Beyond CRUD
Designing MCP tools around trust and consent
Contributions
Azure MCP Server · Azure Cosmos DB MCP Toolkit
Azure Cosmos DB sajeetharan.dev
What is DevGlobe?
An open-source talent graph where humans and AI agents discover developers through public contribution evidence—not popularity alone.
“Find top developers in Bangalore—and contact the audience’s choice.”
Let’s run the system before explaining it.
Every request brings its context.
Like a restaurant order slip: do not depend on what someone remembers.
Do not trust this request only because an earlier request was trusted.
Noinitialize handshake or Mcp-Session-Id; protocol context travels with each request.
The request says which version and capabilities the client supports.
Protocol version and client capabilities travel in request_meta.
The client can first ask who the server is and what it can do.
server/discover exposes server identity and supported primitives.
If something is missing, ask a clear follow-up. Send only requested updates.
MRTR handles follow-ups; filtered subscriptions deliver requested change notifications.Azure MCP’s production baseline
Protect the server, its identity, and every tool call it brokers.
resource in the OAuth flow; validate token issuer, audience, expiry, and scopes on protected requests.Origin; bind local servers to localhost; fail closed on TLS errors.A secure tool can still be the wrong tool.
How do we execute safely?
Identity, least privilege, gateways, context protection, and evidence.
Would you allow this tool?
An authenticated agent can contact this developer immediately. Should this capability exist?
Product design decides the capability.Public discovery
Anonymous. Read-only. Bounded.
Public evidence, explicit freshness, no private contact data.
Consequential action
Authenticated. Rate-limited. Audited.
A request starts a consent workflow. It does not reveal contact details.
inputSchema: SearchInput outputSchema: DeveloperSearchResult structuredContent: { results, resultCount, freshness } // UX hints — not security claims readOnlyHint: true idempotentHint: true
Validate shape. Re-evaluate trust.
Evidence,
not a verdict.
The tool explains the match. It does not invent suitability.
0 results ≠ permission to hallucinate
InputRequiredResult“Which event, and why Sajeetharan?”
IN LOOP
Agent permission
1 · valid DevGlobe credential
2 · confirm request_introduction
Bearer token
↓ SHA-256 + timing-safe compare
{ id, name, owner }
My yes creates the request.
Human permission
3 · approve authentication navigation
4 · developer accepts
pending
↓ Sajeetharan decides
accepted | declined | expired
His yes accepts the introduction.
The chat may close. DevGlobe still remembers his decision.
Seconds, long-running work, or days?
notifications/progressReact search · secondsProgress ends when the search response completes.
close SSE responseCancelled searchClose the request, stop useful work, and ignore late results.
io.modelcontextprotocol/tasksRe-indexing · longerA durable job gets an ID and can be checked later.
Human approval may take days. Keep consent in DevGlobe—not in request progress or a task handle.
Database
Raw access gives the agent far more authority than this demo needs.
query(sql)
Platform
Bounded public discovery is enough to find React profiles.
search_developers(...)
Domain
Identity, reason, limits, history, and consent travel together.
request_introduction(...)
One demo. Three rules.
Evidence before conclusions
Discovery before action
Consent before consequence
Questions?
Continue exploring the protocol, toolkit, and working DevGlobe implementation.