MCPBuilding with AI

Model Context Protocol

4 min readintermediateUpdated 28 Sept 2026
1 · In one line

MCP standardizes how AI applications connect to external context and tools.

1 · What it is

MCP is a universal, open standard for connecting AI applications to external systems. The announcement is dated Nov 25, 2024. That post calls it a standard for connecting assistants to content repositories, business tools and development environments. The announcement describes it as one protocol in place of fragmented integrations.

The host is the LLM application that initiates the connection. The client is the connector inside that host. The server is the service that provides context and capabilities. They communicate with JSON-RPC 2.0 messages. The current specification describes the base protocol as stateless, self-contained requests. Capability negotiation happens on each request.

Resources are context and data for the user or the model. Prompts are templated messages and workflows for users. Tools are functions for the model to execute. The specification says tools represent arbitrary code execution and must be treated with caution. Hosts must obtain explicit user consent before invoking any tool. Hosts must also obtain explicit consent before exposing user data to servers. The protocol cannot enforce these security principles by itself.

A server can also ask the user for more information. The spec calls that elicitation. Users must consent to and understand the data access and the operations. The design takes some inspiration from the Language Server Protocol, which gave many editors one way to add a programming language.

The donation announcement is dated 9 December 2025. That post says Anthropic is donating the Model Context Protocol to the Linux Foundation. The foundation is a directed fund under the Linux Foundation, co-founded by Anthropic. Anthropic, Block and OpenAI co-founded that foundation. The Linux Foundation page announces the formation of the Agentic AI Foundation. That announcement is dated 9 December 2025. It named founding contributions from Anthropic, Block and OpenAI. MCP is named there with goose and AGENTS.md. The foundation’s stated aim is a neutral, open home so agentic AI can evolve in the open. Anthropic said the governance model will remain unchanged, with maintainers still prioritizing community input.

A protected MCP server can act as an OAuth 2.1 resource server. The client then makes protected requests on behalf of a resource owner. A stdio implementation is told to retrieve credentials from the environment instead of the HTTP authorization flow. The security document includes a section called Confused Deputy Problem. In that attack, a client can obtain authorization codes without proper user consent.

2 · Why it exists

Capable models are still cut off from the systems where the relevant data lives.

Data stays elsewhereEven strong models are limited by isolation from data kept in other systems.
Custom connectorsEvery new data source has required its own implementation, which is difficult to scale.
Tools run codeTools represent arbitrary code execution and must be treated with caution.
3 · How it works

Follow one request from the host to the server and back.

The client and the server exchange JSON-RPC 2.0 messages.
  1. 1 · exposeA server can offer resources, prompts and tools.
  2. 2 · connectA client inside the host exchanges JSON-RPC 2.0 messages with that server.
  3. 3 · approveThe host must get explicit user consent before it invokes a tool.
  4. 4 · returnThe server provides context and capabilities.

Hosts must obtain explicit user consent before invoking a tool. MCP cannot enforce its security principles at the protocol level.

A stdio implementation is told to retrieve credentials from the environment instead of the HTTP authorization flow.
4 · Where it's used
WhoWhat they askWhat it works with
IDE“What does this function call in the repo?”A code server's resources
Support app“What plan is this customer on?”A database server's tools
Desktop assistant“Summarise the notes in this folder.”A files server's resources
Team chat“What did we decide in the incident channel?”A chat server's resources
5 · What it solves, and what it doesn't
solves
  • One protocol can replace a separate custom connector for each data source.
  • Servers can offer resources, prompts and tools to clients.
  • MCP takes inspiration from the Language Server Protocol, which standardized language support across development tools.
  • The 2024 launch shared pre-built servers for Google Drive, Slack, GitHub, Git, Postgres and Puppeteer.
doesn't solve
  • MCP cannot enforce its security principles at the protocol level.
  • Tool descriptions count as untrusted unless they come from a trusted server.
  • Tools represent arbitrary code execution and require caution.
  • The host must not transmit resource data elsewhere without the user's consent.
6 · Go deeper

Sources used

This explainer is written in original language. The links below support its factual claims.

  1. officialSpecification, Model Context Protocol · read 28 Sept 2026
  2. officialIntroducing the Model Context Protocol, Anthropic · read 28 Sept 2026
  3. officialDonating the Model Context Protocol and establishing the Agentic AI Foundation, Anthropic · read 28 Sept 2026
  4. officialLinux Foundation Announces the Formation of the Agentic AI Foundation, Linux Foundation · read 28 Sept 2026
  5. officialSecurity Best Practices, Model Context Protocol · read 28 Sept 2026
  6. officialAuthorization, Model Context Protocol · read 28 Sept 2026