Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Kong AI Gateway vs MuleSoft Agent Fabric

Kong AI Gateway

Gateway that governs LLM, MCP, and agent-to-agent traffic

MuleSoft Agent Fabric

Control plane for agents, MCP servers, and APIs across platforms

Short answer

Kong AI Gateway is a gateway for LLM, MCP, and A2A traffic; MuleSoft Agent Fabric is a control plane for agents, MCP servers, and APIs, enforcing policy at its Omni Gateway.⁠Source 1, Source 2, Source 3, Source 4 Kong runs all three through one data plane with shared authentication and policy; Agent Fabric’s scanners register agents, and its brokers orchestrate A2A-compliant ones.⁠Source 2, Source 4, Source 5

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both can put a gateway in front of agents and MCP servers to authenticate callers and enforce access policy, and both offer one access layer to several LLM providers.⁠Source 2, Source 4, Source 6, Source 7, Source 8, Source 9
Where they differ
Agent Fabric’s scanners register agents on supported platforms, and its brokers orchestrate A2A-compliant agents.⁠Source 4, Source 5 Kong’s organization-wide agent inventory is in beta.⁠Source 10
Running both
MuleSoft’s Exchange can scan Kong Gateway for APIs and plugins, and Anypoint can apply policies to APIs on Kong Gateway.⁠Source 11, Source 12 Neither names Kong AI Gateway, agents, or MCP servers.⁠Source 11, Source 12
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not publicly documented

Kong AI Gateway

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedPer-agent allow or deny lists⁠Source 6
  • Registry and governance: PreviewKonnect Catalog agents⁠Source 10
  • Traffic between agents, tools, and models: OfferedGateway for LLM, MCP, A2A⁠Source 1
  • Agents across organizations: Not publicly documented

MuleSoft Agent Fabric

  • Build agents: OfferedAgent brokers in Agent Script⁠Source 4
  • Host and run agents: OfferedAgent brokers on CloudHub 2.0⁠Source 4
  • Identity and access: OfferedOmni Gateway authentication and authorization⁠Source 4
  • Registry and governance: OfferedAgent Registry in Anypoint Exchange⁠Source 4
  • Traffic between agents, tools, and models: OfferedOmni Gateway in request path⁠Source 4
  • Agents across organizations: Not publicly documented

At a glance

TopicKong AI GatewayMuleSoft Agent Fabric
Agent registryIn 2.x, each agent you add is an AI Agent entity, scoped to one gateway instance.⁠Source 2, Source 6 Konnect Catalog’s organization-wide agent inventory is in beta, not for production.⁠Source 10One registry of agents, MCP servers, and APIs, whichever platform built them.⁠Source 4 Scanners fill it from supported platforms; an agent can also be added by uploading its agent card.⁠Source 4, Source 13
Traffic it governsLLM, MCP, and A2A traffic, through one data plane with shared authentication, observability, and policy features.⁠Source 2Omni Gateway sits in the request path of each managed agent, API, or MCP server to enforce policy.⁠Source 4 Model Proxy gives one access layer for several LLM providers.⁠Source 9
Where it runsIn 2.x, Kong runs the control plane in Konnect, in a region you choose; you run the data plane nodes that carry traffic.⁠Source 2, Source 14Agent Fabric runs on MuleSoft-hosted Anypoint Platform control planes in supported geographies.⁠Source 15 Omni Gateway can be managed or self-managed.⁠Source 3
Pricing modelAI Management Plus from $25 a month plus usage; control planes are $200 a month hybrid, $500 Dedicated Cloud, or $25 serverless.⁠Source 16 Enterprise is custom, billed annually.⁠Source 16MuleSoft packages from $2,000 a month, billed annually, with usage metered in Mule Credits.⁠Source 17 MuleSoft lists the Agent Fabric package with no price: contact sales.⁠Source 17
Generally availableVersion 2.0 announced generally available on 1 September 2026; 2.2.0 released 30 September 2026.⁠Source 18, Source 19Yes, MuleSoft says, with new capabilities each month.⁠Source 20 The first release note is dated 3 October 2025.⁠Source 5

What each one is

Kong AI Gateway

Kong AI Gateway is a gateway for LLM, MCP, and A2A traffic, with shared authentication, observability, and policy features.⁠Source 1, Source 2 In 2.x, an agent is added as an AI Agent entity, which exposes it at a gateway endpoint and can carry policies.⁠Source 6, Source 21

MuleSoft Agent Fabric

MuleSoft documents Agent Fabric as an AI control plane for agents, MCP servers, and APIs across platforms.⁠Source 3 Scanners and manual registration fill its registry, Omni Gateway enforces policy in the request path of managed instances, and agent brokers orchestrate A2A-compliant agents.⁠Source 4, Source 5, Source 13

