TL;DR: VSCode’s MCP walkthrough shows how installation friction, API key handling, tool discovery, unlimited tool growth, and context management shape developer adoption and security, according to WorkOS. The deeper lesson is that MCP becomes an identity governance problem once secrets, tool access, and runtime context are made easy to delegate.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “From Pain Points to Solutions: How VSCode Solved MCP's Biggest Developer Challenges”.
Key questions
Q: How should teams govern MCP server installation in developer environments?
A: Treat MCP server installation as a controlled enrollment step, not a convenience action.
Q: Why do MCP workflows increase risk when credentials are entered during setup?
A: Because the credential becomes part of a delegated tool path rather than a one-time login event.
Q: What happens when an MCP client exposes too many tools in one session?
A: The user loses practical visibility into what access is actually active, and least privilege becomes hard to enforce at runtime.
Practitioner guidance
- Treat MCP server installation as a control point Require review of what a server can access before it is installed, not after it is already available in the client.
- Remove API keys from persistent configuration files Move credential entry into managed prompts or vault-backed flows so secrets are not copied into JSON blobs that persist across environments.
- Define tool exposure rules for each session Limit which tools can appear in a given workflow and record when the client broadens that set.
Bottom line: MCP convenience is compressing installation, credentials, and tool choice into a single user flow, which weakens the separation between setup and access governance.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
MCP usability is now an identity problem, not just a developer-experience problem: The article shows that installation, secret entry, and tool selection are being normalised into a single client flow. That means governance no longer sits only at provisioning or in a vault, but inside the runtime path where tool trust is granted and exercised. For practitioners, the relevant question is whether the onboarding path itself is now the access decision.
A few things that frame the scale:
- 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: How do MCP context features change identity and access governance?
A: Context features turn session memory, summarisation, and reusable modes into part of the trust model. If context can carry decisions, data, or tool selections across tasks, then the organisation must govern what is reused, what is summarised, and what is isolated. Otherwise, the client can blur boundaries that policy assumes are separate.
👉 Read our full editorial: VSCode’s MCP usability fixes show where identity controls still lag