Production MCP Gateway Paper Documents an Enterprise Fleet That Went From Zero to Dozens of Internal MCP Servers in One Year
An industry deployment report describes a centralized MCP gateway fronting every downstream server after teams independently implemented auth — some with none, some API keys, some full OAuth — leaving no consistent way to authorize callers, audit actions, or offboard departing employees. The architecture contributes a two-axis model crossing persona (interactive user vs automated non-user) with credential type, a gateway layer supporting three enterprise SSO grants and three token-provisioning models (Bring-Your-Own-Token, Generate-Your-Own-Token, and delegated OAuth via RFC 8693 token exchange), and three end-to-end identity flows. It is in production across web, desktop, custom-SDK and low-code clients, making it one of the few concrete references for MCP identity delegation at scale.
↳ Follow the thread