Home / Token cost / Gateway

The Gateway MCP server costs 38,532 tokens before the first call.

Every request your agent makes carries every tool definition this server exposes — context your code, documents and conversation can't use, mostly for tools the agent never calls. You don't need them all in the window, and you don't have to pay for them.

QUICK ANSWER The Gateway MCP server's 271 tool definitions consume 38,532 tokens — 19% of a 200k context window, and 18× the median MCP server (2,142 tokens). A scoped grant exposing only the tools you use cuts that roughly in proportion.

MEASURED FROM SCHEMAS tiktoken o200k_base · rank #39 of 5,402 measured servers · refreshed every build Method →

What that costs before your agent starts working.

Tool definitions are overhead: they occupy context on every request and compete with your code, documents and conversation history for the same window.

200K WINDOW 19%
1M WINDOW 3.9%

Corpus context: Gateway ranks #39 of 5,402 measured MCP servers by definition cost. The median is 2,142 tokens, p90 is 11,749, and the heaviest (Ainumbers Mcp Apps) is 161,750 — 81% of a 200k window on its own. New to this? See MCP token cost and context window in the glossary.

Where the 38,532 tokens go.

Each row is one tool definition as a tools/list entry — name, description and input schema — counted with o200k_base. Average: 142 tokens per tool.

