With Kong Volcano, Kong Hosts the Agents It Governs

With Kong Volcano, Kong Hosts the Agents It Governs

Analyst(s): Vikram Rathnam, Mitch Ashley
Publication Date: October 9, 2026

At its API + AI Summit, Kong announced Kong Volcano, a platform for building and running AI agents, as well as AI Gateway 2.2 and its Konnect governance roadmap. Volcano gives developers and their coding agents a single place to deploy, and it asks engineering and IT leaders to trust Kong as both the place where agents run and the party that governs them.

What Is Covered in This Article:

  • What Kong announced at API + AI Summit on September 30, 2026, and the availability of each product.
  • What Kong Volcano gives a developer building agents, and what Kong has not yet published about it.
  • Which Kong agent controls are available today, and which remain on the roadmap?
  • How Kong compares with AWS and Cloudflare on running agents.
  • What Kong Volcano means for engineering and IT leaders choosing a governance platform.

The News: On September 30, 2026, at its API + AI Summit in San Francisco, Kong Inc. announced Kong Volcano, a platform to “build, deploy, and operate AI agents and modern web applications.” It bundles the pieces an agent’s application needs in one place: durable workflows, branchable PostgreSQL with vector support, edge functions, frontend hosting, authentication and SSO, and real-time services, including multi-agent coordination, locks, queues, and optional human approvals. Volcano integrates with Claude Code, OpenAI Codex, and Cursor, and Kong says it is “compatible with the broader Kong Konnect platform.” Developers can start free; Kong has not published pricing, and sandboxed compute will follow shortly after this announcement.”

Kong also made AI Gateway 2.2 generally available in Konnect. Most of its capabilities, including MCP server bundling, per-modality cost tracking, identity-keyed access, and Bedrock AgentCore authentication, first shipped in AI Gateway 2.0 on September 1, 2026. New in 2.2 are an AI-native UI, Skills APIs, passthrough for vLLM, Ollama, and NVIDIA NIM, custom plugins, credential-matched rate limits, and Headroom prompt compression in technical preview.

Kong’s third release reframed Konnect as “The AI Connectivity Platform,” listing six products at mixed readiness: Context Mesh and Konnect Catalog are generally available, while the Agent and MCP Registry, Webhook Engine, AI Cost Management, and Advanced AI Observability sit in private beta, early access, or coming soon. Kong’s pages disagree on Token Vault’s status. Kong first presented this roadmap on February 2, 2026, and named no customers for any product. Details are in Kong’s announcement of the Volcano agent platform.

With Kong Volcano, Kong Hosts the Agents It Governs

Analyst Take: Kong Volcano is the one change in direction at Kong’s API + AI Summit; the gateway release and the Konnect roadmap extend earlier work. The company that built the gateway between applications and the APIs they call now offers developers a place to run their agents and the applications their coding agents write.

For a developer, Volcano is the database, sign-in, queues, and hosting for an agent’s application, with Kong’s governance attached. It is worth building on once Kong shows how a team sees what its agents do in production and how it moves them. For engineering and IT leaders, the same move tests whether Kong can host agents while still governing those it does not host, a question we take up from the buyer’s vantage below.

Kong Volcano Moves Kong From a Part of the Backend to the Backend Itself

Until August 2026, Kong was a part of Supabase’s self-hosted stack, which shipped Kong as its API gateway until Supabase made Envoy the default that month. Kong Volcano sells the whole bundle instead: the hosted database, sign-in, and deployment target that Supabase offers on PostgreSQL today. Firebase offered the same bundle to app developers before Google bought the company in October 2014.

Coding agents explain the timing. An application a coding agent writes needs a database, sign-in, and somewhere to run, and Volcano lets the agent deploy it with those pieces in one place. The gateway alone is a weaker business now that Amazon Bedrock AgentCore Gateway, Azure API Management, and Google’s Apigee API hub, where MCP support became generally available in July 2026, all turn an API into a tool an agent can call.

Kong Volcano Deploys an Agent in One Prompt but Can’t Yet Show Developers What It Did

Marco Palladino, Kong’s CTO and co-founder, says “Developers shouldn’t have to stitch together infrastructure to turn an AI agent into a production application,” and that Volcano goes “from zero to running an agent in production in one prompt.” He has named the right problem, and Volcano’s list covers most of it, down to optional human approvals beyond locks and queues.

