Writing
Writing on building for the web, mostly on Cloudflare.
3 posts202633 minutes of reading
9 min
Put the rules in the API, not in the MCP server
APIs and MCP servers are layers, not rivals. A practical rule for architects: implement authentication, authorization, and business policy in the HTTP API exactly once, and build MCP servers as thin discovery layers that contain none of it.
12 min
Building an MCP server on Cloudflare Workers with OAuth
How to build a production MCP server under the 2026-07-28 specification: measure your real client with a probe before choosing auth, pick the protocol library by conformance score, isolate legacy support in one deletable module, and keep policy out entirely.
12 min
Giving an AI agent write access to a live site
How to grant an AI agent real write access to a production site safely: one shared write path, a single human-reserved operation enforced in code, tamper-evident state in version control, and the draft leak that revealed the method's hardest problem.