AI/Explainer

What Is MCP (Model Context Protocol) and Why It Matters

The open standard that lets Claude, ChatGPT, and other AI apps plug into your files, tools, and services — explained via its own hosts-clients-servers architecture and security tradeoffs.

Simple diagram showing an AI application connecting through the Model Context Protocol to external tools, resources, and data sources
The Model Context Protocol's official architecture diagram. Image: Model Context Protocol.

The Model Context Protocol (MCP) is an open standard, created by Anthropic and now stewarded by the Linux Foundation, that gives AI applications a single, consistent way to connect to external tools, files, and data sources — instead of requiring a custom-built integration for every pairing of AI model and system. Anthropic has described it as "a USB-C port for AI applications," and in the two years since its release it has been adopted by OpenAI, Google, Microsoft, and dozens of developer tools, making it one of the fastest-spreading technical standards in the AI industry.

The short version:

  • MCP is a JSON-RPC-based protocol that lets an AI "host" application (like Claude, ChatGPT, or an IDE) connect to "servers" that expose tools, data, and prompt templates.
  • Anthropic open-sourced it in November 2024 to solve what engineers called the "M×N problem" — every AI model needing a bespoke connector for every data source.
  • OpenAI, Google DeepMind, and Microsoft have since added MCP support across ChatGPT, Gemini, Copilot, and Visual Studio Code.
  • In December 2025, Anthropic donated MCP to the Linux Foundation's new Agentic AI Foundation to keep it vendor-neutral.
  • Connecting an AI model to an MCP server means granting it real access to your data and systems — which raises genuine security questions covered below.

What is the Model Context Protocol?

MCP is, in its own documentation's words, "an open-source standard for connecting AI applications to external systems." Using it, AI applications can connect to data sources such as local files and databases, to tools such as search engines and calculators, and to workflows such as specialized prompt templates — all through one shared protocol rather than a different integration for each pairing.

Before MCP, if a company wanted its chatbot to read from Slack, query a Postgres database, and search GitHub, its engineers typically had to write and maintain three separate, bespoke integrations — and every other AI vendor wanting the same three connections had to write their own three again. MCP's architecture page describes this as a protocol that standardizes "the ways developers can share context from MCP servers to MCP clients," so a tool built once as an MCP server can, in principle, work with any MCP-compatible AI application.

Why did Anthropic create it?

Anthropic's original November 2024 announcement framed the problem bluntly: even the most capable models, it said, remain "trapped behind information silos and legacy systems," and building a custom connector for "every new data source" makes "truly connected systems difficult to scale." MCP was Anthropic's answer — "a universal, open standard for connecting AI systems with data sources," released as an open-source specification with SDKs in Python and TypeScript, plus reference server implementations for Google Drive, Slack, GitHub, Git, Postgres, and Puppeteer.

Early partners named in that announcement included Block and Apollo, alongside developer-tool companies such as Zed, Replit, Codeium, and Sourcegraph, which began wiring MCP into their AI coding features almost immediately. That pattern — MCP showing up first inside coding assistants — is one reason it's now baked into tools like Cursor, GitHub Copilot, and Claude Code, which we've compared head-to-head elsewhere.

The architecture: hosts, clients, and servers

MCP follows a client-server architecture with three kinds of participants, as defined in the protocol's own architecture documentation:

  • MCP Host — the AI application itself, such as Claude Desktop, Claude Code, or an IDE like Visual Studio Code, which "coordinates and manages one or multiple MCP clients."
  • MCP Client — a component the host creates for each server it talks to; it "maintains a connection to an MCP server and obtains context from an MCP server for the MCP host to use."
  • MCP Server — "a program that provides context to MCP clients," whether it runs locally on the same machine (connecting over a standard-input/output "stdio" transport) or remotely over the network (using a Streamable HTTP transport).

In practice, a single host can run several clients at once — one connected to a local filesystem server, another to a remote database server, another to a company's internal API. Each connection is independent, and the host is responsible for combining whatever those servers expose into a single set of capabilities the underlying language model can draw on.