The differences that matter

  1. Agent registry

    Kong AI Gateway

    In 2.x, each agent entity belongs to one gateway instance; Kong’s organization-wide inventory, Agents in Konnect Catalog, is in beta and not for production.⁠Source 2, Source 6, Source 10

    MuleSoft Agent Fabric

    One registry lists agents, MCP servers, and APIs whichever platform built them; scanners register what they find on supported platforms.⁠Source 4

    In Kong’s beta, agents are added by pasting an A2A card; Agent Fabric takes an uploaded agent card, and its scanners run at most daily.⁠Source 10, Source 13, Source 22

  2. Building and orchestrating agents

    Kong AI Gateway

    Kong says it governs A2A traffic without changing how agents are built; the gateway proxies traffic to each agent’s own URL.⁠Source 6, Source 23

    MuleSoft Agent Fabric

    Agent brokers, defined in Agent Script, orchestrate A2A-compliant agents and run on CloudHub 2.0 or Runtime Fabric.⁠Source 4, Source 5

    Tools for building agents in Kong AI Gateway are not publicly documented. MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.⁠Source 20

  3. How policy is set

    Kong AI Gateway

    AI Policies, such as rate limiting and logging, can apply to an agent, model, MCP server, consumer, or consumer group, or globally.⁠Source 2

    MuleSoft Agent Fabric

    Governance strategies define access, privacy, cost, and compliance rules once for the agents, APIs, and MCP servers in scope, and show which fail conformance.⁠Source 4

    Agent Fabric can also cap a model-proxy caller’s token or dollar spend; Kong can enforce per-agent or per-consumer rate limits.⁠Source 4, Source 6

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicKong AI GatewayMuleSoft Agent Fabric
Network exposureIn 2.x, data plane nodes you run proxy to each agent’s URL and authenticate to the control plane over mTLS.⁠Source 2, Source 6Managed instances put Omni Gateway in the request path; agent-network ingress gateways get a public endpoint, egress gateways none.⁠Source 4, Source 24
IdentityCan require an API key, or OpenID Connect through Okta, Azure AD, Google, or another OIDC provider, before routing.⁠Source 6, Source 25Agents are set up as service identities in your identity provider for rogue-agent detection; Omni Gateway supports OAuth token exchange.⁠Source 26, Source 27
Access changes and revocationEach agent has an enabled switch; Request Termination or deny lists block callers.⁠Source 6, Source 28, Source 29 Nodes keep their last config without Konnect.⁠Source 2After review, quarantine stops a flagged agent from acting and blocks it at model proxies with the Kill Switch policy.⁠Source 26
Audit trailA2A audit logs: task IDs, method calls, latencies, errors.⁠Source 30 Konnect audit logs (Enterprise): webhook delivery, kept 7 days in Konnect.⁠Source 16, Source 31Omni Gateway can keep a traffic audit trail; Anypoint Platform audit logs are kept one year by default.⁠Source 4, Source 32
Compliance2.2+ FIPS mode: FIPS 140-3 algorithms only, not NIST-validated.⁠Source 33 Kong Inc. lists ISO 27001 and SOC 2 (report under NDA).⁠Source 34MuleSoft says Anypoint Platform is certified to ISO 27001, SOC 2, PCI DSS, and HIPAA; Agent Fabric isn’t named.⁠Source 35

