What Is MCP (Model Context Protocol)?

Related problems: Building a separate custom integration for every AI tool and every system; AI assistants that can't see the data they need to be useful; Vendors asking for broad access so their AI can connect to our apps; Not knowing which AI connectors staff have installed

The Model Context Protocol (MCP) is an open protocol that defines a standard way for AI applications, such as assistants, coding tools and AI agents, to connect to external tools, data sources and services. Instead of building a separate custom integration between every AI application and every system, a system can be exposed once through an MCP server and used by AI applications that support the protocol. Anthropic created and open-sourced it, then donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation; it is implemented by many vendors and open-source projects.

At a glance

  • MCP is a protocol, not a product: a published specification for how AI applications and tools talk to each other.
  • An MCP server exposes a system’s data and actions; an MCP client inside an AI application connects to it.
  • It reduces custom integration work and makes it easier to connect AI tools to business systems.
  • Each MCP connection grants an AI application access, so permissions, trust and monitoring matter.
  • Support and features vary by AI application and by server.

What problem it solves

AI models are far more useful when they can see current, relevant information and take actions: look up a customer record, read a file, search a knowledge base, open a ticket. Without a standard, each AI application needs its own integration with each system, which multiplies effort and leaves many systems unconnected.

MCP offers a common way to make those connections. A software vendor or internal team can build one MCP server for a system, and AI applications that support MCP can use it. For buyers, this can mean faster, cheaper integration between AI tools and business applications, and less dependence on a single AI vendor’s proprietary connector catalog. It is one of the building blocks behind agentic AI, where software needs to act across several systems.

How it works

Hosts and clients. The AI application, such as a desktop assistant, coding tool or agent platform, is the host. It contains an MCP client that manages connections to servers.

Servers. An MCP server wraps a system and describes what it offers. The specification defines categories such as:

  • Tools: actions the AI can request, such as “create ticket” or “search orders”.
  • Resources: data the AI can read, such as files or records.
  • Prompts: reusable templates for common tasks.

Connections. Servers can run locally on a user’s computer or remotely as a network service. Remote servers can use standard authorization so users sign in and grant scoped access.

In use. When a user asks the AI something, the model, typically a large language model (LLM), sees which tools are available, decides which to call and with what inputs, and the client passes the request to the server. Results come back into the conversation. Many hosts ask the user to approve tool calls, depending on configuration.

Security considerations. Each server the AI connects to is a potential path to your data and systems. Main risks include servers with broader permissions than needed, servers from untrusted sources, and prompt injection, where content returned by a server contains instructions that try to redirect the AI.

When it matters for buyers

  • When rolling out AI assistants or agents. MCP support affects which of your systems they can connect to and how much custom work is needed.
  • When evaluating SaaS vendors. Ask whether they offer an MCP server, what it exposes and how access is controlled.
  • When staff install AI connectors themselves. Locally installed MCP servers can be a form of shadow AI; include them in inventories and policy.
  • When setting AI governance. Decide who may approve new connections, what permissions are acceptable and how activity is logged.
  • When avoiding lock-in. A common protocol can make it easier to switch AI applications without rebuilding every integration. Our artificial intelligence overview covers broader evaluation.

Questions to ask vendors

  • Do you offer an MCP server, and which data and actions does it expose?
  • How is authentication handled, and can access be limited to specific users, data and actions?
  • Does the AI act with the user’s own permissions or a broader service account?
  • Are tool calls logged, and can we export those logs to our security tools?
  • How do you protect against prompt injection through content your server returns?
  • Who maintains the server, how are updates and vulnerabilities handled, and is it supported under our contract?

How it differs from an API

An application programming interface (API) is the general way one piece of software exposes functions to another, and most business systems already have one. MCP is a layer designed specifically for AI applications: it standardizes how a system’s capabilities are described to a model and how the model requests them. An MCP server often calls the system’s existing API behind the scenes. In other words, MCP doesn’t replace APIs; it gives AI applications one consistent way to discover and use them.

Frequently Asked Questions

Is MCP a product?
No. MCP is an open protocol, a published specification that anyone can implement. Many AI applications, development tools and software vendors offer MCP support, but MCP itself is not something you buy.
Who created MCP?
Anthropic created MCP and released it as an open specification. In December 2025 Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, and it continues to be developed in the open with contributions from many companies and individuals.
Is MCP secure?
MCP defines how AI applications and tools communicate, including options for authorization on remote connections, but security depends on how each server and client is built and configured. Risks include over-broad permissions, untrusted or malicious servers, and prompt injection through content a server returns. Review MCP servers like any other integration that touches your data.
Do we need MCP to use AI?
No. Many AI tools work without it, and some integrations use other methods such as direct APIs or vendor-specific plugins. MCP matters when you want AI applications to connect to many tools or data sources in a consistent way.
What is an MCP server?
An MCP server is a small program or service that exposes a system, such as a file store, database, ticketing tool or SaaS app, to AI applications using the protocol. It decides what the AI can read and which actions it can request.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.