ToolHive

Runs each MCP server in its own container with a proxy, registry, and secrets management.

Open SourceSelf HostedOffline Capable
0.0 (0)

About

Running an MCP server straight from npx hands it the host shell; Stacklok's ToolHive instead launches each server in its own container behind an HTTP or SSE proxy, so tools get isolation, network controls, and encrypted secret management by default. The Apache-2.0 project, written in Go, ships three ways: a CLI and a desktop app for individual developers, and a Kubernetes operator for platform teams running MCP infrastructure fleet-wide. A built-in registry curates trusted servers, OIDC and OAuth handle single sign-on, and OpenTelemetry plus Prometheus provide monitoring; the proxy layer also claims token usage reductions of up to 85 percent through optimization. It works with every major MCP client, from Claude Code and Cursor to custom agents, and requires only a container runtime such as Docker or Podman on the local machine. With around 2,000 GitHub stars and more than 4,000 commits, it has become one of the main answers to the emerging question of how to run third-party MCP servers without trusting them completely.

Should you use ToolHive?

Pick it when

Pick ToolHive when you run third-party MCP servers and do not want them touching your host: each server gets its own container with network controls and encrypted secrets, from a desktop app up to a Kubernetes operator.

Look elsewhere when

Skip it if you cannot run Docker or Podman, or if your servers are trusted code and you only need one endpoint for many clients, where MCPJungle is simpler. For REST and gRPC translation, ContextForge goes further.

Alternatives to ToolHive

  • MCPJungle

    Lightweight registry and gateway with tool groups; simpler for trusted servers, but it routes to servers rather than isolating them.

  • IBM ContextForge

    Federates MCP, A2A, REST, and gRPC behind one governed gateway; broader integration, heavier stack with PostgreSQL and Redis.

  • E2B

    Isolated cloud sandboxes for AI-generated code; the right isolation tool when the risk is agent-written code rather than MCP servers.

Reviews (0)

Leave a Review

No reviews yet. Be the first to review!

Details

Price
Free
Platform
Local/Desktop
Difficulty
Easy (2/5)
License
Apache-2.0
Added
Aug 24, 2026

Tags