Skip to main content

Stacklok Enterprise

A governance platform for AI infrastructure

Stacklok Enterprise gives your organization centralized control over how LLMs and MCP-connected tools are accessed, used, and secured. Its AI Gateway provides a governed endpoint for routing requests across LLM providers, enforcing per-user and per-team token budgets, and auditing model usage. Its Connector Gateway is an MCP gateway for controlling which tools people can access and how they connect. ToolHive provides the open source MCP runtime; Stacklok Enterprise brings model and tool access, identity, policy, and usage visibility under one organization-wide control plane. The platform is Kubernetes native and self-hosted in your environment.

Schedule a demo​

See how teams go from evaluation to production in under 60 days

Running in production at major financial services, technology, and software companies, including Fortune 500 and Global 2000 enterprises


Already a Stacklok Enterprise customer?

Head straight to Platform setup for the end-to-end deployment sequence, from configuring identity to rolling out clients.

Who should use Stacklok Enterprise​

Teams typically move to Stacklok Enterprise when they hit one of these walls:

  • Developers are bringing their own MCP servers to work, and shadow AI is spreading with no central control
  • Developers are calling LLM providers directly, with no routing controls, usage limits, or visibility into what's being sent
  • Your organization has multiple coding assistants and AI agents that need access to business context
  • Your security or compliance team is asking how MCP servers are authenticated, audited, and patched
  • Your security or finance team needs identity-bound LLM budgets and a full audit trail for model requests
  • You need SSO and IdP integration (Okta, Entra ID) across your organization
  • You are running MCP in production and need SLA-backed support for incidents
  • You need centralized governance and policy enforcement across multiple teams or business units
  • Your environment requires a semantically versioned, supply-chain-attested distribution rather than continuous rolling release

Recognizing these challenges in your organization? Schedule a demo to see how Stacklok Enterprise addresses them.


ToolHive Community vs. Stacklok Enterprise​

Think of ToolHive as the MCP data plane and Stacklok Enterprise as the organization-wide control plane. ToolHive Community runs MCP servers locally or on Kubernetes, proxies tool traffic, applies runtime policy, and emits telemetry. It integrates with registries, clients, and developer workflows. You do not need an Enterprise subscription to run MCP with ToolHive.

Stacklok Enterprise builds on those open runtime capabilities. It centrally manages approved MCP servers and models, access for users and groups, identities and credentials, organizational policies and budgets, and usage visibility across teams. The Connector Gateway governs MCP tool access; the AI Gateway governs model traffic. Administrators can manage the platform through the console and APIs instead of requiring direct Kubernetes access.

For example, you can run an MCP server locally with ToolHive while building an integration. When your organization makes that server available through Stacklok Enterprise, it can define who may use its tools, which credentials and policies apply, and how usage is audited.

Distribution & packaging​

CapabilityCommunityEnterprise
ToolHive core platform✓✓
Release modelContinuousSemantically versioned (MAJOR.MINOR.PATCH)
Sigstore Cosign package signing with SBOM✓✓
Patch versions retained for bug fixes and security updatesNo✓
Scanning attestationsNo✓
SLSA build provenanceNo✓

Security and supply chain​

CapabilityCommunityEnterprise
Basic scanning (Trivy, unit tests, integration tests)✓✓
Static analysis on every release (attested via Sigstore)No✓
Autonomous pen testing on every minor releaseNo✓
Hardened container base imagesNo✓
Proactive notification of vulnerabilitiesNo✓
CVEs addressed within SLO with responsible disclosureNo✓
All Sev 0-3 vulnerabilities backported as patch updatesNo✓

Authentication, identity, and governance​

CapabilityCommunityEnterprise
OIDC/OAuth authentication✓✓
Policy-as-code engine (Cedar)✓✓
Centralized audit visibility and compliance reportingNo✓
Token exchange (RFC 8693)✓✓
Turnkey IdP integration (Okta, Entra ID)No✓
IdP group to ToolHive role mappingNo✓
Entra ID on-behalf-of flowNo✓
Canonical policy packs (read-only, full CRUD, custom)No✓

Interfaces and management​

CapabilityCommunityEnterprise
Run MCP servers locally with Docker or Podman✓✓
Use MCP registries✓✓
Organization-wide approved MCP catalog and access policiesNo✓
ToolHive CLI✓✓
Usage telemetry and analytics (OpenTelemetry)✓✓
Console (administration and self-service workflows)No✓
Stacklok CLI (centrally enforced client policy)No✓

Versioning, maintenance, and support​

CapabilityCommunityEnterprise
Latest release✓✓
Supported versions: LATEST, LATEST-1, LATEST-2No✓
Community support (GitHub)✓✓
Dedicated support with SLANo✓
Proactive security advisoriesNo✓
Onboarding and integration assistanceNo✓

Seen enough to want a closer look? Schedule a demo to walk through the capabilities that matter most to your team.


Product offerings​

Stacklok Enterprise Platform is licensed as an annual subscription. Professional services are priced based on time and materials.

SKUDescriptionPricing Model
Stacklok Enterprise PlatformAI governance platform with an AI Gateway for model access and a Connector Gateway for MCP tool access, plus a console, IdP integration, policy controls, and SLA-backed supportAnnual subscription
Professional ServicesExtended integration, policy configuration, additional IdP onboarding, connector developmentTime & materials

Ready to discuss what the right package looks like for your organization? Schedule a demo to talk through your requirements.


