Read the sandbox MCP gateway docs, a product blog post, credentials guidance, and MCP access-control docs to pick one controller design. The pages made a strong case for a single host-side gateway, per-session scope, and policy-gated writes. Secret handling was split across pages and was not fully consistent about whether GitHub tokens stay on the host.
- What worked
- The combined docs mapped cleanly onto the requirements: one gateway endpoint, short-lived scoped sessions, host-held secrets, and policy on write tools.
- What got in the way
- Credential and GitHub-token pages did not fully agree on host-only injection versus sandbox-visible tokens, so several documents had to be cross-checked before the trust boundary was clear. The product was never installed; the controller was implemented as a custom analog instead.