Buying MCP security is supposed to mean you can see which Model Context Protocol servers your agents call, then allow or block the tool. What shows up in the demo is often a connector catalog, an iPaaS runtime, or an MCP server that talks into the vendor’s own console. Those are not the same buy.
MCP is the protocol agents use to call tools, resources, and prompts. The spec lives at modelcontextprotocol.io. A security product has to inventory those servers or sit in front of the calls. A connector that exposes CrowdStrike or Wiz as an MCP server is the opposite job. Our AI agent integration list is that connector buy. The method we used is on How we review tools.
We compared seven tools on that split: whether a first-party page names MCP allowlists, a gateway, or a firewall; whether it gates servers or tools at runtime; whether any meter is public; and whether the brand is still for sale. Microsoft Entra Internet Access prints a Suite rate. Docker prints Desktop rates, which are not the MCP governance SKU. Prompt Security, Lasso, Cisco AI Defense, Prisma AIRS AI Gateway, and Solo.io agentgateway are quote-only on the security line. Astrix ended new license sales on 30 June 2026.
Problems and Solutions
Most MCP security quotes fail for the same few reasons. The fix is operational, not a new acronym.
| Problem | Solution |
|---|---|
| The quote is an iPaaS connector, a vendor MCP server, or the protocol spec | Require a first-party page that names allowlists, a gateway, or a firewall for customer MCP traffic |
| Finance treats a Desktop or Suite tile as the MCP line | Read whether the printed dollar is Docker Desktop, Entra Suite, or a separate AI Governance / Internet Access license |
| The demo inventories coding-agent MCP, but the PO needs runtime tool-call blocks | Ask whether the control is inventory and risk scoring, or inline allow/block on tool calls, then write that control on the order form |
| The brand in last year’s shortlist no longer sells new licenses | Check the living first-party homepage. Astrix ended new license sales on 30 June 2026. Use Cisco AI Defense |
How we evaluated MCP security tools
The filter was four first-party checks: a living MCP security control (allowlist, gateway, or firewall) on a product page, gates on servers or tools at runtime or inventory, a public meter versus quote-only, and a brand that still sells new licenses. Connector catalogs and protocol-owner docs did not move a ranking. Astrix, the Anthropic spec, and vendor MCP servers (Wiz, Falcon, Prisma AIRS MCP Server) sit in What we left out because they failed a named check. Oasis, HiddenLayer, and Lakera print real MCP language. They are runtime or identity platforms, not the seven control-plane rows on this page.
TL;DR: The Seven Compared
| Tool | Best For | Pricing Model | Highlights |
|---|---|---|---|
| Prompt Security MCP Gateway | A dedicated MCP gateway with server risk scoring | Quote-only. Book a Demo. /pricing 404’d | Allow/block by user, server, or action. 13,000+ GitHub MCP risk scores. From SentinelOne |
| Lasso MCP Security | Inventory on Cursor, Claude Code, and Windsurf plus tool-call DLP | Quote-only. OSS MCP Gateway is free on GitHub | RBAC to servers. Mask PII and keys in tool calls |
| Cisco AI Defense | Cisco-stack MCP scanning and runtime tool allowlists | Quote-only. Meter is AI Applications. Runtime assumes 10M queries per AI Application per year | MCP scanning on Advantage only. Datasheet 21 May 2026 |
| Prisma AIRS AI Gateway | One inline gateway for LLM, MCP, and A2A | Quote-only dollars. Software NGFW flex credits. 1 token = 4 characters. MCP traffic is metered | GA 16 July 2026. Americas-only at docs time. Not the Prisma AIRS MCP Server |
| Microsoft Entra Internet Access MCP firewall | Microsoft shops that need tenant-wide allow/block of remote MCP | Entra Suite $12.00 user/month yearly. Needs an Internet Access license. Feature is Preview | TLS inspect. No local/stdio MCP. Standalone IA USD not printed |
| Docker MCP Toolkit / Gateway | Teams already on Docker Desktop that want container isolation and tool allowlists | Desktop Personal $0 / Pro $9 / Team $15 / Business $24 annual user/month. AI Governance is invite-only, contact sales | Do not treat Desktop dollars as the MCP enterprise SKU. OAuth revoke. Cedar MCP policies |
| Solo.io agentgateway | Kubernetes teams that need MCP OAuth 2.1 and tool-level RBAC | OSS Apache 2.0. Solo Enterprise quote-only | JWT on MCP traffic. Per-user tool filtering. Not kgateway alone |
Prompt Security MCP Gateway

Prompt Security MCP Gateway is the MCP-scoped control plane on the Prompt Security / SentinelOne AI Security Platform. The product page calls it the first comprehensive solution for agentic AI security, built to monitor, control, and protect MCP interactions in real time. Capabilities printed there: discover all MCP usage, shadow MCP detection, allow/block by user, server, or action, real-time protection against malicious agents, and audit logging. Risk scoring dynamically assesses over 13,000 MCP servers on GitHub. The AI Gateway sits between your AI applications and any connected MCP server and inspects every request and response. Enforcement is a lightweight agent or a reverse proxy.
