Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Kong AI Gateway vs Zenity

Kong AI Gateway

Gateway that governs LLM, MCP, and agent-to-agent traffic

Zenity AI Agent Security & Governance Platform

Security and governance platform for AI agents, aimed at security teams

Short answer

Kong AI Gateway is a gateway for LLM, MCP, and agent-to-agent traffic; Zenity is a security and governance platform that, it says, scans for agents, including in SaaS platforms or on laptops.⁠Source 1, Source 2, Source 3, Source 4 Kong can limit who calls each agent; Zenity says it can block agent actions inline on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 5, Source 6, Source 7

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Kong can block agent traffic a rule doesn’t allow and logs agent activity, including traffic between agents; Zenity says it does both, blocking where it runs inline.⁠Source 4, Source 5, Source 6, Source 7, Source 8, Source 9, Source 10
Where they differ
Kong sits in the traffic path: callers reach an agent through a gateway endpoint.⁠Source 2, Source 11 Zenity says it works through integrations, such as OpenTelemetry and coding-agent hooks.⁠Source 12, Source 13
Running both
Zenity says it added step-by-step guides for Cribl, LiteLLM, and Kong on connecting custom agents to Zenity.⁠Source 12
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not publicly documented

Kong AI Gateway

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedPer-agent allow or deny lists⁠Source 5
  • Registry and governance: PreviewKonnect Catalog agents⁠Source 14
  • Traffic between agents, tools, and models: OfferedGateway for LLM, MCP, A2A⁠Source 1
  • Agents across organizations: Not publicly documented

Zenity

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: Not publicly documented
  • Registry and governance: OfferedAI Observability agent inventory⁠Source 4
  • Traffic between agents, tools, and models: OfferedTool-call blocking for coding agents⁠Source 13
  • Agents across organizations: Not publicly documented

At a glance

TopicKong AI GatewayZenity
What it isA gateway for LLM, MCP, and A2A traffic, with shared authentication, observability, and policy features.⁠Source 1, Source 2A SaaS security and governance platform for AI agents, built, Zenity says, so security teams can inventory agents and enforce policies.⁠Source 3, Source 15
How it sees agent trafficIn the path: in 2.x, data plane nodes you run receive LLM, MCP, and A2A traffic and forward allowed calls upstream, including to each agent’s URL.⁠Source 2, Source 5Zenity says it connects through integrations: OpenTelemetry and an Evaluate API for custom agents, agent hooks for coding agents, and Claude’s Compliance API.⁠Source 12, Source 13, Source 16
Agents it coversA2A and plain HTTP agents added as AI Agent entities, including agents on Amazon Bedrock AgentCore Runtime, reached with signed requests.⁠Source 5Zenity says it covers agents in platforms such as Copilot Studio, ChatGPT Enterprise, and Agentforce, plus homegrown agents, coding agents, and agents on laptops.⁠Source 4, Source 13
Pricing modelAI Management Plus from $25 a month plus usage; control planes are $200 a month hybrid, $500 Dedicated Cloud, or $25 serverless.⁠Source 17 Enterprise is custom, billed annually.⁠Source 17Custom pricing by private offer on its main AWS Marketplace listing; a separate Security Hub Extended listing shows usage prices.⁠Source 3, Source 18
MaturityVersion 2.0 announced generally available on 1 September 2026.⁠Source 19 Konnect Catalog’s agent inventory is in beta.⁠Source 14Zenity announced Azure Marketplace availability in March 2025 and AWS in January 2026.⁠Source 20, Source 21 Microsoft says Azure Marketplace is now part of Microsoft Marketplace.⁠Source 22

What each one is

Kong AI Gateway

Kong AI Gateway is one gateway for LLM, MCP, and agent-to-agent (A2A) traffic, with shared authentication, observability, and policy features.⁠Source 1, Source 2 In 2.x, an AI Agent entity exposes each agent at a gateway endpoint and can carry policies.⁠Source 5, Source 11

Zenity AI Agent Security & Governance Platform

Zenity is a SaaS security and governance platform for AI agents across SaaS, homegrown cloud platforms, and end-user devices, which it aims at security teams.⁠Source 3, Source 15 Zenity describes three layers, Surface, Enforce, and Protect, from finding exposure to stopping unsafe actions.⁠Source 15

The differences that matter

  1. How agents are listed

    Kong AI Gateway

    In 2.x, agents are added as AI Agent entities, each scoped to one gateway instance and created in the Konnect UI, the API, or kongctl.⁠Source 2, Source 5, Source 11

