Public posters love a clean ladder: Plan → Build → Validate → Operate, twelve boxes, each with a Tools row. LangChain here, LangSmith there, Docker at the end. Fine as a checkli…
A question that comes up every time someone builds their first MCP server: it's just an HTTP endpoint calling a few functions — why not hand it an API key like any other interna…
[Part 1](2026-07-13-mcp-oauth-vs-api-key.md) and [Part 2](2026-07-13-mcp-auth-api-key-vs-oauth-pkce.md) of this series covered why claims-mcp-oauth-poc uses OAuth and what the p…
[Last post](2026-07-13-mcp-oauth-vs-api-key.md) covered why claims-mcp-oauth-poc uses OAuth 2.1 + PKCE instead of a plain API key — the short version being that MCP's real shape…
Public posters love a clean ladder: Plan → Build → Validate → Operate, twelve boxes, each with a Tools row. LangChain here, LangSmith there, Docker at the end. Fine as a checkli…
A question that comes up every time someone builds their first MCP server: it's just an HTTP endpoint calling a few functions — why not hand it an API key like any other interna…
[Part 1](2026-07-13-mcp-oauth-vs-api-key.md) and [Part 2](2026-07-13-mcp-auth-api-key-vs-oauth-pkce.md) of this series covered why claims-mcp-oauth-poc uses OAuth and what the p…
[Last post](2026-07-13-mcp-oauth-vs-api-key.md) covered why claims-mcp-oauth-poc uses OAuth 2.1 + PKCE instead of a plain API key — the short version being that MCP's real shape…