Field notes on AI-native SaaS.
How to ship MCP servers, embed in-product AI assistants, and monetize AI usage — written by the team building the platform.
- In-product AI
How do I prevent an AI agent from taking actions on the wrong account?
Four controls that make wrong-account actions impossible rather than unlikely: identity known by construction, an identity cache keyed on the credential subject, approvals that replay frozen arguments, and a 403 classified as a wrong-id signal.
Sep 25, 2026 · 7 min - Comparison & discovery
What is the best MCP gateway for production use?
Two different products are called an MCP gateway. Here is how to tell which one you need, and the exact checks a production gateway should run before a request reaches your API.
Sep 22, 2026 · 7 min - MCP education
Per-customer identity for MCP servers: the end of the shared API key
Shared API keys turn MCP servers into liability: no attribution, no selective revocation, silent authz bypass. The gateway pattern gives every customer their own credential — encrypted, forwarded per call, revocable.
Jul 11, 2026 · 5 min - MCP education
MCP audit logs that actually matter at security review
Audit logs are a compliance artifact, not a debug stream. Here's the minimum field set, retention policy, and tamper-evidence pattern that survives enterprise procurement.
Jul 1, 2026 · 5 min - MCP education
OAuth for MCP servers: the 2025-06 spec, explained
OAuth 2.1 with PKCE is how the MCP spec authorizes remote servers. Here's the flow, the spec requirements, and the pitfalls to avoid when shipping a hosted MCP server.
Jun 23, 2026 · 5 min - MCP education
MCP server security: a production checklist
Production security checklist for MCP servers: short-lived per-user JWTs, tool-level authorization, gateway rate limits and cost caps, confirmation for destructive writes, prompt-injection handling, and append-only audit logs.
Jun 21, 2026 · 7 min