← Back to Insights
ORIGINAL

Pack an Allowlist for MCP Dev Summit

MCP Dev Summit opens in Toronto on 5–6 October. The hallway will sell you plugins. Bring a map of the remotes you already run — and a one-page allowlist — or you will come home with stickers.

Operator packing an allowlist notebook before a Toronto MCP conference

MCP Dev Summit opens in Toronto on 5–6 October 2026. It is a Linux Foundation event — the first dedicated conference for people actually shipping Model Context Protocol into production, not just starring GitHub repos.

Four days out, the default packing list is a laptop, a badge, and a wishlist of new servers. That is how you come home with twelve Connect buttons and zero policy.

Pack an allowlist. The hallway will sell you plugins. The useful work is already on your desk: which remotes you run, which ones still assume sticky sessions, which hostnames you cannot name, and which “MCP” demos are actually WebMCP site tools on a webpage.

Why this weekend is not a product launch

The spec fight already happened. 2026-07-28 made MCP stateless. AWS told operators to delete session affinity. Claude is rolling the revision through products. SDKs crossed hundreds of millions of monthly downloads. Toronto is where maintainers and enterprises compare notes on what broke in production.

The public agenda matches that. Day 1 includes Anthropic lead maintainer Den Delimarsky, plus a TELUS keynote on a year of enterprise MCP — registry, workflows, agents, remote hosting. Day 2 includes NVIDIA-side operational patterns and a session on governing MCP for a workforce the size of a city. Full schedule: MCP Dev Summit Toronto.

If you show up without a map of your own estate, you will treat those talks as inspiration. They are a gap analysis.

The packing list (print this)

  1. Every remote URL your agents already call. Cursor mcp.json, Claude connectors, ChatGPT custom MCP, Slack Claude Tag. If it is not on a page, it does not exist. This is the same inventory we argued after OX found $4 abandoned domains.
  2. Transport and session assumptions. Sticky load balancer? Handshake-gated gateway? HTTP+SSE you promised to kill? Mark it. The twelve-month offramp still feels long in October and will not in April.
  3. A one-page allowlist: what may connect, what may write, what is banned. Policy before plugins is not a slogan at a vendor booth. It is the filter for every demo you see.
  4. Quality, not star count. Influzer’s catalog is about 12,870 MCP servers with only about 386 listings that have indexed tools. Ready surface / Auth required / Thin listing is how you refuse demoware in the Solutions Showcase.
  5. The WebMCP vs MCP sentence. ChatGPT site tools are page-scoped. A storefront is not a connector. Do not let a booth collapse the two catalogs. Ours stay separate: MCP servers and WebMCP websites (~864 sites, ~5,660 tools).

Questions that survive a booth conversation

Skip “does it work with Claude?” Everyone will say yes. Ask:

Write the answers on the allowlist row before you accept a sticker.

What to listen for in the rooms

You do not need to attend every breakout. You need three signals:

If you are remote, the same pack still works. Watch the recaps against your inventory. The conference is a calendar, not a requirement.

A 90-minute drill before Monday

  1. 30 min: Export MCP URLs. Resolve DNS. Kill anything that NXDOMAINs.
  2. 30 min: Handshake the remotes you own. Cold instance, no sticky session, one tool call.
  3. 30 min: Fill keep / quarantine / kill. Quarantine is read-only until an owner signs. Then search replacements by capability with Influzer Discovery — not by booth brand.

That is eyes before hands applied to a conference weekend.

Quick answers

Do I have to be in Toronto?

No. The allowlist is the artifact. The event is optional context.

Is this another deprecation-clock article?

The rip-out list from August still stands. This piece is the calendar: what to carry into the first MCP-native conference so you do not trade policy for swag.

Should we pause new MCP until after the summit?

Pause unreviewed installs. Keep Discovery search open. Install stays default-deny for writes.

Where do WebMCP site tools fit?

On the page, with the human looking. Not in the same row as GitHub MCP. Read your website is not an MCP server before you let a vendor mix them.

Final thought

Toronto will be full of people who are right about the protocol and vague about their own fleet. Do not be vague.

Pack the allowlist. Ask the cold-instance question. Leave the wishlist at home.

Start on the directory. Search from inside the agent with Discovery. If a hostname in your config cannot survive a dig tonight, the summit will not fix it.

GET PRACTICAL AI PLAYBOOKS WEEKLY

One clear email each Thursday

Actionable frameworks on AI execution, agents, and MCP. Join 4,200+ builders.

✓ You're in — first briefing Thursday.

Leave a comment

Be the first to share your thoughts.

Related insights

2026-10-02
MCP Apps Are Not WebMCP
SEP-1865 puts a sandboxed widget inside Claude and ChatGPT. WebMCP puts tools on the live page. Classic MCP is still just JSON. Pick the surface before Toronto sells you all three as one demo.
2026-09-28
Your Website Is Not an MCP Server
ChatGPT site tools are WebMCP on a live page — not another remote connector. If you wrap your storefront as an MCP server, you built the wrong trust boundary.
2026-09-26
Abandoned MCP Domains Are an Allowlist Problem
OX Security’s 24 September scan found MCP hostnames on home networks, in other jurisdictions, and six abandoned domains for about $4. Directories do not cause that. Standing approvals without owners do.