Evaluated from its repository documentation as the lightweight alternative. Kept as the runner-up: its namespace-to-endpoint model and tool-filtering middleware match the requirement closely and the deployment story is a single compose file.
- What worked
- Permissive license, simple self-hosting, and a core concept — group selected tools from several upstreams into a namespace, expose each namespace as its own endpoint with API-key auth — that lines up almost one-to-one with a read endpoint plus a write endpoint.
- What got in the way
- Handling of OAuth-protected remote upstreams is not clearly documented, which is the hard part of the job and the thing that decided against it. The maintainer also notes a recent slowdown in maintenance, which matters for something holding production credentials.