11 ms·
Claude Integrations
- behnamoh 1y agoThat "Allow for this chat" pop up should be optional. It ruins the entire MCP experience. Maybe make it automatic for non-mutating MCP tools.
- pcwelder 1y agoIn the latest update they've replaced "Allow for this chat" with "Always Allow".
- avandekleut 1y agoMCP also has support for "hints" which note whether an action is destructive.
- arjie 1y agoThe cookie banner type constant Allow Allow Allow makes their client unusable. Are there any alternative desktop MCP clients?
- rahimnathwani 1y agohttps://github.com/patruff/ollama-mcp-bridge https://github.com/patruff/ollama-mcp-bridge
- jarbus 1y agoAnyone have any data on how effective models are at leveraging MCP? Hard to tell if these things are a buggy mess or a game changer
- striking 1y agoClaude Code is doing pretty well in my experience :) I've built a tool in our CI environment that reads Jira tickets, files GitHub PRs, etc. automatically. Great for one-shotting bugs, and it's only getting better.
- xnx 1y agoIntegrations are nice, but the superpower is having an AI smart enough to operate a computer/keyboard/mouse so it can do anything without the cooperation/consent of the service being used. Lots of people are making moves in this space (including Anthropic), but nothing has broken through to the mainstream.
- WillAdams 1y agoOr even access multiple files? Why can't one set up a prompt, test it against a file, then once it is working, apply it to each file in a folder in a batch process which then provides the output as a single collective file?
- xnx 1y agoYou can probably achieve what you want with https://github.com/simonw/llm https://github.com/simonw/llm and a little bit of command line. Not sure what OS you're on, but in Windows it might look like this: FOR %%F IN (*.txt) DO (TYPE "%%F" | llm -s "execute this prompt" >> "output.txt)
- TheOtherHobbes 1y agoI've just done something similar with Claude Desktop and its built-in MCP servers. The limits are still buggy responses - Claude often gets stuck in a useless loop if you overfeed it with files - and lack of consistency. Sometimes hand-holding is needed to get the result you want. And it's slow. But when it works it's amazing. If the issues and limitations were solved, this would be a complete game changer. We're starting to get somewhat self-generating automation and complex agenting, with access to all of the world's public APIs and search resources, controlled by natural language. I can't see the edges of what could be possible with this. It's limited and clunky for now, but the potential is astonishing - at least as radical an invention as the web was.
- boh 1y agoI think all the retail LLM's are working to broaden the available context, but in most practical use-cases it's having the ability to minimize and filter the context that would produce the most value. Even a single PDF with too many similar datapoints leads to confusion in output. They need to switch gears from the high growth, "every thing is possible and available" narrative, to one that narrows the scope. The "hallucination" gap is widening with more context, not shrinking.
- mikepurvis 1y agoThat's a tough pill to swallow when your company valuation is a $62B based on the premise that you're building a bot capable of transcendent thought, ready to disrupt every vertical in existence. Tackling individual use-cases is supposed to be something for third party "ecosystem" companies to go after, not the mothership itself.
- deleted 1y ago[deleted]
- Etheryte 1y agoThis has been my experience as well. The moment you turn internet access on, Kagi Assistant starts outputting garbage. Turn it off and you're all good.
- fhd2 1y agoDefinitely my experience. I manage context like a hawk, be it with Claude-as-Google-replacement or LLM integrations into systems. Too little and the results are off. Too much and the results are off. Not sure what Anthropic and co can do about that, but integrations feel like a step in the wrong direction. Whenever I've tried tool use, it was orders of magnitude more expensive and generally inferior to a simple model call with curated context from SerpApi and such.
- loufe 1y agoCouldn't agree more. I wish all major model makers would build tools into their proprietary UIs to "summarize contents and start a new conversation with that base". My biggest slowdown with working with LLMs while coding is moving my conversation to a new thread because context limit is hit (Claude) or the coherent-thought threshold is exceeded (Gemini).
- bredren 1y agoHad been planning a custom mcp for our orgs’ jira. I’m a bit skeptical that it’s gonna work out of the box because of the amount of custom fields that seem to be involved to make successful API requests in our case. But I would welcome, not having to solve this problem. Jira’s interface is among the worst of all the ticket tracking applications I have encountered. But, I have found using a LM conversation paired within enough context about what is involved for successful POSTs against the API allow me to create update and relate issues via curl. It’s begging for a chat based LLM solution like this. I’d just prefer the underlying model not be locked to a vendor. Atlassian should be solving this for its customers.
- viraptor 1y agoYou can also do the same thing locally: https://github.com/sooperset/mcp-atlassian https://github.com/sooperset/mcp-atlassian Either with the cloude app, or some other system with any tool-using LLM you want.
- bredren 1y agoI'm familiar with that MCP and was planning to build on top of it. I hadn't realized but the new integration seems to actually just be an official, closed-source MCP produced *by* Atlassian. sooperset's MCP is MIT licensed, so I wonder how much of the Atlassian edition is just a lift of that. There's a comment [1] on the actual integration page asking about custom fields, which I think is possibly a big issue. At first I thought the open-source version would get crushed by an actual Atlassian release, but not if Atlassian doesn't offer all the support for it to work really well no matter what customizations are fitted into each instance. My hypothesis is that it takes custom code to make this work, and using the off-the-shelf for Jira won't work. Hoping to be proven wrong though, as it would be less work for me on that front. [1] https://community.atlassian.com/forums/Atlassian-Platform-articles/Using-the-Atlassian-Remote-MCP-Server-Beta/bc-p/3011641#M230 https://community.atlassian.com/forums/Atlassian-Platform-ar...
