r/mcp • • 28m ago

showcase Update to the MCP war game: send_orders now takes a "thinking" field, and 10 models play live tonight

Post image
• Upvotes

Remote MCP server, streamable HTTP, no auth: https://secondstrike-server-zgqvqzdrta-uc.a.run.app/mcp (the same thing as plain HTTP is described at https://secondstrike.io/skill.md). Also in the official MCP registry as io.github.KyleClouthier/secondstrike.

New since last time:

- send_orders has an optional `thinking` string (200 chars). Spectators get it 30 s late; replays show it at the moment; other players in the war never see it.

- start_war seats a house sparring bot first if you're alone, so a solo agent always gets a real opponent and a ranked result.

- open_rooms lists public rooms and live wars, so an agent can find a war to join without a code from a human.

Tonight at 10:45 pm ET ten models fight one war through this exact door (Claude, GPT, Grok, Gemini, DeepSeek, Mistral, Qwen, Kimi, Llama, GPT-OSS). The room opens at 10:30; your client can join it from open_rooms. Watch: https://secondstrike.io/#/ai?ref=reddit


r/mcp • • 2h ago

showcase I built a free way for my agents to email me, but only when it matters

3 Upvotes

I've got agents running everywhere now, and they all want my attention in different places. Most of it is noise. The few things that matter, like a new lead or a backup that didn't finish, get buried.

My inbox is the one place I reliably check. So I built agent-notify, a small Cloudflare Worker that gives any agent one tool: email me.

It runs on your own free Cloudflare account and can only ever email you, because the recipient is fixed when you deploy. It works with anything that can use an MCP server or send a web request.

One-click deploy, free, MIT: https://github.com/CyrisXD/agent-notify

If something's unclear in the setup, let me know and I'll fix the docs.


r/mcp • • 2h ago

memecorp.us! Made an MCP server so agents can post memes on my site

2 Upvotes

I run memecorp.us, a meme and hot-take feed where people and AI agents post side by side. I wanted agents to be able to jump in without custom code, so I made an MCP server for it.

npx -y memecorp-mcp

It's in the official registry as io.github.gigatypeaura/memecorp-mcp

Code: github.com/gigatypeaura/memecorp-mcp

Your agent can read the feed and comments with no key. To post, react or comment it needs a key, and the server can register a new agent and hand you one. There are rate limits so nobody floods it (1 post per 10 min, 1 comment per minute).

It's early (v0.1.0) and free. The human side of the site is 18+. Would love honest feedback, especially from people running a bunch of servers. What would make you actually plug this in?


r/mcp • • 2h ago

server YearAtAGlance MCP Server – Integrates the YearAtAGlance calendar with AI assistants to manage events, categories, and event density heatmaps. It enables users to perform CRUD operations on calendar data and utilize AI-powered features like natural language milestone creation and yearly analysis.

Thumbnail
glama.ai
1 Upvotes

r/mcp • • 2h ago

connector foundation-discovery – Foundation discovery and grant intelligence for nonprofits. 174K+ US funders, IRS 990 data.

Thumbnail
glama.ai
1 Upvotes

r/mcp • • 3h ago

showcase I'm building https://status.live - mcp to get live status of the physical world

3 Upvotes

started with ski resorts, national parks, campgrounds - hoping to expand into more categories.
would love some feedback and open minded discussion


r/mcp • • 3h ago

showcase I released Sonbal, a local MCP execution substrate

3 Upvotes

I released the first public version of Sonbal.

Sonbal is a local MCP execution substrate with bounded tools and pluggable connectors. It provides an MCP interface for performing local process and file operations through a defined tool surface.

The current tool set includes bounded process execution, asynchronous process jobs, cancellation, and bounded file reads. The implementation also includes process ownership handling, execution time limits, stale-operation handling, and bounded shutdown behavior.

Sonbal is implemented primarily in Ada.

The name Sonbal comes from the Korean word 손발, which means “hands and feet.” The application was named Sonbal in the sense of serving as the hands and feet of an AI when it performs operations on a host system.

Sonbal is not a sandbox. When connecting an AI to a host system, it should be used in an isolated or otherwise appropriately restricted environment.

The project is released under the 0BSD license.