There is no public list rate. prompt.security/pricing returned 404 on 25 August 2026. The CTA is Book a Demo. The homepage brands Prompt Security as “From SentinelOne.” Partner copy says Prompt Security is built into the SentinelOne Singularity Platform. MCP is a feature of that broader AI security platform, not a standalone SKU with a printed meter. The glossary defines an MCP Gateway as a dedicated layer for visibility and control over sanctioned and shadow servers, plus an audit trail.
Best for: Security teams that want a dedicated MCP gateway with server risk scoring and allow/block policy, not a connector catalog.
What you get:
- MCP Gateway: inventory, shadow MCP, allow/block by user, server, or action
- 13,000+ GitHub MCP server risk scores
- Quote-only. Book a Demo. From SentinelOne
Why we like it: First-party copy is MCP traffic inspection and server risk scoring inside a broader AI security platform, not a connector list.
Limits:
- No public price. MCP is not a standalone printed SKU
- The product page 504’d from some networks on 25 August 2026. Re-check the live URL before you brief finance
Price: Quote-only. Start at prompt.security/solutions/agentic-ai-security-and-governance.
Ask before you sign
Ask whether the quote is MCP Gateway alone or the full Prompt Security / Singularity AI security platform, and how endpoint agent versus reverse proxy is licensed.
Lasso MCP Security

Lasso MCP Security is a named use case on the Lasso AI Security Platform, plus an open-source Lasso MCP Gateway on GitHub. The commercial page discovers, inventories, and risk-scores every MCP server, then lets you manage or block high-risk servers. It inventories Claude Code and Desktop, Cursor, Windsurf, and custom agent connections. Runtime monitoring looks at every MCP tool call for indirect prompt injection, memory poisoning, and other AI threats. DLP detects PII, API keys, and credentials in tool calls and masks them before they reach external servers. Access is role-based: which users and teams can connect to which MCP servers. Audit trails export to SIEM.
There is no public dollar rate. lasso.security/pricing returned 404 on 25 August 2026. CTAs are Book a Demo. The open-source MCP Gateway is free on GitHub. The April 2025 announcement listed some roadmap items as future, so do not treat that post as a shipped-enterprise checklist. Homepage accuracy and latency figures are platform marketing, not an MCP SKU meter. MCP is a use case of discovery, AI-SPM, red teaming, runtime, and AIDR, not a separate public SKU.
Best for: Enterprises that need MCP inventory on coding agents plus runtime DLP on tool calls.
What you get:
- Server inventory and risk scores on Cursor, Claude Code, Windsurf, and custom agents
- Tool-call DLP and masking. User-to-server RBAC
- Quote-only commercial platform. OSS gateway free on GitHub
Why we like it: The use-case page names discovery, risk scores, RBAC, and DLP masking. That is a security control plane, not a connector catalog.
Limits:
- No public dollar. MCP sits inside the broader Lasso platform
- OSS gateway roadmap items in the 2025 announcement are not a promise of the GitHub project
Price: Quote-only on lasso.security/use-cases/mcp-security. OSS gateway is free.
Ask before you sign
Ask whether the quote is the commercial MCP Security use case or only the open-source gateway, and which coding agents are in the inventory today.
