A full-stack e-commerce site built to demonstrate MCP authentication and authorization. agentgateway, Keycloak JWTs and CEL rules are enforced at the protocol layer, so agents cannot route around the security boundary.
In a security track, the reason this landed is that it implements a boundary instead of describing one. Pushing authorization down to the protocol layer, rather than trusting each application to behave, assumes agents will do unexpected things — a far clearer premise to argue from. Hanging it on a working storefront keeps the discussion out of abstract governance language: you can point directly at what is actually being prevented and watch it fail.
Slice the archive by year and the winning stack turns over visibly, generation by generation.
MCP is the most common tag of 2026. The subject has shifted from smarter models to safer connections.
See all winners of Hackathon for MCP & AI Agents (Solo.io) →
Summaries are written by this site. Project pages include demo videos, screenshots and the team's own write-up (videos may autoplay).