HN user

kosmozaut

32 karma
Posts0
Comments17
View on HN
No posts found.

MCP supports authentication via OAuth2, which is what we use here. For the most part, this means that a browser window is opened and the user can sign in with their GitHub or Google account. The access token is verified by us and passed to the upstream MCP server.

We'd love to allow orgs to bring their own IdP but there is some refactoring we still have to do for this.

This is so true! While planning a trip abroad last year we were unsure about whether $thing is legal in $country. Google proclaimed in bold letters that, yes, $thing is legal in $country, but this line was taken from a site with the title "common misconceptions about traveling in $country" an in fact $thing was not legal.

Such a basic mistake, I haven't trusted the instant results ever since.

Is there anything that prevents you from doing that today? I mean the app in this post still seems to work. Apart from some parts of the system that have been pretty much locked down, I think one reason that apps are much larger today is that our expectations increased dramatically.