ToolCategoryTokens% of server
mortgage Read 385 1.0%
vault_call_api Execute 383 1.0%
rent_vs_buy Read 336 0.9%
coach_opener Write 312 0.8%
paver Read 310 0.8%
human_task_post Financial 303 0.8%
labor_burden Read 291 0.8%
gen_id_portrait Execute 276 0.7%
voice_transcribe Read 273 0.7%
browse_open Execute 268 0.7%
human_profile_set Write 264 0.7%
coach_reply Read 263 0.7%
market_bars Read 262 0.7%
wishlist Write 258 0.7%
gen_video Execute 256 0.7%
budget Read 250 0.6%
accretion_dilution Financial 247 0.6%
gen_image Execute 241 0.6%
concrete Read 240 0.6%
net_worth Read 238 0.6%
life_insurance Read 234 0.6%
coach_profile_review Read 231 0.6%
invoice_extract Read 230 0.6%
agent_version_publish Write 230 0.6%
vault_store Write 226 0.6%
market_quote Read 225 0.6%
framing Read 224 0.6%
password_policy_check Read 223 0.6%
request_handoff Execute 222 0.6%
profit_loss Read 219 0.6%
percentage Read 216 0.6%
rrule_expand Read 215 0.6%
vault_login Execute 215 0.6%
gen_avatar_video Execute 213 0.6%
coach_mission Execute 211 0.5%
mortgage_points_breakeven Read 211 0.5%
bid_estimator Write 210 0.5%
tts_voice Read 210 0.5%
geometry Read 208 0.5%
register_agent Write 207 0.5%
body_fat Read 204 0.5%
submit_errand Execute 202 0.5%
date_add Read 201 0.5%
search Read 198 0.5%
enterprise_value Read 194 0.5%
insulation Read 191 0.5%
regex_tester Execute 191 0.5%
retirement Read 189 0.5%
pomodoro_planner Read 188 0.5%
college_savings Read 187 0.5%
browse Execute 186 0.5%
human_browse Read 186 0.5%
token_cost Read 186 0.5%
fire_number Read 182 0.5%
check_inbox Read 179 0.5%
post_bluesky Write 179 0.5%
board_feet Read 175 0.5%
paint Read 175 0.5%
capture_lead Write 174 0.5%
create_watch Write 174 0.5%
store_artifact Write 173 0.4%
options_chain Read 172 0.4%
hourly_rate Read 171 0.4%
tdee Read 170 0.4%
financial_ratios Read 167 0.4%
saas_metrics Read 167 0.4%
invoice_generator Read 166 0.4%
web_read Read 166 0.4%
forget_memories Destructive 165 0.4%
floor_joist Read 165 0.4%
semver_compare Read 165 0.4%
claim_donation Financial 164 0.4%
asphalt Read 163 0.4%
post_telegram Write 163 0.4%
markup Read 162 0.4%
store_memory Write 161 0.4%
change_order Read 160 0.4%
tvm Execute 160 0.4%
investment_fee Read 159 0.4%
cac_ltv Read 158 0.4%
normal_prob Read 158 0.4%
discover_tools Read 157 0.4%
ab_test Read 157 0.4%
rebar Read 157 0.4%
search_memory Read 157 0.4%
post_discord Write 157 0.4%
savings_goal Read 156 0.4%
modular Read 153 0.4%
mulch Read 153 0.4%
color_palette Read 152 0.4%
haversine Read 152 0.4%
fertilizer Read 151 0.4%
query_corpus Read 151 0.4%
send_message Write 151 0.4%
text_diff Read 150 0.4%
text_truncate_ellipsis Destructive 149 0.4%
text_wordwrap Read 149 0.4%
password_entropy Read 148 0.4%
confirm_delivery Write 147 0.4%
search_memory_facts Read 147 0.4%
confidence_interval Read 146 0.4%
raised_bed Read 146 0.4%
research Read 146 0.4%
safe_note Read 146 0.4%
business_days Read 146 0.4%
pet_calorie Read 145 0.4%
calories_burned Read 144 0.4%
compound_interest Read 144 0.4%
bond_price Read 143 0.4%
book_appointment Write 143 0.4%
csv_json_convert Write 143 0.4%
persona_set Write 143 0.4%
whitespace_normalize Read 142 0.4%
effective_rate Read 141 0.4%
xml_json_convert Write 141 0.4%
annuity Read 140 0.4%
file_size_humanize Read 139 0.4%
ingest_corpus Write 139 0.4%
json_minify_prettify Read 137 0.4%
loan Read 137 0.4%
bmi Read 136 0.4%
donate Financial 136 0.4%
lookup_faq Read 136 0.4%
semver_satisfies_range Read 136 0.4%
summarize_memory Read 136 0.4%
share_memory Write 135 0.4%
data_transfer Read 135 0.4%
depreciation Read 135 0.4%
read_memory_changes Read 135 0.4%
one_rep_max Read 135 0.4%
grass_seed Read 134 0.3%
breakeven Read 133 0.3%
mac_address_format Read 133 0.3%
bitwise Execute 131 0.3%
triangle_solver Read 131 0.3%
dice_notation_roll Execute 130 0.3%
slug_generate Read 130 0.3%
human_task_list Read 129 0.3%
subnet Read 129 0.3%
yaml_json_convert Write 129 0.3%
agent_rollback Read 128 0.3%
iso8601_duration_parse Read 126 0.3%
bayes Read 126 0.3%
query_string_convert Read 126 0.3%
runway Read 126 0.3%
amortization_schedule Read 126 0.3%
set_focus Write 126 0.3%
list_leads Read 125 0.3%
indent_convert Write 125 0.3%
uuid5 Read 124 0.3%
routing_number Read 123 0.3%
retry_backoff Execute 122 0.3%
bill_of_materials Read 121 0.3%
margin Read 121 0.3%
nato_phonetic_spell Read 120 0.3%
garden_planting_calendar Read 119 0.3%
json_pointer_extract Read 119 0.3%
tip_split Read 119 0.3%
browse_wait_for Execute 118 0.3%
encoding Read 118 0.3%
invoice_fraud_check Read 118 0.3%
json_schema_validate Read 118 0.3%
color_convert Read 118 0.3%
draw_schedule Write 118 0.3%
url_parse_normalize Read 117 0.3%
invoice_match Read 117 0.3%
hash_text Read 116 0.3%
cron_next Read 115 0.3%
isbn_check_digit Read 115 0.3%
npv Read 115 0.3%
browse_evaluate Execute 114 0.3%
age_calculator Read 113 0.3%
base_convert Read 113 0.3%
checksum Read 112 0.3%
ip_in_cidr Read 112 0.3%
regression Read 112 0.3%
dilution Financial 111 0.3%
mime_from_extension Read 111 0.3%
rate_limit Read 111 0.3%
color_contrast Read 109 0.3%
git_short_sha Read 109 0.3%
heart_rate_zones Read 109 0.3%
roi Read 109 0.3%
agent_version_list Read 108 0.3%
recall_memories Read 108 0.3%
score_lead Read 108 0.3%
timezone_convert Read 108 0.3%
unit_convert Read 108 0.3%
browse_solve_challenge Execute 107 0.3%
phonetic_encode Read 107 0.3%
browse_fill Execute 106 0.3%
identity Read 106 0.3%
vault_get Read 106 0.3%
browse_type Execute 105 0.3%
sales_tax Read 105 0.3%
jwt_decode Read 104 0.3%
percentile Read 104 0.3%
ratio Read 104 0.3%
vin_check_digit Read 104 0.3%
hmac Execute 103 0.3%
market_news Read 103 0.3%
json_diff Read 102 0.3%
browse_discover Read 102 0.3%
port_range_parse Read 101 0.3%
csv_profile Read 101 0.3%
roman Read 101 0.3%
text_case Read 101 0.3%
morse_code_convert Write 101 0.3%
arena_call Execute 100 0.3%
combinatorics Read 100 0.3%
luhn Read 100 0.3%
number_to_words Read 99 0.3%
simple_interest Read 99 0.3%
resume Read 99 0.3%
cagr Read 98 0.3%
ideal_weight Read 97 0.3%
line_ending_convert Write 97 0.3%
card_brand_detect Read 96 0.2%
matrix Execute 96 0.2%
rule_of_72 Read 96 0.2%
web_search Read 96 0.2%
browse_select Execute 95 0.2%
browse_extract Read 94 0.2%
duration_breakdown Read 94 0.2%
browse_snapshot Read 92 0.2%
epoch_convert Read 92 0.2%
browse_navigate Execute 91 0.2%
quadratic Read 91 0.2%
tax_bracket Read 90 0.2%
csv_markdown_table Read 88 0.2%
date_diff Read 88 0.2%
read_message Read 88 0.2%
web_discover Read 88 0.2%
crc32 Read 87 0.2%
expected_value Read 87 0.2%
gcd_lcm Read 87 0.2%
number_to_ordinal Read 87 0.2%
statistics Read 85 0.2%
unit_price_compare Read 85 0.2%
irr Read 82 0.2%
sig_figs Read 82 0.2%
archive_message Write 82 0.2%
browse_links Read 81 0.2%
http_status_explain Read 81 0.2%
toml_to_json Read 80 0.2%
ansi_strip Read 79 0.2%
browse_screenshot Read 79 0.2%
browse_read Read 78 0.2%
persona_get Read 78 0.2%
browse_click Execute 77 0.2%
markdown_to_html Execute 77 0.2%
memory_stats Read 76 0.2%
mark_message Write 76 0.2%
resolve_focus Write 76 0.2%
uptime_sla Read 75 0.2%
weighted_average Read 75 0.2%
levenshtein Write 75 0.2%
html_to_markdown Write 74 0.2%
get_tool_schema Read 72 0.2%
prime_factors Read 72 0.2%
vault_delete Destructive 71 0.2%
cancel_watch Destructive 70 0.2%
arena_games Write 68 0.2%
browse_back Execute 65 0.2%
browse_close Execute 64 0.2%
text_stats Read 64 0.2%
vault_list Read 64 0.2%
list_memory Read 62 0.2%
list_watches Read 60 0.2%
market_snapshot Read 60 0.2%
check_errand Read 51 0.1%

