Blank white background with no objects or features visible.

TrueFoundry Named Frost & Sullivan's 2026 Global Transformational Innovation Leader. Read report

تعرّف على TrueForge: مُسخّر الوكلاء مفتوح المصدر والمحايد تجاه الموردين. تكلفة أقل بنسبة 50%. استكشف الآن→

Arcade.dev vs TrueFoundry: Where the Two Overlap, and Where They Do Not

By أشيش دوبي

Published: September 28, 2026

⚡ TL;DR
  • Choose Arcade.dev if your hardest problem is agent authorization: per-action delegated OAuth, token brokering with rotation and injection at execution, thousands of pre-built tools, and the largest public MCP registry via the Smithery acquisition. Arcade wrote the MCP tool authorization spec Anthropic adopted — standards authorship, not marketing.
  • Choose TrueFoundry if you need that MCP governance plus the layer underneath: an LLM gateway across 1,000+ models, GPU model deployment, guardrails, per-team budgets, and RBAC with SCIM — one control plane, in your own cloud or on-prem.
  • The key trade-off is scope, not quality. Arcade is an excellent actions runtime but not an LLM gateway, and its own docs confirm it: no model routing, no GPU serving, no budgets, no guardrail catalogue. Buy Arcade and you still need a gateway; buy TrueFoundry and you do not need a second product for MCP.
  • Where Arcade is genuinely ahead: SIEM log streaming ships today (TrueFoundry’s is coming soon), the OAuth provider catalogue is pre-built rather than configured, and usage-based pricing means no seat conversation to start.
  • Both self-host. Arcade documents Helm self-hosting and markets on-prem and air-gapped. The difference is documentation depth, not presence versus absence.

Most “vs” posts start by making the other product sound worse than it is. This one cannot. Arcade raised a $60M Series A on 12 June 2026 led by SYN Ventures, with strategic investment from Morgan Stanley and Wipro, taking total financing to $72M (Arcade Series A announcement). Morgan Stanley is both investor and named customer.

The useful question is narrower: what does each product cover, and what will you still have to buy afterwards? That has a factual answer in both vendors’ docs.

Arcade.dev: Overview

Arcade no longer calls itself a tool-calling platform. Its framing is now the actions runtime: “Arcade is the actions runtime between your agents and every system they reach. One control point to enforce, execute, and govern every action, every time.”

It also swings directly at gateway vendors, worth quoting because it frames the disagreement honestly: “Start with the API gateway vendors. They’re solving a networking problem. They route traffic. Routing traffic isn’t authorizing an action” (Arcade Series A blog). The control point, Arcade argues, belongs at the action, not the network hop.

[SCREENSHOT: Arcade.dev — the dashboard showing a tool execution with the delegated user authorization step visible]

Authorization is the real differentiator, and it is deep. Every action runs at the intersection of what the user may do and what the agent may do — not a service account, not a shared token. Arcade brokers OAuth, handles refresh and rotation, and injects credentials at execution so they never reach the agent or MCP client. It supports generic OAuth 2.0 plus 33 named providers and five IdP user sources: Auth0, Clerk, Entra ID, Okta and Stytch (Arcade auth providers docs).

Arcade authored the MCP tool authorization specification, which it states is “now adopted by Anthropic and the major MCP clients and servers,” and sits on MCP security and governance steering committees — corroborated externally (SiliconANGLE, 25 November 2025). Standards authorship is a durable advantage; we will not talk around it.

The tool catalogue is large, though how large depends which page you read: “7,000+ tools / 80+ toolkits” on the product page, “7,500+ tools / 81 MCP servers” in the docs, “8,000+” on the homepage and in the Series A blog. We note the inconsistency rather than pick for them. The positioning is “agent-optimized… not thin API wrappers”, backed by a public benchmark at toolbench.arcade.dev.

[SCREENSHOT: Arcade.dev — the toolkit catalogue page showing available toolkits and per-tool detail]

Smithery gives Arcade the registry. On 5 August 2026 Arcade acquired Smithery, “a leading public registry and hosting platform for MCP” (Smithery joins Arcade). Smithery still runs as a separate brand and lists 23,611+ MCP servers. Arcade’s own Registry is still Early Access — but Arcade now owns the biggest public MCP index and its developer funnel.

The rest of the surface. An MCP Gateway federating Arcade-hosted, custom and third-party servers behind one endpoint, with nine documented remote-MCP vendor integrations (Salesforce, ServiceNow, Snowflake, Atlassian, GitHub, Splunk and more). Reference-grade Python SDK docs, ten frameworks, six MCP clients. Contextual Access for pre and post tool-call policy hooks and group-based tool access. And a six-page evals section — scoped to tool-call accuracy rather than model quality, but real and documented, which is more than many competitors offer.

