Free YouTube Transcribe

Video transcript

MCP Is Not Good Yet — David Cramer, Sentry

AI Engineer · 3,875 words · 18 min read

Want to search this transcript, jump the video from any line, or download it as TXT, SRT, or VTT?

Open in the transcript tool

Full transcript

0:03[Music]

0:15Um, welcome everybody. This is a little

0:18bit last minute, so bear with me. If you

0:19don't know me, uh, I started Century a

0:21long time ago. David Kramer. I'm sort of

0:24an engineer, sort of an executive, sort

0:25of a founder. Uh, I would like to think

0:28I have rational opinions. So that's what

0:30this is

0:33going to

0:39complicated. It's just big scary words.

0:41So if you do, great. If you don't, maybe

0:45you walk away, you're like, "Yeah, I

0:46thought that's what it was. We've done

0:48it."

0:50Mostly, uh, I was asked a couple days

0:52ago while I snuck my way into this

0:53conference if I could fill a slot. And

0:55so filling this slot was like, "Oh, come

0:57give some hot takes. Maybe spice it up a

0:59little bit." So that's what we're going

1:00to do. It's not going to be too much of

1:02a rant. If you know me, I like to rant,

1:03but you know, we'll dial back for this

1:05one a little bit. So what is an MCP? You

1:09know, I I got to say this is like one of

1:10the wildest phenomenons. I It's like the

1:12new crypto wave or something.

1:14Everybody's like, "Yeah, MCP. We don't

1:15know what it is, but we're here for it."

1:18And you find a lot of these sort of like

1:19opinions around, you know, how it should

1:22be, how it shouldn't be. And you know

1:23what I often find is people who have

1:25these opinions have not built anything

1:26or at least not built the thing they're

1:28talking about. I built Century's MCP

1:30server mostly as a fun project. Um so

1:33take this for what it is. Um it's also

1:35Century's MCP server. These are biased

1:37opinions towards what Sentry is. If

1:39you're not familiar with Sentry, you

1:41probably should be, but we do

1:42application monitoring. We do a bunch of

1:44stuff. Um if you have bugs on the

1:46internet, they probably go to us. Uh and

1:48so it's in context of a B2B SAS

1:50business. A lot of you probably work at

1:52enterprise companies if you will. So

1:54think about it that way. But the way we

1:55think about MCP is it is a pluggable

1:57architecture for agents. Full stop.

2:00That's it. It's pretty simple to reason

2:01about.

2:03And again,

2:05all of this is contextualized in an

2:07enterprise cloud service kind of way.

2:10There's a lot of other variations of how

2:11you might adapt MCP. There's tool chains

2:13that make sense locally. We're talking

2:15about we run cloud services. That's most

2:18of the industry. We're B2B. we're

2:19enterprise. I think a lot of this

2:21actually still applies. Um, but take

2:23that with a grain of salt. So, how we

2:26think about MCP with Sentry particularly

2:28because this again relevant here. We fix

2:31bugs. There are things like cursor where

2:34you also fix bugs. What if we could all

2:36fix bugs together? And so everything's

2:38contextualized in that. And I think

2:40there's this whole thing of like how do

2:42we be relevant? That's like the the name

2:44of the game for every single company in

2:45the world right now. Um, is like oh how

2:47how do we become an AI company?

2:49We too are now an AI company. Um, but

2:54Sentry has a lot of bugs. I fix those in

2:55my editor. Wouldn't it be cool if the

2:57bugs could be inside my editor

2:58sometimes? That's a great example of

3:00where maybe an MCP is useful, but at the

3:02very least we're going to pretend it's

3:03useful. So, that's the context here. Um,

3:06but it all comes back to like probably

3:07the reason everybody's here is like, how

3:09do I become relevant? I've got an AI

3:11mandate. I've got infinite money to

3:12spend all of a sudden for some reason

3:14that didn't exist yesterday. How do we

3:16get involved? Okay, so everybody

3:18probably same stage. I know how this

3:19works. So,

3:21all right. Um, we built this a few

3:23months ago. We are not first to market

3:25with MCP.

