We deleted our MCP server's permission model—reuse your REST authz instead
Wide-Excitement-1315 · reddit · 2026-09-29
After a year running an MCP server against a multi-tenant production app, the author's team found their REST and MCP authorization policies had drifted, and fixed it by deleting MCP's separate policy layer. Key lessons: MCP tools must run the same capability and record-scope checks as REST endpoints; secure what agents hold, not what they're asked (grant only capabilities you hold yourself); check who already holds a tool before locking it down; and beware granted tools failing silently when names miss the registry—a bug that shipped twice, now caught at build time.
More from coding & agent
- Who grades the grader? A practical method for testing checks written by coding agents — jonah_omninode · 2026-09-29
- Perplexity launches multi-agent trading, running models like GPT-6 Astra and Grok 4.7 on Coinbase — AravSrinivas · 2026-09-29
- Perplexity details agent safety engineering: 'governance is an engineering problem' — perplexity_ai · 2026-09-29
- OpenRouter coding model share: GLM 5.3 Flash leads at 29.2%, DeepSeek V4.1 Flash at 25.6% — togethercompute · 2026-09-29
- InstaCloud raises $8M seed for agent-native serverless cloud that deploys itself — Shruti_0810 · 2026-09-29
- Routing with small models is 200x faster and 400x cheaper than LLMs, reshaping AI software architecture — Pavan_Belagatti · 2026-09-29