    Zenity

    Zenity says AI Observability scans the environment and catalogs agents in SaaS platforms, custom builds, and on laptops, with their permissions and tool access.⁠Source 4

    Konnect Catalog’s organization-wide agent inventory is in beta.⁠Source 14 Zenity says it flags agents operating outside sanctioned deployment channels.⁠Source 4

  2. Where rules apply

    Kong AI Gateway

    On gateway traffic: an agent’s callers can be required to authenticate by API key or OpenID Connect, then checked against an allow or deny list.⁠Source 2, Source 5

    Zenity

    Runtime Boundaries can check agent actions in real time; Zenity says it can block them on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 6, Source 7

    For MCP, Kong says it can show each caller only the tools it may use; Zenity says it can block or modify a coding agent’s dangerous tool call.⁠Source 13, Source 19

  3. Where it runs

    Kong AI Gateway

    In 2.x, Kong runs the control plane in Konnect, in a region you choose, and you run the data plane nodes that carry traffic.⁠Source 2, Source 23

    Zenity

    Zenity is delivered as software as a service, deployed on AWS according to its AWS Marketplace listing.⁠Source 3

    Fully self-hosted Kong AI gateways are part of Kong’s separate Gateway Enterprise offering.⁠Source 17 Zenity’s hosting regions and self-hosting aren’t in Zenity’s public docs.

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicKong AI GatewayZenity
Network exposureIn 2.x, data plane nodes you run proxy to each agent’s URL and authenticate to Kong’s control plane over mTLS.⁠Source 2, Source 5Delivered as SaaS, deployed on AWS per its AWS Marketplace listing.⁠Source 3 Network requirements aren’t in Zenity’s public docs.
IdentityAgents can require API key or OpenID Connect (Okta, Azure AD, Google, or any OIDC provider) authentication before routing.⁠Source 5, Source 24Zenity says Boundaries rules can use Okta attributes like role and status.⁠Source 6 Issuing agent identities isn’t in Zenity’s public docs.
Access changes and revocationEach agent has an enabled switch; Request Termination or deny lists block callers.⁠Source 5, Source 25, Source 26 Nodes keep their last config without Konnect.⁠Source 2Zenity says its kill switch immediately disables an agent’s tool and data access.⁠Source 6
Audit trailA2A audit logs record task IDs, method calls, latencies, and errors; Konnect telemetry omits request bodies unless you opt in.⁠Source 2, Source 9Zenity says it logs agent messages and tool calls, and can stream audit log events to Splunk or Microsoft Sentinel.⁠Source 4, Source 12
Compliance2.2+ FIPS mode: FIPS 140-3 algorithms only, not NIST-validated.⁠Source 27 Kong Inc. lists ISO 27001 and SOC 2 (report under NDA).⁠Source 28Zenity says the company holds SOC 2 Type II and is ISO 27001 compliant; FedRAMP “In Process” announced March 2026.⁠Source 29, Source 30

