Choose Willow when your IT and security team needs to manage the AI tools employees use across devices, browsers, and company connections. Willow brings local MCP configurations, coding-agent skills, supported browser prompts, and connected tool actions into company rules. That helps your team address how employees actually use AI, including configurations that never send traffic through the Willow gateway.
Zuplo also supports employees and internal agents. Its MCP Gateway manages access to registered remote MCP servers, and its AI Gateway gives employees personal model keys and budgets. Choose Zuplo only if your developers need to build programmable API services, and only if Willow’s rules for local MCP servers and coding skills fall outside your requirements.
MCP gives an AI assistant a standard way to call tools. An API gives software a way to request data or perform an action. Both Willow and Zuplo manage MCP connections. For employee AI management, start with the devices, approved tools, and actions your company needs to control.
Willow’s Scan Agent finds supported MCP configurations on macOS, Windows, and Linux. It reads configurations in clients such as Cursor, Claude Desktop, and VS Code, including local servers launched by the client. IT can inspect those configurations even when their tool calls never pass through Willow.
The agent runs a full scan daily and a quick scan every five minutes. Extra scans need enabling; running MCP and AI process discovery applies to macOS. MCP configurations inside Windows Subsystem for Linux appear in the inventory without blocking controls. Plan the rollout around the devices and formats your employees use.
Zuplo’s server directory lists MCP routes already registered on its gateway. The directory updates from the gateway’s route configuration and helps clients find those services. Directory discovery allows unauthenticated access by default; administrators can configure or disable it. Calls to the listed tools still follow their configured sign-in and access rules.
Willow Prompt Guard checks messages and attachments before submission in supported browser AI services: ChatGPT, Claude, Gemini, Microsoft 365 Copilot, and DeepSeek. This gives IT a place to apply prompt rules within those existing browser workflows. The extension carries a Beta label, and prompt checking starts off. Deploy the extension and enable the setting.
Zuplo’s AI Gateway handles model requests sent through its configured connection. Each project includes a User App where employees create personal keys for coding tools, use company-approved models, and see their own usage. After an administrator sets a budget, it follows that person’s requests. User Apps start without a budget. That supports employees who can point their tools at the company’s model gateway.
Willow gives employees a Connect Panel and plugin marketplace for approved tools. Administrators choose whether employees can add personal MCP connections, need approval before activation, or can freely connect them. Company-managed connections follow group assignments. This lets IT offer approved access while setting a separate rule for employee-added services.
For human tool calls, Willow checks the resources available through the caller’s groups. Group grants add together; they contain no deny rule. Use the separate tool conditions and guards when a call needs an additional block. A group assignment therefore needs review alongside any rules attached to the tool.
Both products support individual and shared sign-in arrangements for connected services. Willow can use each employee’s sign-in token or supplied API key, while its shared service-sign-in mode presents one service account to the connected server. Zuplo offers separate sign-ins for each user and shared sign-ins. Choose the mode that matches the permissions the connected service should apply.
Zuplo also supports a shared API key held in its encrypted key store. Separate stored API keys for every MCP user remain a roadmap item. Its available personal model keys belong to the AI Gateway User App, a separate feature. Keep that distinction clear when planning employee access to MCP tools and model providers.
Zuplo can filter tools by the caller’s roles or groups and reject a call to a hidden tool before sending it to the connected server. The filter starts with public access to its listed tools; sign-in and other route rules still apply. Configure the per-person rules explicitly. Leaving the tools section out of the filter settings passes all tools through.
For more detailed access rules, Zuplo offers Enterprise integrations with OpenFGA, AuthZEN, and Okta FGA. These let teams use a separate service to decide whether a person may access a tool. Developers can also write custom rules for gateway requests, with responsibility for testing that custom logic.
Willow can require human approval for every call to a selected tool. Its conditions run before the connected API and can block a call based on a rule. Conditions currently enforce blocking; use the separate tool approval setting for human approval. A condition error blocks the call by default unless an administrator chooses to let calls continue after a check fails.
A Willow approval rule on a tool’s input can pause the action before execution. When the rule fires on an output after execution, the approval becomes a warning. Claude Guard separately offers approval popups for intercepted outgoing requests while Claude in Chrome runs, giving users a chance to review those browser actions.
Willow’s built-in guards check for prompt injection, where instructions try to redirect an assistant, and for secrets or personal data. They start disabled and protect the connections wired to them. Checks connected to coding agents let a request continue after a timeout or when Willow cannot be reached. Claude Enterprise prompt checks support allow or deny decisions and let requests continue after Willow internal errors. Configure each connection deliberately.