3:28And the reason why is because the

3:30there's two interfaces for MCPS. I'm

3:31going to focus on a remote interface,

3:32but there's also the standard IO. You

3:34probably learned about that or know

3:35something about that. I don't think

3:36standard IO is super useful for

3:38businesses like ours. I'll talk about

3:39that, but but sort of the analogy of why

3:42MCP is useful. This is VS Code Insiders,

3:44which you just uh heard from Harold, but

3:47like they do a pretty good job. They're

3:48the only ones with OAS support that's

3:50like useful today. Cursor promised me

3:52end of week. I don't know, hold them to

3:53that. Um, but it works pretty well. You

3:55plug in Century's MCP, you can look up

3:57data from Sentry and a bunch of curated

3:59workflows. You can maybe fix some bugs,

4:01maybe easier than it was before, or at

4:02least more fun than it was before. Um,

4:05and for the sake of this, I I needed a

4:07screen grab. So, last night I'm like

4:08literally last night I'm working on

4:09these slides and I go into VS Code. And

4:11I'm like, I'm just going to plug it in.

4:13I don't have time to fuss around if the

4:14thing's going to break. And so I use the

4:15VS Code and I'm like, okay, I'll just do

4:17a thing where it's like, fix all my bugs

4:18for me. And then immediately it does

4:21like 20 API queries this entry. Probably

4:23cost me like five bucks to run this

4:25thing. Um,

4:27but it did start fixing some bugs. Uh, I

4:30don't know if the fixes were good, mind

4:31you. They're they're probably garbage.

4:32Um, but it does the thing, right? It's

4:35like it brought context into the editor,

4:37which is what we want. And that context

4:38was provided by somebody else. Sentry in

4:41this case. So that is like one of the

4:42interesting things. It's one of the

4:43interesting things we think about and

4:44why MCP is like like valuable to sort of

4:47a traditional I don't know we're kind of

4:50an enterprise company but like like

4:52every company in the world and that's

4:54part of why we're all hopping on it.

4:55It's pretty accessible and that's what

4:56I'm going to talk about. It is actually

4:57super accessible. So

5:00this is you. This was me. Um and this is

5:04why I have opinions about it now. It's

5:06like oh it's just an API plugs in. We've

5:08got an API. we've got some OOTH going

5:10on. You know, we had our own OOTH

5:12provider. You know, a lot of you might

5:13use something like a work OS or, I don't

5:15know, pick one of these authentication

5:16services that just gives you it out of

5:18the box. If you have that, you're pretty

5:20much ready to go, which is pretty cool.

5:21It's actually like a pretty low

5:22boilerplate uh implementation. Um, but

5:25then you quickly learn that it's

5:27actually not that easy. And so, first

5:29you kind of go into this OOTH like dance

5:30and you're like, "Oh, okay." Like, yeah,

5:32we're going to do this, but it needs

5:33oath 2.1 and nobody in the world

5:35supports this thing. like it's like I

5:37don't know how old it is, but I had

5:38never heard of it before MCP. Um, and so

5:41there's a little bit of complexity

5:42there, but you're like, "Okay, it's

5:43almost there. It's OOTH. We've got that.

5:44We can plug it into our API." You kind

5:46of get it working. In our case, we use

5:48Cloudflare Shim, which basically lets us

5:50proxy our OOTH 2 API on top of

5:53Cloudflare workers, which has a 2.1

5:55client registration thing. I don't know

5:57if anybody's talked about that. TLDDR,

5:58it's complicated. Um, but it's not that

6:01complicated. This was built in a couple

6:03days, mind you, and I'm also an

6:04executive at the company. So, it's like,

6:06yeah, if I can do it, everybody can do

6:07it. Um, but you go through the OOTH flow

6:09and then you're like, cool, but the the

6:12robots don't know actually how to reason

6:13about giant JSON payloads that were not

6:15built for them. And this is actually

6:18where I think a lot of people break

6:19down. There was like a big conversation.

6:21This is sort of one of my first

6:22opinions, if you will, what I might call

6:24common sense, is that MCP is not a thing

6:28that just sits on top of Open API. Like

6:30you cannot just be like I got an API.

6:32I'm going to expose all those end points

6:33as tools. You're going to get the worst

6:35results you can possibly imagine. You're

6:36be like oh this doesn't make any sense.