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Kong AI Gateway and Zenity compared on 18 criteria
Kong AI GatewayZenity
What it is
What it is and who it’s forGateway for LLM, MCP, and A2A traffic.⁠Source 1, Source 2 All three run through one data plane, with shared authentication, observability, and policy features.⁠Source 2A security and governance platform for AI agents across SaaS, cloud, and end-user devices; Zenity says it lets security teams inventory agents.⁠Source 3, Source 15
MaturityVersion 2.0 announced generally available on 1 September 2026; 2.2.0 released 30 September 2026.⁠Source 19, Source 31 Konnect Catalog’s agent inventory is in beta.⁠Source 14Zenity announced AWS Marketplace availability in January 2026.⁠Source 21 It says coverage for GitHub Copilot and OpenAI Codex became generally available in August 2026.⁠Source 12
Control
Agent registry and discoveryIn 2.x, each agent you add is an AI Agent entity, scoped to one gateway instance.⁠Source 2, Source 5 Konnect Catalog’s organization-wide agent inventory is in beta.⁠Source 14Zenity says AI Observability scans and catalogs agents in SaaS platforms, custom builds, and on laptops, with their permissions and tool access.⁠Source 4
Identity and access controlAn agent can require API key or OpenID Connect authentication before routing, and an allow or deny list enforced before traffic reaches it.⁠Source 5Zenity says Boundaries rules can reference Okta attributes such as active status, role, and department.⁠Source 6 Issuing agent identities isn’t in Zenity’s public docs.
Ownership, policy, and revocationAgent policies include input validation, logging, and rate limits.⁠Source 5 Kong’s AI PII Sanitizer scrubs requests to AI models: a Plus add-on, included on Enterprise.⁠Source 17, Source 32Zenity says it blocks actions inline on Copilot Studio, Microsoft Foundry, and coding agents.⁠Source 7 It says ownership is surfaced per discovered agent.⁠Source 33
Audit log and observabilityA2A audit logs record task IDs, method calls, latencies, and errors.⁠Source 9 Logging policies can route logs to external systems.⁠Source 34Zenity says it logs agent messages, tool calls, retrievals, and handoffs.⁠Source 4 It says its audit log events can stream to Splunk or Microsoft Sentinel.⁠Source 12
Connection
How agents connectIn 2.x, data plane nodes you run forward allowed agent traffic to each agent’s URL.⁠Source 2, Source 5 An outbound-only path for agents is not publicly documented.Zenity says custom agents connect over OpenTelemetry with an Evaluate API; coding agents use hooks.⁠Source 12, Source 13 Network needs aren’t in Zenity’s public docs.
Agents across organizationsNot publicly documented (checked 2 October 2026)Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 35
Protocol supportDetects A2A over JSON-RPC and REST bindings and rewrites agent-card URLs.⁠Source 5 Converts REST APIs into MCP tools, and proxies or combines MCP servers.⁠Source 2Zenity says custom agents use OpenTelemetry and AIDR shows agent-to-agent requests and responses.⁠Source 10, Source 12 Whether Zenity supports A2A isn’t publicly documented.
Frameworks, models, and clouds supportedProxies A2A and plain HTTP agents, including ones on AgentCore Runtime via SigV4.⁠Source 5 Kong says it doesn’t change how agents are built.⁠Source 8Zenity says it covers agents in Copilot Studio, ChatGPT Enterprise, and Agentforce, homegrown agents on Bedrock or Vertex AI, and coding agents.⁠Source 4, Source 13
Operations
Deployment options and data residency2.x: a Konnect-managed control plane in a region you choose, data plane nodes you run.⁠Source 2, Source 23 Kong also sells Kong-managed Dedicated Cloud and serverless gateways.⁠Source 17, Source 36, Source 37Software as a service, deployed on AWS per its AWS Marketplace listing.⁠Source 3 Regions, data residency, and self-hosting aren’t in Zenity’s public docs.
Compliance attestationsFrom 2.2, FIPS mode uses only FIPS 140-3 approved algorithms; not submitted for NIST validation.⁠Source 27 Kong lists ISO 27001, SOC 2, and PCI DSS for Kong Inc.⁠Source 28Zenity says the company holds SOC 2 Type II and is ISO 27001 compliant.⁠Source 29 It announced FedRAMP “In Process” status in March 2026, with authorization pending.⁠Source 30
Support and SLAKonnect targets 99.9% availability; Dedicated Cloud Gateways list a 99.99% SLA, serverless gateways none.⁠Source 17 Enterprise support SLAs: 30 min to 2 hours.⁠Source 17Zenity’s subscription terms commit to commercially reasonable efforts toward 99.9% monthly uptime.⁠Source 38 Support requests go through Zendesk during business hours.⁠Source 38
Time and effort to get runningA quickstart script creates a Konnect control plane and a local Docker data plane; you then add each agent as an AI Agent entity and attach policies.⁠Source 11, Source 39Zenity says it added custom-agent guides for Cribl, LiteLLM, and Kong.⁠Source 12 Prerequisites aren’t in Zenity’s public docs.
Pricing model and public pricesPlus: from $25 a month plus usage; per control plane, $200 hybrid, $500 Dedicated Cloud, $25 serverless.⁠Source 17 Enterprise: custom, billed annually.⁠Source 17Main AWS Marketplace listing: custom pricing by private offer.⁠Source 3 Security Hub Extended listing: usage prices, such as $130 per resource a month for Observability.⁠Source 18
Building
Agent building toolsKong says AI Gateway can generate MCP tools and servers from Kong-managed APIs.⁠Source 1 Tools for building agents in Kong AI Gateway are not publicly documented.Not in Zenity’s public docs; its product docs require a login (checked 2 October 2026)⁠Source 35
Model accessOne API to providers including OpenAI, Anthropic, Gemini, Amazon Bedrock, Mistral, and Ollama, with your own credentials.⁠Source 2, Source 39, Source 40Zenity says AIDR pairs rules mapped to OWASP LLM and MITRE ATLAS with LLM-based detections.⁠Source 10 Its models aren’t in Zenity’s public docs.
Integrations and ecosystemA Policies Hub of policies and integrations.⁠Source 25 AI Vault resolves secrets from backends such as AWS, GCP, Azure, and HashiCorp Vault.⁠Source 2Zenity says it integrates with Microsoft Agent 365, sends findings to AWS Security Hub Extended, and is on the Cursor Marketplace.⁠Source 41, Source 42, Source 43

