Shipping MCP to Real Users: Scaling, Auth, and the PII Leak You Didn't See Coming
-
Hadar Geva
Myop
CTO & Co-founder
November 25β26, 2026
Bengaluru, India
Joining remotely?
Watch live with ProMost MCP server design advice stops at βwrite good tool descriptions.β That advice falls apart the moment your agent has the power to break things on purpose.
I own the Resilience Testing MCP at Harness, where agents drive chaos experiments against live infrastructure: killing pods, injecting latency, partitioning networks. An ambiguous tool call does not get clarified, it gets guessed, the wrong experiment runs, and the blast radius becomes a real number.
This talk covers what survived and what did not:
Tool granularity: why we collapsed five experiment tools into one, and the one case where splitting them back out was the right call Descriptions agents actually use correctly, shown with before-and-after tool-call traces Confirmation and dry-run patterns for destructive tools Auth and multi-tenant context isolation across agent sessions Error responses that let an agent recover instead of giving up The eval harness we run against our own server to catch regressions before they hit production
Attendees leave with a checklist they can run against any MCP server they own or are about to build.
This talk is for engineers already building MCP servers that touch anything destructive or stateful, not for people evaluating whether to build one. Assumes familiarity with LLM tool calling; no prior MCP experience required.
Conference India 2026
Hadar Geva
Myop
CTO & Co-founder
Navin Pai
StackGen
Director of Engineering
Pradumna Saraf
Kestra Technologies
Quality Assurance Engineer
Sajeetharan Sinnathurai
Microsoft
Principal Product Manager