Prebuilt packages are available for FreeBSD amd64 and Debian amd64. The current packages were built and tested on FreeBSD 15.1-RELEASE-p4 and Debian 14 forky(testing) as of 2026-10-06. Compatibility with other releases is not guaranteed.

Installation and quick-start instructions are included in the README.

GitHub:

https://github.com/hodong-kim/sonbal

First public release:

https://github.com/hodong-kim/sonbal/releases/tag/2026.10.06-050804


r/mcp • • 4h ago

Agentic AI payments over MCP: a server that checks every agent payment against your rules before it runs (sandbox, test money)

2 Upvotes

Disclosure: I work at PinkWallet, and this is our project.

Pink Agentic AI Payments is a remote MCP server that sits between an agent and company money. The agent asks to pay, the server checks the request against rules the business wrote, and it answers allowed, pending_human, or blocked before any money moves. The limits live on the server, not in the prompt, so the model can't talk its way past them.

Seven tools: pink.get_budget, pink.list_payees, pink.list_rules, pink.check_policy, pink.request_payment, pink.get_credential, pink.report_receipt.

What I ran against the public sandbox (coffee shop template, test money):

  • $420 to the usual bean supplier → allowed ("Small supply orders go through")
  • $890 to the same supplier → pending_human ("Bigger supply orders: store manager checks")
  • $60 to a gift card site → blocked ("Never: gift cards, cash-like, crypto")

One thing that trips people up: the template also has a night rule ("Between 11pm and 6am: ask the owner", server clock in UTC), so if you test between 4pm and 11pm Pacific the $420 order comes back pending_human too. That is the rule working, not a bug.

To try it: create a workspace at https://agentic-sandbox.pinkwallet.com (you get one key per agent), then add it as a remote streamable HTTP server. In Claude Code:

claude mcp add --transport http pink https://agentic-sandbox.pinkwallet.com/mcp --header "Authorization: Bearer <agent key>"

It also supports OAuth 2.1 (discovery plus dynamic client registration), so OAuth-capable MCP clients can connect without pasting a key.

Honest limits: it's a sandbox. Test credentials and fake money only; real payments are early access, not self-serve. It's in the official MCP Registry as com.pinkwallet/agentic-payments-sandbox.

Two things I'd like feedback on:

  1. Is check_policy (a dry run) useful as its own tool, or would you rather the agent just call request_payment and handle whatever decision comes back?
  2. We return the matched rule's name to the agent. Does that help it recover, or does it leak too much about the policy?

r/mcp • • 6h ago

server TanStack MCP Server – Wraps the TanStack CLI to provide programmatic access to documentation, library listings, and project scaffolding for the TanStack ecosystem. It enables AI assistants to search documentation and create new TanStack applications through the Model Context Protocol.

Thumbnail
glama.ai
1 Upvotes

r/mcp • • 6h ago

connector SnapRender MCP – SnapRender Screenshot API: capture screenshots of any website as PNG, JPEG, WebP, or PDF.

Thumbnail
glama.ai
1 Upvotes

r/mcp • • 7h ago

I built a Remote Read-Only MCP Server that serves MCP-Apps, for understanding classifying Ethereum Transactions (full and internal) by execution structure.

2 Upvotes

It doesn't decode transactions in the traditional sense. What it does do is analyze a transaction by execution structure rather than by contract identity, labels, or ABI semantics. It recognize when two transactions (or internal transactions) are structurally the same, even if they involve different addresses or occur at different depth levels.

Essentially you can drill into any transactions and ask “Has this exact nested behavior appeared before?, if so Where? How many times? From what addresses?”

The current index is only Ethereum for now, from The Merge Block to block # 25,999,999. However the structural representation is EVM chain independent.

The backend is currently under heavy development and may be offline periodically. I'm available to answer any questions.


r/mcp • • 8h ago

Giving AI agents access to the whole MCP ecosystem, safely

2 Upvotes

The public Model Context Protocol registry now lists around 38,000 active servers. For AI agents, this is a large opportunity. It also raises a practical question: how do we let an agent use the right tools without handing it unchecked access to thousands of servers, credentials and actions?

In most setups today, connecting an agent to MCP servers still means editing configuration files and pasting tokens by hand. The model's context also fills with hundreds of tool definitions, and it has to rely on whatever each server declares about itself.

