2026-08-20 12:36:06
A post I wrote about securing an #OpenAPI scheme using Duende IdentityServer gets a decent amount of reads a month (https://duendesoftware.com/blog/202511
π toolport_search_tools ranks by relevance across all servers, with optional semantic re-ranking through any /v1/embeddings endpoint. No tool is ever hidden.
π Secrets live in the OS keychain, never in client configs. OAuth or API key, one click per server, and newly authenticated servers propagate live without a client restart.
I've been dusting off my #ScottishIndependence canvassing app, to see how hard it would be to get it working if a new #IndyRef did actually happen.
It's suffered much less bit rot than I thought. It's mostly ready to go, there are still some issues to fix.
π OAuth PKCE login, device-code login for headless machines and unattended refresh of stored tokens without opening a browser
π₯οΈ Token-guarded local dashboard on 127.0.0.1 with Health, Credential Inventory, Policy Findings, Lease Inventory and Audit Activity views - metadata only, no raw secrets
π€ MCP server exposes policy-gated tools: list_services, get_ephemeral_env, verify_credential, rotate_credential and oauth_refresh, for Claude Desktop, Cursor and other hosts
πΎ hvbackup-v2 backup format carries audit integrity evidence. backup-verify and restore --dry-run prove recovery without mutating the live vault
Tomorrow! Join Grist Labs co-founder Stan for a demo of Grist's new MCP server.
We'll start small and then show off a complex workflow that leverages multiple integrations, so there's something for everyone.
Connect Claude, ChatGPT, Gemini, or your own local models to your docs over the Model Context Protocol, then list and query tables, read and write rows, and build schema, all via OAuth with scoped access.
Register:
Is this app that deep so that you have to streamline the app to keep the churn low?
I mean, I guess I can see that, especially when you are starting to squeeze more from the VIP users to the point that they may get annoyed. But then, you already have OAuth via Google and Apple, so the bar is pretty low, and keeping a password field shouldn't affect much, unless research said otherwise.
#Trakt
π Optional remote access via #Tailscale serve, keeping the server bound to loopback behind an authenticated HTTPS proxy
π No OAuth tokens are copied into project data β config lives in data/accounts.json, tokens stay in their CLI directories
Six MCP servers here. No key, no account, no OAuth, nothing to install, every tool read-only. The config, complete as it stands:
{"mcpServers":{"ai-crawler-index":{"type":"streamable-http","url":"#MCP
Tomorrow! Join Grist Labs co-founder Stan for a demo of Grist's new MCP server.
We'll start small and then show off a complex workflow that leverages multiple integrations, so there's something for everyone.
Connect Claude, ChatGPT, Gemini, or your own local models to your docs over the Model Context Protocol, then list and query tables, read and write rows, and build schema, all via OAuth with scoped access.
Register: