The Model Context Protocol (MCP) is an open standard for connecting AI applications to the tools and data they need. Anthropic introduced it on 25 November 2024, describing it as "an open standard that enables developers to build secure, two-way connections between their data sources and AI-powered tools."[1] The problem it targets is easy to state: "Even the most sophisticated models are constrained by their isolation from data—trapped behind information silos and legacy systems."[1]
Before a protocol like this, each application wrote its own connector for each data source. MCP aims to replace that matrix of custom integrations with one interface that any compliant application and any compliant server can share.
What Anthropic released at launch
The original announcement had three parts: the specification and SDKs, support for local MCP servers in the Claude Desktop app, and an open-source repository of ready-made servers. The sample servers covered Google Drive, Slack, GitHub, Git, Postgres and Puppeteer.[1]
How MCP is structured
MCP uses a client-server design. An AI application connects to MCP servers through MCP clients. A server exposes capabilities, and the client discovers and calls them. Messages are encoded with JSON-RPC and must be UTF-8.[2]
The three server primitives
The specification describes three building blocks a server can offer, and it assigns control of each to a different party.[3]
| Primitive | What it is | Who controls it | Example |
|---|---|---|---|
| Prompts | Pre-defined templates that guide model interactions | The user | Slash commands, menu options |
| Resources | Structured data that gives the model additional context | The application | File contents, git history |
| Tools | Executable functions that let a model take actions or fetch information | The model | API calls, writing a file |
The control column matters for safety. A tool is "model-controlled," so the model decides when to call it. That is the primitive where a mistaken or manipulated model can cause real effects.
The two standard transports
The specification defines two standard ways for a client and server to talk.[2]
- stdio. The client launches the server as a subprocess and exchanges newline-delimited JSON-RPC messages over standard input and output. The specification says clients "SHOULD support stdio whenever possible."
- Streamable HTTP. The server runs as an independent process behind a single HTTP endpoint that handles POST and GET, and can use Server-Sent Events to stream messages. It replaced the older HTTP+SSE transport from the 2024-11-05 protocol version.
The specification also contains a security warning for Streamable HTTP. Servers "MUST validate the Origin header on all incoming connections to prevent DNS rebinding attacks," and local servers "SHOULD bind only to localhost (127.0.0.1) rather than all network interfaces (0.0.0.0)."[2]
Who governs it now
On 9 December 2025, Anthropic announced it was donating MCP to the Agentic AI Foundation (AAIF), which it described as "a directed fund under the Linux Foundation." Anthropic, Block and OpenAI co-founded the foundation, with support from Google, Microsoft, AWS, Cloudflare and Bloomberg. In that announcement Anthropic reported "more than 10,000 active public MCP servers" and "97M+ monthly SDK downloads across Python and TypeScript," and listed ChatGPT, Cursor, Gemini, Microsoft Copilot and Visual Studio Code among the products that had adopted MCP.[4] Those are Anthropic's figures as of that date, not independently audited ones.
When MCP is the right tool
Our view, based on the published design:
- Use it when several applications need the same set of tools, when you want third-party tools to plug into your application without custom code, or when you want users to bring their own servers.
- Skip it when one application needs a handful of functions. Calling your own code directly is simpler, easier to test and has fewer moving parts. Our guide to how AI agents work and how to secure them explains why starting simple is usually the better default.
Security: a standard protocol is not a safe tool
MCP standardises the connection. It does not vouch for what is on the other end. Three habits follow from that:
- Treat tool descriptions and tool results as untrusted input. Text that a server returns can contain instructions aimed at the model. This is the indirect prompt injection problem described in the OWASP list of LLM risks.
- Give each server the least privilege it needs. A read-only file server should not also be able to delete files.
- Require human approval for irreversible actions. Payments, deletions and messages sent on your behalf should not happen on the model's say-so alone.


