Prefect
  • Blog
  • Customers
Get a Demo
Sign InSign Up

Product

  • Prefect Cloud
  • Prefect Open Source
  • Prefect Cloud vs OSS
  • Pricing
  • How Prefect Works
  • Prefect vs Airflow
  • Prefect vs Dagster
  • FastMCP
  • Prefect Horizon
    NEW

Resources

  • Docs
  • Case Studies
  • Blog
  • Resources
  • Community
  • Learn
  • Support
  • Cloud Status

Company

  • About
  • Contact
  • Careers
  • Legal
  • Security
  • Brand Assets
  • Open Source Pledge

Social

  • Twitter
  • GitHub
  • LinkedIn
  • YouTube

© Copyright 2026 Prefect Technologies, Inc. All rights reserved.

The MCP Gateway for Authentication,
Access Control, and Audit

Most enterprises are governing AI agents with system prompts and wishful thinking. Horizon Gateway replaces vibe governance with real access control — authentication, RBAC, and audit enforced at the infrastructure layer, not in a prompt a model can ignore.

From the creators of FastMCP
OAuth 2.1 & SSO
Tool-level RBAC
Audit logging
Start freeView Documentation

Tool access is not a binary.
It's a policy surface.

When you build the framework most MCP servers run on, you learn quickly that the questions are always the same: Who can call this tool? Under what conditions? Using which credentials? With what audit trail?

Horizon Gateway answers those questions at the infrastructure layer — authentication, access control, and audit logging enforced by the platform, not by prompts.

Enterprise MCP Gateway

Horizon works with your identity provider.

Put Gateway between every AI client and every MCP tool, then keep identity anchored in the IdP your company already trusts. User claims, group membership, policy decisions, and audit events stay in one governed path. Popular configurations include Okta, Microsoft Entra ID, Google Workspace, Auth0, OneLogin, JumpCloud, Ping Identity, CyberArk, and Duo.

Claims

Read from IdP

Policy

Applied per tool

Audit

Written once

Identity source
MCP tools
claim
group
session
server
tool
event
Horizon Gateway
Identity-aware access for every MCP server and tool call.
Read SSO session
Evaluate policy
Authorize tool call

Supported identity providers

65 supported identity integrations across SAML, OIDC, OAuth, SCIM, and directory sync.