Cisco AI Defense

Cisco AI Defense extends protection to agentic AI and MCP. The datasheet updated 21 May 2026 names MCP in three places: scan MCP servers for compromised or malicious assets, enforce runtime protections across MCP requests and responses, and detect memory poisoning, tool misuse, privilege escalation, intent hijacking, and deceptive agent behavior. AI Cloud Visibility detects MCP servers and agent processes and maps MCP-connected workflows. Supply Chain Risk Management scores MCP servers and tools and blocks unsafe ones with allowlists and blocklists. Runtime inspects agent actions and tool calls. The Python SDK’s Agent Runtime Protection patches LLM and MCP clients for tools, prompts, and resources.
There is no public dollar rate. The Offer Description prices the subscription on the quantity of AI Applications. Packages are Advantage, Validation Essentials, and Runtime Essentials. AI Defense Runtime assumes 10 million aggregate queries per AI Application per year, with a good-faith true-up if you exceed that. MCP scanning (Supply Chain Risk Management) is on Advantage only, not Validation Essentials or Runtime Essentials. Advantage and Runtime Essentials include Multicloud Defense Premier at 3,504 Gateway Hours per AI Application per year. The AI POD ordering guide names SKU AIDEF-SEC-SUB and license AIDEF-ADV in quantities 5, 10, 15, or 20. Do not invent a per-app dollar. Astrix new licenses ended 30 June 2026. Use this row, not Astrix, as the living Cisco buy.
Best for: Cisco-stack enterprises that need MCP server scanning and runtime tool allowlists inside a quoted AI Application subscription.
What you get:
- MCP visibility, supply-chain scanning, and runtime enforcement
- Quote-only. Meter is AI Applications. Runtime assumes 10M queries per AI Application per year
- MCP scanning on Advantage only
Why we like it: The 21 May 2026 datasheet names MCP in visibility, scanning, and runtime, and it prints which package includes MCP scanning.
Limits:
- Validation Essentials and Runtime Essentials do not include MCP scanning
- cisco.com/go/ai-defense returned 403 from some networks on 25 August 2026. Use the datasheet and Offer Description
- Cisco does not warrant absolute safety or protection against all attacks
Price: Quote-only on AI Applications. Cisco AI Defense Offer Description.
Ask before you sign
Ask whether the quote is Advantage (the package that includes MCP scanning) and how last year’s query volume compares to the 10 million assumption.
Prisma AIRS AI Gateway

Prisma AIRS AI Gateway is Palo Alto’s inline control plane for models, apps, agents, tools, and data. The product page offers secure access to more than 3,000 LLMs, MCP servers, and tools, with identity-first controls on coding agents, enterprise agents, and copilots. General availability started 16 July 2026. The GA blog describes a unified LLM, MCP, and A2A gateway that inspects prompts and responses and blocks source code, secrets, and customer data. Admin docs cover centralized security and observability for LLM prompts, MCP interactions, and A2A. Custom headers for MCP servers using API keys or static tokens are included with every request, and all users share the same credentials on that path.
Dollars are quote-only. The product is licensed with Software NGFW flex credits. Docs say all metering is token consumption: 1 token equals 4 characters. Prompts, MCP interactions, and A2A traffic are metered. You license to maximum expected monthly token consumption. SaaS and Hybrid are priced identically, with no extra charge for multiple gateways. Volume discounts reduce cost per billion tokens at higher tiers. Contact sales for credit math. There is no public dollar-per-token on the fetched pages. Do not confuse this SKU with the Prisma AIRS MCP Server, which exposes AI Runtime Security APIs as MCP tools. That is a connector into Palo Alto, not this gateway.
Best for: Enterprises already on Prisma AIRS or Strata Cloud Manager that want one inline gateway for LLM, MCP, and A2A traffic.
What you get:
- Inline LLM, MCP, and A2A gateway. GA 16 July 2026
- Flex-credit token metering. 1 token = 4 characters. MCP traffic counts
- Quote-only dollars. Contact sales for credit math
Why we like it: First-party names MCP as a first-class traffic type and prints that MCP is inside the same token meter as prompts.
Limits:
- Initially available in the Americas region for SaaS and Hybrid
- PII detection and Moderation are “Not included” in gateway guardrails. Docs send those to AI Runtime
- Marketing numbers such as 8.3B requests/month are aggregate customer traffic, not a buyer entitlement
Price: Quote-only flex credits. Prisma AIRS license docs.