Kong’s own release names the piece the list leaves out. Agents need “observability to understand what is happening in production,” it says, yet none of the eight services in the release provides it, and Volcano’s documentation has no section on it. Kong’s answer, Advanced AI Observability, is not yet generally available, so an agent deployed in one prompt runs in production before its developer can follow a full session of what it did.

Kong’s governance roadmap ships what lets an agent act before what lets a developer check it. The two controls that are generally available, tool filtering in AI Gateway 2.2 and Context Mesh, help an agent find and call the right tools. The three that would show a developer what an agent did and spent, and keep credentials out of its code, are Advanced AI Observability, AI Cost Management, and Token Vault, and none are generally available yet.

AI already contributes to production incidents; few organizations stop agents before their riskiest actions, and the share of software AI builds is set to grow. In The Futurum Group’s 2H 2026 Software Lifecycle Engineering Global Enterprise Decision Maker Survey (n=839, fielded June 2026), 75% of organizations had a production incident in the previous 12 months in which AI-generated code, AI agent actions, or AI tooling was a contributing factor, and 36% of those saw agents take unintended or out-of-scope actions. Only 32% have human approval gates in place for irreversible agent actions, while 58% expect AI to build 80% or more of their software within three years. Volcano’s optional approvals let the developer add that gate while building the agent. Nothing Kong has published says whether approvals are on by default or who gets asked to approve.

Migration is the other open question; PostgreSQL moves to any PostgreSQL host. Nothing Kong has published says whether Volcano’s workflows, queues, and approvals use open interfaces; if they don’t, code written against them runs only on Volcano. Kong also has not published where Volcano runs or how a workflow and its data move off it.

Kong Volcano Enters a Field Where Others Already Run Agents

AWS and Cloudflare already sell developers an agent runtime and the controls around it. Amazon Bedrock AgentCore includes a runtime, a gateway that turns APIs into agent tools, and a token vault that AWS documents as compatible with self-hosted and hybrid agents.

Cloudflare runs agents on Workers through its Agents SDK, routes their model calls through its AI Gateway, and published code mode in September 2025. Kong says Context Mesh is “built on code mode.” Kong arrives after both.

Build One Agent on Kong Volcano Before Committing a Team

For developers and engineering managers trying Kong Volcano:

  • Prototype first, and keep the agent’s logic separate from its calls to Volcano’s workflows and queues.
  • Decide which actions require a human and which do not before the agent ships, then enable Volcano’s approvals for those actions.
  • Before a production agent goes on Volcano, get answers in writing: how its traces get into the tools your team already uses, where Volcano runs, and how a workflow and its PostgreSQL database move off it.

Kong should publish how a Volcano agent is observed in production and how it moves off Volcano. With both, Volcano becomes a fast way to ship an agent that a team can see and still move. Without them, the time Volcano saves during deployment comes back later as debugging and migration work.

The CIO Question: Can a Host Still Referee?

A CIO buys a governance layer for one reason: a neutral place to set policy across runtimes nobody owns. Kong Volcano changes what that neutrality costs. The company asking to govern agents on Amazon Bedrock AgentCore, Microsoft Foundry, and Volcano now runs a platform that competes for those same agents. Konnect’s value to a buyer rests on treating every runtime alike, and the moment one of those runtimes is Kong’s own, the committee has to verify that sameness rather than assume it. Runtime parity moves onto the buying checklist, and Kong should be made to prove it rather than asked to assert it.

The move does not disqualify Kong. It changes the evidence a buying committee needs before it commits. Ask Kong to show that a Konnect control, tool filtering, or a cost policy behaves identically on a non-Kong runtime, and to commit to that parity in writing. Keep the Volcano decision and the Konnect decision on separate tracks, so a bet on a developer platform does not quietly become a bet on a single governance vendor. The test is concrete: if Kong cannot govern an agent on AgentCore exactly as it governs one on Volcano, Volcano is a runtime choice, and Konnect’s neutrality is a claim the buyer still has to check.

What to Watch:

  • Whether Kong publishes Volcano’s pricing, hosting providers, and a migration path for workflows and data before sandboxed compute ships, and whether its workflow and queue services use open interfaces.
  • Whether Konnect features work the same for agents on AgentCore and Microsoft Foundry as for agents on Volcano, or whether any capability appears only for Volcano-hosted agents.
  • Whether Token Vault, AI Cost Management, and Advanced AI Observability become generally available, and whether Advanced AI Observability exports traces in OpenTelemetry format to existing observability tools.
  • Whether MuleSoft’s federated governance of Kong gateways wins accounts where Kong pitches Konnect as the neutral layer.
  • Whether AWS, Microsoft, or Google extends their agent registries to govern agents on other clouds, removing Kong’s main point of difference.

See the complete press release on the Konnect governance roadmap on PR Newswire.


Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.

Other Insights From Futurum:

MuleSoft Omni Gateway: As Close to an Agent Control Plane as It Gets

The Hard(er) Challenge in Agent Governance Is Authorization

OpenAI Moves Up the Stack and Competes With the Platforms It Powers

env zero EZ Control: Telling a Fix From a Mistake

Author Information

Vikram Rathnam is Research Director, Software Lifecycle Engineering at The Futurum Group. His research examines how software is built, tested, secured, and operated as AI agents move from assisting developers to doing the work. His coverage includes observability, platform engineering, and the control planes that govern agents. Before joining Futurum, he spent 24 years on the vendor side: ten in engineering at Silicon Labs and fourteen in product and partner strategy, with roles at Cisco, Secureworks, Dell, and CMIT Solutions. Across those roles, he managed B2B cybersecurity, IoT, and AI products, with partner and channel ecosystems as the common thread. At CMIT Solutions, he led product strategy across a franchise network of 180 locations. He reads a vendor’s roadmap as someone who has had to ship one and take it to market.

Mitch Ashley is VP and Practice Lead for the CIO & Technology Buyers and Software Lifecycle Engineering practices at The Futurum Group. A multi-time CIO and CTO with 30+ years leading technical organizations, Mitch built and operated production systems spanning cybersecurity for the U.S. Department of Defense, PKI services for the broadband and 5G industries, SaaS platforms, large-scale telecom and banking systems, and a national broadband network. His work with AI began early, developing expert systems that diagnosed and repaired complex mainframe environments. That operator foundation grounds his analysis in operational consequence, covering the technology buyer's world of software engineering, cybersecurity, DevOps, cloud, and AI.

Related Insights
env zero EZ Control Telling a Fix From a Mistake
October 6, 2026

env zero EZ Control: Telling a Fix From a Mistake

Mitch Ashley, VP and Practice Lead, CIO and Tech Buyers, and Vikram Rathnam, Research Director, Software Lifecycle Engineering at The Futurum Group, share insights on env zero EZ Control and...
Does a 17-Year-Old Movement Need a DevOps Standard
October 6, 2026

Does a 17-Year-Old Movement Need a DevOps Standard?

Vikram Rathnam and Mitch Ashley of Futurum Research share insights on The DevOps Standard, why its AI agent governance is a well-built retrofit, and what enterprise leaders and platform vendors...
NETSCOUT nGenius Copilot Caps a Three-Release Data-First Strategy
October 6, 2026

NETSCOUT nGenius Copilot Caps a Three-Release Data-First Strategy

Mitch Ashley, VP and Practice Lead, CIO & Technology Buyers and Software Lifecycle Engineering at Futurum, shares his insights on NETSCOUT nGenius Copilot and why its September AI sequence puts...
OPSWAT Firmware 4.3.0 Deepens OT/IT Data-Sharing for Industrial Diodes
October 6, 2026

OPSWAT Firmware 4.3.0 Deepens OT/IT Data-Sharing for Industrial Diodes

OPSWAT's MetaDefender NetWall Fend 4.3.0 adds UDP Multicast, Syslog, and MQTT support, enhancing secure data-sharing between operational and IT environments....
OPSWAT Targets Critical Infrastructure Gaps With MetaDefender Endpoint v7.6.2609
October 5, 2026

OPSWAT Targets Critical Infrastructure Gaps With MetaDefender Endpoint v7.6.2609

OPSWAT's MetaDefender Endpoint v7.6.2609 release introduces configurable media controls, air-gapped anti-malware updates, and expanded audit trails—addressing critical security gaps for enterprises in high-compliance sectors....
Scalian Names First CAIO to Scale AI in Critical Engineering
October 5, 2026

Scalian Names First CAIO to Scale AI in Critical Engineering

Scalian has named Clément Charruel as its first Chief AI Officer, positioning the engineering services firm to compete in a $344B software lifecycle engineering market by embedding AI across critical...

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.