Tools, resources, and prompts: the three primitives

Underneath the host-client-server structure, MCP defines a small set of "primitives" — the actual things a server can offer a client. The protocol's documentation names three core primitives that servers expose to AI applications:

PrimitiveWhat it isWho decides when it's usedExample
ToolsExecutable functions the AI can invoke to take an actionThe AI model, during a conversationA function that queries a database or sends a Slack message
ResourcesData sources that provide context without taking actionThe host application or the userThe contents of a file, or a set of database records
PromptsReusable templates that structure an interactionThe user, typically via a menu in the host appA pre-written template with few-shot examples for a specific task

A single MCP server can expose all three. The architecture documentation's own example is a server that provides context about a database: it can offer tools for querying the database, a resource containing the database's schema, and a prompt with few-shot examples for writing queries against it. Underneath these primitives, MCP communicates using the JSON-RPC 2.0 message format, and newer protocol versions added a discovery step (a server/discover request) so a client can learn a server's capabilities and supported protocol version before using it.

Why MCP became a cross-industry standard

MCP's adoption outside Anthropic has been unusually fast and, notably, has included Anthropic's direct competitors. OpenAI began adding MCP support across its products in 2025, with CEO Sam Altman saying at the time that "people love MCP" and that support was rolling out through the Agents SDK, with the ChatGPT desktop app and Responses API following. OpenAI's own developer documentation now describes MCP as "an open protocol that's becoming the industry standard for extending AI models with additional tools and knowledge," and documents MCP support in ChatGPT and through its Responses API.

Google DeepMind CEO Demis Hassabis likewise confirmed that Gemini's models and SDK would add native MCP support, calling it "a good protocol" that was "rapidly becoming an open standard for the AI agentic era." Microsoft added MCP support to Windows, Copilot, and developer tools including Visual Studio Code.

That momentum culminated in December 2025, when Anthropic donated MCP itself to a new Linux Foundation project, the Agentic AI Foundation (AAIF), co-founded with Block and OpenAI and backed by Google, Microsoft, AWS, Cloudflare, and Bloomberg. In its own announcement of the donation, Anthropic said doing so would ensure MCP "stays open, neutral, and community-driven as it becomes critical infrastructure for AI," and cited more than 10,000 active public MCP servers and over 97 million combined monthly downloads of its Python and TypeScript SDKs roughly a year after launch. Anthropic also noted that Claude itself now offers more than 75 MCP-powered connectors. MCP's governance remains structured as a technical steering group of individual maintainers — not company seats — operating under Linux Foundation project policies, the same open-governance model used for projects like Kubernetes.

Practical examples of MCP servers

Because MCP servers are just programs that speak a shared protocol, the ecosystem that's grown around it is broad. Some concrete examples, drawn from the protocol's own reference implementations and widely used integrations:

  • Filesystem server — a local server that exposes a directory's files as resources an AI application can read, letting a coding assistant see a project's source files.
  • Database servers (Postgres and others) — expose schema information as a resource and querying as a tool, so a chatbot can answer questions against live data without a bespoke integration.
  • Developer-platform servers, such as the official Sentry MCP server, which runs remotely over Streamable HTTP and lets an AI application pull error reports and stack traces into a debugging session.
  • Productivity and collaboration servers for systems like Google Drive, Slack, and GitHub — among the first reference servers Anthropic published alongside MCP's initial release.
  • Browser-automation servers, such as Microsoft's Playwright-MCP, which exposes browser control as a set of tools an AI model can call to navigate and interact with web pages.

Many of these servers are now one click away inside AI applications' own plugin or connector directories — a pattern similar to how Claude's own marketplace surfaces add-ons, and one that underpins how modern AI agents reach beyond pure conversation and into real systems — MCP is frequently the plumbing an agent framework uses to actually call a tool once it decides an action is needed.

