Building a remote MCP server with ~100 tools and OAuth: six pitfalls worth knowing

AdPitiful4816 · reddit · 2026-10-03

The team behind Your Next Tours (an app letting tour guides broadcast live audio to their group) shipped a remote MCP server so guides can plug Claude, ChatGPT or Cursor into their account — drop an itinerary PDF in chat and the model builds the tour program, departure and guest list via tools. Endpoint: Streamable HTTP, stateless; auth via OAuth 2.1 + PKCE with self-hosted Ory Hydra.

Their hard-won lessons for anyone building MCP servers:

Scope design: every tool (reads included) requires a scope; trip edits can never notify guests — announcement emails are a separate scope; guest lists are masked by default with explicit, logged full-data access.

Original post →

More from coding & agent

coding & agent channel →