{ "issuer": "pinned" }
How an MCP client pins its OAuth issuer
Python SDK 1.30 or 2.2 is not the whole fix. Machine-to-machine still needs issuer, and old client_info has to go.
Read moreJSONVue · Developer notes
JSON tips, step-by-step tutorials, comparisons, and best practices to help you understand and work with JSON in more depth.
{ "issuer": "pinned" }
Python SDK 1.30 or 2.2 is not the whole fix. Machine-to-machine still needs issuer, and old client_info has to go.
Read morePrevious tutorials
The gateway turns tools/call back into the original HTTP request. The body sits under body, and an API key cannot lock tool discovery.
Official a2a.json is non-normative and often skips required. Point at AgentCard, assert §4.4 non-empty, then switch the pointer for Task.
A2A does not specify a catalog API. Three strategies land on the same Card. Only then do you select, pick an interface, and send a Task.
Fill §4.4 field by field. Top-level url is 0.3. No tags, no search.
Not a third protocol. The Registry indexes A2A Cards and MCP toolspecs. Searchable first, then delegate.
The call hop did not retire. The full menu at startup did. Discovery thins the window; packaging stops the fork.
Not a fine-tune. Five hops later, memory holds identity, skill metadata, and tools/list. Check it with a snapshot JSON.
Not a three-way vote. Brief, hand, and box each own a discovery hop. Walk four questions before you pack.
A plugin is a box, not another tool protocol. Read the closed schemas for plugin.json and mcp.json, and why the Cloud Developer Plugin ships that way.
One OpenAPI 3.1 schema grows docs, types, and a typed client. Check the contract first, then run codegen—do not hand-write three copies.
After 2026-07-28, stop sticking sessions. JSON-RPC crosses a normal LB, SSE buffering stays off, rollouts drain long streams first.
Remote MCP 401s, RFC 9728 discovery, PKCE for a token, Bearer on tools/call—auth lives on the HTTP header, not in the JSON-RPC envelope.
What may change in Responses, Structured Outputs, Tool Calling, and MCP—and six schemas to freeze now. Predictions are not the agenda; contracts can be ready anyway.
An engineering definition of 2026 agent state: the checkpoint is the position, memory is only recall, who writes the JSON in a workflow vs a loop, and how run/step become recoverable.
Coding agents enter the multi-model era: how a local /v1 gateway unifies Claude Code, Cursor, and Codex, then reroutes requests when quotas run out or providers go down.
Siri in 2026 can pick an App, fill arguments, and read the screen. Map that to an agent definition, then split Apple Intelligence, App Intents / App Actions, and the two parallel tool contracts.
Keep product, model, and API on separate layers: what Siri AI and PCC, the ChatGPT extension, and the Gemini foundation each own — and why the three JSON contracts must not be mixed.
An engineering definition of MCP: which layer the protocol, the JSON-RPC envelope, the agent loop, and model tool calling each own — and why arguments still need a local check.
Turn 1M tokens from a marketing number into a window budget: what fits, how output and pricing fork, and why long JSON should be validated locally first.
An engineering definition of the 2026 agent: the observe–decide–call loop, how two product names map, and how three JSON payloads share one Schema.
On 3 September 2026 three front-door models overlapped. Separate the official timeline, Azure ingress clues, and retry cascades — and how an Agent JSON pipeline should fail over.
January’s joint statement put the next AFM on Gemini. June expanded PCC onto Google Cloud. Separate official facts from reported numbers—and why your JSON contract did not change owners.
Before 29 September, track Responses, MCP, Structured Output, and enterprise identity from the changelog—predictions are not the agenda; JSON contracts can be ready anyway.
MCP connects tools; A2A connects agents—complementary, not rivals. Where JSON fits in Agent Cards, tools/call, and task lifecycles.
Align inputSchema, function.parameters, and Structured Output; full flow from model arguments to tools/call plus validation.
Structured Output locks shape, not semantics. Four error layers, 2026 API map, Schema rules, parse→Schema→business pipeline.
Assistants, Threads, Runs go away; map to Responses + Conversations, backfill Threads manually, reuse vector stores.
V4-Flash public beta: model migration, Thinking replay of reasoning_content, Tool Calling strict beta, json_object output, and empty-response handling.
The 2026-07-28 MCP spec makes the protocol layer stateless: every JSON-RPC request carries its own version and capabilities, and Remote Servers can run behind ordinary HTTP load balancers.
The system agent uses App Intents; the in-app model uses Foundation Models tools. Split the three call chains, and see what JSON actually does in arguments, schemas, and HTTP bodies.
Constrain Gemini’s response shape with Structured Output and JSON Schema instead of begging the prompt for “JSON only”. Covers JSON mode vs Schema mode, Python/JS samples, and production validation.