1
1 Comment

Show HN: One config makes a Next.js app agent-ready (MCP, OAuth DCR, PKCE, discovery)

We just shipped @buildbase/sdk 0.0.54 with a new createAgentStack() helper: one config object turns a Next.js app into an MCP-native, agent-ready backend.

What that means concretely: on the client side, a one-liner (claude mcp add --transport http my-app https://<app>/mcp) is enough. The agent discovers the app, self-registers via RFC 7591 DCR, walks the user through a hosted consent screen, gets a PKCE-verified token, and starts calling tools. No client IDs pasted anywhere, no config files.

Standards all the way down: MCP 2025-06-18 (streamable HTTP), OAuth 2.0 with PKCE (RFC 7636), dynamic client registration (RFC 7591), protected-resource metadata (RFC 9728), authorization-server metadata (RFC 8414), resource indicators (RFC 8707), plus llms.txt, A2A agent cards, and security.txt (RFC 9116).

Security model I'm most proud of: the platform (which hosts login/consent/PKCE) never sees the app's secret or the minted tokens. The app mints its own HS256 tokens with the user's session embedded as an AES-256-GCM-encrypted claim. Every tool call runs under the granting user's real session. An agent can never exceed the person who approved it.

The starter ships with 42 built-in platform tools + a 5-tool CRUD example demonstrating custom tools with zod schemas. Production hardening (per-user rate limiting, error redaction, env fail-fast, CI) is wired. Verified end-to-end with Claude Code, including real writes (member invites, project CRUD) and 429s on the 121st request.

MIT. Would especially love feedback on the discovery surface and the tool-scoping model.

on July 10, 2026
  1. 1

    Starter: https://github.com/buildbase-app/nextjs-agent-mcp-starter

    SDK 0.0.54 on npm: https://www.npmjs.com/package/@buildbase/sdk

    Claude skill v0.2.0 (updated today to teach this end-to-end, with a failure library from real bugs hit during dev): https://github.com/buildbase-app/claude-skill

    Would love feedback, especially from anyone who's wired this manually.