Market map / Battle
Market map · scheduled battle

The MCP and AI-tool-integration ecosystem

September 13 at 20:57 · $0.147 total

gpt-5.6-luna-pro wins
judged by claude-fable-5 · both position-swapped passes agree
“Sharper segmentation (incl. app vendors as tools), more accurately placed real players (Invariant Labs, Docker, Composio), and denser value-flow/white-space reasoning; A's security list is vague guesses.”
deepseek-v4-pro
$0.03368s7608 tokens

Thesis MCP is restructuring AI-tool integration from closed, per-vendor function-calling into an open middleware stack—hosts, servers, registries, gateways and governance—shifting value away from model providers toward the integration and control plane.

---

1. Protocol & model layer

Companies: Anthropic, OpenAI, Google DeepMind (less sure on full MCP depth), Microsoft (less sure) Dynamics: Anthropic created MCP, but OpenAI, Google and Microsoft are converging on it to avoid being shut out of tool connectivity; this commoditizes raw tool-calling as a model differentiator.

2. Client/host applications & agent workbenches

Companies: Claude desktop, ChatGPT desktop, Cursor, Windsurf (less sure on ownership/MCP depth), Zed (less sure), Cline Dynamics: These own the user workflow and are adding MCP support fast; MCP lowers integration switching costs but dramatically expands the tool surface each host can offer.

3. Registry & developer tooling

Companies: Smithery, PulseMCP, Glama, Mintlify (less sure), Speakeasy (less sure), Stainless (less sure) Dynamics: Fragmented and discovery-driven; competition is shifting from simple directories toward hosted, searchable, validated server catalogs and API-to-MCP generation.

4. Managed integration, gateway & iPaaS layer

Companies: Cloudflare, Zapier, Composio, Apify, ngrok (less sure), Hookdeck (less sure) Dynamics: This is becoming the revenue-grade control plane: auth, routing, rate limiting, caching, observability and multi-tenant policy enforcement for MCP traffic.

5. Security, governance & trust

Companies: Prompt Security (less sure), Aim Security (less sure), Lasso Security (less sure), HiddenLayer (less sure), Cyberhaven (less sure), Nightfall AI (less sure) Dynamics: Enterprise urgency is high, but MCP-native enforcement is still early; most players are adjacent GenAI security or DLP vendors extending toward MCP rather than building natively on it.

---

Where most value accrues

Long-term, segment 4 — managed integration/gateway — wins the most durable value. It becomes the chokepoint between hosts, servers and enterprise policy: every MCP call can flow through it for authentication, data redaction, cost controls, audit and multi-model routing. That gives it high switching costs and monetization per call/seat without owning the model or the end-user application. Client workbenches may capture more near-term revenue, but the gateway layer is the structural control point.

---

White-space opportunities

  1. MCP-native zero-trust data governance and consent broker
  2. A proxy that intercepts MCP tool calls and responses, applies field-level PII/PHI/payment-data redaction, user-level consent prompts, egress allow-listing and audit-ready logs across arbitrary MCP servers and hosts. No current player cleanly owns this end-to-end; security vendors are mostly prompt-focused or endpoint/web DLP rather than MCP tool-payload-native.
  3. MCP server certification and continuous trust/quality platform
  4. A CI/CD-style harness that runs sandboxed MCP servers, tests tool schemas, detects breaking changes and drift, measures latency/uptime, scans dependencies and egress behavior, and publishes a trust score. Registries list servers, but nobody owns the “app store review” or certification layer at scale.
gpt-5.6-luna-pro · winner
$0.01036s6931 tokens

1) Thesis

The MCP and AI-tool-integration market is being restructured from bespoke, point-to-point API integrations into a standardized “tool layer,” with value migrating toward the control planes that discover, authenticate, govern, observe, and monetize tool access—not merely the protocol itself.

2) Market map

Segment 1: MCP protocol, model runtimes, and agent platforms

| Companies | Role | |---|---| | Anthropic | Created and maintains the Model Context Protocol | | OpenAI | Supports MCP in parts of its agent/developer stack | | Microsoft | Integrating MCP-related capabilities across Copilot, Azure, and developer tooling [medium confidence on breadth of product support] | | Google | Supporting MCP through parts of the Gemini/developer ecosystem [medium confidence; product coverage is evolving] | | Cursor | One of the most visible developer clients supporting MCP servers |

Dynamics: Protocol adoption is being driven by model and IDE distribution, but the protocol itself is likely to commoditize; the strategic battle is over which platforms become the default client, runtime, and policy layer.

---

Segment 2: Tool and connector creation platforms

| Companies | Role | |---|---| | Zapier | Broad SaaS action/connectivity layer, increasingly exposed to AI-agent and MCP use cases | | Pipedream | API and workflow infrastructure for building tool integrations and AI actions | | Composio | Managed integrations and authentication for AI agents, including MCP-oriented workflows | | Nango | Unified integrations and credential management for product teams building agentic features | | Paragon | Embedded integration infrastructure for SaaS products and automation | | Workato | Enterprise automation and integration platform moving toward AI-agent connectivity [MCP-specific scope is evolving] |

Dynamics: This is the supply side of the market. The key differentiators are breadth of connectors, authentication quality, normalized schemas, write-action reliability, and the ability to convert an API into a safe, agent-usable tool.

