<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet type="text/xsl" href="rss.xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>Bloque Documentation Blog</title>
        <link>https://docs.bloque.run/blog</link>
        <description>Bloque Documentation Blog</description>
        <lastBuildDate>Mon, 28 Sep 2026 00:00:00 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <item>
            <title><![CDATA[MCP setup for a 15-person team: what breaks]]></title>
            <link>https://docs.bloque.run/blog/mcp-setup-what-breaks</link>
            <guid>https://docs.bloque.run/blog/mcp-setup-what-breaks</guid>
            <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A 15-person team wires up Claude and other AI tools to five everyday apps. Here's where that setup quietly falls apart — and who ends up cleaning it up.]]></description>
            <content:encoded><![CDATA[<p>Fifteen people. No IT department. Just a developer who was the first to get Claude and other AI tools talking to the team's actual work — Slack, the accounting app, the CRM, GitHub, the shared drive.</p>
<p>It works great for about six weeks. Then it starts breaking in ways nobody planned for.</p>
<!-- -->
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="it-starts-with-one-connection">It starts with one connection<a href="https://docs.bloque.run/blog/mcp-setup-what-breaks#it-starts-with-one-connection" class="hash-link" aria-label="Direct link to It starts with one connection" title="Direct link to It starts with one connection" translate="no">​</a></h2>
<p>Someone wants Claude to read invoices from Xero. There's a community <a href="https://github.com/xeroapi/xero-mcp-server" target="_blank" rel="noopener noreferrer" class="">MCP server for Xero</a>, and it gives you two ways to connect: a full OAuth flow, or a simpler bearer token you generate once in Xero's own settings and paste into the server's configuration. Bearer token, obviously — why do the OAuth dance for an internal tool.</p>
<p>Except "paste into the server's configuration" means: install Node.js if it isn't already on this machine, edit a JSON file by hand, and launch the server with <code>npx</code>. None of that has anything to do with the credential. It's just what running a local MCP server looks like, and it's the same set of unfamiliar steps whether the app behind it needs a token or not.</p>
<p>The developer does this in ten minutes without thinking about it. Then a non-technical coworker tries to do the same thing for their own laptop, and the ten minutes turns into a screen-share.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="not-every-server-works-this-way">Not every server works this way<a href="https://docs.bloque.run/blog/mcp-setup-what-breaks#not-every-server-works-this-way" class="hash-link" aria-label="Direct link to Not every server works this way" title="Direct link to Not every server works this way" translate="no">​</a></h2>
<p>Here's the part that makes this harder to reason about, not easier: half the team's other apps don't use a config file at all. HubSpot and Zoho, for instance, connect over OAuth — no token to paste anywhere, just a browser popup and a "click to authorize" screen the first time you use the tool.</p>
<p>So "setting up MCP" isn't one repeatable process. It's two different processes that happen to look similar from the outside, and which one you get depends on which app you're connecting that week.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-multiplication-nobody-notices">The multiplication nobody notices<a href="https://docs.bloque.run/blog/mcp-setup-what-breaks#the-multiplication-nobody-notices" class="hash-link" aria-label="Direct link to The multiplication nobody notices" title="Direct link to The multiplication nobody notices" translate="no">​</a></h2>
<p>Neither path stays a one-person problem for long.</p>
<p>The token-and-config-file apps accumulate the obvious way: the same bearer token, copied into a plain text file on every laptop that needs it. Five apps like that across fifteen laptops isn't fifteen files — it's a matrix, and every cell is a credential nothing is watching.</p>
<p>The OAuth apps are better in one real sense: nobody's sharing a token, everyone authorizes as themselves. But someone still has to make that possible in the first place. A few services support Dynamic Client Registration, where the AI client can register itself and a person just clicks "Authorize" — genuinely no setup. Most of the everyday SME apps don't support it yet, though, which means before anyone can click anything, someone has to go into that vendor's developer portal, register an OAuth application, and hand-configure a client ID, a client secret, and a list of scopes. That's real, unfamiliar work, and unlike the token sprawl, it doesn't scale with headcount — it scales with the number of apps. Every new app the team connects is another one-time setup task that only one person knows how to do.</p>
