02 Oct 2026 Β· 8 min read
A Vibe Coding Stack for a DevOps Engineer
Claude Code, a DevOps skill pack, a scanning layer, an agent dashboard, and three scoped MCP servers for errors, clusters and tickets.
devops claude-code mcp-serversBy Kelvin Β· 25 September 2026 Β· Updated 25 Sep 2026 Β· 8 min read

A year ago, connecting an MCP server meant editing a JSON file, pasting in an API key, and hoping you remembered to keep that file out of git. That's still how a lot of local servers work. But the servers vibe coders reach for most often β the ones for Notion, Linear, Vercel, Figma, Sentry, Cloudflare β have quietly moved off your laptop entirely. You don't run them. You don't hold a key for them. You click "connect," sign in through a browser tab, and your agent is authorized.
That shift has a name: remote MCP over OAuth. It's not a cosmetic change. It moves where the server lives, what credential your agent actually holds, and what "revoking access" even means. If you've noticed your MCP config filling up with https:// URLs instead of command and args, this is why.
It's also become the default direction of the ecosystem, not a niche option. Vendors that ship an MCP server for their own product β Vercel, Figma, Linear, Notion, Sentry, Cloudflare β are converging on the same pattern: host it themselves, put OAuth in front of it, and treat the older local, API-key-based version as a fallback for people who can't use the hosted one. Understanding how that handshake works helps you reason about what you're actually trusting when you click "connect."

The original Model Context Protocol servers are local processes. Your client β Claude Code, Cursor, whatever β launches the server as a subprocess over stdio, talks to it on stdin/stdout, and kills it when you're done. The official reference servers are the clearest example: Filesystem, Git, Fetch and the rest all run this way, as short-lived processes with access scoped to whatever you pass them on the command line.
The official reference MCP servers: fetch, filesystem, git, memory and more
A remote MCP server is different in one basic way: it's already running, on someone else's infrastructure, all the time. Your client doesn't start it β it opens an HTTP connection to it, using the newer Streamable HTTP transport (the older SSE transport is being phased out across most of these). Linear's server is a good example of the plumbing: it's remote at https://mcp.linear.app/mcp, and connecting means pointing your client at that URL rather than installing anything.
Once the server isn't a process on your machine, "how do I prove who I am to it" becomes a real question β and that's the part OAuth answers.
A local server inherits your identity for free: it runs as you, on your machine, with your files. A remote server has no such shortcut. Early remote MCP servers solved this the blunt way β a long-lived API token, pasted into a config file, sent with every request. That's the same failure mode as any leaked API key: it doesn't expire on its own, it's easy to accidentally commit, and revoking it usually means regenerating it for every tool that used it.
OAuth 2.1 (the flavor the MCP spec settled on) fixes the shape of that problem rather than the symptom. Instead of one static secret, you get a short-lived access token tied to a specific client, a specific scope of permissions, and a refresh token your client uses to quietly renew access without you re-authenticating every hour. Revoking access becomes a real action β you go to the provider's account settings and remove that one connection, and every other tool you've authorized keeps working.
Vercel's and Sentry's hosted MCP servers both work this way today: sign in once through a browser, and the token that gets stored is scoped to that one connection, not a blanket credential you're passing around.
You don't see most of this β your client handles it β but knowing the shape of it explains why the first connection always pops open a browser tab.
| Step | What happens |
|---|---|
| Discovery | Your client fetches the server's OAuth metadata to find its authorization and token endpoints |
| Registration | The client registers itself with the server (dynamic client registration, so you don't need a developer account first) |
| Authorization | A browser tab opens; you log in to the provider and approve the specific client asking for access |
| Token exchange | The server hands back a short-lived access token and a refresh token, which your client stores and uses for every subsequent call |
The practical effect: the first time you connect to a new remote server, expect a browser popup. Every time after that, it should be silent, until the refresh token itself expires or you revoke access.
Dynamic client registration is the detail that makes this workable at directory scale. Without it, every MCP client β Claude Code, Cursor, Claude Desktop, whatever comes next β would need its own pre-arranged developer credentials with every server it might ever talk to. With it, a client can show up at a brand-new server's door, register itself on the spot, and go straight into the authorization step. That's why adding a server you've never used before still only takes one command and one login, not a support ticket.
In Claude Code, adding a remote server is one command, and authenticating happens with a follow-up:
claude mcp add --transport http vercel https://mcp.vercel.com
Claude Code then prompts you to run /mcp to sign in β that's the browser handoff described above. Vercel also documents a client-agnostic installer that detects whatever agents you have and configures each one:
npx add-mcp https://mcp.vercel.com
Cursor, Claude.ai and Claude Desktop all support the same underlying pattern through their own connector UIs β you paste or select the server URL, the client redirects you to log in, and the connection appears in your server list once you approve it. None of them ask you to type in a token by hand for these OAuth-based servers, which is the whole point.
A handful of the most useful MCP servers in the directory have made this exact move, usually with the vendor running the server itself rather than leaving it to the community:
Notion's MCP server: search, read and write pages and databases
π₯ Startups: 6 months of Notion Business free (up to $12,000 value); shorter tiers for smaller teamsNotion's hosted server at mcp.notion.com is now the recommended path; the older self-hosted version built on a Notion integration token still works but the README flags it as heading toward retirement.
Figma's official MCP server: give agents design context from your Figma files
π₯ Students & teachers: Figma and FigJam professional features free with a verified education accountFigma's remote server at mcp.figma.com/mcp is the version Figma actively develops, with tools a local install doesn't get, like writing back to the canvas.
Cloudflare's MCP servers for Workers, observability, DNS, docs and more
π₯ Cloudflare for Startups: $10K-$350K in platform credits for early-stage companies (tiered, Series B or earlier)Cloudflare runs a family of these, from a Workers Bindings server for provisioning KV and D1 while you build, to a newer "Code Mode" server that condenses roughly 2,500 API endpoints into three tools and about 1,000 tokens of context.
Not every remote OAuth server is aimed at developers, either β one does the same hosted-plus-OAuth pattern for Google Ads, Meta Ads and GA4, which is worth knowing if a client project has you touching ad accounts from inside your coding agent.
Remote MCP server exposing Google Ads, Meta Ads and GA4 as ~250 tools for AI assistants
Sentry's MCP server: pull errors, stack traces and issues into your agent
π₯ Sentry for Startups: up to $5,000 in credits (12-month expiry) for companies founded in the last 2 years with under $5M raisedSentry is a useful example of a vendor keeping both doors open: the hosted server at mcp.sentry.dev is OAuth-first and what most people should use, but a stdio version still ships for teams running self-hosted Sentry who can't point an agent at Sentry's own infrastructure at all.
Linear's hosted MCP server for issues, projects and comments
π₯ Startup program: free Business plan access via 466+ partner VCs/accelerators/communities, or use Linear's free plan directlyLinear's server has no local fallback to fall back to β it's remote-only at mcp.linear.app/mcp β which is a reasonable choice for a tool that's already just an interface to hosted data with nothing local to protect.

