logoalt Hacker News

simonwyesterday at 3:11 PM1 replyview on HN

My point about MCPs here is that they provide a way to make those secrets and API keys deterministically inaccessible to the agents - even agents that's have a shell execution environment.

That's the opposite of a false sense of security.


Replies

mjburgessyesterday at 3:23 PM

just use an api gateway (ie., a reverse proxy for apis), eg., envoy. This should also be connected to observability and finops style management anyway rather than leaving it to model providers.