Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

DIY vs MuleSoft Agent Fabric: an in-house build or an AI control plane for agents across platforms

Build it yourself (DIY)

Building agent connections and controls in-house from open protocols, existing infrastructure, and open-source tools

MuleSoft Agent Fabric

Control plane for agents, MCP servers, and APIs across platforms

Short answer

DIY is not a product: you govern agents yourself on open protocols such as A2A, which sets no standard registry API and leaves authorization logic to each implementation.⁠Source 1, Source 2 MuleSoft Agent Fabric is a product: a MuleSoft-hosted control plane with a registry that scanners fill from supported platforms and a gateway in the request path.⁠Source 3, Source 4, Source 5, Source 6

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both can give a company one registry plus a gateway that enforces policy: Uber built its own for MCP servers; Agent Fabric covers agents, MCP servers, and APIs.⁠Source 6, Source 7
Where they differ
DIY also covers building agents with frameworks like Google’s ADK.⁠Source 8 Agent Fabric brokers are written in Agent Script.⁠Source 6 MuleSoft says Salesforce’s separate Agentforce is for building end-to-end agents.⁠Source 9
Running both
MuleSoft says an agent built in-house can be registered manually into the same registry, without a connection check.⁠Source 9, Source 10 The Uber and Pinterest write-ups describe in-house builds.⁠Source 7, Source 11
Public sources · checked 2 October 2026
  • Offered
  • You build it
  • Not publicly documented

DIY

  • Build agents: You build itOpen-source frameworks like ADK⁠Source 8
  • Host and run agents: You build itSelf-hosted, like LangGraph⁠Source 12
  • Identity and access: You build itYour own identity provider⁠Source 13
  • Registry and governance: You build itYour own agent registry⁠Source 1
  • Traffic between agents, tools, and models: You build itYour gateway and service mesh⁠Source 7
  • Agents across organizations: You build itA2A with API management⁠Source 14

MuleSoft Agent Fabric

  • Build agents: OfferedAgent brokers in Agent Script⁠Source 6
  • Host and run agents: OfferedAgent brokers on CloudHub 2.0⁠Source 6
  • Identity and access: OfferedOmni Gateway authentication and authorization⁠Source 6
  • Registry and governance: OfferedAgent Registry in Anypoint Exchange⁠Source 6
  • Traffic between agents, tools, and models: OfferedOmni Gateway in request path⁠Source 6
  • Agents across organizations: Not publicly documented

At a glance

TopicDIYMuleSoft Agent Fabric
What it isNot a product: an in-house build on open protocols such as A2A, an open standard for agent communication, and MCP, which A2A calls complementary.⁠Source 2An AI control plane for agents, MCP servers, and APIs across platforms.⁠Source 3 MuleSoft says it is generally available.⁠Source 9
Control planeYours to build: Uber built an MCP registry as its control plane and a proxy gateway as its data plane.⁠Source 7Hosted by MuleSoft in regional clouds, such as US Cloud or EU Cloud.⁠Source 4, Source 5 Omni Gateway can be managed or self-managed.⁠Source 3
Agent registryA2A prescribes no standard API for curated registries; running one means deploying and maintaining a registry service.⁠Source 1 The official MCP Registry is in preview and lists public servers only.⁠Source 15One inventory of agents, MCP servers, and APIs, filled by scanners, which run at most once a day, or by uploading an agent card.⁠Source 6, Source 10, Source 16
Agents built elsewhereA2A gives agents built with different frameworks, languages, or vendors a common language.⁠Source 2Scanners import agents from external platforms.⁠Source 17 Orchestration needs A2A-compliant agents; an A2A bridge covers Agentforce.⁠Source 3, Source 6
PricingThe A2A and MCP specifications are openly licensed, A2A under Apache 2.0.⁠Source 2, Source 18 Build and running costs are not publicly documented.Packages start at $2,000 a month, billed annually, with usage metered in Mule Credits.⁠Source 19 MuleSoft lists the Agent Fabric package with no price: contact sales.⁠Source 19 MuleSoft’s 30-day free trial covers its full portfolio.⁠Source 19

What each one is

Build it yourself (DIY)

DIY means connecting and governing agents without buying an agent platform: open protocols wired together in-house, existing infrastructure stretched, an in-house platform, self-hosted open source, or no central approach; Pinterest, for example, runs a growing ecosystem of MCP servers and a central registry.⁠Source 11

