Category leaders

Guide

What Is MCP?

A plain-English guide to MCP, the Model Context Protocol: what it is, how it works, what the latest specification changed, who supports it, how it differs from APIs and A2A, how to use it, and the documented security risks.

October 4, 2026 · The AI Rankings

Quick answer: MCP, the Model Context Protocol, is an open standard that lets AI applications such as Claude, ChatGPT, Cursor and VS Code connect to outside tools and data through one common interface, instead of a custom integration for every pairing. The official documentation calls it “a USB-C port for AI applications”: a tool is wrapped once as an MCP server, and any MCP-compatible app can use it. Anthropic introduced MCP in November 2024, and the protocol is now run under the Linux Foundation’s Agentic AI Foundation, which reported MCP SDK downloads of 110 million a month in April 2026. The current specification, 2026-07-28, made the protocol stateless. The one caveat: every MCP server you connect acts with your permissions and feeds the model content it may obey, so MCP widens what a prompt injection can reach.

This page is the explainer: what MCP is, how it works and where it falls short. It does not rank MCP servers. For how agents use tools in general, see what is agentic AI. For the libraries developers use to build agents that consume MCP servers, see best AI agent frameworks. For the one-line definition next to the rest of the vocabulary, see the AI glossary.


What is MCP?

MCP is an open-source protocol that defines how an AI application discovers and uses external tools, data and prompt templates.

The official definition is one sentence: “MCP (Model Context Protocol) is an open-source standard for connecting AI applications to external systems.” Using MCP, an assistant can read local files, query a database, search the web, open a ticket or draw a diagram, provided someone has built an MCP server for that system.

The name breaks down simply:

MCP does not make a model smarter. It changes what the model can reach. A model with no tools can only answer from its training data and what you paste in. The same model connected to a GitHub server, a calendar server and a database server can read your repository, check your diary and run a query, because the application around the model passes those abilities to it in a standard shape.

The MCP documentation gives four example uses: an agent that reads your Google Calendar and Notion, Claude Code building a web app from a Figma design, an enterprise chatbot querying several company databases, and a model creating 3D designs in Blender (modelcontextprotocol.io).

The problem MCP solves

MCP exists to replace many one-off integrations with one shared interface.

Before MCP, every AI application that wanted to use a tool needed its own integration with that tool. Ten AI apps and ten tools meant up to 100 separate integrations, each written and maintained by someone. Developers call this the “M×N problem”: M applications multiplied by N tools.

MCP turns M×N into M+N. Each tool is wrapped once as an MCP server. Each AI application implements MCP once as a client. Any client can then talk to any server. This is the same reason the USB-C analogy keeps appearing: a laptop maker builds one port, a monitor maker builds one plug, and neither needs to know about the other.

Without MCPWith MCP
Each AI app writes its own connector for each toolEach tool ships one MCP server
A new tool needs new code in every appA new tool works in every MCP-compatible app
Switching AI app means rebuilding integrationsIntegrations move with you to any MCP client
Tool descriptions and permissions differ app by appTools, resources and prompts are described the same way everywhere

The practical result for a user is that a connector built for one assistant usually works in another. A Notion or GitHub MCP server connects to Claude, ChatGPT, Cursor and VS Code without the vendor writing four integrations.

How MCP works

MCP connects three roles, a host, a client and a server, and passes JSON-RPC messages between them.

Hosts, clients and servers

The MCP architecture specification defines a “client-host-server architecture where each host can run multiple client instances”.

RoleWhat it isExample
HostThe AI application you use. It runs the model, manages connections, enforces security policy and asks you for consentClaude Desktop, ChatGPT, Cursor, VS Code
ClientA connector inside the host. Each client “communicates with exactly one server”One client per connected server
ServerA program that exposes tools, data or prompts to the hostA GitHub server, a filesystem server, a database server

The host sits in the middle on purpose. One of MCP’s stated design principles is that “servers should not be able to read the whole conversation, nor ‘see into’ other servers”: the full conversation stays with the host, each server receives only what it needs, and the host controls any interaction between servers (MCP architecture).

