Guide
What Is MCP?
A plain-English guide to MCP, the Model Context Protocol: what it is, how it works, what the latest specification changed, who supports it, how it differs from APIs and A2A, how to use it, and the documented security risks.
Quick answer: MCP, the Model Context Protocol, is an open standard that lets AI applications such as Claude, ChatGPT, Cursor and VS Code connect to outside tools and data through one common interface, instead of a custom integration for every pairing. The official documentation calls it “a USB-C port for AI applications”: a tool is wrapped once as an MCP server, and any MCP-compatible app can use it. Anthropic introduced MCP in November 2024, and the protocol is now run under the Linux Foundation’s Agentic AI Foundation, which reported MCP SDK downloads of 110 million a month in April 2026. The current specification, 2026-07-28, made the protocol stateless. The one caveat: every MCP server you connect acts with your permissions and feeds the model content it may obey, so MCP widens what a prompt injection can reach.
This page is the explainer: what MCP is, how it works and where it falls short. It does not rank MCP servers. For how agents use tools in general, see what is agentic AI. For the libraries developers use to build agents that consume MCP servers, see best AI agent frameworks. For the one-line definition next to the rest of the vocabulary, see the AI glossary.
What is MCP?
MCP is an open-source protocol that defines how an AI application discovers and uses external tools, data and prompt templates.
The official definition is one sentence: “MCP (Model Context Protocol) is an open-source standard for connecting AI applications to external systems.” Using MCP, an assistant can read local files, query a database, search the web, open a ticket or draw a diagram, provided someone has built an MCP server for that system.
The name breaks down simply:
- Model means a large language model, the AI behind an assistant or agent.
- Context means the information and abilities a model has to work with beyond its training data: your files, your calendar, a live search result, a tool it can call.
- Protocol means an agreed message format, so both sides know exactly what to send and what to expect back.
MCP does not make a model smarter. It changes what the model can reach. A model with no tools can only answer from its training data and what you paste in. The same model connected to a GitHub server, a calendar server and a database server can read your repository, check your diary and run a query, because the application around the model passes those abilities to it in a standard shape.
The MCP documentation gives four example uses: an agent that reads your Google Calendar and Notion, Claude Code building a web app from a Figma design, an enterprise chatbot querying several company databases, and a model creating 3D designs in Blender (modelcontextprotocol.io).
The problem MCP solves
MCP exists to replace many one-off integrations with one shared interface.
Before MCP, every AI application that wanted to use a tool needed its own integration with that tool. Ten AI apps and ten tools meant up to 100 separate integrations, each written and maintained by someone. Developers call this the “M×N problem”: M applications multiplied by N tools.
MCP turns M×N into M+N. Each tool is wrapped once as an MCP server. Each AI application implements MCP once as a client. Any client can then talk to any server. This is the same reason the USB-C analogy keeps appearing: a laptop maker builds one port, a monitor maker builds one plug, and neither needs to know about the other.
| Without MCP | With MCP |
|---|---|
| Each AI app writes its own connector for each tool | Each tool ships one MCP server |
| A new tool needs new code in every app | A new tool works in every MCP-compatible app |
| Switching AI app means rebuilding integrations | Integrations move with you to any MCP client |
| Tool descriptions and permissions differ app by app | Tools, resources and prompts are described the same way everywhere |
The practical result for a user is that a connector built for one assistant usually works in another. A Notion or GitHub MCP server connects to Claude, ChatGPT, Cursor and VS Code without the vendor writing four integrations.
How MCP works
MCP connects three roles, a host, a client and a server, and passes JSON-RPC messages between them.
Hosts, clients and servers
The MCP architecture specification defines a “client-host-server architecture where each host can run multiple client instances”.
| Role | What it is | Example |
|---|---|---|
| Host | The AI application you use. It runs the model, manages connections, enforces security policy and asks you for consent | Claude Desktop, ChatGPT, Cursor, VS Code |
| Client | A connector inside the host. Each client “communicates with exactly one server” | One client per connected server |
| Server | A program that exposes tools, data or prompts to the host | A GitHub server, a filesystem server, a database server |
The host sits in the middle on purpose. One of MCP’s stated design principles is that “servers should not be able to read the whole conversation, nor ‘see into’ other servers”: the full conversation stays with the host, each server receives only what it needs, and the host controls any interaction between servers (MCP architecture).
