Case Study
How Wix scaled Al-native work to 5,000 employees with Willow
Read More
MCP Gateways

Willow vs Lunar

Willow finds supported AI clients, local MCP configurations, skills, agent instruction files, and browser OAuth activity and controls for supported web AI chats before employees register them with a gateway. Choose Lunar when the platform team already controls the traffic and needs detailed request policies, MCP sandbox testing, model routing, or token-budget controls.

TL;DR
  • Choose Willow when IT and security need to find AI clients, local MCP configurations, skill files, agent instruction files, and browser OAuth activity without waiting for employees to register them.
  • Choose Lunar when your platform team needs request-level MCP policy, isolated server testing, model routing, token-budget controls, or credentials stored in Kubernetes secrets or HashiCorp Vault.
  • Check this first: Can IT see the AI clients, local configurations, skills, browser OAuth activity, and supported web AI chats employees use on managed devices? If not, start with Willow.

Willow

Willow scans managed macOS and Windows devices for local MCP configurations, skill files, agent instruction files, and installed AI clients. It also records browser OAuth activity and checks prompts and attachments in supported web AI chats.

Lunar

Lunar inventories agents connecting through MCPX and applies detailed controls to gateway traffic. It also provides MCP sandbox testing, model routing, quotas, and external secret-manager integrations.

Start with the AI activity IT cannot see.

Start with Willow when employees can use AI outside managed gateways, because gateway policy cannot govern activity it never receives. Choose Lunar when the relevant traffic already reaches managed gateways and finer request or model controls decide the purchase.

Willow extends governance to managed devices and supported web AI chats. Lunar provides finer controls for traffic routed through its MCP and model gateways.

WillowLunar
Main jobFind and govern employee AI use across devices, browsers, identities, agents, and MCP connectionsSecure MCP, model, and API traffic connected to Lunar gateways
Primary operatorIT, security, and AI enablementPlatform engineering and security
DiscoveryLocal MCP configurations, installed AI clients, skills, CLAUDE.md, AGENTS.md, browser OAuth activity, and controls for supported web AI chatsAgents, servers, tools, and endpoints observed through MCPX and the Lunar AI Gateway
Request policyTool controls, approvals, guards, rate limits, and beta Conditions that currently block matching callsPer-agent, per-tool, and request-based controls
Risk testingRisk scores and Guard CheckRisk scores plus an isolated MCP evaluation sandbox
Model trafficUsage and token analytics, with per-user tool-call limitsProvider routing, quotas, token controls, and Enterprise token-budget controls
DeploymentSaaS, hybrid, and on-premises, including strict air-gap deploymentsMCPX Enterprise is self-hosted; AI Gateway also has a hosted option
AssuranceSOC 2 Type IISOC 2 Type II and SLA-backed Enterprise support

Willow finds AI before employees register it

Willow finds supported AI tools and files on managed devices. It also governs supported browser AI, machine users, and background agents.

Find local AI clients and MCP configurations

The Scan Agent finds installed AI coding tools and local MCP connections on managed macOS and Windows devices, including configurations in Cursor, Claude Desktop, VS Code, and Windsurf.

Find skills and agent instruction files

Willow identifies SKILL.md files, Cursor rules, CLAUDE.md, and AGENTS.md on managed devices, including files that never reach a gateway.

Control supported browser AI

Willow Guard checks prompts and attachments before they leave supported web AI chats. For Claude in Chrome, Willow can pause outgoing requests until someone approves them. Willow Guard is currently in Beta.

Give bots and agents clear owners

Willow assigns each machine user and background agent an accountable owner and shows its credentials, permissions, activity, and deployment status in one place.

Choose Lunar for these requirements

Choose Lunar when the relevant traffic already reaches its gateways and isolated MCP testing, model routing, or token-budget controls decide the purchase.

Test MCP servers before production

Lunar’s Enterprise sandbox runs MCP servers in isolation, tests policies and failure scenarios, scores individual tools, and adds approved servers to the company catalog.

Apply deeper gateway policy

Lunar restricts agents and individual tools, and applies policy to user, agent, server, tool, and request parameters.

Route models and enforce usage controls

Lunar routes requests between model providers and applies quotas, token controls, and Enterprise token-budget controls. Willow provides usage analytics and per-user tool-call limits.

Keep credentials in existing secret managers

Lunar supports Kubernetes secrets and HashiCorp Vault. Willow provides its own encrypted Vault.

Bottom line

Willow finds AI use beyond the gateway. Lunar governs traffic already routed through one.

Willow finds supported AI clients, MCP configurations, skills, agent instruction files, plus browser OAuth activity and controls for supported web AI chats across managed devices, then ties those findings to employee identity, access policy, ownership, and offboarding. Lunar inventories and secures agents, tools, model calls, and APIs observed through its gateways, with deeper controls for requests that already reach them.

  • Use Willow if IT must discover and govern AI that employees adopted without registering it first.
  • Use Lunar if the platform team already controls the relevant traffic and needs MCP sandbox testing, detailed request policy, model routing, token-budget controls, or credentials stored in Kubernetes secrets or HashiCorp Vault.

Willow governs AI use across large organizations

We are six to ten months ahead of most companies in AI adoption. More code to production, fewer incidents, real outcomes. Willow is what made it possible to move that fast without slowing down our security posture.

Asaf Yonay Head of AI Core, Wix

  • ~5,000 weekly active users at Wix
  • ~600 governed tools and MCPs
  • 300K+ governed tool calls every week

Frequently asked questions

Common questions from teams comparing Willow with Lunar

Does Lunar discover shadow MCP use?

Yes, within its gateway architecture. Lunar inventories agents, servers, and tools observed through MCPX. Willow additionally scans managed macOS and Windows devices and records browser OAuth activity. Its browser extensions apply controls to supported web AI products.

Can Willow deny access to an individual tool?

Willow can disable a tool for everyone, hide it from AI clients, require approval for every call, or block matching calls with beta Conditions. Group access remains additive. Lunar provides more detailed per-agent and per-tool gateway restrictions.

Which product is stronger for model traffic?

Lunar. It routes between model providers and applies quotas, token controls, and Enterprise token-budget controls. Willow focuses on agent, tool, identity, device, and browser governance.

Should you evaluate Willow and Lunar together?

Possibly. Willow addresses employee AI discovery and governance; Lunar addresses traffic connected to its MCP and model gateways. Verify overlapping enforcement, identity ownership, audit correlation, and support boundaries before using both.

Table of contents

    Willow vs CrowdStrike Falcon AIDR

    CrowdStrike Falcon AIDR detects prompt attacks and data loss at the model layer. Willow governs what agents are allowed to do: identity, scoped access, and audit. How they compare, and why many enterprises run both.

    Willow vs Ovalix

    Both Willow and Ovalix find AI on employee devices, control public AI apps, and check coding agents. Willow adds approved tool connections by group and human approval of tool calls; Ovalix adds risk scores for third-party AI apps.

    Willow vs Arthur

    Arthur discovers agents, assigns ownership and risk, and enforces policy across the agent fleet. Willow governs the access layer: which tools each agent can call, scoped at runtime and fully audited.

    ‍

    Your agents are already in the wild.

    Give them a Basecamp. Go from AI chaos to AI work, in minutes.