6:38You have to massage everything. You have

6:39to design around the system. But like

6:41generally speaking, and I'll talk a

6:42little bit about this, like you need to

6:44really think about how would you use an

6:45agent today? How do the models react to

6:47what you do when you provide them

6:49context, which is what this really is

6:51for, and design a system around that. So

6:53might leverage your API. It is not your

6:55API. And then you get past that and you

6:57wire it up to things like cursor and VS

6:59code and you're like why is this

7:00breaking all the time? You can't you

7:02can't solve for that one. It's just you

7:04got to wait for everybody to catch up.

7:06They're almost there. Uh you know

7:08handful of clients support native

7:10authentication now. They're kind of

7:12stable. Um to the code's credit, it

7:14hasn't broken much recently. Cursor's

7:16broken quite a lot on me, but they're

7:17both great. Don't get me wrong. Cloud

7:19has support. Cloud Code has sort of

7:21support, but not really. Um, so I guess

7:25it might work, it might not. I think

7:27particularly in the developer ecosystem,

7:29we're much more ahead of the curve. And

7:31so if you're trying to adapt your

7:33services to third party agents that are

7:35in our ecosystem like these editors,

7:37you've probably got a good shot of it

7:38working tomorrow,

7:41if I don't know, it's Salesforce or

7:43something. I have no idea. So So you're

7:46you're kind of beholden to like the

7:47clients and the implementation because

7:48again, it's a plug-in architecture for

7:50agents. Um there's a lot of other use

7:51cases that are not just third parties,

7:52but that's kind of the focus. And so I'm

7:55going to try to be constructive from

7:56here. Let's see, we got nine minutes. Um

8:00just a few learnings and I'm happy to

8:01talk more about this later. I'll be

8:02around. Um

8:05you'll probably somebody in this room is

8:06going to disagree with this, but you

8:07should only care about OOTH if you're a

8:10B2B SAS company like me. Um

8:13and particularly you care about OOTH

8:15with remote environments for the most

8:17part. If you're like, "How do I

8:19integrate my services into various

8:20agents?

8:22I want bugs to exist in cursor." I want

8:25to run a cloud service. And I want to

8:26run a cloud service for the exact same

8:27reason I've always wanted to run a cloud

8:29service because I can iterate on it. I

8:30can ship fast. I can dial in security.

8:33All the advantages it turns out are

8:35exactly the same because technology has

8:36not changed. And so if I were you and

8:39you're not building something hyper

8:41specific that is like a local

8:42devicecentric thing just focus on the

8:44remote MCP server focus on the O

8:46specification and just like don't worry

8:48about it. The the problems will solve

8:49themselves. Security will solve itself

8:51because there's a whole world of

8:53security problems and the standard IO

8:55interface is filled with most of them.

8:57Um I'm not going to talk about that. I'm

8:58sure there's some other talks here about

8:59prompt injection but it is like very

9:01very very scary. Do not allow random MCP

9:04tools in your organization. Um, trust

9:07people that have earned trust. Don't

9:09download random packages off the

9:10internet. Uh, it will be a very bad time

9:12for your organization. Um, I did mention

9:14this cloud desktop has I think full OS

9:16support right now in production in G. VS

9:19Code Insiders has it. Um, these are

9:20great because you just drop in the MCP

9:22URL and it handles everything from

9:24there. Cursor like I said I think this

9:26week. Um, I don't know about anybody

9:28else. I don't pay attention much beyond

9:30anybody else and I think cloud code has

9:31not at least I've not seen anything. Um,

9:34and then there's a bunch like a long

9:35tail, right? So, works pretty well.

9:37There is this MCP remote package which

9:38is how we shipped all this stuff. It

9:40works okay. I applaud early adopters for

9:42getting this out. It's not a great

9:43experience and you'll find a lot of this

9:45is not a great user experience. It's

9:47rough. It's beta. That's fine. Um, this

9:51is the biggest thing going back to the

9:52open API thing. You actually have to

9:53spend the calories. You can't just be

9:54like, "Haha, we proxied Open API and

9:56exposed it as tools. It's going to do

9:58nothing." And so, what the right answer

10:00here is, who knows? um our version of

10:03this and I'll talk a little bit about

10:05why is like we return markdown. We've

10:08we've taken some API endpoints and we've

10:10directly translated some of the response

10:12to markdown but it's intentional. It's

10:14like I want to get a bug out of Sentry.

