Deep-Dives / MCP
MCP
Building, testing, securing, and operating Model Context Protocol servers — the practical layer above mcp-architecture's conceptual introduction.
- Building MCP Servers in PracticeIdiomatic server construction beyond hello-world — FastMCP decorators, TypeScript Standard Schema, when to expose a capability as a tool vs a resource vs a prompt, and what to actually put in the median five-tool server.
- Designing MCP ToolsMCP tools are prompts as much as APIs — description phrasing changes selection, granularity changes token cost, and the search-then-fetch pattern beats "give the model the whole document" every time.
- Testing MCP ServersThe in-process pattern still wins, but both SDKs changed the door — and with no handshake left to test, what you assert instead is that every request stands alone.
- Streamable HTTP: the current MCP transportThe single-endpoint transport after the session header, the GET stream and resumability were all removed — what every POST must now carry, and what subscriptions/listen replaced.
- MCP Auth: the OAuth 2.1 ProfilePKCE mandatory, RFC 8707 resource indicators, Protected Resource Metadata for AS discovery, Client ID Metadata Documents beating Dynamic Client Registration — the MCP-shaped subset of OAuth, and why 39% of production servers ship with none of it.
- MCP Security Anti-PatternsThe six patterns the 2025-11-25 spec forbids by name — confused deputy, token passthrough, session hijacking, SSRF via discovery, javascript-URL injection, startup-command execution — with the trace signature and mechanical fix for each.
- Sampling & Elicitation via MRTRServer-initiated requests are gone: the server now returns its questions and the client retries the call carrying the answers — and the state it hands over in between is attacker-controlled input.
- Tool Poisoning: Prompt Injection via Tool DescriptionsTool descriptions are prompts your model reads — when they come from a downstream data source that also takes untrusted input, they become an indirect prompt injection surface (CVE-2025-54136, MCPTox).
- MCP Ops in ProductionPer-tool kill switches, argument-shape (not value) audit logs, tenant isolation from verified token claims (not request bodies), and rate-limits sized for agent traffic.
- MCP Registry & DistributionThe registry is still in preview: publishing with mcp-publisher and a server.json manifest, the six package types, the two 2026 changes that break existing publishers, and why the manifest cannot tell a host which protocol revision you speak.
- The 2026-07-28 RevisionRemoving the handshake deleted the one place negotiation, identity and server-initiated requests used to live — so all three reappeared on every single request, and a server that does not restate them is now malformed.