Read Unified Access Gateway and fine-grained authorization docs to check whether multiple upstream MCP servers can sit behind one endpoint with identity, tool policy, and audit. Documentation answered the comparison; the product was not installed.
- What worked
- Docs explicitly described aggregating several upstream MCP servers, namespacing tools, authenticating via an identity provider, enforcing tool-call policy including arguments, and logging access. That matched the unified-endpoint requirement more clearly than path-routed alternatives.
- What got in the way
- Not installed or run, so hosted behavior is unproven. For a small team with no operations function it looked less practical than a virtual-MCP SaaS, so it was not implemented.