- rubenfiszel 1y agoI feel dumb but how do you actually add Zapier or Confluence or custom MCP on the web version of claude? I only see it for Drive/Gmail/Github. Is it zoned/slow release?
- throwaway314155 1y agoedit: <Incorrect>im fairly certain these additions only work on Claude Desktop?</Incorrect> That or they're pulling an OpenAI and launching a feature that isn't actually fully live.
- rubenfiszel 1y agoBut the videos show claude web
- 85392_school 1y agoThis part seems relevant: > in beta on the Max, Team, and Enterprise plans, and will soon be available on Pro
- joshwarwick15 1y agoCreated a list of remote MCP servers here so people can keep track of new releases - https://github.com/jaw9c/awesome-remote-mcp-servers https://github.com/jaw9c/awesome-remote-mcp-servers
- zhyder 1y agoIs there any way to access this via the API, after perhaps some oauth from the Anthropic user account?
- throwup238 1y agoThe leap frogging at this point is getting insane (in a good way, I guess?). The amount of time each state of the art feature gets before it's supplanted is a few weeks at this point. LLMs were always a fun novelty for me until OpenAI DeepResearch which started to actually come up with useful results on more complex programming questions (where I needed to write all the code by hand but had to pull together lots of different libraries and APIs), but it was limited to 10/month for the cheaper plan. Then Google Deep Research upgraded to 2.5 Pro and with paid usage limits of 20/day, which allowed me to just throw everything at it to the point where I'm still working through reports that are a week or more old. Oh and it searched up to 400 sources at a time, significantly more than OpenAI which made it quite useful in historical research like identifying first edition copies of books. Now Claude is releasing the same research feature with integrations (excited to check out the Cloudflare MCP auth solution and hoping Val.town gets something similar), and a run time of up to 45 minutes. The pace of change was overwhelming half a year ago, now it's just getting ridiculous.
- user_7832 1y agoI agree with your overall message - rapid growth appears to encourage competition and forces companies to put their best foot forward. However, unfortunately, I cannot shower much praise on Claude 3.7. And if you (or anyone) asks why - 3.7 seems much better than 3.5, surely? - Then I’m moderately sure that you use Claude much more for coding than for any kind of conversation. In my opinion, even 3.5 Haiku (which is available for free during high loads) is better than 3.7 Sonnet. Here’s a simple test. Try asking 3.7 to intuitively explain anything technical - say, mass dominated vs spring dominated oscillations. I’m a mechanical engineer who studied this stuff and I could not understand 3.7’s analogies. I understand that coders are the largest single group of Claude’s users, but Claude went from being my most used app to being used only after both chatgpt and Gemini, something that I absolutely regret.
- airstrike 1y agoI too like 3.5 better than 3.7 and I use it pretty often. It's like 3.7 is better in 2 metrics but worse in 10 different ones
- WhitneyLand 1y agoThe integrations feel so rag-ish. It talks, tells you it’s going to use a tool, searches, talks about what it found… Hope one day it will be practical to do nightly finetunes of a model per company with all core corporate data stores. This could create a seamless native model experience that knows about (almost) everything you’re doing.
- pyryt 1y agoI would love to do this on my codebase after every commit
- notgiorgi 1y agowhy is finetuning talked about so much less than RAG? is it not viable at all?
- mring33621 1y agoi'm not an expert in either, but RAG is like dropping some 'useful' info into the prompt context, while fine tuning is more like a performing mix of retraining, appending re-interpretive model layers and/or brain surgery. I'll leave it to you to guess which one is harder to do.
- disgruntledphd2 1y agoRAG is much cheaper to run.
- computerex 1y agoIt’s significantly harder to get right, it’s a very big stepwise increase in technical complexity over in context learning/rag. There are now some light versions of fine tuning that don’t update all the model weights but train a small adapter layer called Lora which is way more viable commercially atm in my opinion.
