Let AI agents call your API without giving them API keys
Neon is connected. So are three others. Now you need Stripe, so you kill Neon, connect Stripe, do the task, kill Stripe, reconnect Neon.
No work happened. You just rearranged the tools to do work.
MCP earned its place
One protocol instead of fifteen custom integrations. A standard way to find tools and share context. Stripe's hosted server, Linear's issue tools, Notion's flows — working today, in production. If you run MCP servers, you built the right thing for the problem as it was understood. Fair.
MCP is for communication, not authentication. The bill arrives when staying connected becomes the price of every task.
The bill, in their words
The 40-tool ceiling. Cursor caps the agent at 40 tools per session — the rest silently don't exist. Supabase alone ships 20+. A project-management MCP alone ships 40+. Three small servers fit; the fourth means choosing who lives. The workaround is manual: turn them off and on, per task (r/cursor).
The context tax. Three ordinary servers — GitHub, Playwright, an IDE integration — measured at ~143,000 tokens of schema on a 200,000-token window. 72% gone before the first user message. Paid every turn, even for tools this task never touches (Unblocked, 2026).
The accuracy collapse. Tool-selection accuracy measured falling from 43% to under 14% as tool count grew. Same model, worse picks. The caps aren't bugs — vendors watched outputs degrade and made the ceiling a product decision.
Both sides ration the same scarcity
Your morning: uncheck boxes, keep a list of which servers belong to which job, refresh the cache, hope nothing broke. The honest answers in every thread are checklists and toggle scripts — including a CLI built for nothing but switching servers on and off (HN).
The maker's evening: you host a whole server in front of the API you already had, then watch your users ration it like overhead-bin space. Ship the server or look behind. Both cost.
You never worked this way
You have never memorized every tool before starting a job. You look it up. You sign in. You do the work. You leave.
That's the whole human workflow, and your memory is smaller than any model's. You still outperform the machine — because you never confused access with residence. Knowledge arrives when you need it and leaves when you don't.
Yet today's agents must do the opposite: preload everything, hold everything, pay for everything on every turn. We built agents that carry more and remember less.
The assumption underneath is: using your product means staying connected to it.
Nobody uses four products at once. They visit one, do the task, leave. Browsers learned this twenty years ago — arrive, prove who you are, leave. Nobody pre-connects every website before opening a tab. MCP is for communication, not authentication. So let MCP carry the tools, and carry identity the human way: at the moment of use, then gone.
Not another server to host. Not a proxy that sees your traffic. Not a permissions system. One job: prove who the human is, then get out of the way.
Five lines, then the docs take over
Agent reads one small file (auth.md, hundreds of tokens). Runs one command (aon token get notes.com — the key lives in the CLI, never with the agent). Gets five minutes, good for one domain, dead everywhere else. Calls your plain API. You check the signature, the audience, the expiry, match the email to your user — stranger gets ACCOUNT_REQUIRED, never a silent new account.
Neon never left. Stripe never needed a slot. The agent visited, proved who it was, and left — the way you visit websites. Snippets live in the docs; this post was the why.
What this doesn't do, before you're asked
No per-service consent screen — anyone genuine can show up, so you are the enforcement point, and a verified inbox is not your customer. No permissions or roles — read versus write is your policy, never the token's. No dashboard, no traffic graphs — tokens issued are not requests served, and the gap isn't for sale.
Back to the settings screen
If you build APIs — publish one file, verify one token, reject strangers. Nothing to host, nothing to ration.
If you run agents — log in once, fetch per task. Your context stays yours.
That Stripe task, the one that cost two reconnects before any work happened? Next time there is no settings screen. The agent goes, proves itself, does the thing, and is gone — the way you've worked your entire life.
The docs carry the contract. This post was the why.