Control AI agent access for your whole team from one place

Aptible MCP Gateway gives teams access to the same tools with role-based permissions, full audit logging, and centralized credentials enforced at the gateway.

Control AI agent access for your whole team from one place

Aptible MCP Gateway gives teams access to the same tools with role-based permissions, full audit logging, and centralized credentials enforced at the gateway.

Control AI agent access for your whole team from one place

Aptible MCP Gateway gives teams access to the same tools with role-based permissions, full audit logging, and centralized credentials enforced at the gateway.

why team AI rollouts break down

Getting AI to your team is easy. Knowing what it's doing is not.

Most teams using Claude Desktop or Claude Code are running it the same way: each engineer sets up their own MCP servers, manages their own credentials, and connects to whatever tools they need. It doesn’t scale.

That’s why 492 MCP servers are exposed to the internet with zero authentication and 97% of AI-related breaches occur at organizations without proper access controls.

There's no audit trail for tool calls

Claude Desktop and Claude Code don't produce a queryable audit log of what tools were called, what arguments were passed, or which user made the call. When a security review asks what your AI did last week, there's no record to pull.

Tool access is all-or-nothing

Native MCP gives a user everything a server exposes or nothing. There's no way to give an engineer read access to Notion while giving a lead write access. Everyone who connects gets the same permissions.

Credentials live on individual machines

Every engineer maintains their own MCP configuration, with their own tokens and server connections. There's no central place to rotate credentials, audit what's connected, or enforce which tools are approved for team use.

Agents use their creator's credentials

An agent running on an engineer's session uses that engineer's credentials and grants. Its tool calls look like the engineer's calls in any log you have. As agent use scales, attribution disappears.

how aptible works

One gateway for your whole team, with controls that actually enforce

MCP Gateway sits between your team and their MCP-connected tools. Every tool call goes through the gateway, where access controls, audit logging, and credential management are enforced automatically.

MCP Gateway sits between your team and their MCP-connected tools. Every tool call goes through the gateway, where access controls, audit logging, and credential management are enforced automatically.

Access control
Audit logging
Centralized credentials
Agent identity

Tool-level access control

Assign tool grants by role. The same Notion server can give engineers read access and leads write access. PHI-sensitive tools can be restricted to the roles that need them. Access is enforced at the gateway, not by asking people to self-limit.

Access Grants

Search...

role

Deploy Owners

Robots (No PHI)

Robots (PHI Access)

Account Owners

servers

github

notion

sentry

+ 3 more

github

notion

github

notion

sentry

+ 2 more

github

notion

sentry

+ 5 more

allowed tools

23/47

12/20

18/31

55/58

  • Tool-level access control

    Assign tool grants by role. The same Notion server can give engineers read access and leads write access. PHI-sensitive tools can be restricted to the roles that need them. Access is enforced at the gateway, not by asking people to self-limit.

    Access Grants

    Search...

    role

    Deploy Owners

    Robots (No PHI)

    Robots (PHI Access)

    Account Owners

    servers

    github

    notion

    sentry

    + 3 more

    github

    notion

    github

    notion

    sentry

    + 2 more

    github

    notion

    sentry

    + 5 more

    allowed tools

    23/47

    12/20

    18/31

    55/58

  • Audit log of every tool call

    Every tool call is logged with user identity, tool name, server, arguments, and timestamp. Arguments are encrypted at rest. When a security or compliance review asks what your AI did, the record is already there.

    date range

    last 7 days

    server

    All

    tool

    All

    user

    All

    Occurred at

    Jan 17, 2026

    13:11:43 UTC

    Jan 17, 2026

    13:09:13 UTC

    Jan 17, 2026

    13:07:49 UTC

    Jan 17, 2026

    13:05:22 UTC

    user

    qualification-agent

    Robot

    Sally G.

    sally.green@acme.com

    Jane D.

    jane.doe@acme.com

    qualification-agent

    Robot

    server

    notion

    github

    github

    notion

    Tool

    notion_notion-update-view

    create_pull_request

    create_branch

    notion_notion-update-view

    args

    2 args

    1 arg

    1 arg

    2 arg

    user agent

    claude-code/2.1.141

    claude-code/2.1.141

    claude-code/2.1.141

    claude-code/2.1.141

  • Centralized credentials, no per-engineer setup

    Connect servers once at the org level. Claude Desktop and Claude Code can be configured via MDM profiles so every team member gets access to the right tools without individual setup. Credentials rotate in one place. Supports both shared credentials (team-wide access) and personal credentials (per-engineer accounts), configured per server.

    Access Grants

    Search...

  • Robot users for agents

    Agents get their own identity, separate from any human. Robot users have their own API keys, role-based tool grants, and a distinct entry in the audit log. Agent activity is attributable at the agent level, not collapsed into the engineer who deployed it.

    ← Robot Users

    qualification-agent

    API keys

    id

    0301g87e0-8c67-123b-1er5-d6cc1b22c33b

    created

    Jan 17, 2026

    13:15:52 UTC

    Role Memberships

    role

    CRM Team

    Send Email

    added

    Jan 17, 2026

    13:11:43 UTC

    Feb 11, 2026

    12:31:09 UTC

    allowed tools

    23/47

    4/20

    servers

    notion

    sentry

    pylon

Access control
Audit logging
Centralized credentials
Agent identity

Tool-level access control

Assign tool grants by role. The same Notion server can give engineers read access and leads write access. PHI-sensitive tools can be restricted to the roles that need them. Access is enforced at the gateway, not by asking people to self-limit.

