Contributing Writer · MCP Implementation

Alexander Groman

Contributing Writer, Explore Agentic

About Alexander

Alexander writes the implementation side of the Model Context Protocol: the MCP pillar, the MCP glossary entry, and the MCP gateway vendor-selection guide. The material is the spec and what production does to it — Anthropic's November 2024 release, the move to the Linux Foundation, mandatory PKCE, Client ID Metadata Documents, and the March 2026 revision that made RFC 8707 resource indicators mandatory so a token minted for one server cannot be replayed against another.

The gateway auth work covers the everyday failures: repeated logins, mid-task token expiry, lost context after consent, and the elicitation, silent-refresh, and deep-link-resume patterns that fix them. Security runs parallel, with a hardening checklist that treats every tool-calling agent as a confused deputy holding real credentials — prompt injection, tool poisoning, token replay — plus the AWS Agentic AI Security Scoping Matrix mapped to NIST AI RMF and ISO 42001 controls. Cost is the third thread: prompt caching on Bedrock and the Anthropic API, and what MCP tool definitions do to a context window.

MCP server implementationOAuth 2.1 & RFC 8707MCP gateway authAgent security hardeningPrompt caching
By this contributor

Pieces written or reviewed by Alexander

19 pieces across 4 formats on this site — 10 written by Alexander and 9 reviewed. A written byline means Alexander researched and drafted the piece; a reviewed byline means Alexander read it against its cited sources and could defend its claims before it published. Every row below is labelled either way.