<p>Nobody sat down and designed either pattern. They're just what happens, once per app for the OAuth apps, once per app per laptop for the token apps, until both piles are real.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-questions-you-cant-answer">The questions you can't answer<a href="https://docs.bloque.run/blog/mcp-setup-what-breaks#the-questions-you-cant-answer" class="hash-link" aria-label="Direct link to The questions you can't answer" title="Direct link to The questions you can't answer" translate="no">​</a></h2>
<p>Once both patterns exist, some ordinary questions stop having answers:</p>
<ul>
<li class=""><strong>Which of these tokens still work?</strong> For the bearer-token apps, nobody's sure if three people are sharing one token or holding three separate ones.</li>
<li class=""><strong>Which tools even got called?</strong> Most of these setups can't say which MCP tools were invoked last week, on which app, by whom — not the data behind them, just the fact that something ran — without asking each person directly.</li>
<li class=""><strong>Which apps did we ever wire up OAuth for, and how?</strong> The OAuth app's own admin panel will happily show connected users once you're looking at it — the problem is remembering which of the team's apps have one, and where the client ID and secret for each one are even stored.</li>
<li class=""><strong>Who set this up, again?</strong> One developer has all of it — which apps use tokens, which use OAuth, which laptops have Node.js — in their head. If they're out sick, the next hire's setup depends on someone reconstructing it from scratch.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="onboarding-is-fine-offboarding-is-the-problem">Onboarding is fine. Offboarding is the problem.<a href="https://docs.bloque.run/blog/mcp-setup-what-breaks#onboarding-is-fine-offboarding-is-the-problem" class="hash-link" aria-label="Direct link to Onboarding is fine. Offboarding is the problem." title="Direct link to Onboarding is fine. Offboarding is the problem." translate="no">​</a></h2>
<p>Adding a new person is a known quantity: hand them the bearer-token apps' config, point them at the OAuth apps' login button, maybe walk through the Node.js install once. It's the reverse that has no playbook.</p>
<p>When someone leaves, "cut their access" isn't one action, it's two kinds of cleanup in different places: rotate the Xero token they had, <em>and</em> log into HubSpot's admin settings, and Zoho's, to find and revoke their individual grant — a different console for each one. Both chores land on the same one person, and neither shows up on a checklist because nobody wrote the checklist.</p>
<p>Multiply that by however many people cycle through a growing team over a year, and the setup that took ten minutes six weeks ago is now a standing chore with no owner.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="why-this-doesnt-show-up-on-anyones-radar">Why this doesn't show up on anyone's radar<a href="https://docs.bloque.run/blog/mcp-setup-what-breaks#why-this-doesnt-show-up-on-anyones-radar" class="hash-link" aria-label="Direct link to Why this doesn't show up on anyone's radar" title="Direct link to Why this doesn't show up on anyone's radar" translate="no">​</a></h2>
<p>This isn't a security incident. Nothing gets breached. That's exactly why it survives so long — there's no single moment that forces anyone to fix it. It's just a slow accumulation of plain text files, unrevoked OAuth grants, and one person's memory as the only record of how the team's AI tools are actually wired together.</p>
<p>The team that outgrows this fastest is the one that took AI seriously earliest — the same one now discovering that "one developer configures it by hand" was never a real system, just the thing that happened before anyone needed one.</p>]]></content:encoded>
            <category>Guides</category>
        </item>
        <item>
            <title><![CDATA[Bloque public beta: the hosted MCP gateway for your team]]></title>
            <link>https://docs.bloque.run/blog/public-beta</link>
            <guid>https://docs.bloque.run/blog/public-beta</guid>
            <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Bloque's public beta is live — one hosted MCP endpoint for your whole team. Approved servers, encrypted credentials, per-member keys. No infrastructure.]]></description>