Enterprise platform components​

Stacklok Enterprise Platform governs model and MCP tool access across your organization through its AI Gateway, Connector Gateway, registry, and console. It builds on ToolHive's open source runtime for MCP servers.

In an Enterprise deployment, the ToolHive CLI is distributed as the Stacklok CLI. Functionally it is the enterprise edition of its Community counterpart, with additional policy-enforcement and identity-provider features, so documentation that refers to the ToolHive CLI applies to it as well.

Registry​

An authoritative catalog of approved MCP servers and tools for your organization.
Integrate with the official MCP registry
Add custom MCP servers and skills
Group servers based on role or use case
Centrally manage which servers and tools are approved and who can use them
Manage your registry with an API-driven interface
Verify provenance and sign servers with built-in security controls
Preset configurations and permissions for a frictionless user experience

Runtime​

Deploy, run, and manage MCP servers in Kubernetes with security guardrails.
Deploy MCP servers in the cloud via Kubernetes
Run MCP servers locally via Docker or Podman
Proxy remote MCP servers securely for unified management
Kubernetes Operator for fleet and resource management
Leverage OpenTelemetry for centralized monitoring and audit logging

Connector Gateway​

Identity-aware MCP gateway for tool access, policy enforcement, and per-user configuration.
Integrate with your IdP for SSO (OIDC/OAuth compatible)
Control connector access per user with directory groups or Cedar policies
Broker connector credentials on each user's behalf
Discover MCP servers in your cluster and add them as connectors
Connect with local clients like Claude Desktop, Cursor, and VS Code

AI Gateway​

Governed access point for LLM providers with budget enforcement and full audit trail.
Route requests across LLM providers through a single governed endpoint
Enforce per-user and per-team token budgets
Broad model coverage across major providers
Full audit trail for model access and usage

Explore the AI Gateway documentation for full details.

Console​

One place for teams to discover, deploy, and manage approved MCP servers.
Administration and end-user experiences in a single web interface
Make it easy for admins to curate MCP servers and tools
Automate server discovery
Install MCP servers with a single click
Compatible with hundreds of AI clients

Ready to see how the platform works in your environment? Start a proof of concept to take the next step.


Validate Stacklok Enterprise in your environment​

Stacklok helps you validate Stacklok Enterprise in your environment at your pace with forward-deployed engineering support.

Learn about the proof of concept

Scoped to your environment. Hands-on support throughout.

Frequently asked questions​

How does Stacklok Enterprise relate to ToolHive Community?

ToolHive Community is open source and supports running and connecting MCP servers locally or on Kubernetes, including in environments you manage yourself. Stacklok Enterprise builds on those capabilities with an organization-wide approved catalog, centrally managed access and policies, turnkey IdP integration, semantically versioned releases, and SLA-backed support. Moving from Community to Enterprise is a supported migration where Stacklok provides the enterprise binaries and dedicated engineering support. See the full comparison or learn about the proof of concept engagement.

What happens to my data if I end my Enterprise contract?

Your data never leaves your environment. Stacklok Enterprise is fully self-hosted: you retain complete control over your data and infrastructure, regardless of contract status. If you end your subscription, you can downgrade to the open source version at any time. The only things you lose are access to Enterprise features, forward-deployed engineers, backported security patches, and dedicated support. There is zero vendor lock-in. Learn more about the product offerings.

How long does a typical deployment take?

Most customers begin to see value in less than 2 weeks of contract signing. Stacklok works directly with your platform team, and every Enterprise license includes dedicated engineering support throughout the process. You will need an existing Kubernetes environment to get started, then work through Platform setup. Timelines are scoped to your environment, so if your situation is more complex, Stacklok will work at your pace. Learn about the proof of concept engagement.

Why should I use an MCP platform instead of running MCP servers directly?

Running MCP servers without a managed runtime can leave you without isolation, access controls, or visibility into what those servers do. ToolHive provides container isolation, least-privilege permissions, and OpenTelemetry tracing for MCP servers. Stacklok Enterprise adds organization-wide governance, IdP-backed authentication, an approved catalog, and centralized audit visibility into MCP and LLM usage across your organization. Explore the core concepts to dig deeper into how ToolHive works.

What AI clients work with Stacklok Enterprise?

Stacklok Enterprise works with any AI coding assistant or agent that supports MCP. This includes Claude Code, GitHub Copilot, Cursor, Windsurf, VS Code, Zed, Cline, Continue, Goose, LM Studio, OpenAI Codex, and many more. Most clients support automatic configuration so developers can connect without manual setup. See the full client compatibility reference for the complete list.

Can I run custom MCP servers outside the Stacklok registry?

Yes. Stacklok Enterprise starts with a base registry of vetted, hardened MCP servers maintained by Stacklok. From there, you have full control to add your own servers from public package managers, Docker images, remote URLs, or build a private registry tailored to your organization. You are never limited to Stacklok's catalog. See how to run MCP servers in Kubernetes for the full details.


Explore ToolHive Community​

Not ready for Stacklok Enterprise yet?

ToolHive Community is free and open source. Run and manage MCP servers with it without an Enterprise subscription. When you need centralized governance of MCP and model access across your organization, explore Stacklok Enterprise.

Get started with ToolHive Community →