Model Context Protocol (MCP): connecting AI to tools and data

Every AI application that needs to reach a database, a helpdesk or a file store has traditionally needed its own integration for each of them. With several applications and several systems, the number of connectors multiplies quickly. The Model Context Protocol, MCP, replaces that with a single open protocol: one server has to be built per system, and every MCP-capable application can then use it.

Anthropic introduced MCP as an open standard in November 2024. In December 2025 it donated the protocol to the Agentic AI Foundation, a directed fund under the Linux Foundation; decisions about the protocol remain with its maintainers.

Hosts, clients and servers

An MCP host is the AI application, for example a coding tool or a chat application. For every MCP server it connects to, the host creates one MCP client, which maintains a dedicated connection to that server. The server is the program that provides the context.

Servers can run locally and communicate through standard input and output, typically serving a single client, or remotely over Streamable HTTP, typically serving many. For remote servers, MCP recommends using OAuth to obtain authentication tokens. Messages follow JSON-RPC 2.0.

What a server can offer

  • Tools are functions the application can call in order to act.
  • Resources are data that provide context.
  • Prompts are reusable templates for working with the model.

A sales assistant might use a CRM server whose tool looks up a customer, whose resource is the account history and whose prompt structures a call summary. Servers can also ask users for input through elicitation, for instance to confirm an update. Protocol version 2026-07-28 deprecated some older client features, including sampling, which let servers request completions from the host application’s language model.

Before you install a server

  • Who publishes it? Prefer servers from the vendor of the system itself or from maintainers you can identify, and check that the project is maintained.
  • What does it expose? The list of tools shows what the server can do. A server with write or delete tools should run with the smallest permissions that still work, and calls to those tools should need approval.
  • What does it return? Content from web pages or emails can carry injected instructions. The specification itself says descriptions of tool behaviour should be treated as untrusted unless they come from a trusted server; red teaming checks whether your setup falls for them, and the Prompt Injection Scanner shows what such instructions look like in web pages.

Where it is used

Coding agents such as Claude Code connect to MCP servers directly; our Claude Code cheat sheet lists the relevant commands. In organisations, a typical first candidate is the CRM a sales team already uses, or a contract repository, that several assistants should be able to query. Connecting your own systems to AI applications is the kind of work we take on as custom tooling, and agentic systems are where such connections matter most.

Related terms

TermWhat it means
APIThe interface of one service; MCP servers often sit on top of one.
JSON-RPC 2.0The message format MCP uses for requests, responses and notifications.

Sources

This page expands an entry from the minoka AI glossary, which covers many more terms in brief.

Frequently Asked Questions

Frequently Asked Questions

What problem does MCP solve?

Without a shared protocol, every pairing of AI application and system needs its own connector. With MCP, each system needs one server and each application needs to support the protocol once.

Who maintains the Model Context Protocol?

Anthropic introduced MCP in November 2024 and donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025. Decisions about the protocol remain with its maintainers.

What is the difference between MCP and an API?

An API is the interface of one particular service. MCP is a common protocol through which AI applications can discover and use tools, data and prompts from many services, each of which may wrap its own API.

What should I check before installing an MCP server?

Who publishes and maintains it, which tools it exposes and what they can change, and whether the content it returns could contain injected instructions. Grant narrow permissions and require approval for consequential actions.

Preferred source

Prefer minoka.de on Google

If you add minoka.de as a preferred source, Google shows articles from this site more often in Top Stories, AI Overviews and AI Mode. One click, a Google account, revocable at any time in your source settings.

Prefer on GoogleOpens the source settings at Google