agentgateway vs Bifrost

The question that decides it: Do you want the whole feature set in one Apache-2.0 build from a foundation project, or a generous free build from one vendor with guardrails, clustering and SSO behind a quote?

Our verdict

Routing plain LLM traffic and wanting semantic caching, a prompt repository and audio and image modalities now: Bifrost, accepting that guardrails, cluster mode, SSO, RBAC, audit logs and air-gapped installs are an Enterprise conversation at custom pricing. Routing MCP or A2A agent traffic, or needing PII masking and moderation in the free build: agentgateway, where nothing is gated.

Why

Start with an honest boundary, because these two are not rivals across their whole surface. They overlap squarely in the middle: both are Apache-2.0, self-host only, zero token markup, no seat fee and BYOK-only; both are an OpenAI-compatible base-URL swap for existing clients; both are real MCP gateways with tool filtering; both ship virtual keys, per-key budgets, rate limits, fallback and load balancing, config-as-code and OpenTelemetry export to collectors you run; and in both cases request logs stay in a database you operate. Inside that overlap the choice below is a genuine one. Outside it they answer different questions. agentgateway is also a general-purpose HTTP and gRPC data plane with A2A agent traffic as a first-class protocol alongside MCP, which is a shape Bifrost's record does not describe. Bifrost is a routing proxy that is also embeddable as a Go library (go get github.com/maximhq/bifrost/core) and is the open front end of Maxim AI's commercial platform. If either of those descriptions is what you need, the comparison is over before the feature table.

Within the overlap, the feature edges run in both directions and they are specific. Bifrost has caching agentgateway does not: exact-match and semantic caching, both in the free tier, against agentgateway's provider-side prompt-cache breakpoint control and nothing else. Bifrost also carries a prompt repository in the free tier, where agentgateway records no prompt-management surface at all; audio in both directions through Hugging Face, ElevenLabs and vLLM, where agentgateway's only audio path is a realtime WebSocket proxy whose documented examples are text-only; image support behind its common interface, where agentgateway documents no image route type; a Terraform module and a documented LangChain integration, neither of which agentgateway has. agentgateway leads on breadth of routed catalogue — a headline 1002+ models and 44+ providers on its cookbook, 20 of them natively documented with a capability matrix, against Bifrost's 23+ on GitHub and 20+ in its docs with no model total published — and on guardrails, which is the sharpest single difference.

That guardrail difference is really a licensing difference, and it is the axis. agentgateway's guards are in the Apache-2.0 build and they enforce rather than observe: named regex PII patterns for credit cards, SSNs, email and phone numbers defaulting to mask, external moderation through OpenAI, Bedrock Guardrails, Google Model Armor and Azure Content Safety defaulting to reject, a webhook guard for your own classifier, and a separate guardrail surface for MCP traffic. Bifrost's guardrail suite is arguably richer in the abstract — Microsoft Presidio, Azure AI Language PII, Gitleaks-based secret detection, Bedrock Guardrails, Model Armor and several dedicated vendors, with the most nuanced redaction model in this catalogue in logs_only, runtime and runtime_reversible modes — but it sits in the Enterprise tier, alongside cluster mode, adaptive load balancing, SAML/OIDC SSO, RBAC, audit logs, vault integration, log exports and the VPC, on-prem and air-gapped deployment paths, all at "Custom Pricing" after a 14-day trial. agentgateway has a commercial edition too, Solo Enterprise for agentgateway, whose pricing is likewise not published — but it is a distribution of the same project rather than the gate on features the open build lacks.

The remaining separator is who stands behind each, and how each behaves with your data by default. agentgateway is vendor-neutral: created by Solo.io, donated to the Linux Foundation in 2025, an Agentic AI Foundation hosted project in 2026, with 300+ contributors across 60+ organisations including CoreWeave, Red Hat, Adobe, Salesforce, Amdocs and Microsoft, and correspondingly nothing to show an auditor — no SOC 2, ISO, HIPAA posture or SLA is published. Bifrost is one company: Maxim AI, founded 2023, US-based, funded by a $3M seed led by Elevation Capital, holding SOC 2 Type 2 at company level, reporting GDPR compliance on its governance page, publishing a 99.999% uptime figure on its enterprise deployment page — and carrying its own contradictions, with ISO 27001 and HIPAA marked compliant on the trust centre and in progress or not applicable on the governance page. Bifrost is ahead on stars, 7,600 against 4,691. Defaults differ too: Bifrost logs full content by default, offloads every offloadable payload field to object storage by default and defaults to 365-day retention, while agentgateway logs metadata only until you opt in and documents no retention setting at all, which means nothing prunes your tables unless you build it.

