‹ BackHN Continuity

Thread

MCP was always a bad idea?

335 points · 331 comments · maharshi365

  1. simonw · · focus · HN ↗
    This article entirely misses the value that MCP brings today.

    Sure, there's almost no reason to use MCPs if you are running a full-blown terminal agent (Claude Code, Codex, Meta Muse, OpenClaw etc) with unfettered internet access - just let it call APIs directly.

    If you want to operate something that's less YOLO than that, you'll find yourself wanting:

    1. Control over exactly which external services it can access

    2. A way to handle authentication that doesn't allow the agent to directly access API keys

    3. A sensible UI to allow users to connect and authenticate further services

    4. Strong audit logging for what's going on

    MCP makes all of that so much easier to provide.

    Thinking MCP is obsolete because full coding agents don't need it misses out on all of the other things we might want to build.

    1. mikeocool · · focus · HN ↗
      All of these things are perfectly possible with a plain REST API with an Open API spec and using some standard auth options, and an AI client that implements a reasonable “make api request tool” (just like the AI clients implement MCP today).

      I think the real value of MCP is that it allowed companies to say “we’re doing AI!” When they built an MCP server. Just saying “use our api” was a lot less exciting.

      Giving it a different name probably also helped cut through politics at companies where non-technical people didn’t want to open up user data with an API, but they did want to do AI.

      1. simonw · · focus · HN ↗
        Hah, I made that same point last December: <a href="https:&#x2F;&#x2F;simonwillison.net&#x2F;2025&#x2F;Dec&#x2F;31&#x2F;the-year-in-llms&#x2F;#the-only-year-of-mcp" rel="nofollow">https:&#x2F;&#x2F;simonwillison.net&#x2F;2025&#x2F;Dec&#x2F;31&#x2F;the-year-in-llms&#x2F;#the-...

        &gt; For a while it also felt like MCP was a convenient answer for companies that were under pressure to have “an AI strategy” but didn’t really know how to do that.

        I&#x27;ve since come back to MCPs, because I want to build my own agents without first having to solve the problem of effectively sandboxing Bash.

        1. jimbokun · · focus · HN ↗
          Understood but it seems like effectively sandboxing cash is a very very important problem for the industry to solve!

          Would be a much more robust and general solution of the problem of controlling and auditing agentic access to sensitive information.

          1. tadfisher · · focus · HN ↗
            It&#x27;s such an important problem that it is sucking all available VC money into an exponentially-growing number of startups promising to make sandboxed agents safe and usable. In other news, MCP exists.
            1. jimbokun · · focus · HN ↗
              Honest question: which startups are trying to write a sandboxed-by-default easy to configure bash meant to be safely used by agents?
              1. tadfisher · · focus · HN ↗
                It&#x27;s not &quot;bash&quot;, it&#x27;s containers&#x2F;VMs&#x2F;whatever that are isolated from the host and run the agent, which can access a shell to do work.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.