MuleSoft Agent Fabric

MuleSoft Agent Fabric is an AI control plane for agents, MCP servers, and APIs across platforms.⁠Source 3 Its registry catalogs agents in Anypoint Exchange, Omni Gateway enforces policy in managed instances’ request path, and brokers orchestrate A2A-compliant agents.⁠Source 5, Source 6, Source 17 MuleSoft says it is generally available.⁠Source 9

The differences that matter

  1. Finding and registering agents

    DIY

    A2A prescribes no standard API for curated registries, and its docs say one means deploying and maintaining a registry service.⁠Source 1

    MuleSoft Agent Fabric

    Scanners watch supported platforms and register the agents, APIs, and MCP servers they find; other agents can be registered by uploading an agent card.⁠Source 6, Source 10

    Uber and Pinterest each describe their own internal MCP registry.⁠Source 7, Source 11

  2. Enforcing access

    DIY

    A2A calls authorization logic implementation-specific, and MCP makes authorization optional; Uber’s gateway applies policies from Uber’s internal Access Control System to humans, services, and agents.⁠Source 2, Source 7, Source 20

    MuleSoft Agent Fabric

    Omni Gateway sits in managed instances’ request path and can require authentication and authorization, and limit which tools and APIs an agent can call.⁠Source 6

  3. Where it runs

    DIY

    Where you choose: Pinterest optimized for MCP servers in its internal cloud, and Uber’s gateway runs downstream requests through its service mesh sidecar.⁠Source 7, Source 11

    MuleSoft Agent Fabric

    MuleSoft hosts the control plane in regional clouds.⁠Source 4, Source 5 Omni Gateway can also be self-managed, in a data center or on EKS, AKS, or GKE.⁠Source 3, Source 21

    Self-hosting Agent Fabric’s control plane is not publicly documented; MuleSoft’s self-hosted Private Cloud Edition doesn’t list Agent Fabric.⁠Source 22

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicDIYMuleSoft Agent Fabric
Network exposureAn MCP server on Streamable HTTP exposes an endpoint.⁠Source 23 An A2A interface over HTTP declares an HTTPS URL in production.⁠Source 2Omni Gateway sits in managed instances’ request path.⁠Source 6 In agent networks, ingress gateways get a public endpoint; egress gateways, none.⁠Source 24
IdentityIn A2A, identity is established at the HTTP layer; clients get credentials out of band.⁠Source 2, Source 14 MCP authorization is optional.⁠Source 20Rogue-agent detection needs agents set up as service identities in your IdP.⁠Source 3, Source 25 A gateway policy supports OAuth 2.0 Token Exchange.⁠Source 26
Access changes and revocationA2A servers apply their own policies.⁠Source 2 In a standard MCP deployment, offboarding means revoking access service by service.⁠Source 27Quarantine blocks a flagged agent’s access to model proxies that use the Kill Switch policy.⁠Source 25 Nothing quarantines automatically.⁠Source 25
Audit trailA2A docs advise auditing task creation, critical state changes, and agent actions.⁠Source 14 Pinterest’s MCP servers log inputs and outputs.⁠Source 11Anypoint audit logs are kept a year by default.⁠Source 28 Quarantine actions are logged with the agent instance, user, and timestamp.⁠Source 25
ComplianceA2A docs say to comply with relevant regulations, such as GDPR, CCPA, and HIPAA.⁠Source 14 MCP leaves data protections to implementers.⁠Source 29MuleSoft says Anypoint Platform is certified to ISO 27001, SOC 2, PCI DSS, and HIPAA; Agent Fabric isn’t named.⁠Source 30

