Every AI app used to need its own custom connector for every data source. Ten apps and ten tools meant up to 100 bespoke integrations. Model Context Protocol (MCP) replaces that matrix with one open standard: build a connector once, and any compatible AI client can use it. Anthropic introduced MCP in November 2024, and it has since been adopted across the industry, including by OpenAI, Google, and Microsoft, and it is now stewarded as an open standard under the Linux Foundation.
Quick Takeaways
- MCP is an open protocol that standardizes how LLM applications connect to external tools, data, and prompts.
- It uses JSON-RPC 2.0 over two main transports: stdio (local) and Streamable HTTP (remote).
- Servers expose three primitives: Tools (actions), Resources (read-only data), and Prompts (reusable templates).
- A working server takes about 15 lines of Python with the official SDK.
What Is MCP? A Plain-English Definition
MCP (Model Context Protocol) is an open specification that defines how an AI application talks to external systems. Those systems include databases, file systems, SaaS APIs, and internal services.
The USB-C comparison holds up. Before USB-C, every device shipped with its own charger and port. USB-C gave you one connector that handles power, data, and video. MCP does the same for context: one interface that handles tool calls, data retrieval, and prompt templates.
The problem it solves is the N×M integration problem:
| Approach | Integrations needed (10 apps, 10 tools) | Maintenance burden |
|---|---|---|
| Custom connectors | 10 × 10 = 100 | Every API change breaks multiple apps |
| MCP | 10 + 10 = 20 | Each side implements the protocol once |
MCP also borrows its design philosophy from the Language Server Protocol (LSP). LSP let any code editor support any programming language through one protocol. MCP lets any AI client support any tool or data source.
How MCP Works: The Architecture
MCP uses a client-server model with three roles.
The Three Roles
- Host: The AI application the user interacts with, such as Claude Desktop, an IDE, or your own agent app. It manages the LLM and the user session.
- MCP Client: A component inside the host. Each client maintains a 1:1 connection with one MCP server.
- MCP Server: A lightweight program that exposes capabilities such as querying Postgres, searching Slack, or reading a GitHub repo.
The Protocol Layer
MCP messages use JSON-RPC 2.0. A connection starts with an initialize handshake where client and server agree on a protocol version and declare their capabilities. After that, the client can list and call what the server offers.
Here is what a tool invocation looks like on the wire:
{
"jsonrpc": "2.0",
"id": 7,
"method": "tools/call",
"params": {
"name": "get_forecast",
"arguments": { "city": "Berlin" }
}
}
The server replies with a result the host feeds back into the model’s context:
{
"jsonrpc": "2.0",
"id": 7,
"result": {
"content": [{ "type": "text", "text": "Berlin: 14°C, light rain" }]
}
}
Transports
| Transport | Best for | Auth model | Notes |
|---|---|---|---|
| stdio | Local servers launched as a subprocess | Inherits user environment | Zero network exposure; simplest setup |
| Streamable HTTP | Remote, multi-user servers | OAuth 2.1-based authorization | Replaced the older HTTP+SSE transport; supports streaming |
The Three Core Primitives
Servers expose capabilities through three primitives. Each has a different control model: who decides when it gets used.
| Primitive | Controlled by | Purpose | Example |
|---|---|---|---|
| Tools | The model | Executable actions with side effects | create_issue, run_sql_query |
| Resources | The application | Read-only context, addressed by URI | file:///logs/app.log, db://customers/schema |
| Prompts | The user | Reusable templated workflows | /summarize-pr, /code-review |
Clients can also offer capabilities back to servers:
- Sampling: The server asks the host’s LLM to generate a completion, so servers need no API keys of their own.
- Roots: The client tells the server which filesystem or URI boundaries it may operate within.
- Elicitation: The server asks the user for missing input mid-task.
MCP vs. Function Calling vs. RAG vs. Plugins
These get conflated constantly. They solve different layers of the problem.
| Feature | MCP | Native Function Calling | RAG | Legacy Plugins |
|---|---|---|---|---|
| What it is | Open connection protocol | Model-level capability | Retrieval technique | Vendor-specific extensions |
| Portability | Works across hosts and models | Tied to each provider’s schema | Framework-dependent | Locked to one platform |
| Discovery | Dynamic (tools/list) |
Static, defined per request | N/A | Manifest-based |
| Handles actions? | Yes | Yes | No (read-only) | Yes |
| Relationship | Often uses function calling underneath | Foundation MCP builds on | Can be served through MCP | Largely superseded |
The key distinction: function calling is how a model requests a tool call. MCP is how an application discovers and executes tools in a standard way. They work together.
Build Your First MCP Server in Python
You need Python 3.10+ and the official SDK. The SDK’s FastMCP helper generates tool schemas from your type hints and docstrings.
