Kong Gateway

Prev Next

The PlainID integration for Kong Gateway enforces PlainID Policies directly at your gateway. You can govern REST APIs, MCP servers, and LLM traffic under the same Policies you already manage in PlainID, without changing your upstream services.

The integration runs as a set of Kong plugins on your own Kong data plane. You install the plugins once, then attach them to the routes you want to protect. Kong handles the traffic and the plugin configuration, and PlainID evaluates each transaction against your Policies in real time. When you change a Policy, the change applies on the next request, with no redeploy and no Kong configuration change.

The PlainID Plugins

PlainID provides four plugins. Three of them enforce Policies, one for each kind of route. The fourth sends transactional data to PlainID and runs alongside any of the others.

Plugin Attach it to What it does
plainid-api-authz REST API routes Asks PlainID to permit or deny each request. Kong blocks denied requests before they reach your API.
plainid-mcp-authz MCP server routes Filters the tool list so each caller sees only the tools its Policies allow, and authorizes every tool call. It can also report each MCP server's tool inventory to PlainID for discovery.
plainid-prompt-authz LLM routes served by Kong AI Gateway Applies Prompt Control to the input: checks which content categories the prompt touches and blocks prompts the caller may not send. Applies Output Control to the output: masks or encrypts sensitive data in the model's response before it reaches the caller.
plainid-insights Any route Sends transactional data for each inbound request to the PlainID Collector, which PlainID uses for agentic insights. It never blocks or changes a request.

How It Works

For each request on a protected route:

  1. A Kong authentication plugin, such as openid-connect or jwt, identifies the caller.
  2. The PlainID plugin sends the caller's identity and the request details to the PlainID Policy Decision Point (PDP).
  3. The PDP evaluates your Policies and returns a decision.
  4. The plugin forwards permitted requests to the upstream service and blocks denied ones. For LLM routes, the plugin can also mask the model's response on the way back.

If a plugin cannot reach PlainID, or cannot verify what it would forward, it denies the request instead of letting it through.

AI Gateway Authorization Architecture (1).png

Each Kong route serves exactly one kind of traffic: a REST API, an MCP server, or an LLM endpoint. Attach exactly one enforcement plugin to each route: plainid-api-authz, plainid-mcp-authz, or plainid-prompt-authz. Each plugin reads the request body in its own format, so two enforcement plugins on the same route misread each other's traffic. PlainID does not support this configuration.

plainid-insights is the exception. You can attach it to any route alongside one of the enforcement plugins.

Supported Deployments

The plugins run on self-managed Kong Gateway data planes, including on-premises deployments and data planes connected to a Kong Konnect control plane.

MCP tool discovery and plainid-insights require a data plane connected to a Konnect control plane. On a data plane without Konnect, plainid-api-authz, plainid-mcp-authz, and plainid-prompt-authz still enforce Policies, but PlainID receives no tool inventories and no transactional data.


See Configuring Kong to install the plugins and configure them on your routes.

© 2026 PlainID LTD. All rights reserved.