Layer researchIntegration fabric
Vendor landscape
As of 2026-08-19. All vendor capability claims are vendor-published unless a third-party source appears in sources.md. Maturity states carry dates; this layer converges fast, re-verify quarterly.
Categories at this layer
- Dedicated MCP gateways: purpose-built proxies for agent tool traffic (allowlisting, credential injection, tool-description integrity, elicitation mediation, audit).
- API management incumbents with MCP capability: existing gateways extended to route, authorize, and auto-generate MCP tools from managed APIs.
- iPaaS platforms pivoting agentic: connector estates repositioned as agent tool catalogs.
- RPA platforms pivoting agentic: bot estates gaining reasoning layers.
- Event streaming platforms: the trigger fabric for ambient agents.
- Inter-agent protocol infrastructure: A2A implementations and agent discovery/identity projects.
Vendor map
- Vendor / product
- agentgateway (Solo.io origin)
- Category
- Dedicated MCP+A2A gateway
- Embedded or independent
- Independent, Linux Foundation since Aug 25 2025
- Maturity (as of Aug 2026)
- OSS, active
- Notes
- Neutral governance is the differentiator
- Vendor / product
- IBM ContextForge
- Category
- Dedicated MCP gateway
- Embedded or independent
- Independent OSS (IBM)
- Maturity (as of Aug 2026)
- OSS, active
- Notes
- Federates MCP, A2A, REST-to-MCP on Kubernetes
- Vendor / product
- Cloudflare MCP Server Portals
- Category
- Dedicated gateway (SaaS)
- Embedded or independent
- Independent
- Maturity (as of Aug 2026)
- Open beta since Aug 26 2025
- Notes
- Zero Trust policy over all MCP traffic
- Vendor / product
- Lasso Security, TrueFoundry, MintMCP, Lunar.dev MCPX, Obot, Composio
- Category
- Dedicated gateways (commercial)
- Embedded or independent
- Independent
- Maturity (as of Aug 2026)
- Varied; mostly 2025 entrants
- Notes
- Security-enforcement and catalog features vary widely; assess against the gateway feature consensus (allowlist, credential injection, inspection, audit)
- Vendor / product
- Docker MCP Gateway/Toolkit; Microsoft MCP Gateway (OSS)
- Category
- Dedicated gateways
- Embedded or independent
- Independent OSS
- Maturity (as of Aug 2026)
- Developer-oriented
- Notes
- Not enterprise control planes by themselves
- Vendor / product
- Kong (Konnect MCP, Gateway 3.12 MCP + OAuth 2.1 plugin)
- Category
- APIM incumbent
- Embedded or independent
- Independent
- Maturity (as of Aug 2026)
- Shipped Oct 2025
- Notes
- Auto-generates MCP servers from managed APIs
- Vendor / product
- Google Apigee
- Category
- APIM incumbent
- Embedded or independent
- Independent (GCP)
- Maturity (as of Aug 2026)
- Shipped 2025; managed MCP servers for Google services Dec 2025
- Notes
- Exposes Apigee-governed APIs as tools via API hub
- Vendor / product
- AWS (Bedrock AgentCore Gateway; API Gateway native MCP proxy)
- Category
- APIM incumbent + agent platform
- Embedded or independent
- Embedded in AWS
- Maturity (as of Aug 2026)
- AgentCore Gateway GA Oct 2025; API GW proxy Dec 2025
- Notes
- Turns APIs/Lambda into MCP tools with inbound/outbound authorization
- Vendor / product
- Microsoft (Azure API Management MCP; API Center private registry)
- Category
- APIM incumbent
- Embedded or independent
- Embedded in Azure
- Maturity (as of Aug 2026)
- Public preview May 2025
- Notes
- Private registry pattern worth copying regardless of stack
- Vendor / product
- WSO2, Tyk, Traefik, Zuplo
- Category
- APIM incumbents
- Embedded or independent
- Independent
- Maturity (as of Aug 2026)
- Shipping or positioning 2025-2026
- Notes
- WSO2 auto-generates MCP servers from OpenAPI
- Vendor / product
- MuleSoft (Salesforce)
- Category
- iPaaS pivoting agentic
- Embedded or independent
- Embedded (Salesforce gravity)
- Maturity (as of Aug 2026)
- Agentic messaging through 2026
- Notes
- Its surveys are load-bearing marketing; flag numbers [vendor]
- Vendor / product
- Boomi, Informatica, Workato
- Category
- iPaaS pivoting agentic
- Embedded or independent
- Independent/embedded varies
- Maturity (as of Aug 2026)
- 2025-2026 agentic features
- Notes
- Connector estates as tool catalogs; governance depth varies
- Vendor / product
- UiPath (agentic automation platform)
- Category
- RPA pivoting agentic
- Embedded or independent
- Independent
- Maturity (as of Aug 2026)
- Launched Apr 2025; ~450 customers building agents in 2025 [vendor]
- Notes
- 10,800+ customer estate is the coexistence base
- Vendor / product
- Automation Anywhere (Process Reasoning Engine)
- Category
- RPA pivoting agentic
- Embedded or independent
- Independent
- Maturity (as of Aug 2026)
- 2025
- Notes
- Same pattern: reasoning over deterministic bots
- Vendor / product
- Confluent (Kafka), Solace, Redpanda
- Category
- Event streaming
- Embedded or independent
- Independent
- Maturity (as of Aug 2026)
- Mature
- Notes
- The trigger fabric; maturity of enterprise EDA practice lags installation
- Vendor / product
- A2A implementations (Google, Microsoft, AWS platform integrations); AGNTCY (Cisco origin, LF)
- Category
- Inter-agent infrastructure
- Embedded or independent
- Mixed
- Maturity (as of Aug 2026)
- A2A v1.0 Mar 2026; adoption evidence thin
- Notes
- See CD-4: defer broad adoption to demand
Agent-washing watch
- "MCP support" without an authentication story (no OAuth resource-server behavior, no token exchange): treat as a demo, not a capability.
- Connector catalogs relabeled as "agent tools" with no per-tool authorization or audit.
- Orchestration products marketed as agents; Gartner estimates only ~130 of thousands of self-described agentic vendors are real (Jun 2025).
What rolls up to Phase 7
This layer contributes the clearest convergence story for the vendor-by-layer matrix: incumbents absorbed the new protocol within a year, so the buy decision is mostly "extend what you govern" vs "add a specialized enforcement point", not a new platform bet. Lock-in surfaces to track: private tool catalogs and their metadata, gateway policy configuration, and per-vendor auth extensions ahead of the standards.
Source: research/R03-integration-fabric/vendors.md in the evidence repository behind this site.