266 posts tagged with "Model Context Protocol"
Content about the Model Context Protocol (MCP)

Dokploy Has an MCP Server Too — and It's Bigger Than Coolify's: An AI-Agent Operator's Comparison on a $5 Hetzner Box
Dokploy's official MCP server gives AI agents full deploy and lifecycle control while Coolify's built-in MCP is read-only — here is what each agent interface can actually do, and what each control plane costs in idle RAM on a $5 Hetzner box.

Don't Hand-Write an MCP Server: Project Your REST API Through a Gateway
Hand-writing an MCP server means maintaining a second governed interface. What projecting your REST API through a gateway gives you for free — OpenAPI-derived tools, OAuth 2.1 auth, rate limits — and the write-scoping, approval, and rollback semantics a deploy API still has to build itself.

E2B Is Now Native in OpenAI's Agents SDK: The Bar a Self-Hosted Agent Sandbox Has to Clear
OpenAI's Agents SDK declares E2B sandboxes natively since April 2026. This post turns that integration into a six-part checklist — cold start, isolation, templates, lifecycle, MCP sandboxing, egress policy — and scores four self-hosted paths against it.

Hardening an Infrastructure MCP Server: TLS, Scoped Credentials, and Rate Limits Before an Agent Touches Production
An MCP server that can redeploy production is a deploy pipeline with natural-language input. A seven-control hardening checklist — TLS, per-tool scopes, short-lived credentials, schema validation, rate limits, and audit logging — mapped to the three attacks that actually happen.

MCP Retires Dynamic Client Registration: The OAuth Migration Your Self-Hosted Server Has Twelve Months to Finish
The final MCP spec deprecates Dynamic Client Registration in favor of Client ID Metadata Documents, with removal eligible after July 2027. Here is the ordered checklist for migrating a self-hosted MCP server, plus the two companion hardenings to ship in the same window.

Deploy Agents That Wait: Building a Stateless Rollout-and-Approval Agent on MCP Tasks and Multi Round-Trip Requests
MCP's July 2026 release made the protocol stateless and gave agent builders Tasks and Multi Round-Trip Requests. Here is the concrete design for a deploy agent that returns a task handle, polls rollout status against Kubernetes Deployment conditions, and stops for an expiring human approval before promoting to production.

One Missing Middleware Call, 2,689 Exposed Servers: What nginx-ui's MCPwn (CVE-2026-33032) Teaches Anyone Shipping an MCP Server
nginx-ui shipped an MCP endpoint without its AuthRequired check — a CVSS 9.8 that left roughly 2,689 servers open to unauthenticated takeover. The full MCPwn timeline, the two-route bug, and a seven-item audit checklist for anyone shipping an MCP server.

Cloudflare Deprecated McpAgent: What a Stateless MCP Handler Buys (and Costs) a Deploy-From-Chat Server
Cloudflare's Agents SDK v0.20.0 deprecated McpAgent in favor of a stateless createMcpHandler, tracking MCP spec 2026-07-28. Here is what dropping the per-session Durable Object buys, where multi-step deploy state moves instead, and how to migrate without breaking older clients.

Falco's Prempti Is a Policy Layer for AI Coding Agents, Not Kernel Security: What It Catches and Misses
Falco's Prempti judges an AI coding agent's tool calls before they execute — but it never sees a syscall. A scenario-by-scenario map of what hook-level policy, eBPF monitoring, and microVM sandboxes each catch and miss on the deploy-from-chat path.