Skip to main content

Roadmap

Our vision for STOA Platform β€” building the gateway for the AI era.

Living Document

This roadmap reflects our current priorities and may evolve based on community feedback and market needs. Have ideas? Join the discussion on Discord.

Latest Release

v2.2.0 (March 2026) β€” LLM Proxy, Self-Service Signup, Skills System, MCP 2025-11-25, OAuth 2.1 DPoP, and 12 new API endpoints.


Available Today​

Core Platform, MCP Gateway, LLM Proxy & Multi-Vendor Support

FeatureStatusSince
Control Plane API (Python/FastAPI)Donev0.1.0
STOA Gateway (Rust/Tokio/axum)Donev0.2.0
MCP Protocol 2025-11-25 β€” tool discovery, resources, prompts, completionDonev2.2.0
Developer Portal β€” self-service API discovery + signupDonev0.1.0
Admin Console β€” API catalog, observability, tenant opsDonev0.1.0
Multi-tenant Architecture β€” namespace-level isolationDonev0.1.0
Keycloak SSO β€” OIDC, LDAP federation, multi-realmDonev0.1.0
LLM Proxy β€” multi-provider routing (OpenAI, Azure, Mistral)Donev2.2.0
LLM Cost Management β€” per-tenant budgets, enforcement, dashboardDonev2.2.0
Self-Service Signup β€” tenant provisioning, trial limitsDonev2.2.0
Skills System β€” gateway-native CRUD with circuit breakerDonev2.2.0
UAC (Universal API Contract) β€” JSON Schema validator, OpenAPI transformDonev2.2.0
OAuth 2.1 β€” DPoP binding, RFC 7592 DCR managementDonev2.2.0
Rate Limiting β€” per-consumer quotasDonev0.2.0
Circuit Breaker β€” per-upstream with zombie reaperDonev0.2.0
mTLS β€” certificate-bound tokens (RFC 8705)Donev0.2.0
Security Headers β€” OWASP best practices, SSRF blocklistDonev0.2.0
PII Masking β€” middleware + admin endpointsDonev2.2.0
Security Posture ScannerDonev2.2.0
Gateway Adapters β€” webMethods, Kong, Gravitee, Apigee, AWS, Azure APIMDonev2.2.0
Gateway Auto-Registration β€” zero-config heartbeatDonev0.2.0
Observability β€” Prometheus, Grafana, OpenSearchDonev0.1.0
Gateway Arena β€” continuous benchmark lab (20 enterprise dimensions)Donev2.2.0
Platform Continuous Verification β€” 3 CUJs every 15 minDonev2.2.0
W3C Traceparent β€” distributed tracing propagationDonev2.2.0
Helm Charts β€” full platform deploymentDonev0.1.0
OPA Policy EngineDonev0.1.0
Consumer Onboarding β€” data model, Keycloak sync, quotasDonev0.2.0
Born GitOps β€” declarative API lifecycle (ADR-040)Donev0.2.0
Audit Trail β€” PG dual-write + OpenSearch pipelineDonev2.2.0
ArgoCD Integration β€” GitOps deployment on OVH + HetznerDonev0.2.0
CRDs β€” Tool, ToolSet, GatewayInstance, GatewayBindingDonev0.2.0
Usage Metering PipelineDonev2.2.0
Billing β€” budgets, consumers, models APIDonev2.2.0
Contract Lifecycle ManagementDonev2.2.0
Data Governance EndpointsDonev2.2.0
SCIM-to-Gateway ReconciliationDonev2.2.0
i18n Framework (Console)Donev2.2.0
Integrated AI Chat AssistantDonev2.2.0
Tenant Export/Import (Disaster Recovery)Donev2.2.0
Documentation β€” 100+ guides, references, ADRs, and API docsDonev2.2.0

In Progress​

GitOps Operator, Sidecar Mode & Developer Experience

FeatureStatus
GitOps Reconciliation Operator β€” K8s operator replacing AWX (ADR-042)In Progress
Gateway Sidecar Mode β€” coexist with Kong, Envoy, etc. (ADR-024)In Progress
CLI Tool (stoactl) β€” kubectl-style management (Go/Cobra)In Progress
Landing Page & Pricing (gostoa.dev)In Progress

Planned​

Performance, Scale & Ecosystem

FeatureStatus
Gateway Proxy Mode β€” transparent proxy for legacy backendsPlanned (Q3 2026)
Gateway Shadow Mode β€” traffic mirroring and UAC generationPlanned (Q4 2026)
Terraform ProviderPlanned
OpenAPI Import β€” auto-register from specPlanned
SDK (Python, TypeScript)Planned
Edge DeploymentPlanned
WebAssembly PluginsPlanned
Response CachingPlanned
Pre-built MCP ConnectorsPlanned
GitOps Templates (ArgoCD)Planned
Public Helm RegistryPlanned

Under Consideration​

  • Policy as Code β€” Define access policies in natural language
  • Marketplace β€” Discover and share MCP tool configurations
  • Multi-Cloud Native β€” Provider-specific optimizations
  • Agent Observability β€” End-to-end AI agent workflow tracing

Get Involved​

We build in public and welcome contributions!


This roadmap is directional and subject to change. For enterprise roadmap discussions, contact sales@gostoa.dev.