Inspiration
Access work still lives in chat. A request has an owner, a status and a date — until someone asks “where is it?” and the answer is a thread. I already keep that file on the web (Medicine Support Hub). This hackathon is the window: ask by request ID, hear the same row.
What it does
MSH Status exposes that row to Alexa+ and to a classic Alexa skill.
get_status— owner, status, due datelist_open— open IDs onlyset_owner— assign an owner code
One spoken sentence. No patient name, no medicine, no diagnosis.
How we built it
- Node server:
/mcpwith JSON-RPCinitialize,tools/list,tools/call(protocol 2025-11-25), plus a simple{name, arguments}demo shape - OAuth 2.0 authorization-code + PKCE, and client-credentials for the recorded demo
- Bearer gate on
/mcp(OAuth access token or a static demo token) - ASK custom skill: invocation “medicine status”,
GetStatusIntent, cert-chain check on/alexa - Vercel route wrappers for
/mcpand/alexa
Pre-existing: the hub file. Built for this hackathon: MCP, OAuth, ASK wrapper.
Challenges we ran into
Alexa+ wants Streamable HTTP MCP. Vercel isolates do not share in-memory tokens, so the reliable demo is one Node process. ASK rejects unsigned local curls — that is correct. I did not add a general “Egyptian alternatives” chatbot; that would invent substitutes.
Accomplishments that we're proud of
A working tools/call on request 4821 returns the same sentence the skill speaks. Unauthorized /mcp is 401. The web file, MCP and ASK do not keep three different statuses.
What we learned
Voice is a window. If Alexa and the web disagree, the file is wrong. Tools return the row, not a paragraph.
What's next for MSH Status
Point store.js at the live hub table. Product facts only from a cited register. No invented alternatives.
Built With
- alexa-skills-kit
- amazon-alexa
- http
- javascript
- json-rpc
- mcp
- node.js
- oauth2
- pkce
Log in or sign up for Devpost to join the conversation.