Lompat ke konten
Rahman FakhruDiskusi proyek

Pelajaran 05 / 09

5. OAuth, Protocol, Transport, Skill, dan Packaging

Memilih transport MCP, OAuth untuk hosted clients, official SDK, skills, dan portable Agent Plugin packaging.

Visual

OAuth, Protocol, Transport, Skill, dan Packaging

Transport

Untuk remote MCP, gunakan Streamable HTTP/current MCP transport bila sesuai. Untuk local developer tooling, stdio masih relevan.

Business logic tidak boleh berbeda antara ChatGPT, Claude, Cursor, Codex, atau MSO. Yang boleh berbeda hanya registration, packaging, UI metadata, atau compatibility adapter.

OAuth untuk Hosted Clients

Jika MCP akan dipakai hosted clients, implement auth berdasarkan spesifikasi MCP/OAuth terbaru. Audit docs current sebelum coding.

  • Protected Resource Metadata
  • Authorization Server Metadata
  • PKCE S256
  • issuer + resource/audience
  • exact redirect validation
  • scopes
  • single-use auth code
  • token expiry + revoke
  • WWW-Authenticate challenge yang benar

Protocol Discipline

Prefer official MCP SDK. Advertise hanya protocol revision/capability yang benar-benar diimplementasikan. Jika ada modern + legacy compatibility, keduanya harus memakai handler/policy yang sama dan dites parity-nya.

Portable Agent Plugin

plugin.json
mcp.json
skills/
assets/

Gunakan portable-first packaging. Compatibility file host-specific hanya jika diperlukan. Jangan commit API keys, cookies, OAuth token, npm token, atau registered connection ID palsu.

Kapan Membuat Skill

Skill berguna untuk workflow yang membutuhkan sequencing, stop/retry rules, recovery, opaque-ID flow, atau policy guidance yang terlalu panjang untuk tool description.

Skill bukan tempat menduplikasi seluruh schema tool.

Reference Implementasi

Buat MCP kamu sendiri

Gunakan MCP Builder Kit sebagai starter/reference production-grade.

Buka MCP Builder Kit di GitHub →

Baca: Kenapa MCP Penting →