Install:
pip install "mcp[cli]"
# or, with uv
uv add "mcp[cli]"
Create server.py:
from mcp.server.fastmcp import FastMCP
mcp = FastMCP("demo-server") # Server name shown to the client
@mcp.tool()
def add(a: float, b: float) -> float:
"""Add two numbers and return the sum.""" # Docstring becomes the tool description
return a + b
@mcp.resource("config://app-version")
def app_version() -> str:
"""Expose the current app version as a read-only resource."""
return "2.4.1"
@mcp.prompt()
def review_code(code: str) -> str:
"""Reusable code review prompt."""
return f"Review this code for bugs and style issues:\n\n{code}"
if __name__ == "__main__":
mcp.run(transport="stdio") # Use "streamable-http" for remote deployment
Test it with the MCP Inspector:
mcp dev server.py
The Inspector opens a browser UI where you can list tools, call them, and inspect raw JSON-RPC traffic.
Connect It to Claude Desktop
Edit claude_desktop_config.json and use absolute paths:
{
"mcpServers": {
"demo-server": {
"command": "python",
"args": ["/absolute/path/to/server.py"]
}
}
}
Restart the app. The add tool now appears in the tools menu, and the model can call it when a user asks an arithmetic question.
Write a Minimal MCP Client
If you are building your own agent, connect programmatically:
import asyncio
from mcp import ClientSession, StdioServerParameters
from mcp.client.stdio import stdio_client
params = StdioServerParameters(command="python", args=["server.py"])
async def main():
async with stdio_client(params) as (read, write):
async with ClientSession(read, write) as session:
await session.initialize() # Handshake
tools = await session.list_tools() # Dynamic discovery
print([t.name for t in tools.tools])
result = await session.call_tool("add", {"a": 2, "b": 3})
print(result.content[0].text) # "5.0"
asyncio.run(main())
Pass the discovered tool schemas to your LLM’s function-calling interface, route the model’s tool requests to session.call_tool, and return the results. That loop is the core of every MCP-enabled agent.
Real-World Use Cases and Workflows
1. Developer Workflows
Connect an IDE agent to GitHub, Sentry, and Postgres servers. A prompt like “Find the top error from last night, locate the failing commit, and open a draft fix PR” then spans three systems with no custom glue code.
2. Enterprise Knowledge Access
Teams expose internal wikis, ticketing systems, and data warehouses as MCP servers behind OAuth. Employees query company data from any approved AI client, and security teams enforce permissions at the server layer instead of per application.
3. Hallucination Mitigation
Instead of letting a model guess at current figures, an MCP server returns live data from the system of record. Pair this with a prompt rule such as “Answer only from tool results; say ‘unknown’ otherwise.” Grounding answers in tool output cuts fabricated numbers, though it does not eliminate errors.
4. Prompt Template for MCP-Aware Agents
You have access to MCP tools. Follow this procedure:
1. List the tools relevant to the task before acting.
2. Call read-only tools first to gather facts.
3. Ask for confirmation before any tool that modifies data.
4. Cite which tool produced each fact in your answer.
Run agent loops at a low temperature (0–0.3) for reliable tool selection and valid JSON arguments.
Security: The Part You Cannot Skip
MCP gives models real capabilities, so the attack surface is real.
| Risk | What happens | Mitigation |
|---|---|---|
| Prompt injection via tool output | Malicious text in a fetched page or ticket hijacks the agent | Treat tool results as untrusted data; add human approval for sensitive actions |
| Tool poisoning | A malicious server hides instructions in tool descriptions | Install servers only from sources you trust; review tool metadata |
| Over-permissioned servers | A server with broad scopes leaks or destroys data | Apply least privilege; use read-only credentials where possible |
| Token theft / confused deputy | Misused OAuth tokens reach other services | Follow the spec’s OAuth 2.1 guidance; scope tokens narrowly |
Treat third-party MCP servers like third-party code, because that is what they are.
MCP Performance Considerations
Context cost is the practical bottleneck. Every tool definition consumes tokens, and a client connected to dozens of servers can burn thousands of tokens before the user types a word.
- Keep tool sets small. Expose only the tools an agent needs for the task.
- Write tight descriptions. Short, specific descriptions improve both token cost and selection accuracy.
- Return concise results. Paginate or summarize large payloads instead of dumping them into the context window.
- Consider code-execution patterns, where the agent writes code that calls tools, so intermediate data never passes through the model.
Getting Started Checklist
- Install the SDK (
pip install "mcp[cli]"or the TypeScript SDK). - Build one small server with one tool.
- Validate it in the MCP Inspector.
- Connect it to a host such as Claude Desktop.
- Add authentication and logging before any remote deployment.
- Check the official specification at modelcontextprotocol.io for the latest protocol revision, since the spec has been updated several times since launch.
Frequently Asked Questions
What does MCP stand for in AI?
MCP stands for Model Context Protocol. It is an open standard that lets AI applications connect to external tools, data sources, and prompt templates through one consistent interface.
Is MCP the same as an API?
No. An API is a service’s own interface, and every API is different. MCP is a standard wrapper layer that lets AI clients discover and call capabilities from many different APIs in the same way. An MCP server typically calls a regular API underneath.
Which AI models and apps support MCP?
MCP is model-agnostic. Support exists across Claude, ChatGPT, Gemini-based tooling, and many IDEs and agent frameworks. Because it is a protocol, compatibility depends on the host application, not on a specific model.
Is MCP free and open source?
Yes. The specification and official SDKs (Python, TypeScript, Java, C#, Kotlin, and others) are open source. Individual servers may rely on paid third-party services, but the protocol itself carries no licensing cost.