Which to choose

Choose Kong AI Gateway if

  • You want one gateway for LLM, MCP, and A2A traffic, with shared authentication, observability, and policy features.⁠Source 1, Source 2
  • You want calls to agents checked in the traffic path, with per-agent allow or deny lists, rate limits, and A2A audit logs.⁠Source 5, Source 9
  • You’d rather run the data plane yourself: Kong’s control plane never carries your data traffic, and nodes keep proxying if it’s unreachable.⁠Source 2
  • You want one API to model providers such as OpenAI, Anthropic, Gemini, and Amazon Bedrock, switching or combining them without rewriting integrations.⁠Source 39, Source 40

Choose Zenity if

  • Your agents live in platforms such as Copilot Studio, ChatGPT Enterprise, and Agentforce, where Zenity says it builds an inventory.⁠Source 4
  • You want the checks Zenity says it runs on agent actions, blocking inline on Copilot Studio and coding agents.⁠Source 6, Source 7
  • You need coding agents such as Claude Code and Cursor covered, with agent hooks Zenity says can block a dangerous tool call.⁠Source 13
  • You want what Zenity says it offers: rules mapped to OWASP LLM and MITRE ATLAS, and audit events in Splunk or Sentinel.⁠Source 10, Source 12

Questions buyers ask

How does each one build its list of agents?

In Kong AI Gateway 2.x, you add each agent as an AI Agent entity; Konnect Catalog’s agent inventory, in beta, takes an agent’s pasted A2A card.⁠Source 11, Source 14 Zenity says AI Observability scans an organization’s environment and catalogs agents, including in SaaS platforms or on laptops.⁠Source 4

Do they support MCP and A2A?

Kong AI Gateway detects A2A requests over JSON-RPC and REST, and accepts four MCP revisions, 2025-03-26 to 2026-07-28 (the last from version 2.1).⁠Source 5, Source 44 Zenity says its agent hooks can block a coding agent’s dangerous tool call.⁠Source 13 Whether Zenity supports A2A isn’t publicly documented.

How is each one priced?

Kong’s AI Management Plus starts at $25 a month plus usage, and $200 a month per hybrid control plane; Enterprise is custom.⁠Source 17 Zenity’s main AWS Marketplace listing is by private offer; its Security Hub Extended listing shows usage prices, such as $130 per resource monthly.⁠Source 3, Source 18

Can either one be self-hosted?

Fully self-hosted Kong AI gateways are part of Kong’s separate Gateway Enterprise offering; the 2.x AI entities are hybrid, with a Konnect-managed control plane.⁠Source 2, Source 17 Zenity is software as a service, deployed on AWS per its AWS Marketplace listing.⁠Source 3 Self-hosting isn’t in Zenity’s public docs.

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

49 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Kong AI Gateway product page Kong · checked Back:abcdefg

  2. Source 2: AI Gateway architecture - Kong Docs Kong · checked Back:abcdefghijklmnopqrstuv

  3. Source 3: AWS Marketplace: Zenity Zenity · checked Back:abcdefghijk

  4. Source 4: AI Observability | See Every Agent, Know What it Touches | Zenity Zenity · checked Back:abcdefghijkl

  5. Source 5: AI Agents - Kong AI Gateway docs Kong · checked Back:abcdefghijklmnopqrs

  6. Source 6: Runtime Boundaries | The Runtime Boundary for Autonomous AI | Zenity Zenity · checked Back:abcdefg

  7. Source 7: Zenity's Coverage of the 2026 OWASP Top 10 for LLM Apps Zenity · checked Back:abcde

  8. Source 8: The Agent Gateway for Secure, Observable Agent-to-Agent Communication (Kong) Kong · checked Back:ab

  9. Source 9: Route A2A traffic through AI Gateway - Kong Docs Kong · checked Back:abcd

  10. Source 10: AI Detection and Response (AIDR) | See the Threat, Stop the Action | Zenity Zenity · checked Back:abcd

  11. Source 11: Route A2A agent traffic through AI Gateway - Kong Docs Kong · checked Back:abcde

  12. Source 12: From Triage to Full Coverage: The Shift AI Agent Security Took in August Zenity · checked Back:abcdefghijk