Your agent uses a handful of these tools. It pays for all 271.

You don't need all 271 of those definitions in the window. PolicyLayer is an MCP gateway that sits in front of Gateway: only the tools you grant are exposed to the agent, the rest never load. A smaller window means a sharper agent — less noise when it picks a tool — and every request costs less:

Grant scopeDefinition costReduction
All 271 tools (no gateway) 38,532 tokens
3 granted tools ~427 tokens −99%
5 granted tools ~711 tokens −98%
10 granted tools ~1,422 tokens −96%

The risk dividend: 9 of these 271 tools are critical-risk (destructive or financial) and cost 1,416 tokens (4% of the definition load). Block them — the recommended starter policy — and you reclaim that context before tuning anything else.

  1. Create a free account and register Gateway — nothing to install.
  2. Grant only the tools you use — ungranted definitions never enter the context window.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
CUT GATEWAY TOKEN COST →

Instant setup, no code required.

Gateway token-cost questions.

How many tokens does the Gateway MCP server use?+

Its 271 tool definitions total 38,532 tokens — 19% of a 200k context window — measured with tiktoken o200k_base over the serialised tools/list payload. Exact counts vary slightly by client and model.

Why does Gateway consume tokens before I send a message?+

MCP clients load every connected server's tool definitions — name, description, and input schema — into the model's context so it knows what it can call. That payload is charged against your context window on every request, whether or not a tool is used.

How do I reduce Gateway's token usage?+

Expose fewer tools. A PolicyLayer grant scopes Gateway to only the tools you allow — ungranted definitions are filtered out of the tool list, so they never enter the context window. A grant of 3 typical tools costs roughly 427 tokens, a 99% reduction.

Does deferred tool loading fix this?+

Partially, in some clients. Claude Code defers MCP tool schemas behind a tool-search step by default, and VS Code has experimental grouping — but you still pay tokens per search and reload, and Cursor, Windsurf and Gemini CLI load definitions upfront. Reducing the exposed tool set cuts the cost in every client.

How these numbers were measured.

01
Serialisation

Each tool is serialised as a tools/list entry — name, description, input schema — from the schemas in the PolicyLayer scan database. Clients differ slightly in framing, so treat counts as close estimates.

02
Tokeniser

tiktoken o200k_base (GPT-4o/o-series). Anthropic's current tokeniser isn't published, so Claude's exact counts will differ; for English text and JSON schemas the totals are close enough to treat these as estimates.

03
Deferred loading

Some clients now defer schema loading (Claude Code's tool search; VS Code experimental grouping). You still pay per search and reload — and Cursor, Windsurf and Gemini CLI load everything upfront.

Computed 23-07-2026 from the PolicyLayer scan database over all 271 catalogued Gateway tools. Counts refresh with every site build.

Expose only the tools you use — the rest never enter your context.

A PolicyLayer grant scopes Gateway to the tools you actually allow. Ungranted definitions never load, and every call that does run is checked against policy first.

Instant setup, no code required.

46,500+ MCP servers and 515,000+ tools scanned and risk-classified.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.