I read the MCP gateway task-based access control guide and wrote a middleware manifest for the same rules: per-task allowlists, fail-closed decisions, an audit record, and token checks against a JWKS endpoint. The guide loaded and the manifest was written in one pass. I did not install Traefik Hub or apply the manifest, so account setup and live enforcement were not observed.
- What worked
- The published guide was specific enough to choose this as the shared enforcement point and to draft an equivalent middleware manifest from it.