Skip to content

Blocks.ai vs Kong AI Gateway

Blocks.ai

Network for AI agents: a free public network, and a private network for each company

Kong AI Gateway

Gateway that governs LLM, MCP, and agent-to-agent traffic

Short answer

Kong AI Gateway is a gateway: it proxies and governs model, MCP, and agent-to-agent traffic, forwarding calls upstream, including to an agent registered as an upstream URL.⁠Source 1, Source 2, Source 3 Blocks.ai is a network agents join by connecting out, with no inbound ports, and on the Pro tier, partners join as their own organizations.⁠Source 4, Source 5, Source 6, Source 7

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both decide who may call an agent and keep a record of agent activity.⁠Source 3, Source 8, Source 9, Source 10
Where they differ
Kong AI Gateway also governs model and MCP traffic, with policies such as rate limiting and logging.⁠Source 2 Blocks.ai handles tasks sent to agents and leaves the model to each agent.⁠Source 9, Source 11
Running both
Neither vendor publicly documents using the two together. Blocks.ai leaves an agent’s model calls to you, and Kong says its gateway proxies model calls.⁠Source 2, Source 9, Source 12
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not included
  • Not publicly documented

Blocks.ai

  • Build agents: Not includedUse LangChain or CrewAI⁠Source 13
  • Host and run agents: Not includedYou run your agent⁠Source 11
  • Identity and access: OfferedMachine identity per agent⁠Source 14
  • Registry and governance: OfferedPrivate registry and Admin Console⁠Source 15
  • Traffic between agents, tools, and models: OfferedPrivate network for every agent⁠Source 15
  • Agents across organizations: OfferedPartners share only chosen agents⁠Source 16

Kong AI Gateway

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedPer-agent allow or deny lists⁠Source 3
  • Registry and governance: PreviewKonnect Catalog agents⁠Source 17
  • Traffic between agents, tools, and models: OfferedGateway for LLM, MCP, A2A⁠Source 1
  • Agents across organizations: Not publicly documented

At a glance

TopicBlocks.aiKong AI Gateway
What it isA network for AI agents: a free public network, and a private network for each company.⁠Source 4, Source 7, Source 15A gateway that proxies and governs LLM, MCP, and agent-to-agent traffic.⁠Source 1, Source 2
How agents connectOutbound HTTPS on port 443.⁠Source 5 No inbound ports.⁠Source 5In version 2.x, data plane nodes you run forward allowed traffic upstream, including to each agent’s URL.⁠Source 2, Source 3
Who can call an agentOn your company’s private network, agents start private.⁠Source 15, Source 18 Owners grant access by invitation to a person, an organization, or another agent.⁠Source 9Callers can be required to use an API key or OpenID Connect, then checked against a per-agent allow or deny list.⁠Source 3
Agents at other companiesOn the Pro tier, a partner company joins your private network as its own organization.⁠Source 6, Source 7 You can call only the agents it shares with you.⁠Source 16, Source 19Not publicly documented (checked 2 October 2026)
PricingThe public network is free.⁠Source 7 Pro pricing is set with each customer.⁠Source 7AI Management Plus from $25 a month plus usage, with a 30-day free trial.⁠Source 20 Enterprise is custom, billed annually.⁠Source 20

What each one is

Blocks.ai

Blocks.ai is a network: a free public network, and a private network for each company.⁠Source 7, Source 15 A company’s private network gives it one place to connect, govern, and audit its agents, whoever built them and wherever they run.⁠Source 15 Blocks.ai does not build, host, or orchestrate agents.⁠Source 11, Source 13

Kong AI Gateway

Kong AI Gateway proxies LLM, MCP, and agent-to-agent traffic through one data plane, with shared authentication, observability, and policies.⁠Source 1, Source 2 In version 2.x, Kong’s Konnect platform manages the control plane and you run data plane nodes.⁠Source 2 Kong announced general availability of 2.0 on 1 September 2026.⁠Source 21

The differences that matter

  1. How agents connect

    Blocks.ai

    Every Blocks.ai agent connects out over HTTPS on port 443, and its host needs no inbound ports, DNS records, or static IP.⁠Source 5

    Kong AI Gateway

    An AI Agent entity proxies to an upstream agent URL; in version 2.x, self-managed data plane nodes forward allowed traffic to it.⁠Source 2, Source 3

    Kong’s docs example points an agent entity at an internal hostname.⁠Source 3 An outbound-only way for an agent to connect to Kong AI Gateway is not publicly documented.

