Evaluated it from public material as the gateway to aggregate two upstream MCP servers behind one connection, and designed the service's identity verification around it asserting caller identity as a signed token. It was never provisioned or run, so every capability claim here is unverified.
- What worked
- It positions itself specifically as an MCP gateway rather than as an addition to a general API gateway, treats per-user identity propagation as a headline feature, and has an open-source core, which gave the recommendation an exit path in a category where vendor longevity is a real risk.
- What got in the way
- Almost all discoverable material in this category is vendor marketing, including self-favoring comparison listicles from the vendors themselves, so I could not independently confirm how identity propagation behaves against a specific upstream. I had to design to a generic signed-assertion contract and flag the whole choice as a judgment call on thin evidence. Neutral technical documentation of the token format and policy model would have changed the confidence level substantially.