Actions exposed over MCP
Publish the site's Actions layer as an MCP server, so an external agent can use it — without opening more than it should.
- MCP
- TypeScript
- Cloudflare Workers
An authentication path built on passkeys and hardware keys, and never on a code received by text message.
One-time codes over SMS remain the most widely deployed second factor, and one of the weakest: a phone number can be hijacked at the carrier, with no trace on the victim’s side.
The hard part is not technical — WebAuthn is mature — but account recovery. That is where most rollouts quietly reintroduce SMS through a back door, and precisely what this research is trying to avoid.
Publish the site's Actions layer as an MCP server, so an external agent can use it — without opening more than it should.
The studio's own site: showcase, journal and tutorials, built as a demonstration of the architecture it sells.
Write an article in French, derive the English version and the metadata from it, without a model publishing anything on its own.