Discussion about this post

User's avatar
JP's avatar

The Q&A note about MCP not being production-ready, mainly due to auth, is one that's been getting addressed piece by piece. Google just open-sourced `gws`, a Workspace CLI with MCP built in, and they tackled that directly: credentials encrypted with AES-256-GCM stored in the OS keyring, and a --sanitize flag that runs API responses through Google Cloud Model Armor to catch prompt injection. Not a universal fix for MCP auth, but a concrete step for the Workspace side of things. Wrote it up here: https://reading.sh/google-workspace-finally-has-a-cli-and-its-built-for-agents-5f5fe87d0425

No posts

Ready for more?