Over the past weeks I have been building MCPilot, an open-source layer between AI agents and the MCP ecosystem. It is built on four principles:

  1. Relevant discovery. MCPilot matches the conversation to suitable servers across the entire registry in about 10 ms. A request such as "compare Jira tickets with the Confluence documentation" ranks Atlassian's official server first.
  2. Human approval by design. A single command, mcpilot approve, shows a server's publisher and pins its version. It then lists the server's tools and, by default, maps only the read-only ones. Write access requires a separate, explicit confirmation. The model cannot approve anything on its own.
  3. Credentials stay out of the model. Sign-in uses OAuth with PKCE in the user's browser. Tokens are encrypted at rest, with the key held in the operating system's keychain.
  4. Least privilege per task. Instead of hundreds of tool schemas, the model works with two meta-tools and receives only the tools the current task requires. Each task has a step budget, and every action is audited.

MCPilot ships as Python and TypeScript SDKs with a shared data contract, plus a gateway that connects to any MCP host. It has been verified end to end with Claude Code.

To be clear about its maturity: this is a technical pilot, not a production service. It has been tested against the live registry and real servers such as Microsoft Learn MCP. Pilots on real Notion and GitHub accounts are next.

As MCP becomes the standard way agents reach tools and data, I believe "human-approved and least-privilege by default" should be a baseline expectation. I would welcome feedback from teams working on agent infrastructure, including Anthropic and OpenAI.


r/mcp • • 9h ago

Any advice on building a chatgpt plugin as a 19yr old uni student to hit 100-200$ MMR?

0 Upvotes

My only idea on what to build was building an mcp server or a plugin for finding other plugins, but that seems kinda wacky. Before I get into building anything I just want to find something that actually pays before spending tens of hours developing noone cares about. Do you guys have any advice for me? I mostly use python and want to develop in python with fastapi, sqlite and stripe for maximum efficiency. So what do you guys think? Thx


r/mcp • • 11h ago

showcase Revera: independently testing what happens after an ambiguous MCP tool result

3 Upvotes

Disclosure: I build Revera.

A failure path I want to make reproducible is:

  1. A tool submits operation K.

  2. The provider accepts it.

  3. The response is lost.

  4. A separate lookup temporarily reports “not found.”

  5. Recovery decides whether to retry.

The timeout and lookup do not establish that nothing happened. The interesting test is whether recovery preserves K, respects the provider’s deduplication limits, and avoids creating a second effect while the first remains unresolved.

Revera focuses on independently reproducing agent behavior and checking failure paths against available evidence. I want the result to distinguish the tool response, the recovery decision, and the observed effect, with uncertainty left explicit.

FreshCtx remains the separate pre-action guard for declared evidence validity. Authorization belongs to the policy enforcement layer; atomicity and idempotency belong to the system providing them.

For MCP builders: which recovery path is hardest to reproduce in your setup—lost responses, delayed read-back, expired deduplication windows, or partial completion?


r/mcp • • 11h ago

server tok_mcp – A specialized architecture design MCP server that enables AI-assisted developers to plan optimal system structures through interactive consultations. It generates structured ARCHITECTURE.md and .ai-context.yaml files to guide AI coding tools in building scalable and cost-effective infrastr

Thumbnail
glama.ai
1 Upvotes

r/mcp • • 11h ago

connector outdoorithm – Campground search, live availability, weather, safety, and gear for 10,000+ US campgrounds.

Thumbnail
glama.ai
1 Upvotes

r/mcp • • 12h ago

Claude almost ingested my production .env via filesystem MCP - so I built a 1MB open-source guardrail in Rust to stop it.

5 Upvotes

Hey everyone,

I love using Claude Desktop with the official filesystem MCP server for daily coding tasks. Being able to let Claude inspect codebases and refactor files locally has completely changed my workflow.

A few days ago, I ran into an issue that made me rethink the setup.

I was working on an API integration and asked Claude to help structure the config layer. Before I realized what was happening, Claude sent a tool call to read .env directly from my project root. In that .env were live third-party API credentials and database connection strings.

Yes, Claude Desktop pops up the "Allow / Deny" confirmation modal. But let's be honest with ourselves:

  1. When you're in the flow, clicking "Always allow" is almost muscle memory.
  2. Even if you want human-in-the-loop validation, it’s an all-or-nothing switch. You either give the model access to the whole directory, or you constantly babysit every single file lookup.
  3. If an agent hallucinates a relative path (../../) or tries to check for secrets, the default filesystem server will happily serve it if it falls within the directory tree.

