Two companies. One gateway. A trade secret complaint just turned the Model Context Protocol ecosystem into a courtroom exhibit.
Runlayer, a startup selling enterprise-grade MCP gateways, filed suit against Rippling โ the HR, IT, and payroll decacorn โ alleging "almost 1-to-1" copying of its gateway deployment architecture. Not feature-level similarity. Code-level. Architecture-level. The kind of allegation that, if proven, converts competitive overlap into a copy-paste scandal.
The complaint landed while the MCP stateless specification was still being finalized. That timing is not a footnote. It is the story.
Two weeks ago, this case was a niche legal brief. Today, it is the clearest evidence yet that the agent economy has a value-capture problem โ and that the problem is about to be litigated, line by line, in public.
The mainstream narrative around AI agents has been all models, frameworks, and agentic loops. The real battleground โ the gateway layer between an autonomous agent and an enterprise's most sensitive data โ just got its first legal landmine. The precedent will shape the next three to five years of agentic infrastructure. Far beyond two companies fighting over source code in a California courtroom.
Here is the structural reality most coverage misses. MCP was built as an open protocol. The stateless specification finalization pushes the protocol layer toward standardization and public interoperability. But the spec deliberately leaves the control plane open. Authentication. Access control. Observability. Policy execution. Session management. State handling. Those functions did not vanish when the protocol went stateless. They migrated upward, into the gateway.
That is the crux. The gateway is not a thin proxy bolted onto a model. It is a concentrated control plane where engineering complexity runs an order of magnitude deeper than a simple API proxy. That is where proprietary, protectable space actually lives. The stateless spec is significant precisely because it removed state from the protocol's core. Statelessness lowers the barrier for servers to plug in โ but it does not eliminate state. It relocates it. Session governance, conversation context, data provenance, permission caching: all of it moves upstream to the gateway. The layer that manages state is the layer that holds the leverage.
Consider what an enterprise gateway actually does in production. It authenticates every agent request. It decides which data sources an agent can touch. It enforces policy in real time. It logs everything for audit. It caches permissions. It tracks data lineage. None of this is defined by MCP. The protocol specifies how clients and servers talk. Everything after the handshake is implementation โ and implementation is where trade secrets live.
Snowflake and AWS launched their own gateway products in the same window. That is the market acknowledging gateway infrastructure is no longer an accessory. It also means independent gateway startups are being squeezed from above โ and from the side, by platform companies like Rippling deciding to build rather than pay.
I have watched this pattern play out in my own sector. In DeFi, the oracle layer was supposed to be neutral plumbing. It became the Achilles' heel of the entire stack โ and the most monetized layer in it. Oracle feed latency broke protocols. The agent economy is replaying the same script. The protocol is open. The value capture point is not.
This case lands at a specific moment in the adoption curve. Enterprise AI spending has moved past the pilot phase. Procurement teams are now asking hard questions about governance, audit, and data access. That is exactly when a control-plane product like the gateway stops being a developer convenience and becomes a purchasing category. The moment a category forms, the land grabbing starts. Snowflake, AWS, and Rippling all recognized it at roughly the same time. So did Runlayer โ which is why it wrapped its architecture in NDAs from the first trial.
Start with the technical claim. "Almost 1-to-1 copying" is an aggressive legal statement. In my experience chasing code-level disputes, copy-paste allegations usually die at the first line-by-line comparison. The ones that survive carry forensic fingerprints: watermark constants, unique identifier formats, deployment sequencing, configuration breadcrumbs. The complaint is deliberately vague about Runlayer's actual secrets. That is not a weakness. That is trade secret hygiene. Every specific disclosed in a complaint narrows the protected scope. Obscurity is the asset.
This is where my forensic history kicks in. In December 2017, when the Parity wallet library was gutted by a reentrancy attack, I spent 48 hours mapping the vulnerability path through the initWallet function while most outlets waited on press releases. That taught me a rule that has never failed: when a copy claim surfaces, look for the watermark. Did Runlayer embed unique identifiers in its gateway deployment? Did it build configuration traps that only fire in a copy? If yes, discovery will be devastating for Rippling. If no, the case rests on inference โ and inference is a weak foundation for a trade secret claim.
