MCP Gateway
Governed access to every MCP server your agents use
Register the tools and MCP servers an agent can reach, and Chalk injects the credential at call time so the agent never holds one. Every call is recorded and checked against your policy, arguments included.

Explore Chalk MCP Gateway
Registered servers with per-agent scoping
Approved MCP servers are declared once and scoped per agent.
No access to raw credentials
The agent calls with a placeholder. The gateway injects the secret.
Policy on every call
Decisions on user, scope, backend, tool, and the arguments themselves.
Full call audit
Who called what, with which arguments, and what came back.
Runs in your own cloud
The proxy sits with your Chalk deployment. No tool traffic leaves your account without permission.
Rate limits per agent
Cap how often an agent may call a backend.
We're using Chalk to embed AI everywhere - from smart budgeting to fraud to lifecycle engagement. It's foundational now.

Write the policy once,
apply it to every agent
Register a server once and every agent reaches it through the same proxy. A Rego policy decides each call on the user, the scopes, the backend, the tool and the arguments, and returns the decision with its reasons.
MCP Gateway Docs
Keep up with Chalk
What we've been up to and where to find us next.
Most Innovative Companies
See why Fast Company named us on their list.
Register for the upcoming webinar
Learn how to give agents context for evals and production
Raising the Talent Bar
How Chalk filled 40+ roles in one quarter without lowering the bar
Introducing Chalk Notebooks
Read more about our latest product announcement
Give agents tools while keeping data secure
Talk to an engineer about running agents in your own cloud.
