Scanner, gateway, allow-list, gate
Four categories separated by when they act and what they can do about it. Only one is contract-aware and in the call path.
Read Fig. 13 as text
what it +-----------------------------------------------------------+
can do | |
| * mcpindex gate |
HOLD -------| contract-aware, in-path |
| |
| * allow-list / auth * API gateway |
BLOCK -------| gates identity, gates the network, |
| not the contract contract-blind |
| |
ADVISE -------| * static scanner * audit log |
| reads it once tells you after|
+-----------------------------------------------------------+
BEFORE INSTALL AT INSTALL IN THE CALL PATH AFTER
when it acts
categories, not vendors. the axes are factual: when a control runs, and what
it is able to do when it runs.A positional map of four tool categories by when they act and what they can do. A static scanner reads a server before install and can only advise. An allow-list or authentication check acts at install time and gates identity rather than the contract. An API gateway acts in the call path but at the network layer and is contract-blind. An audit log acts after the fact and can only tell you. The mcpindex gate acts in the call path, is contract-aware, and can hold. Categories only; no vendor is named.
Licensed CC BY 4.0. Use it anywhere, including commercially. Keep the credit.
Paste under the figure. That is the whole licence obligation.
<a href="https://mcpindex.ai/diagrams/category-map">Scanner, gateway, allow-list, gate - mcpindex.ai</a> (CC BY 4.0)Standalone image/svg+xml. Vector, editable, no stylesheet needed.
https://mcpindex.ai/diagrams/category-map/svgLast reviewed 2026-07-27
mcp scanner vs gateway · mcp security tools comparison · mcp allow list vs gate · trust to act