AI Models & Platforms

Kong Ships AI Gateway 2.2 With MCP Tool Governance, Identity Policies

mm
Add Unite.AI to your preferred sources on Google

Kong Inc. announced the general availability of Kong AI Gateway 2.2 on September 30, 2026, adding governed access to MCP tools, identity-aware AI policies, modality-aware cost management, and broader model and provider support. The release is available in Kong Konnect, the company’s AI Connectivity Platform, with no beta enablement required.

Kong said the release is built for an increasingly diverse AI ecosystem, in which new model architectures, new provider APIs, self-hosted models, and specialized AI services are making the interfaces connecting enterprise AI more diverse rather than less. The company describes AI Gateway as giving AI its own platform and release cadence, so enterprises can adopt what is next in AI without compromising security, compliance, cost control, resilience, or visibility. Kong frames the 2.2 update around a goal it calls strategic portability: developers should be able to adopt the right AI technology for the job without creating a new infrastructure and governance stack every time the underlying model, provider, or interface changes.

Tool and Identity Governance

MCP Server Bundling consolidates multiple MCP servers into a single Kong route, revealing only the tools each caller is authorized to see and execute. Identity-aware AI policies, powered by Kong Identity, let rate limiting, analytics, cost attribution, and access control key on an authenticated principal rather than a gateway-local Consumer, which Kong says gives enterprises a consistent way to know who, or what agent, is behind every call.

The release adds native AWS IAM authentication for Amazon Bedrock AgentCore, which Kong describes as declarative, platform-managed SigV4 authentication that replaces hand-rolled workarounds for AWS-native teams running agents and MCP servers on AgentCore. Separately, the AI Rate Limiting Advanced plugin gains credential-based matching, so policies can use a credential as a matching dimension; Kong says this gives organizations a more granular way to control AI consumption where multiple credentials access the same models or AI services.

Expanded Model and Interface Support

AI Gateway 2.2 adds native support for TypeSafe JEV as a provider and a format, including its decisions capability. Kong describes JEV as returning typed, probabilistic decisions that software can act on directly rather than generating text, and says JEV can work with the gateway to inform intelligent LLM routing, deciding which model should handle a request while Kong AI Gateway executes the routing to the selected model. The release also adds support for Skills APIs, with Kong translating between its common representation and provider-specific formats so teams can work with reusable, versioned Skills across supported providers without hardwiring applications to a single implementation. Native support for Kimi, Microsoft Foundry, and Amazon SageMaker was added as well.

A new passthrough mode covers AI workloads that use custom or non-standard interfaces, including self-hosted model servers such as vLLM, Ollama, and NVIDIA NIM, provider preview APIs with evolving schemas, and specialized non-LLM AI endpoints. In passthrough mode, Kong forwards requests and responses without transforming the body, while preserving capabilities such as upstream provider authentication, Kong authentication, rate limiting, and logging.

Cost Management and Extensibility

Dynamic, modality-aware pricing tracks text, audio, image, and video separately, along with cache reads versus cache writes; Kong says this gives platform and finance teams accurate cost attribution instead of flat, token-based estimates. A Tech Preview integration with Headroom applies prompt compression to reduce output token consumption using output shaping and adaptive verbosity, while Kong remains the primary LLM egress point. The integration captures metrics including tokens saved, compression ratio, and transformations applied, and if Headroom is unavailable or times out, Kong can forward the original content rather than interrupting the AI request.

AI Gateway 2.2 also adds support for custom plugins in the AI Gateway control plane, including streaming custom plugins from the control plane to data planes as well as plugins installed directly on the data plane. Kong says this brings the extensibility enterprises expect from its API infrastructure into AI Gateway, letting platform teams add organization-specific logic and policies that fit their own architecture, security, and governance requirements.

Executive Statement

“The promise of agentic AI is not just about what an agent can do, but whether an enterprise can confidently put it to work,” Reza Shafii, Senior Vice President of Product at Kong, said in the company’s release. That foundation of AI governance, he said, requires visibility into what is happening, control over what agents can access and execute, and the ability to manage the risks and economics that come with it, which he described as what will make agentic AI viable in the enterprise.

Kong describes itself as the AI Connectivity Company, building the connectivity layer of AI, with a unified API and AI platform that secures, manages, accelerates, governs, and monetizes API and AI traffic. The company’s announcement post, written by Alex Drag, Head of Product Marketing, was published September 30, 2026.

Aiden Cross is an AI-generated strategist at Unite.AI, covering AI product strategy, execution, and the practical challenges of turning experimental models into scalable, market-ready products. His work focuses on how startups and enterprise teams move from prototypes and demos to reliable systems used by real customers.

With a pragmatic and detail-oriented perspective, Aiden analyzes product roadmaps, go-to-market strategies, platform decisions, and organizational trade-offs that determine whether AI initiatives succeed or stall. He pays particular attention to deployment realities, user adoption, infrastructure constraints, and the alignment between technical capability and business value.

Articles authored by Aiden Cross are AI-generated and reviewed by Unite.AI’s editorial team to ensure clarity, accuracy, and responsible coverage of how AI products are built, shipped, and scaled in the real world.