fold

v1.3.0 Apache-2.0 40/40 MCP conformant

The enterprise MCP gateway.

One governed endpoint between every MCP (Model Context Protocol) client and every MCP server. Federation, auth, policy, caching, and audit — built on the official MCP Go SDK on both sides of the proxy.

clientclientclientfoldcfdocs__*git__*jobs__*auth · policy · auditone governed endpoint · /mcpany MCP clientupstreams

See it live.

demo.fold.run federates three public MCP servers behind one endpoint — the unmodified release binary, governed by its own config. Point any MCP client at it. Rate-limited, unauthenticated, no warranty; live status on /status. Copy-paste walkthrough: try the demo.

demo.fold.run/mcpthree upstreams · one endpoint

cfdocs__*

Cloudflare's public docs MCP server — a real third-party upstream, governed and namespaced like any internal one.

git__*

GitMCP — a public 2025-era server on the session handshake. Behind the gateway it is just another namespace.

jobs__*

A task-minting demo server. Start a job, then poll it with nothing but the task id — fold routes every poll to the owner.

Run it in 60 seconds.

fold is a single static binary with no local state. One config file in front of your first server, governance when you're ready.

  1. Describe your upstreams

    fold.config.json
    {
      "upstreams": [
        {
          "id": "github-tools",
          "url": "https://mcp.platform.acme.com/mcp",
          "namespace": "gh",
          "owner": { "org": "acme-platform", "team": "devex" }
        }
      ]
    }
  2. Run it

    shell
    # one upstream, one governed endpoint — 60 seconds
    $ go run github.com/fold-run/fold/cmd/fold@latest --config fold.config.json
    # or the container:
    $ docker run -p 8080:8080 -e FOLD_CONFIG="$(cat fold.config.json)" ghcr.io/fold-run/fold
  3. Point a client at it

    Any MCP client connects to /mcp and sees one virtual server named fold with every team's tools. MCP endpoint: http://localhost:8080/mcp · health: /healthz · metrics: /metrics

Binary

A single static Go binary — go install, or grab a prebuilt archive from GitHub releases. Linux and macOS, amd64 and arm64.go install github.com/fold-run/fold/cmd/fold@latest

Container

Multi-arch and distroless, ~22 MB. Config injected as a file or straight through FOLD_CONFIG.ghcr.io/fold-run/fold

Kubernetes

A Helm chart with probes, HPA, and ServiceMonitor — plus fold-discovery, so labeled Services join the federation on their own.

One gateway. A family of problems.

Most deployments start with one of these and grow into the others — they all ride the same config file.

Federate

Unify a federation

Acquisitions, child orgs, and teams each ship their own MCP servers — any language, any SDK. fold presents them as one virtual server with namespaced tools. No team rewrites anything.

Discover upstreams automatically

A team ships an MCP server, the registry lists it, and it appears behind the gateway — no config change. On Kubernetes, label a Service fold.run/upstream: "true" and fold-discovery does the rest.

Run tasks across the federation

Long-running work flows through fold: task polls and updates route to the server that owns the task — remembered at mint, or found by probe — and tasks/list merges every org, scoped per principal.

Govern

Draw the security boundary

One choke point for authentication, deny-by-default tool allowlists, per-principal visibility, and an audit event for every request — including the denials.

Broker credentials

Clients hold one token with fold as audience; fold exchanges it per upstream (RFC 8693) or injects service credentials. API keys never reach agents.

Govern vendor MCP servers

Put third-party and SaaS MCP endpoints behind your own auth, policy, and audit — instead of scattering per-user API keys across every client.

Operate

Protect fragile services

List caching, global and per-upstream rate limits, and circuit breakers stand between agent traffic storms and your internal systems.

Expose tools outward, carefully

Offer partners a curated, policy-scoped subset of internal tools on one hardened endpoint — a single static binary, self-hosted in your VPC.

Conformant, provably

The official MCP conformance suite runs through fold on every merge — 40/40 checks, including sampling, elicitation, and subscriptions bridged through the gateway.

Start where it hurts.

A single passthrough upstream in front of your most-used server is one config file away. Governance grows from there.

Get started