
30 Sep 2026
Kong ships AI Gateway 2.2 with MCP tool governance and identity-aware AI policies
Kong Inc. said Wednesday it generally available'd Kong AI Gateway 2.2, adding governed MCP tool access through a single endpoint, identity-aware AI policies, modality-aware cost management, native AWS IAM authentication for Amazon Bedrock AgentCore, and expanded provider support including Kimi, Microsoft Foundry, and Amazon SageMaker.
Enterprises keep bolting agents onto every API, and Kong is selling the control plane that decides which tools an agent can touch, who is behind the call, and what the multimodal bill looks like. Version 2.2 is not a new chatbot; it is gateway governance catching up to sprawl in the Model Context Protocol — the plug an agent uses to call tools — and to the identity on the call.
On Wednesday, 30 September 2026, Kong Inc. announced that Kong AI Gateway 2.2 is generally available. PR Newswire carries the release. The dateline is San Francisco. The page stamps the item Sep 30, 2026, 15:00 ET, which is 3:00 p.m. Eastern. Kong calls itself the AI Connectivity Company. The release says 2.2 is now in Kong Konnect, which Kong calls the AI Connectivity Platform, with no beta enablement required. That means a customer does not have to turn a beta on before this release is available. The deck says the new standalone platform adds unified MCP tool governance, modality-aware cost management, identity-aware AI policies, and wider provider support. The opening also says 2.2 brings a new AI-native user experience, advanced cost management, and broader model support. Those lines are Kong’s.
Kong’s account of the gap is speed. New models, agent designs, protocols, and price lists, the release says, are arriving in weeks rather than quarters. The tools a company uses to govern them are not keeping up. An agent, in this release, is software that takes a next step, such as calling a tool, rather than only answering a question. Kong says AI Gateway gives that traffic its own platform and its own release schedule. A company can take what is new without dropping security, compliance, cost control, resilience, or a clear view of what is running. The same-day product blog is headed “Kong AI Gateway 2.2: Built for what comes next in AI.” Alex Drag, head of product marketing, wrote it. The page dates it 30 September 2026, labels it a 4 min read, and does not print an hour. The blog’s name for the idea is strategic portability. A team should be able to pick the model, the provider, or the interface that fits the job without building a new set of rules every time that choice changes. Those lines are Kong’s.
The wire’s first capability is governed MCP tool access through one endpoint. MCP is the Model Context Protocol. It is the plug an agent uses to see tools and call them. A tool, here, is something the agent can do, such as look up a record or start a job in another system. MCP Server Bundling, Kong says, pulls a growing pile of MCP servers onto one Kong route. A route is the single address Kong publishes for that bundle. The route shows each caller only the tools that caller is allowed to see and to run. The other tools stay hidden. Those lines are Kong’s.
The next piece is identity-aware AI policies, powered by Kong Identity. Kong says rate limits, analytics, cost attribution, and access control can now key off an authenticated principal, instead of a Consumer that exists only on the gateway. A principal is the person or the agent that signed in. A Consumer, in Kong’s wording, is a caller account the gateway keeps locally. Cost attribution means the bill can be tied to that principal. The release says this is a consistent way to know who, or which agent, is behind every call. Those lines are Kong’s.
On price, the wire says the gateway now tracks how AI is actually billed. Dynamic, modality-aware pricing counts text, audio, image, and video separately. A modality is the kind of content: words, sound, a picture, or video. The same pricing also splits cache reads from cache writes. A cache read reuses a copy already stored. A cache write is the first save of that copy. Kong says platform teams and finance teams get a real cost split, instead of one flat estimate based only on tokens. A token is a small piece of text the model reads or writes. The wire also says 2.2 ships support for Headroom, for advanced prompt compression, as a way to hold the cost down. Prompt compression, as the product blog describes it, cuts the number of tokens sent to a model or returned by it, while keeping what the task needs. The blog calls the Headroom work a Tech Preview. It says Headroom uses output shaping and adaptive verbosity, which means the reply is trimmed to the task instead of a long default. Kong says it stays the main path out to the model. The integration records tokens saved, the compression ratio, and the changes applied. If Headroom is down or too slow, Kong says it can send the original content on, rather than failing the request. The wire’s word is support. The blog’s word is Tech Preview. Both are Kong’s account of its own integration. They are not an outside audit of how far a bill falls.
For Amazon Bedrock AgentCore, the wire says 2.2 adds native AWS IAM authentication. IAM is Amazon’s system for who may call what. The authentication is declarative and platform-managed, and it uses SigV4. SigV4 is Signature Version 4, the method AWS uses to sign a request so the service can check that the caller is allowed. Declarative, here, means the team states the rule and Kong applies it, instead of each app building the signature by hand. Kong says this replaces those hand-built workarounds for teams that already run agents and MCP servers on AgentCore inside AWS. Those lines are Kong’s.