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

DIY and MuleSoft Agent Fabric compared on 18 criteria
DIYMuleSoft Agent Fabric
What it is
What it is and who it’s forNot a product: agent connections and controls built in-house on open protocols such as A2A and MCP, which A2A’s specification calls complementary.⁠Source 2An AI control plane for agents, MCP servers, and APIs across platforms.⁠Source 3 MuleSoft says it adds new capabilities to existing MuleSoft products.⁠Source 31
MaturityVaries by component: MCP’s latest revision is 2026-07-28.⁠Source 29 The official MCP Registry is in preview; breaking changes or data resets may occur.⁠Source 15Generally available, MuleSoft says.⁠Source 9 Release notes add agent brokers on 3 October 2025, and rogue-agent containment and the A2A bridge on 31 August 2026.⁠Source 5, Source 32
Control
Agent registry and discoveryBuild your own: A2A prescribes no standard registry API.⁠Source 1 The official MCP Registry is in preview and doesn’t support private servers.⁠Source 15One inventory of agents, MCP servers, and APIs, whatever platform built them.⁠Source 6 Scanners register what they find; others by uploading an agent card.⁠Source 10
Identity and access controlIn A2A, identity is established at the HTTP layer and authorization logic is implementation-specific.⁠Source 2, Source 14 MCP authorization is optional.⁠Source 20Omni Gateway can require authentication and authorization and limit which tools and APIs an agent calls.⁠Source 6 Roles come from Anypoint access management.⁠Source 3
Ownership, policy, and revocationMCP says implementers should build consent and authorization flows.⁠Source 29 Pinterest ties every MCP server but one-off experiments to an owning team and review.⁠Source 11Governance strategies set rules for in-scope agents, APIs, and MCP servers and can block or flag noncompliance.⁠Source 6 Budgets cap model-proxy spend.⁠Source 6
Audit log and observabilityA2A docs advise auditing significant events and distributed tracing, for example with OpenTelemetry.⁠Source 14 MCP documents trace context propagation.⁠Source 33Anypoint audit log, kept a year by default; Omni Gateway traffic audit trail.⁠Source 6, Source 28 With Integration Advanced or Titanium, audit logs export to tools like Splunk.⁠Source 28, Source 34
Connection
How agents connectMCP servers on Streamable HTTP expose an endpoint; A2A interfaces over HTTP declare HTTPS URLs in production.⁠Source 2, Source 23 AWS PrivateLink privately links a VPC to services.⁠Source 35Omni Gateway sits in each managed instance’s request path.⁠Source 6 Agent networks add ingress gateways with a public endpoint and egress gateways without one.⁠Source 24
Agents across organizationsA2A is designed for agents from different companies on separate servers; each server authorizes requests under its own policies.⁠Source 2, Source 36Agent networks can use agents defined elsewhere in your company.⁠Source 37 Partner-held access controls: not publicly documented.
Protocol supportMCP defines stdio and Streamable HTTP transports; its latest revision is 2026-07-28.⁠Source 29, Source 38 A2A maps to JSON-RPC, gRPC, and HTTP/REST bindings.⁠Source 2Omni Gateway supports MCP and A2A.⁠Source 39 Connectors run MCP or A2A servers and clients in Mule apps; MCP Bridge turns an API into an MCP server.⁠Source 6
Frameworks, models, and clouds supportedA2A gives agents built with different frameworks, languages, or vendors a common language.⁠Source 2 Google’s ADK says it is model- and deployment-agnostic.⁠Source 8MuleSoft says it applies control to agents wherever they run, without rebuilding them.⁠Source 9 Orchestration needs A2A-compliant agents; a bridge covers Agentforce.⁠Source 3, Source 6
Operations
Deployment options and data residencyWhere you choose: Pinterest optimized for MCP servers in its internal cloud.⁠Source 11 A2A docs say to protect data at rest under your own security policies.⁠Source 14MuleSoft hosts the control plane in regional clouds.⁠Source 4, Source 5 Omni Gateway can be self-managed.⁠Source 3, Source 21 Self-hosting Agent Fabric’s control plane is not publicly documented.
Compliance attestationsSits with the implementer: A2A docs say to comply with relevant regulations such as GDPR, CCPA, and HIPAA, and MCP leaves data protections to implementers.⁠Source 14, Source 29MuleSoft says Anypoint Platform holds ISO 27001, SOC 2, PCI DSS, HIPAA, and GDPR compliance.⁠Source 30 Coverage of Agent Fabric isn’t publicly documented.
Support and SLADepends on the component: MCP SDKs are tiered partly by maintenance commitments.⁠Source 40 The official MCP Registry, in preview, gives no uptime guarantee.⁠Source 41MuleSoft’s Cloud Offerings SLA commits to 99.95% monthly availability for covered services (subscriptions started by 1 May 2025).⁠Source 42 Premier Success Plans exist.⁠Source 43
Time and effort to get runningA curated A2A registry is a service you deploy and maintain.⁠Source 1 Pinterest built a unified deployment pipeline after new MCP servers took too much setup.⁠Source 11Needs product access, turned on by an admin for a business group or organization.⁠Source 3 Managed instances need Omni Gateway; scanners, a connected cloud provider.⁠Source 3
Pricing model and public pricesThe A2A and MCP specifications are openly licensed, A2A under Apache 2.0.⁠Source 2, Source 18 Build and running costs are not publicly documented.MuleSoft packages from $2,000 a month, billed annually; usage is metered in Mule Credits.⁠Source 19 MuleSoft lists the Agent Fabric package with no price: contact sales.⁠Source 19
Building
Agent building toolsOpen-source frameworks such as Google’s ADK and LangGraph build and deploy agents.⁠Source 8, Source 12 A2A has SDKs in six languages.⁠Source 44Agent networks in YAML, brokers in Agent Script; MuleSoft Vibes can generate both.⁠Source 6, Source 37 MuleSoft says Salesforce’s separate Agentforce is for end-to-end agents.⁠Source 9
Model accessChosen by whoever builds the agents: Google’s ADK, for one, says it is optimized for Gemini and model-agnostic.⁠Source 8Brokers support OpenAI, Azure OpenAI, Bedrock OpenAI, and Gemini models.⁠Source 37 Model Proxy is one access layer for several LLM providers.⁠Source 45
Integrations and ecosystemThe official MCP Registry, in preview, has a REST API for clients and aggregators to discover public MCP servers.⁠Source 15Hundreds of enterprise connectors, MuleSoft says.⁠Source 9 Credentials can stay in AWS Secrets Manager, Azure Key Vault, or HashiCorp Vault.⁠Source 6

