Nango in Practice: Let Users Add Their Own MCP Servers in Chat

A model needs a tool to check project status. A user asks, “What’s blocking the demo project?” The model understands the question, but has no way to read the project’s state. The experience we want is straightforward: the user adds their project service, authorizes access once, then returns to the same conversation and gets an answer grounded in data. What this article verifies Sources were checked as of October 3, 2026, using Nango source and client version 0.71.12. The local examples use Node.js 22+ and have been tested for tool discovery, input validation, and request/response handling, including a local replacement for the proxy adapter. Project data is synthetic; the experiment does not call a model or execute real OAuth and proxy requests through Nango Cloud. The public-server sections provide integration steps to test in your own account. Rolling documentation, pinned source, and cloud deployments may differ; a dependency version does not prove protocol support, and customer stories establish only their stated use cases. The available evidence also does not establish that external MCP tools are automatically imported into Nango’s Action catalog. ...

October 3, 2026 · 19 min · 3888 words · Xinwei Xiong, Me
Concept illustration: a Personal Agent's bounded run, persistent task, execution environment and result receipt; not an accurate OpenClaw architecture diagram

Personal Agent Technical Research: How OpenClaw Connects One Run to Long-Lived Work

For a Personal Agent to do things reliably on someone’s behalf, it has to connect a single model run to a recoverable task and confirm the result against external state. The model saying “I’ve cancelled it” still does not prove that the merchant stopped the renewal. Consider a design example: the user asks the agent to cancel a monthly subscription, keep the benefits already paid for in the current period, accept no new offers, and not delete the account. The agent finds the subscription and reviews the terms, then clicks confirm; the merchant has already processed the request, but the browser disconnects before the result comes back. Clicking again at that point might do one step too many, and reporting success outright has no basis. Whether this can safely continue depends on what was saved beyond the button. ...

October 3, 2026 · 36 min · 7471 words · Xinwei Xiong, Me
Concept illustration: a user delegates errands through a phone, with email, calendar, and completion receipts connected to the user's approval

Personal Agent Product Research: How Instinct Makes People Willing to Delegate Again

For a Personal Agent to earn repeated use, the user has to genuinely carry less of the mental load. If handing over an operation still means chasing progress, rereading results, and nagging it to fix mistakes, the delegation is not complete. One Instinct user documented his own stress test on Reddit: buying snacks across apps and monitoring flight prices, and also researching startups. He was satisfied with part of the results, but he also hit long waits between steps and website verification that required a human to step in. He was willing to let the agent find things and compare prices, and willing to let it prepare an order, but not yet ready to hand over his credit card and let it pay freely. Original stress-test post ...

October 3, 2026 · 32 min · 6710 words · Xinwei Xiong, Me
OpenClaw routing from internet channels through the resident Gateway, deterministic bindings and session keys into per-agent enclaves, device nodes and external side effects

OpenClaw's Long-Running Gateway: Continuity Does Not Mean One Shared Session

Suppose one company runs two Telegram bots: one serves European customers, one serves American customers. Both bots hand messages to the same support agent, and the session isolation policy is set to per-channel-peer. One platform user ID happens to appear in both accounts. The system generates the same key: agent:support:telegram:direct:tg:12345 A conversation from the European inbox can then surface in the American inbox’s context. No model jailbreak, no database corruption, no random routing. The system worked exactly as configured — the session key simply lacked the accountId dimension. ...

August 7, 2026 · 19 min · 3864 words · Xinwei Xiong, Me
The n8n deterministic workflow spine, the constrained Agent spur, human and idempotency gates, external receipt reconciliation, and the Redis worker Postgres queue-mode yard

n8n's Deterministic Exoskeleton: Why Queues and Workers Do Not Guarantee Exactly-Once Side Effects

The previous article, the n8n primer , already started from Manual Trigger → Edit Fields → IF and covered Growth OS, constrained Agents, human approval, the operation ledger, result feedback and alternatives. This article does not build another three-node workflow. We start from a less photogenic failure window: worker → external API write succeeds worker → execution success not yet written back worker → crashes At this moment Redis may hold no active job and Postgres still holds a running execution, yet a third-party system has already received an email, created a record or charged a payment. Re-running the execution can turn n8n green again, and it can also repeat an external write. ...

August 7, 2026 · 21 min · 4346 words · Xinwei Xiong, Me
The Pi minimal agent kernel, the detachable extension rail, provider and host OS trust boundaries, and the JSONL session tree below

Pi by Subtraction: What the Minimal Agent Kernel Keeps and Who Takes Responsibility

By default Pi hands the model only four tools: read, bash, edit, write. It has no built-in Plan Mode, Todo, MCP, subagent, permission popup or background bash. Reading this far, it would be easy to write Pi as a hymn to minimalism: four tools are enough, and every complex framework can be deleted. The more useful question is tougher. After you delete a capability, where does the duty it used to carry go? ...

August 7, 2026 · 18 min · 3766 words · Xinwei Xiong, Me
A shared organizational agent dispatch console connected to permission vaults, memory archives, and isolated work cells

Claude Tag Deep Dive: From Shared Slack AI to an Organizational Agent Runtime

Calling Claude Tag a Slack bot misses its most consequential product decision. It turns a channel into a place where an agent can be authorized, remember, and keep working: a team shares one executor; each task runs asynchronously in a thread-level sandbox hosted by Anthropic; Agent Proxy injects external credentials at the network boundary; and the result returns to the public thread with a traceable record. The Claude Tag documentation describes these mechanisms in unusually concrete terms. ...

