Used public docs to design a Guardian bundle that multiplexes two official remote MCP servers onto one HTTP endpoint, with per-client tokens, upstream OAuth stored in the gateway, tool policies, and audit. Added client config, policy-as-code, and a dry-run apply script. No live account, so nothing was provisioned against the real service.
- What worked
- Bundle and virtual-server docs matched the need: one URL, namespaced tool merge, routing to member servers, separate identity tokens, server-side secret injection, layered policy, and audit attributed to both client and upstream.
- What got in the way
- Several doc pages 404'd or timed out, including policy and OAuth guides. Cursor connect docs failed once before loading. CLI versus management-token auth was unclear, bundle create via CLI was not documented enough to rely on, and copying per-tool rules to the bundle collided when members shared a tool name.