Analyst(s): Vikram Rathnam, Mitch Ashley
Publication Date: October 9, 2026
At its API + AI Summit, Kong announced Kong Volcano, a platform for building and running AI agents, as well as AI Gateway 2.2 and its Konnect governance roadmap. Volcano gives developers and their coding agents a single place to deploy, and it asks engineering and IT leaders to trust Kong as both the place where agents run and the party that governs them.
What Is Covered in This Article:
- What Kong announced at API + AI Summit on September 30, 2026, and the availability of each product.
- What Kong Volcano gives a developer building agents, and what Kong has not yet published about it.
- Which Kong agent controls are available today, and which remain on the roadmap?
- How Kong compares with AWS and Cloudflare on running agents.
- What Kong Volcano means for engineering and IT leaders choosing a governance platform.
The News: On September 30, 2026, at its API + AI Summit in San Francisco, Kong Inc. announced Kong Volcano, a platform to “build, deploy, and operate AI agents and modern web applications.” It bundles the pieces an agent’s application needs in one place: durable workflows, branchable PostgreSQL with vector support, edge functions, frontend hosting, authentication and SSO, and real-time services, including multi-agent coordination, locks, queues, and optional human approvals. Volcano integrates with Claude Code, OpenAI Codex, and Cursor, and Kong says it is “compatible with the broader Kong Konnect platform.” Developers can start free; Kong has not published pricing, and sandboxed compute will follow shortly after this announcement.”
Kong also made AI Gateway 2.2 generally available in Konnect. Most of its capabilities, including MCP server bundling, per-modality cost tracking, identity-keyed access, and Bedrock AgentCore authentication, first shipped in AI Gateway 2.0 on September 1, 2026. New in 2.2 are an AI-native UI, Skills APIs, passthrough for vLLM, Ollama, and NVIDIA NIM, custom plugins, credential-matched rate limits, and Headroom prompt compression in technical preview.
Kong’s third release reframed Konnect as “The AI Connectivity Platform,” listing six products at mixed readiness: Context Mesh and Konnect Catalog are generally available, while the Agent and MCP Registry, Webhook Engine, AI Cost Management, and Advanced AI Observability sit in private beta, early access, or coming soon. Kong’s pages disagree on Token Vault’s status. Kong first presented this roadmap on February 2, 2026, and named no customers for any product. Details are in Kong’s announcement of the Volcano agent platform.
With Kong Volcano, Kong Hosts the Agents It Governs
Analyst Take: Kong Volcano is the one change in direction at Kong’s API + AI Summit; the gateway release and the Konnect roadmap extend earlier work. The company that built the gateway between applications and the APIs they call now offers developers a place to run their agents and the applications their coding agents write.
For a developer, Volcano is the database, sign-in, queues, and hosting for an agent’s application, with Kong’s governance attached. It is worth building on once Kong shows how a team sees what its agents do in production and how it moves them. For engineering and IT leaders, the same move tests whether Kong can host agents while still governing those it does not host, a question we take up from the buyer’s vantage below.
Kong Volcano Moves Kong From a Part of the Backend to the Backend Itself
Until August 2026, Kong was a part of Supabase’s self-hosted stack, which shipped Kong as its API gateway until Supabase made Envoy the default that month. Kong Volcano sells the whole bundle instead: the hosted database, sign-in, and deployment target that Supabase offers on PostgreSQL today. Firebase offered the same bundle to app developers before Google bought the company in October 2014.
Coding agents explain the timing. An application a coding agent writes needs a database, sign-in, and somewhere to run, and Volcano lets the agent deploy it with those pieces in one place. The gateway alone is a weaker business now that Amazon Bedrock AgentCore Gateway, Azure API Management, and Google’s Apigee API hub, where MCP support became generally available in July 2026, all turn an API into a tool an agent can call.
Kong Volcano Deploys an Agent in One Prompt but Can’t Yet Show Developers What It Did
Marco Palladino, Kong’s CTO and co-founder, says “Developers shouldn’t have to stitch together infrastructure to turn an AI agent into a production application,” and that Volcano goes “from zero to running an agent in production in one prompt.” He has named the right problem, and Volcano’s list covers most of it, down to optional human approvals beyond locks and queues.
Kong’s own release names the piece the list leaves out. Agents need “observability to understand what is happening in production,” it says, yet none of the eight services in the release provides it, and Volcano’s documentation has no section on it. Kong’s answer, Advanced AI Observability, is not yet generally available, so an agent deployed in one prompt runs in production before its developer can follow a full session of what it did.