Which one, concretely

Choose agentgateway if

  • You route MCP or A2A agent traffic, or want one data plane in front of ordinary HTTP and gRPC as well
  • You need PII masking and moderation without buying a tier: regex guards default to mask, external guards default to reject
  • You want vendor-neutral governance — Linux Foundation donation in 2025, AAIF hosted project in 2026, 300+ contributors across 60+ organisations
  • You are moving off LiteLLM and want the documented conversion path, agentgateway import --from litellm, with per-field compatibility findings

Choose Bifrost if

  • You want exact-match and semantic caching in the free build; agentgateway has neither
  • You need audio in both directions and image support behind one common interface
  • You want a prompt repository alongside budgets, virtual keys and an MCP gateway in the Free Forever tier
  • You want one vendor to buy cluster mode, SSO, RBAC, audit logs, air-gapped deployment and a published 99.999% uptime figure from later

What catches people out

Side by side

5 of 17 fields differ, marked with a dot. Every figure links to the vendor page it came from. Blank values read Not published rather than No — silence from a vendor is not a negative answer.

Field agentgateway Bifrost
Ease of leaving Derived score, higher is easier 100/100 Easy to leave 100/100 Easy to leave
What kind of product Category Open source Open source
Who runs it Deployment model Self-host only Self-host only
Licence Licence Apache-2.0 Apache-2.0
Models available Models available ~1,002 Not published
Model providers reachable Upstream providers 20–44 20–23
Markup on model prices Token markup None None
Fee to add funds Credit purchase fee Not published None
Monthly cost per person Seat fee None None
Similar-question caching Semantic cache No Yes
Content guardrails Content guardrails Yes Yes
Prompt versioning Prompt management Not published Yes
Speech and audio Speech and audio Not published Yes
Runs fully disconnected Air-gapped deployment Not published Yes
How long they keep it Default content retention (days) Not published 365 days
GitHub stars GitHub stars 4,985 8,359
Delay it adds Proxy overhead 0.863 ms 0.99 ms
Requests per second ceiling Throughput 35,502 rps 5,000 rps

for agentgateway and for Bifrost. Want more fields, or a third option in the mix? Open these two in the full comparison tool.

Common questions

Are agentgateway and Bifrost really alternatives to each other?

Partly. They genuinely overlap on OpenAI-compatible LLM routing, MCP gateway duties, virtual keys, budgets, rate limits and config-as-code, all self-hosted under Apache-2.0, and in that zone the comparison is real. Outside it they differ in kind: agentgateway also routes A2A agent traffic and ordinary HTTP and gRPC, which Bifrost does not document, and Bifrost is embeddable as a Go library, which agentgateway is not.

Which one is genuinely free?

Both are Apache-2.0 with no vendor charge, but the free builds are not equivalent. agentgateway gates nothing — guardrails, budgets, virtual keys, MCP and A2A are all in the open build, and Solo Enterprise for agentgateway is a commercial distribution of the same project. Bifrost calls its OSS tier Free Forever and includes semantic caching, MCP, budgets, virtual keys and a prompt repository, but guardrails, clustering, SSO, RBAC and audit logs are Enterprise-priced on quote.

Which one is faster?

Both publish sub-millisecond overhead from their own harnesses against mock upstreams, so neither number should decide anything. agentgateway reports p50 0.863 ms and 35,502 QPS from Fortio runs against a mock backend. Bifrost reports 0.99 ms derived from a 60.99 ms median against a mock holding 60 ms, plus a 5,000 RPS Bifrost-only stress run; against real OpenAI on a t3.medium it sustained 424 requests per second. LiteLLM's competing benchmark measured Bifrost at 4.54 ms added p99.