Interceptors Working Group Meeting - August 18th, 2026 #3266
Degiorgio
started this conversation in
Meeting Notes - Interceptors WG
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Repo: modelcontextprotocol/experimental-ext-interceptors Discord: #interceptors-wg
Antitrust Reminder
At the start of each meeting, we remind all participants that we must comply with the MCP Antitrust Policy. Discussion must remain focused on technical standards and avoid:
Competitively sensitive information (pricing, customer lists, market strategies) Non-technical business discussions
Any coordination that could be construed as anti-competitive
Interceptor Working Group Meeting - August 18th, 2026
MCP Event page: https://meet.modelcontextprotocol.io/2026/08/mcp-interceptors-working-group-gG4oM3MVyTYO
Agenda
Attendees
Discussion
interceptors/listandinterceptor/invokemethods, what calls them, or why they exist instead of client/server config. Answer: an interceptor is a standalone MCP server, at the same level as tools, invoked over an MCP transport (stdio or Streamable HTTP). Configuration lives on the client or server side; execution is always out of process. No in-process interceptor use case has come up; none of Bloomberg's run in process. The SEP's "first-party / in-process" wording and the sequence diagrams (which read as the client calling itself) say otherwise and will be fixed.configSchemain the list response andconfigon every invoke; the reason is statelessness. Both models should work: a server started with static config, or config passed per call. The server declares which settings are configurable and their defaults; the client may override; a server may expose no settings at all. Clare raised cases where per-invoke config fits poorly: expensive setup that needs warm-up or caching, and platform teams that want a static configuration with only a few client-facing knobs.interceptor/invokethrough an adapter, which also allows the logic to run in infrastructure rather than on employee machines. Many enterprises in the wild handle PII on LLM traffic at an LLM gateway, in process and vendor-specific, and the interface is standardizing on open responses; ideally a gateway like LiteLLM would call out to an MCP interceptor server. Sambhav: gateways cover enterprise-wide policies; agent-specific mutators need a client-side hook when you do not control the harness. Clare wants this on the core maintainer calendar and discussed in Amsterdam; no consensus yet.Action Items
Post-meeting: out-of-process wording, the SHOULD NOT co-host rule, and
configdefault semantics are in experimental-ext-interceptors#43; chain removal (7/23 action) is in #44.All reactions