4 ms·
Reflections on building with Model Context Protocol
- OutOfHere 2y agoDoes this work with GPT too or only with Claude? If it does, where is a relevant example?
- outlore 2y agoI believe ChatGPT does not support MCP integrations yet
- outlore 2y agoAfter recently learning about MCP from HN, I started working on some demos. I jotted down my thoughts about my developer experience and potential room for improvement.
- verdverm 2y ago> letting servers notify clients that a resource (like a database) was updated Do you have a link to the spec where they cover this use case? Why is callback in OpenAPI not sufficient for this? https://swagger.io/docs/specification/v3_0/callbacks/ https://swagger.io/docs/specification/v3_0/callbacks/
- outlore 2y agoSure that would be here https://modelcontextprotocol.io/docs/concepts/resources#content-changes https://modelcontextprotocol.io/docs/concepts/resources#cont... I think OpenAPI callback would certainly work but the client application must support this. For e.g. I don’t think ChatGPT supports callbacks (I might be wrong). Broadly speaking I am agreed with you that OpenAPI can replicate much of the functionality of MCP, but what’s missing is the opinionated contract between client and server (similar to LSPs)
- verdverm 2y ago> opinionated contract between client and server That makes it more of a DSL on a protocol (json-rpc) than a protocol itself If you want to implement notifications without callbacks, you either (1) use an always connected session and pass messages or (2) have the client poll an endpoint
- cadamsau 2y ago> jotted down As an MCP fan, am curious! Care to share. Link maybe? Or even just a comment would be great!
- outlore 2y agoOops sorry, I am OP and was referring to the submission link :)
- somnium_sn 2y agoReally appreciate the write up. I am one of the authors of MCP and this helps a great deal giving a good overview of where we need to do better. I was a bit under the water over the last few weeks with talking to people about MCP and just generally a bit overwhelmed about how well it has been received. I'll take a look at issue88 this week. Thanks so much
- outlore 2y agoThanks so much! Appreciate all that you do. I gave my demo at work and it was really well received. The MCP server was rock solid. Hope you get some time to rest!
- andrewchambers 2y agoThanks for MCP, I think it is sorely needed, it shouldn't take more than a single file shell/python script to teach an llm how to access a resource.
- lmeyerov 2y agoHow is the community doing authentication & authorization? We're considering how to support in louie.ai, anticipating a large ecosystem of sites supporting it, yet the original spec had essentially TODO for how to do authentication & authorization bindings...
- babyshake 2y agoIt seems that maybe the direction things are heading in is having desktop apps that can take over the computer, and prompt you to sign in yourself when auth is needed. Which would limit the usefulness of something like MCP as the interface becomes the UI, not APIs. But I'd be curious what other approaches to auth seem to be promising.
- Terretta 2y ago> what other approaches to auth seem to be promising Speaking on behalf of a regulated enterprise, more SaaS (who may be interested to support MCP so AIs can use their SaaS, not just people), should — for both people and agentic tools — be OIDC first, without charging an "SSO Tax". "Sign in with" is now effectively ubiquitous, gets you out of the business of user credentials liability and password management flows, and for businesses ticks the same boxes as SAML SSO if you build in (extra work, granted) a DNS validation and domain name match. In the USA, for B2B, some 85% of SMB are able to "Sign in with Microsoft" (HN tends to ignore this customer base), a majority of the rest can "Sign in with Google". By "wallet share" for B2C, you need "Sign in with Apple" and the rest are again "Sign in with Google". I am not with, nor using, WorkOS, but appreciate this paragraph in their OIDC vs. SAML explainer: Use OIDC to: add enterprise SSO to your app in a dramatically easier way, most IdPs support it. It’s also an obvious choice if you’re already using OAuth 2.0 to access users' data (for example, to access a user’s Google files or Facebook profile data). https://workos.com/blog/oidc-vs-saml https://workos.com/blog/oidc-vs-saml Once you've done this, as WorkOS mentions you can use this from browser perspective to access other APIs such as social sites, but for things like MCP (we're all building TRON!) if you're building from services perspective, you can build to let agents leverage “OAuth 2.0 Device Authorization Grant” or similar, and for bonus points “OAuth 2.0 Token Exchange”. https://www.rfc-editor.org/rfc/rfc8628 https://www.rfc-editor.org/rfc/rfc8628 https://datatracker.ietf.org/doc/html/rfc8693 https://datatracker.ietf.org/doc/html/rfc8693 Even consumer users understand these device login flows by now since they use SaaS from TV sets: https://www.netflix.com/tv8 https://www.netflix.com/tv8 https://myaccount.microsoft.com/devicelogin https://myaccount.microsoft.com/devicelogin