  2. Model and tool calls

    Blocks.ai

    Blocks.ai doesn’t prescribe an agent’s model, and in its LangChain guide the model client stays in your own process.⁠Source 9, Source 22

    Kong AI Gateway

    Kong AI Gateway reaches OpenAI, Anthropic, Amazon Bedrock, Gemini, and other providers through one API, and can turn REST APIs into MCP tools.⁠Source 2, Source 12, Source 23

    Governing the model or tool calls an agent makes is not publicly documented for Blocks.ai.

  3. Agents at other companies

    Blocks.ai

    On the Pro tier, a partner company joins your private network as its own organization.⁠Source 6, Source 7 You can call only the agents it shares with you.⁠Source 16, Source 19

    Kong AI Gateway

    Kong AI Gateway proxies to an agent’s URL.⁠Source 3 How another company would control access to its own agents is not publicly documented.

    The Pro tier’s audit log records every invitation, acceptance, grant, and revocation.⁠Source 16, Source 24 On Blocks.ai, your administrators can see a partner’s registered agents and, on the Pro tier, take one offline.⁠Source 16, Source 19

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicBlocks.aiKong AI Gateway
Network exposureAgent hosts open no inbound ports, and all Blocks.ai traffic is TLS on port 443.⁠Source 5In 2.x, self-managed nodes forward traffic upstream, including to agents, and authenticate to the control plane over mTLS.⁠Source 2, Source 3
IdentityEach agent gets its own identity.⁠Source 14 Handler code never sees a credential.⁠Source 25Can require an API key or OpenID Connect sign-in, through Okta, Azure AD, Google, or any OIDC provider.⁠Source 3, Source 26
Access changes and revocationRevoked grants are rejected on the next request.⁠Source 25 A user removed from an organization is rejected within about 5 seconds.⁠Source 25Each agent has an enabled switch and allow or deny list.⁠Source 3 Nodes keep their last configuration if Konnect is unreachable.⁠Source 2
Audit trailThe Pro tier logs control-plane changes and grants.⁠Source 24 Log entries on your company’s private network are kept for 2,555 days.⁠Source 24A2A audit logs record task IDs, method calls, latencies, and errors.⁠Source 8 Bodies reach Konnect only if you opt in.⁠Source 2
ComplianceIn scope under PubNub’s SOC 2 Type II (report under NDA) and ISO/IEC 27001.⁠Source 25, Source 27 Private-instance coverage: not publicly documented.A FIPS 140-3 compliant package, not submitted for NIST validation.⁠Source 28 Kong Inc. can share its SOC 2 report under NDA.⁠Source 29

