Customers use MuleSoft Omni Gateway to secure and govern API, MCP, LLM and agent traffic. Omni Gateway supports multiple deployment models including a MuleSoft hosted option called Managed Omni Gateway and customer hosted option called Self Managed Omni Gateway.
MuleSoft customers often prefer Managed Omni Gateway as it offers less overhead, automatic updates and maintenance and faster time to market. However, it previously faced two constraints:
- It was exclusively available on CloudHub 2.0 Private Spaces, requiring dedicated infrastructure
- Customers needed to deploy separate gateways to handle ingress and egress traffic. These constraints added operational overhead, cost, and complexity to customer architectures
We’re solving these challenges by bringing Managed Omni Gateway to CloudHub 2.0 Shared Spaces and further introducing a unified gateway capability which handles both ingress and egress traffic within a single deployment. This allows for faster prototyping and reduced infrastructure without compromising control.
Omni Gateway in Shared Spaces
CloudHub 2.0 Shared Spaces offers a multi-tenant deployment model. Unlike Private Spaces, Shared Spaces uses a shared global region model, providing logical isolation without the need for custom CIDR blocks or VPNs.
Inbound traffic enters through a shared load balancer to a public endpoint, while outbound egress traffic reaches downstream services via an internal cluster endpoint (ensuring egress remains isolated from the internet.
This model is ideal for three scenarios:
- Free trialsenabling immediate exploration and experimentation
- Proof of concept and developmentallowing teams to build agent networks quickly
- Cost-efficient, non-production environmentsaving resources by using Shared Spaces for testing and QA


Agent Network deployed in Private Space
Below is a depiction of a typical architecture of Agent Network. As seen in the diagram, the architecture includes two gateways deployed in CloudHub 2.0 private space, respectively for inbound and outbound traffic, multiplying configuration and monitoring efforts.
While this architecture is ideal for production deployments, it may be an overkill for prototyping or development use cases. There is an opportunity to simplify this.
Agent Network Deployed in Shared Spaces
This unified model consolidates ingress and egress Omni Gateways in a single deployment. Inbound prompts and outbound tool calls now flow through one instance, providing four core benefits: simplified provisioning, unified policy governance, consistent observability via a single telemetry path, and lower resource consumption.
For teams building MuleSoft Agent Fabric networks, the unified Omni Gateway is not just an operational convenience. It is a meaningful architectural simplification that aligns the deployment model with the way agent networks actually work: as a continuous, governed flow of traffic in both directions, coordinated by a single intelligent gateway layer.
demo
This demo illustrates a scenario where a Mule App connects weather services to Agentforce, Gemini, and OpenAI. We will walk through adding Omni Gateway in a Shared Space; selecting it at runtime; and configuring unified ingress/egress settings.
- Experience for Omni Gateway in a Shared Space
- Experience for Omni Gateway in a Private Space
The Public endpoint (Ingress) exposes the gateway’s public-facing CloudHub URL, the entry point for all inbound prompt traffic arriving from external clients. The Internal endpoint for Private Space/ Cluster Endpoint for Share Space (Egress) used for outbound calls to external agents and services, thus isolating these internal resources from external access.
Availability of Omni Gateway in Shared Spaces simplifies deployments for prototyping and experimentation. Developers can start a free trial to deploy Omni Gateway in minutes. Existing customers can access Omni Gateway in their Anypoint Platform account. To learn more about MuleSoft Agent Fabric, Omni Gateway, and CloudHub 2.0 Shared Spaces, read the MuleSoft documentation or reach out to your MuleSoft account team.