Citrix says new NetScaler MCP Gateway capabilities provide a centralized layer for routing, authentication, policy enforcement, rate limiting and observability across traffic between AI clients and Model Context Protocol servers. The company is also adding model-routing and token-usage tracking features for large la...
Citrix has introduced NetScaler MCP Gateway capabilities intended to centralize controls for traffic between AI clients and backend Model Context Protocol (MCP) servers.
In its announcement, Citrix said the capabilities can route, govern, authenticate, rate-limit and observe AI-agent traffic directed to MCP servers. The company also described model routing and token-usage tracking features for large language model (LLM) traffic.
MCP is used to connect AI applications to tools, services and data sources. As organizations give AI systems access to more internal and external services, they need ways to define which services may be reached, apply authentication and authorization requirements, and monitor how requests are handled.
NetScaler documentation describes MCP Gateway as a control layer between MCP clients and backend MCP servers. This placement allows the gateway to apply routing, authentication, policy enforcement and rate limits before requests are passed to connected services.
According to the MCP Gateway documentation, the product supports centralized routing and security controls for MCP connections. NetScaler’s separate AI capabilities documentation lists access control, authentication, rate limiting and tool-use monitoring among its functions.
A centralized gateway can give administrators a common point for applying policies across multiple AI applications and MCP servers. Rather than requiring equivalent rules to be configured separately for each connection, teams can use the gateway layer to manage traffic controls consistently.
Citrix is pairing MCP controls with features aimed at LLM traffic. The company said NetScaler can route model requests and track token usage. Model routing can be used to direct requests to different models according to an organization’s policies or an application’s requirements.
Token tracking matters because LLM usage is often measured in tokens, with consumption affecting both expenditure and capacity planning. Citrix’s announcement does not detail the supported model providers or deployment options, but the stated feature set is intended to give organizations visibility into model consumption at the network gateway layer.
The NetScaler AI documentation also refers to Kubernetes-aware AI gateway capabilities, indicating that the product is designed for environments where AI applications and related services run on containerized infrastructure.
Citrix’s release reflects an infrastructure challenge created by AI systems that can use external tools. Governance in those deployments extends beyond the choice of model: organizations must control access to backend services, establish rules for requests, and maintain visibility into system activity.
NetScaler MCP Gateway is Citrix’s proposed intermediary for those functions. Its documented role is to sit between MCP clients and servers, enforcing traffic and access policies while Citrix extends routing and usage reporting to LLM requests. The practical results will depend on how customers configure identities, authorization rules, monitoring and service integrations.
In its announcement, Citrix said the capabilities can route, govern, authenticate, rate limit and observe AI agent traffic directed to MCP servers.
The company also described model routing and token usage tracking features for large language model (LLM) traffic.
MCP is used to connect AI applications to tools, services and data sources.
Continue reading