Which to choose

Choose DIY if

  • You want no agent platform contract: A2A and MCP are openly licensed specifications, A2A under Apache 2.0.⁠Source 2, Source 18
  • You want every part, control plane included, to run where you choose; Pinterest optimized for MCP servers in its internal cloud.⁠Source 11
  • You want MCP calls checked by systems you already run: Pinterest uses end-user JWTs and mesh identities; Uber, its Access Control System.⁠Source 7, Source 11
  • You want your own review rules: Uber starts every MCP server and tool disabled until the owning team reviews and enables it.⁠Source 7

Choose MuleSoft Agent Fabric if

  • You want an inventory built for you: scanners register agents, APIs, and MCP servers from platforms such as LangSmith and Copilot Studio.⁠Source 6, Source 46, Source 47
  • You want policy enforced at a gateway in managed agents’ request path, where MuleSoft says third-party agents can be governed unmodified.⁠Source 6, Source 9
  • You want to contain a rogue agent: quarantine blocks its access to model proxies using the Kill Switch policy, and is reversible.⁠Source 25
  • You already run MuleSoft: Agent Fabric uses Anypoint Platform access management and catalogs agents into Anypoint Exchange.⁠Source 3, Source 17

Questions buyers ask

Is MuleSoft Agent Fabric an alternative to building it yourself?

For the control-plane parts, yes: it provides a registry, policy enforcement through Omni Gateway, and agent brokers.⁠Source 5, Source 6 MuleSoft hosts the control plane.⁠Source 4, Source 5 A self-hosted Agent Fabric control plane isn’t publicly documented. Uber, for example, built its own MCP registry and gateway.⁠Source 7

Can MuleSoft Agent Fabric govern agents built outside MuleSoft?

Yes. Scanners import agents from external platforms so they can be governed, and other agents can be registered by uploading an agent card.⁠Source 10, Source 17 Orchestration needs A2A-compliant agents: a bridge covers Agentforce, and one for Microsoft Copilot Studio is planned.⁠Source 3, Source 6, Source 49

Can MuleSoft Agent Fabric connect agents at other companies?

Agent networks can call agents outside the network through an egress gateway and use agents defined elsewhere in your company.⁠Source 24, Source 37 Bringing in another organization’s agents under access it controls isn’t publicly documented. For DIY builds, A2A is designed for agents from different companies.⁠Source 36

How do the costs compare?

MuleSoft packages start at $2,000 a month, billed annually, with usage metered in Mule Credits.⁠Source 19 MuleSoft lists the Agent Fabric package with no price: contact sales.⁠Source 19 For DIY, A2A and MCP are openly licensed specifications.⁠Source 2, Source 18 Build and running costs are not publicly documented.

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

54 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Agent Discovery - A2A Protocol a2a-protocol.org · checked Back:abcdef

  2. Source 2: Agent2Agent (A2A) Protocol Specification a2a-protocol.org · checked Back:abcdefghijklmnopq

  3. Source 3: Get Started with Agent Fabric Salesforce · checked Back:abcdefghijklmno

  4. Source 4: Salesforce Hyperforce Overview Salesforce · checked Back:abcde

  5. Source 5: Agent Fabric Release Notes Salesforce · checked Back:abcdefgh

  6. Source 6: Agent Fabric Overview Salesforce · checked Back:abcdefghijklmnopqrstuvwxyz272829

  7. Source 7: Designing MCP Gateway Uber's MCP Management Platform - Uber Blog uber.com · checked Back:abcdefghij

  8. Source 8: google/adk-python README (GitHub) github.com · checked Back:abcde

  9. Source 9: See Every Agent. Govern Every Agent. Control AI Costs. (mulesoft.com home page) Salesforce · checked Back:abcdefghi

