DoorDash developed a dedicated Agent Gateway to manage how AI agents discover, access, and securely use various tools and services within an enterprise environment. This gateway centralizes critical functions like authentication, authorization, credential management, tool catalog curation, and operational monitoring, addressing the complexities that standard protocols like MCP do not cover at scale. The architecture separates concerns into a data plane proxy and a control plane registry to enforce policies and ensure consistent security and access control for AI agents.
Read original on ByteByteGoAI agents' utility significantly increases when they can interact with real systems using tools (e.g., searching documentation, updating tickets, or creating pull requests). However, directly connecting agents to numerous internal and third-party services presents significant challenges. While protocols like Model Context Protocol (MCP) standardize tool description and invocation, they don't inherently address critical enterprise concerns such as authentication, authorization, credential management, tool visibility, and operational governance at scale.
DoorDash built a shared Agent Gateway to centralize these responsibilities. This gateway acts as an intermediary for all AI agent tool requests, ensuring consistent application of policies across diverse tools and agents. This prevents individual teams from re-implementing complex security and access logic, leading to a more maintainable and secure ecosystem for AI agents.
Key Responsibilities of the Agent Gateway
The gateway integrates several crucial functions: - Access Management: Verifying agent/user identity and permissions, attaching appropriate credentials. - Tool-surface Curation: Filtering and presenting only relevant and approved tools to agents from a larger catalog. - Operations: Monitoring traffic, handling failures, applying rate limits, and logging usage for auditing.
The Agent Gateway architecture comprises two core components:
This clear separation of concerns allows tool owners to define policies via the control plane (registry), which are then enforced by the data plane (proxy) at runtime. DoorDash also segregates internal and external use cases into different proxy planes to maintain separate trust boundaries, while sharing underlying libraries and registry concepts.
The gateway distinguishes between authentication (who is calling) and authorization (what they can do), evaluating permissions based on the agent, user, requested tool, and environment. It can differentiate between read-only and modifying capabilities. Importantly, the gateway also manages credential injection, handling various types of credentials (internal service identity, gateway-held tokens, per-user OAuth, service principals) required by downstream systems without exposing them directly to agents. This ensures secure and context-aware access to diverse external and internal services.