Open source prototype on GitHub

One governed front door
for every agent.

Apigee and Azure APIM turn their own APIs into MCP servers. But your estate spans gateways, and no vendor governs the others. Avouch is the neutral control plane across all of them: one policy model, one agent identity, one audit log.

avouch
$ avouch compile estate/ -o server.py
✓ 3 gateways → 1 policy model
✓ auth: inherited per gateway, one agent identity
✓ audit: every call lands in one trail
# server.py is runnable: official MCP SDK, stdio transport
$

The problem

Your vendors ship MCP.
Only for themselves.

Apigee and Azure APIM turn their own APIs into MCP servers. Your estate runs on four gateways, and none of them will govern the others.

Four gateways, four truths

Apigee here, APIM there, Kong at the edge, MuleSoft on the legacy estate. Each vendor's MCP export stops at its own border. Your agents live across all of them.

Agents borrow keys

Without one identity, agents act on borrowed credentials and nobody can say which agent called what, where. Auditors notice.

Drift breaks agents silently

A policy change in any gateway moves under your agents with no warning. The first sign is a failed run in production.

How it works

From estate to agent tools
in one compile step.

Avouch reads every gateway you run and produces one governed agent interface.

01

Ingest

Point Avouch at your Apigee bundles, APIM exports, Kong config, and OpenAPI specs. No migration, no re-platforming.

02

Normalize

Operations, auth schemes, rate limits, and timeouts from every gateway merge into one policy model. Per-operation overrides win where you set them.

03

Emit

A runnable MCP server is generated, one tool per operation, with governance inherited. Agents get one identity; every call lands in one audit log.

The difference

Not another gateway.

Your vendors sell you their own MCP export. Avouch is the neutral plane above all of them.

Your vendor's MCP export
Avouch

Stops at the vendor's border. Your other gateways stay dark.

Reads Apigee, APIM, Kong, and MuleSoft into one policy model.

The agent authenticates per gateway, on borrowed keys.

One agent identity across gateways, with delegated OAuth2.

Audit trails live in four consoles.

One audit log for every tool call, whatever served it.

A policy change in the gateway breaks agents silently.

Drift detection flags what moved before your agents find out.

No vendor will govern the others. Avouch does.

Roadmap

Built in the open.

The prototype is public today. This is what it does, and what comes next.

Working now

  • OpenAPI parsing with policy annotations
  • MCP server codegen on the official SDK
  • CLI: compile, inspect, and diff commands
  • Test suite covering the full compile path
  • Apigee proxy bundle exporter
  • Azure APIM policy exporter
  • Policy packs: strict-mode validation for estates
  • CI gates for generated agent tools

Built by Manoj Kagitha, a cloud and API architect with nine years across Azure, GCP, and AWS, including Apigee X migrations and enterprise LLM gateway work. Connect on LinkedIn

Get started

Make your estate agent-ready.

The prototype is public. Compile your first spec and see your APIs as agent tools.