MCP Bridge by AppFactor - API-to-MCP Translation Platform
AppFactor · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
- MCP Bridge is a self-hosted enterprise grade platform that turns any existing API into AI-ready tools using the Model Context Protocol (MCP). Point it at a REST, GraphQL, SOAP, or gRPC endpoint, and it auto-generates fully described MCP tool definitions that any LLM client can discover and invoke - no custom integration code required. * THE PROBLEM: Connecting LLMs to enterprise APIs today requires writing bespoke tool definitions for every endpoint, maintaining parameter mappings by hand, and rebuilding when schemas change. For organisations with dozens of internal services and hundreds of endpoints, this is a significant engineering tax that slows AI adoption. Meanwhile, uncontrolled MCP server sprawl creates security blind spots, credential exposure, and governance gaps. * HOW IT WORKS: MCP Bridge imports API schemas (OpenAPI, GraphQL introspection, WSDL, gRPC .proto files), auto-generates typed MCP tools with input/output schemas, behavioural annotations, and documentation, then executes at runtime - validating inputs, mapping parameters, handling authentication (Bearer, Basic, API Key, OAuth2, AWS Cognito SRP), and post-processing responses to reduce token waste. For large APIs (100+ endpoints), Code Mode replaces the full tool catalogue with 3 meta-tools, cutting context window usage by approximately 98%. * KEY CAPABILITIES: Protocol translation across REST, GraphQL, SOAP, and gRPC. Per-tool response post-processing (filter, transform, aggregate). Tool curation with metadata enhancement for optimal LLM performance. Enterprise-grade authentication and authorisation. Centralised rate limiting, connection pooling, and retry logic. Comprehensive analytics dashboard with latency, throughput, token usage, and error tracking. Hybrid search with optional semantic similarity for tool discovery. Structured MCP logging with configurable verbosity. * WHO IT IS FOR: Platform teams exposing internal APIs to AI agents. AI engineers building agents that need a managed tool layer. Organisations adopting MCP as a standard and bridging their existing API portfolio. Security teams seeking centralised governance over AI-to-API connectivity. * WHY APPFACTOR: MCP Bridge eliminates the glue code tax, provides a single control plane for all AI-to-API connectivity, and gives security and platform teams the visibility and governance they need - without slowing down AI adoption.
Highlights
Highlighted by the publisher on AWS Marketplace.
Transform any REST, GraphQL, SOAP, or gRPC API into MCP tools with zero custom code. Auto-generate fully typed MCP tool definitions with input/output schemas, behavioural annotations, and documentation.
Reduce LLM context window usage by ~98% with Code Mode for large API portfolios (100+ endpoints). Enterprise-grade security: OAuth2, Bearer, Basic, API Key, and AWS Cognito SRP authentication.
Per-tool response post-processing to filter, transform, and aggregate API responses - cutting token waste from large payloads. Centralised analytics dashboard covering latency, throughput, token usage, error rates, and per-tool cost tracking.
Preview
1 imageAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Plans and pricing as listed
9 listed- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
Refund terms
As stated by the publisher on AWS Marketplace.
non-refundable
Sources
Publisher resources
2 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

