frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

MCP is missing secure auth

https://blog.arcade.dev/mcp-server-authorization-guide
1•shawneechase•1h ago

Comments

shawneechase•1h ago
MCP (Model Context Protocol) makes it easy for agents to expose tools. It works great… until your agent needs OAuth.

Example: you’ve got an MCP server for Gmail. The client and tool definitions all work. But there’s no secure way in the protocol to get an OAuth token. Current hacks? Hardcoded credentials, service accounts with way too much scope, or passing tokens through untrusted clients. All bad.

At Arcade.dev we’ve been working on a proposal to fix this: PR #887

. It extends MCP’s new elicitation system with a url mode. That means:

Form elicitation → for non-sensitive parameters (preferences, configs)

URL elicitation → for sensitive flows like OAuth, payments, WebAuthn

Clients just open the URL in a browser. Servers handle tokens and scopes. Credentials never touch the LLM or the client — mirroring how web auth has worked for 15+ years.

Why it matters:

Scoped OAuth without leaking secrets

Proper token refresh + revocation

Works cleanly for multi-provider auth (Gmail + Slack + GitHub, etc.)

Moves MCP closer to being production-ready, not just local demos

Spec PR link again: https://github.com/modelcontextprotocol/modelcontextprotocol...

Curious what the HN crowd thinks: does this strike the right balance between flexibility and security?

Secret Service dismantles telecom threat capable of crippling cell service in NY

https://www.politico.com/news/2025/09/23/secret-service-un-nyc-telecom-00576100
1•rdli•1m ago•0 comments

Scam targeting hopeful Y Combinator applicants

1•mulka•1m ago•0 comments

Create and send AI-enriched postcards in 3 easy steps

https://waysor.com
1•maezeller•2m ago•0 comments

Ask HN: Is ycombinatooor real? Just got spammy looking email alegedly from

1•jemiluv8•6m ago•3 comments

Axon Says It Will Buy 911 AI Call Center Tech Firm Prepared

https://www.govtech.com/biz/axon-says-it-will-buy-911-ai-call-center-tech-firm-prepared
1•cebert•7m ago•1 comments

Space Mission Options for Mitigation of Asteroid 2024 YR4

https://arxiv.org/abs/2509.12351
1•geox•11m ago•0 comments

I Built a $40k Military Drone for $120.07 [video]

https://www.youtube.com/watch?v=bmLE9BT76Pc
1•nikolay•14m ago•1 comments

Things You Should Never Plug into a Power Strip

https://www.bobvila.com/articles/power-strip-safety/
1•domofutu•17m ago•0 comments

Show HN: Comparegpt.io – Trustworthy Mode to reduce LLM hallucinations

1•tinatina_AI•22m ago•0 comments

The Sad World of Tech Blogging

https://freddiedeboer.substack.com/p/the-sad-sad-world-of-tech-blogging
1•paulpauper•24m ago•1 comments

Chromatin-associated condensates as an inspiration for future DNA computers

https://nyaspubs.onlinelibrary.wiley.com/doi/10.1111/nyas.15415
1•PaulHoule•26m ago•0 comments

Show HN:[Feedback Request] Chrome extension for structured learning with ChatGPT

https://www.youtube.com/watch?v=YvL65pdc16U
2•sridhar87•28m ago•0 comments

Dead Internet Theory

https://en.wikipedia.org/wiki/Dead_Internet_theory
1•RyanShook•29m ago•0 comments

If A.I. Can Diagnose Patients, What Are Doctors For?

https://www.newyorker.com/magazine/2025/09/29/if-ai-can-diagnose-patients-what-are-doctors-for
3•pseudolus•31m ago•3 comments

Periodic Table of Cognition

https://kk.org/thetechnium/the-periodic-table-of-cognition/
3•garspin•34m ago•0 comments

Try: Feature flags shouldn't require a separate service

https://atono.io/
2•troy55_yort55•36m ago•1 comments

Amazon is closing all Fresh grocery stores in the UK

https://www.engadget.com/amazon-is-closing-all-fresh-grocery-stores-in-the-uk-195200222.html
4•ksec•40m ago•0 comments

Baldur's Gate 3 Steam Deck – Native Version

https://larian.com/support/faqs/steam-deck-native-version_121
31•_JamesA_•41m ago•12 comments

Show HN: A reaction-diffusion system in an SVG

https://oisinmoran.com/projects/reaction_diffusion.svg
1•OisinMoran•44m ago•0 comments

Solar tax credits are ending. Here's why that could be good for solar

https://www.washingtonpost.com/climate-environment/2025/09/23/rooftop-solar-price-energy-tax-cred...
1•thelastgallon•45m ago•0 comments

Community Crime Heat Map

https://communitycrimemap.com/
1•fallinditch•47m ago•1 comments

Psyche asteroid probe uses lasers to phone home from 218M miles away

https://www.space.com/space-exploration/nasa-laser-communication-demo-shows-promise-for-mars-miss...
3•pseudolus•51m ago•0 comments

The Strange Math That Predicts Almost Anything [video]

https://www.youtube.com/watch?v=KZeIEiBrT_w
1•teleforce•56m ago•0 comments

Australian government may require age verification for GitHub access

https://www.abc.net.au/news/2025-09-24/digital-dilemna-social-media-age-ban-platforms/105807302
3•yeetosaurusrex•56m ago•3 comments

Why Electric Truck Sales Are Accelerating Quickly

https://www.bloomberg.com/news/newsletters/2025-09-23/why-electric-truck-sales-are-accelerating-q...
1•toomuchtodo•57m ago•6 comments

Breakfast by Country

https://en.wikipedia.org/wiki/Breakfast_by_country
2•domofutu•58m ago•0 comments

The Switch 2 version of Borderlands 4 has been delayed

https://www.theverge.com/news/784277/borderlands-4-nintendo-switch-2-delay
1•corvad•58m ago•0 comments

Ask HN: Should I quit starting companies?

2•failedagain•59m ago•5 comments

Home – Connect Seattle

https://communityconnectseattle.org/
1•petethomas•1h ago•0 comments

How close are we to having chatbots officially offer counseling?

https://news.harvard.edu/gazette/story/2025/09/how-close-are-we-to-having-chatbots-officially-off...
1•Improvement•1h ago•1 comments