Willow finds supported AI clients, local MCP configurations, skills, agent instruction files, and browser OAuth activity and controls for supported web AI chats before employees register them with a gateway. Choose Lunar when the platform team already controls the traffic and needs detailed request policies, MCP sandbox testing, model routing, or token-budget controls.
Willow scans managed macOS and Windows devices for local MCP configurations, skill files, agent instruction files, and installed AI clients. It also records browser OAuth activity and checks prompts and attachments in supported web AI chats.
Lunar inventories agents connecting through MCPX and applies detailed controls to gateway traffic. It also provides MCP sandbox testing, model routing, quotas, and external secret-manager integrations.
Start with Willow when employees can use AI outside managed gateways, because gateway policy cannot govern activity it never receives. Choose Lunar when the relevant traffic already reaches managed gateways and finer request or model controls decide the purchase.
Willow extends governance to managed devices and supported web AI chats. Lunar provides finer controls for traffic routed through its MCP and model gateways.
| Willow | Lunar | |
|---|---|---|
| Main job | Find and govern employee AI use across devices, browsers, identities, agents, and MCP connections | Secure MCP, model, and API traffic connected to Lunar gateways |
| Primary operator | IT, security, and AI enablement | Platform engineering and security |
| Discovery | Local MCP configurations, installed AI clients, skills, CLAUDE.md, AGENTS.md, browser OAuth activity, and controls for supported web AI chats | Agents, servers, tools, and endpoints observed through MCPX and the Lunar AI Gateway |
| Request policy | Tool controls, approvals, guards, rate limits, and beta Conditions that currently block matching calls | Per-agent, per-tool, and request-based controls |
| Risk testing | Risk scores and Guard Check | Risk scores plus an isolated MCP evaluation sandbox |
| Model traffic | Usage and token analytics, with per-user tool-call limits | Provider routing, quotas, token controls, and Enterprise token-budget controls |
| Deployment | SaaS, hybrid, and on-premises, including strict air-gap deployments | MCPX Enterprise is self-hosted; AI Gateway also has a hosted option |
| Assurance | SOC 2 Type II | SOC 2 Type II and SLA-backed Enterprise support |
Willow finds supported AI tools and files on managed devices. It also governs supported browser AI, machine users, and background agents.
The Scan Agent finds installed AI coding tools and local MCP connections on managed macOS and Windows devices, including configurations in Cursor, Claude Desktop, VS Code, and Windsurf.
Willow identifies SKILL.md files, Cursor rules, CLAUDE.md, and AGENTS.md on managed devices, including files that never reach a gateway.
Willow Guard checks prompts and attachments before they leave supported web AI chats. For Claude in Chrome, Willow can pause outgoing requests until someone approves them. Willow Guard is currently in Beta.
Willow assigns each machine user and background agent an accountable owner and shows its credentials, permissions, activity, and deployment status in one place.
Choose Lunar when the relevant traffic already reaches its gateways and isolated MCP testing, model routing, or token-budget controls decide the purchase.
Lunar’s Enterprise sandbox runs MCP servers in isolation, tests policies and failure scenarios, scores individual tools, and adds approved servers to the company catalog.
Lunar restricts agents and individual tools, and applies policy to user, agent, server, tool, and request parameters.
Lunar routes requests between model providers and applies quotas, token controls, and Enterprise token-budget controls. Willow provides usage analytics and per-user tool-call limits.
Lunar supports Kubernetes secrets and HashiCorp Vault. Willow provides its own encrypted Vault.
Willow finds supported AI clients, MCP configurations, skills, agent instruction files, plus browser OAuth activity and controls for supported web AI chats across managed devices, then ties those findings to employee identity, access policy, ownership, and offboarding. Lunar inventories and secures agents, tools, model calls, and APIs observed through its gateways, with deeper controls for requests that already reach them.
We are six to ten months ahead of most companies in AI adoption. More code to production, fewer incidents, real outcomes. Willow is what made it possible to move that fast without slowing down our security posture.
Asaf Yonay Head of AI Core, Wix
Common questions from teams comparing Willow with Lunar
Yes, within its gateway architecture. Lunar inventories agents, servers, and tools observed through MCPX. Willow additionally scans managed macOS and Windows devices and records browser OAuth activity. Its browser extensions apply controls to supported web AI products.
Willow can disable a tool for everyone, hide it from AI clients, require approval for every call, or block matching calls with beta Conditions. Group access remains additive. Lunar provides more detailed per-agent and per-tool gateway restrictions.
Lunar. It routes between model providers and applies quotas, token controls, and Enterprise token-budget controls. Willow focuses on agent, tool, identity, device, and browser governance.
Possibly. Willow addresses employee AI discovery and governance; Lunar addresses traffic connected to its MCP and model gateways. Verify overlapping enforcement, identity ownership, audit correlation, and support boundaries before using both.
Give them a Basecamp. Go from AI chaos to AI work, in minutes.