- ijk 1y agoThere were initial difficulties in finetuning that made it less appealing early on, and that's snowballed a bit into having more of a focus on RAG. Some of the issues still exist, of course: * Finetuning takes time and compute; for one-off queries using in-context learning is vastly more efficient (i.e., look it up with RAG). * Early results with finetuning had trouble reliably memorizing information. We've got a much better idea of how to add information to a model now, though it takes more training data. * Full finetuning is very VRAM intensive; optimizations like LoRA were initially good at transferring style and not content. Today, LoRA content training is viable but requires training code that supports it [1]. * If you need a very specific memorized result and it's costly to get it wrong, good RAG is pretty much always going to be more efficient, since it injects the exact text in context. (Bad RAG makes the problem worse, of course). * Finetuning requires more technical knowledge: you've got to understand the hyperparameters, avoid underfitting and overfitting, evaluate the results, etc. * Finetuning requires more data. RAG works with a handful datapoints; finetuning requires at least three orders of magnitude more data. * Finetuning requires extra effort to avoid forgetting what the model already knows. * RAG works pretty well when the task that you are trying to perform is well-represented in the training data. * RAG works when you don't have direct control over the model (i.e., API use). * You can't finetune most of the closed models. * Big, general models have outperformed specialized models over the past couple of years; if it doesn't work now, just wait for OpenAI to make their next model better on your particular task. On the other hand: * Finetuning generalizes better. * Finetuning has more influence on token distribution. * Finetuning is better at learning new tasks that aren't as present in the pretraining data. * Finetuning can change the style of output (e.g., instruction training). * When finetuning pays off, it gives you a bigger moat (no one else has that particular model). * You control which tasks you are optimizing for, without having to wait for other companies to maybe fix your problems for you. * You can run a much smaller, faster specialized model because it's been optimized for your tasks. * Finetuning + RAG outperforms just RAG. Not by a lot, admittedly, but there's some advantages. Plus the RL Training for reasoning has been demonstrating unexpectedly effective improvements on relatively small amounts of data & compute. So there's reasons to do both, but the larger investment that finetuning requires means that RAG has generally been more popular. In general, the past couple of years have been won by the bigger models scaling fast, but with finetuning difficulty dropping there is a bit more reason to do your own finetuning. That said, for the moment the expertise + expense + time of finetuning makes it a tough business proposition if you don't have a very well-defined task to perform, a large dataset to leverage, or other way to get an advantage over the multi-billion dollar investment in the big models. [1] https://unsloth.ai/blog/contpretraining https://unsloth.ai/blog/contpretraining
- VSerge 1y agoOngoing demo of integrations with Claude by a bunch of A-list companies: Linear, Stripe, Paypal, Intercom, etc.. It's live now on: https://www.youtube.com/watch?v=njBGqr-BU54 https://www.youtube.com/watch?v=njBGqr-BU54 In case the above link doesn't work later on, the page for this demo day is here: https://demo-day.mcp.cloudflare.com/ https://demo-day.mcp.cloudflare.com/
- mkagenius 1y agoare people really doing this mcp thing, yikes. Tomorrow, let me reinvent css as model context design (mcd)
- warkdarrior 1y agoDo you have a better solution to give models on-demand access to data sources?
- mkagenius 1y agoyou mean other than writing an api? no
- cruffle_duffle 1y agoAnd what is the protocol for the interface between the GPU-based LLM and the API? How does the LLM signal to make a tool call? What mechanism does it use? Because MCP isn’t an API it’s the protocol that defines how the LLM even calls the API in the first place. Without it, all you've got is a chat interface. A lot of people misunderstand what is the role of MCP. It’s the signaling the LLM uses to reach out of its context window and do things.
- turblety 1y agoIs there a reason they went and built some new standard, rather than just using a http api?
- knowaveragejoe 1y agoYou can use either HTTP or stdio.
- imbnwa 1y agoFeel like middle management is gonna go well before engineers do with LLM rate of advancement
- DebtDeflation 1y agoThat started awhile ago. Google "the great flattening".
- 6stringmerc 1y agoFeed Claude the data willingly to learn more about human behavior they can’t scrape or obtain otherwise without consent? Hard pass. I’m not telling any AI any more about what it means to be a creative person because training it how to suffer will only further hurt my job prospects. Nice try, no dice.
- n_ary 1y agoIs this the beginning of the apps for everything era and finally the SaaS for your LLM begins? Initially we had internet but value came when instead of installed apps, webapps arrived to become SaaS. Now if LLMs can use specific remote MCP which is another SaaS for your LLM, the remote MCP powered service can charge a subscription to do wonderful things and voila! Let the new golden age of SaaS for LLMs begin and the old fad(replace job XYZ with AI) die already.
- throwaway7783 1y agoMCP is yet another interface for an existing SaaS (like UI and APIs), but now magically "agent enabled". And $$$ of course
- clvx 1y agoI'm more excited I can run now a custom site, hook an MCP for it, and have all the cool intelligence I had to pay for SaaS without having to integrate to them plus govern my data, it's a massive win. I just see AI assistant coding replicating current SaaS services that I can run internally. If my shop was a specific stack, I could aim to have all my supporting apps in that specific stack using AI assistant coding, simplifying operations, and being able to hook up MCP's to get intelligence from all of them. Truly, OSS should be more interesting in the next decade for this alone.
- heyheyhouhou 1y agoWe should all thank the chinese companies for releasing so many incredible open weight models. I hope they keep doing it, I dont want to rely on OpenAI, Anthropic or Google for all my future computer interactions.
- achierius 1y agoDon't forget Meta, without them we probably wouldn't have half the publicly available models we do today.
- naravara 1y ago
- drivingmenuts 1y agoIs each Claude instance a separate individual or is a shared AI? Because I'm not sure I would want an AI that learned about my confidential business information sharing that with anyone else, without my express permission. This does not sound like it would be learning general information helpful across an industry, but specific, actionable information. If not available now, is that something that AI vendors are working toward? If so, what is to keep them from using that knowledge to benefit themselves or others of their choosing, rather than the people they are learning from? While people understand ethics, morals and legality (and ignore them), that does not seem like something that an AI understands in a way that might give them pause before doing an action.