            <content:encoded><![CDATA[<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="somebody-on-your-team-just-became-the-it-department">Somebody on your team just became the IT department<a href="https://docs.bloque.run/blog/public-beta#somebody-on-your-team-just-became-the-it-department" class="hash-link" aria-label="Direct link to Somebody on your team just became the IT department" title="Direct link to Somebody on your team just became the IT department" translate="no">​</a></h2>
<p>If your company uses AI tools seriously, someone — probably a developer who never asked for the job — is now responsible for how the whole team connects its AI tools to the outside world.</p>
<p>That person deals with three problems every week:</p>
<p>API keys pasted into random config files on a dozen laptops. No way to see what the team's AI tools are actually touching. And every new hire means another afternoon walking someone through MCP setup by hand.</p>
<!-- -->
<p>The tools built to solve this are built for enterprises: gateways you deploy on Kubernetes, platforms that assume an identity provider, products whose pricing page is a "Talk to sales" button. If you're a 20-person company, you're not the customer — you're just told to become one.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-bloque-does">What Bloque does<a href="https://docs.bloque.run/blog/public-beta#what-bloque-does" class="hash-link" aria-label="Direct link to What Bloque does" title="Direct link to What Bloque does" translate="no">​</a></h2>
<p>Bloque is a hosted MCP gateway. One admin sets up the servers; everyone else just points their MCP client at one endpoint. Behind that endpoint:</p>
<p><strong>Approved servers, shared by the team.</strong> You pick which MCP servers your company uses. Everyone gets them — nobody configures anything locally.</p>
<p><strong>Credentials stored once, encrypted.</strong> Connect your GitHub org, your Slack workspace, your shared database once. Keys never live in anyone's local config again.</p>
<p><strong>A key per member.</strong> Someone leaves? Revoke their key. Nothing else changes.</p>
<p><strong>Who-called-what logs.</strong> Not enterprise audit machinery — just an answer to "what did our AI touch today?"</p>
<p>Plus a playground for testing servers and debug logs for when things break.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="where-bloque-comes-from">Where Bloque comes from<a href="https://docs.bloque.run/blog/public-beta#where-bloque-comes-from" class="hash-link" aria-label="Direct link to Where Bloque comes from" title="Direct link to Where Bloque comes from" translate="no">​</a></h2>
<p>Bloque started as a fork of the open-source <a href="https://plugged.in/" target="_blank" rel="noopener noreferrer" class="">Plugged.in</a>, an AI content platform with MCP management as one of its features. We wanted only that one feature — so we kept the MCP server management core, removed everything else, and rebuilt it as a hosted, multi-tenant gateway: one router, isolated runners, per-member keys, team billing. The fork is a statement of focus, not a shortcut — and credit to the Plugged.in team for the foundation. If you'd rather self-host a broader platform, their project is worth your time.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-the-beta-is-and-isnt">What the beta is (and isn't)<a href="https://docs.bloque.run/blog/public-beta#what-the-beta-is-and-isnt" class="hash-link" aria-label="Direct link to What the beta is (and isn't)" title="Direct link to What the beta is (and isn't)" translate="no">​</a></h2>
<p>We're launching as a paid public beta. Beta means we're honest about scope: shared servers currently use a shared upstream identity — per-member keys and logs live on Bloque's side. That makes today's Bloque great for team resources (GitHub org, shared Slack connection, shared DB) and not yet the right tool for personal accounts.</p>
<p>The GA release, roughly 8 weeks out, ships per-user OAuth: every member acts as themselves in every tool. In the enterprise-gateway world, getting there means plans that start around $499/mo for 10 users. On Bloque, the same 10-person team pays $101/mo at GA — $85/mo locked for a year if you join during the beta. A price a small team can expense without asking anyone.</p>
<p>Beta customers lock in beta pricing for 12 months — Team at $29/mo + $7/seat (seats rise to $9 at GA). There's a free tier if you just want to try the playground.</p>
<p><strong><a href="https://bloque.run/" target="_blank" rel="noopener noreferrer" class="">Start free →</a></strong> · <strong><a href="https://bloque.run/#pricing" target="_blank" rel="noopener noreferrer" class="">See pricing →</a></strong></p>]]></content:encoded>
            <category>Announcements</category>
        </item>
    </channel>
</rss>