IdentityGatewayMCP
Access People HR logo

Access People HR

Identity provider

Apple logo

Apple

Identity provider

AWS Cognito logo

AWS Cognito

Identity provider

Breathe HR logo

Breathe HR

Identity provider

CAS SAML logo

CAS SAML

SAML

ClassLink logo

ClassLink

Identity provider

Cloudflare logo

Cloudflare

Identity provider

CyberArk SCIM logo

CyberArk SCIM

SCIM

Entra ID OIDC logo

Entra ID OIDC

OIDC

Entra ID SCIM logo

Entra ID SCIM

SCIM

Fourth logo

Fourth

Identity provider

GitLab OAuth logo

GitLab OAuth

OAuth

Google OAuth logo

Google OAuth

OAuth

Google SAML logo

Google SAML

SAML

Intuit OAuth logo

Intuit OAuth

OAuth

JumpCloud SCIM logo

JumpCloud SCIM

SCIM

LastPass logo

LastPass

Identity provider

Login.gov OpenID Connect logo

Login.gov OpenID Connect

OIDC

Microsoft OAuth logo

Microsoft OAuth

OAuth

NetIQ logo

NetIQ

Identity provider

Okta OIDC logo

Okta OIDC

OIDC

Okta SCIM logo

Okta SCIM

SCIM

OneLogin SCIM logo

OneLogin SCIM

SCIM

PingFederate SAML logo

PingFederate SAML

SAML

PingOne SAML logo

PingOne SAML

SAML

Rippling SAML logo

Rippling SAML

SAML

SailPoint SCIM logo

SailPoint SCIM

SCIM

Salesforce SAML logo

Salesforce SAML

SAML

Shibboleth Unsolicited SAML logo

Shibboleth Unsolicited SAML

SAML

Slack OAuth logo

Slack OAuth

OAuth

Supabase + WorkOS SSO logo

Supabase + WorkOS SSO

SSO

VMware logo

VMware

Identity provider

Xero OAuth logo

Xero OAuth

OAuth

Access People HR logo

Access People HR

Identity provider

Apple logo

Apple

Identity provider

AWS Cognito logo

AWS Cognito

Identity provider

Breathe HR logo

Breathe HR

Identity provider

CAS SAML logo

CAS SAML

SAML

ClassLink logo

ClassLink

Identity provider

Cloudflare logo

Cloudflare

Identity provider

CyberArk SCIM logo

CyberArk SCIM

SCIM

Entra ID OIDC logo

Entra ID OIDC

OIDC

Entra ID SCIM logo

Entra ID SCIM

SCIM

Fourth logo

Fourth

Identity provider

GitLab OAuth logo

GitLab OAuth

OAuth

Google OAuth logo

Google OAuth

OAuth

Google SAML logo

Google SAML

SAML

Intuit OAuth logo

Intuit OAuth

OAuth

JumpCloud SCIM logo

JumpCloud SCIM

SCIM

LastPass logo

LastPass

Identity provider

Login.gov OpenID Connect logo

Login.gov OpenID Connect

OIDC

Microsoft OAuth logo

Microsoft OAuth

OAuth

NetIQ logo

NetIQ

Identity provider

Okta OIDC logo

Okta OIDC

OIDC

Okta SCIM logo

Okta SCIM

SCIM

OneLogin SCIM logo

OneLogin SCIM

SCIM

PingFederate SAML logo

PingFederate SAML

SAML

PingOne SAML logo

PingOne SAML

SAML

Rippling SAML logo

Rippling SAML

SAML

SailPoint SCIM logo

SailPoint SCIM

SCIM

Salesforce SAML logo

Salesforce SAML

SAML

Shibboleth Unsolicited SAML logo

Shibboleth Unsolicited SAML

SAML

Slack OAuth logo

Slack OAuth

OAuth

Supabase + WorkOS SSO logo

Supabase + WorkOS SSO

SSO

VMware logo

VMware

Identity provider

Xero OAuth logo

Xero OAuth

OAuth

Okta logo

Okta

SAML, OIDC, SCIM

Microsoft Entra ID logo

Microsoft Entra ID

SAML, OIDC, SCIM

Google Workspace logo

Google Workspace

SAML, OIDC

Auth0 logo

Auth0

SAML federation

OneLogin logo

OneLogin

SAML, SCIM

JumpCloud logo

JumpCloud

SAML, SCIM

Ping Identity logo

Ping Identity

SAML, SCIM

CyberArk logo

CyberArk

SAML, SCIM

Duo logo

Duo

SAML

ADP OpenID Connect logo

ADP OpenID Connect

OIDC

Auth0 logo

Auth0

Identity provider

BambooHR logo

BambooHR

Identity provider

Bubble Plugin logo

Bubble Plugin

Identity provider

Cezanne HR logo

Cezanne HR

Identity provider

Clever OIDC logo

Clever OIDC

OIDC

CyberArk SAML logo

CyberArk SAML

SAML

Duo logo

Duo

Identity provider

Entra ID SAML logo

Entra ID SAML

SAML

Firebase logo

Firebase

Identity provider

GitHub OAuth logo

GitHub OAuth

OAuth

Google Directory Sync logo

Google Directory Sync

Directory sync

Google OIDC logo

Google OIDC

OIDC

HiBob logo

HiBob

Identity provider