- zoogeny 1y agoI'm curious what kind of research people are doing that takes 45 minutes of LLM time. Is this a poke at the McKinsey consultant domain? Perhaps I am just frivolous with my own time, but I tend to use LLMs in a more iterative way for research. I get partial answers, probe for more information, direct the attention of the LLM away from areas I am familiar and towards areas I am less familiar. I feel if I just let it loose for 45 minutes it would spend too much time on areas I do not find valuable. This seems more like a play for "replacement" rather than "augmentation". Although, I suppose if I had infinite wealth, I could kick of 10+ research agents each taking 45 minutes and then review their output as it became available, then kick off round 2, etc. That is, I could do my process but instead of interactively I could do it asynchronously.
- throwup238 1y agoThat iterative research process is exactly how I use Google Deep Research since it has a 20/day rate limit. Research a problem, notice some off hand assumption or remark the report made, and fire off another research run asking about it. It depends on what you work on; in my use case I often have to do hours of research for 30 minutes of work like when integrating a bunch of different vendors’ APIs or pouring over datasheets for EE, so it’s worth firing off research and then working on something else for 10-20 minutes (it helps that the Gemini app fires off a push notification when the report is done - Anthropic please do this! Even for requests made from the web app). As for long research times, one thing I’ve been using it for is historical research on old books. Gemini DeepResearch was the first one able to properly explain the nuances of identifying a chimeral first edition Origin of Species after taking half an hour and reading 400 sources. It went into all the important details like spelling errors and the properties of chimeral FY2** copies found in various libraries around the world.
- abhisek 1y agoWhere is Skynet and when is judgement day?
- 52-6F-62 1y ago1. Publishing advertisements all over the place. 2. Some Tuesday
- pton_xd 1y ago"To start, you can choose from Integrations for 10 popular services, including Atlassian’s Jira and Confluence, Zapier, Cloudflare, Intercom, Asana, Square, Sentry, PayPal, Linear, and Plaid. ... Each integration drastically expands what Claude can do." Give us an LLM with better reasoning capabilities, please! All this other stuff just feels like a distraction.
- Centigonal 1y agoBuilding integrations is a more predictable way of developing a smaller competitive advantage versus research. I think most of the leading AI companies are adopting a multi-arm strategy of research + product/ecosystem development to balance their risks.
- atonse 1y agoI disagree. They can walk and chew gum, do both things at once. And this practical stuff is very important. I've been using the Atlassian MCP for nearly a month now, and it's completely changed (and eliminated) the feeling of having an overwhelming backlog. I can have it do things like "find all the tickets related to profile editing and combine them into one epic" where it works perfectly. Or "help me prioritize the 15 tickets assigned to me this sprint" and it'll actually go through and suggest "maybe you can do these two tickets first since they seem smaller, then do this big one" – i haven't hooked it up to my calendar yet. But I'd love for it to suggest things like "do this one ticket that requires a lot of heads down time on wednesday since you don't have any meetings. I can create a block on your calendar so that nobody will schedule a meeting then" Those are all superhuman things that can be done with MCP and a smart model. I've defined rules in cursor that say "when I ask you to mark something ready for test, change the status and assign it to <x person>, and leave a comment summarizing the changes" If you look at my JIRA comments now, you'd wonder how I had so much time to write such thorough comments. I don't, Cursor and whatever model is doing it for me. It's been an absolute game changer. MCP is going to be what the App store was to mobile. Yes you can get by without it, but actually hooking into all your daily tool is when this stuff gets insanely valuable in a practical sense.
- organsnyder 1y ago
- edaemon 1y agoLots of reported security issues with MCP servers seemed to be mitigated by their local-only setup. These MCP implementations are remotely accessible, do they address security differently?
- paulgb 1y agoLargely, yes -- one of the big issues with using other people's random MCP servers is that they are run by default as a system process, even if they only need to speak over an API. Remote MCP mitigates this by not running any untrusted code locally. What it _doesn't_ seem to yet mitigate is prompt injection attacks, where a tool call description of one tool convinces the model to do something it shouldn't (like send sensitive data to a server owned by the attacker.) I think these concerns are a little bit overblown though; things like pypi and the Chrome Extension store scare me more and it doesn't stop them from mostly working.
- zoogeny 1y agoThey offhand mention OAuth integration in their discussion of Cloudflare integrated solutions. I can't see how that would be any less secure than any other OAuth protected API offering.
- indigodaddy 1y agoSo any chat to Claude will now just auto-activate web search to be included? What if I try to use it just as a search engine exclusively? Also will proxies like Openrouter have access to the web search capabilities?
- Nijikokun 1y agocontext windows are too small and conversely larger windows are not accurate enough its annoying
- gianpaj 1y ago> Web search is now globally available to all Claude.ai paid plans.
- surfingdino 1y agoI don't know why web search is such a big deal. You can implement it with any LLM that offers an API and function calling.
- tene80i 1y agoDo you think most people know how to do that, or even what it means? The market is larger than just software engineers.
- ChicagoDave 1y agoThere is targeted value in integrations, but everything still leads back to larger context windows. I love MCP (it’s way better than plain Claude) but even that runs into context walls.