Servers can run in two places. A local server runs as a program on your own computer and is started by the host. A remote server (also called a hosted server) runs on the vendor’s infrastructure and is reached over the internet, usually with an OAuth sign-in.
The three things a server can offer
An MCP server offers some combination of three primitives, and the specification assigns each one to a different decision-maker.
| Primitive | Who decides when it is used | What it is | Example |
|---|---|---|---|
| Tools | The model | Functions the model can call to take an action or fetch information | Create a GitHub issue, run a SQL query, write a file |
| Resources | The application | Data the host attaches to the conversation as context | A file’s contents, a database schema, git history |
| Prompts | The user | Reusable templates the user picks, often as slash commands | ”/summarise-pr”, “/draft-release-notes” |
Tools get most of the attention because they let a model act. Resources are read-only context. Prompts are packaged instructions a server author ships so users do not have to write them.
A server can also ask the client for something mid-task. Elicitation lets a server request information from the user, such as a missing parameter or a confirmation. Sampling lets a server ask the host’s model to generate text, and roots let a server ask which folders it may work in. The 2026-07-28 specification marked Sampling and Roots as deprecated (see below).
Transports: how the messages travel
MCP messages are encoded as JSON-RPC, a lightweight request-and-response format. The 2026-07-28 specification defines two standard transports:
| Transport | How it works | Typical use |
|---|---|---|
| stdio | The host launches the server as a subprocess and exchanges newline-delimited messages over standard input and output | Local servers on your own machine |
| Streamable HTTP | Each message is an HTTP POST to a single MCP endpoint; replies come back as JSON or a request-scoped event stream | Remote, hosted servers |
An older HTTP+SSE transport has been deprecated since the 2025-03-26 revision, and the 2026-07-28 changelog formally classifies it as Deprecated with a migration path to Streamable HTTP (MCP changelog).
A request, step by step
Here is what happens when you ask an MCP-connected assistant, “What open issues are assigned to me?”
- Discovery. The host’s client asks the GitHub MCP server what it offers. Under the 2026-07-28 specification, servers answer a mandatory
server/discoverrequest with their supported versions, capabilities and identity, and list their tools withtools/list. - Tool descriptions reach the model. The host passes the list of tools, each with a name, a plain-language description and an input schema, to the model alongside your question.
- The model chooses a tool. The model decides the
list_issuestool fits and produces a structured request with the arguments it wants. - The host asks you, if configured. Many hosts require your approval before a tool runs, especially one that writes data.
- The client calls the server. The client sends a
tools/callrequest; the server queries GitHub and returns the result. - The model answers. The host adds the result to the conversation and the model writes the answer in plain language.
The model never talks to GitHub directly. It only ever sees tool descriptions and tool results, and the host decides what is sent where.
What the 2026-07-28 specification changed
The 2026-07-28 revision made MCP stateless: each request now stands alone, with no handshake and no session.
MCP versions are named by date, in YYYY-MM-DD format, marking the last date backwards-incompatible changes were made (MCP versioning). The previous revision was 2025-11-25. The current revision, 2026-07-28, was finalised on 28 July 2026.
| Change | What it means | Source |
|---|---|---|
No more initialize handshake | Every request carries its own protocol version and client capabilities | SEP-2575 |
| No protocol-level sessions | The Mcp-Session-Id header is gone; servers that need state pass explicit handles as tool arguments | SEP-2567 |
New server/discover request | Servers must advertise versions, capabilities and identity in one call | SEP-2575 |
| Multi Round-Trip Requests | Servers no longer send requests to clients; they return an “input required” result and the client retries with the answer | SEP-2322 |
| Tasks moved to an extension | Long-running operations become the official io.modelcontextprotocol/tasks extension | SEP-2663 |
| Cacheable list results | List responses carry ttlMs and cacheScope, so clients can cache tool lists | SEP-2549 |
| Roots, Sampling and Logging deprecated | Still functional during a deprecation window, but new implementations should not adopt them | SEP-2577 |
| Dynamic Client Registration deprecated | OAuth client registration moves to Client ID Metadata Documents | PR #2858 |
| Feature lifecycle policy | Deprecated features stay in the specification for at least 12 months before removal | SEP-2596 |
The practical reason for statelessness is scale. A server that keeps no session can sit behind an ordinary load balancer, and any instance can answer any request. Google’s developer blog framed the update around scaling AI agent infrastructure, and Microsoft published guidance on what the change means for scaling on Azure App Service.
