Model Context Protocol
Model Context Protocol is an open protocol for connecting AI applications to tools, resources and reusable prompts exposed by servers. It standardizes discovery and communication across integrations, while the host application remains responsible for deciding what the model may access and when an operation is authorized.
What it is
MCP separates a host application from clients that communicate with servers providing capabilities. Servers can advertise tools for actions, resources for contextual data and prompts for reusable interaction patterns. The protocol defines messages and lifecycle behavior so an integration can be reused by compatible hosts. This differs from function calling, which describes how a model requests a tool within a model interaction; an MCP-backed tool can be exposed through that mechanism. It also differs from agent-to-agent protocols concerned with delegating work to another agent. Protocol compatibility does not imply that every host supports every feature or that a discovered tool is safe to invoke.
What the work involves
The practitioner implements or selects a server, chooses a supported transport and verifies capability discovery and tool contracts. Authentication and authorization need to match the connected service and user. Tool descriptions should state scope and effects clearly. Useful outputs include an integration contract, permission mapping and tests for malformed requests, unavailable servers and cancellation. Returned resources and tool content remain data for the application to interpret; connecting a server should not allow its text to redefine the user's instructions or grant new authority.
Illustrative example
A company exposes a read-only documentation search service through an MCP server. A host discovers the search tool, invokes it with a query and receives passages with document identifiers and URLs. A separate write-capable issue tool is available only to authorized users and requires an application-side action policy. Integration tests check both discovery and denied operations, showing that sharing a protocol endpoint does not collapse the distinction between reading evidence and changing records.
Limits and common mistakes
MCP standardizes an interface, not the truth of results or reliability of the server. Tool schemas can be valid while descriptions are misleading or permissions are too broad. Hosts and servers may implement different protocol versions or optional features. Quality requires tested compatibility, explicit trust boundaries and observable authorization decisions. A large tool catalog can also complicate selection, so discovery should support meaningful scope without assuming that exposing more capabilities always improves agent behavior.
Prerequisites
Related skills
- → is an instance of: AI Agent Design
Sources and further reading
- Model Context Protocol architecture overview
Defines host, client and server responsibilities and the protocol's tools, resources, prompts and communication model.
Last updated: 2026-10-10