Resources

Gateway vs MCP scanner — what does UnitOne Gateway do?

UnitOne Gateway is a runtime control point for agent traffic in your network. An MCP scanner is a pre-connect rubric for Model Context Protocol servers. Gateway can block a bad tool call; a scanner cannot.

Security teams often ask whether they need both. Use a scan as due diligence when you onboard a server. Use Gateway every time an agent invokes a tool. UnitOne sells Gateway as the self-serve product. The standalone scanner is a legacy helper.

What each one is for

  1. 1

    Scanner: grade the server before you connect it

    Score authentication, least-privilege tools, secret handling, untrusted input, logging, and change control. Fail the server if a prototype would get implicit standing in production. See the MCP server security rubric.

  2. 2

    Gateway: inspect the call when the agent runs

    The agent may pass attacker-controlled context into a tool that looked safe at scan time. Gateway sits in your network, applies policy, and can deny the call.

  3. 3

    Gateway: keep CRA-style evidence from live traffic

    Article 14-style questions are about what happened, not what a server scored last quarter. Export agent, tool, decision, and timestamp. That is operational evidence, not legal advice.

  4. 4

    Gateway: attribute spend after you can deny

    Cost without a deny path is a dashboard. Once traffic is on Gateway, you can cap discovery agents separately from published production agents.

  5. 5

    Do not wait on a scan to start free

    Free includes Gateway in your network, 10 agents, and 25,000 events per month. A scan report is not a trial. Start free, then scan servers you have not yet connected.

Frequently asked questions

Gateway vs MCP scanner — what does UnitOne Gateway do?
UnitOne Gateway inspects and governs live agent traffic in your network: it can block unsafe tool use, export logs for Article 14-style duties, and attribute spend by agent. An MCP scanner is a due-diligence check on a server before you connect it. The scanner is a legacy helper, not a Gateway SKU, and is not required to start free.
When should we still scan an MCP server?
Before you attach a new or third-party MCP server to production agents. Grade identity, tool scope, secrets, and untrusted input. Then enforce those controls at runtime with Gateway. A passing scan does not watch the next tool call.
Does Gateway only work with MCP?
No. Gateway is an agent gateway: model and tool traffic, including MCP. The product is runtime inspection, not a one-time server score.
Is the MCP scanner on the pricing grid?
No. Public SKUs are Gateway Free, Team at $99/month, and Enterprise. The scanner is legacy and is not part of those SKUs.
How do I start Gateway if we already scanned servers?
Start free on Gateway. Scanning does not provision a gateway, event budget, or spend cap. See How to start a Gateway trial.

Runtime first. Scan as due diligence.

Start free on Gateway to inspect tool calls in your network. Use the MCP rubric when you onboard a server. Talk to us for Enterprise; request a remediation POC only when you need Finding → Fix Spec → PR.