Installed this library to host one HTTP endpoint that mounts several upstream MCP servers, checks a short-lived task token, and records each tool call before returning it. Guides for auth, proxying, and logging described an older API than the release that was installed, so the working design came from the installed package. Final tests passed, including upstream credential replacement and token revocation.
- What worked
- Proxy mounting, bearer-token verification, middleware around tool listing and calls, custom HTTP routes, and the ASGI app were all available. After the code matched the installed interfaces, tests covered rejected and revoked tokens, credential replacement on upstream calls, and the controller path that mints and revokes a token.
- What got in the way
- Published guides did not match the installed major version: expected top-level exports were missing and helpers had moved, so the package source had to be read before the proxy would start. By default the proxy forwarded the caller's Authorization header upstream, which would leak the task token. A custom client credential was required to strip or replace that header. Host allowlisting and transport mode also had to be set explicitly.