Servers can run in two places. A local server runs as a program on your own computer and is started by the host. A remote server (also called a hosted server) runs on the vendor’s infrastructure and is reached over the internet, usually with an OAuth sign-in.

The three things a server can offer

An MCP server offers some combination of three primitives, and the specification assigns each one to a different decision-maker.

PrimitiveWho decides when it is usedWhat it isExample
ToolsThe modelFunctions the model can call to take an action or fetch informationCreate a GitHub issue, run a SQL query, write a file
ResourcesThe applicationData the host attaches to the conversation as contextA file’s contents, a database schema, git history
PromptsThe userReusable templates the user picks, often as slash commands”/summarise-pr”, “/draft-release-notes”

Tools get most of the attention because they let a model act. Resources are read-only context. Prompts are packaged instructions a server author ships so users do not have to write them.

A server can also ask the client for something mid-task. Elicitation lets a server request information from the user, such as a missing parameter or a confirmation. Sampling lets a server ask the host’s model to generate text, and roots let a server ask which folders it may work in. The 2026-07-28 specification marked Sampling and Roots as deprecated (see below).

Transports: how the messages travel

MCP messages are encoded as JSON-RPC, a lightweight request-and-response format. The 2026-07-28 specification defines two standard transports:

TransportHow it worksTypical use
stdioThe host launches the server as a subprocess and exchanges newline-delimited messages over standard input and outputLocal servers on your own machine
Streamable HTTPEach message is an HTTP POST to a single MCP endpoint; replies come back as JSON or a request-scoped event streamRemote, hosted servers

An older HTTP+SSE transport has been deprecated since the 2025-03-26 revision, and the 2026-07-28 changelog formally classifies it as Deprecated with a migration path to Streamable HTTP (MCP changelog).

A request, step by step

Here is what happens when you ask an MCP-connected assistant, “What open issues are assigned to me?”

  1. Discovery. The host’s client asks the GitHub MCP server what it offers. Under the 2026-07-28 specification, servers answer a mandatory server/discover request with their supported versions, capabilities and identity, and list their tools with tools/list.
  2. Tool descriptions reach the model. The host passes the list of tools, each with a name, a plain-language description and an input schema, to the model alongside your question.
  3. The model chooses a tool. The model decides the list_issues tool fits and produces a structured request with the arguments it wants.
  4. The host asks you, if configured. Many hosts require your approval before a tool runs, especially one that writes data.
  5. The client calls the server. The client sends a tools/call request; the server queries GitHub and returns the result.
  6. The model answers. The host adds the result to the conversation and the model writes the answer in plain language.

The model never talks to GitHub directly. It only ever sees tool descriptions and tool results, and the host decides what is sent where.

What the 2026-07-28 specification changed

The 2026-07-28 revision made MCP stateless: each request now stands alone, with no handshake and no session.

MCP versions are named by date, in YYYY-MM-DD format, marking the last date backwards-incompatible changes were made (MCP versioning). The previous revision was 2025-11-25. The current revision, 2026-07-28, was finalised on 28 July 2026.

ChangeWhat it meansSource
No more initialize handshakeEvery request carries its own protocol version and client capabilitiesSEP-2575
No protocol-level sessionsThe Mcp-Session-Id header is gone; servers that need state pass explicit handles as tool argumentsSEP-2567
New server/discover requestServers must advertise versions, capabilities and identity in one callSEP-2575
Multi Round-Trip RequestsServers no longer send requests to clients; they return an “input required” result and the client retries with the answerSEP-2322
Tasks moved to an extensionLong-running operations become the official io.modelcontextprotocol/tasks extensionSEP-2663
Cacheable list resultsList responses carry ttlMs and cacheScope, so clients can cache tool listsSEP-2549
Roots, Sampling and Logging deprecatedStill functional during a deprecation window, but new implementations should not adopt themSEP-2577
Dynamic Client Registration deprecatedOAuth client registration moves to Client ID Metadata DocumentsPR #2858
Feature lifecycle policyDeprecated features stay in the specification for at least 12 months before removalSEP-2596

The practical reason for statelessness is scale. A server that keeps no session can sit behind an ordinary load balancer, and any instance can answer any request. Google’s developer blog framed the update around scaling AI agent infrastructure, and Microsoft published guidance on what the change means for scaling on Azure App Service.

