Engineering
Writing from the team building the gateway — API-to-MCP conversion, policy engines, session routing, and the things we refuse to log. Written for people who've shipped an MCP server and hit the interesting problems.
Published
We publish as we build. Each piece is a problem we actually hit, written down once we understood it.
Follow one request from an AI application to an MCP server, into an external system, and back to the model.
Thirteen subsystems, rebuilt inside every hand-rolled MCP server, and the security review that never happens. A live model you can set to your own server count — with a checklist of what each subsystem actually covers.
Why filtering the tool list at discovery time is subtler than denying at call time — and what it does to caching, sessions, and client behavior.
Designing a metadata-only audit trail: how to make "no secrets in the record" a structural property instead of a code-review hope.
Upgrades and revocations against long-lived agent sessions: affinity, reconnect contracts, and the drain path that doesn't page anyone.
Follow along
No cadence promises, no content calendar — we write when we learn something worth writing down.
We'll send new writing from the boundary as it ships.
Next step
The docs get you a running gateway; a walkthrough gets you the architecture conversation.