Security and trust: what changes when you connect a model to MCP servers

Granting an AI model a live connection to a tool or data source is a meaningful trust decision, and MCP's own specification maintainers have published a detailed security best-practices document addressing it directly. Several risks are specific to how MCP connections work:

  • Local server compromise. A locally running MCP server executes with the same privileges as the AI application itself. The protocol's security documentation warns that a malicious or compromised local server can run arbitrary commands — including data exfiltration or destructive file operations — and recommends that AI applications show users the exact command before running any locally configured server, and sandbox servers with least-privilege file and network access.
  • Token passthrough and the "confused deputy" problem. When an MCP server acts as a proxy to a third-party API, the specification explicitly forbids it from accepting or forwarding authentication tokens that weren't issued specifically for it, since doing so can let an attacker skip a user's consent step entirely and hijack access to a connected account.
  • Server-side request forgery (SSRF). Because MCP clients follow URLs supplied by servers during authorization flows, the documentation warns a malicious server could point a client at internal network addresses or cloud metadata endpoints to try to steal credentials, and recommends clients block private IP ranges and enforce HTTPS.
  • Overly broad permissions. The security guidance also flags "scope inflation" — servers requesting or being granted far more access than a given action needs — and recommends a progressive, least-privilege model where an AI application starts with minimal access and only requests more when a specific task actually requires it.

None of this makes MCP uniquely dangerous — it's the same category of risk that applies to installing any browser extension or granting any app OAuth access to an account — but it does mean the practical security burden sits with whoever chooses which MCP servers to connect, and with the AI application vendor's own consent and sandboxing design, not with the protocol's existence alone.

What's next for MCP

With MCP now housed inside the Linux Foundation's Agentic AI Foundation alongside OpenAI's AGENTS.md and Block's goose project, its future development is explicitly structured to be vendor-neutral rather than Anthropic-led, governed by a steering group of individual maintainers rather than company representatives. Expect continued work on authorization and consent flows (an area the security documentation itself flags as still evolving), on the registry of public MCP servers, and on narrowing the gap between MCP's original "local tool" use case and its fast-growing remote, multi-tenant deployments inside enterprise software. For a site that covers how AI products actually get built, MCP is likely to keep coming up — not as a single product, but as the plumbing increasingly sitting underneath them.

Frequently asked questions

What does MCP stand for?

MCP stands for Model Context Protocol. It's an open standard, originally released by Anthropic, that defines how an AI application connects to external tools, data sources, and prompt templates through a shared client-server protocol.

Who created MCP and when?

Anthropic created and open-sourced MCP, announcing it on November 25, 2024, along with Python and TypeScript SDKs and reference servers for systems like Google Drive, Slack, GitHub, and Postgres.

Is MCP only for Claude?

No. While Anthropic built it for Claude, MCP is an open protocol. OpenAI has added MCP support across ChatGPT and its Responses API, Google DeepMind has added it to Gemini, and Microsoft has built it into Copilot, Windows, and Visual Studio Code.

What's the difference between an MCP tool and an MCP resource?

A tool is an executable function the AI model can actively invoke to take an action, like querying a database. A resource is contextual data the server makes available, like a file's contents or a database schema, without the model needing to execute anything.

Who governs MCP now?

In December 2025, Anthropic donated MCP to the Agentic AI Foundation, a Linux Foundation project co-founded with Block and OpenAI and backed by Google, Microsoft, AWS, Cloudflare, and Bloomberg. Technical decisions are made by a steering group of individual maintainers rather than company representatives.

Is it safe to connect an AI model to an MCP server?

It depends on the server. MCP's own security documentation warns that a local server runs with the same privileges as the AI application itself, so a malicious or poorly secured server can access files or run commands. The protocol's maintainers recommend sandboxing servers, reviewing exactly what a server will run before connecting it, and granting the minimum access a task actually needs.

Sources

More on Model Context Protocol →MCPModel Context ProtocolAnthropicAI agentsAI toolsopen standards
Theo Park
Written byTheo Park

Theo Park runs the AI desk at Pandromeda. He follows model launches from the frontier labs and the open-weight community, tracks the assistants and developer tools built on them, and explains what each release changes on pricing, capability and safety. His reporting leans on primary sources: model cards, technical reports, API documentation and the companies' own announcements.

More from AI

See all