For users, nothing visible changes overnight. Clients and servers built for 2025-11-25 and earlier keep working through the backwards-compatibility rules in the versioning specification, and the deprecated features keep working for at least the 12-month window.

MCP extensions: Apps, Tasks, Skills and enterprise sign-in

Extensions are optional add-ons to MCP that both the client and the server must switch on before they apply.

The MCP project publishes official extensions under the io.modelcontextprotocol prefix, and they are “always disabled by default and require explicit opt-in from the developer” (MCP extensions).

ExtensionWhat it adds
MCP AppsServers can return interactive interfaces (charts, forms, dashboards, viewers) that render inside the chat
MCP TasksLong-running operations with polling, mid-task input and durable handles
Skills over MCPServers can publish Agent Skills, workflow instructions with supporting files, for the client to discover and read
OAuth Client CredentialsMachine-to-machine sign-in with no interactive user login
Enterprise-Managed AuthorizationCentral access control through a company’s identity provider

MCP Apps

MCP Apps is the extension most users will notice, because it turns a tool’s text reply into an interactive interface inside the conversation.

A tool that supports MCP Apps points to a ui:// resource containing an HTML page. The host fetches it and renders it in a sandboxed iframe, which, per the MCP Apps documentation, cannot “access the parent page, steal cookies, or escape their container”. The app talks to the host over the browser’s postMessage channel and can call the server’s tools, so a user can click through a chart or fill in a form without typing another prompt.

The extension was first proposed in November 2025 as SEP-1865 and arrived in Claude on 26 January 2026 with launch partners including Amplitude, Asana, Box, Canva, Clay, Figma, Hex, monday.com and Slack (The Register). The official extension support matrix lists MCP Apps support in Claude (web and desktop), ChatGPT, Cursor, VS Code GitHub Copilot, Microsoft 365 Copilot, Goose, Postman, MCPJam, Archestra.AI and PostHog Code. The matrix is maintained by the community.

Who supports MCP

Every major AI lab and the main developer tools support MCP as a client, and the big cloud and SaaS vendors publish MCP servers.

CompanyMCP supportSource
AnthropicCreated MCP; Claude apps connect to remote servers as connectors, and Claude Desktop and Claude Code also run local serversmodelcontextprotocol.io
OpenAIThe Responses API has a remote MCP tool type; the Agents SDK, ChatGPT (through developer mode and apps), Codex and Deep Research also support MCPOpenAI developer docs
GoogleFully managed remote MCP servers for Google Maps, BigQuery, Compute Engine and Kubernetes Engine, announced 10 December 2025, with more Google Cloud services to followGoogle Cloud
MicrosoftNative MCP in Windows 11 through an on-device agent registry, previewed in Insider build 26220.7344 on 5 December 2025 with File Explorer and Windows Settings connectors; MCP Apps support in VS Code GitHub Copilot and Microsoft 365 CopilotWindows Insider blog, MCP client matrix
Cursor and VS CodeBoth act as MCP clients for local and remote serversmodelcontextprotocol.io

The detail that matters for an ordinary user is where a server runs. Web and mobile assistants can only reach remote servers over the internet. Local servers, which run on your own computer, need a desktop or developer app: Claude Desktop, Claude Code, Cursor, VS Code or Gemini CLI. Plan limits also apply: Anthropic’s help centre says Claude’s Free plan allows one custom connector (Anthropic), and OpenAI’s help centre and developer documentation describe ChatGPT’s plan eligibility for custom MCP differently, so check your own workspace settings.