Zuplo can mask, block, or log sensitive data in routed requests, and its AI Gateway data checks can check responses as they arrive. Its AI prompt-injection check blocks by default when the check fails and examines the newest message by default. Tool results count as messages; the application’s system and developer instructions, which define how the assistant should behave, fall outside that check.
Zuplo’s other checks have different error behavior. Its general outgoing prompt check lets traffic continue when the checking service cannot complete the check. Administrators can configure it to block on those errors. Its Akamai policy sends selected content to the configured external Akamai service and blocks on errors by default. Choose the check, data destination, and error setting together.
Willow Usage Hooks can stop prompts to a model after its monthly budget gets reached, with the plugin deployed and blocking enabled. Model budgets cannot stop Codex prompts. Claude Code can change models within a session without updating the budget check. Use the supported client reporting and model settings when deciding where to rely on these limits.
Zuplo offers spending and usage budgets, including limits on request counts and tokens. Models count their inputs and outputs in small units called tokens. Budgets can use hourly, daily, weekly, or monthly periods, with warning or blocking actions. User Apps apply individual budgets and show personal usage. Budget checks allow requests through on errors by default, and delayed accounting or requests already in progress can take spending above the limit. Model costs remain estimates from configured prices. A configured backup model can keep receiving requests after a budget runs out.
Both products also limit gateway requests. Willow sets tool-call caps independently for each user, with group and server filters. Zuplo can group request limits by authenticated user. Its MCP sign-in endpoints need a separate rate-limit policy; they start without request limits. Include sign-in routes when configuring protection against repeated requests.
Willow logs handled tool calls, connections, and sign-in activity with the identified user. Administrators can configure content logging, export filtered records as CSV, and send records to configured destinations. Retention settings can remove stored tool-call contents while preserving basic call details. This helps your team keep useful activity records with an explicit choice about retained content.
Zuplo’s MCP records include route and authenticated-user details, and can send activity records and recorded request steps to other systems through a configured logging connection. These MCP logs leave out the contents of customer requests. Enterprise account audit logs retain administrative actions for 90 days by default and prevent modification or deletion. The separate gateway request-audit policy records events on a best-effort basis, so a recording failure allows the request to continue.
Willow connects supported device discovery to allow, warn, and block rules for MCP servers and skills. Rules can target users, groups, or devices. Publish a rule to activate it; a saved draft changes nothing. For a blocked MCP configuration, the agent redirects its entry to a local Willow blocking service. IT can act on discovered configurations through that supported process.
Willow finds SKILL.md folders for about forty coding agents, plugin.json files for Claude Code, Cursor, and Codex, and supported instruction files such as CLAUDE.md and AGENTS.md. That gives IT an inventory of files employees add to their coding assistants. MCP and skill rules provide the corresponding allow, warn, or block choices for supported items.
Zuplo publishes Skills and plugins that help coding assistants build and operate Zuplo projects. Those development aids serve a useful engineering workflow. For a company reviewing employees’ installed skills and local MCP configurations, Willow’s Scan Agent and discovery rules directly address that work.
Willow gives IT several places to apply rules: supported local MCP configurations, supported browser prompts, connected MCP calls, and selected Claude-in-Chrome requests. Each needs its own setup. This suits a rollout where employees use more than one AI application and the company wants rules applied within those supported workflows.
Willow machine users give company agents a key and secret, a human owner, and access to the MCP servers assigned to their groups. That gives IT a named owner to review when agent access changes. Agents that sign in with a key and secret need removal in Willow separately from the sign-in provider’s employee offboarding. Assign an owner and a removal process before deploying those agents.
Choose Zuplo only if your developers need to build and operate a programmable API service, and only if Willow’s local MCP and skill rules fall outside your requirements. Zuplo can turn selected API operations into MCP tools and apply the configured rules. Developers can also check requests against the API’s expected format and write custom rules for those requests.
Consider Zuplo’s User Apps only if personal model keys drive your purchase, and only if Willow’s human tool-call approval does not matter to your team. Employees generate personal gateway keys without receiving the model provider’s keys. Administrators set model access and budgets. Separate administrator and AI User roles require the user-permission add-on; without it, every account member has administrator access.
Choose Zuplo for remote MCP access only if you need it within a Zuplo API project, and only if Willow’s supported browser prompt checks do not matter to your rollout. Zuplo combines individual or shared sign-in with configured tool access rules. Clients must send each request themselves; the gateway works without continuing sessions or messages initiated by the server. Check that your AI applications support that connection pattern.