  10. Source 10: Register Services Manually Salesforce · checked Back:abcdef

  11. Source 11: Building an MCP Ecosystem at Pinterest - Pinterest Engineering Blog medium.com · checked Back:abcdefghij

  12. Source 12: langchain-ai/langgraph README (GitHub) github.com · checked Back:ab

  13. Source 13: Integrating with Model Context Protocol (MCP) - Keycloak keycloak.org · checked Back to text

  14. Source 14: Enterprise Features - A2A Protocol a2a-protocol.org · checked Back:abcdefgh

  15. Source 15: The MCP Registry - Model Context Protocol modelcontextprotocol.io · checked Back:abcd

  16. Source 16: Discovering and Cataloging External Services with Scanners Salesforce · checked Back to text

  17. Source 17: Agent Scanners Salesforce · checked Back:abcd

  18. Source 18: modelcontextprotocol/modelcontextprotocol LICENSE (GitHub) github.com · checked Back:abcd

  19. Source 19: MuleSoft Pricing | Plans From $2,000 a Month Salesforce · checked Back:abcdefg

  20. Source 20: Authorization - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:abc

  21. Source 21: Requirements and Limits for Omni Gateway Salesforce · checked Back:ab

  22. Source 22: Anypoint Platform PCE Overview Salesforce · checked Back to text

  23. Source 23: Streamable HTTP - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:ab

  24. Source 24: Deploying Agent Network Ingress and Egress Managed Omni Gateways Salesforce · checked Back:abc

  25. Source 25: Detect and Contain Rogue Agents Salesforce · checked Back:abcde

  26. Source 26: OAuth 2.0 OBO Credential Injection Policy Salesforce · checked Back to text

  27. Source 27: Enterprise-Managed Authorization - Model Context Protocol extensions modelcontextprotocol.io · checked Back to text

  28. Source 28: Audit Logging in Anypoint Platform Salesforce · checked Back:abc

  29. Source 29: Specification - Model Context Protocol 2026-07-28 modelcontextprotocol.io · checked Back:abcde

  30. Source 30: Anypoint Platform Trust Center Salesforce · checked Back:ab

  31. Source 31: MuleSoft Agent Fabric | Agent Governance and Orchestration Salesforce · checked Back to text

  32. Source 32: Enhanced MuleSoft Experience Release Notes Salesforce · checked Back to text

  33. Source 33: Key Changes - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back to text

  34. Source 34: Exporting Telemetry Data to Third-Party Monitoring Systems Salesforce · checked Back to text

  35. Source 35: What is AWS PrivateLink? - Amazon Virtual Private Cloud docs.aws.amazon.com · checked Back to text

  36. Source 36: a2aproject/A2A README (GitHub) github.com · checked Back:ab

  37. Source 37: Building Agent Networks for Agent Fabric Salesforce · checked Back:abcd

  38. Source 38: Transports - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back to text

  39. Source 39: Securing Agent Interactions with Omni Gateway Salesforce · checked Back to text

  40. Source 40: SDK Tiers - Model Context Protocol modelcontextprotocol.io · checked Back to text

  41. Source 41: MCP Registry Aggregators - Model Context Protocol modelcontextprotocol.io · checked Back to text

  42. Source 42: MuleSoft Cloud Offerings Service Level Agreement (SLA) for subscriptions with an Order Start Date on or before May 1, 2025 Salesforce · checked Back to text

  43. Source 43: MuleSoft Subscription Plans - effective for Customer purchases made from Salesforce on or after June 27, 2025 Salesforce · checked Back to text

  44. Source 44: A2A protocol roadmap a2a-protocol.org · checked Back:ab

  45. Source 45: Creating and Managing Model Proxies Salesforce · checked Back to text

  46. Source 46: Adding a Scanner for LangChain LangSmith Salesforce · checked Back to text

  47. Source 47: Adding a Scanner for Microsoft Azure Copilot Salesforce · checked Back to text

  48. Source 48: Enhanced MuleSoft Experience Overview Salesforce · checked Back to text

  49. Source 49: Make an Agent A2A-Compliant Salesforce · checked Back to text

  50. Source 50: Your company's private network Blocks.ai · checked Back to text

  51. Source 51: Network requirements Blocks.ai · checked Back to text

  52. Source 52: Solutions: Agent sprawl Blocks.ai · checked Back to text

  53. Source 53: Solutions: Partner networks Blocks.ai · checked Back to text

  54. Source 54: Pricing Blocks.ai · checked Back to text