10:16I'm just going to give you the bare

10:17essentials. I'm going to give it in a

10:18structured way that a human can reason

10:20about because generally speaking, if a

10:21human can reason about it, the language

10:23model can reason about it because it's

10:25effectively pattern matching on

10:26language. um it can kind of figure out

10:28JSON here and there, but if if you

10:30actually push it, you're going to find

10:31it breaks all the time. So, just use

10:32something like Markdown. Um it's not

10:35scientific. I think there's a lack of

10:37science in a lot of this. It's hard.

10:38Just go with whatever works. But you you

10:39have to really think about you don't

10:41control the the consumer. You don't

10:43control the model. And so, you're kind

10:44of like this least common denominator

10:46thing. And so, think about that. But you

10:48need to design the system and you need

10:49to treat it as like you are providing

10:50context to an agent that you don't know

10:52what the agent is doing, right? And so,

10:54that's the name of the game is context.

10:57that same thing. Uh sorry, here's an

10:58example of that. I forgot what my slides

11:00were. Uh we just like give kind of a

11:02reasonable description of tools as the

11:04first version of context. Um which

11:07sometimes you hit token limits with all

11:08this. So there's some other challenges.

11:09We give a reasonable description of a

11:11tool with the hopes that clients figure

11:13out how to make use of this context. So

11:15it can call the right tool. It can call

11:16it when it needs to. It can choose one

11:19tool over the other tool, which is a

11:20really unfortunately hard problem for it

11:22to figure out. Um mostly

11:23straightforward.

11:25errors. Same thing. You got to design

11:26the errors. They are still context

11:28because just like a human can't figure

11:30out how to call your API, the machine

11:32also can't figure out how to call your

11:33API. In my example, I'm like fix all my

11:35bugs for me. And it it queries like

11:38every organization in century that I

11:39have access to. It queries all it's like

11:41like 20 API calls when it should have

11:42been one even with all this context. So

11:45we are a long ways from this being

11:46great. But it's like a glimmer, right?

11:48So you know in this case it's like oh

11:50you didn't pass the the thing or rather

11:52you pass an invalid value for the thing.

11:54give it a real human response. This is

11:56now more important than ever because

11:58again it's not just a sort of machine

12:00reasoning about it where you can

12:01hardcode all this stuff. It's abstract.

12:03You don't know who's reasoning about it.

12:06The biggest thing and this is sort of

12:07leading to like the my overarching view

12:09of the world is like you don't you have

12:10no control which already is a problem.

12:13You are also passing the cost on in a

12:15lot of these cases. So you actually kind

12:16of need to be mindful. So another reason

12:18to not just be like here's my API. I'm

12:20just going to return everything to you

12:21because all of a sudden, you know, that

12:22that call, if you will, that tool call

12:24that could have been a dollar might be

12:26$10 now because of the amount of tokens

12:28you needed. And more importantly, it

12:29might just not work. Like early on in

12:32and I don't know if VS Code and or

12:33OpenAI, I don't know who's to blame, fix

12:35this, but like there was and may still

12:37be a limit to the amount of tokens or

12:40description lengths of tools. Makes

12:42sense, right? You want to constrain the

12:44cost of every API call, but all of a

12:45sudden now you have problems again. So,

12:47you got to be really thoughtful about

12:48this. This is going to be evolved. And I

12:49think the big thing is like if you build

12:50one of these, it's not set and forget.

12:52Like we're still updating this thing

12:53every week, tweaking it here and there,

12:54trying to look at like what's happening

12:55and evolving it, right? But the biggest

12:57thing, and this is sort of my my

12:59takeaway, my my very very strong belief

13:01is like you just need to really focus on

13:03building agents. MCP is a plug-in

13:05architecture. There's a lot of value

13:06behind it, but the like the inherent

13:07value of a lot of what LLM are bringing

13:09is this sort of agent architecture,

13:11which by the way is just a service

13:12architecture with a fancy new word on

13:14it. Common sense kind of stuff, right?

13:16Um, and so we've done this in Century.

13:19It does not work well with MCP yet for

13:20for what it's worth. There is no

13:22streaming responses for tools yet. And

13:23that's a big problem when you think

13:24about sort of this agent to agent. And I

13:26don't mean this in like the Google way.

