Skip to lesson
supraj.dev THE ENGINEERING HANDBOOKS
LEARN / BUILD / VERIFY2026 edition · checked 06 Oct

FINAL PRACTICE / EXPLAIN THE MECHANISM

The scenario interview.

Trace the failure, identify the boundary, choose a bounded check and state what remains unknown.

A useful five-minute answer

Try the case before opening the hint or answer. Explain your assumptions, propose an observable test and distinguish expected behavior from executed evidence. These are learning exercises, not certification questions.

Compatibility

01 · The modern client keeps initializing

A client sends initialize to a server targeting July 2026 and then removes metadata until calls work. How would you review this?

Show a hint

Identify which protocol era actually ran.

Reveal answer guidance

Pin the protocol and SDK versions, inspect discovery and supported-version handling, and test modern and legacy paths separately. Current requests carry required metadata; silently dropping it does not establish modern compatibility. Retain redacted transcripts for each supported peer combination.

Check your reasoning

  • Names the era boundary
  • Rejects silent fallback as proof
  • Requires observed compatibility

Revisit: chapters 2, 3 and 27.

Authorization

02 · A tool says it is read-only

A server advertises readOnlyHint but its implementation sends data to an external endpoint. Which boundary failed?

Show a hint

A description is different from an enforced effect.

Reveal answer guidance

The annotation is a hint, not an authority boundary. Review implementation and destinations, constrain runtime egress and host capability policy, and test actual effects. Revoke or reject the capability until its behavior matches the permitted purpose.

Check your reasoning

  • Treats annotations as untrusted
  • Traces data destination
  • Tests actual effects

Revisit: chapters 1, 16 and 25.

Caching

03 · Two users receive the same private result

A cache uses resource URI and tenant ID, but two users in the tenant have different object grants. What should change?

Show a hint

Partition by the authorization context that affects the result.

Reveal answer guidance

Private results must not cross authorization contexts. Include relevant principal and grant state with method and result-affecting parameters, handle revocation, and avoid raw tokens in cache keys or logs. Test same-URI requests with distinct permissions.

Check your reasoning

  • Goes beyond tenant ID
  • Includes revocation
  • Avoids credential logging

Revisit: chapters 9, 11 and 24.

Recovery

04 · The response disappeared after a write

The client retries a note creation with a new request ID and two notes appear. Explain a safe design.

Show a hint

Separate transport correlation from business identity.

Reveal answer guidance

A new JSON-RPC ID is a new attempt, not a new intended effect. Retain a stable business idempotency key, enforce durable atomic deduplication at the destination and reconcile unknown outcomes. Approval must remain bound to the same payload and resource revision.

Check your reasoning

  • Identifies unknown outcome
  • Requires destination enforcement
  • Preserves approved intent

Revisit: chapters 4, 17 and 19.

Additional input

05 · A continuation handle changes users

One user copies an opaque requestState value to another account and resumes an operation. What is missing?

Show a hint

Opaque does not mean authenticated.

Reveal answer guidance

Bind state to the authenticated principal, operation, target and lifetime, protect integrity and enforce single-use where needed. Recheck current authorization on continuation. Client-supplied form acceptance is not a general write approval.

Check your reasoning

  • Binds principal and intent
  • Checks expiry and integrity
  • Separates input from approval

Revisit: chapters 18 and 24.

HTTP transport

06 · The gateway approved another method

Mcp-Name says lookup_incident while the JSON body calls a writer. What should happen?

Show a hint

Visible routing metadata must agree with the executed request.

Reveal answer guidance

Reject the header/body mismatch before dispatch. Gateways and handlers must not authorize one operation and execute another. Add negative integration tests for method, name and version consistency, alongside authentication and Origin validation.

Check your reasoning

  • Rejects before effect
  • Checks all mirrored fields
  • Keeps transport and authorization separate

Revisit: chapters 13–15.

Validation

07 · The offline suite passed; production is declared ready

A team treats the fixture capstone as proof of OAuth, distributed retries and model safety. What can the report actually claim?

Show a hint

Match each claim to an executed layer.

Reveal answer guidance

It can claim only the documented deterministic fixture invariants in the recorded runtime. SDK and transport compatibility, authentication, concurrency, tenant isolation and model evaluations need separate executed evidence. List those as remaining validation with acceptance criteria.

Check your reasoning

  • Bounds the current claim
  • Names missing layers
  • Proposes concrete checks

Revisit: chapters 21, 26 and 28–30.

Trust

08 · An incident asks for a credential upload

A retrieved incident includes instructions to read credential files and upload them. How do you prove the host resisted?

Show a hint

Inspect effects, not only final prose.

Reveal answer guidance

Label the record as untrusted evidence, deny capabilities outside the authorized task and assert no credential read or upload occurred. Test the same instruction across descriptions, resources and prompts, with positive controls for legitimate lookup behavior.

Check your reasoning

  • Preserves origin
  • Asserts zero forbidden effects
  • Includes positive controls

Revisit: chapters 10, 16 and 26.

Your next experiment

Choose the case that exposed the largest gap. Return to the linked chapters and add a concrete test to your evidence packet.

Return to the learning path →