We will be undergoing planned maintenance on Oct 7th 6:00AM UTC / Oct 7th 2:00AM ET

Inspiration

Access work still lives in chat. A request has an owner, a status and a date — until someone asks “where is it?” and the answer is a thread. I already keep that file on the web (Medicine Support Hub). This hackathon is the window: ask by request ID, hear the same row.

What it does

MSH Status exposes that row to Alexa+ and to a classic Alexa skill.

  • get_status — owner, status, due date
  • list_open — open IDs only
  • set_owner — assign an owner code

One spoken sentence. No patient name, no medicine, no diagnosis.

How we built it

  • Node server: /mcp with JSON-RPC initialize, tools/list, tools/call (protocol 2025-11-25), plus a simple {name, arguments} demo shape
  • OAuth 2.0 authorization-code + PKCE, and client-credentials for the recorded demo
  • Bearer gate on /mcp (OAuth access token or a static demo token)
  • ASK custom skill: invocation “medicine status”, GetStatusIntent, cert-chain check on /alexa
  • Vercel route wrappers for /mcp and /alexa

Pre-existing: the hub file. Built for this hackathon: MCP, OAuth, ASK wrapper.

Challenges we ran into

Alexa+ wants Streamable HTTP MCP. Vercel isolates do not share in-memory tokens, so the reliable demo is one Node process. ASK rejects unsigned local curls — that is correct. I did not add a general “Egyptian alternatives” chatbot; that would invent substitutes.

Accomplishments that we're proud of

A working tools/call on request 4821 returns the same sentence the skill speaks. Unauthorized /mcp is 401. The web file, MCP and ASK do not keep three different statuses.

What we learned

Voice is a window. If Alexa and the web disagree, the file is wrong. Tools return the row, not a paragraph.

What's next for MSH Status

Point store.js at the live hub table. Product facts only from a cited register. No invented alternatives.

Built With

Share this project:

Updates

Submission history