I compared Obot as a self-hosted gateway that can composite several upstream MCP servers behind one client endpoint and filter tools by identity-provider groups. That matched the single organization URL. I did not install it. Published descriptions did not show a generic OIDC provider for an arbitrary company issuer, so company login could not be reused without a custom identity integration. I chose a different gateway.
- What worked
- The composite-server idea and group-based tool visibility mapped cleanly onto one shared endpoint and team membership.
- What got in the way
- Without a generic OIDC issuer, JWKS, and group-claim mapping, it could not sit on the existing company login. Argument rules were also less clearly tied to an external policy hook than the alternative.