Deployment: Arcade is not SaaS-only. Its docs list Arcade Cloud, the Azure and AWS marketplaces, GCP (explicitly “coming soon”), self-hosting with Helm, and hybrid MCP servers (Arcade deploy docs). Marketing goes further — “Cloud, on-prem, air-gapped, or hybrid”. Anyone saying Arcade cannot run in your own infrastructure has not read the docs.

Compliance: SOC 2 Type 2, achieved 18 August 2025 (Arcade SOC 2 post). HIPAA, ISO 27001 and GDPR: [VERIFY] — not claimed on any page we could read, and the trust centre is a JavaScript-rendered portal with no crawlable content.

Pricing, published and usage-based:


Free Team Enterprise
Price $0/mo $25/mo + usage Custom
Auth events 2,000/mo $0.10 each Annual bundles
Tool calls 2,000/mo $0.01 each Annual bundles
Hosting Cloud Cloud Cloud, your VPC, air-gapped
Governance Community NBD email SSO, RBAC, audit logs, private registry, 24/7 SLA

Two metered dimensions — auth events and tool calls — is unusual and worth modelling before you commit. And SSO, RBAC and audit logs are Enterprise-gated on the pricing page, despite the homepage saying “SSO, RBAC, and full audit logs out of the box.”

TrueFoundry: Overview

TrueFoundry is an AI control plane. The MCP gateway is one component inside it rather than the whole product — the crux of this comparison.

MCP gateway and registry. Six documented ways to add a server — TrueFoundry-managed, official remote, any remote, Virtual MCP Server, OpenAPI import, hosted stdio — plus 43 per-vendor doc pages and a registry with public list/version APIs.

How MCP authentication and authorization flow through the TrueFoundry gateway
How MCP authentication and authorization flow through the TrueFoundry gateway

On auth — the head-to-head with Arcade’s strongest area — TrueFoundry documents nine outbound modes: OAuth2 authorization code, client credentials, token exchange / on-behalf-of (Okta and Entra jwt-bearer), shared and individual API keys, no auth, token passthrough, token forwarding and AWS SigV4, plus four inbound modes. It also publishes an MCP protocol support matrix across four spec revisions through 2026-07-28, covering OAuth 2.1, RFC 9728, RFC 7591, RFC 8707 and OIDC discovery per revision. Arcade publishes no equivalent matrix.

Human-in-the-loop approval is a capability Arcade does not document: scopes of named, destructive or all, grant expiry, and Email, Slack, PagerDuty or Teams notifications. With MCP tool annotations (None / Read-only / Destructive), you can require sign-off before an agent runs anything write-shaped (more detail).

Creating an approval policy and selecting which tools require a human gate
Creating an approval policy and selecting which tools require a human gate

The AI Gateway. 1,000+ models across 28 named providers behind one OpenAI-compatible API, with weight-based routing (canary, sticky sessions), priority-based fallback with SLA cutoffs on TTFT and TPOT, latency-based strategies, exact-match and semantic caching, and token or request rate limiting per minute, hour or day.

Routing configuration in the TrueFoundry AI Gateway
Routing configuration in the TrueFoundry AI Gateway

Model deployment. vLLM, SGLang, Triton, TorchServe, TF Serving, MLflow and LitServe, with a model registry, autoscaling on CPU, RPS or cron, and fractional GPUs via TimeSlicing and MIG. Arcade has no product here and does not claim one.

Guardrails. Four hook points — LLM input, LLM output, MCP pre-tool and MCP post-tool — with nine built-in guardrails (secrets detection, code safety, SQL sanitizer, regex, prompt injection, PII, content moderation, Cedar, OPA) and 17 external providers including Bedrock Guardrails, Azure Content Safety, CrowdStrike and Google Model Armor. Honest caveat: content moderation, PII and prompt-injection guardrails run only on the TrueFoundry-hosted gateway, not when you host it yourself.

Guardrails applied to MCP tool calls before and after execution
Guardrails applied to MCP tool calls before and after execution

Cost and budgets. Budget Limiting V2 with tenant-level and team-scoped budgets — “use team budgets when a team lead should manage their own team’s spending without tenant-admin access” — scoped by subject, model, provider account or metadata, with a warn-only mode. Cost tracking runs off an open-source pricing catalog at github.com/truefoundry/models; attribution flows through an X-TFY-METADATA header.