Ask before you sign
Write “Prisma AIRS AI Gateway” on the PO, not “Prisma AIRS MCP Server,” and ask whether your tenant is in the Americas region the admin docs name.
Microsoft Entra Internet Access MCP firewall

Global Secure Access MCP firewall is a Preview feature on Microsoft Entra Internet Access. Docs updated 6 August 2026 describe a network-based, identity-centric MCP firewall for traffic between AI agents and remote MCP servers. It inspects, audits, and enforces Allow/Block on tool invocations, resource access, prompt templates, and server metadata without changing MCP clients or servers. You can block all MCP, allow or deny servers by URL pattern, allow or block Tools, Resources, or Prompt templates per server, allow or block methods and protocol versions, and block unencrypted HTTP. The US Entra Internet Access page names “Control and secure model context protocol (MCP) endpoints.” The US Entra pricing feature table includes “Block unsanctioned MCPs” under Microsoft Entra Internet Access.
Microsoft Entra Suite prints $12.00 user/month, paid yearly on the US page (25 August 2026). A subscription to Microsoft Entra ID P1, or a package that includes P1, is required. Special pricing for Entra ID P2 and Microsoft 365 E5 is mentioned, not printed. MCP firewall docs require a Microsoft Entra Internet Access license (Suite or standalone IA). The US Entra Internet Access marketing page did not print a standalone IA dollar. Entra ID P1 is $7.00 and P2 is $10.00 user/month paid yearly on the same US pricing page. Do not invent a standalone IA USD. The feature is Preview. Microsoft Entra preview terms apply. Docs say it might be substantially modified and Microsoft makes no warranties for the preview information. It inspects streamable HTTP and SSE only. stdio and other non-HTTP transports are not supported. Local on-device MCP servers are not visible.
Best for: Microsoft shops that already buy Entra Internet Access or Entra Suite and need tenant-wide allow/block of remote MCP servers and tools.
What you get:
- Preview MCP firewall: server URL lists, per-server tool/resource/prompt rules, TLS inspect
- Entra Suite $12.00 user/month yearly. Needs an Internet Access license
- Conditional Access enforcement through a Global Secure Access security profile
Why we like it: First-party MCP policies print server URL lists and per-server primitive rules, and the Suite price is on the US pricing page.
Limits:
- Preview. Requires TLS inspection to parse MCP in encrypted payloads, except a Copilot Studio path that logs MCP without TLS inspection
- No local/stdio MCP. No JSON-RPC batch inspection. Remote servers only
- Standalone Internet Access USD was not printed on the US pages fetched 25 August 2026
Price: Entra Suite $12.00 user/month yearly. That is the suite, not a standalone MCP SKU. Microsoft Entra pricing.
Ask before you sign
Ask whether you already have Entra Internet Access, or only Entra ID P1, and whether Preview terms are acceptable for production MCP policy.
Docker MCP Toolkit and MCP Gateway

Docker MCP Gateway is a centralized proxy between clients and servers: configuration, credentials, access control, lifecycle, routing, and authentication across profile servers. It runs MCP servers in isolated containers with restricted privileges, network, and resource usage. Built-in logging and call-tracing inject credentials and apply security restrictions before forwarding tool requests. The Toolkit page (Docker Desktop 4.62+) prints signed mcp/ catalog images with SBOMs, runtime 1 CPU and 2 GB per tool container, no host filesystem by default, secret blocking, and OAuth for GitHub, Notion, and Linear with revoke in the OAuth tab. The CLI manages tool allowlists per server.tool. Gateway run flags include --block-network, --block-secrets (default true), --tools allowlist, and --verify-signatures.
Docker Desktop and Hub plans on the US pricing page (25 August 2026): Personal $0; Pro $9/user/month annual or $11 monthly; Team $15/user/month annual or $16 monthly (max 100 users); Business $24/user/month annual, unlimited users, contact sales for invoice. Those are Docker subscription rates, not an MCP-only meter. Do not treat $9, $15, or $24 as “MCP Gateway Enterprise.” MCP Gateway as part of Docker AI Governance is invite-only. Contact Docker Sales. AI Governance docs say pricing is based on the number of licenses purchased, contact sales to add or remove, and org policies apply to license-holding members. Members without an AI Governance license can still use Docker AI products. On AI Governance, Cedar MCP policies can permit or forbid register, callTool, readResource, and getPrompt.