- davee5 1y agoI'm quite struck by the title of this announcement. The box being drawn around "your world" shows how narrow the AI builder's window into reality tends to be. > a new way to connect your apps and tools to Claude. We're also expanding... with an advanced mode that searches the web. The notion of software eating the world, and AI accelerating that trend, always seems to forget that The World is a vast thing, a physical thing, a thing that by its very nature can never be fully consumed by the relentless expansion of our digital experiences. Your worldview /= the world. The cynic would suggest that the teams that build these tools should go touch grass, but I think that misses the mark. The real indictment is of the sort of thinking that improvements to digital tools [intelligences?] in and of themselves can constitute truly substantial and far reaching changes. The reach of any digital substrate inherently limited, and this post unintentionally lays that bare. And while I hear accelerationists invoking "robots" as the means for digital agents to expand their potent impact deeper into the real world I suggest this is the retort of those who spend all day in apps, tools, and the web. The impacts and potential of AI is indeed enormous, but some perspective remains warranted and occasional injections of humility and context would probably do these teams some good.
- dang 1y ago(Just for context: we've since changed the title above. Corporate press release titles are rarely a good fit for HN and we usually change them. https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sort=byDate&type=comment&query=corporate%20press%20release%20by:dang https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...)
- atonse 1y agoI think with MCPs and related tech, if Apple just internally went back to the drawing board and integrated the concept of MCPs directly into iOS (via the "Apple Intelligence" umbrella) and seamlessly integrated it into the App Store and apps, they will win the mobile race for this. Being Apple, they would have to come up with something novel like they did with push (where you have _one_ OS process running that delegates to apps rather than every app trying to handle push themselves) rather than having 20 MCP servers running. But I think if they did this properly, it would be so amazing. I hope Apple is really re-thinking their absolutely comical start with AI. I hope they regroup and hit it out of the park (like how Google initially stumbled with Bard, but are now hitting it out of the park with Gemini)
- mattlondon 1y agoDo you really think Apple can catch up with and then surpass all these SOTA AI labs? They bet big and got distracted on VR. It was obviously the wrong choice at the time, and even more so now. They're going to have to abandon all that VR crap and pivot hard to AI to try and catch up. I think the more likely case is they can't catch up now and will just have to end up licensing Gemini from Google/Google paying them to use Gemini as the default AI.
- atonse 1y agoNo I’m not saying Apple even has to build their own model. I’m saying Apple can build a stellar _product_ experience around it. As others have pointed out, if that’s what App Intents are, have they started to integrate this as part of Apple Intelligence?
- mattlondon 1y agoSo what is Apple Intelligence then? Just using CharGPT for Siri's backend? Bit uninspiring really isn't it?
- _pdp_ 1y agoApple already has the equivalent of MCP. https://developer.apple.com/documentation/appintents https://developer.apple.com/documentation/appintents.
- cruffle_duffle 1y agoThe video demos never really showed the auth “story” but I assume that there is some oauth step to connect Claude with your MCP service, right?
- belter 1y agoAll these integrations are likely to cause a massive security leak sooner or later.
- OJFord 1y agoWhere's the permissioning, the data protection? People will say 'aaah ad company' (me too sometimes) but I'd honestly trust a Google AI tool with this way more. Not just because it already has access to my Google Workspace obviously, but just because it's a huge established tech firm with decades of experience in trying not to lose (or have taken) user data. Even if they get the permissions right and it can only read my stuff if I'm just asking it to 'research', now Anthropic has all that and a target on their backs. And I don't even know what 'all that' is, whatever it explored deeming it maybe useful. Maybe I'm just transitioning into old guy not savvy with latest tech, but I just can't trust any of this 'go off and do whatever seems correct or helpful with access to my filesystem/Google account/codebase/terminal' stuff. I like chat-only (well, +web) interactions where I control the input and taking the output, but even that is not an experience that gives me any confidence in giving uncontrolled access to stuff and it always doing something correct and reasonable. It's often confidently incorrect too! I wouldn't give an intern free reign in my shell either!
- joshwarwick15 1y agoPermissoning: OAuth Data protection: Local LLMs
- weinzierl 1y agoIf you do not enable "Web Search" are you guaranteed it does not access the web anyway? Sometimes I want a pure model answer and I used to use Claude for that. For research tasks I preferred ChatGPT, but I found that you cannot reliably deny it web access. If you are asking it a research question, I am pretty sure it uses web search, even when "Search" and "Deep Research" are off.
- rafram 1y agoOh no, remote MCP servers. Security was nice while it lasted!
- rvz 1y agoThis is a fantastic time to get into the security space and trick all these LLMs into leaking sensitive data and make a lot of money out of that. MCP is a flawed spec and quite frankly a scam.
- knowaveragejoe 1y agoWhat makes a remotely hosted MCP server less secure? The alternative, and what most of MCP consists of at the moment, is essentially running arbitrary code on your machine, as your user, and hooking this up to an LLM.
- rvz 1y agoCan't wait for the first security incident relating to the fundamentally flawed MCP specification which an LLM will inadvertently be tricked to leak sensitive data. Increasing the amount of "connections" to the LLM increases the risk in a leak and it gives your more rope to hang yourself with when at least one connection becomes problematic. Now is a great time to be a LLM security consultant.