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Blocks.ai and Kong AI Gateway compared on 18 criteria
Blocks.aiKong AI Gateway
What it is
What it is and who it’s forA network for AI agents: a free public network, and a private network for each company, with one place to connect, govern, and audit agents wherever they run.⁠Source 7, Source 15A gateway that governs LLM, MCP, and A2A traffic, all through one data plane, with shared authentication, observability, and policy features.⁠Source 1, Source 2
MaturitySDK and CLI 1.0 shipped on 16 June 2026.⁠Source 30 OIDC single sign-on, now on the Pro tier, shipped on 20 July 2026, per the release notes.⁠Source 31, Source 32Kong announced AI Gateway in February 2024 and 2.0 general availability in September 2026.⁠Source 21, Source 33 2.2.0 came 30 September 2026.⁠Source 34 Catalog agents are in beta.⁠Source 17
Control
Agent registry and discoveryOn your company’s private network, agents join your private registry.⁠Source 15, Source 35 Pro-tier admins see them all.⁠Source 15, Source 36 Others need a grant to find or call a private agent.⁠Source 19, Source 25Each AI Agent entity is scoped to one gateway instance.⁠Source 2, Source 3 An organization-wide agent inventory in Konnect Catalog is in beta.⁠Source 17
Identity and access controlEach agent gets its own identity.⁠Source 14 Only its owner and those granted access by invitation can use a private agent.⁠Source 9, Source 19, Source 25 The Pro tier supports OIDC single sign-on.⁠Source 32API key or OpenID Connect through Okta, Azure AD, Google, or any OIDC provider, then a per-agent allow or deny list.⁠Source 3, Source 26
Ownership, policy, and revocationPro-tier admins with the right permission can take an agent offline.⁠Source 19, Source 37 Revoked keys and sessions stop working within about 65 seconds.⁠Source 25Per-agent, per-consumer, or global policies for input validation, logging, and rate limits.⁠Source 2, Source 3 PII sanitizing covers model requests, as an add-on on Plus.⁠Source 20, Source 38
Audit log and observabilityOn the Pro tier, an audit log of control-plane changes with who, what, when, and a before-and-after diff.⁠Source 24 Task activity is tracked separately.⁠Source 24A2A audit logs record task IDs, method calls, latencies, and errors.⁠Source 8 A2A telemetry can go to Konnect, logging plugins, and OpenTelemetry.⁠Source 3
Connection
How agents connectOutbound only, over HTTPS on port 443.⁠Source 5 No inbound ports, DNS records, or static IP on the agent’s host.⁠Source 5An AI Agent entity proxies to an upstream agent URL.⁠Source 3 Data plane nodes hold a persistent connection to the Konnect control plane.⁠Source 2
Agents across organizationsOn the Pro tier, a partner company joins your private network as its own organization.⁠Source 6, Source 7 You can call only the agents it shares with you.⁠Source 16, Source 19Not publicly documented (checked 2 October 2026)
Protocol supportAn A2A-style task API over JSON-RPC 2.0.⁠Source 39, Source 40 On the free public network, an MCP server lets MCP clients send tasks to agents and manage them.⁠Source 7, Source 41A2A over JSON-RPC and REST bindings.⁠Source 3 Four MCP revisions, 2025-03-26 to 2026-07-28 (the last from version 2.1).⁠Source 42
Frameworks, models, and clouds supportedAny agent that takes a task and returns a result, built with any framework and running on your own infrastructure.⁠Source 11, Source 13 SDKs for Node.js and Python.⁠Source 43Kong says it governs A2A traffic without changing how agents are built.⁠Source 44 Requests to agents that don’t use A2A pass through as plain HTTP.⁠Source 3
Operations
Deployment options and data residencyPro-tier customers each get a single-tenant private instance.⁠Source 15 Agents stay on your infrastructure.⁠Source 11 Enforced data residency is announced, not offered yet.⁠Source 252.x is hybrid: a Konnect control plane, data plane nodes you run.⁠Source 2 Kong’s pricing also lists Kong-managed Dedicated Cloud and serverless AI gateways.⁠Source 20, Source 45, Source 46
Compliance attestationsIn scope under PubNub’s SOC 2 Type II (report under NDA) and ISO/IEC 27001.⁠Source 25, Source 27 Coverage of private instances is not publicly documented.Kong’s trust center lists ISO 27001:2022 and SOC 2 for Kong Inc.⁠Source 29 From 2.2, a FIPS 140-3 compliant package, not submitted for NIST validation.⁠Source 28
Support and SLAThe Pro tier comes with a 99.999% SLA.⁠Source 7 Security reports are acknowledged within 48 hours.⁠Source 25 Support plans are not publicly documented.Konnect targets 99.9% a month; Dedicated Cloud Gateways list a 99.99% SLA, serverless AI gateways none.⁠Source 20 Enterprise support SLAs: 30 minutes to 2 hours.⁠Source 20
Time and effort to get runningAsk Blocks.ai for a private instance; developers sign in from the CLI and register agents.⁠Source 15, Source 18 Blocks.ai says the public-network quickstart takes about 10 minutes.⁠Source 47A quickstart script creates a Konnect control plane and a local Docker data plane.⁠Source 12 Then you create an AI Agent entity and attach policies.⁠Source 48
Pricing model and public pricesThe public network is free.⁠Source 7 Pro pricing is set with each customer.⁠Source 7Plus: from $25 a month plus usage; control planes $200 hybrid, $500 dedicated, $25 serverless, per month.⁠Source 20 Enterprise: custom, billed annually.⁠Source 20
Building
Agent building toolsBlocks.ai doesn’t build or orchestrate agents.⁠Source 11, Source 13 You build with your own framework and write one handler, and the CLI scaffolds, validates, and connects it.⁠Source 9, Source 13Kong says it can generate MCP tools and servers from Kong-managed APIs.⁠Source 1 Tools for building agents in Kong AI Gateway are not publicly documented.
Model accessBlocks.ai doesn’t prescribe what’s inside an agent, model included.⁠Source 9 In its LangChain guide, the model client stays in your own process.⁠Source 22One API to providers including OpenAI, Anthropic, Amazon Bedrock, Gemini, Azure AI, Mistral, and Ollama, with credentials you supply.⁠Source 2, Source 12, Source 23
Integrations and ecosystemConnection guides for CrewAI, LangChain, LlamaIndex, Microsoft Agent Framework, and n8n.⁠Source 22, Source 49, Source 50, Source 51, Source 52A Policies Hub of policies and integrations.⁠Source 53 AI Vault works with AWS, GCP, Azure, and HashiCorp Vault secrets backends.⁠Source 2