  13. Source 13: Coding and Personal Agents | Zenity Zenity · checked Back:abcdefghi

  14. Source 14: Agents in Catalog - Kong Docs Kong · checked Back:abcdef

  15. Source 15: Platform | AI Agent Security & Governance Platform | Zenity Zenity · checked Back:abcd

  16. Source 16: Claude's Agents Are Already Running Across Your Enterprise. Now Security Teams Can Catch Up. Zenity · checked Back to text

  17. Source 17: Kong Pricing & Plans Kong · checked Back:abcdefghijk

  18. Source 18: AWS Marketplace: Zenity AI Security & Governance Platform for Security Hub Extended Zenity · checked Back:abc

  19. Source 19: Kong AI Gateway 2.0 Is Now GA - And It's Already Moving Faster Kong · checked Back:abc

  20. Source 20: Zenity Now Available in the Microsoft Azure Marketplace Zenity · checked Back to text

  21. Source 21: Zenity Now Available on AWS Marketplace, Bringing End-to-End Security to Amazon Bedrock AgentCore and Enterprise AI Agents Everywhere Zenity · checked Back:ab

  22. Source 22: Introducing Microsoft Marketplace - Thousands of solutions. Millions of customers. One Marketplace. - The Official Microsoft Blog Zenity · checked Back to text

  23. Source 23: Geographic regions - Kong Docs Kong · checked Back:ab

  24. Source 24: AI Auth Strategies - Kong AI Gateway docs Kong · checked Back to text

  25. Source 25: Kong AI Gateway Policies - Kong Docs Kong · checked Back:ab

  26. Source 26: Request Termination - Configuration Reference - Policy | Kong Docs Kong · checked Back to text

  27. Source 27: FIPS 140-3 compliance in AI Gateway - Kong Docs Kong · checked Back:ab

  28. Source 28: Trust Center - Kong Inc. Kong · checked Back:ab

  29. Source 29: Zenity Trust Center Zenity · checked Back:ab

  30. Source 30: Zenity Achieves FedRAMP “In Process” Status for AI Agent Security Zenity · checked Back:ab

  31. Source 31: Kong AI Gateway changelog - Kong Docs Kong · checked Back to text

  32. Source 32: AI PII Sanitizer - Policy | Kong Docs Kong · checked Back to text

  33. Source 33: AI Security Posture Management (AISPM) | Stop Agent Risk Before Deployment | Zenity Zenity · checked Back to text

  34. Source 34: AI Gateway audit log reference - Kong Docs Kong · checked Back to text

  35. Source 35: Zenity Documentation (login) Zenity · checked Back:abc

  36. Source 36: Dedicated Cloud Gateways - Kong Docs Kong · checked Back to text

  37. Source 37: Serverless Gateways - Kong Docs Kong · checked Back to text

  38. Source 38: Zenity Subscription Terms and Conditions (EULA linked from Zenity's AWS Marketplace listings) Zenity · checked Back:ab

  39. Source 39: Kong AI Gateway | Kong Docs Kong · checked Back:abc

  40. Source 40: AI Gateway providers - Kong Docs Kong · checked Back:ab

  41. Source 41: Zenity Now Integrates with Microsoft Agent 365 Zenity · checked Back to text

  42. Source 42: Zenity Selected for AWS Security Hub Extended to Secure Enterprise AI Agents Zenity · checked Back to text

  43. Source 43: Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace Zenity · checked Back to text

  44. Source 44: MCP version support - Kong AI Gateway docs Kong · checked Back to text

  45. Source 45: Your company's private network Blocks.ai · checked Back to text

  46. Source 46: Network requirements Blocks.ai · checked Back to text

  47. Source 47: Solutions: Agent sprawl Blocks.ai · checked Back to text

  48. Source 48: Solutions: Partner networks Blocks.ai · checked Back to text

  49. Source 49: Pricing Blocks.ai · checked Back to text