MCP

Building, testing, securing, and operating Model Context Protocol servers — the practical layer above mcp-architecture's conceptual introduction.

  1. Building MCP Servers in Practice
    Idiomatic server construction beyond hello-world — FastMCP decorators, TypeScript Standard Schema, when to expose a capability as a tool vs a resource vs a prompt, and what to actually put in the median five-tool server.
  2. Designing MCP Tools
    MCP tools are prompts as much as APIs — description phrasing changes selection, granularity changes token cost, and the search-then-fetch pattern beats "give the model the whole document" every time.
  3. Testing MCP Servers
    The in-process pattern still wins, but both SDKs changed the door — and with no handshake left to test, what you assert instead is that every request stands alone.
  4. Streamable HTTP: the current MCP transport
    The single-endpoint transport after the session header, the GET stream and resumability were all removed — what every POST must now carry, and what subscriptions/listen replaced.
  5. MCP Auth: the OAuth 2.1 Profile
    PKCE mandatory, RFC 8707 resource indicators, Protected Resource Metadata for AS discovery, Client ID Metadata Documents beating Dynamic Client Registration — the MCP-shaped subset of OAuth, and why 39% of production servers ship with none of it.
  6. MCP Security Anti-Patterns
    The six patterns the 2025-11-25 spec forbids by name — confused deputy, token passthrough, session hijacking, SSRF via discovery, javascript-URL injection, startup-command execution — with the trace signature and mechanical fix for each.
  7. Sampling & Elicitation via MRTR
    Server-initiated requests are gone: the server now returns its questions and the client retries the call carrying the answers — and the state it hands over in between is attacker-controlled input.
  8. Tool Poisoning: Prompt Injection via Tool Descriptions
    Tool descriptions are prompts your model reads — when they come from a downstream data source that also takes untrusted input, they become an indirect prompt injection surface (CVE-2025-54136, MCPTox).
  9. MCP Ops in Production
    Per-tool kill switches, argument-shape (not value) audit logs, tenant isolation from verified token claims (not request bodies), and rate-limits sized for agent traffic.
  10. MCP Registry & Distribution
    The registry is still in preview: publishing with mcp-publisher and a server.json manifest, the six package types, the two 2026 changes that break existing publishers, and why the manifest cannot tell a host which protocol revision you speak.
  11. The 2026-07-28 Revision
    Removing the handshake deleted the one place negotiation, identity and server-initiated requests used to live — so all three reappeared on every single request, and a server that does not restate them is now malformed.