---

Segment 3: MCP registries, catalogs, hosting, and gateways

| Companies | Role | |---|---| | Smithery | MCP server discovery, hosting, and ecosystem distribution | | Glama | MCP server directory and related hosting/discovery services | | Docker | MCP catalog and tooling for packaging/running MCP servers | | Cloudflare | Building infrastructure for remote MCP servers and agent/tool connectivity | | Kong | API gateway and AI gateway capabilities that can sit between agents and tools [MCP-specific product depth is evolving] | | Portkey | AI gateway, routing, and governance layer with MCP-related support [medium confidence on current breadth] |

Dynamics: Distribution and gateway companies can become the “app store plus network router” for tools. However, catalogs face low switching costs, while enterprise gateways can defend value through policy, traffic, identity, and observability.

---

Segment 4: Security, identity, governance, and observability

| Companies | Role | |---|---| | Snyk | Security scanning and risk analysis for MCP servers and AI-generated code | | Invariant Labs | Specialized research and security tooling focused on MCP and agent/tool vulnerabilities | | Auth0 | Identity and authorization infrastructure relevant to MCP tool access | | Descope | Authentication and authorization for agentic and MCP-style workflows | | Okta | Enterprise identity, access policy, and governance for AI applications [MCP-specific packaging is evolving] | | Langfuse | LLM/agent tracing and observability, including tool-call monitoring [MCP-specific support may vary by deployment] |

Dynamics: Security is moving from model-level concerns to tool-level concerns: prompt injection, confused-deputy attacks, excessive permissions, malicious servers, secret leakage, and untraceable write actions. Enterprise adoption will require this layer even if it is initially purchased as an extension of existing IAM, API-security, or observability products.

---

Segment 5: Enterprise applications becoming native tools

| Companies | Role | |---|---| | GitHub | Code, issue, pull-request, and repository tools used by coding agents | | Notion | Knowledge and workspace tools exposed to AI workflows | | Slack | Communication and enterprise-context tools for agents | | HubSpot | CRM, marketing, and customer-data actions | | Atlassian | Jira and Confluence context and workflow actions | | Salesforce | CRM and enterprise workflow actions through its broader Agentforce ecosystem |

Dynamics: Application vendors want to own the authoritative, permissioned version of their data and actions. Their strategic choice is whether to expose direct MCP servers, rely on aggregators, or force usage through their own agent platform; distribution and data ownership give these vendors substantial bargaining power.

3) Which segment captures the most value?

Likely winner: Security, governance, and enterprise control planes

The protocol and basic server implementations are likely to become relatively low-margin and interchangeable. The highest-value layer should be the enterprise control plane that:

  • Authenticates users, agents, tools, and servers
  • Enforces granular, dynamic permissions
  • Prevents prompt-injection and unauthorized tool use
  • Manages secrets and delegated credentials
  • Provides audit logs, traceability, approvals, and rollback
  • Measures tool reliability, cost, latency, and business outcomes
  • Works across MCP, APIs, function calling, plugins, and non-MCP systems

This layer sits directly in the path of enterprise risk and spend. It can also become embedded in procurement, compliance, and security workflows, producing stronger retention than a standalone MCP directory or connector catalog.

Important caveat: In the near term, the largest absolute revenue may still accrue to existing application, cloud, and automation platforms—such as Microsoft, Salesforce, Google, AWS, Zapier, and Workato—because they already control distribution and customer relationships. The highest incremental strategic value is more likely to accrue to the governance/control-plane layer.

4) White-space opportunities

A. Cross-protocol enterprise “agent access broker”

A vendor-neutral control plane that governs MCP servers, REST APIs, OpenAI-style function calls, browser agents, RPA tools, and internal data systems in one policy engine.

Required capabilities would include:

  • Per-user, per-agent, per-tool permissions
  • Just-in-time credentials and scoped OAuth
  • Human approval for high-risk actions
  • Data-loss prevention and sensitive-field filtering
  • Tool provenance and supply-chain verification
  • Centralized audit and incident response
  • Deployment across VPC, on-premises, and multiple clouds

Existing API gateways, IAM providers, and AI gateways each cover pieces of this, but no clearly dominant vendor appears to own the complete cross-protocol agent access layer.

B. Tool quality, reliability, and economic benchmarking network

An independent system that continuously evaluates MCP servers and agent tools on:

  • Functional correctness and schema quality
  • Permission safety
  • Prompt-injection resilience
  • Uptime, latency, and rate-limit behavior
  • Version compatibility
  • Data freshness
  • Cost per successful task
  • Real-world task completion rates

It could provide certification, SLAs, reputation scores, regression testing, and insurance/procurement evidence. Current directories primarily emphasize discovery, while security vendors emphasize vulnerabilities; a neutral “tool credit rating” and performance benchmark layer is still largely missing.

Note: MCP product coverage is changing quickly, particularly at Microsoft, Google, Kong, Portkey, Okta, and Langfuse. The companies named above are real; the confidence flags indicate areas where public product scope is still evolving rather than claims that the companies are not active in the category.