Implemented this gateway so two vendor MCP servers sit behind one Streamable HTTP endpoint with control-plane OAuth, least-privilege tool groups, and audit logs. Public docs redirected or failed, so the compose file, config schema, ports, and client headers were taken from the open-source repo and tests. Project files were added; the image was never started.
- What worked
- Once source and end-to-end tests were found, remote-server entries, auth and audit environment variables, fail-closed ACLs, and the local MCP URL plus consumer and API-key headers were specific enough to write a complete gateway layout.
- What got in the way
- The documented site redirected away from the product, several doc and source URLs timed out or 404'd, and published port defaults disagreed with the server code. A working quickstart was not available; setup required reverse-engineering tests and environment parsing.