TL;DR: MCP is an open protocol that standardizes how AI applications connect to external tools and data. A tool provider writes one MCP server; any MCP-compatible client - a chat app, an IDE, a coding agent - can then use it without custom integration code. It does for AI integrations what USB did for peripherals: one connector instead of a cable per device.
How it works
Before MCP, connecting a model to a database, a ticketing system, or a file store meant writing bespoke glue for every app-integration pair: N applications times M systems equals N times M integrations. MCP collapses that to N plus M. The integration is written once, as a server; every client application that speaks the protocol gets it for free. The design is deliberately boring: JSON-RPC messages over a local pipe (stdio) for programs on your machine, or Streamable HTTP for remote services, with an older HTTP-plus-SSE transport now deprecated. The protocol is also stateless as of its 2026-07-28 revision - there is no connection handshake and no session header, so each request stands alone and a remote server behaves like any ordinary HTTP workload behind a load balancer.
The architecture has three roles. The host is the AI application the user actually runs - a chat interface, an editor, an agent harness. Inside it, a client maintains a connection to one server. The server is a small program wrapping some capability: a database, a browser, a company's internal API. The client learns what the server offers at runtime rather than having it compiled in, and that discovery step is the protocol's core trick. Since the 2026-07-28 revision there is no opening negotiation: every request carries its own protocol version and client capabilities, and a client that wants the server's capabilities up front calls a server/discover method that every server must implement.
Servers expose three kinds of things. Tools are functions the model can invoke - "run this query", "create this ticket" - each described with a JSON Schema, exactly like ordinary function calling. Resources are readable data the host can pull into context: files, records, live documents. Prompts are reusable, server-provided templates for common operations. In practice tools carry most of the traffic; resources and prompts round out the cases where the application needs data or canned instructions rather than actions. In the other direction a client can offer elicitation - the server asking the user for a missing value or a confirmation partway through a call. Two older server-initiated features, roots and sampling, were deprecated in the 2026-07-28 revision, so new implementations should not adopt them.
A typical run flows like this: the host launches or connects to its configured servers, each client fetches the catalog, and the discovered tools are offered to the model alongside any built-in ones. When the model calls one, the client relays the request to the server, the server executes it, and the result travels back into the model's context. The standardization also concentrates the risk: a malicious or compromised server feeds text straight into the model, so hosts treat server output as untrusted input and gate dangerous tools behind user approval.
Where it sits in the AI stack
MCP is the connective layer between an AI application and everything outside it:
Adoption spread fastest through coding agents, where one server can hand an agent a browser, a database, or an issue tracker. Most agent frameworks now consume MCP servers as a native tool source. The protocol itself is no longer a single vendor's project: in December 2025 Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation co-founded with Block and OpenAI, where MCP is a founding project. It is now governed by maintainers drawn from several companies, with a published specification, a dated revision history, a public enhancement-proposal process, and a formal deprecation policy that guarantees a twelve-month window.
Key tools and implementations
-
Reference servers
A small set maintained by the MCP steering group - filesystem, Git, web fetching, memory - meant as examples rather than production tools.
-
Client applications
Chat apps, IDEs, and agent harnesses that can attach any MCP server as a tool source.
-
Protocol SDKs
Official libraries in major languages that handle the JSON-RPC plumbing for server authors.
-
The MCP Registry
The official registry publishes server metadata, still in preview, and vendor stores and marketplaces build on its API.
Related entries
- Tool use (function calling) Letting a language model request actions by emitting structured calls that your code executes and whose results feed back in.
- Agent frameworks Libraries and SDKs that handle the agent loop, tool wiring, and state so you build behavior instead of plumbing.
- AI agent A system where a language model plans, calls tools, and loops on results to finish a task with minimal supervision.
- AI coding agent Software that plans and executes multi-step coding tasks - reading files, editing code, and running tests with minimal supervision.