Skip to content

Topic

Model Context Protocol

Model Context Protocol (MCP) is an open standard from Anthropic that lets AI models and agents discover and call external tools and data sources.

Current stories

build1 publisher

DoorDash wraps MCP tool calls in one gateway for permissions, credentials and audit

DoorDash built a shared Agent Gateway that checks permissions, manages credentials, filters which tools agents see, forwards calls and logs them. MCP settles how tools are listed and called, but deciding who may call which tool, and with whose account, was work DoorDash still had to build.

Reality

Evidence40
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence45
build1 publisher

Six OAuth steps run before an MCP client makes its first tool call

The MCP spec mandates OAuth 2.1 with PKCE, dynamic client registration and metadata discovery for remote servers. The one-hour tokens and customer-facing audit logs procurement asks about come from a guide's own bar.

Publishers:dev.to

Reality

Evidence40
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence48

Earlier coverage

  1. Foundry's Toolbox pins the MCP allow-list that a server can otherwise redefine at any time

    Build · September 17, 2026 · 1 publisher

  2. The default MCP deployment buys a Kubernetes operational surface for request/response traffic

    Build · September 17, 2026 · 1 publisher

  3. Mapbox's Agent Toolkit lets a model add a stop to a route the driver is already driving

    Build · September 17, 2026 · 1 publisher

  4. Eight MCP servers per session push the p90 connect wait to 35.5 seconds

    Build · September 15, 2026 · 1 publisher

  5. A $4 rewrite of MCP tool descriptions moved Toolmetry's SQLite success from 34% to 100%

    Build · September 15, 2026 · 1 publisher

  6. MCP's Python SDK 2.0 yields two values where wrapper libraries still unpack three

    Build · September 13, 2026 · 1 publisher

  7. Leaving readOnlyHint unset is what makes a missing destructiveHint default to true

    Build · September 12, 2026 · 1 publisher

  8. Salesforce exposes its platform to coding agents through more than 60 new MCP tools

    Product · September 11, 2026 · 1 publisher

  9. Renaming FastMCP to MCPServer closes stdio before an unpinned server finishes its handshake

    Build · September 11, 2026 · 1 publisher

  10. A caching proxy handed one caller's poisoned MCP instructions to a client that never connected

    Build · September 11, 2026 · 1 publisher

  11. A hand audit of 45 register questions found 34 hedges and three confabulations

    Build · September 10, 2026 · 1 publisher

  12. MCP's stateless revision moves session continuity into a string the model repeats back

    Build · September 6, 2026 · 1 publisher

  13. Empty tax IDs turned a risk check into eleven clean sellers

    Build · September 2, 2026 · 1 publisher

  14. MapMcp publishes your whole tool list before you add a single auth check

    Build · September 2, 2026 · 1 publisher

  15. Curator approval gates every record AWS Agent Registry shows a consumer

    Build · August 31, 2026 · 1 publisher

  16. A read-only MCP key drops the write tools out of tools/list

    Build · August 30, 2026 · 1 publisher

  17. Auto-approving read_resource moves MCP's retrieval decision into the model

    Build · August 29, 2026 · 1 publisher

  18. MCP's 2026-07-28 revision relocates client capabilities from the handshake into every request

    Build · August 29, 2026 · 1 publisher

  19. Agents climbed from 3% to 50% of the work created in Linear in four quarters

    Invest · August 28, 2026 · 1 publisher

  20. AWS wires Bedrock Guardrails into the hook that fires before a Strands agent calls a tool

    Build · August 27, 2026 · 1 publisher

  21. Lovable will hand your published app to any AI assistant as a set of callable tools

    Product · August 27, 2026 · 1 publisher

  22. Nutanix puts agent token quotas and a single-control-plane claim into Enterprise AI 2.8

    Product · August 26, 2026 · 1 publisher

  23. AWS puts the trace waterfall inside the tool response, betting verification is the slow part

    Build · August 25, 2026 · 1 publisher

  24. MCP's empty-string cursor: the null check that hides most of a tool catalog

    Build · August 24, 2026 · 1 publisher

  25. AWS's phone-ordering host is really an MCP wiring diagram with no retry button

    Build · August 24, 2026 · 1 publisher

  26. MCP standardizes the tool call, not the authority to cause the effect

    Build · August 24, 2026 · 1 publisher

  27. A 200 Is Not A Row Count: How Agents Inherit Open Data's Silent Caps

    Build · August 23, 2026 · 1 publisher

  28. A SKILL.md layer quietly rerouted an agent off the MCP tools it was given

    Build · August 22, 2026 · 1 publisher

  29. MCP's roadmap fast-tracks five priorities and quietly queues everything else

    Build · August 22, 2026 · 1 publisher

  30. EDR sees the file write, not the reason: the case for an agent-native detection layer

    Build · August 21, 2026 · 1 publisher

  31. The agent did not fail, the client did: 90 logged MCP trials and a validator that ate the calls

    Build · August 21, 2026 · 1 publisher

  32. MCP is a discovery layer, and your exposure list is a governance decision

    Build · August 21, 2026 · 1 publisher

  33. Twin1's $20M bet: the unit of enterprise AI is one employee, not the org

    Product · August 20, 2026 · 1 publisher

  34. MCP 2026-07-28 drops the `result` wrapper, and your unit tests will not notice

    Build · August 20, 2026 · 1 publisher

  35. Binance gives agents a trading seat, and gives users the permission slip

    Product · August 20, 2026 · 1 publisher

  36. x-mcp-header is a wire contract: one bad annotation invalidates the whole MCP tool

    Build · August 19, 2026 · 1 publisher

  37. Amazon Q executed code from any repo you opened, and it is not the only one

    Build · August 19, 2026 · 1 publisher

  38. Salesforce turns 200-plus Data 360 APIs into MCP endpoints, and governance into a grant decision

    Product · August 19, 2026 · 1 publisher

  39. Kubernetes MCP servers hide the delete tool; hiding is not removing

    Build · August 18, 2026 · 1 publisher

  40. Foundry IQ knowledge bases ship as MCP servers, and four behaviours break naive clients

    Build · August 18, 2026 · 1 publisher