13k.euES
Menu

Explainer · AI Agents & Automation

What is MCP (Model Context Protocol)?

By 13k.eu editorsUpdated and checked 4 min read

Short answer

MCP is an open standard for connecting AI applications to outside tools and data. An app (the host) opens one client connection per MCP server; each server offers tools (actions), resources (data) and prompts (templates) over JSON-RPC, locally via stdio or remotely via Streamable HTTP. The specification requires explicit user consent before data is shared or tools run, but says the protocol itself cannot enforce that.

An industrial robotic arm placing small metal cubes connected by glowing orange cables

Prices, limits and features change often. We date every figure and link to its source: check the vendor's page before you buy or build. How we make money.

The Model Context Protocol (MCP) is an open standard that lets AI applications connect to outside tools and data in the same way, whoever built them. Its own documentation compares it to "a USB-C port for AI applications": instead of every assistant needing a custom integration for every service, a service publishes one MCP server and any MCP-compatible app can use it. This explainer follows the official specification, version 2026-07-28, checked on October 1, 2026.

The problem it solves

Without a shared protocol, connecting five AI apps to five services means building up to 25 separate integrations. With MCP, each service builds one server and each app builds one client, and they all speak the same language. The protocol's documentation lists support in assistants such as Claude and ChatGPT and in developer tools such as Visual Studio Code and Cursor.

Some examples from the official introduction:

  • an assistant that reads your Google Calendar and Notion to act as a more personal assistant;
  • Claude Code building a web app from a Figma design;
  • a company chatbot that queries several internal databases.

How it works: hosts, clients and servers

MCP has three roles:

Role What it is Example
Host The AI application the user works in Claude Desktop, Claude Code, Visual Studio Code
Client A connector inside the host; the host creates one per server The connection VS Code opens to a Sentry server
Server A program that offers context and actions to clients A filesystem server, a database server, Sentry's server

A server can run on your own machine or on the internet. Local servers usually talk over standard input and output (the "stdio" transport) and serve one client. Remote servers use "Streamable HTTP" and can serve many clients; the specification recommends OAuth to obtain the access tokens they need. All messages, local or remote, use the JSON-RPC 2.0 format.

What a server can offer: tools, resources and prompts

The specification defines three core building blocks ("primitives") that servers expose:

  • Tools: actions the AI can carry out, such as querying a database, calling an API or editing a file.
  • Resources: data the AI can read for context, such as a file's contents or a database schema.
  • Prompts: reusable templates, such as a system prompt or worked examples for using the server's tools.

Clients discover what a server offers by asking for its lists (tools/list, for example) and then call what they need (tools/call). Because the lists are fetched at run time, a server can add or remove tools without the app changing.

Servers can also ask the user for information through the client, which the specification calls elicitation: for example, to confirm an action before it runs. An older feature, sampling, which let servers request model completions through the client, is deprecated as of protocol version 2026-07-28.

MCP and AI agents

MCP is one of the ways an AI agent gets its tools. The agent's model decides which tool to use next; MCP is the standard plug through which those tools are found and called. Many tools that do not speak MCP natively can be wrapped in a small MCP server.

Security: what the specification asks for

MCP connects models to data and to actions with real effects, so the specification sets out principles that implementers must address:

  • User consent and control: users must understand and agree to what data is accessed and what actions are taken, through clear interfaces for reviewing and authorizing activity.
  • Data privacy: hosts must get explicit consent before exposing user data to servers, and must not send resource data elsewhere without consent.
  • Tool safety: tools "represent arbitrary code execution and must be treated with appropriate caution". Descriptions of what a tool does should be treated as untrusted unless they come from a trusted server, and hosts must get explicit consent before invoking any tool.

The specification is also clear about its limits: MCP "cannot enforce these security principles at the protocol level". Whether an app asks for your consent properly depends on the app. In practice, install servers only from sources you trust, review what each tool can do, and be careful with any server that can both read private data and send data out. Injected instructions hidden in documents or web pages ("prompt injection") are the top risk in OWASP's 2025 list for LLM applications, and connecting more tools gives an injected instruction more to work with.

How to start using MCP

  • As a user: many assistants and coding tools let you add MCP servers ("connectors") from their settings. Read what a server can do before you enable it.
  • As a developer: the official site has SDKs, a reference list of servers and the MCP Inspector, a tool for testing servers during development.

If you run models on your own computer, LM Studio can also act as an MCP client for local models; see Ollama vs LM Studio.

What we checked

  • MCP is an open-source standard for connecting AI applications to external systems, compared to a USB-C port, supported by Claude, ChatGPT, Visual Studio Code and Cursor. (Model Context Protocol, )
  • Hosts create one MCP client per server; local servers use stdio, remote servers use Streamable HTTP with OAuth recommended; messages use JSON-RPC 2.0; servers expose tools, resources and prompts; clients can expose elicitation; sampling is deprecated as of 2026-07-28. (Model Context Protocol, )
  • The specification (2026-07-28) requires user consent and control, data privacy and tool safety, and says MCP cannot enforce these principles at the protocol level. (Model Context Protocol, )
  • Prompt injection is the first risk (LLM01) in OWASP's 2025 Top 10 for LLM applications. (OWASP GenAI Security Project, )
  • LM Studio can act as an MCP client for local models. (LM Studio, )

What may change

  • The protocol is versioned by date; features can be added or deprecated in new versions.
  • The list of apps that support MCP grows quickly.

Frequently asked questions

What is an MCP server?

A program that offers tools, data (resources) or prompt templates to AI applications through the Model Context Protocol. It can run on your computer (stdio transport) or remotely (Streamable HTTP).

Who supports MCP?

The official documentation lists AI assistants such as Claude and ChatGPT and developer tools such as Visual Studio Code and Cursor, among many others.

Is MCP safe?

It depends on the app and the servers. The specification requires explicit user consent before tools run or data is shared, but notes that the protocol cannot enforce this. Install servers only from trusted sources and check what each tool can do.

What is the difference between MCP and an API?

An API is one service's own interface. MCP is a common protocol on top: a service wraps its capabilities in an MCP server once, and any MCP-compatible AI app can discover and use them without a custom integration.

Sources

  1. What is the Model Context Protocol (MCP)?, Model Context Protocol. Accessed October 1, 2026.
  2. MCP architecture overview: hosts, clients, servers, primitives and transports, Model Context Protocol. Accessed October 1, 2026.
  3. Model Context Protocol specification (version 2026-07-28), including Security and Trust & Safety, Model Context Protocol. Accessed October 1, 2026.
  4. OWASP Top 10 for LLM Applications 2025, OWASP GenAI Security Project. Accessed October 1, 2026.
  5. LM Studio documentation, LM Studio. Accessed October 1, 2026.

Spotted an error or an outdated price? Tell us and we will fix it.

Change history

  • : First published, following specification version 2026-07-28.

Next review: .

Part of our AI Agents & Automation guide.