Who runs MCP now

MCP is governed as a Linux Foundation project, not by Anthropic alone.

Anthropic donated MCP to the Linux Foundation’s new Agentic AI Foundation (AAIF) in December 2025. The foundation was co-founded with Block and OpenAI and is supported by Google, Microsoft, AWS, Cloudflare and Bloomberg (Anthropic). The protocol’s legal entity is “Model Context Protocol a Series of LF Projects, LLC”, and contributions are made under the Apache License 2.0 (MCP governance).

Technical decisions follow a structure modelled on Python and PyTorch. Lead Maintainers hold final authority; the current Lead Maintainers are David Soria Parra and Den Delimarsky, and co-inventor Justin Spahr-Summers is listed as Lead Maintainer Emeritus (MCP governance). Seats belong to individuals, not companies: “there are no seats reserved for specific companies”. Changes to the specification go through public Specification Enhancement Proposals (SEPs), which is why every change in the table above has a SEP number.

The adoption numbers come from the foundation and from developer surveys:

MeasureFigureSource
Monthly MCP SDK downloads110 million (April 2026)AAIF
Monthly MCP SDK downloads, earlier97 million (December 2025)Anthropic
MCP Dev Summit North America attendance1,200 (13 April 2026, New York), double the previous yearAAIF
AAIF member organisations170 within four months of launch; 247 after the August 2026 intakeAAIF, AAIF
Developers using AI agents who use MCP servers34.4%Stack Overflow 2025 Developer Survey

Download counts measure developer activity, not end users, and the foundation that reports them also promotes the protocol. Treat them as evidence of momentum rather than a count of people using MCP.

MCP vs APIs, function calling, A2A and Skills

MCP sits alongside several other ways of giving AI access to the world, and each one solves a different problem.

TechnologyWhat it standardisesRelationship to MCP
A regular APIHow software talks to one specific serviceAn MCP server usually wraps an API, adding descriptions a model can read and a format every MCP client understands
Function callingHow a model returns a structured request to run a named functionThe model-level mechanism underneath tool use; MCP standardises how those functions are described, discovered and called across apps (AI glossary)
A2A (Agent2Agent)How agents from different vendors discover each other and hand off tasksComplementary: MCP connects an agent to its tools, A2A connects agents to other agents
Agent SkillsPackaged instructions and files that teach an agent a workflowComplementary: Skills teach an agent how to do a job, MCP gives it the tools to do it; the Skills over MCP extension lets servers publish Skills

MCP vs API. An API is built for programmers who read documentation and write code against it. An MCP server is built for models: each tool carries a plain-language description and a schema, so a model can work out when and how to use it. Most MCP servers are thin layers over an existing API, which is why vendors such as GitHub, Notion and Google can ship them quickly.

MCP vs A2A. Google announced A2A on 9 April 2025 and donated it to the Linux Foundation on 23 June 2025; on 20 August 2026 it joined the Agentic AI Foundation, the same body that hosts MCP (AI glossary). In one sentence: MCP standardises how one agent reaches its tools, and A2A standardises how agents reach each other. Our what is agentic AI guide covers how the two fit together.

How to use MCP

Using MCP means connecting a server to an app that acts as an MCP client; building with MCP means writing a server or a client with one of the official SDKs.

If you use an AI assistant

  1. Check that your app supports MCP and which kind. Web and mobile apps take remote servers only; desktop and developer apps also run local servers.
  2. Find the official server for the tool you want. Most major SaaS vendors publish their own. The official MCP Registry lists public servers, but it is still in preview and “breaking changes or data resets may occur”.
  3. Add the server. In Claude, ChatGPT and similar apps, a remote server is added as a connector by pasting its URL and signing in through OAuth. In Claude Code, the command is claude mcp add --transport http <name> <url> (Anthropic). In Cursor and VS Code, servers are added in the app’s MCP settings or configuration file.
  4. Grant the narrowest access that works. Use read-only modes where a server offers them, and keep approval prompts switched on for any tool that writes, sends or pays.
  5. Ask in plain language. The assistant decides when to call a tool; you do not need to name it, though naming the service (“check my GitHub issues”) helps.

