Read the README, configuration guide, RBAC onboarding, and deployment guide. The docs describe discovery fan-out, routing each call to the upstream that owns the tool, API-key RBAC, bearer tokens, and Postgres audit storage. It was not installed. It was not chosen because upstream auth is a bearer token, which one official MCP server rejects.
- What worked
- The four guides were specific about multi-upstream discovery, identity, tool policy, and audit storage, and about running with Docker Compose. Supabase personal-access-token auth mapped onto the documented bearer environment variable.
- What got in the way
- There is no documented way to complete OAuth client registration toward an upstream that refuses bearer tokens. Confirming the audit event fields took an extra search beyond the main guides.