266 posts tagged with "Model Context Protocol"
Content about the Model Context Protocol (MCP)

Never Trust the Model: The AI Agent Gateway Pattern for Least-Privilege Infrastructure Access
40% of reachable MCP servers need no authentication and tool-poisoning fools flagship models. A concrete blueprint — scoped credential exchange, an OPA default-deny policy, ephemeral runners — that makes the gateway, not the model, the enforcement point.

Agents Deploy, Agents Never Hold the Keys: What Arcade.dev's OAuth-Handling MCP Runtime Means for Deploy-from-Chat
Deploy-from-chat dies the moment the agent asks for your API key. Arcade.dev's MCP runtime — Engine-vaulted OAuth, URL elicitation co-built with Anthropic, per-call scoped credentials — shows how agents deploy without holding tokens, with the deny, revoke, and re-scope paths spelled out.

Your Deploy Agent Is a Script With an API Key: What Agent Lifecycle Managers Actually Gate
A deploy agent with a scoped API key is a script with credentials that can improvise. How SPIFFE identity, RFC 8693 delegation, and Kagenti's agent registry gate every deploy call — and what scoped-keys-plus-audit-logs can't see.

MCP Breaks Forward Again: Pinning a Shipped Infrastructure Server Through the 2026-07-28 Protocol Churn
MCP revision 2026-07-28 deletes the initialize handshake and session IDs while 10,000-plus servers run in production. What broke, how each client/server era-mismatch fails for deploy, rollback, and log reads, and the pinning checklist — plus why a stable REST API under the MCP layer is the real durability story.

Your Infra MCP Server Is grep+read: What Semble's 98% Token Cut Teaches Tool Builders
Semble cut code-search tokens 98% by chunking, ranking, and refusing to dump whole files into context. Measured tokenizer counts show the same four techniques cut infra MCP responses 87-99% — fleet state, deploy status, and logs costed per 100 agent ops.

A2A Hit 150 Organizations in a Year: The Agent-to-Agent Protocol MCP Was Never Meant to Be
A2A grew from a Google proposal to 150+ organizations and a stable v1.0 in twelve months. What the agent-to-agent protocol covers that MCP deliberately doesn't — plus the precise triggers for when a deploy-from-chat roadmap needs both.

Great at Code, Bad at the Terminal: Why Deploy Agents Need Structured APIs, Not Shell Access
Top coding agents score 74-79% on SWE-bench but drop twenty-plus points on Terminal-Bench's real shell tasks. Those failure modes map directly onto deploy incidents — and argue for scoped MCP tools over raw kubectl access.

MCP Crosses 97 Million Installs: Who Actually Operates the Servers Behind Your Agent's Tool Calls
MCP's 97 million installs count client SDK downloads, not servers anyone operates. A custody accounting of vendor-hosted endpoints versus self-operated servers — token custody, poisoning audits, and what running your own MCP server takes.

Netlify Put Claude Code Inside the Deploy Pipeline: Embedded Runners vs MCP Servers for Agent-Driven Deploys
Netlify runs Claude Code and Codex inside its own infrastructure with full pipeline access; self-hosters expose deploys over MCP instead. A concrete accounting of what each position buys, what each costs, and why a platform on owned machines should ship the MCP surface first.