---
title: "MCP connector engineering guides | Invokary"
description: "Tested guides on MCP 2026-07-28, OAuth with Client ID Metadata Documents, tool design, evals and platform review."
canonical: "https://invokary.com/guides"
dateModified: "2026-10-05"
---

# Guides

Implementation guides for MCP connectors. Every guide lists its sources, and a guide with code says which spec and SDK version it was tested against.

[Subscribe with RSS](https://invokary.com/guides/rss.xml)

October 5, 2026

## [MCP OAuth for SaaS connectors: Client ID Metadata Documents, the DCR fallback and API keys](https://invokary.com/guides/mcp-oauth-for-saas-connectors)

How a SaaS MCP server and its authorization server meet the MCP spec: protected resource metadata, Client ID Metadata Documents, a DCR fallback and API keys.

- Claude
- ChatGPT

October 5, 2026

## [MCP connector security: prompt injection, tool poisoning and SSRF](https://invokary.com/guides/mcp-connector-security)

The attacks a SaaS company's MCP server is exposed to, from prompt injection to tool poisoning and SSRF, and the defenses the MCP spec and OWASP set out.

- ChatGPT
- Claude

October 5, 2026

## [MCP vs API: what changes when an AI agent calls your product](https://invokary.com/guides/mcp-vs-api)

What an MCP server adds on top of your API: runtime tool discovery, descriptions the model reads, per-user OAuth, and tools designed around jobs, not endpoints.

- MCP Registry

October 5, 2026

## [Why connector submissions get rejected on Claude, ChatGPT and Cursor](https://invokary.com/guides/why-connector-submissions-get-rejected)

The rules each directory's reviewers check for MCP connectors and plugins on Claude, ChatGPT and Cursor, from the platforms' docs, and how to check them first.

- Claude
- ChatGPT
- Cursor

## Find out where you stand in five days.

$750. Credited in full to your build.

[Book a $750 Audit](https://invokary.com/book)
