DXH Gateway Community Edition. Install and docs: https://github.com/DXHeroes/mcp-gateway
10K+
Self-hosted governance for MCP tools: one endpoint in front of your MCP servers, with profiles, per-tool permissions, approvals and an audit trail.
This is the public Community Edition (CE) image. Installation materials, documentation and the CE terms live at github.com/DXHeroes/mcp-gateway.
CE is free for eligible production use in companies with at most 50 employees including affiliates, and for nonproduction evaluation at any company size. It includes 25 active accounts, one organization, one REST/OpenAPI connection and one active gateway instance. MCP connections, profiles and tool calls have no commercial quota. Enterprise Edition and trials: [email protected].
latest tagdocker pull dxheroes/mcp-gateway-ce # fails: manifest unknown
docker pull dxheroes/mcp-gateway-ce:<version> # a release, for example v0.4.0
That is deliberate. A moving latest would hand you a breaking configuration change with no
warning. Pin a version, or better the digest from that release's release.json. If you would
rather take every release of a major as it comes, pin the compatibility line vX instead: it
moves, but only inside one major.
| Tag | What it is |
|---|---|
vX.Y.Z | A release. Immutable: never overwritten. |
vX.Y, vX | Compatibility lines: the newest patch of that minor, and the newest release of that major from 1.0.0 on. They move, but never across a breaking change — that bumps the major. No v0 exists, because a pre-1.0 minor may break compatibility. |
vX.Y.Z-beta.N, beta | Built from every change to the development branch. Audited, scanned and signed like a release, but unsupported; beta moves without notice. Not for production. |
sha256-….sig | Cosign signatures. Not images. |
This repository is a copy of ghcr.io/dxheroes/mcp-gateway-ce, not a second build: both serve
the same digest with the same SBOM and build provenance for linux/amd64 and
linux/arm64. Pull from whichever registry suits you. Releases older than the mirror itself
(up to and including v0.3.0) exist only on GHCR.
Follow the installation guide.
In short: take compose.yaml and .env.example from the public repository, set GATEWAY_IMAGE
to the image and digest from release.json, generate the two secrets, read LICENSE-CE.txt
and record your acceptance in GATEWAY_CE_TERMS_ACCEPTED, then:
docker compose config
docker compose pull
docker compose up -d --wait
The gateway refuses to start until the CE terms are accepted. It needs PostgreSQL; the supplied Compose file brings one.
Every image is signed with keyless Cosign by the release workflow:
cosign verify dxheroes/mcp-gateway-ce@sha256:<digest> \
--certificate-identity "$(jq -r .signingIdentity release.json)" \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
Full procedure, SBOM and provenance: image verification. Upgrading between versions: upgrade notes.
The image is distributed under the DXH Gateway CE terms (LICENSE-CE.txt in the public
repository). No service source is published.
Content type
Image
Digest
sha256:291fd7e1b…
Size
255 Bytes
Last updated
about 16 hours ago
docker pull dxheroes/mcp-gateway-ce:sha256-87d68ce740ab49d6e240f756ce00da408429a01ed3a7cd82066e850db8f01bd0.sig