If you are a developer

The MCP project maintains official SDKs in ten languages, tiered by feature completeness and maintenance commitment (MCP SDKs):

TierLanguages
Tier 1TypeScript, Python, C#, Go, Rust, Ruby
Tier 2Java
Tier 3Swift, PHP, Kotlin

A minimal server registers one or more tools, each with a name, a description and an input schema, and handles calls to them. The MCP Inspector is the official tool for testing a server before connecting it to a real client, and OpenAI’s documentation recommends it for testing servers before connecting them to ChatGPT (OpenAI).

Three design choices matter most when building a server:

MCP security risks

MCP is as safe as the permissions you grant and the content your servers read, and its security record since 2025 is long.

An MCP server acts with whatever credentials you give it, and anything it returns, from a web page to a GitHub issue, lands in the model’s context, where hidden instructions can steer the model. Simon Willison named the dangerous combination the “lethal trifecta” in June 2025: an agent with access to private data, exposure to untrusted content, and a way to send data out can be tricked into leaking that data. Connecting several MCP servers to one agent is the easiest way to assemble all three.

The main attack types

AttackWhat happens
Prompt injectionUntrusted content returned by a server, such as a web page or an issue comment, contains instructions the model follows
Tool poisoningA malicious server hides instructions inside its tool descriptions, which the model reads but the user rarely sees
Malicious or compromised packagesA local server, or an update to one, ships code that steals data
Local server compromiseA local server runs with the same privileges as your app, so a malicious startup command in a configuration can execute anything on your machine (MCP security best practices)
Confused deputy and token passthroughFlawed OAuth handling lets an attacker obtain access through a proxy server without the user’s consent; the specification forbids servers from accepting tokens not issued to them
Over-broad scopesA stolen token carrying wide permissions gives an attacker everything at once; the specification recommends a “progressive, least-privilege scope model”

Documented incidents

DateIncidentSource
April 2025Invariant Labs demonstrated tool poisoning, with hidden instructions in a tool description hijacking an agentInvariant Labs
May 2025A malicious public GitHub issue made an agent using the GitHub MCP server leak private repository dataInvariant Labs
June 2025Asana disclosed that a bug in its MCP feature exposed some customers’ data to other organisationsBleepingComputer
July 2025CVE-2025-6514: a booby-trapped authorisation endpoint gave remote code execution in the widely used mcp-remote proxyJFrog
September 2025postmark-mcp, the first malicious MCP server found in the wild, silently copied every email it sent to an attackerThe Hacker News
January 2026CVE-2026-0755 in gemini-mcp-tool, CVSS 9.8, allowed arbitrary code executionAuthZed
April 2026OX Security reported command execution through stdio server configuration across packages with more than 150 million downloads; Anthropic called the behaviour expectedCloud Security Alliance

The April 2026 report is a genuine disagreement rather than a settled flaw. OX Security described stdio configuration as a systemic design weakness; Anthropic’s position, as reported by the Cloud Security Alliance, is that a configuration file which launches a program is meant to launch that program. Both sides agree on the practical lesson: a local MCP server configuration is code, and should be trusted only as far as its source.

Audits show the server ecosystem lags the specification. Astrix Security studied 5,205 MCP servers in October 2025 and found 53% relied on static secrets such as API keys, while 8.5% used OAuth (Astrix).

How to use MCP safely

  1. Use official servers from the vendor whose data they touch, not third-party copies.
  2. Prefer remote servers with OAuth over local servers holding long-lived API keys.
  3. Turn on read-only modes unless the agent needs to write.
  4. Keep approval on for write actions, especially anything that sends messages, moves money or deletes data.
  5. Avoid the lethal trifecta in one agent. Keep servers that read untrusted content away from servers that hold private data and can send it out.
  6. Pin versions of local servers and update deliberately; postmark-mcp’s malicious behaviour arrived as a routine package update.
  7. Read the startup command before approving a one-click local server install. The specification requires clients to show “the exact command that will be executed, without truncation” (MCP security best practices).