August 5, 2026 · 23 min · 4772 words · Xinwei Xiong, Me
I Ran Ten Agents Overnight, Woke Up to Ten PRs, and Then I Got Stuck

I Ran Ten Agents Overnight, Woke Up to Ten PRs, and Then I Got Stuck

This is part two of “The Super Individual’s Gear Stack.” If you haven’t read the overview , start there — every judgment in this piece rests on the yardstick that essay proposed: does an advance in a layer of gear help only you, or does it help all of your competitors at the same time? ...

July 19, 2026 · 32 min · 6628 words · Xinwei Xiong
Agent Skill design shown as code, model judgment, permission gates, and human confirmation

Agent Skill Design: What a Dangerous SKILL.md Taught Me

What makes an Agent Skill valuable is not a clever prompt, but a clean division of responsibility: deterministic work goes to code, judgment goes to the model, and execution confirmation returns to the human. Structured contracts hold those parts together. I reached that conclusion by dissecting a storage-cleanup Skill that can delete local files from a web page. Deletion is one of the most consequential powers an agent-adjacent tool can expose. The design did not make me fearless; it gave me specific controls I could inspect before deciding whether to click. ...

July 18, 2026 · 11 min · 2310 words · Xinwei Xiong, Me
A quiet control room supervising an unattended AI agent workflow

How to Build Real Trust in Unattended AI Agents That Act

Suppose you actually have one now — an agent that takes a job end to end. Pulls the data, writes the code, runs the tests, opens the PR, updates the docs. It doesn’t need you feeding it prompts line by line. You hand it the task at night and go to sleep. The real question isn’t whether it finishes. In coding, research, and content workflows, model capability is often already sufficient to produce a plausible result. That does not mean capability has stopped mattering everywhere: in unfamiliar domains and genuinely novel tasks, it can still be the limiting factor. But once an agent is capable enough to act, a different bottleneck appears — ...

July 15, 2026 · 27 min · 5726 words · Xinwei Xiong, Me
Editorial architecture diagram of Relay with a coordinator, five domain agents, safeguards, browser delivery, and audit boundaries

Relay Agent Architecture in 2026: A Local Implementation Audit

An architecture diagram is a promise. A code audit asks which parts of that promise have acquired weight. My first version of this article treated Relay as a public open-source proposal whose Agent layer had not yet been built. Both claims are now wrong. As of July 31, 2026, the public GitHub URL previously cited by this article returns 404, while I can inspect a private local checkout. This piece is therefore a private/local implementation audit, fixed to local commit 22586e17ccd43cfaff0512511e71a100c5341608. Readers should not assume that repository or commit is publicly downloadable. ...

June 24, 2026 · 11 min · 2298 words · Xinwei Xiong, Me
Argo CD continuously comparing desired state in Git with live Kubernetes state

Argo CD in Production: GitOps Sync, ApplicationSets, Rollbacks, and Security

A green sync does not prove the delivery system is safe When Argo CD turns an application green, it proves one narrow thing: at that moment, the cluster matches the desired manifests Argo CD calculated. It does not prove that the image passed its tests, that a deletion is safe, or that the next Git change belongs in production. That boundary is the right place to begin. Argo CD is not a pipeline that makes release judgments for a team. It is a Kubernetes controller that repeatedly compares, reports, and—when policy permits—reconciles state. Its value is not another attractive dashboard. Its value is turning deployment intent from scattered commands into something reviewable and reproducible. ...

May 9, 2025 · 15 min · 3131 words · Xinwei Xiong, Me
Several model pipelines converge at an AI Gateway where cost and governance are weighed

AI Gateway Guide: LiteLLM, Kong, APISIX, Cloudflare, or Portkey?

An AI Gateway is not merely a reverse proxy placed in front of a language model. Once an application reaches production, every model call carries several kinds of uncertainty at once: long-lived streaming connections, token-based billing, provider quotas, sensitive inputs, changing model behavior, and outputs that cannot be trusted by default. A conventional API gateway can handle part of this traffic. It may authenticate clients, terminate TLS, enforce request limits, and route HTTP requests. It does not automatically answer the questions that matter most to an AI product: ...

April 16, 2025 · 16 min · 3223 words · Xinwei Xiong, Me
From Language Models to RAG: Capabilities, Limits, and Engineering

From Language Models to RAG: Capabilities, Limits, and Engineering

Introduction: Do Not Learn the Model from the Chat Window The first encounter with a large language model creates a powerful illusion. Something on the other side of the screen appears to have read widely, reasoned carefully, and chosen to explain itself. It can write code, summarize papers, preserve a tone across a conversation, and offer a polished rationale for an answer that is completely wrong. The chat window shows behavior, not mechanism. Fluency hides missing evidence. Completeness hides uncertainty. A human voice invites us to overestimate how firmly the model is connected to the world. ...

May 15, 2024 · 20 min · 4118 words · Xinwei Xiong, Me
A timeline of Sora from research preview and product launch to shutdown

Sora Retrospective: From Research Preview and Sora 2 to Shutdown

Status update, July 2026: The Sora website and app shut down on April 26, 2026. The Sora API is scheduled to shut down on September 24, 2026. This is no longer a guide to getting started; it is a record of what the technology, the product, and their ending can teach us. When I first wrote about Sora in February 2024, the irresistible detail was the one-minute video. Two years later, the more useful story is about boundaries: a research result is not a product specification, a better model does not guarantee a permanent service, safeguards do not erase risk, and generated media does not arrive with a simple answer to copyright. ...

February 24, 2024 · 10 min · 1942 words · Xinwei Xiong, Me