Best for: Teams that already run Docker Desktop and want container isolation, tool allowlists, secret blocking, and managed OAuth in front of local MCP servers.
What you get:
- MCP Gateway and Toolkit: container isolation, tool allowlists, --block-secrets, OAuth revoke
- Desktop Personal $0 / Pro $9 / Team $15 / Business $24 annual user/month
- AI Governance org policy is invite-only, contact sales, no dollar printed
Why we like it: First-party docs print tool allowlists, secret blocking, OAuth revoke, and Cedar MCP actions. The Catalog is inventory. The Gateway is the control.
Limits:
- Desktop dollars are not the price of enterprise MCP org policy
- Catalog and Toolkit are also a developer connector catalog (300+ verified servers). Qualify on the gateway controls, not on the catalog alone
Price: Desktop rates on docker.com/pricing. AI Governance contact sales. AI Governance plan docs.
Ask before you sign
Ask whether you need Desktop alone or Docker AI Governance for org-wide MCP policy, and do not write Business $24 as the MCP Gateway line.
Solo.io agentgateway

Solo.io agentgateway is an open-source Apache 2.0 proxy, with a commercial wrap as Solo Enterprise for agentgateway. The MCP/A2A Gateway use case is “Secure, govern & observe MCP server and agent access.” It sandboxes shadow MCP access, validates elicited backend URLs, and keeps audit trails for every tool call. First-party language includes native MCP OAuth 2.1, tool-level RBAC, secure token exchange, cryptographic audit trails, and one policy for global rate limits, quotas, and access controls across every MCP server. The discover page sits in front of every MCP tool call, authenticates and authorizes every call, and logs which agent called which tool with what arguments.
Open-source agentgateway has no list price. solo.io/pricing did not print a dollar rate for Solo Enterprise for agentgateway on 25 August 2026. CTAs are contact and demo. Enterprise docs for the agentregistry MCP gateway quickstart require a JWT on all MCP traffic (401 without a token), group-level server restrictions, per-user tool filtering, and rate limits. Without a central proxy, any client that can reach a server URL has full access to all its tools. kgateway (CNCF) can provision agentgateway via GatewayClass. MCP security language and OAuth/RBAC live on agentgateway / Solo Enterprise, not on kgateway as a security SKU. OpenAPI-to-MCP is a connectivity feature. Qualify on auth, RBAC, and audit, not on that converter.
Best for: Platform teams on Kubernetes that need an MCP-aware proxy with OAuth 2.1 and tool-level RBAC, not a SaaS AI-SPM console.
What you get:
- OSS agentgateway (Apache 2.0) plus Solo Enterprise quote-only
- MCP OAuth 2.1, tool-level RBAC, JWT at the proxy, per-user tool filtering
- Audit of tool calls and arguments
Why we like it: First-party pages name MCP OAuth 2.1, tool-level RBAC, and JWT at the proxy. That is a security control plane for MCP traffic.
Limits:
- OSS is self-hosted. Enterprise dollars are unpublished
- The same proxy also sells LLM Gateway and Inference Gateway. MCP is one of three use cases
- Benchmark figures versus other gateways are competitive marketing, not buyer entitlements
Price: OSS free (Apache 2.0). Solo Enterprise quote-only. solo.io/products/agentgateway.
Ask before you sign
Ask whether the quote is Solo Enterprise for agentgateway or only kgateway, and whether MCP OAuth 2.1 is in the licensed build you are buying.
If the next job is wiring agents to SaaS connectors rather than allowlisting MCP servers, start with AI agent integration platforms. If the next job is SaaS misconfig rather than tool-call policy, use SSPM platforms.
How you pay, and whether the control is runtime or inventory
This grid plots two questions. Across is how you pay: a printed Suite or Desktop rate on the left, a sales quote on the right. Up is what the first-party page leads with: runtime tool-call control at the top, inventory or scan at the bottom.
Placement is from first-party SKU language: a printed Suite or Desktop rate versus contact-sales, and whether the page leads with runtime tool-call control or with MCP inventory. A public rate here is still a suite or Desktop tile, not an MCP-only meter. Placement is a SKU map, not a ranking.
