Key Concepts
- AI Agents/MCP Servers: AI programs that act on behalf of users to automate tasks.
- Authorization: Controlling what actions agents are allowed to perform.
- Work OS: A platform for authorization and user management.
- Cloudflare: A platform offering compute (Cloudflare Workers), storage (Durable Objects, KV), AI model hosting, and more.
- Durable Objects: Fast, persistent storage on Cloudflare's edge, suitable for agent memory.
- Bindings: Allow Cloudflare Workers (including agents) to interact with other Cloudflare products and external services.
- OAuth: A standard for authorization, traditionally used for humans, now extended to agents.
- JWT (JSON Web Token): A standard for securely transmitting information between parties as a JSON object.
- KV (Key-Value) Storage: A simple database for storing data as key-value pairs.
- MCP (Machine-to-Cloud Provider): An API that allows AI agents to interact with services.
- Wrangler: Cloudflare's CLI tool for developing and deploying Cloudflare Workers.
- Prompt Engineering: Designing effective prompts to guide AI models.
- Deputization: Granting agents access to tools with appropriate authorization.
AI Agents and the Need for Authorization
The speakers, Lizzie from Cloudflare and Nick from Work OS, discuss the increasing use of AI agents and MCP servers to automate tasks. Lizzie shares examples of agents she built, such as one for auto-voting in NBA finals and another for booking tennis courts. Nick highlights the potential of GitHub MCPs for managing GitHub tasks.
The core problem addressed is the need for robust authorization mechanisms for these agents. Currently, many MCP setups require developers to manually edit JSON files and grant permissions, which is not user-friendly or scalable. The speakers argue that OAuth, traditionally used for human users, should be extended to agents to control their actions and access to resources.
Cloudflare's Role in Building AI Agents
Lizzie emphasizes that Cloudflare offers more than just security and CDN services. It provides a comprehensive platform for building and deploying AI agents, including:
- Cloudflare Workers: A serverless compute environment for running agent code on the edge.
- Durable Objects: Persistent storage for maintaining agent memory and state. They are fast, located close to the user, and now available on a free tier.
- KV Storage: Key-value storage for storing data like order information.
- Bindings: Allow agents to interact with other Cloudflare products and external services.
- AI Model Hosting: Ability to host and run AI models, including inference on vectorized data.
Cloudflare's infrastructure allows developers to deploy code close to users and store persistent data, making it ideal for building responsive and reliable AI agents. The authorization framework within Cloudflare's agents framework facilitates setting up authorization, enabling developers to know who the agent is acting on behalf of.
Demo: MCP Server with Cloudflare and Work OS
The speakers demonstrate a basic MCP server built using Cloudflare and Work OS. The demo involves:
- Deployment: Using
npm run deploy(which executes Wrangler) to deploy the MCP server to Cloudflare Workers. - Integration with Claude: Connecting the MCP server to a Claude client as an integration.
- OAuth Flow: The user signs in with GitHub to authorize the agent to act on their behalf.
- Ordering a Shirt: The user instructs Claude to order a shirt through the MCP server. Claude interacts with the MCP server to list available shirts, collect the user's information (size, address, company name), and place the order.
- Data Persistence: The order information is stored in Cloudflare KV storage.
- User Information Retrieval: The agent retrieves user information (name, email, favorite song, admin permissions) from the JWT.
- Durable Object Interaction: The agent changes the demo mode to "band" by updating the context associated with the worker object, demonstrating the use of Durable Objects for storing user-specific data.
- Authorization Enforcement: The agent refuses to fulfill another shirt order when in "band" mode, showcasing authorization enforcement based on the user's state.
- "Pretty Please" Tool: A "pretty please" tool is used to reset the demo mode, allowing another shirt order.
The demo illustrates how Work OS and Cloudflare can be used to build AI agents with OAuth-based authorization and persistent storage.
Key Arguments and Future Directions
The speakers argue that authorization is crucial for AI agents to prevent misuse and ensure accountability. They envision a future with more fine-grained authorization, such as authorizing per-line changes or per-tool access. Audit trails, enabled by OAuth tools, will be essential for tracking agent actions and identifying potential issues.
The speakers emphasize the importance of treating users as "deputies" who have access to tools that they can use and potentially misuse. They encourage developers to "deputize" their own tools with appropriate authorization mechanisms.
Call to Action
The speakers provide a GitHub repository with the code for the demo MCP server. They also invite viewers to order a free t-shirt from mcp.shop to experience the demo firsthand. They encourage developers to explore building their own MCP servers with OAuth and share their creations.
Notable Quotes
- "OAuth really just isn't for humans anymore. It's for our agents acting on our behalf." - Nick
- "Think of your users not as users but as deputies. They have access to tools and they can use and also misuse them as well." - Lizzie
Technical Terms Explained
- Durable Objects: Very fast storage. You can spin them up per user. They're close to the user as well for like faster retrieval and storage.
- KV (Key-Value) Storage: This is key value storage.
- MCP (Machine-to-Cloud Provider): An API that allows AI agents to interact with services.
Synthesis/Conclusion
The presentation highlights the growing importance of AI agents and the critical need for robust authorization mechanisms. Cloudflare provides a comprehensive platform for building and deploying these agents, while Work OS offers tools for managing authorization and user identity. The demo showcases a practical example of an MCP server with OAuth-based authorization and persistent storage, demonstrating the potential for building secure and user-friendly AI agents. The speakers encourage developers to explore these technologies and contribute to the development of a more secure and accountable AI ecosystem.
AI summaries can miss context or contain errors. Check important details against the original video.