13:27I mean in like the generalized point of

13:29view of agent to agent. Um, but it gives

13:32you control and it's it's the same as

13:33all software. If you have control, you

13:35can be responsible for the success, for

13:37the failure. I can be responsible for

13:38the prompt that dictates how the tool is

13:40called. I can be responsible for the

13:42result from the tool. I can make many

13:44calls behind the scenes and wrap those

13:46up. So I I just get a lot more control

13:48if I pick up the cost of that agent. I

13:50control the model even, right? And so I

13:52think this is this is my big bet and I

13:54think this is where B2B is going to

13:55shine is when we start exposing agents

13:57through the MCP architecture. Again,

13:59treating MCP as a plug-in architecture.

14:02We've done that with one of ours which

14:04is this thing. We keep renaming it so

14:05bear with me. It's like called Seir now,

14:06but it's just like Century's got a lot

14:08of data on what's broken in your

14:09application. And we do this thing where

14:10we do this really high quality root

14:12cause analysis that's done via an agent.

14:15Um we expose that root cause analysis

14:17mostly to our UI to be fair. We also

14:19expose it to the MCP but because it

14:22doesn't do streaming we have to do like

14:23some pulling check where it's like okay

14:24start the job and then let's check in on

14:26it a few times but then there because

14:28the way agents work it just gives up at

14:29some point. So it's a little complicated

14:31but again beta testing the promise is

14:33there. Um but when this works I I really

14:37think this is going to be the value

14:38unlock for a lot of us. Again, MCP does

14:40a lot of things. It's an abstract

14:41protocol. Um, but the agent analogy is

14:43really good. Um, aside, all this is open

14:45source. You can find Century's MCP

14:46somewhere on the internet. You'll find

14:48it on GitHub. I should say fair source.

14:50There's some complexity there. This is

14:51what the agent looks like in the UI.

14:53Check it out if you haven't. We'll be

14:54around. Give me feedback. Um, I think

14:57the last thing I want to sort of part

14:59with is just like this stuff is not that

15:02hard. Um, it's quite broken all the

15:04time, but it's not that hard. I again I

15:06built it in two days. I got a lot of

15:07jobs to do at the company. you can just

15:09go build it and try it out and learn and

15:10like all this stuff is pretty obvious. I

15:12think the lesson we've learned at Sentry

15:14uh or still are learning I should say.

15:16Uh everybody is scared of all this stuff

15:18because there's fancy new words for

15:20everything. But the fancy new words are

15:22just new words for the same thing. It's

15:23just a new like code of paint, right?

15:25You know MCP is just a plug-in

15:26architecture. Agents are just services

15:28like the the LLM calls or MCP calls

15:31actually half of tools are just API

15:32calls with a new response format, right?

15:34So it's pretty accessible to do all

15:35this. There's a lot of great like

15:36technology that's been going on in here.

15:38Um, like I said, we used a lot of

15:39Cloudflare tech. We did not use

15:40Cloudflare at all before this. And then

15:43in a couple days, we're like, cool, we

15:44can shim up a thing on on workers.

15:46They've got an OOTH proxy for us.

15:48Problem solved. And this is important

15:49because we don't run websocket

15:51infrastructure at Century. It's just not

15:52a thing we had, right? And

15:54unfortunately, the protocol requires

15:56something like that, which makes it a

15:57little bit annoying to adopt, but but

15:58again, it's not that hard. It's pretty

15:59easy to adopt. Uh, try it out. You'll

16:02probably hit a lot of bugs, but just

16:03stick with it. I I think this one will

16:04stick around. Um, but I would really

16:06dial in the thinking around agents and

16:08how you're optimizing for context in the

16:10workflows you understand for your data.

16:12Uh, with that said, I will be around the

16:14rest of the afternoon, probably at our

16:15our booth in the expo hall if you want

16:17to come chat. Uh, come say hi. I'm

16:20always happy to like rant about other

16:22things or give you my semi-informed

16:24opinions. Um, I'm not an AI guy to be

16:26clear, but um, cool. With that, you

16:29know, thanks everybody for for showing

16:31up to this talk in this wild conference,

16:33which is interesting. and I'll call it

16:35there.

This transcript was generated from the captions YouTube publishes for this video. Get the transcript of any YouTube video atfreeyoutubetranscribe.com: free, unlimited, no sign-up.