Visual

Transport
Untuk remote MCP, gunakan Streamable HTTP/current MCP transport bila sesuai. Untuk local developer tooling, stdio masih relevan.
Business logic tidak boleh berbeda antara ChatGPT, Claude, Cursor, Codex, atau MSO. Yang boleh berbeda hanya registration, packaging, UI metadata, atau compatibility adapter.
OAuth untuk Hosted Clients
Jika MCP akan dipakai hosted clients, implement auth berdasarkan spesifikasi MCP/OAuth terbaru. Audit docs current sebelum coding.
- Protected Resource Metadata
- Authorization Server Metadata
- PKCE S256
- issuer + resource/audience
- exact redirect validation
- scopes
- single-use auth code
- token expiry + revoke
WWW-Authenticatechallenge yang benar
Protocol Discipline
Prefer official MCP SDK. Advertise hanya protocol revision/capability yang benar-benar diimplementasikan. Jika ada modern + legacy compatibility, keduanya harus memakai handler/policy yang sama dan dites parity-nya.
Portable Agent Plugin
plugin.json mcp.json skills/ assets/
Gunakan portable-first packaging. Compatibility file host-specific hanya jika diperlukan. Jangan commit API keys, cookies, OAuth token, npm token, atau registered connection ID palsu.
Kapan Membuat Skill
Skill berguna untuk workflow yang membutuhkan sequencing, stop/retry rules, recovery, opaque-ID flow, atau policy guidance yang terlalu panjang untuk tool description.
Skill bukan tempat menduplikasi seluruh schema tool.
Reference Implementasi
Gunakan MCP Builder Kit sebagai starter/reference production-grade.