TLDRocket
Sign in

MCP gets AI agents into your APIs. It doesn’t decide what they should see.

The New Stack Matt DeBergalis

MCP can connect AI agents to company APIs fast. The hard part is still deciding what those agents are allowed to see.

Based on reporting by The New Stack, Matt DeBergalis — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

An operations team can already ask an AI assistant to spot orders that will miss a shipping cutoff, check other warehouses, and open transfer requests to cover the gap. That kind of move needs live API calls, not yesterday’s report. So engineers reach for MCP servers because they make internal systems reachable quickly. But reach is only the first step.

Once an agent is inside an order system, the real problem shows up fast. The API may contain personal data, financial details, fraud signals, and operational records that were never meant to spill outside a trusted boundary. Traditional apps solve that with user permissions and backend filtering. Agents complicate the picture. Send everything through and you’ve built a security problem. Filter too much at the tool level and you end up cloning the same service into a pile of nearly identical views for finance, support, inventory, and everyone else.

The cleaner answer is a field-level contract: a deterministic rule that says exactly what an agent can read or change, regardless of the upstream API or the downstream agent. MCP handles discovery and tool calls. Something else has to define the boundary. GraphQL fits that job because it was built so callers ask for only the fields they need. A query can be as small as order { status shipBy }, and the response stays that small.

That same idea gives security teams a lever. If an agent asks for internalFraudScore or customerSSN, the GraphQL layer can block the request or make those fields unreachable. The rule lives with the field, not in every tool wrapper someone remembers to maintain. Writes work the same way. A requestInventoryTransfer mutation exposes a specific business action, while the runtime and the underlying service still enforce availability and approvals before anything goes through.

And none of this means ripping out the systems already running the business. GraphQL can sit on top of REST, gRPC, SOAP, and other protocols. The order service can keep returning a broad record to the integration layer while the agent sees only the slice it is allowed to use. That model has been around for more than a decade and already powers billions of daily transactions at Shopify, Netflix, Airbnb, Expedia Group, and Walmart.

My take — AI-written commentary, not fact-checked reporting

This is one of those rare moments where the boring answer is the right one. MCP makes agents useful, but GraphQL makes them governable, which matters a lot more than another demo that can click around your backend like a raccoon with a clipboard. The industry keeps treating access as the hard part; the real work is control.

Read more about this at: The New Stack

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.