The limits and criticisms of MCP

MCP’s main weaknesses are context cost, an ecosystem full of unmaintained servers, and a security model that depends on users and clients behaving carefully.

Context cost. Every tool a connected server exposes is described to the model on every turn, which consumes the context window and adds cost. Anthropic showed in November 2025 that letting a model write code against MCP tools, instead of loading every tool definition up front, cut one workflow from 150,000 tokens to 2,000, a 98.7% reduction (Anthropic). Cloudflare made the same argument with its Code Mode in September 2025. The 2026-07-28 specification’s request that servers return tools “in a deterministic order” to improve prompt-cache hit rates is a direct response to the same problem.

The “MCP is dead” debate. Through 2026 a run of developer essays argued that command-line tools plus Skills do the job with less overhead, with titles from “MCP is dead” to “MCP is Dead; Long Live MCP!”. The counter-argument is that a CLI works for a coding agent with a terminal, while MCP is what lets a web or mobile assistant, or a company’s governed agent, reach tools with sign-in, permissions and audit. Both positions hold for different users: a solo developer in a terminal may need little MCP; an enterprise wiring agents to systems of record leans on it heavily.

Most real use is internal. The Pragmatic Engineer’s survey of 46 engineers (December 2025) found the median user’s main need was reaching their own company’s data through an internal MCP server. MCP co-creator David Soria Parra said at the April 2026 summit: “Behind every corporate firewall, we’re quietly wiring MCPs to systems of record” (AAIF).

Directories are mostly noise. Third-party directories list tens of thousands of MCP servers, and most are unofficial, duplicated or unmaintained. The official MCP Registry verifies who published a server through namespace authentication, but it “delegates security scanning” to package registries and downstream aggregators rather than vetting the code itself (MCP Registry).

The protocol is still moving. Two backwards-incompatible revisions eight months apart (2025-11-25 and 2026-07-28) mean server authors carry real maintenance work, though the new 12-month deprecation window is meant to slow the churn.

MCP timeline

DateEventSource
November 2024Anthropic introduces the Model Context Protocol as an open standardAnthropic
26 March 2025Specification revision 2025-03-26; the HTTP+SSE transport is deprecated in favour of Streamable HTTPMCP changelog
8 September 2025The official MCP Registry launches in previewMCP blog
25 November 2025Specification revision 2025-11-25MCP changelog
5 December 2025Windows 11 Insider build 26220.7344 previews native MCP supportWindows Insider blog
December 2025Anthropic donates MCP to the Linux Foundation’s Agentic AI FoundationAnthropic
10 December 2025Google announces managed remote MCP servers for Google Maps, BigQuery, Compute Engine and Kubernetes EngineGoogle Cloud
26 January 2026MCP Apps arrives in Claude with launch partners including Asana, Canva, Figma and SlackThe Register
13 April 2026MCP Dev Summit North America in New York; AAIF reports 110 million monthly SDK downloadsAAIF
28 July 2026Specification revision 2026-07-28 makes MCP statelessMCP blog
20 August 2026Google’s A2A protocol joins the Agentic AI Foundation alongside MCPAI glossary

Frequently asked questions

What is MCP in simple terms?

MCP, the Model Context Protocol, is a shared plug standard that lets AI assistants use outside tools and data. A company wraps its service once as an MCP server, and any AI app that supports MCP, such as Claude, ChatGPT, Cursor or VS Code, can then use it. The official documentation compares it to a USB-C port for AI applications.

What does MCP stand for?

MCP stands for Model Context Protocol. “Model” refers to the large language model behind an AI assistant, “context” to the information and tools the model can use beyond its training data, and “protocol” to the agreed message format that lets AI apps and tools talk to each other.

Who created MCP?

