How do you secure 15-plus MCP servers without confusing the model?
Dangerous-Tree-6734 · reddit · 2026-07-21
A user running 15+ MCP servers asks how people manage secrets and permissions without turning the setup into a mess.
Their current approach is:
- keep credentials out of tool configs and reference them from a single gitignored file;
- lock down servers that can send, write, or delete anything, and require confirmation before destructive actions;
- leave read-only servers freer to run;
- keep only the servers actively in use loaded, because too many tools confuse the model.
They ask whether people use env vars, a proper secrets manager/vault, client-side or server-side permission scoping, or a gateway/proxy for central auth and logging.
More from coding & agent
- Anthropic researcher: 99% of engineers now run swarms of 300+ self-improving agents — AlishaOutridge · 2026-09-11
- Gergely Orosz: Shipping 10x PRs With AI Agents, Sites Fill With Small Regressions — ducha_aiki · 2026-09-11
- Same Echo Maze prompt, three frontier models: all passed visually but shipped the same hidden bug — eyishazyer · 2026-09-11
- Astra storyboards plus Minimax H3 per-shot generation boost video success rates — Hailuo_AI · 2026-09-11
- Codex tip: use Sol with Astra and Luna sub-agents to save usage — pvncher · 2026-09-11
- agents-best-practices: a provider-neutral Agent Skill for designing and auditing agentic harnesses — tom_doerr · 2026-09-11