Explainer
What Is MCP? The Model Context Protocol Explained
The open standard that lets any AI agent plug into tools and data — why it exists, how the pieces fit, and what it means for buyers.
MCP (Model Context Protocol) is an open standard that lets AI applications connect to external tools and data through one shared protocol. Instead of every AI app building its own custom integration for every database, API, and file system, MCP defines a single contract: build the capability once as an MCP server, and any MCP-compatible client — Claude Code, Cursor, and a growing list of others — can discover and use it.
The analogy the industry reaches for is USB-C: one plug shape that ends the era of proprietary chargers. Before MCP, connecting an assistant to your issue tracker, your database, and your docs meant three bespoke integrations, rebuilt for every new assistant. MCP collapses that N-by-M mess into one interface both sides implement.
MCP was introduced and open-sourced by Anthropic in November 2024, and in December 2025 it was donated to the Agentic AI Foundation under the Linux Foundation — making it vendor-neutral and co-governed alongside A2A, the agent-to-agent protocol. As of 2026 it is the de facto standard for AI tool connectivity, with broad support across model labs, cloud providers, and developer tools.
How MCP works: host, client, server
MCP defines three roles that communicate using JSON-RPC messages:
- Host — the AI application you actually use. It runs the model and owns the conversation.
- Client — the connector living inside the host. The host spins up one client per connected server; the client handles discovery and calls.
- Server — the capability provider. It exposes tools the model can call, resources it can read, and reusable prompt templates.
In practice: you connect your AI app to an MCP server for, say, your project tracker. The client asks the server "what can you do?", the server lists its tools ("search issues," "create ticket"), and from then on the model can call those tools as part of its work — no custom plugin code on either side.
What MCP servers expose
Tools
Functions the model can invoke: run a database query, create a calendar event, search a knowledge base. Tools are where the agent's ability to act comes from — the "hands" in our AI agent explainer.
Resources
Read-only data the model can pull in for context: file contents, database schemas, documentation. Resources give the agent something accurate to reason about instead of guessing.
Prompts
Reusable, pre-built prompt templates — standardized ways to invoke common workflows ("review this pull request," "summarize this thread") so users and teams get consistent behavior.
MCP vs. APIs vs. A2A
- MCP vs. plain APIs: an API is a fixed contract between two specific systems; MCP is a discovery protocol that lets any compatible agent find and use capabilities dynamically, without per-pairing integration work.
- MCP vs. A2A: MCP connects an agent downward to its tools and data (vertical); A2A connects agents sideways to each other for delegating whole tasks (horizontal). They solve different problems and are designed to be used together — an agent might use MCP to reach its tools and A2A to hand a subtask to another agent.
What MCP means for buyers
- Portability: capabilities you build or buy as MCP servers aren't locked to one AI app — they work across the ecosystem.
- Faster evaluation: when choosing an agent, MCP support signals how easily it will reach your stack.
- Ecosystem depth matters: the value of MCP grows with the servers available for your tools — check coverage for your specific systems.
- Security is on you: MCP is a transport contract, not a security boundary. Vet servers like vendors, scope permissions tightly, authenticate connections, and treat server outputs as untrusted data — the same agent safety practices apply.
Frequently asked questions
What is MCP (Model Context Protocol)?
An open standard, originally created by Anthropic and now governed by the Agentic AI Foundation under the Linux Foundation, that lets AI applications connect to external tools and data sources through one shared protocol — build a capability once, use it from any MCP-compatible client.
How does MCP work?
Three roles: a host (the AI app you use), a client (the connector inside the host), and servers exposing tools, resources, and prompts. The client discovers a server's capabilities and calls them via JSON-RPC — no custom integration code per pairing.
What is the difference between MCP and A2A?
MCP connects an agent to its tools and data (vertical integration). A2A connects agents to each other for task delegation (horizontal communication). They're complementary — see our A2A explainer — and both now sit under the Agentic AI Foundation.
Is MCP secure?
MCP itself is a transport contract, not a security system. Security comes from deployment: vetting servers, scoping permissions to least privilege, authenticating connections, and treating server outputs as untrusted data.