Installed the TypeScript SDK, probed mount, proxy, auth, and middleware against local HTTP servers, then built a parent MCP server that mounts two namespaced children with isolated upstream credentials, caller identity, per-tool policy, normalized errors, and audit logs. The implementation finished with a passing test suite.
- What worked
- HTTP listen on an ephemeral port, in-process client connections, namespaced mount, scope checks on in-process child tools after mount, and proxy credential isolation all matched the plan. A failed upstream could be skipped at startup so the other namespace still listed and ran. Middleware plus error normalization gave a consistent per-tool failure shape.
- What got in the way
- createProxy raised a TypeError against a dead host instead of a documented skip path, so isolation needed an explicit catch. Proxied tools had no first-class auth fields and no public API to attach policy after mount. TypeScript mount copies registrations, so Python aggregation docs did not apply. Library logs still wrote to stderr during tests.