- dimgl 1y agoThis is great, but can you fix Claude 3.7 and make it more like 3.5? I'm seriously disappointed with 3.7. It seems to be performing significantly worse for me on all tasks. Even my wife, who normally used Claude to create interesting recipes to bake cookies, has noticed a huge downgrade in 3.7.
- OhioMan2943 1y ago3.7 seems to be way more filler and ambiguity and less insights for me.
- bjornsing 1y agoThe strategic business dynamic here is very interesting. We used to have "GPT-wrapper SaaS". I guess what we're about to see now is the opposite: "SaaS/MCP-wrapper GPTs".
- jimbokun 1y agoThe GPT wrappers were always going to be subsumed by improvements to the models themselves. LLMs wrapping the services makes more sense, as the data stored in those services adds a lot of value to off the shelf LLMs.
- bjornsing 1y agoI think I agree. There’s a lot of utility in a single LLM that can talk to many SaaS and integrate them. Feels like a better path forward than a separate LLM inside every SaaS.
- hdjjhhvvhga 1y agoThe people who connect a LLM to their Paypal and CLoudflare accounts perfectly deserve the consequences, both positive and negative.
- conroy 1y agoRemote MCP servers are still in a strange space. Anthropic updated the MCP spec about a month ago with a new Streamable HTTP transport, but it doesn't appear that Claude supports that transport yet. When I hooked up our remote MCP server, Claude sends a GET request to the endpoint. According to the spec, clients that want to support both transports should first attempt to POST an InitializeRequest to the server URL. If that returns a 4xx, it should then assume the SSE integration.
- kordlessagain 1y agoClaude Desktop doesn't support resources without directly importing them and now they've taken the button away for that and tools so I have to build the status of them into a tool so I could see what was loading and what wasn't. Here's my tool for Desktop: https://github.com/kordless/EvolveMCP https://github.com/kordless/EvolveMCP
- gonzan 1y agoSo there are going to be companies built on just an MCP server I guess, wonder what the first big one will be, just a matter of time I think
- worldsayshi 1y agoIs it just me that would like to see more of confirmations before making opaque changes to remote systems? I might not dare to add an integration if it can potentially add a bunch of stuff to the backing systems without my approval. Confirmations and review should be part of the protocol.
- sepositus 1y agoYeah, this was my first thought. I was watching the video of it creating all of these Jira tickets just thinking in my head: "I hope it just did all that correctly." I think the level of patience with my team would be very low if I started running an LLM that accidentally deleted a bunch of really important tickets.
- worldsayshi 1y agoYeah. Feels like it's breaking some fundamental UX principle. If an action is going to make any significant change make sure that it fulfills at least one of these: 1. Can be rollbacked/undone 2. Clearly states exactly what it's going to do in a reviewable way If those aren't fulfilled you're going to end up with users that are afraid of using your app.
- todsacerdoti 1y agoCheck out 2500+ MCP servers at https://mcp.pipedream.com https://mcp.pipedream.com
- the_clarence 1y agoBeen playing with MCP in the last few days and it's basically a more streamlined way to define tools/function calls. That + the agent SDK of openAI makes creating agentic flow so easy. On the other hand you're kinda forced to run these tools / MCP servers in their own process which makes no sense to me.
- nilslice 1y agoyou might like mcp.run, a tool management platform we're working on... totally agree running a process per tool, with all kinds of permissions is nonsensical - and the move to "remote MCP" is a good one! but, we're taking it a step (or two) further, enabling you to dynamically build up a MCP server from other servers managed in your account with us. try it out, or let me get you a demo! this goes for any casual comment readers too ;) https://cal.com/team/dylibso/mcp.run-demo https://cal.com/team/dylibso/mcp.run-demo
- the_clarence 1y agoI meant I wanted to run them synchronously in the same process :)
- nilslice 1y agothat's what this does :) you bundle mcp servers into a profile, which acts as a single virtual mcp server and can be dynamically updated without re-configuring your mcp client (e.g. claude)
- kostas_f 1y agoAnthropic's strategy seems to go towards "AI as universal glue". They want to tie Claude into all the tools teams already live in (Jira, Confluence, Zapier, etc.). That's a smart move for enterprise adoption, but it also feels like they're compensating for a plateau in core model capabilities. Both OpenAI and Google continue to push the frontier on reasoning, multimodality, and efficiency whereas Claude's recent releases have felt more iterative. I'd love to see Anthropic push into model research again.
- bl4ckneon 1y agoI am sure they are already doing that. To think that an AI researcher is doing essentially api integration work is a bit silly. Multiple efforts can happen at the same time
- kostas_f 1y agoThey certainly have internal research efforts underway, but I'm talking about what’s actually been released to end users via the Claude app or API. Their latest public Sonnet release 3.7 (feb 2025) felt pretty incremental compared to Sonnet 3.5 (june 2024), especially when you compare them to OpenAI and Google released models. In terms of the models you can integrate today, Anthropic hasn’t quite kept pace on either reasoning performance or cost efficiency.
- freewizard 1y agoI would expect Slack do this. Maybe Slack and Claude should merge one day, given MS and Google has their own core models.
- tjsk 1y agoSlack is owned by Salesforce which is doing its own Agentforce stuff
- spacebanana7 1y agoSalesforce loves acquisitions. I can already picture Benioff’s victory speech on CNBC.
