Menu
ByteByteGo·September 30, 2026

Building an AI Agent Gateway for Tool Access and Security

DoorDash developed a dedicated Agent Gateway to manage how AI agents discover, access, and securely use various tools and services within an enterprise environment. This gateway centralizes critical functions like authentication, authorization, credential management, tool catalog curation, and operational monitoring, addressing the complexities that standard protocols like MCP do not cover at scale. The architecture separates concerns into a data plane proxy and a control plane registry to enforce policies and ensure consistent security and access control for AI agents.

Read original on ByteByteGo

The Challenge of AI Agent Tooling in the Enterprise

AI agents' utility significantly increases when they can interact with real systems using tools (e.g., searching documentation, updating tickets, or creating pull requests). However, directly connecting agents to numerous internal and third-party services presents significant challenges. While protocols like Model Context Protocol (MCP) standardize tool description and invocation, they don't inherently address critical enterprise concerns such as authentication, authorization, credential management, tool visibility, and operational governance at scale.

Introducing the DoorDash Agent Gateway

DoorDash built a shared Agent Gateway to centralize these responsibilities. This gateway acts as an intermediary for all AI agent tool requests, ensuring consistent application of policies across diverse tools and agents. This prevents individual teams from re-implementing complex security and access logic, leading to a more maintainable and secure ecosystem for AI agents.

ℹ️

Key Responsibilities of the Agent Gateway

The gateway integrates several crucial functions: - Access Management: Verifying agent/user identity and permissions, attaching appropriate credentials. - Tool-surface Curation: Filtering and presenting only relevant and approved tools to agents from a larger catalog. - Operations: Monitoring traffic, handling failures, applying rate limits, and logging usage for auditing.

Architectural Components: Proxy and Registry

The Agent Gateway architecture comprises two core components:

  • Proxy (Data Plane): Handles incoming requests from AI agents. It performs authentication, authorization checks, rate limiting, credential injection, and forwards requests to the appropriate downstream MCP server. It also generates metrics for monitoring and auditing.
  • Registry (Control Plane): Stores all configuration data necessary to govern traffic, including registered agents, MCP servers, ownership, authentication modes, access policies, and curated tool catalogs. Engineering teams configure the gateway via a management interface interacting with the registry.

This clear separation of concerns allows tool owners to define policies via the control plane (registry), which are then enforced by the data plane (proxy) at runtime. DoorDash also segregates internal and external use cases into different proxy planes to maintain separate trust boundaries, while sharing underlying libraries and registry concepts.

Authentication, Authorization, and Credential Management

The gateway distinguishes between authentication (who is calling) and authorization (what they can do), evaluating permissions based on the agent, user, requested tool, and environment. It can differentiate between read-only and modifying capabilities. Importantly, the gateway also manages credential injection, handling various types of credentials (internal service identity, gateway-held tokens, per-user OAuth, service principals) required by downstream systems without exposing them directly to agents. This ensures secure and context-aware access to diverse external and internal services.

AI agentsAPI GatewayToolingAuthenticationAuthorizationCredential ManagementMicroservicesSecurity

Comments

Loading comments...