527 posts tagged with "AI agents"
AI agents and autonomous systems

E2B vs Modal vs Daytona in 2026: What Agent Sandboxes Get Right That Agent-Operated Deploys Still Don't
E2B and Daytona charge $0.0504/vCPU-hour for agent sandboxes while Modal charges about 40% more — but none of them hands an agent a persistent HTTPS URL with a custom domain, TLS, and rollback. A 2026 three-way comparison plus the deploy gap a PaaS still has to close.

Whose Token Is It? Solving the MCP and OAuth2 Identity Problem for AI Agent Deploys
Every deploy, rollback, or scale call an AI agent makes must answer who authorized it: the developer, the agent, or the tenant. This post maps the three-identity model, the July 2026 MCP authorization rules, and the token-exchange pattern that keeps deploy-from-chat auditable.

Deploy From Chat Without Handing the Agent Your Production Keys: Remote MCP After the 2026-07-28 Spec
A production design for a deploy-capable remote MCP server under the 2026-07-28 spec: OAuth discovery via protected-resource metadata, audience-bound tokens, narrow per-environment scopes, human approval gates for destructive tools, and chain-complete audit logs.

Stripe's Agentic Provisioning Protocol Puts Railway One CLI Command Away — and Draws the Line Where MCP Stops
Stripe's Agentic Provisioning Protocol takes agents from nothing to a running Railway resource — account, $5 trial, credentials, Postgres — in one CLI flow MCP cannot express. How discovery, authorization, and tokenized payment work under the hood, and a seven-item checklist for the self-hosted equivalent.

CIS Shipped the First MCP Server Benchmark: A 10-Domain Hardening Checklist Before Agents Get Production Credentials
The CIS MCP Server Benchmark v1.0.0 packs 55 recommendations into 10 security domains — here is each domain mapped to a concrete pass/fail check for a self-hosted PaaS deploy/operate surface, plus the four gaps to close before agent credentials touch production.

MCP Won: Why Every Major AI Vendor Shipping One Protocol Makes 'Deploy From Chat' a Safe Roadmap Bet
Anthropic, OpenAI, Google, Microsoft, and Amazon all ship MCP now — 97M monthly SDK downloads, 10,000+ servers, neutral foundation governance. What that convergence changes about betting your platform's deploy/rollback/logs agent surface on one protocol, and the four residual risks to budget for.

MLflow's MCP Registry: Versioned, Governed Tool Dependencies for Production Agents
MLflow 3.15.0's experimental MCP Registry versions MCP servers with semver, promotes them through staging and production aliases, snapshots their tools, and links traces to exact versions — a worked walkthrough of the promotion loop, the registry-vs-gateway boundary, and when a second tenant makes the catalog mandatory.

OpenAI Built Codex a Windows Sandbox Out of SIDs and Firewall Rules: What It Teaches a Linux-First PaaS About Isolating Agent Code
OpenAI's May 2026 write-up shows how Codex sandboxes agent commands on Windows with synthetic SIDs, write-restricted tokens, dedicated sandbox users, and firewall rules — here is the two-tier design, the three isolation lessons a Linux-first PaaS should take from it, and an explicit verdict on whether it needs a Windows tier.

Pangolin Puts SSO and WireGuard in Front of LLM Access Instead of API Keys: What Tunnel-Based Identity Means for Agent Credential Hygiene
Pangolin's AI Gateway authenticates LLM access with SSO-backed WireGuard tunnels instead of static API keys, and joins self-hosted models to the same gateway as public ones. Here's how the mechanism works, how it compares to Tailscale Aperture, and what it changes in your threat model.