Access Grants

Search...

role

Deploy Owners

Robots (No PHI)

Robots (PHI Access)

Account Owners

servers

github

notion

sentry

+ 3 more

github

notion

github

notion

sentry

+ 2 more

github

notion

sentry

+ 5 more

Built for teams that have adopted AI tools and want to govern them

MCP Gateway is for engineering and security teams that are already using AI clients with MCP servers across the org and need security controls that scale with adoption. Not limited to Claude; any MCP-compatible client is supported. Not limited to regulated industries; any team that cares about security and auditability benefits from the same controls.

AI Gateway is designed for regulated workloads. BAA coverage, PHI de-identification, and seven-year audit log retention are enforced by default.

MCP Gateway adds the agent layer: tool-level access control for agents handling PHI, with audit logging that satisfies the same auditability requirements as any other PHI access event.

AI Gateway is designed for regulated workloads. BAA coverage, PHI de-identification, and seven-year audit log retention are enforced by default.

MCP Gateway adds the agent layer: tool-level access control for agents handling PHI, with audit logging that satisfies the same auditability requirements as any other PHI access event.

Join the waitlist

Access Grants

role

CRM Team

Robots (No PHI)

Robots (PHI Access)

Account Owners

servers

notion

sentry

+ 3 more

github

notion

github

pylon

sentry

+ 2 more

github

pylon

sentry

+ 5 more

allowed tools

23/47

12/20

18/31

55/58

Access Grant Details

Role

*

CRM Team

Tools Available (20)

Search...

github

0/24

notion

8/17

All tools (wildcard *)

notion_notion-create-comment

notion_notion-create-database

notion_notion-create-pages

notion_notion-create-view

notion_notion-duplicate-page

notion_notion-fetch

notion_notion-get-comments

notion_notion-get-teams

notion_notion-get-users

notion_notion-move-pages

notion_notion-query-database-view

notion_notion-query-meeting-notes

notion_notion-search

notion_notion-update-data-source

notion_notion-update-page

notion_notion-update-view

sentry

12/12

shortcut

0/20

Access Grants

Access Grants

role

CRM Team

Robots (No PHI)

Robots (PHI Access)

Account Owners

servers

notion

sentry

+ 3 more

github

notion

github

pylon

sentry

+ 2 more

github

pylon

sentry

+ 5 more

allowed tools

23/47

12/20

18/31

55/58

Access Grant Details

Role

*

CRM Team

Tools Available (20)

Search...

github

0/24

notion

8/17

All tools (wildcard *)

notion_notion-create-comment

notion_notion-create-database

notion_notion-create-pages

notion_notion-create-view

notion_notion-duplicate-page

notion_notion-fetch

notion_notion-get-comments

notion_notion-get-teams

notion_notion-get-users

notion_notion-move-pages

notion_notion-query-database-view

notion_notion-query-meeting-notes

notion_notion-search

notion_notion-update-data-source

notion_notion-update-page

notion_notion-update-view

sentry

12/12

shortcut

0/20

Use Cases

How teams use Aptible MCP Gateway

Use Cases

How teams use Aptible MCP Gateway

Your security team wants to know what MCP servers are connected to Claude across the org

Instead of asking engineers to self-report, the gateway maintains the registry. Anything not explicitly approved doesn't get a connection. You control what's reachable before someone connects to something they shouldn't.

Your Snowflake server is connected to your AI tools, but not everyone should have the same access

Engineers get read access. Leads get write access. The analyst team gets no access at all. Define it once at the role level; the gateway enforces it on every tool call.

Answer customer security questionnaires with actual evidence

Customer security reviews now include AI sections. Pull audit records for LLM usage and agent tool calls directly from the platform, without a reconstruction effort.

You're rolling out Claude to 30 engineers and don't want 30 different configurations

Connect your approved MCP servers once at the org level. Push Claude Desktop and Claude Code configurations via MDM so every engineer gets the right setup on day one, with no manual config required.

A customer asks what AI tools touched their data last quarter

Pull a filtered audit record of every tool call, by user and date range, in under a minute. No piecing together logs from individual machines.

An automated onboarding agent is running in production and something goes wrong

Because the agent has its own robot user identity, you can pull every tool call it made, see exactly what arguments it passed, and trace the issue without it being mixed in with your engineers' activity.

Connect to the tools your team already uses

Aptible MCP Gateway works with any MCP-compatible server. A few examples of what teams are connecting today:

Github

Aptible MCP Gateway works with any MCP-compatible server. A few examples of what teams are connecting today:

Personal

Notion

Read and write pages, search docs, and create content with role-based access per team


Personal

Sentry

Query errors, review stack traces, and investigate incidents directly in Claude


shared

Metabase

Run queries and pull data from your analytics stack without direct database access

shared

Shortcut

Search stories, update tickets, and manage workflows from Claude

Personal

Granola

Query meeting notes and summaries across your org


Personal

Pylon

Access customer support context and ticket history


Shared

Slack

Search messages, summarize threads, and draft replies without switching context

Personal

Shared vs. personal credentials

Some servers connect via shared credentials (one set of credentials the whole team uses, like a company Metabase instance or a Sentry org. Others connect via personal credentials) each team member authenticates their own account, like individual GitHub or Notion logins. The MCP Gateway supports both and lets you configure each server accordingly.

join the waitlist

Keep shipping. Safety happens automatically.

Deploy in minutes.

Keep shipping. Safety happens automatically.

Deploy in minutes.