The phrase "specific gateway deployment architecture" in the complaint deserves closer reading. Runlayer is not claiming Rippling stole a single algorithm or a chunk of source code. It is claiming Rippling took a deployment paradigm โ the way authentication, routing, policy, and audit are composed into a coherent security architecture. That is harder to prove and harder to defend against. Single-function copying is easy to rebrand as independent implementation. Architectural copying leaves structural fingerprints that survive refactoring. This is the strongest technical card Runlayer holds.
Now Rippling's defense. The MCP specification is public. Reference implementations are public. If Rippling's gateway was engineered to conform to the same spec, a substantial portion of its architecture will resemble Runlayer's by necessity. Protocol-interop-required replication is not misappropriation. The court must draw the line between "replication required for interoperability" and "replication beyond what interoperability requires." That line is the entire case โ and no court has ever drawn it for MCP.
Trade secret law has a quiet technical requirement that most tech coverage skips: the plaintiff must prove it took reasonable measures to maintain secrecy. NDAs count. But the bar is demanding. Widespread distribution of documentation, permissive API access, or loose partner agreements can gut a claim before the copying question is even reached. Runlayer's early commercialization through enterprise trials was, in part, a legal strategy โ each trial under NDA builds the evidentiary record that the secret was actually secret. That detail matters more than the rhetoric in the complaint.
Discovery is where this gets dangerous for both sides. Runlayer wants to prove copying. To do that, it must expose its architecture in granular detail โ feeding the public record the very secrets it is protecting. Trade secret litigation is a paradox: you sue to defend a secret, then spend eighteen months disclosing it to prove the claim. Rippling wants to prove independent development. To do that, it must open its engineering timeline, its git history, its internal communications. Discovery exposes things neither party planned to expose.
The business layer matters here. The gateway is the toll gate of the agent economy. Runlayer's path was textbook enterprise software: trials under NDA, controlled customer access, then license negotiation. When the negotiation with Rippling broke down, Runlayer suspended service rather than discount. That is a pricing signal. Runlayer believes its gateway carries strategic value, not commodity value. The filing does not disclose the pricing model โ seat-based, call-based, data-volume-based, or subscription. The structure matters because it reveals where Runlayer believes its leverage sits. A vendor charging per data volume is selling access to enterprise data as the product. A vendor charging per seat is selling compliance. The absence of pricing details on the docket is itself a data point.
Rippling's response โ self-build instead of buy โ is the more interesting signal. Rippling sits on a mountain of enterprise data: payroll, HR records, IT assets, employee lifecycle information. A gateway connecting AI agents to that data is not a tool. It is a moat. The shift from "buying a tool" to "buying a capability" may have been the real reason the negotiation collapsed. Rippling's engineers likely realized the gateway could become part of its own product ecosystem โ a closed data-access foundation linking AI tools to Rippling's systems. That is not supplier behavior. That is competitor behavior.
Then there is Rippling's public claim that Runlayer is a "commercial failure." That is an odd thing to put in a legal filing. It reads less like an assertion of fact and more like a narrative weapon: even if the code is similar, the argument goes, Runlayer has no legitimate market position to protect. Courts are not supposed to care about market share in trade secret disputes. But juries do. The smear tells you the fight is not really about code. It is about who gets to own the enterprise data access layer.
The second-order competition makes this existential. Snowflake and AWS are now in the gateway market. Both can bundle gateway functionality into existing cloud contracts at near-zero marginal cost. An independent gateway vendor is competing against infrastructure priced at zero. That is a squeeze. Runlayer's lawsuit may be less about vindication and more about survival โ a legal claim as a business strategy. When you cannot win on pricing, you litigate.
The Terra collapse in 2022 taught me something similar. The public narrative was all about external market manipulation โ the data showed a major player quietly exiting positions days before the crash. Narratives are always cleaner than the underlying flows. The same applies here: the clean narrative is "startup wronged by platform giant." The underlying flow is a structural fight over where value concentrates in the agent stack. Volume spikes lie; liquidity flows tell the truth.
