The friction of connecting AI agents to external tools often lies in local configuration hell. Michael Freeman, creator of Demo My Product, has bypassed this entirely by shipping a remote Model Context Protocol (MCP) server hosted directly at https://demomyproduct.com/mcp. This move allows agents like Claude Code, Cursor, and ChatGPT to build and publish interactive product walkthroughs without requiring users to install npm packages or manage local processes.
Remote Architecture and OAuth Integration
Unlike many MCP implementations that run as local processes, this server operates on Streamable HTTP, using JSON-RPC over POST to a single URL. The architecture leverages OAuth for authentication, directing clients to https://demomyproduct.com/api/auth for dynamic client registration and PKCE with S256. This design choice ensures that API keys are never pasted into config files; instead, users sign in via their browser, granting specific scopes like 'demos' to the agent. The system also supports immediate revocation via the app's 'Connected agents' settings, offering a clear security boundary that local installs often lack.
Tooling for Screenshot Processing and Hotspots
The agent's workflow revolves around a structured data model where demos consist of steps, each containing an image with hotspots and tooltips. To handle large image data efficiently, the server avoids pushing binary data through tool arguments. Instead, agents request one-time upload links to send PNG or JPEG files (up to 10 MB) directly to the server. For Pro plan users, the agent can even capture public pages by providing a URL, allowing the server to screenshot the page and return element coordinates. This feature prevents agents from guessing hotspot positions based solely on pixel analysis, ensuring clicks land on actual buttons.
Guardrails and Human-in-the-Loop Verification
Freeman implemented strict guardrails to prevent runaway automation. The agent operates under the user's plan limits, with rate caps set at 120 calls per minute, 60 uploads per hour, and 30 captures per hour. Crucially, all agent-generated content remains visible in the standard editor, allowing users to review and edit steps before or after publishing. This design treats the AI output as a first draft rather than a final product, maintaining human oversight in the creation of sensitive assets like blurred email addresses or marketing copy.
Key Takeaways
- Remote MCP servers eliminate local installation friction for AI agents.
- OAuth 2.0 with dynamic client registration streamlines secure agent connections.
- Element coordinate mapping improves hotspot accuracy over blind pixel guessing.
- Rate limits and editor visibility ensure human control over automated workflows.
The Bottom Line
By moving the MCP server to the cloud, Demo My Product proves that agent tooling should live where the data does, not where the user's terminal happens to be. This approach kills configuration hell while keeping humans firmly in the loop for final quality control.