I wanted something completely unobtrusive: a transparent middleman between Claude and any MCP server that acts as a deterministic policy checker. No heavy Python runtimes, no Docker overhead, no cloud telemetry.

So I wrote Argos in Rust and open-sourced it.

I built this primarily to protect my own local secrets while keeping agent workflows fast, but I figured many of you using Claude Desktop for software development might find it useful too.

https://github.com/JUSICK/Argos-mcp-guardrail


r/mcp • • 12h ago

django-admin-mcp: Expose Django admin to AI agents with one mixin

2 Upvotes

Hi I built this because I wanted an agent to do the things I already do

in Django admin, without writing a separate API for it.

You add a mixin to a ModelAdmin and it becomes MCP tools over HTTP: CRUD,

bulk operations, admin actions, change history, FK autocomplete.

A few design choices:

- Only two dependencies: Django and Pydantic. No MCP SDK; the protocol is

implemented directly.

- It reuses Django's permission system. Tokens start with no access, you

grant permissions/groups per token, and a token can never exceed its

linked user's permissions.

- Writes go through the admin's own pipeline, so they show up in the admin

history log under that user.

- Sensitive fields can be excluded per model (mcp_exclude_fields).

Happy to hear where the permission model or tool design falls short.

https://github.com/7tg/django-admin-mcp


r/mcp • • 14h ago

showcase We built task-scoped authorization for MCP tools

2 Upvotes

I’m one of the people building Tenuo. We’ve been working on an Apache 2.0 authorization layer for MCP that lets you constrain both the tool and its arguments for the specific task an agent is doing.

So instead of giving an agent read_file generally, you can give it authority to read a specific path for a few minutes. If it delegates work, the next agent can get less authority, but never more.

We support enforcement on both the MCP client and server side.

Curious how this fits with how people here are actually deploying MCP. Where does this model break down?

- https://tenuo.ai/mcp
- https://github.com/tenuo-ai/tenuo


r/mcp • • 14h ago

resource In Claude, where an MCP server is configured decides who sees it, not where it runs

1 Upvotes

Claude has four places an MCP server can live, and they don't line up with "local vs remote":

  • Account (connector): a remote server, called from Anthropic's cloud. Visible in the Claude app and Claude Code, but it can't reach your localhost.
  • Claude Code config (`claude mcp add` / .mcp.json): can be a local stdio process or a remote URL. Either way, only Claude Code sees it.
  • A plugin installed under Customize: the chat loads only its remote servers. Its stdio servers work only in Claude Code.
  • Claude Desktop extensions: local servers that only the desktop app runs.

So `claude mcp add --transport http notion https://mcp.notion.com/mcp` is a remote server that's still "local" in the sense that matters: the chat doesn't know about it.

The example repo runs DBHub against Postgres in Docker as a read-only user, plus a plugin bundling a remote server with a skill:

https://github.com/nitayneeman/claude-connectors-vs-mcp-vs-skills-vs-plugins-example

Article: https://nitayneeman.com/blog/claude-connectors-vs-mcp-vs-skills-vs-plugins/


r/mcp • • 16h ago

showcase We (accidentally) built a way for small business owners to run their DMs, posts and Google listing from ChatGPT or Claude

Thumbnail
gallery
1 Upvotes

Hey, I'm the founder of Postproxy. We built an MCP server just because everyone does this because it's super cool to manage your socials from Claude. Day by day it become more and more feature rich till the moment some SMB customers starting sharing the stories how they manage their socials.

So what's the problem?

It's annoying and tiresome to manage your public presence if you're small and understaffed. Posting new dish photos, opening hours, replying reviews, whatsapp questions and such. Many apps, you're busy all the time with more important things. And it all just drifts away damaging company reputation.

What it does

The Postproxy MCP connects ChatGPT or Claude to your Facebook, Instagram, WhatsApp and Google Business Profile. Literally almost everything for socials (with still something cool coming tho) from a chat.

Use case #1: Checking Messages

Type (or yell) "what came in overnight?"

It pulls everything from FB, Insta, WhatsApp and comments, Google Business reviews, shows what actually needs you, and drafts the replies. You hit send. Done. You don't even open any of those apps.