Anthropic created MCP and released it as an open standard in November 2024. MCP’s governance page lists Justin Spahr-Summers as co-inventor, and the Agentic AI Foundation describes Lead Maintainer David Soria Parra as MCP’s co-creator. Anthropic donated MCP to the Linux Foundation’s Agentic AI Foundation in December 2025, and the protocol is now governed by individual maintainers under the Linux Foundation, with no seats reserved for any company.

What is an MCP server?

An MCP server is a program that gives an AI app access to one system, such as GitHub, a database, a file folder or a web browser, by exposing tools, data or prompt templates in the MCP format. A server can run locally on your computer or remotely on a vendor’s infrastructure, where you connect to it by URL and sign in.

What is the difference between an MCP client and an MCP server?

An MCP client is the connector inside an AI app that talks to a server, and an MCP server is the program that provides the tools or data. The AI app itself is called the host; it runs one client for each connected server, and each client communicates with exactly one server.

Is MCP only for Claude?

No. MCP is supported by Anthropic’s Claude, OpenAI’s ChatGPT, Responses API, Agents SDK and Codex, Google Cloud’s managed MCP servers, Microsoft’s Windows 11, VS Code GitHub Copilot and Microsoft 365 Copilot, and developer tools including Cursor. Anthropic created MCP, but it is now an open standard run under the Linux Foundation.

How is MCP different from an API?

An API is an interface built for programmers to call one service from code. An MCP server usually wraps an API and adds plain-language tool descriptions and schemas that an AI model can read, in a format every MCP-compatible app understands. MCP does not replace APIs; it makes them usable by AI assistants without a custom integration for each app.

What is the difference between MCP and A2A?

MCP connects an AI agent to tools and data, while A2A (Agent2Agent) connects AI agents to other agents. Google announced A2A in April 2025, and since August 2026 both protocols sit under the Linux Foundation’s Agentic AI Foundation. They are complementary: an agent can use MCP to reach its tools and A2A to delegate work to another agent.

Is MCP safe to use?

MCP is safe to use when you connect official servers, grant the narrowest permissions that work and keep approval prompts on for write actions. The documented risks include prompt injection through content a server returns, tool poisoning through hidden instructions in tool descriptions, and malicious server packages, such as postmark-mcp, which copied users’ emails to an attacker in September 2025.

What is the latest MCP specification version?

The current MCP specification is version 2026-07-28, finalised on 28 July 2026. It made the protocol stateless by removing the initialisation handshake and protocol-level sessions, added a mandatory server/discover request, moved long-running tasks into an official extension, and deprecated the Roots, Sampling and Logging features.

What are MCP Apps?

MCP Apps is an official MCP extension that lets a server display an interactive interface, such as a chart, form, dashboard or document viewer, directly inside an AI chat. The interface runs in a sandboxed iframe controlled by the AI app. MCP Apps arrived in Claude on 26 January 2026 and is listed as supported in ChatGPT, Cursor, VS Code GitHub Copilot and Microsoft 365 Copilot.

How do I use MCP?

To use MCP, open an AI app that supports it, such as Claude, ChatGPT, Cursor or VS Code, and add an MCP server as a connector by pasting the server’s URL and signing in, or by adding it to the app’s MCP settings. Web and mobile apps can only use remote servers; desktop and developer apps such as Claude Desktop, Claude Code, Cursor and VS Code can also run servers locally on your computer.

Do I need to code to use MCP?

No. Connecting an existing remote MCP server in Claude or ChatGPT means pasting a URL and signing in, with no code. Coding is only needed to build your own MCP server, for which the MCP project maintains official SDKs in ten languages, including TypeScript, Python, C#, Go, Rust, Ruby and Java.

Is MCP dead?

No. MCP SDK downloads reached 110 million a month in April 2026 according to the Agentic AI Foundation, and a new specification shipped in July 2026. The “MCP is dead” argument, made in several 2026 developer essays, is that command-line tools and Agent Skills use less context for coding agents; it applies mainly to developers working in a terminal, not to web assistants or enterprise agents that need sign-in, permissions and audit.

← All guides