For users, nothing visible changes overnight. Clients and servers built for 2025-11-25 and earlier keep working through the backwards-compatibility rules in the versioning specification, and the deprecated features keep working for at least the 12-month window.
MCP extensions: Apps, Tasks, Skills and enterprise sign-in
Extensions are optional add-ons to MCP that both the client and the server must switch on before they apply.
The MCP project publishes official extensions under the io.modelcontextprotocol prefix, and they are “always disabled by default and require explicit opt-in from the developer” (MCP extensions).
| Extension | What it adds |
|---|---|
| MCP Apps | Servers can return interactive interfaces (charts, forms, dashboards, viewers) that render inside the chat |
| MCP Tasks | Long-running operations with polling, mid-task input and durable handles |
| Skills over MCP | Servers can publish Agent Skills, workflow instructions with supporting files, for the client to discover and read |
| OAuth Client Credentials | Machine-to-machine sign-in with no interactive user login |
| Enterprise-Managed Authorization | Central access control through a company’s identity provider |
MCP Apps
MCP Apps is the extension most users will notice, because it turns a tool’s text reply into an interactive interface inside the conversation.
A tool that supports MCP Apps points to a ui:// resource containing an HTML page. The host fetches it and renders it in a sandboxed iframe, which, per the MCP Apps documentation, cannot “access the parent page, steal cookies, or escape their container”. The app talks to the host over the browser’s postMessage channel and can call the server’s tools, so a user can click through a chart or fill in a form without typing another prompt.
The extension was first proposed in November 2025 as SEP-1865 and arrived in Claude on 26 January 2026 with launch partners including Amplitude, Asana, Box, Canva, Clay, Figma, Hex, monday.com and Slack (The Register). The official extension support matrix lists MCP Apps support in Claude (web and desktop), ChatGPT, Cursor, VS Code GitHub Copilot, Microsoft 365 Copilot, Goose, Postman, MCPJam, Archestra.AI and PostHog Code. The matrix is maintained by the community.
Who supports MCP
Every major AI lab and the main developer tools support MCP as a client, and the big cloud and SaaS vendors publish MCP servers.
| Company | MCP support | Source |
|---|---|---|
| Anthropic | Created MCP; Claude apps connect to remote servers as connectors, and Claude Desktop and Claude Code also run local servers | modelcontextprotocol.io |
| OpenAI | The Responses API has a remote MCP tool type; the Agents SDK, ChatGPT (through developer mode and apps), Codex and Deep Research also support MCP | OpenAI developer docs |
| Fully managed remote MCP servers for Google Maps, BigQuery, Compute Engine and Kubernetes Engine, announced 10 December 2025, with more Google Cloud services to follow | Google Cloud | |
| Microsoft | Native MCP in Windows 11 through an on-device agent registry, previewed in Insider build 26220.7344 on 5 December 2025 with File Explorer and Windows Settings connectors; MCP Apps support in VS Code GitHub Copilot and Microsoft 365 Copilot | Windows Insider blog, MCP client matrix |
| Cursor and VS Code | Both act as MCP clients for local and remote servers | modelcontextprotocol.io |
The detail that matters for an ordinary user is where a server runs. Web and mobile assistants can only reach remote servers over the internet. Local servers, which run on your own computer, need a desktop or developer app: Claude Desktop, Claude Code, Cursor, VS Code or Gemini CLI. Plan limits also apply: Anthropic’s help centre says Claude’s Free plan allows one custom connector (Anthropic), and OpenAI’s help centre and developer documentation describe ChatGPT’s plan eligibility for custom MCP differently, so check your own workspace settings.
Who runs MCP now
MCP is governed as a Linux Foundation project, not by Anthropic alone.
