Skip to content

What is the Model Context Protocol (MCP)?

The Model Context Protocol (MCP) is an open protocol that connects AI applications to other systems. An AI application such as Claude or Codex uses it to read data and to call functions in other programs. Anthropic introduced the protocol and published it as an open standard. The specification and the documentation are public at modelcontextprotocol.io.

How MCP works

MCP has three roles. The host is the AI application a person works with. For each server, the host starts a client that holds the connection. The server is a program that puts one system in reach of the model, such as a database or an issue tracker.

Client and server exchange JSON-RPC messages. When a connection opens, the server lists what it has. The model reads the list and picks the entry that fits the task. The host sends the call, and the server returns the result.

What is an MCP server?

An MCP server is a program that gives a model access to one system through the protocol. It can provide three kinds of entries. Tools are functions the model calls, such as a database query. Resources are data the application loads as context, such as a file. Prompts are prepared instructions for a recurring task.

A server runs in one of two ways. A local server runs as a process on the same machine and talks over standard input and output (stdio). A remote server has a web address and talks over HTTP. For remote servers the specification describes authorization with OAuth.

MCP server vs. API

APIMCP server
Written forA program whose developer has read the documentationA model that reads the description while it works
DescriptionDocumentation for peopleA list of tools that the client requests from the server
Who decides on a callThe code of the programThe model, within what the host allows

An MCP server does not replace an API. Many servers are a thin layer over an API that exists already. The layer adds the descriptions a model needs to choose a call.

Which rights an MCP server gets

An MCP server acts with the rights of the account it runs under. A model that calls a tool can do what that account can do. The description of a tool is text that the model reads, so a server from an unknown source can steer the model. A company therefore installs servers whose source it knows. It gives a server an account with narrow rights, and it lets a person confirm a call that changes data.

My work with MCP servers

I am an IT expert for data platforms. Today AI agents speed up how I build and transform data platforms. In a client project, Claude and Codex work in one repository under rules that a machine checks.

MCP servers are part of the agent harness, the code and rules around a model. Agent harness engineering is the work of fitting that harness to one codebase and one team. In my client work, AI agents work under the same rules as humans. An agent gets the rights of a new colleague on the first day: a database role that only reads, and tokens scoped to the development environment. The database enforces these limits, so they hold for a call that arrives through an MCP server.

Paperclip is an open-source control plane for AI agents. Its MCP server speaks stdio only. I put an OAuth gateway, built with FastMCP, in front of it. Since then Claude on my phone reads and writes the issues of a client platform.

In my teaching at Claude Hacker House, a workshop series on practical work with Claude, I focus on building MCP servers and on virtual organizations. What I teach comes from daily work with Claude. I take on this work as a freelancer or as a permanent employee.

Searches this page answers

  • what is the model context protocol (mcp)
  • what is mcp in ai
  • what is an mcp server
  • mcp vs api
  • mcp tools vs resources
  • mcp stdio vs http
  • mcp authentication oauth
  • mcp security
  • mcp security best practices
  • mcp server security risks
  • how does mcp work