
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Axel Cuevas</title>
      <link>https://www.axl-devhub.me/en/blog</link>
      <description>Axel Cuevas, backend &amp; AI engineer from Santo Domingo, DR. Warehouse systems, payment rails and permission-gated AI agents in TypeScript and Python.</description>
      <language>en-us</language>
      <managingEditor>axeljcuevast@gmail.com (Axel Cuevas)</managingEditor>
      <webMaster>axeljcuevast@gmail.com (Axel Cuevas)</webMaster>
      <lastBuildDate>Tue, 06 Oct 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.axl-devhub.me/tags/security/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.axl-devhub.me/en/blog/mcp-tool-list-is-the-permission-check</guid>
    <title>The Tool List Is the Permission Check: Building a Per-User MCP Server with OAuth 2.1</title>
    <link>https://www.axl-devhub.me/en/blog/mcp-tool-list-is-the-permission-check</link>
    <description>How I put a warehouse system inside Claude and ChatGPT without giving any model more access than the person using it: one MCP server inside the existing API, tools gated at registration, an audience check on every token, and a write ledger for agent retries.</description>
    <pubDate>Tue, 06 Oct 2026 00:00:00 GMT</pubDate>
    <author>axeljcuevast@gmail.com (Axel Cuevas)</author>
    <category>MCP</category><category>Model Context Protocol</category><category>OAuth 2.1</category><category>AI agents</category><category>NestJS</category><category>security</category><category>authorization</category>
  </item>

    </channel>
  </rss>