Anthropic donated MCP to the Linux Foundation’s new Agentic AI Foundation (AAIF) in December 2025. The foundation was co-founded with Block and OpenAI and is supported by Google, Microsoft, AWS, Cloudflare and Bloomberg (Anthropic). The protocol’s legal entity is “Model Context Protocol a Series of LF Projects, LLC”, and contributions are made under the Apache License 2.0 (MCP governance).
Technical decisions follow a structure modelled on Python and PyTorch. Lead Maintainers hold final authority; the current Lead Maintainers are David Soria Parra and Den Delimarsky, and co-inventor Justin Spahr-Summers is listed as Lead Maintainer Emeritus (MCP governance). Seats belong to individuals, not companies: “there are no seats reserved for specific companies”. Changes to the specification go through public Specification Enhancement Proposals (SEPs), which is why every change in the table above has a SEP number.
The adoption numbers come from the foundation and from developer surveys:
| Measure | Figure | Source |
|---|---|---|
| Monthly MCP SDK downloads | 110 million (April 2026) | AAIF |
| Monthly MCP SDK downloads, earlier | 97 million (December 2025) | Anthropic |
| MCP Dev Summit North America attendance | 1,200 (13 April 2026, New York), double the previous year | AAIF |
| AAIF member organisations | 170 within four months of launch; 247 after the August 2026 intake | AAIF, AAIF |
| Developers using AI agents who use MCP servers | 34.4% | Stack Overflow 2025 Developer Survey |
Download counts measure developer activity, not end users, and the foundation that reports them also promotes the protocol. Treat them as evidence of momentum rather than a count of people using MCP.
MCP vs APIs, function calling, A2A and Skills
MCP sits alongside several other ways of giving AI access to the world, and each one solves a different problem.
| Technology | What it standardises | Relationship to MCP |
|---|---|---|
| A regular API | How software talks to one specific service | An MCP server usually wraps an API, adding descriptions a model can read and a format every MCP client understands |
| Function calling | How a model returns a structured request to run a named function | The model-level mechanism underneath tool use; MCP standardises how those functions are described, discovered and called across apps (AI glossary) |
| A2A (Agent2Agent) | How agents from different vendors discover each other and hand off tasks | Complementary: MCP connects an agent to its tools, A2A connects agents to other agents |
| Agent Skills | Packaged instructions and files that teach an agent a workflow | Complementary: Skills teach an agent how to do a job, MCP gives it the tools to do it; the Skills over MCP extension lets servers publish Skills |
MCP vs API. An API is built for programmers who read documentation and write code against it. An MCP server is built for models: each tool carries a plain-language description and a schema, so a model can work out when and how to use it. Most MCP servers are thin layers over an existing API, which is why vendors such as GitHub, Notion and Google can ship them quickly.
MCP vs A2A. Google announced A2A on 9 April 2025 and donated it to the Linux Foundation on 23 June 2025; on 20 August 2026 it joined the Agentic AI Foundation, the same body that hosts MCP (AI glossary). In one sentence: MCP standardises how one agent reaches its tools, and A2A standardises how agents reach each other. Our what is agentic AI guide covers how the two fit together.
How to use MCP
Using MCP means connecting a server to an app that acts as an MCP client; building with MCP means writing a server or a client with one of the official SDKs.
If you use an AI assistant
- Check that your app supports MCP and which kind. Web and mobile apps take remote servers only; desktop and developer apps also run local servers.
- Find the official server for the tool you want. Most major SaaS vendors publish their own. The official MCP Registry lists public servers, but it is still in preview and “breaking changes or data resets may occur”.
- Add the server. In Claude, ChatGPT and similar apps, a remote server is added as a connector by pasting its URL and signing in through OAuth. In Claude Code, the command is
claude mcp add --transport http <name> <url>(Anthropic). In Cursor and VS Code, servers are added in the app’s MCP settings or configuration file. - Grant the narrowest access that works. Use read-only modes where a server offers them, and keep approval prompts switched on for any tool that writes, sends or pays.
- Ask in plain language. The assistant decides when to call a tool; you do not need to name it, though naming the service (“check my GitHub issues”) helps.
