Hardening MCP Servers:Auth, Least Privilege, and Tool Safety
Trust boundaries, host approval UX, env secrets, input validation, read-only vs mutating tools, and a practical hardening checklist for a TypeScript MCP bookmarks server.
Read MoreBrowse the full archive. Use topics in the sidebar to explore by tag.
Trust boundaries, host approval UX, env secrets, input validation, read-only vs mutating tools, and a practical hardening checklist for a TypeScript MCP bookmarks server.
Read MoreServe the bookmarks MCP tools over Streamable HTTP with createMcpHandler, protect them with a bearer token, deploy one PaaS URL, and point Cursor at url plus headers.
Read MorePackage a TypeScript MCP server for npm, add mcpName verification, publish with npm, and register metadata with mcp-publisher — distribution, not hosting.
Read MoreWhat compact source files are (JEP 512 / Java 25): implicit classes, instance main methods, java.lang.IO, and automatic java.base imports — without public static void main ceremony.
Read MoreWire a local MCP server in Cursor with mcp.json — project vs global config, field-by-field stdio setup, verify Connected, and run one approved tool call.
Read MoreBuild a local bookmarks MCP server in TypeScript — McpServer, Zod tools, stderr logging, MCP Inspector first, then wire the build into Cursor over stdio.
Read MoreAdd an MCP resource and prompt to a TypeScript stdio server — bootstrap from the bookmarks part-3 tag, verify in Inspector, and note Cursor host limits.
Read MoreWhat the Model Context Protocol is, the host/client/server vocabulary, tools vs resources vs prompts, and when agents need MCP — or when Skills and rules are enough.
Read MoreDFS to record finish order, transpose the digraph, DFS again in reverse finish order — each second-pass tree is a strongly connected component, and the condensation is a DAG.
Read MoreWhat JEP 519 compact object headers are: shrink 64-bit HotSpot headers from 12–16 bytes to 8 without changing application source, how to enable the flag on 24/25, and why Java 27 turns it on by default.
Read More