Exposes the full Kong Gateway Admin API as MCP tools, enabling AI assistants to manage services, routes, consumers, plugins, upstreams, and more.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
process.env. You'll be asked to provide them before it can run.KONG_ADMIN_HEADERS— _(none)_ Extra headers, e.g. X-Foo: bar or a JSON objectKONG_ADMIN_TOKEN— _(none)_ Sent as the Kong-Admin-Token header (RBAC)KONG_ADMIN_URL— env =http://localhost:8001 \KONG_TLS_INSECURE— false true to skip TLS verification (self-signed certs)KONG_WORKSPACE— _(none)_ Default EE workspace to scope requests to[](https://m8ven.ai/mcp/monohitoxx-kongapigateway-mcp-server-k4w75q)