If you are a developer
The MCP project maintains official SDKs in ten languages, tiered by feature completeness and maintenance commitment (MCP SDKs):
| Tier | Languages |
|---|---|
| Tier 1 | TypeScript, Python, C#, Go, Rust, Ruby |
| Tier 2 | Java |
| Tier 3 | Swift, PHP, Kotlin |
A minimal server registers one or more tools, each with a name, a description and an input schema, and handles calls to them. The MCP Inspector is the official tool for testing a server before connecting it to a real client, and OpenAI’s documentation recommends it for testing servers before connecting them to ChatGPT (OpenAI).
Three design choices matter most when building a server:
- Write tool descriptions for a model, not a human. The description is the only thing the model reads when deciding whether to call a tool.
- Expose fewer, sharper tools. Every tool description is sent to the model, so a server with dozens of tools costs context on every turn (see the limits section below).
- Mark destructive tools. OpenAI’s guidance is that servers should “require confirmation for consequential write actions”, using the
destructiveHintannotation for tools with irreversible outcomes (OpenAI).
MCP security risks
MCP is as safe as the permissions you grant and the content your servers read, and its security record since 2025 is long.
An MCP server acts with whatever credentials you give it, and anything it returns, from a web page to a GitHub issue, lands in the model’s context, where hidden instructions can steer the model. Simon Willison named the dangerous combination the “lethal trifecta” in June 2025: an agent with access to private data, exposure to untrusted content, and a way to send data out can be tricked into leaking that data. Connecting several MCP servers to one agent is the easiest way to assemble all three.
The main attack types
| Attack | What happens |
|---|---|
| Prompt injection | Untrusted content returned by a server, such as a web page or an issue comment, contains instructions the model follows |
| Tool poisoning | A malicious server hides instructions inside its tool descriptions, which the model reads but the user rarely sees |
| Malicious or compromised packages | A local server, or an update to one, ships code that steals data |
| Local server compromise | A local server runs with the same privileges as your app, so a malicious startup command in a configuration can execute anything on your machine (MCP security best practices) |
| Confused deputy and token passthrough | Flawed OAuth handling lets an attacker obtain access through a proxy server without the user’s consent; the specification forbids servers from accepting tokens not issued to them |
| Over-broad scopes | A stolen token carrying wide permissions gives an attacker everything at once; the specification recommends a “progressive, least-privilege scope model” |
Documented incidents
| Date | Incident | Source |
|---|---|---|
| April 2025 | Invariant Labs demonstrated tool poisoning, with hidden instructions in a tool description hijacking an agent | Invariant Labs |
| May 2025 | A malicious public GitHub issue made an agent using the GitHub MCP server leak private repository data | Invariant Labs |
| June 2025 | Asana disclosed that a bug in its MCP feature exposed some customers’ data to other organisations | BleepingComputer |
| July 2025 | CVE-2025-6514: a booby-trapped authorisation endpoint gave remote code execution in the widely used mcp-remote proxy | JFrog |
| September 2025 | postmark-mcp, the first malicious MCP server found in the wild, silently copied every email it sent to an attacker | The Hacker News |
| January 2026 | CVE-2026-0755 in gemini-mcp-tool, CVSS 9.8, allowed arbitrary code execution | AuthZed |
| April 2026 | OX Security reported command execution through stdio server configuration across packages with more than 150 million downloads; Anthropic called the behaviour expected | Cloud Security Alliance |
The April 2026 report is a genuine disagreement rather than a settled flaw. OX Security described stdio configuration as a systemic design weakness; Anthropic’s position, as reported by the Cloud Security Alliance, is that a configuration file which launches a program is meant to launch that program. Both sides agree on the practical lesson: a local MCP server configuration is code, and should be trusted only as far as its source.
Audits show the server ecosystem lags the specification. Astrix Security studied 5,205 MCP servers in October 2025 and found 53% relied on static secrets such as API keys, while 8.5% used OAuth (Astrix).
How to use MCP safely
- Use official servers from the vendor whose data they touch, not third-party copies.
- Prefer remote servers with OAuth over local servers holding long-lived API keys.
- Turn on read-only modes unless the agent needs to write.
- Keep approval on for write actions, especially anything that sends messages, moves money or deletes data.