- deanc 1y agoI find it absolutely astonishing that Atlassian hasn’t yet provided an LLM for confluence instances and instead a third party is required. The sheer scale of documentation and information I’ve seen at some organisations I’ve worked with is overwhelming. This would be a killer feature. I do not recommend confluence to my clients simply because the search is so appalling . Keyword search is such a naive approach to information discovery and information sharing - and renders confluence in big orgs useless. Being able to discuss and ask questions is a more natural way of unpacking problems.
- deleted 1y ago[deleted]
- artur_makly 1y agoon their announcement page they wrote " In addition to these updates, we're making WEB SEARCH available globally for all Claude users on paid plans." So I tested a basic prompt: 1. go to : SOME URL 2. copy all the content found VERBATIM, and show me all that content as markdown here. Result : it FAILED miserably with a few basic html pages - it simply is not loading all the page content in its internal browser. What worked well: - Gemini 2.5Pro (Experimental) - GPT 4o-mini // - Gemini 2.0 Flash ( not verbatim but summarized )
- meander_water 1y agoLooks like this is possible due to the relatively recent addition of OAuth2.1 to the MCP spec [0] to allow secure comms to remote servers. However, there's a major concern that server hosters are on the hook to implement authorization. Ongoing discussion here [1]. [0] https://modelcontextprotocol.io/specification/2025-03-26 https://modelcontextprotocol.io/specification/2025-03-26 [1] https://github.com/modelcontextprotocol/modelcontextprotocol/issues/205 https://github.com/modelcontextprotocol/modelcontextprotocol...
- dmarble 1y agoDirect link to the spec page on authorization: https://modelcontextprotocol.io/specification/2025-03-26/basic/authorization https://modelcontextprotocol.io/specification/2025-03-26/bas... Source: https://github.com/modelcontextprotocol/modelcontextprotocol/blob/63ccd1a416de4ffe7c24d8257f8f3c849e4ea0f8/docs/specification/draft/basic/authorization.mdx https://github.com/modelcontextprotocol/modelcontextprotocol...
- marifjeren 1y agoThat github issue is closed but: > major concern that server hosters are on the hook to implement authorization Doesn't it make perfect sense for server hosters to implement that? If Claude wants access to my Jira instance on my behalf, and Jira hosts a remote MCP server that aids in exposing the resources I own, isn't it obvious Jira should be responsible for authorization? How else would they do it?
- cruffle_duffle 1y agoThe authorization server and resource server can be separate entities. Meaning that jira instance can validate the token but not be the one issuing it or handling credentials.
- marifjeren 1y agoYes, this is true of OAuth, which is exactly what the latest Model context protocol is using.. What's the concern again? I guess maybe you are saying the onus is NOT on the MCP server but on the authorization server. Anyway while technically true this is mostly just distracting because: 1. in my experience the resource server and the authorization server are almost always maintained by the same company -- Jira/Atlassian being an example 2. the resource server still minimally has the responsibility of identifying and integrating with some authorization server, and *someone* has to be the authorization server, so I'm not sure deferring the responsibility to that unidentified party is a strong defense against the critique anyway. The strong defense is: of course the MCP server should have these responsibilities.
- bdd_pomerium 1y agoThis is very cool. Integrations look slick. Folks are understandably hyped—the potential for agents doing "deep research-style" work across broad data sources is real. But the thread's security concerns—permissions, data protection, trust—are dead on. There is also a major authN/Z gap, especially for orgs that want MCP to access internal tools, not just curated SaaS. Pushing complex auth logic (OAuth scopes, policy rules) into every MCP tool feels backwards. * Access-control sprawl. Each tool reinvents security. Audits get messy fast. * Static scopes vs. agent drift. Agents chain calls in ways no upfront scope list can predict. We need per-call, context checks. * Zero-Trust principles mismatch. Central policy enforcement is the point. Fragmenting it kills visibility and consistency. We already see the cost of fragmented auth: supply-chain hits and credential reuse blowing up multiple tenants. Agents only raise the stakes. I think a better path (and in one in full disclosure, we're actively working on at Pomerium ) is to have: * One single access point in front of all MCP resources. * Single sign-on once, then short-lived signed claims flow downstream.. * AuthN separated from AuthZ with a centralized policy engine that evaluates every request, deny-by-default. Evaluation in both directions with hooks for DLP. * Unified management, telemetry, audit log and policy surface. I’m really excited about what MCP is putting us in the direction of being able to do with agents. But without a higher level way to secure and manage the access, I’m afraid we’ll spend years patching holes tool by tool.
