt;admin_token&amp;gt;"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  🖥️ User Provisioning and role mapping
&lt;/h2&gt;

&lt;p&gt;There is no &lt;code&gt;role_sync&lt;/code&gt; config block. Role assignment comes from &lt;strong&gt;User Provisioning over OIDC&lt;/strong&gt;, supported for Okta, Microsoft Entra and others.&lt;/p&gt;

&lt;p&gt;When SSO is configured:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Users sign in with corporate credentials via OAuth 2.0 / OIDC (Authorization Code + PKCE)&lt;/li&gt;
&lt;li&gt;Roles are mapped from &lt;strong&gt;IdP groups&lt;/strong&gt;, &lt;strong&gt;app roles&lt;/strong&gt;, or &lt;strong&gt;custom claims&lt;/strong&gt; to Bifrost roles (Admin, Developer, Viewer, or custom roles)&lt;/li&gt;
&lt;li&gt;Role and team assignments are &lt;strong&gt;synchronized on each session&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Background reconciliation runs every &lt;strong&gt;24 hours&lt;/strong&gt;; OIDC session refresh checks run every &lt;strong&gt;15 minutes&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Inactive or deprovisioned users are decommissioned locally (including via inbound SCIM 2.0)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Configuration lives under &lt;code&gt;scim_config&lt;/code&gt; in &lt;code&gt;config.json&lt;/code&gt;. See the &lt;a href="https://docs.getbifrost.ai/enterprise/user-provisioning" rel="noopener noreferrer"&gt;User Provisioning docs&lt;/a&gt; for provider-specific setup guides.&lt;/p&gt;




&lt;h2&gt;
  
  
  📋 Audit logs
&lt;/h2&gt;

&lt;p&gt;Audit logs in Bifrost record &lt;strong&gt;administrative activity&lt;/strong&gt;  who changed what, when, and which resource was affected. They do not use a &lt;code&gt;log_level&lt;/code&gt; / &lt;code&gt;capture&lt;/code&gt; / &lt;code&gt;export_to&lt;/code&gt; block.&lt;/p&gt;

&lt;p&gt;Real configuration shape:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"audit_logs"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"disabled"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"hmac_key"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"env.AUDIT_HMAC_KEY"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"retention_days"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;365&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"object_storage"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"s3"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"bucket"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"acme-audit-archive"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"prefix"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"acme-prod"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"compress"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"region"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"us-east-1"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"access_key_id"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"env.AUDIT_S3_KEY"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"secret_access_key"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"env.AUDIT_S3_SECRET"&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Key features:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Signed events&lt;/strong&gt; — configure an HMAC key for verification&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Dashboard review&lt;/strong&gt; — filter by search text, action, outcome, and date range&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Export&lt;/strong&gt; — JSON, JSON Lines, or Syslog (requires &lt;code&gt;AuditLogs:Download&lt;/code&gt; permission)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Retention&lt;/strong&gt; — &lt;code&gt;retention_days&lt;/code&gt; controls database retention&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Object storage archival&lt;/strong&gt; — optional mirror to S3/GCS for long-term compliance retention&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;View audit entries at &lt;strong&gt;Governance → Audit Logs&lt;/strong&gt; in the dashboard.&lt;/p&gt;




&lt;h2&gt;
  
  
  ✅ Implementation best practices
&lt;/h2&gt;

&lt;h3&gt;
  
  
  1. Rely on deny-by-default
&lt;/h3&gt;

&lt;p&gt;Do not look for a &lt;code&gt;"policy": "default_deny"&lt;/code&gt; setting. It does not exist. Instead:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Create virtual keys with explicit &lt;code&gt;mcp_configs&lt;/code&gt; for each team or environment&lt;/li&gt;
&lt;li&gt;Set client-level &lt;code&gt;tools_to_execute&lt;/code&gt; to the minimum needed&lt;/li&gt;
&lt;li&gt;Leave production database tools off keys used for local development&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  2. Keep human-in-the-loop as the default
&lt;/h3&gt;

&lt;p&gt;Only enable &lt;a href="https://docs.getbifrost.ai/mcp/agent-mode" rel="noopener noreferrer"&gt;Agent Mode&lt;/a&gt; auto-execution for tools you have explicitly reviewed. The default flow — chat → review → &lt;code&gt;/v1/mcp/tool/execute&lt;/code&gt; — is your strongest safety net.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Separate runtime access from admin access
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Runtime&lt;/strong&gt; (what agents can do): virtual keys + &lt;code&gt;mcp_configs&lt;/code&gt; + request headers&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Administration&lt;/strong&gt; (who can change configs): RBAC + SSO&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  4. Use environment-scoped virtual keys
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"name"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"production-readonly"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"mcp_configs"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"mcp_client_name"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"production_database"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"tools_to_execute"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"query"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"name"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"staging-full"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"mcp_configs"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"mcp_client_name"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"staging_database"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"tools_to_execute"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"*"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  5. Configure audit logging early
&lt;/h3&gt;

&lt;p&gt;Enable HMAC signing, set &lt;code&gt;retention_days&lt;/code&gt; comfortably above your archival window, and optionally mirror to object storage for compliance.&lt;/p&gt;

&lt;h3&gt;
  
  
  6. Perform regular access reviews
&lt;/h3&gt;

&lt;p&gt;Schedule quarterly reviews to answer:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Which virtual keys grant access to production MCP clients?&lt;/li&gt;
&lt;li&gt;Who has Admin or Developer RBAC roles in Enterprise?&lt;/li&gt;
&lt;li&gt;Are there overprivileged virtual keys or dormant SSO accounts?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Use the dashboard and &lt;code&gt;/api/roles&lt;/code&gt; endpoints, there is no &lt;code&gt;bifrost audit&lt;/code&gt; CLI command. The &lt;code&gt;@maximhq/bifrost-cli&lt;/code&gt; package is an interactive launcher for coding agents (Claude Code, Codex CLI, Gemini CLI, Opencode), not an audit tool.&lt;/p&gt;




&lt;h2&gt;
  
  
  🖋️ Conclusion
&lt;/h2&gt;

&lt;p&gt;With Bifrost, you can configure your company's MCP server much more securely. This ready-made solution will save you not only money but also time, which can be spent on product development.&lt;/p&gt;




&lt;h2&gt;
  
  
  🔗 Resources:
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Bifrost GitHub&lt;/strong&gt;: &lt;a href="https://github.com/maximhq/bifrost" rel="noopener noreferrer"&gt;https://github.com/maximhq/bifrost&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Bifrost Docs&lt;/strong&gt;: &lt;a href="https://docs.getbifrost.ai" rel="noopener noreferrer"&gt;https://docs.getbifrost.ai&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Bifrost CLI&lt;/strong&gt;: &lt;code&gt;npx -y @maximhq/bifrost-cli&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Thanks for reading this article! ❤️&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;I'd love to hear your thoughts on this mode in the comments!&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>webdev</category>
      <category>programming</category>
      <category>opensource</category>
    </item>
  </channel>
</rss>
