← Portfolio

MCP servers: one protocol, many agents

The Model Context Protocol (MCP) is an open standard that lets AI agents use tools: a small server exposes functions with a clear description, and any MCP client, such as Claude Code, can call them. For this platform I built MCP servers in Python for very different jobs: deploying the lakehouse, writing to my blog, generating queries for self-service BI, and searching my platform standards (RAG). Each server hides the risky details (credentials, APIs, Terraform, kubectl) behind a few well-described tools, so an agent never needs raw access. Specialised agents only get the tools they need: the design agents use OpenMetadata and the standards search, the deployment orchestrator uses the deploy tools. Humans stay in the loop: blog posts are only published after approval, generated SQL is reviewed and executed read-only, and infrastructure changes run in phases with validation.

Model Context ProtocolClaude CodeSub-agentsPythonTerraformHelmOpenMetadatapgvector RAG

The hub: Claude Code and four MCP servers

Claude Code (with its sub-agents) is the MCP client. Each server is a separate Python process with its own tools and its own access to one system.

How it works: four use cases

Each diagram shows who calls whom, step by step. Pick a use case; the steps play automatically.

The MCP servers and their tools

Tool names as defined in the server code. The description of each tool is what the agent reads to decide when and how to use it.

Design principles

Least privilege per agentEach sub-agent lists the exact tools it may use; the deploy tools are not available to the design agents.
Secrets stay in the serverCredentials and tokens live in the MCP server and on the VM, never in the prompt or the conversation.
Human approval for side effectsPublishing, deploying and writing data are separate, explicit steps that I approve.
Read-only by defaultQuery tools block write statements; agents can look, not change.
Good tool descriptionsThe tool description is the contract: what it does, when to use it, what it returns.
LLM inside the server where it helpsThe blog and OpenMetadata servers call an LLM themselves, with a fixed prompt and fixed context, for predictable output.