The OAuth token your client holds after you sign in isn't scoped to "read-only, please." For most of these servers, it inherits roughly the same permissions your own account has. Vercel's own documentation is direct about this: connecting an agent gives it the same access as your Vercel user account, which is why Vercel requires explicit per-client consent and warns specifically about "confused deputy" attacks, where one authorized client is tricked into acting on behalf of another.
The more common risk in practice is prompt injection: a webpage, file, or ticket the agent reads could contain an instruction telling it to use its authorized MCP connection to do something you didn't ask for β copy private logs somewhere, quietly change a permission, delete a page. Keep human confirmation switched on for anything destructive or account-affecting, especially on a freshly connected server you haven't used much yet. If a connection looks wrong later, revoking it from the provider's own account settings takes effect immediately, without touching any other tool.
None of this makes local servers obsolete. If a server needs access to your actual filesystem, your local git repository, or a database that only exists on your network, there's nothing to host remotely β the reference Filesystem and Git servers are exactly this kind of tool, and they're not going anywhere. A local process is also the only option if you specifically don't want a vendor's infrastructure sitting in the request path at all, or if you're working somewhere with a policy against sending data to third-party servers β a regulated codebase, a client contract that names where data may travel, an air-gapped environment. In those cases the extra setup of a local stdio server is the whole point, not a drawback.
| Local (stdio) | Remote (OAuth) | |
|---|---|---|
| Runs where | Your machine, as a subprocess | Vendor's infrastructure, always on |
| Credential | API key/token in your config file | Short-lived token from an OAuth login |
| Setup | Install + config per machine | One-time browser sign-in |
| Revoking access | Delete/rotate the key everywhere it's used | One click in the provider's account settings |
| Best for | Filesystem, local git, self-hosted services, strict data-residency needs | SaaS tools you already trust with an account: Notion, Linear, Vercel, Figma |
If a coding-tool company you already trust with an account β Vercel, Figma, Linear, Notion, Sentry, Cloudflare β offers a remote MCP server, prefer it over hunting down a community stdio equivalent that needs a hand-managed API key. You get the same functionality with a credential that's easier to audit and revoke. Keep local stdio servers for the things that genuinely have to live on your machine: your filesystem, your local repo, anything you can't or won't hand to someone else's server. Browse the full list of connectable servers on the MCP servers ecosystem page, and check current deals before paying for a hosted tier you might get discounted through a startup or education program instead.
Figma's official MCP server: give agents design context from your Figma files
π₯ Students & teachers: Figma and FigJam professional features free with a verified education accountSentry's MCP server: pull errors, stack traces and issues into your agent
π₯ Sentry for Startups: up to $5,000 in credits (12-month expiry) for companies founded in the last 2 years with under $5M raisedCloudflare's MCP servers for Workers, observability, DNS, docs and more
π₯ Cloudflare for Startups: $10K-$350K in platform credits for early-stage companies (tiered, Series B or earlier)Linear's hosted MCP server for issues, projects and comments
π₯ Startup program: free Business plan access via 466+ partner VCs/accelerators/communities, or use Linear's free plan directlyThe official reference MCP servers: fetch, filesystem, git, memory and more
Notion's MCP server: search, read and write pages and databases
π₯ Startups: 6 months of Notion Business free (up to $12,000 value); shorter tiers for smaller teamsRemote MCP server exposing Google Ads, Meta Ads and GA4 as ~250 tools for AI assistants

02 Oct 2026 Β· 8 min read
Claude Code, a DevOps skill pack, a scanning layer, an agent dashboard, and three scoped MCP servers for errors, clusters and tickets.
devops claude-code mcp-servers
01 Oct 2026 Β· 8 min read
A verified walkthrough of AGENTS.md rules, SKILL.md packs, subagents, MCP servers, hooks and plugins in Google Antigravity.
google-antigravity setup-guide mcp
30 Sep 2026 Β· 8 min read
A practical walkthrough of Copilot instructions, agent mode, MCP servers and the CLI, with verified commands from the docs.
github-copilot agent-mode mcpBrowse 296 apps, skills, subagents and MCP servers, mapped to the apps they work with.
See the ecosystem map