RBAC and SSO. Subjects can be a user, team, virtual account or agent. Resources span provider accounts, MCP servers, agents, clusters, workspaces, repositories and secret groups, each with its own role family. SSO over OIDC or SAML 2.0 with SCIM 2.0 provisioning — SAML guides for nine IdPs, SCIM for four. Arcade documents five IdP sources and no SCIM.

Deployment and compliance. Seven documented scenarios: SaaS across 12+ regions and 3 clouds; self-hosted and VPC via Helm plus OpenTofu/Terraform, with guides for AWS, GCP, Azure, OpenShift and generic Kubernetes; on-prem; and air-gapped, documented concretely in three places. SOC 2 Type II, HIPAA and GDPR are consistently claimed. ISO 27001: [VERIFY] — older doc pages list it, the security page does not. SIEM export is coming soon, a live gap against Arcade.

Pricing: Developer $0 (3 users, 10k requests/user, 5 MCP servers), Pro $25/user/mo (unlimited users, 20k requests/user, +$20 per additional 100K requests), Enterprise custom. MCP tool calls draw on the same allowance as LLM requests — no separate MCP meter.

Scope: what each product actually covers

Every “Not documented” entry was checked against Arcade’s docs navigation and its product, pricing and tools pages on 25 September 2026.

Capability Arcade.dev TrueFoundry
Tool authorization Deep — delegated OAuth, 33 providers, spec authorship 9 outbound + 4 inbound modes, token exchange / OBO
MCP gateway Yes — hosted, custom, third-party Yes — 6 add methods, 43 vendor doc pages
MCP registry Smithery, 23,611+ servers; own Registry in Early Access Built-in, public list/version APIs
MCP protocol matrix Not published Four spec revisions through 2026-07-28
Tool approval gate Not documented Named / destructive / all, expiry, 4 channels
LLM gateway and routing Not documented — only gateway is MCP 1,000+ models, weight / priority / latency
Model deployment on GPUs Not documented vLLM, SGLang, Triton; fractional GPUs
Cost attribution, budgets Not documented — rate limits throttle, not cap Budget Limiting V2, team-scoped
Guardrails No catalogue; hooks are BYO policy 9 built-in + 17 external, 4 hook points
Tool-call evals Yes — six doc pages, ToolBench Not a documented surface
Observability Audit logs; SIEM streaming today OTEL, Prometheus; SIEM export coming soon
RBAC / SCIM Named on homepage, no docs page; no SCIM 6 role families; SAML 9 IdPs, SCIM for 4
Self-hosting Helm; AWS/Azure marketplaces; GCP coming soon Helm + Terraform; AWS, GCP, Azure, OpenShift
Air-gapped Marketed; no install guide in docs deploy Documented across three doc pages
Metering Auth events and tool calls, separately One allowance for LLM and MCP calls

Two product boundaries, not a scorecard. Arcade drew its boundary at the action and went deeper there than anyone; TrueFoundry drew it around the whole model-and-agent path.

Where teams hit trouble

1. The two-product problem. Arcade governs tool calls; it does not carry model traffic. The moment your agent calls an LLM — which is every agent — you need a second product for routing, fallback, caching and rate limits. That is not a criticism; it is what Arcade’s docs say. But the real evaluation becomes “Arcade plus a gateway” versus “one control plane,” and cost and operational surface should be compared on that basis.

2. Identity fragments across two control planes. Two places where a user, team or agent is defined, two places to provision and deprovision, two places to revoke a departing employee. Arcade documents five IdP user sources and no SCIM; your gateway will have its own model. Keeping those in sync is work nobody budgets for. More in MCP access control.

3. Cost lives in two places and reconciles in neither. Arcade meters auth events and tool calls; your gateway meters tokens. Neither knows about the other, so “what did the support agent cost last month” becomes a spreadsheet. Arcade documents no budget or chargeback feature — rate limits throttle, they do not cap spend.

4. Audit surfaces do not join up. Arcade streams tool-execution logs to your SIEM, which is genuinely useful. But the prompt that triggered the call, the model that produced it, and the guardrail that did or did not fire live in the other system. Reconstructing an incident means correlating two log formats by timestamp.

Running agents across more than one system?
Point your existing agents at one control plane and see tool calls, model spend and traces in the same place before you change anything.

TrueFoundry’s position

The argument is not that TrueFoundry does authorization better than Arcade. It is that authorization is one of six or seven things a platform has to get right, and solving one leaves six.

TrueFoundry’s AI Gateway adds roughly 3-4 ms of latency, handles 350+ RPS on 1 vCPU, and fronts 1,000+ LLMs behind one OpenAI-compatible API. Those numbers decide whether you can put the gateway in front of everything or only the important traffic — and a control point that covers some of the traffic is not a control point.