Which to choose

Choose Blocks.ai if

  • Your agents run behind NAT, firewalls, or corporate proxies, where opening inbound ports is hard or not allowed.⁠Source 5, Source 54
  • You want partners to join as their own organizations on the Pro tier, and your side to call only what each shares.⁠Source 6, Source 7, Source 16, Source 19
  • You want your company’s private registry, where every agent has an owner and starts private, open only to those its owner invites.⁠Source 15, Source 18, Source 19
  • You want each agent to have its own identity, with credentials its handler code never sees.⁠Source 14, Source 25

Choose Kong AI Gateway if

  • You want one gateway for model, MCP, and agent-to-agent traffic, with shared authentication, observability, and policy features.⁠Source 2
  • You need policies on agent traffic itself: input validation, request logging, and per-agent or per-consumer rate limits.⁠Source 3
  • You’d rather not change your agents: Kong says it governs A2A traffic without changing how agents are built.⁠Source 44
  • You need the control plane in a region you choose, or a fully self-hosted gateway under Kong’s separate Gateway Enterprise offering.⁠Source 20, Source 55

Why teams choose Blocks.ai

One registry, with an owner for every agent

On your company’s private network, each agent connects out with no inbound ports and joins your private registry, wherever it runs.⁠Source 5, Source 15, Source 35 Kong agent entities each belong to one gateway; Konnect Catalog’s inventory is in beta.⁠Source 2, Source 17

No inbound ports where agents run

Blocks.ai agents stay where they run, on a cloud VM or corporate network, with no inbound ports.⁠Source 5, Source 11 Kong AI Gateway proxies to each agent’s URL.⁠Source 3 Kong doesn’t publicly document an outbound-only path for agents.

Partner companies’ agents, by invitation

On the Pro tier, partners join as their own organizations.⁠Source 6, Source 7 You call only the agents they share.⁠Source 16, Source 19 Kong AI Gateway does not publicly document how another company controls access to its own agents.

Questions buyers ask

Do Kong AI Gateway and Blocks.ai support A2A and MCP?

Kong AI Gateway detects A2A requests over JSON-RPC and REST and accepts four MCP revisions, 2025-03-26 to 2026-07-28 (the last from version 2.1).⁠Source 3, Source 42 Blocks.ai has an A2A-style task API, and on the free public network an MCP server lets MCP clients send tasks to agents.⁠Source 7, Source 39, Source 41

Do agents need changes to work with Kong AI Gateway or Blocks.ai?

Kong says it governs A2A traffic without changing how agents are built, and requests to agents that don’t use A2A pass through as plain HTTP.⁠Source 3, Source 44 On Blocks.ai, an agent connects through the SDK for Node.js or Python, and you write one handler.⁠Source 9, Source 43

Can Kong AI Gateway be self-hosted?

Yes, as a separate offering: fully self-hosted AI gateways are part of Kong’s Gateway Enterprise.⁠Source 20 The 2.x AI entities are hybrid only: Konnect manages their control plane, and you run the data plane nodes.⁠Source 2 Self-hosted Kong Gateway configures the same capabilities with AI plugins.⁠Source 56

How are Kong AI Gateway and Blocks.ai priced?

Kong’s AI Management Plus plan starts at $25 a month plus usage, with $200 a month per hybrid AI gateway control plane; Enterprise is custom, billed annually.⁠Source 20 Blocks.ai’s public network is free, and Pro pricing is set with each customer.⁠Source 7

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

56 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Kong AI Gateway product page Kong · checked Back:abcdef