As of 4 October 2026, Willow’s Free plan costs $0 and lists up to 15 users. Teams below 250 seats can move to the in-app team plan after outgrowing Free. Enterprise pricing follows annual human-seat tiers. Enterprise adds device discovery, browser and tool guards, machine users, and model-budget controls. Confirm which of these features the in-app team plan includes. Confirm the integration allowance for your selected plan and size the managed-agent allowance separately: each new hosted Willow Agents session consumes one credit from its monthly allowance.
As of 4 October 2026, Zuplo offers a Free plan with 100,000 requests per month and a $25-per-month Builder plan. Free MCP use has a separate development allowance of 1,000 tool calls per month. Builder targets solo and hobby use and lists five MCP users. Enterprise starts at $1,000 per month on an annual contract, with usage and add-ons affecting the total. Its basic service agreement includes 99.5% availability, with higher custom agreements available.
Deployment also affects the work your team takes on. Willow offers a hosted service and customer-hosted options, including Enterprise deployment with every component installed in the customer’s own environment. Zuplo offers customer-hosted deployment and vendor-operated dedicated hosting. Its standard customer-hosted setup still uses Zuplo cloud services for supporting features and requires outbound connections to them.
Start with Willow for supported employee device, browser, and connection rules. Add Zuplo’s API services or shared model connection only if your developers need that separate service, and only if Willow’s employee controls fall outside the added purchase. Where both handle MCP access, assign responsibility for sign-in, tool permissions, request limits, and activity records before building the connection path.
Start the employee rollout with Willow’s approved tool connections. Buy Zuplo only if a separate API project needs programmable request rules, and only if Willow’s device and skill rules fall outside that project.
For an IT or security team managing employee AI use, choose Willow’s supported device discovery, connection choices, browser checks, and tool approvals. These features address where employees configure tools and request actions. Choose Zuplo only if a separate API development or shared model project drives the purchase, and only if those Willow controls fall outside that project’s requirements.
Choose Willow for supported device configurations, browser prompts, company connections, and tool approvals. Zuplo also serves employees through registered MCP services, APIs, and model connections. Choose Zuplo only if API development or shared model access drives the purchase, and only if Willow’s employee controls do not matter to you.
Yes. AI Gateway User Apps offer personal keys, approved models, individual budgets, and usage views. Separate administrator and AI User permissions require an add-on. Without it, every account member has administrator access. Include those permissions in the rollout.
Willow’s deployed Scan Agent inventories supported MCP configurations, including those outside its gateway. Extra scans need enabling; running-process discovery applies to macOS. Windows Subsystem for Linux configurations appear without blocking controls. Coverage follows the supported clients and configuration formats.
Willow can require approval for each call to a selected tool. Apply approval before execution. An approval triggered by an already-executed output becomes a warning. Connection approval separately controls whether an employee-added MCP connection can become active.
Willow model budgets need the client plugin, cannot block Codex prompts, and can miss Claude Code model changes within a session. Zuplo offers budgets for spending and model use. These can limit request counts and tokens, the units a model counts in its input and output. Its error handling and delayed accounting can allow spending above a limit. A configured backup model can keep receiving requests after a budget runs out.
Willow supports Okta and JumpCloud directory sync. Test account deactivation and remove agents that use a key and secret separately in Willow. For either product, review connected-service sign-ins, shared accounts, and keys during removal. The chosen access method determines which account the connected service sees.
Yes. Willow offers customer-hosted deployment for tool execution or the full application, plus Enterprise deployments isolated from outside networks. Zuplo offers customer-hosted deployment and dedicated hosting; its standard self-hosted setup uses supporting Zuplo cloud services. Review required external connections for the selected deployment and connected tools.
Request applicable SOC 2 Type II reports from Willow and Zuplo, Willow’s ISO 27001 certificate, and the deployment scope. Willow also offers an Enterprise penetration-test report. Zuplo provides an Enterprise Business Associate Agreement for healthcare use as an add-on. Match assurance documents and contractual terms to the service you plan to buy.
As of 4 October 2026, Willow Free costs $0 for up to 15 users; team and Enterprise prices depend on the selected plan. Enterprise adds device scans, browser and tool checks, machine users, and model-budget controls. Confirm the team plan’s included features. Zuplo Builder costs $25 monthly; Enterprise starts at $1,000 monthly on an annual contract. Include allowances, add-ons, hosting, and managed-agent credits.
Give them a Basecamp. Go from AI chaos to AI work, in minutes.