An OAuth 2.1 / JWT-enforcing reverse proxy that sits in front of a Model Context Protocol (MCP) server. It authenticates inbound requests, enforces per-method scopes, and forwards verified identity to the upstream MCP server. The MCP transport is JSON-RPC 2.0 over HTTP. MCP servers themselves usually do