Here is the angle nobody is covering. The conventional framing casts Runlayer as the wronged startup and Rippling as the bully. That framing may be exactly backwards. If Runlayer wins โ if a court rules that "almost 1-to-1 copying" of a gateway architecture built on an open protocol constitutes trade secret misappropriation โ then every vendor building on MCP inherits a legal fog. How similar is too similar? Where does spec compliance end and architectural copying begin? The chilling effect will hit small builders hardest. Incumbents will hire armies of lawyers. Litigation becomes a moat. That is not innovation. That is rent extraction by other means.
There is also a doctrine lurking in the background that nobody in the AI press has mentioned: inevitable disclosure. Some jurisdictions recognize that once a person or a company absorbs a trade secret, they cannot simply unlearn it. If Rippling's engineers worked with Runlayer's gateway during the trial period and then built a similar system, the argument writes itself. The defense will counter with clean-room evidence โ proof that the in-house team never saw Runlayer's internals. The discovery record will decide which story survives.
This mirrors a debate my own industry has circled for years. The market obsesses over the data availability layer while 99% of rollups do not generate enough data to justify a dedicated DA chain. The obsession is misplaced โ the value sits elsewhere. The MCP ecosystem is making the same mistake. Everyone treats the protocol spec as the center of gravity. But the stateless spec did not decentralize anything. It consolidated power into the control plane. The "open standard" is the lure. The gate is the business.
The Lightning Network has been functionally half-dead for seven years. Not because the technology is unsound, but because routing complexity and channel management never scaled for ordinary users. Open protocols that push complexity upward do not democratize. They centralize. MCP's stateless spec pushes state management into proprietary gateways โ the same structural error. The outcome was always predictable: whoever controls the gateway controls the flows.
One more question nobody is asking: why sue a customer? Rippling was a prospective customer. Launching a trade secret suit against a prospect sends a signal to every enterprise evaluating next-generation gateway products: do business with this vendor and you might be next. Even if Runlayer prevails, its sales pipeline may have been sacrificed to win. That is a brutal trade, and it reveals how cornered the company feels.
Crypto-AI projects should be reading this filing carefully. The same dynamics apply to decentralized inference networks, agent marketplaces, and anything built on open protocols with proprietary execution layers. If a court endorses aggressive trade secret protection for gateway architectures, the cost of building in the open goes up. If the court rejects it, the value of proprietary control planes drops. Either way, the "decentralized" pitch for AI infrastructure collides with the legal reality of who can claim ownership over software architecture.
Investors should watch this docket for another reason. The gateway layer is becoming a distribution point for AI compute and data access. Whoever controls it controls pricing. In crypto terms, this is the same fight as the oracle wars of 2020 โ except the winners are clearer now. Oracle projects captured enormous valuations by owning the price-feed layer. The gateway layer is the agent economy's equivalent. This lawsuit is a signal that the battle for that layer has begun โ and it will not be settled by technology alone.
The deeper question for MCP governance is whether the spec should absorb gateway functionality in future iterations. If the protocol itself standardizes authentication, policy, and audit interfaces, the proprietary surface shrinks and Runlayer's claim weakens. If the spec stays thin, gateways remain proprietary, and litigation becomes a recurring feature of the ecosystem. That is a governance decision, not a legal one. This lawsuit just made it urgent.
The docket, not the headline, is the next thing to watch. Discovery will reveal whether Runlayer planted watermarks. It will reveal Rippling's engineering timeline. It will reveal whether the negotiation breakdown was about price or strategic repositioning.
Speed is safety when the exploit is already live. The exploit here is ambiguity โ the undefined boundary between open protocol and proprietary control plane. Every company building agent infrastructure is exposed to it. The next three to five years of the agent economy will be written in the margins of this case.
The adoption chart doesn't lie. Neither will the discovery record. We don't need more predictions. We need the evidence โ and for once, the evidence is going to be public.