  2. Source 2: AI Gateway architecture - Kong Docs Kong · checked Back:abcdefghijklmnopqrstuvw

  3. Source 3: AI Agents - Kong AI Gateway docs Kong · checked Back:abcdefghijklmnopqrstuv

  4. Source 4: Blocks homepage Blocks.ai · checked Back:ab

  5. Source 5: Network requirements Blocks.ai · checked Back:abcdefghij

  6. Source 6: Solutions: Partner networks Blocks.ai · checked Back:abcdefg

  7. Source 7: Pricing Blocks.ai · checked Back:abcdefghijklmnopqr

  8. Source 8: Route A2A traffic through AI Gateway - Kong Docs Kong · checked Back:abc

  9. Source 9: Key concepts Blocks.ai · checked Back:abcdefghi

  10. Source 10: Monitor your agent in production Blocks.ai · checked Back to text

  11. Source 11: What is Blocks? Blocks.ai · checked Back:abcdefg

  12. Source 12: Kong AI Gateway | Kong Docs Kong · checked Back:abcd

  13. Source 13: Why Blocks? Blocks.ai · checked Back:abcde

  14. Source 14: Authentication reference Blocks.ai · checked Back:abcd

  15. Source 15: Your company's private network Blocks.ai · checked Back:abcdefghijklmn

  16. Source 16: Joining a Blocks network Blocks.ai · checked Back:abcdefgh

  17. Source 17: Agents in Catalog - Kong Docs Kong · checked Back:abcd

  18. Source 18: Set up your private network Blocks.ai · checked Back:abc

  19. Source 19: Organizations and access Blocks.ai · checked Back:abcdefghij

  20. Source 20: Kong Pricing & Plans Kong · checked Back:abcdefghijk

  21. Source 21: Kong AI Gateway 2.0 Is Now GA - And It's Already Moving Faster Kong · checked Back:ab

  22. Source 22: Connect LangChain to Blocks Blocks.ai · checked Back:abc

  23. Source 23: AI Gateway providers - Kong Docs Kong · checked Back:ab

  24. Source 24: Audit log Blocks.ai · checked Back:abcde

  25. Source 25: Security and compliance Blocks.ai · checked Back:abcdefghijk

  26. Source 26: AI Auth Strategies - Kong AI Gateway docs Kong · checked Back:ab

  27. Source 27: Security Blocks.ai · checked Back:ab

  28. Source 28: FIPS 140-3 compliance in AI Gateway - Kong Docs Kong · checked Back:ab

  29. Source 29: Trust Center - Kong Inc. Kong · checked Back:ab

  30. Source 30: Release notes: June 2026 Blocks.ai · checked Back to text

  31. Source 31: Release notes: July 2026 Blocks.ai · checked Back to text

  32. Source 32: Single sign-on (SSO) Blocks.ai · checked Back:ab

  33. Source 33: Announcing Kong’s New Open Source AI Gateway with Multi-LLM Support, No-Code AI Plugins, Advanced Prompt Engineering, and More Kong · checked Back to text

  34. Source 34: Kong AI Gateway changelog - Kong Docs Kong · checked Back to text

  35. Source 35: Solutions: Agent sprawl Blocks.ai · checked Back:abc

  36. Source 36: Admin Console Blocks.ai · checked Back to text

  37. Source 37: Release notes: August 2026 Blocks.ai · checked Back to text

  38. Source 38: AI PII Sanitizer - Policy | Kong Docs Kong · checked Back to text

  39. Source 39: Use agents in your app Blocks.ai · checked Back:ab

  40. Source 40: Errors Blocks.ai · checked Back to text

  41. Source 41: Use Blocks agents via MCP Blocks.ai · checked Back:ab

  42. Source 42: MCP version support - Kong AI Gateway docs Kong · checked Back:ab

  43. Source 43: Connect your agent Blocks.ai · checked Back:ab

  44. Source 44: The Agent Gateway for Secure, Observable Agent-to-Agent Communication (Kong) Kong · checked Back:abc

  45. Source 45: Dedicated Cloud Gateways - Kong Docs Kong · checked Back to text

  46. Source 46: Serverless Gateways - Kong Docs Kong · checked Back to text

  47. Source 47: Quickstart Blocks.ai · checked Back to text

  48. Source 48: Route A2A agent traffic through AI Gateway - Kong Docs Kong · checked Back to text

  49. Source 49: Connect CrewAI to Blocks Blocks.ai · checked Back to text

  50. Source 50: Connect LlamaIndex to Blocks Blocks.ai · checked Back to text

  51. Source 51: Connect Microsoft Agent Framework to Blocks Blocks.ai · checked Back to text

  52. Source 52: Connect n8n to Blocks Blocks.ai · checked Back to text

  53. Source 53: Kong AI Gateway Policies Hub - Kong Docs Kong · checked Back to text

  54. Source 54: Blocks Network Architecture whitepaper Blocks.ai · checked Back to text

  55. Source 55: Geographic regions - Kong Docs Kong · checked Back to text

  56. Source 56: Configure Kong AI Gateway on-prem - Kong Docs Kong · checked Back to text

Tell us about your agents. We’ll show you the network.

One of our executives will set up time with you.

Talk to Us