Toolport is a local, open source MCP gateway: you configure and authenticate each MCP server once, and every AI client on the machine (Claude, Cursor, Codex, VS Code and others) points at the one gateway instead of carrying its own server configs. It is a Tauri desktop app for Windows, macOS and Linux with a separate toolport-gateway binary, MIT licensed under an open core model where the paid hosted or self hosted Teams service funds the free local app. Product Repository Privacy policy
The headline mechanism is lazy tool discovery. Instead of every connected server dumping its full tool schema list into the model context on every request, Toolport advertises four meta tools (toolport_status, toolport_search_tools, toolport_call_tool, toolport_fetch_result) that the agent uses to search and call tools on demand. Its published benchmark reports 74 percent total token reduction at 63 tools and 91 percent at 183 tools at identical graded task success, and a 99.5 percent cut in per request definition overhead on a real 415 tool catalog, with honest caveats: one frontier model, three read only list tasks, five runs each. Measured gateway overhead per tool call is about 0.75 ms. Benchmark
Beyond cost, Toolport positions the gateway as the agent tool trust boundary. It fingerprints every tool definition and flags rug pulls (an approved tool changing later) and tool poisoning (hidden instructions in descriptions), wraps flagged tool results with provenance markers, keeps API keys in the OS keychain instead of client config files, offers a one switch hide and block for destructive tools, and records a full audit trail. The posture is explicitly detection first rather than blocking, and the security page plainly states what a gateway cannot see: tool calls made by client native shells are outside its view. Security
Two newer layers extend this beyond servers. Agent rules let you write one ruleset (importing an existing CLAUDE.md or AGENTS.md) and apply it to every connected client without hand syncing. Agent permissions puts a policy in Claude Code's own rule syntax into Claude Code settings and enforces the same rules in Cursor through a guard hook. Agent rules Release notes
The project is young but moving fast and takes security reporting seriously: the repository shows about 196 stars, 50 forks and 1,289 commits, with recent releases fixing a real approval broker vulnerability (a local peer could have answered approval prompts and received call arguments, now gated by an HMAC challenge) and hardening Teams consent so a member's enablement no longer silently follows a changed server command. Teams, free for up to 5 people and 39 dollars per month beyond, syncs one governed server set across a team while each member's keys stay on their own machine. Latest release Teams