- Avoid the lethal trifecta in one agent. Keep servers that read untrusted content away from servers that hold private data and can send it out.
- Pin versions of local servers and update deliberately; postmark-mcp’s malicious behaviour arrived as a routine package update.
- Read the startup command before approving a one-click local server install. The specification requires clients to show “the exact command that will be executed, without truncation” (MCP security best practices).
The limits and criticisms of MCP
MCP’s main weaknesses are context cost, an ecosystem full of unmaintained servers, and a security model that depends on users and clients behaving carefully.
Context cost. Every tool a connected server exposes is described to the model on every turn, which consumes the context window and adds cost. Anthropic showed in November 2025 that letting a model write code against MCP tools, instead of loading every tool definition up front, cut one workflow from 150,000 tokens to 2,000, a 98.7% reduction (Anthropic). Cloudflare made the same argument with its Code Mode in September 2025. The 2026-07-28 specification’s request that servers return tools “in a deterministic order” to improve prompt-cache hit rates is a direct response to the same problem.
The “MCP is dead” debate. Through 2026 a run of developer essays argued that command-line tools plus Skills do the job with less overhead, with titles from “MCP is dead” to “MCP is Dead; Long Live MCP!”. The counter-argument is that a CLI works for a coding agent with a terminal, while MCP is what lets a web or mobile assistant, or a company’s governed agent, reach tools with sign-in, permissions and audit. Both positions hold for different users: a solo developer in a terminal may need little MCP; an enterprise wiring agents to systems of record leans on it heavily.
Most real use is internal. The Pragmatic Engineer’s survey of 46 engineers (December 2025) found the median user’s main need was reaching their own company’s data through an internal MCP server. MCP co-creator David Soria Parra said at the April 2026 summit: “Behind every corporate firewall, we’re quietly wiring MCPs to systems of record” (AAIF).
Directories are mostly noise. Third-party directories list tens of thousands of MCP servers, and most are unofficial, duplicated or unmaintained. The official MCP Registry verifies who published a server through namespace authentication, but it “delegates security scanning” to package registries and downstream aggregators rather than vetting the code itself (MCP Registry).
The protocol is still moving. Two backwards-incompatible revisions eight months apart (2025-11-25 and 2026-07-28) mean server authors carry real maintenance work, though the new 12-month deprecation window is meant to slow the churn.
MCP timeline
| Date | Event | Source |
|---|---|---|
| November 2024 | Anthropic introduces the Model Context Protocol as an open standard | Anthropic |
| 26 March 2025 | Specification revision 2025-03-26; the HTTP+SSE transport is deprecated in favour of Streamable HTTP | MCP changelog |
| 8 September 2025 | The official MCP Registry launches in preview | MCP blog |
| 25 November 2025 | Specification revision 2025-11-25 | MCP changelog |
| 5 December 2025 | Windows 11 Insider build 26220.7344 previews native MCP support | Windows Insider blog |
| December 2025 | Anthropic donates MCP to the Linux Foundation’s Agentic AI Foundation | Anthropic |
| 10 December 2025 | Google announces managed remote MCP servers for Google Maps, BigQuery, Compute Engine and Kubernetes Engine | Google Cloud |
| 26 January 2026 | MCP Apps arrives in Claude with launch partners including Asana, Canva, Figma and Slack | The Register |
| 13 April 2026 | MCP Dev Summit North America in New York; AAIF reports 110 million monthly SDK downloads | AAIF |
| 28 July 2026 | Specification revision 2026-07-28 makes MCP stateless | MCP blog |
| 20 August 2026 | Google’s A2A protocol joins the Agentic AI Foundation alongside MCP | AI glossary |
Frequently asked questions
What is MCP in simple terms?
MCP, the Model Context Protocol, is a shared plug standard that lets AI assistants use outside tools and data. A company wraps its service once as an MCP server, and any AI app that supports MCP, such as Claude, ChatGPT, Cursor or VS Code, can then use it. The official documentation compares it to a USB-C port for AI applications.
What does MCP stand for?
MCP stands for Model Context Protocol. “Model” refers to the large language model behind an AI assistant, “context” to the information and tools the model can use beyond its training data, and “protocol” to the agreed message format that lets AI apps and tools talk to each other.