Kong’s governance roadmap ships what lets an agent act before what lets a developer check it. The two controls that are generally available, tool filtering in AI Gateway 2.2 and Context Mesh, help an agent find and call the right tools. The three that would show a developer what an agent did and spent, and keep credentials out of its code, are Advanced AI Observability, AI Cost Management, and Token Vault, and none are generally available yet.
AI already contributes to production incidents; few organizations stop agents before their riskiest actions, and the share of software AI builds is set to grow. In The Futurum Group’s 2H 2026 Software Lifecycle Engineering Global Enterprise Decision Maker Survey (n=839, fielded June 2026), 75% of organizations had a production incident in the previous 12 months in which AI-generated code, AI agent actions, or AI tooling was a contributing factor, and 36% of those saw agents take unintended or out-of-scope actions. Only 32% have human approval gates in place for irreversible agent actions, while 58% expect AI to build 80% or more of their software within three years. Volcano’s optional approvals let the developer add that gate while building the agent. Nothing Kong has published says whether approvals are on by default or who gets asked to approve.
Migration is the other open question; PostgreSQL moves to any PostgreSQL host. Nothing Kong has published says whether Volcano’s workflows, queues, and approvals use open interfaces; if they don’t, code written against them runs only on Volcano. Kong also has not published where Volcano runs or how a workflow and its data move off it.
Kong Volcano Enters a Field Where Others Already Run Agents
AWS and Cloudflare already sell developers an agent runtime and the controls around it. Amazon Bedrock AgentCore includes a runtime, a gateway that turns APIs into agent tools, and a token vault that AWS documents as compatible with self-hosted and hybrid agents.
Cloudflare runs agents on Workers through its Agents SDK, routes their model calls through its AI Gateway, and published code mode in September 2025. Kong says Context Mesh is “built on code mode.” Kong arrives after both.
Build One Agent on Kong Volcano Before Committing a Team
For developers and engineering managers trying Kong Volcano:
- Prototype first, and keep the agent’s logic separate from its calls to Volcano’s workflows and queues.
- Decide which actions require a human and which do not before the agent ships, then enable Volcano’s approvals for those actions.
- Before a production agent goes on Volcano, get answers in writing: how its traces get into the tools your team already uses, where Volcano runs, and how a workflow and its PostgreSQL database move off it.
Kong should publish how a Volcano agent is observed in production and how it moves off Volcano. With both, Volcano becomes a fast way to ship an agent that a team can see and still move. Without them, the time Volcano saves during deployment comes back later as debugging and migration work.
The CIO Question: Can a Host Still Referee?
A CIO buys a governance layer for one reason: a neutral place to set policy across runtimes nobody owns. Kong Volcano changes what that neutrality costs. The company asking to govern agents on Amazon Bedrock AgentCore, Microsoft Foundry, and Volcano now runs a platform that competes for those same agents. Konnect’s value to a buyer rests on treating every runtime alike, and the moment one of those runtimes is Kong’s own, the committee has to verify that sameness rather than assume it. Runtime parity moves onto the buying checklist, and Kong should be made to prove it rather than asked to assert it.
The move does not disqualify Kong. It changes the evidence a buying committee needs before it commits. Ask Kong to show that a Konnect control, tool filtering, or a cost policy behaves identically on a non-Kong runtime, and to commit to that parity in writing. Keep the Volcano decision and the Konnect decision on separate tracks, so a bet on a developer platform does not quietly become a bet on a single governance vendor. The test is concrete: if Kong cannot govern an agent on AgentCore exactly as it governs one on Volcano, Volcano is a runtime choice, and Konnect’s neutrality is a claim the buyer still has to check.
What to Watch:
- Whether Kong publishes Volcano’s pricing, hosting providers, and a migration path for workflows and data before sandboxed compute ships, and whether its workflow and queue services use open interfaces.
- Whether Konnect features work the same for agents on AgentCore and Microsoft Foundry as for agents on Volcano, or whether any capability appears only for Volcano-hosted agents.
- Whether Token Vault, AI Cost Management, and Advanced AI Observability become generally available, and whether Advanced AI Observability exports traces in OpenTelemetry format to existing observability tools.
- Whether MuleSoft’s federated governance of Kong gateways wins accounts where Kong pitches Konnect as the neutral layer.
- Whether AWS, Microsoft, or Google extends their agent registries to govern agents on other clouds, removing Kong’s main point of difference.
See the complete press release on the Konnect governance roadmap on PR Newswire.
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.
Other Insights From Futurum:
MuleSoft Omni Gateway: As Close to an Agent Control Plane as It Gets
The Hard(er) Challenge in Agent Governance Is Authorization
OpenAI Moves Up the Stack and Competes With the Platforms It Powers
env zero EZ Control: Telling a Fix From a Mistake
