open-source prototype · MIT

Every gateway secures its own MCP. Nobody governs all of them.

Apigee, Azure APIM and Kong each turn their APIs into MCP tools. Oxvara reads the policies on all of them, gives you one inventory of what agents can reach, and fails CI when someone weakens auth, loosens a limit or changes a tool description.

# real output from the examples in the repo
$ oxvara inventory apigee@https://apigee.example.com apim kong.yaml@https://kong.example.com
Agent-facing inventory: 10 tools across 3 source(s)
  apigee:petstore   apigee_petstore_create_pet   POST  apiKey  10/second
  apim:petstore     apim_petstore_create_pet     POST  apiKey  5000/hour
  kong:kong         payments_refund_payment_post POST  oauth2  2000/hour
  ...

$ oxvara validate --pack strict --pack owasp-mcp ...
strict+owasp-mcp: 10 operations, no violations

# someone removes key-auth from a Kong service
$ oxvara drift --lock oxvara.lock.json ...
error   auth-weakened [orders_list_orders_get]: auth went from apiKey to none
error   rate-limit-loosened [orders_list_orders_get]: 120/minute -> 100000/minute

Agents are reaching your APIs. Who checks the policy?

Each gateway vendor now ships a way to expose its APIs as MCP tools. That is good for one gateway. Large enterprises run several.

01

Three gateways, three stories

Apigee, APIM and Kong each have their own MCP feature, console and policy model. There is no single view of what is agent-exposed.

02

Policy fidelity is uneven

APIM's documentation says its policies apply to all operations exposed as tools in an MCP server, not to individual tools.

03

No shared audit or identity

Agent tool calls and delegated identity are logged in different shapes, if at all. Auditors ask one question; you answer it three ways.

Inventory it. Check it. Lock it. Gate it.

Oxvara normalizes every gateway into one policy model, then works from that model.

INGEST

Apigee, APIM and Kong

Apigee proxy bundles, APIM policy XML and Kong decK files, read with each gateway's own precedence rules. One inventory across all of them.

CHECK

Policy packs, in CI

validate runs the strict pack and rules mapped to the OWASP MCP Top 10, with SARIF output for GitHub code scanning.

LOCK

Drift gate

lock pins every tool's policy and description hash. drift fails when auth weakens, a limit loosens or a description changes.

EMIT

Optional MCP server

One server across gateways that always calls the gateway, exchanges the user's token (RFC 8693) and audits every call.

Honest comparison with vendor-native MCP

If you run one gateway, use its native MCP feature. Oxvara is for the cross-gateway layer those features do not cover.

Vendor-native (Apigee, APIM, Kong, MuleSoft)Oxvara
Expose APIs as MCPYes, inside that vendor's platformOptional, via a generated standalone server
ScopeThat vendor's estate onlyOne policy model across sources
Per-tool policy viewVaries; APIM applies policy at server levelPer operation, shown in diff
CI gate on policy gapsNot a built-in conceptvalidate with policy packs
Inventory across gatewaysPer vendor consoleOne table, JSON or CSV
Drift and tool-description pinningNolock + drift
MaturityShipping, supported productsEarly prototype

Why this matters: vendor features are the competition and the reason this exists. Oxvara is only worth using where more than one gateway is in play.

Where it stands

Working now

  • Apigee, Azure APIM and Kong importers
  • inventory across gateways
  • validate: strict and OWASP MCP packs, SARIF
  • lock + drift gate
  • OAuth2: client credentials and RFC 8693 token exchange
  • Audit log, injection-safe codegen, tool annotations
  • CI and 101 passing tests

Next

  • MuleSoft and AWS API Gateway importers
  • Live import from gateway management APIs
  • Remote MCP transport with OAuth resource metadata
  • Per-consumer and per-product policy
  • Shared rate budgets across replicas

Early prototype. Not production-ready. Prompt-injection controls reduce risk but do not eliminate it. The repo's README states exactly what is and is not built.

MK

Manoj Kagitha

Cloud and API architect with Apigee X migration and multi-cloud API design experience. Building this in the open.

LinkedIn

Run oxvara inventory on your estate.

Running more than one API gateway? I am looking for a handful of design partners for a 20-minute conversation. Read-only, no data leaves your machine.