Diagrams · Fig. 13

Scanner, gateway, allow-list, gate

Four categories separated by when they act and what they can do about it. Only one is contract-aware and in the call path.

Scanner, gateway, allow-list, gateA positional map of four tool categories by when they act and what they can do. A static scanner reads a server before install and can only advise. An allow-list or authentication check acts at install time and gates identity rather than the contract. An API gateway acts in the call path but at the network layer and is contract-blind. An audit log acts after the fact and can only tell you. The mcpindex gate acts in the call path, is contract-aware, and can hold. Categories only; no vendor is named.HOLDstops the call before it runsBLOCKstops traffic, not the contractADVISEtells you, cannot interveneWHAT IT CAN DOBEFORE INSTALLAT INSTALLIN THE CALL PATHAFTERWHEN IT ACTSstatic scannerreads the server onceallow-list / authgates identity, not the contractAPI gatewaygates the network, contract-blindaudit logtells you afterin-path trust gatecontract-aware, can HOLDCATEGORIES, NOT VENDORS. THE AXES ARE FACTUAL: WHEN A CONTROL RUNS, AND WHAT IT IS ABLE TO DO WHEN IT RUNS.
Fig. 13 · Four categories separated by when they act and what they can do about it. Only one is contract-aware and in the call path.
Read Fig. 13 as text
  what it       +-----------------------------------------------------------+
  can do        |                                                           |
                |                              * mcpindex gate              |
   HOLD  -------|                              contract-aware, in-path      |
                |                                                           |
                |        * allow-list / auth        * API gateway           |
   BLOCK -------|        gates identity,            gates the network,      |
                |        not the contract           contract-blind          |
                |                                                           |
  ADVISE -------|  * static scanner                          * audit log    |
                |  reads it once                             tells you after|
                +-----------------------------------------------------------+
                   BEFORE INSTALL    AT INSTALL    IN THE CALL PATH   AFTER
                                        when it acts

  categories, not vendors. the axes are factual: when a control runs, and what
  it is able to do when it runs.
What the figure says

A positional map of four tool categories by when they act and what they can do. A static scanner reads a server before install and can only advise. An allow-list or authentication check acts at install time and gates identity rather than the contract. An API gateway acts in the call path but at the network layer and is contract-blind. An audit log acts after the fact and can only tell you. The mcpindex gate acts in the call path, is contract-aware, and can hold. Categories only; no vendor is named.

Where this is explained
Use this diagram

Licensed CC BY 4.0. Use it anywhere, including commercially. Keep the credit.

Credit line (HTML)

Paste under the figure. That is the whole licence obligation.

<a href="https://mcpindex.ai/diagrams/category-map">Scanner, gateway, allow-list, gate - mcpindex.ai</a> (CC BY 4.0)
Direct SVG

Standalone image/svg+xml. Vector, editable, no stylesheet needed.

https://mcpindex.ai/diagrams/category-map/svg

Last reviewed 2026-07-27

Questions this answers

mcp scanner vs gateway &middot; mcp security tools comparison &middot; mcp allow list vs gate &middot; trust to act