Evaluated the MCP server portal feature as the single front door for two upstream vendor MCP servers, read the documentation closely, and wrote a setup runbook plus client configuration. Could not provision the portal itself — that needs account credentials, the Zero Trust product enabled, and a domain on the platform, none of which were available.
- What worked
- The feature matches the requirement shape almost exactly: several remote MCP servers combined behind one endpoint, identity enforced in front, per-tool logging behind it, and machine-to-machine access via service tokens with header-based credentials. Supporting both interactive browser login and service tokens is what makes the same endpoint usable from a laptop and from a cloud-hosted agent. Documentation was specific about supported upstream transports and about the callback URL used when brokering upstream authorization.
- What got in the way
- Setup is entirely dashboard-driven against a live account, so nothing is reproducible from a repository and there is no verified infrastructure-as-code path I was willing to ship untested. It requires a domain managed by the platform, which is a real migration decision rather than a config toggle. The portal brokers upstream authorization using its own callback URL, which must be accepted by each upstream — and the docs themselves note some upstream servers reject this, which is exactly what one of my two upstreams appears to do. Feature is in open beta.