Writing
Writing on building for the web, mostly on Cloudflare.
1 post20269 minutes of reading
9 min
Put the rules in the API, not in the MCP server
APIs and MCP servers are layers, not rivals. A practical rule for architects: implement authentication, authorization, and business policy in the HTTP API exactly once, and build MCP servers as thin discovery layers that contain none of it.