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Kong AI Gateway and MuleSoft Agent Fabric compared on 18 criteria
Kong AI GatewayMuleSoft Agent Fabric
What it is
What it is and who it’s forA gateway that governs LLM, MCP, and A2A traffic.⁠Source 1, Source 2 All three run through one data plane, with shared authentication, observability, and policy features.⁠Source 2An AI control plane for agents, MCP servers, and APIs across platforms.⁠Source 3 MuleSoft says it discovers, governs, orchestrates, and observes agents.⁠Source 36
Maturity2.0 announced generally available on 1 September 2026, and 2.2.0 released 30 September 2026.⁠Source 18, Source 19 Konnect Catalog’s agent inventory is in beta, not for production.⁠Source 10MuleSoft says it is generally available, with new capabilities each month.⁠Source 20 Its first release note is dated 3 October 2025.⁠Source 5
Control
Agent registry and discoveryIn 2.x, each AI Agent entity is scoped to one gateway instance.⁠Source 2, Source 6 Konnect Catalog’s agent inventory is in beta; agents are added by pasting an A2A card.⁠Source 10One inventory of agents, MCP servers, and APIs, whichever platform built them.⁠Source 4 Scanners fill it from supported platforms, or you upload an agent’s card.⁠Source 4, Source 13
Identity and access controlAn agent can require API key or OpenID Connect authentication before routing, and an allow or deny list enforced before traffic reaches it.⁠Source 6Omni Gateway can require authentication and authorization and limit which tools and APIs an agent can call.⁠Source 4 User roles come from Anypoint access management.⁠Source 3
Ownership, policy, and revocationAgent policies include input validation, logging, and rate limits.⁠Source 6 Kong’s AI PII Sanitizer scrubs requests to AI models: a Plus add-on, included on Enterprise.⁠Source 16, Source 37Governance strategies set rules for in-scope agents, APIs, and MCP servers and can block or flag noncompliance.⁠Source 4 A flagged agent can be quarantined after review.⁠Source 26
Audit log and observabilityA2A audit logs: task IDs, method calls, latencies, errors; telemetry can also go to OpenTelemetry.⁠Source 6, Source 30 Konnect audit logs (Enterprise): webhook, 7 days in Konnect.⁠Source 16, Source 31Omni Gateway can keep a traffic audit trail.⁠Source 4 Platform audit logs are kept a year by default; Integration Advanced or Titanium adds export to third-party tools.⁠Source 32
Connection
How agents connectEach agent is an upstream URL the gateway proxies to.⁠Source 6 In 2.x, data plane nodes you run hold a persistent connection to the Konnect control plane.⁠Source 2Omni Gateway sits in the request path of each managed agent, API, or MCP server.⁠Source 4 An egress gateway carries agent networks’ calls to agents outside the network.⁠Source 24
Agents across organizationsThe gateway proxies to each agent at its upstream URL.⁠Source 6 A way for another organization to control access to its agents isn’t publicly documented.An egress gateway enforces policy on agent networks’ calls to agents outside the network.⁠Source 24 Partner-held access controls: not publicly documented.
Protocol supportA2A over JSON-RPC and REST bindings.⁠Source 6 Four MCP revisions, 2025-03-26 to 2026-07-28 (the last from version 2.1).⁠Source 38Omni Gateway supports MCP and A2A, and A2A powers orchestration in agent networks.⁠Source 7, Source 39 MCP Bridge turns an existing API into an MCP server without custom code.⁠Source 4
Frameworks, models, and clouds supportedKong says it governs A2A traffic without changing how agents are built.⁠Source 23 Agents that don’t speak A2A can pass through as plain HTTP.⁠Source 6MuleSoft calls it vendor agnostic and says its scanners cover Amazon, Google, Microsoft, Kong, and more.⁠Source 20, Source 36 Brokers orchestrate only A2A-compliant agents.⁠Source 4
Operations
Deployment options and data residency2.x: a Konnect-managed control plane in a region you choose, data plane nodes you run.⁠Source 2, Source 14 Kong also sells Kong-managed Dedicated Cloud and serverless gateways.⁠Source 16, Source 40, Source 41Agent Fabric runs on MuleSoft-hosted control planes; Omni Gateway can be self-managed.⁠Source 15, Source 42 A self-hosted Agent Fabric control plane isn’t publicly documented.
Compliance attestationsFrom 2.2, FIPS mode uses only FIPS 140-3 approved algorithms; not submitted for NIST validation.⁠Source 33 Kong lists ISO 27001, SOC 2, and PCI DSS for Kong Inc.⁠Source 34MuleSoft says Anypoint Platform is certified to ISO 27001, SOC 2, PCI DSS, and HIPAA.⁠Source 35 An attestation naming Agent Fabric is not publicly documented.
Support and SLAKonnect targets 99.9% availability; Dedicated Cloud Gateways list a 99.99% SLA, serverless gateways none.⁠Source 16 Enterprise support SLAs: 30 min to 2 hours.⁠Source 16MuleSoft’s Cloud Offerings SLA commits to 99.95% monthly availability for covered services, for orders started by 1 May 2025.⁠Source 43 Premier Success Plans are offered.⁠Source 44
Time and effort to get runningA quickstart script creates a Konnect control plane and a local Docker data plane.⁠Source 8 To route A2A traffic, you then create an AI Agent entity and attach policies.⁠Source 21With product access, an admin turns Agent Fabric on.⁠Source 3 Agent networks need a Managed Omni Gateway; scanners need a connected cloud provider for each source.⁠Source 3
Pricing model and public pricesPlus: from $25 a month plus usage; per control plane, $200 hybrid, $500 Dedicated Cloud, $25 serverless.⁠Source 16 Enterprise: custom, billed annually.⁠Source 16MuleSoft packages from $2,000 a month, billed annually, metered in Mule Credits.⁠Source 17 MuleSoft lists the Agent Fabric package with no price: contact sales.⁠Source 17
Building
Agent building toolsKong says it can generate MCP tools and servers from Kong-managed APIs.⁠Source 1 Tools for building agents in Kong AI Gateway are not publicly documented.Agent networks are defined in YAML, brokers in Agent Script.⁠Source 4, Source 45 MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.⁠Source 20
Model accessOne API to providers including OpenAI, Anthropic, Amazon Bedrock, Gemini, Azure AI, Mistral, and Ollama, with credentials you supply.⁠Source 2, Source 8, Source 46Brokers support OpenAI, Azure OpenAI, Bedrock OpenAI, and Gemini models.⁠Source 45 Model Proxy is one access layer for several providers, with spend caps.⁠Source 4, Source 9
Integrations and ecosystemA Policies Hub of policies and integrations.⁠Source 28 AI Vault works with AWS, GCP, Azure, and HashiCorp Vault secrets backends.⁠Source 2Curated public MCP servers from the Official MCP Registry and Informatica.⁠Source 4 Policies can apply to APIs on Apigee, Kong Gateway, or Azure API Management.⁠Source 3