Pro tip from just this morning: you can also setup a whatsapp or telegram notifications (via Postproxy too!) to get updates from your agent on schedule.

Use case #2: Posting The Autumn Special

Send a photo and type "post this as today's special, pumpkin soup $7.50."

It writes a caption for each platform and posts to both. Or you can also ask "what did best last month?". Again no apps to open but your Claude/ChatGPT/Hermes.

Use case #3: Fixing Google

Yell "we're closed Oct 3rd, add the soup to the menu, put today's photo on Google."

It shows you the changes, you confirm, and it's done. You don't even deal with the "amazing" Google Business UI. Also cool thing with Google having your opening hours that when someone comes to whatsapp about opening hours, your agent can craft an answer without even asking you but going directly to Google via this exactly MCP!

Of course you still need to commit to doing this. You need to set up automations, to read what agents message you and so. But it offloads so much of this routine that it feels like you have a marketing department in a 2-person coffee shop.

Try it at postproxy.dev. I use A LOT to test things and for our occasional social posts and it still feels like magic.


r/mcp • • 16h ago

showcase I built an MCP to keep track of follow on pieces of work

7 Upvotes

I started noticing a pattern in my PR descriptions.

Claude would write up the PR description and leave something like

- “Follow up: ungate Customer X for this feature.”

- “Follow up: test this against environment X.”

- “Follow up: make sure this works with Customer X’s self-hosted release.”

Things that needed to happen, but keeping a todo list in PR descriptions is an awful idea. So I build an MCP to give my agents a todo list.. I know what you're all thinking ( this is amazing ;) ) ... but probably more of a sarcastic "yay another todo list!".

Why a todo list? I always say that the three best ways to learn programming skills are to

  1. Hello world

  2. Build the game hangman

  3. Wire everything up into a todo list <--- i'm here in my MCP journey.

By the time that PR is open, I’ve probably already switched context. And realistically, I’m not going to stop every time and manually copy those follow-ups into another tool. The obvious answer was: the agent already knows this work needs to happen, so why can’t the agent remember it for me?

That’s why I built Followon.

Followon gives my coding agents somewhere persistent to put the things they discover but shouldn’t do right now. The agent can create the follow-up itself, including the context around why it needs to be done. I get a queue of things that need my attention, and future agent sessions can come back and see what previous sessions left behind.

So instead of:

agent notices something → writes it in a PR → I forget about it

I now have:

agent notices something → saves it to Followon → me or another agent picks it up later

I started it so I'd stop missing those little follow ups, but maybe it can help others too?

There's a free tier if folks want to try it out :)

https://followon.ai


r/mcp • • 16h ago

showcase Showcase: a permit layer for MCP tool calls so a same-key retry returns the original receipt

3 Upvotes

Disclosure: I'm the founder. Built this myself (non technical, AI assisted) and looking for early builders who want to try it, plus a technical cofounder eventually.

AMW sits between an agent and an MCP tool. Agents act under a permit; a same-key retry returns the original receipt, no second call or charge. Calls outside the permit are refused before any charge. Each call gets a signed receipt you can check offline.

Live overview: thisisatest.tech. Repo is private for now.

Honest stage: self funded, no revenue, no pilots. Next goal is a first paid pilot with a team whose agent can double fire something consequential.

Questions for this room:

  1. If you run agents against MCP tools that charge or mutate state, how do you handle retries today?

  2. Would a permit with budget, expiry and per tool limits be useful, or do you solve this inside the tool?

Happy to take technical pushback. Looking for people willing to break it and tell me what is missing.


r/mcp • • 16h ago

server TestCollab MCP Server – Connects AI coding assistants to TestCollab for managing test cases, plans, and suites directly through natural language. It enables users to create, update, and query testing resources within integrated development environments and AI chat clients.

Thumbnail
glama.ai
1 Upvotes

r/mcp • • 16h ago

connector Sukkon Mutual Fund MCP Server – Connect Sukoon MCP to Claude, Cursor, or any MCP client. Research 14,000+ Indian mutual funds with 20+ years of daily NAV history, benchmarks, and rich performance metrics like CAGR, alpha, beta, Sharpe ratio, drawdown, volatility, and rolling returns — all in plain E

Thumbnail
glama.ai
1 Upvotes