Citrix turns NetScaler into a gateway that governs MCP traffic
Auth, allow lists, tool-level rate limits, and per-team usage tracking for agent-to-tool traffic. The network vendors have decided MCP is plumbing, and they sell the valves.
- Citrix added MCP Gateway capabilities to NetScaler, giving enterprises a central point to route, authenticate, monitor, and rate-limit AI agent traffic to backend MCP servers.
- Features include per-user and global tokens, OAuth and hybrid flows, server allow and block lists, tool-level rate limiting, session persistence for multi-step workflows, and token usage tracking by team, user, or application.
- Citrix is aiming it at financial services, healthcare, and government.
Citrix has added MCP Gateway capabilities to NetScaler, its application delivery controller, positioning the box that already fronts enterprise web traffic as the control point for AI agent traffic too, the company announced.
What the gateway does
The feature list is the enterprise checklist MCP has been missing: per-user and global token management, OAuth and hybrid authentication flows, allow and block lists for MCP servers, rate limiting down to the individual tool, session persistence so multi-step agent workflows survive, protocol-aware health monitoring, and content-switching-based model routing with token usage visibility by team, user, or application, per Help Net Security. Target sectors are financial services, healthcare, and government. Citrix is also privately previewing a Claude Code use case, according to Cyberpress, a detail worth watching given how fast that tool is landing inside enterprises.
The pilot-to-production gap, sold as hardware
Once Microsoft turned MCP into a certified distribution channel, it was inevitable that the network vendors would show up to sell the governance layer. This is what a protocol winning looks like: not more servers, but appliances that assume the servers exist and fight over who controls access to them. For anyone exposing or consuming MCP servers, gateway-level auth and rate limiting is precisely the piece that separates a pilot from a production deployment, and until now the answer was mostly do-it-yourself proxies. The security argument writes itself after a quarter in which an agent platform landed on CISA's must-patch list: a choke point you govern beats a sprawl you discover.