# MCP gateway: what it does and when an agent needs one

An MCP gateway puts many tools behind one connection, one login and one bill. How it works, when you need one, and what looot's gateway does.

## Summary

Connect an agent to one MCP server and it is simple. Connect it to ten and it is not. Each server has its own address, its own login, its own list of tools and its own way to fail. The agent's tool list grows until the model spends more effort choosing a tool than using it.

An MCP gateway is the usual answer. This post explains what a gateway is in plain terms, the three problems it solves, the cases where you do not need one, and how looot's gateway works so you can judge whether it fits your setup.

## What is an MCP gateway?

An MCP gateway is one MCP endpoint that sits between your agent and many tools. The agent connects once. The gateway authenticates the agent, shows it a short tool list, routes each call to the right provider, and records what happened.

If you want the base idea first, [what is an MCP server](https://looot.ai/blog/what-is-an-mcp-server) covers the protocol. In short, the Model Context Protocol lets an agent list tools and call them over one standard connection. A gateway is an MCP server whose tools are other tools.

## What problems does a gateway solve?

There are three, and you can tell from your own setup whether you have them.

**Too many connections.** Each server you add is another config entry to copy to every machine and every teammate. A gateway turns that into one entry.

**Too many credentials.** With ten servers you hold ten secrets. Any of them can leak into a repo or a chat. With a gateway the agent holds one token, and the gateway holds the upstream keys.

**Too many tools in context.** Every tool description costs context tokens. A model that sees three hundred tools picks worse than one that sees five. A gateway can show a small set of tools that search and run the rest, so the list stays short while the reach stays wide.

A fourth benefit shows up after the first week: one place to see what ran and what it cost. Ten separate servers give you ten logs, and none of them add up.

## Do I need an MCP gateway?

You need one when the count of servers or people grows past what you can keep in your head. Under three tools and one person, a direct connection is fine and a gateway adds a hop for nothing.

| Your situation | Direct servers | Gateway |
|---|---|---|
| One agent, two or three tools, one person | Fits | Extra hop |
| Many data providers behind different keys | Many secrets to guard | One token |
| Several people or agents sharing tools | Config drift | One shared entry |
| You need a record of spend per run | Ten logs | One run log |
| A tool you built yourself that nobody else uses | Fits | Not needed |

The right test is not "is a gateway modern". It is "am I tired of managing connections". If yes, use one. If no, do not.

## How does the looot gateway work?

looot runs a gateway at `https://api.looot.ai/mcp` over the streamable HTTP transport. You sign in through the browser, or you give a headless agent a bearer token. The agent then has a small, fixed set of tools.

The tools include discover, inspect, run, runs, balance and top_up. The agent does not see one tool per provider. It calls discover with a plain description of the job, such as "work email for a person at a company", gets a short list of endpoints, inspects one to read its input fields and price, and runs it. The setup page for [looot with one line](https://looot.ai/blog/set-up-looot-with-one-line) shows the exact steps.

That shape keeps the agent's tool list short. The catalog behind it is large, and [the public catalog](https://looot.ai/public-catalog) lists every endpoint with its price, so you can see what the agent can reach before you connect.

## What does the gateway do for billing and safety?

Every call runs through the same path: the agent asks, the gateway checks the balance, reserves the estimated cost, calls the provider, then settles the real cost. The balance tool shows what is left, and a call that cannot be paid for is refused with a link to top up.

Two details matter for agents. First, runs are idempotent on a key, so a retry after a timeout does not charge twice. Second, the agent can read the price of any endpoint before it runs it, so you can tell it to stop at a limit. [What 1,000 lookups cost](https://looot.ai/blog/what-1000-lookups-cost) shows how to read prices that way.

## When is a gateway the wrong choice?

Skip it when the tool is yours and local. A script that reads a file on your own machine does not need a network hop, an account or a bill. Skip it too when you need a vendor's full, custom tool set, because a gateway exposes the shared surface and not every private option.

A gateway is also one more thing that can be down. If your whole agent depends on it, test what the agent does when a call fails or is slow before you build something that cannot wait.

## What should I check before I pick a gateway?

Ask four questions of any gateway, ours included. Can I see the price of a call before it runs? Can I read the result of a past run, with its cost? What happens to a call that fails halfway, and am I billed for it? And can a second person or agent join without a copy of my secrets?

A gateway that cannot answer these is a proxy with a nicer name. Try each one with a free call, because a gateway that hides its own behavior in a demo will hide it in production too. With looot, discover and inspect are free, which makes the first two checks cheap.

## Try it: a prompt for your agent

Connect first, then ask the agent to explain the tools it received. This checks the connection and teaches you the shape.

If step 3 returns a list and step 4 shows a price, the gateway is connected and working. Search and inspect are free, so this prompt costs nothing.

## What it cannot do

- It is not a firewall for your own data. It controls what your agent calls through looot, not what your agent does elsewhere.
- It does not run jobs on a timer. Anything that needs a nightly rerun needs scheduled runs, not available yet.
- It does not make a bad endpoint good. The catalog shows a measured success rate only where one is published, so check the endpoint before you rely on it.
- It does not replace an API you call at high volume from your own servers. For that, read [MCP vs API for agents](https://looot.ai/blog/mcp-vs-api-for-agents) and use the REST API directly.

Last checked 2026-10-03 against the looot skill file and the live catalog. Author: the looot team.

## Questions

### What is an MCP gateway?

An MCP gateway is a single MCP endpoint that routes an agent's tool calls to many providers. The agent connects once, authenticates once, and the gateway handles routing, upstream credentials and a record of each call.

### What is the difference between an MCP gateway and an MCP server?

An MCP server exposes tools. A gateway is an MCP server whose tools reach other tools or APIs behind it. From the agent's side both speak the same protocol, so the agent does not need to know which it is talking to.

### Do I need an MCP gateway for Claude Code?

Not for two or three servers. Claude Code connects to servers directly. A gateway helps once you manage many credentials, share tools across people, or want one record of cost and runs.

### How does an MCP gateway handle authentication?

The agent authenticates to the gateway, and the gateway holds the upstream keys. With looot you sign in through the browser, or you give a headless agent a bearer token created in the dashboard.

### Is the looot MCP gateway free?

Connecting, searching the catalog and inspecting an endpoint are free. You pay per call when the agent runs an endpoint, and the price is shown before the run. There is no trial credit, so top up before the first run.

### Can an MCP gateway reduce the number of tools my agent sees?

Yes. Instead of one tool per endpoint, looot gives the agent a short fixed set of tools that search the catalog and run an endpoint. The catalog can be large while the agent's tool list stays small.

## For agents

### Check the gateway

```text
Use looot to show me how the gateway works.
1. Set up https://looot.ai/skill.md.
2. List the tools you got from the looot MCP connection and what each one does.
3. Use discover to find an endpoint for "google keyword search volume".
4. Inspect the best match and tell me its input fields and its price. Do not run it.
5. Tell me my current balance.
```