Which to choose

Choose Kong AI Gateway if

  • You want one gateway for LLM, MCP, and A2A traffic, with one API to providers including Mistral, Cohere, Ollama, and vLLM.⁠Source 1, Source 2, Source 8, Source 46
  • You want a Kong-managed control plane (2.x) outside the traffic path, with nodes you run that keep proxying if it’s unreachable.⁠Source 2
  • You want published prices: on Plus, $25 a month plus usage and $200 a month per hybrid control plane.⁠Source 16
  • You need a fully self-hosted AI gateway: Kong’s separate Gateway Enterprise offering has one, configured with AI plugins.⁠Source 16, Source 47

Choose MuleSoft Agent Fabric if

  • Your agents already run on several platforms, and you want scanners, which MuleSoft says cover Amazon, Google, and Microsoft, to register them.⁠Source 4, Source 36
  • You already use MuleSoft: Agent Fabric uses Anypoint Platform access management, and MuleSoft cites hundreds of enterprise connectors.⁠Source 3, Source 20
  • You want brokers to orchestrate A2A-compliant agents across ecosystems, and caps on each caller’s model spend.⁠Source 4, Source 5
  • You want to contain rogue agents: after an admin reviews flagged activity, a reversible quarantine stops the agent from acting.⁠Source 26

Questions buyers ask

Do they support MCP and A2A?

Yes. Kong AI Gateway detects A2A requests over JSON-RPC and REST bindings and accepts four MCP revisions, 2026-07-28 from version 2.1.⁠Source 6, Source 38 Omni Gateway supports both, and MCP Bridge turns an existing API into an MCP server without custom code.⁠Source 4, Source 7

How is each one priced?

Kong’s AI Management Plus starts at $25 a month plus usage, with $200 a month per hybrid control plane.⁠Source 16 MuleSoft packages start at $2,000 a month, billed annually; the Agent Fabric package lists no price: contact sales.⁠Source 17 Kong and MuleSoft each have 30-day free trials.⁠Source 16, Source 17

Can either one be self-hosted?

Fully self-hosted AI gateways are part of Kong’s separate Gateway Enterprise offering; the 2.x AI entities run hybrid only.⁠Source 2, Source 16 Omni Gateway can be self-managed in a data center or on GKE, EKS, or AKS.⁠Source 42 A self-hosted Agent Fabric control plane isn’t publicly documented.

Can either one connect agents across organizations?

Kong AI Gateway proxies to agents at their upstream URLs.⁠Source 6 Agent Fabric’s egress gateway enforces policy on agent networks’ calls to agents outside the network.⁠Source 24 Neither publicly documents a way for another organization to bring in its own agents while keeping control of their access.

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

52 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Kong AI Gateway product page Kong · checked Back:abcdef

