Command K
Build MCP
  • API → MCP
    OpenAPI or GraphQL in, MCP out.
  • Hosting & analytics
    Quotas, logs, free tier.
  • MCP auth
    OAuth 2.1, shared presets.
CMD+K Widget
  • AI assistant
    AutoView, confirm-UX.
  • Knowledge base
    Grounding with citations.
  • Connected tools
    End-user marketplace.
  • Guided toursSoon
    Step-by-step in-product.
  • Whitelabel
    Your brand end-to-end.
Monetize
  • Usage attribution
    Per-user spend & margin.
  • Billing meters
    Stripe today, more soon.
One layer. Three pillars.Explore the product
Use casesMarketplacePricing
  • Learn MCP
    What MCP is, why it matters, how to ship one.
  • Docs
    Guides, references, and quickstarts.
  • Blog
    MCP, in-product AI, and monetization.
  • Changelog
    What shipped, week by week.
  • MCP servers
    Public directory of hosted MCPs.
Book a demoSign inStart free trial
The Command+K blog

Field notes on AI-native SaaS.

How to ship MCP servers, embed in-product AI assistants, and monetize AI usage — written by the team building the platform.

All clustersMCP educationIn-product AIAI monetizationComparison & discovery
Clear tag: #Security ×
  • MCP education

    Per-customer identity for MCP servers: the end of the shared API key

    Shared API keys turn MCP servers into liability: no attribution, no selective revocation, silent authz bypass. The gateway pattern gives every customer their own credential — encrypted, forwarded per call, revocable.

    Jul 11, 2026 · 5 min
  • MCP education

    MCP audit logs that actually matter at security review

    Audit logs are a compliance artifact, not a debug stream. Here's the minimum field set, retention policy, and tamper-evidence pattern that survives enterprise procurement.

    Jul 1, 2026 · 5 min
  • MCP education

    OAuth for MCP servers: the 2025-06 spec, explained

    OAuth 2.1 with PKCE is how the MCP spec authorizes remote servers. Here's the flow, the spec requirements, and the pitfalls to avoid when shipping a hosted MCP server.

    Jun 23, 2026 · 5 min
  • MCP education

    MCP server security: a production checklist

    Production security checklist for MCP servers: short-lived per-user JWTs, tool-level authorization, gateway rate limits and cost caps, confirmation for destructive writes, prompt-injection handling, and append-only audit logs.

    Jun 21, 2026 · 7 min
Command K

The MCP, widget, and monetization layer for product teams shipping AI features in production.

Product
  • Build MCP
  • CMD+K Widget
  • Monetize
  • Use cases
  • Marketplace
  • Compare
  • Alternatives
  • Pricing
  • Predictable pricing
Developers
  • Learn MCP
  • Docs
  • MCP servers
  • Blog
  • AI-native SaaS playbook
  • Guides
  • Changelog
  • Status
  • Security
Company
  • About
  • Partners
  • Contact
  • Trust & refunds
  • Terms
  • Privacy
  • DPA
commandplusk.com · © 2026