On models, the wire says 2.2 adds native support for Kimi, Microsoft Foundry, and Amazon SageMaker. Kong says that is more choice in where a workload runs, without dropping the same governance. The release does not print a price for each of those providers. It also adds support for Jev. The wire calls Jev an emerging decision-oriented model. A developer can adopt it without a separate integration and a separate set of rules. The product blog calls that support TypeSafe Jev, and also JEV. The blog says Jev does not write a paragraph. It returns a typed, probabilistic decision that software can act on. Typed, here, means the answer has a shape the program expects. Probabilistic means the choice carries uncertainty, rather than a guaranteed fact. The blog says that cuts ambiguity and the extra tokens a long answer would cost. Its example is routing. Jev picks which model should handle a request, and Kong AI Gateway sends the request to that model. Teams keep the same gateway, the same rules, and the same operations they use for the rest of their AI traffic. Those lines are Kong’s.
The product blog lists more of the release than the wire’s bullet list. Skills APIs, Kong says, are a common way to use reusable, versioned Skills across the providers the gateway supports. A Skill, in that post, is a reusable capability a provider exposes, with a version, rather than a one-off prompt. Kong translates between its own representation and each provider’s format, so an app is not wired to one provider’s version of Skills. Passthrough mode is for workloads that do not match a standard provider format yet. Kong names self-hosted model servers such as vLLM, Ollama, and NVIDIA NIM, provider preview APIs whose shape is still changing, and specialized endpoints that are not large language models. A large language model is the kind of model that reads and writes text. In passthrough mode Kong forwards the request and the response without rewriting the body. It still applies the provider’s authentication, Kong’s own authentication, rate limits, and logging. Custom plugins can now live in the AI Gateway control plane. The control plane is where the rules are set. The data plane is where the traffic flows. Kong says plugins can be streamed from the control plane to data planes, or installed on a data plane directly. A platform team can add logic that is specific to that company. AI Rate Limiting Advanced, the blog says, can now match on a credential. A credential is the key or login the caller presents. A limit can sit on that credential, which matters when several credentials share the same models. Those lines are on the product blog. They are Kong’s.
Reza Shafii, senior vice president of product at Kong, is quoted in the wire. He said the update is one of the most exciting changes the company has made. He said the promise of this kind of AI is not only what an agent can do. It is whether a company can put that agent to work with confidence. That, he said, takes visibility into what is happening, control over what agents can reach and run, and a way to manage the risks and the economics. He called that the foundation of AI governance Kong is giving customers with AI Gateway 2.2, and what will make this kind of AI workable in the enterprise. That quotation is his, in Kong’s release.
The about box describes the company. It says Kong is building the connectivity layer of AI. It says Kong is trusted by the Fortune 500 and by AI-native startups. It says the platform is there to secure, manage, speed up, govern, and charge for traffic across APIs and AI, on any model and any cloud. An API is the hook one piece of software uses to call another. That Fortune 500 line is Kong’s description of the company. The release does not say how many of those companies are running 2.2, and it does not print revenue. The wire points readers to the Kong AI Gateway product page. The source line is Kong Inc.
The picture is Kong’s launch graphic for AI Gateway 2.2. On a black field, the title is KONG AI GATEWAY 2.2 in neon green. A line-drawn gorilla, the company’s mascot, sits in the same green, with circuit traces in the drawing. The line under the title reads: Streamline AI Models, Custom Plugins, Passthrough Mode, and Token Compression. A Learn More mark is on the graphic. It is the company’s art for this release. It does not print a calendar date.
In plain terms, Kong said on Wednesday that AI Gateway 2.2 is generally available in Kong Konnect. A customer does not have to turn on a beta. The wire covers one route for MCP tools, rules that follow the signed-in person or agent, a bill split by text, audio, image, and video, AWS sign-in for Bedrock AgentCore, and support for Kimi, Microsoft Foundry, Amazon SageMaker, and Jev. The same-day product blog adds Skills, passthrough for custom model servers, custom plugins, rate limits on a credential, and a Tech Preview of Headroom. Headroom, as Kong describes it, shortens prompts to cut what a company pays in tokens. The release does not print a customer count or a revenue figure.
RELATED
Sources
- Kong — AI Gateway 2.2, 30 Sep 2026
konghq.com
- PR Newswire — Kong AI Gateway 2.2, 30 Sep 2026
prnewswire.com