- tkgally 1y agoFor the past couple of months, I’ve been running occasional side-by-side tests of the deep research products from OpenAI, Google, Perplexity, DeepSeek, and others. Ever since Google upgraded its deep research model to Gemini 2.5 Pro Experimental, it has been the best for the tasks I give them, followed closely by OpenAI. The others were far behind. I ran two of the same prompts just now through Anthropic’s new Advanced Research. The results for it and for ChatGPT and Gemini appear below. Opinions might vary, but for my purposes Gemini is still the best. Claude’s responses were too short and simple and they didn’t follow the prompt as closely as I would have liked. Writing conventions in Japanese and English https://claude.ai/public/artifacts/c883a9a5-7069-419b-808d-08d49fe76b32 https://claude.ai/public/artifacts/c883a9a5-7069-419b-808d-0... https://docs.google.com/document/d/1V8Ae7xCkPNykhbfZuJnPtCMHQEKyKd172-6GsVIxk7w/edit?usp=sharing https://docs.google.com/document/d/1V8Ae7xCkPNykhbfZuJnPtCMH... https://chatgpt.com/share/680da37d-17e4-8011-b331-6d4f3f5ca7a9 https://chatgpt.com/share/680da37d-17e4-8011-b331-6d4f3f5ca7... Overview of an industry in Japan https://claude.ai/public/artifacts/ba88d1cb-57a0-4444-8668-e21c5b59c2b2 https://claude.ai/public/artifacts/ba88d1cb-57a0-4444-8668-e... https://docs.google.com/document/d/1j1O-8bFP_M-vqJpCzDeBLJa3TVszuc21ry9r81P3Xa0/edit?usp=sharing https://docs.google.com/document/d/1j1O-8bFP_M-vqJpCzDeBLJa3... https://chatgpt.com/share/680da9b4-8b38-8011-8fb4-3d0a4ddcf7d3 https://chatgpt.com/share/680da9b4-8b38-8011-8fb4-3d0a4ddcf7... The second task, by the way, is just a hypothetical case. Though I have worked as a translator in Japan for many years, I am not the person described in the prompt.
- noisy_boy 1y agoWhat is the best stack/platform to get started with MCP? I'm talking in terms of ergonomics, features and popularity.
- _1tem 1y agoFinally I can do something simple that I’ve wanted to do for ages: paste in a poster image or description of an event and tell the AI to add it to my calendar.
- gjohnhazel 1y agoI just have it create an .ics file and open that
- jngiam1 1y agoThis is awesome. We implemented a MCP client that's fully compatible with the new remote MCP specs, support OAuth and all. It's really smooth and I think paves the way for AI to work with tools. https://lutra.ai/mcp https://lutra.ai/mcp
- jes5199 1y agothe MCP spec as it stands today is pretty half-baked. It’s pretty clear that the first edition was trying to emulate STDIO over HTTP, but that meant holding open a connection indefinitely. The new revision tries to solve this by letting you hold open as many connections as you want! but that makes it vague about message delivery ordering when you have multiple streams open. There even seems to be part of the spec that is logically impossible - people are wrestling with it in the GitHub issues. which is to say: I’m not sure it actually wins, technically, over the OpenAI/OpenAPI idea from last year, which was at least easy to understand
- sagarpatil 1y agoShould have just called it Remote MCP. Integrations sounds very vague.
- Surac 1y agoI often use Claude 3.7 on programming things never done before. Even extensive search in the web brings up zero hits. I understand that this is very uncommon but my work portfolio is more science than real programming. Claude 3.7 really „thinks“ about the questions i ask. But 3.5 regularly drifts into dream mode if asked anything over it‘s training data. So if you ask for code easy found on the web you will see no difference. Try asking things not so common and you will see a difference
- franze 1y ago> Integrations and advanced Research are now available in beta on the Max, Team, and Enterprise plans, and will soon be available on Pro.
- MarkMarine 1y agoThe plaid integration is to let you look at your install? I was excited to see all my accounts (as a consumer) knit together and reported on by Claude. Bummer
- sebstefan 1y agoAn AI that is capable of responding to a "How do I do X" prompt with "Hey this seems related to a ticket that was already opened on your Jira 2 months ago", or "There is a document about this in Sharepoint", it would bring me such immense value, I think I might cry. Edit: Actually right in the tickets themselves would probably be better and not require MCP... but still
- MagicMoonlight 1y agoCopilot can already be setup to use sharepoint etc. And you can set it up to only respond based on internal content. So if you ask it “who is in charge of marketing” it will read it off sharepoint instead of answering generically
- elia_42 1y agoVery interesting. The integration videos are great to start right away and try out the new features. The extensions of the deep reasoning capabilities are also incredible. I think we are coming to a new automated technology ecosystem where LLMs will orchestrate many different parts of software with each other, speeding up the launch, evolution and monitoring of products.
- abhisek 1y agoLooks to me another apps ecosystem coming up similar to Android or iPhone. We are probably going to see a lot of AI apps marketplaces that solve the problem of discovery, billing & integration with AI hosts like Claude Desktop.
- deleted 1y ago[deleted]
- game_the0ry 1y agoIts only a matter of time where folks write user stories and an LLM takes over for the first draft, then iterate from there. Btw, that speaks to how important it is to get clear business requirements for work.
- clintonb 1y agoGreptile (https://www.greptile.com/ https://www.greptile.com/) tries to do that, at least for bug tickets. I recall being annoyed by its suggestions (posted as Linear comments).
- dakshgupta 1y agoCo-founder of Greptile - that was a bad feature that we since deprecated to focus entirely on AI code reviews
- game_the0ry 1y agoGenuinely curious -- Why pivot to code reviews?
- dakshgupta 1y agoOf the things we had built it was the most useful for us, and the early users found it very useful too
- ausbah 1y agousability like this seems to be a big nail through oss llm usage