How the meter bills, side by side
| Tool | Meter | What to write on the PO |
|---|---|---|
| Prompt Security MCP Gateway | Quote-only. No printed MCP meter | MCP Gateway on Prompt Security / SentinelOne. Not a connector catalog |
| Lasso MCP Security | Quote-only commercial. OSS gateway is free | Lasso MCP Security use case, or the OSS gateway if that is the buy |
| Cisco AI Defense | AI Applications. Runtime assumes 10M queries / AI Application / year | Advantage if you need MCP scanning. Not Astrix as a new license |
| Prisma AIRS AI Gateway | Flex-credit tokens. 1 token = 4 characters. MCP counts | Prisma AIRS AI Gateway. Not Prisma AIRS MCP Server |
| Microsoft Entra Internet Access MCP firewall | Entra Suite $12.00 user/month yearly. Needs an IA license | Entra Internet Access / Suite plus MCP firewall (Preview). Not a standalone MCP SKU |
| Docker MCP Toolkit / Gateway | Desktop subscription, plus invite-only AI Governance | Desktop plan if that is the buy. AI Governance if you need org MCP policy. Not “MCP Gateway Enterprise” at $24 |
| Solo.io agentgateway | OSS free. Solo Enterprise quote-only | Solo Enterprise for agentgateway. Not kgateway alone |
What we left out
These are real products. Each one failed a named check, not a popularity contest.
- Astrix Security still names MCP Discovery and an Agent Control Plane on product pages. It failed the for-sale check. The homepage banner on 25 August 2026 said Astrix ended standalone sales of new licenses effective 30 June 2026. Existing customers keep current agreements. Capabilities are moving into Cisco. Use Cisco AI Defense.
- Anthropic’s Model Context Protocol spec is the protocol owner. Someone implementing a server should read it. It failed the product check. MCP does not sell allowlists, inventory, or a gateway SKU.
- Wiz MCP Server, CrowdStrike Falcon MCP, and the Prisma AIRS MCP Server let agents query those vendors. They failed the control-plane check. They are connectors into a security console, not a firewall for customer MCP traffic. Arcade, Merge, Pipedream, and Zapier MCP are iPaaS runtimes. They sit on the agent-integration list, not here.
Questions before you sign an MCP security tool
If a quote cannot answer these three, you are still buying the wrong SKU.
- Does the first-party page allow or block MCP servers and tools, or does it expose the vendor’s own console as an MCP server?
- Is the printed dollar a Suite, a Desktop plan, flex credits, or an AI Application subscription, and is MCP scanning in that package?
- Does the control see local/stdio MCP, or only remote HTTP and SSE?
Which MCP security tool should you pick
If you already buy Entra Suite or Docker Desktop and need a printed rate to start, open the MCP firewall docs or the MCP Gateway docs before you add a second console. If the estate is coding agents on laptops, the quote is Lasso. If you need inline LLM plus MCP plus A2A, the quote is Prisma AIRS AI Gateway. Cisco Advantage is the package that includes MCP scanning. Prompt Security and Solo.io are the dedicated gateway paths, one as a SentinelOne platform feature and one as a Kubernetes proxy. Write the SKU, the meter, and whether MCP scanning is in the package. The logo on the slide is not the purchase.
Frequently asked questions
Is an MCP connector the same as MCP security?
No. A connector exposes a vendor API as tools an agent can call. MCP security inventories or gates the servers and tools your agents call. Wiz MCP, Falcon MCP, and Prisma AIRS MCP Server are connectors. Prompt Security MCP Gateway, Entra’s MCP firewall, and Solo.io agentgateway are control planes. Our agent-integration list is the connector buy.
Can I still buy Astrix for MCP discovery?
Not as a new standalone license. Astrix’s homepage said new license sales ended 30 June 2026. Existing customers keep current agreements. The living Cisco product on this page is AI Defense. Write Advantage if you need MCP scanning.
Is Docker Business $24 the price of MCP Gateway?
No. $24 per user per month annual is Docker Business, a Desktop and Hub subscription. MCP Toolkit and Gateway run with Desktop. Org-wide MCP policy sits on Docker AI Governance, which is invite-only and contact sales, with no dollar printed. Do not write Business $24 as MCP Gateway Enterprise.









