MCP was always a bad idea?
- ID
- 27008
- Status
- summarized
- Published
- 21 Sep 2026, 4:24 AM
- Fetched
- 22 Sep 2026, 6:38 AM
- Provider
- Simon Willison
- Category
- developer-ai
- Original URL
- https://simonwillison.net/2026/Sep/20/hn-49779718/
- Source URL
- https://simonwillison.net/atom/everything/
Summary
- Score
- 7.0
- Created
- 22 Sep 2026, 6:38 AM
- Tags
- Audience
- developersai_agent_usersvibe_coders
What happened
Simon Willison pushes back on the claim that MCP (Model Context Protocol) is obsolete. He argues that while full terminal agents with unfettered internet access (Claude Code, Codex, etc.) can just call APIs directly, MCP remains valuable when you need granular control over which external services an agent can access, authentication that doesn't expose API keys directly to the agent, user-facing UI for connecting services, and strong audit logging.
Why it matters
If you're building AI agent products for end users (not just running your own coding agent), MCP solves real problems around access control, auth delegation, and auditability that raw API calls don't. Don't abandon MCP just because terminal-based coding agents don't need it — evaluate it specifically for multi-tenant or user-facing agent deployments where you can't hand the agent unrestricted access.
Discussion angle
Where's the line between 'just let the agent call APIs directly' and 'you need MCP'? Concrete use cases: internal dev tools vs. user-facing SaaS agents — which actually need the control plane MCP provides?