  2. Source 2: AI Gateway architecture - Kong Docs Kong · checked Back:abcdefghijklmnopqrstu

  3. Source 3: Get Started with Agent Fabric Salesforce · checked Back:abcdefghi

  4. Source 4: Agent Fabric Overview Salesforce · checked Back:abcdefghijklmnopqrstuvwxyz27282930313233

  5. Source 5: Agent Fabric Release Notes Salesforce · checked Back:abcdefg

  6. Source 6: AI Agents - Kong AI Gateway docs Kong · checked Back:abcdefghijklmnopqrstu

  7. Source 7: Securing Agent Interactions with Omni Gateway Salesforce · checked Back:abc

  8. Source 8: Kong AI Gateway | Kong Docs Kong · checked Back:abcd

  9. Source 9: Creating and Managing Model Proxies Salesforce · checked Back:abc

  10. Source 10: Agents in Catalog - Kong Docs Kong · checked Back:abcdefg

  11. Source 11: Adding a Scanner for Kong Gateway Salesforce · checked Back:abc

  12. Source 12: Enhanced MuleSoft Experience Overview Salesforce · checked Back:ab

  13. Source 13: Register Services Manually Salesforce · checked Back:abcde

  14. Source 14: Geographic regions - Kong Docs Kong · checked Back:ab

  15. Source 15: Salesforce Hyperforce Overview Salesforce · checked Back:ab

  16. Source 16: Kong Pricing & Plans Kong · checked Back:abcdefghijklmno

  17. Source 17: MuleSoft Pricing | Plans From $2,000 a Month Salesforce · checked Back:abcdef

  18. Source 18: Kong AI Gateway 2.0 Is Now GA - And It's Already Moving Faster Kong · checked Back:ab

  19. Source 19: Kong AI Gateway changelog - Kong Docs Kong · checked Back:ab

  20. Source 20: See Every Agent. Govern Every Agent. Control AI Costs. (mulesoft.com home page) Salesforce · checked Back:abcdef

  21. Source 21: Route A2A agent traffic through AI Gateway - Kong Docs Kong · checked Back:ab

  22. Source 22: Discovering and Cataloging External Services with Scanners Salesforce · checked Back to text

  23. Source 23: The Agent Gateway for Secure, Observable Agent-to-Agent Communication (Kong) Kong · checked Back:ab

  24. Source 24: Deploying Agent Network Ingress and Egress Managed Omni Gateways Salesforce · checked Back:abcd

  25. Source 25: AI Auth Strategies - Kong AI Gateway docs Kong · checked Back to text

  26. Source 26: Detect and Contain Rogue Agents Salesforce · checked Back:abcd

  27. Source 27: OAuth 2.0 OBO Credential Injection Policy Salesforce · checked Back to text

  28. Source 28: Kong AI Gateway Policies - Kong Docs Kong · checked Back:ab

  29. Source 29: Request Termination - Configuration Reference - Policy | Kong Docs Kong · checked Back to text

  30. Source 30: Route A2A traffic through AI Gateway - Kong Docs Kong · checked Back:ab

  31. Source 31: Konnect and Dev Portal audit logs - Kong Docs Kong · checked Back:ab

  32. Source 32: Audit Logging in Anypoint Platform Salesforce · checked Back:ab

  33. Source 33: FIPS 140-3 compliance in AI Gateway - Kong Docs Kong · checked Back:ab

  34. Source 34: Trust Center - Kong Inc. Kong · checked Back:ab

  35. Source 35: Anypoint Platform Trust Center Salesforce · checked Back:ab

  36. Source 36: MuleSoft Agent Fabric | Agent Governance and Orchestration Salesforce · checked Back:abc

  37. Source 37: AI PII Sanitizer - Policy | Kong Docs Kong · checked Back to text

  38. Source 38: MCP version support - Kong AI Gateway docs Kong · checked Back:ab

  39. Source 39: Using A2A Protocol in Agent Networks Salesforce · checked Back to text

  40. Source 40: Dedicated Cloud Gateways - Kong Docs Kong · checked Back to text

  41. Source 41: Serverless Gateways - Kong Docs Kong · checked Back to text

  42. Source 42: Requirements and Limits for Omni Gateway Salesforce · checked Back:ab

  43. Source 43: MuleSoft Cloud Offerings Service Level Agreement (SLA) for subscriptions with an Order Start Date on or before May 1, 2025 Salesforce · checked Back to text

  44. Source 44: MuleSoft Subscription Plans - effective for Customer purchases made from Salesforce on or after June 27, 2025 Salesforce · checked Back to text

  45. Source 45: Building Agent Networks for Agent Fabric Salesforce · checked Back:ab

  46. Source 46: AI Gateway providers - Kong Docs Kong · checked Back:ab

  47. Source 47: Configure Kong AI Gateway on-prem - Kong Docs Kong · checked Back to text

  48. Source 48: Your company's private network Blocks.ai · checked Back to text

  49. Source 49: Network requirements Blocks.ai · checked Back to text

  50. Source 50: Solutions: Agent sprawl Blocks.ai · checked Back to text

  51. Source 51: Solutions: Partner networks Blocks.ai · checked Back to text

  52. Source 52: Pricing Blocks.ai · checked Back to text