Who created MCP?
Anthropic created MCP and released it as an open standard in November 2024. MCP’s governance page lists Justin Spahr-Summers as co-inventor, and the Agentic AI Foundation describes Lead Maintainer David Soria Parra as MCP’s co-creator. Anthropic donated MCP to the Linux Foundation’s Agentic AI Foundation in December 2025, and the protocol is now governed by individual maintainers under the Linux Foundation, with no seats reserved for any company.
What is an MCP server?
An MCP server is a program that gives an AI app access to one system, such as GitHub, a database, a file folder or a web browser, by exposing tools, data or prompt templates in the MCP format. A server can run locally on your computer or remotely on a vendor’s infrastructure, where you connect to it by URL and sign in.
What is the difference between an MCP client and an MCP server?
An MCP client is the connector inside an AI app that talks to a server, and an MCP server is the program that provides the tools or data. The AI app itself is called the host; it runs one client for each connected server, and each client communicates with exactly one server.
Is MCP only for Claude?
No. MCP is supported by Anthropic’s Claude, OpenAI’s ChatGPT, Responses API, Agents SDK and Codex, Google Cloud’s managed MCP servers, Microsoft’s Windows 11, VS Code GitHub Copilot and Microsoft 365 Copilot, and developer tools including Cursor. Anthropic created MCP, but it is now an open standard run under the Linux Foundation.
How is MCP different from an API?
An API is an interface built for programmers to call one service from code. An MCP server usually wraps an API and adds plain-language tool descriptions and schemas that an AI model can read, in a format every MCP-compatible app understands. MCP does not replace APIs; it makes them usable by AI assistants without a custom integration for each app.
What is the difference between MCP and A2A?
MCP connects an AI agent to tools and data, while A2A (Agent2Agent) connects AI agents to other agents. Google announced A2A in April 2025, and since August 2026 both protocols sit under the Linux Foundation’s Agentic AI Foundation. They are complementary: an agent can use MCP to reach its tools and A2A to delegate work to another agent.
Is MCP safe to use?
MCP is safe to use when you connect official servers, grant the narrowest permissions that work and keep approval prompts on for write actions. The documented risks include prompt injection through content a server returns, tool poisoning through hidden instructions in tool descriptions, and malicious server packages, such as postmark-mcp, which copied users’ emails to an attacker in September 2025.
What is the latest MCP specification version?
The current MCP specification is version 2026-07-28, finalised on 28 July 2026. It made the protocol stateless by removing the initialisation handshake and protocol-level sessions, added a mandatory server/discover request, moved long-running tasks into an official extension, and deprecated the Roots, Sampling and Logging features.
What are MCP Apps?
MCP Apps is an official MCP extension that lets a server display an interactive interface, such as a chart, form, dashboard or document viewer, directly inside an AI chat. The interface runs in a sandboxed iframe controlled by the AI app. MCP Apps arrived in Claude on 26 January 2026 and is listed as supported in ChatGPT, Cursor, VS Code GitHub Copilot and Microsoft 365 Copilot.
How do I use MCP?
To use MCP, open an AI app that supports it, such as Claude, ChatGPT, Cursor or VS Code, and add an MCP server as a connector by pasting the server’s URL and signing in, or by adding it to the app’s MCP settings. Web and mobile apps can only use remote servers; desktop and developer apps such as Claude Desktop, Claude Code, Cursor and VS Code can also run servers locally on your computer.
Do I need to code to use MCP?
No. Connecting an existing remote MCP server in Claude or ChatGPT means pasting a URL and signing in, with no code. Coding is only needed to build your own MCP server, for which the MCP project maintains official SDKs in ten languages, including TypeScript, Python, C#, Go, Rust, Ruby and Java.
Is MCP dead?
No. MCP SDK downloads reached 110 million a month in April 2026 according to the Agentic AI Foundation, and a new specification shipped in July 2026. The “MCP is dead” argument, made in several 2026 developer essays, is that command-line tools and Agent Skills use less context for coding agents; it applies mainly to developers working in a terminal, not to web assistants or enterprise agents that need sign-in, permissions and audit.