The agentic call path through the TrueFoundry control plane
The agentic call path through the TrueFoundry control plane

Because MCP tool calls and LLM requests run the same path, they land in the same metrics, traces and budgets. MCP metrics cover total calls, top servers, top tools, RPS per server and P50-P99 latency with tool-level drill-down — next to model spend, not in a different product.

MCP tool metrics alongside model traffic in the TrueFoundry console
MCP tool metrics alongside model traffic in the TrueFoundry console

Auto Routing is a cost lever that does not exist in a tool-only product. Across 550 prompts, routing between model tiers by request complexity cut cost by 69% while retaining 98% of baseline quality, with mean latency falling from 7.6s to 4.0s; on production-shaped traffic the reduction reached 80%. Pair that with team-scoped budgets and you get cost attribution a team lead can actually manage.

Per-tool enable and disable controls on an MCP server
Per-tool enable and disable controls on an MCP server

When Arcade is the better choice

We would rather you pick correctly.

  • Your problem is genuinely just authorization. You already have a gateway, model routing is settled, and what hurts is OAuth brokering across thirty SaaS tools. Arcade’s 33 pre-built providers and managed token lifecycle will save you months.
  • You want the catalogue more than the control plane. Thousands of agent-optimized tools plus Smithery’s 23,611+ MCP servers is the largest supply of ready-made agent actions anywhere.
  • SIEM streaming is a hard requirement today. Arcade ships it; TrueFoundry’s is coming soon. If security will not approve a rollout without it on day one, that is a real difference.
  • You want usage-based pricing with no seat conversation. $0 to start, $25/mo plus metered usage, no per-seat charge.
  • Standards alignment matters. Arcade wrote the MCP tool authorization spec and sits on the governance committees. If you are betting on the spec, betting on its authors is defensible.

Head-to-head

The scope table carries the detail. This is the decision summary.


Arcade.dev TrueFoundry
Category Actions runtime for agent tool calls AI control plane: gateway, MCP, models, agents
Core bet Control point at the action Control point on the whole call path
Strongest at Delegated OAuth, tool catalogue, MCP registry Model routing, budgets, guardrails, approvals
Compliance SOC 2 Type 2 (Aug 2025); HIPAA/ISO/GDPR [VERIFY] SOC 2 Type II, HIPAA, GDPR; ISO 27001 [VERIFY]
Current edge SIEM streaming ships today Budgets, guardrails, approvals, SCIM ship today
Entry pricing $0 free tier; $25/mo + usage $0 Developer; $25/user/mo Pro
Best for Teams whose hardest problem is tool authorization Teams governing models, agents and MCP in one place

Related reading

Conclusion

Arcade.dev is a strong product with a defensible thesis, real enterprise customers, standards authorship and $72M behind it. If someone tells you it is lightweight or that it cannot run in your infrastructure, they have not looked.

The reason to choose differently is scope. Arcade governs what an agent is allowed to do. It does not govern what model the agent talks to, what that costs, whether the prompt leaked a secret, or who approved the destructive call — and its own documentation is clear about that. So the real comparison is Arcade plus a gateway plus a guardrail layer plus a budgeting story, versus one control plane that contains all four.

If your hardest problem is OAuth across thirty SaaS tools, buy the thing that solves it. If it is that nobody can say what your agents cost, what they touched, and who said yes, you want the control plane.

Start free with TrueFoundry

Try now.

One gateway for all your models, MCP servers, and agents.
No credit card needed.

Start free
Table of Contents

One Gateway for Every LLM, Agent and MCP Server

Book a 30-min with our AI expert

Book a Demo

The fastest way to build, govern and scale your AI

Book Demo
Summarize with
ChatGPT logo by OpenAI
Perplexity AI logo
Blurry red snowflake on white background, symmetrical frosty design with soft edges and abstract shape.

Discover More

No items found.
September 28, 2026
|
5 min read

Langfuse Alternatives: 7 Options Compared on Licence, Price and Limits

No items found.
September 28, 2026
|
5 min read

Data Loss Prevention for LLM Traffic: Where It Has to Sit

No items found.
September 28, 2026
|
5 min read

Data Masking in the AI Gateway: What Actually Works

No items found.
September 28, 2026
|
5 min read

API Rate Limiting for LLMs: Count Tokens, Not Requests

No items found.
No items found.

Recent Blogs

Black left pointing arrow symbol on white background, directional indicator.
Black left pointing arrow symbol on white background, directional indicator.
Take a quick product tour
Start Product Tour
Product Tour