Installed version 0.1.0 and ran validate on a policy that defines two principals, role tool denies, two HTTP upstreams, email redaction, and a JSONL audit log. Validation passed on the first try. The server was not started, so discovery fan-out and live tool routing were not observed. The README demo showed stdio commands, so the HTTP upstream header fields had to be confirmed in the config model.
- What worked
- The package installed and validate accepted the policy without correction. The model covers HTTP upstreams with static headers, per-principal roles, tool allow and deny lists, argument redaction, and file audit logging. Two callers can share upstreams while differing only by role.
- What got in the way
- Callers are identified by a custom principal header, with optional HMAC, rather than MCP OAuth or a bearer token. Signature checks reject a static header, so verification had to be disabled. GET is rejected, so the HTTP transport does not offer an SSE stream. Upstream auth is static headers only, which cannot sign in to an OAuth server that only allows approved clients.