ANTM
AgentsExplainer

What Is Model Context Protocol (MCP)? A Practical Guide

MCP is an open standard for connecting AI applications to tools and data. Here is what it defines, what it leaves to you, and where it can go wrong.

Editorial desk

Published 3 min read

A ring-shaped hub at the centre linked by thin teal lines to rounded square and rectangular nodes, with small coral dots, on a dark navy background
Illustration generated with AI (FLUX.1 [schnell] (Black Forest Labs) via Cloudflare Workers AI, Apache 2.0). Prompt and direction by ANTM.

The Model Context Protocol (MCP) is an open standard for connecting AI applications to the tools and data they need. Anthropic introduced it on 25 November 2024, describing it as "an open standard that enables developers to build secure, two-way connections between their data sources and AI-powered tools."[1] The problem it targets is easy to state: "Even the most sophisticated models are constrained by their isolation from data—trapped behind information silos and legacy systems."[1]

Before a protocol like this, each application wrote its own connector for each data source. MCP aims to replace that matrix of custom integrations with one interface that any compliant application and any compliant server can share.

What Anthropic released at launch

The original announcement had three parts: the specification and SDKs, support for local MCP servers in the Claude Desktop app, and an open-source repository of ready-made servers. The sample servers covered Google Drive, Slack, GitHub, Git, Postgres and Puppeteer.[1]

How MCP is structured

MCP uses a client-server design. An AI application connects to MCP servers through MCP clients. A server exposes capabilities, and the client discovers and calls them. Messages are encoded with JSON-RPC and must be UTF-8.[2]

The three server primitives

The specification describes three building blocks a server can offer, and it assigns control of each to a different party.[3]

PrimitiveWhat it isWho controls itExample
PromptsPre-defined templates that guide model interactionsThe userSlash commands, menu options
ResourcesStructured data that gives the model additional contextThe applicationFile contents, git history
ToolsExecutable functions that let a model take actions or fetch informationThe modelAPI calls, writing a file

The control column matters for safety. A tool is "model-controlled," so the model decides when to call it. That is the primitive where a mistaken or manipulated model can cause real effects.

The two standard transports

The specification defines two standard ways for a client and server to talk.[2]

  1. stdio. The client launches the server as a subprocess and exchanges newline-delimited JSON-RPC messages over standard input and output. The specification says clients "SHOULD support stdio whenever possible."
  2. Streamable HTTP. The server runs as an independent process behind a single HTTP endpoint that handles POST and GET, and can use Server-Sent Events to stream messages. It replaced the older HTTP+SSE transport from the 2024-11-05 protocol version.

The specification also contains a security warning for Streamable HTTP. Servers "MUST validate the Origin header on all incoming connections to prevent DNS rebinding attacks," and local servers "SHOULD bind only to localhost (127.0.0.1) rather than all network interfaces (0.0.0.0)."[2]

Who governs it now

On 9 December 2025, Anthropic announced it was donating MCP to the Agentic AI Foundation (AAIF), which it described as "a directed fund under the Linux Foundation." Anthropic, Block and OpenAI co-founded the foundation, with support from Google, Microsoft, AWS, Cloudflare and Bloomberg. In that announcement Anthropic reported "more than 10,000 active public MCP servers" and "97M+ monthly SDK downloads across Python and TypeScript," and listed ChatGPT, Cursor, Gemini, Microsoft Copilot and Visual Studio Code among the products that had adopted MCP.[4] Those are Anthropic's figures as of that date, not independently audited ones.

When MCP is the right tool

Our view, based on the published design:

  • Use it when several applications need the same set of tools, when you want third-party tools to plug into your application without custom code, or when you want users to bring their own servers.
  • Skip it when one application needs a handful of functions. Calling your own code directly is simpler, easier to test and has fewer moving parts. Our guide to how AI agents work and how to secure them explains why starting simple is usually the better default.

Security: a standard protocol is not a safe tool

MCP standardises the connection. It does not vouch for what is on the other end. Three habits follow from that:

  1. Treat tool descriptions and tool results as untrusted input. Text that a server returns can contain instructions aimed at the model. This is the indirect prompt injection problem described in the OWASP list of LLM risks.
  2. Give each server the least privilege it needs. A read-only file server should not also be able to delete files.
  3. Require human approval for irreversible actions. Payments, deletions and messages sent on your behalf should not happen on the model's say-so alone.

Frequently asked questions

Is MCP only for Claude?
No. Anthropic introduced it, but in December 2025 it reported adoption by ChatGPT, Cursor, Gemini, Microsoft Copilot and Visual Studio Code, and donated the protocol to a Linux Foundation fund. [4]
How is MCP different from function calling?
Function calling lets a model ask your application to run functions that your application defined. MCP standardises how an application discovers and calls tools, resources and prompts hosted by separate servers, so the same server can work with many applications.
Do I need MCP to build an agent?
No. For a single application with a few functions, calling your own code directly is simpler. MCP pays off when many applications or many third-party tools need to connect.

The ANTM newsletter

The signal, not the noise.

Sourced AI coverage in your inbox. Double opt-in, unsubscribe in one click.

Referenced sources

  1. 1.
    Introducing the Model Context Protocol(opens in a new tab)

    AnthropicCompanyPublished Nov 25, 2024Accessed Oct 3, 2026

  2. 2.
    Model Context Protocol specification (2025-06-18): Transports(opens in a new tab)

    Model Context ProtocolPrimary sourceAccessed Oct 3, 2026

  3. 3.
  4. 4.

ANTM Editorial

Editorial desk

The editorial desk at AI's Next Top Model. Every article is sourced to primary documents and approved by an editor before publication. See the editorial policy for how we work.

Concentric teal orbital rings with a dashed coral line running from a small circle to a central ellipse, marked with coral ticks
Agents

How AI Agents Work, and How to Secure Them

An agent is a model that directs its own tool use. That flexibility is useful and risky. Here is how agents differ from workflows, when to use one, and the controls that matter.

Explainer4 min read