JumpCloud SAML logo

JumpCloud SAML

SAML

Keycloak logo

Keycloak

Identity provider

LinkedIn OAuth logo

LinkedIn OAuth

OAuth

Microsoft AD FS SAML logo

Microsoft AD FS SAML

SAML

miniOrange logo

miniOrange

Identity provider

NextAuth.js logo

NextAuth.js

Identity provider

Okta SAML logo

Okta SAML

SAML

OneLogin SAML logo

OneLogin SAML

SAML

Oracle SAML logo

Oracle SAML

SAML

PingFederate SCIM logo

PingFederate SCIM

SCIM

React Native Expo logo

React Native Expo

Identity provider

Rippling SCIM logo

Rippling SCIM

SCIM

Salesforce OAuth logo

Salesforce OAuth

OAuth

Shibboleth Generic SAML logo

Shibboleth Generic SAML

SAML

SimpleSAMLphp logo

SimpleSAMLphp

SAML

Supabase + AuthKit logo

Supabase + AuthKit

AuthKit

Vercel OAuth logo

Vercel OAuth

OAuth

Workday logo

Workday

Identity provider

ADP OpenID Connect logo

ADP OpenID Connect

OIDC

Auth0 logo

Auth0

Identity provider

BambooHR logo

BambooHR

Identity provider

Bubble Plugin logo

Bubble Plugin

Identity provider

Cezanne HR logo

Cezanne HR

Identity provider

Clever OIDC logo

Clever OIDC

OIDC

CyberArk SAML logo

CyberArk SAML

SAML

Duo logo

Duo

Identity provider

Entra ID SAML logo

Entra ID SAML

SAML

Firebase logo

Firebase

Identity provider

GitHub OAuth logo

GitHub OAuth

OAuth

Google Directory Sync logo

Google Directory Sync

Directory sync

Google OIDC logo

Google OIDC

OIDC

HiBob logo

HiBob

Identity provider

JumpCloud SAML logo

JumpCloud SAML

SAML

Keycloak logo

Keycloak

Identity provider

LinkedIn OAuth logo

LinkedIn OAuth

OAuth

Microsoft AD FS SAML logo

Microsoft AD FS SAML

SAML

miniOrange logo

miniOrange

Identity provider

NextAuth.js logo

NextAuth.js

Identity provider

Okta SAML logo

Okta SAML

SAML

OneLogin SAML logo

OneLogin SAML

SAML

Oracle SAML logo

Oracle SAML

SAML

PingFederate SCIM logo

PingFederate SCIM

SCIM

React Native Expo logo

React Native Expo

Identity provider

Rippling SCIM logo

Rippling SCIM

SCIM

Salesforce OAuth logo

Salesforce OAuth

OAuth

Shibboleth Generic SAML logo

Shibboleth Generic SAML

SAML

SimpleSAMLphp logo

SimpleSAMLphp

SAML

Supabase + AuthKit logo

Supabase + AuthKit

AuthKit

Vercel OAuth logo

Vercel OAuth

OAuth

Workday logo

Workday

Identity provider

MCP Access Control

Every tool call. Authenticated, authorized, audited.

Who can call this tool?

MCP RBAC down to the individual tool. Tie access to identity provider roles and groups so teams only see the tools they should actually use.

Under what conditions?

Separate permissions for discovering a server, using it, and managing it. Granular MCP governance instead of a binary allow or deny.

Using which credentials?

Authentication handled at the gateway. OAuth, SSO, and API key controls keep your underlying systems from ever exposing raw credentials to agents.

With what audit trail?

Every access attempt is logged, showing who called what, when, and whether they were allowed. Usage dashboards and audit trails give security teams the visibility they actually need.

The Risk

You can't prompt-engineer your way out of operational risk

Vibe governance is everywhere. Agents with access to billing systems, production databases, and customer credentials — constrained by nothing more than a system prompt asking them to “please be careful.” You already know how that ends.

That's not MCP server security. That's a breach report waiting to be written.

Horizon Gateway turns MCP tools into governed capabilities. Every tool invocation passes through the gateway, where authentication is verified, permissions are enforced, and access is logged. Your agents get exactly the capabilities they need, nothing more and nothing less.

Add MCP governance in minutes

Start free, then layer on enterprise governance as your MCP footprint grows.

Start freeTalk to the experts