What Is the Model Context Protocol (MCP)?
Learn key Model Context Protocol (MCP) definitions, how it works, personal and enterprise use cases, and critical security limitations.
Article Contents
What is Model Context Protocol (MCP)?
The Model Context Protocol (MCP) is an open standard that lets AI applications and agents connect to external tools, data sources, and services through one consistent interface. Anthropic introduced MCP in November 2024, and the protocol is now governed by the Agentic AI Foundation under the Linux Foundation, with support across the major AI providers. An assistant that speaks MCP can query a database, read a file, or call an API through any server that implements the standard, without a custom integration for each pairing.
The guide covers what the Model Context Protocol is, how MCP works, what MCP servers, tools, and resources do, where the protocol is used, how MCP compares with a traditional API, and what MCP security requires.
MCP in plain English
A protocol that gives an AI application a standard way to call tools and reach data. An MCP server exposes what a system can do, and any MCP-capable assistant or agent can connect to it.
Understanding the Model Context Protocol
The Model Context Protocol standardizes how an AI application reaches the systems around it. Before MCP, every connection between a large language model (LLM) application and an external system was a custom build, so ten assistants reaching ten tools meant a hundred separate integrations. MCP replaces that with one interface that any client and any server can speak, so an integration written once works everywhere the protocol is supported.
Adoption moved quickly because the value was obvious to every side of the market. OpenAI added MCP support across its products in March 2025, Google DeepMind announced support the same year, and thousands of MCP servers now exist for databases, file stores, developer tools, and business applications. On December 9, 2025, Anthropic donated the protocol to the Agentic AI Foundation, a directed fund under the Linux Foundation co-founded with Block and OpenAI, which placed MCP under neutral, community-driven governance.
Neutral governance removes the concern enterprises weigh before betting infrastructure on a standard, which is what happens if the original vendor changes direction. The donation kept the maintainer structure and the open proposal process intact, the same path Kubernetes followed on its way to becoming default infrastructure.
How does the Model Context Protocol work?
MCP follows a client-server design with three roles. The host is the AI application the user interacts with, such as a desktop assistant, an IDE, or an agent runtime. The host runs one or more MCP clients, and each client holds a connection to a single MCP server. The server is the program that exposes capabilities, whether the system behind it is a database, a file store, a ticketing system, or an internal API.
The two sides communicate through JSON-RPC 2.0 messages over a transport. A local server runs as a process on the same machine and talks over standard input and output, which suits personal tools and development. A remote server runs as a service and communicates over streamable HTTP, with OAuth 2.1 handling authorization, which is the setup production and multi-user deployments use. When a client connects, the two sides negotiate a session, and the client discovers which tools, resources, and prompts the server offers before anything is invoked.
MCP servers, tools, resources, and prompts
An MCP server exposes its capabilities through three building blocks. Tools are functions the AI can call to take an action, such as running a query or creating a ticket. Resources are data the server makes readable, such as a file, a schema, or a log excerpt, which give the AI context without an action. Prompts are reusable templates the server offers so common workflows start from a well-formed instruction.
| Building block | What it provides | Example |
|---|---|---|
| Tools | Actions the AI can invoke | Run a database query, create an issue, send a message |
| Resources | Data the AI can read for context | A file’s contents, a table schema, a log excerpt |
| Prompts | Reusable instruction templates | A code-review workflow, a report-summary starter |
What is the Model Context Protocol used for?
Coding assistants were the first large use case. An assistant connected to MCP servers for the file system, Git, and a test runner can read a codebase, make changes, and verify them, which is why IDEs and developer tools adopted the protocol early.
Enterprise data access is the second. Connecting an assistant to internal systems such as a data warehouse, a CRM, or a document store through MCP servers means one integration per system rather than one per assistant, and the same servers serve every MCP-capable application the company runs.
Agent workflows are the fastest-growing use. An AI agent that plans and executes multi-step tasks needs to reach many systems in sequence, and MCP gives it a uniform way to discover and call each one. Agents acting through MCP are also the reason MCP security has become its own discipline, which the section further down covers.
MCP vs traditional APIs
MCP does not replace APIs. An MCP server usually wraps an existing API and translates it into the protocol, so the underlying service keeps its interface while gaining a standard way for AI applications to find and call it. The difference lies in who the interface is designed for.
A traditional API is written for developers, who read documentation and write code against each endpoint. MCP is written for AI applications, which discover capabilities at runtime, receive descriptions the LLM can reason over, and call any conforming server the same way. A developer integrates an API once per application, while an MCP server integrates a system once for every MCP-capable application at the same time.
| Traditional API | Model Context Protocol | |
|---|---|---|
| Designed for | Developers writing code per endpoint | AI applications discovering capabilities at runtime |
| Integration effort | One integration per application and service pair | One server per service, reused by every client |
| Discovery | Read the documentation | Capabilities listed by the server at connection time |
| Interface | Different for every service | The same protocol for every service |
| Authorization | Varies by service | OAuth 2.1 for remote servers |
Model Context Protocol security
MCP gives AI agents real reach into infrastructure, so the protocol raises security questions that deployments have to answer deliberately. The risks named by the official MCP security guidance and the OWASP work on LLM applications include prompt injection, where hidden instructions in content an agent reads cause unintended actions, and tool poisoning, where a malicious server exposes a tool crafted to mislead the agent. Over-permissioned servers, stolen static tokens, and the absence of an audit trail complete the list.
The controls come back to identity, least privilege, and audit. Each agent and MCP server needs its own verifiable identity rather than a shared token, access limited to the systems a task requires, and a record of every action tied to the identity that took it. Agents and MCP servers are non-human identities, and short-lived cryptographic identity secures them the same way it secures other workloads, which our articles What are Non-Human Identities? and What is Workload Identity explain. Teleport extends that same cryptographic identity to AI agents and MCP servers through the Teleport Agentic Identity Framework.
Explore how Teleport provides secure MCP access to govern connections between AI applications, MCP servers, and sensitive enterprise data.
Frequently Asked Questions
What is the Model Context Protocol in simple terms?
The Model Context Protocol is an open standard that gives AI applications one consistent way to connect to external tools, data, and services. An MCP server exposes what a system can do, an MCP client inside the AI application connects to it, and the AI can then read data and take actions through that connection instead of through a custom integration.
Who created the Model Context Protocol, and who governs it now?
Anthropic introduced MCP in November 2024 and open-sourced it from the start. On December 9, 2025, Anthropic donated the protocol to the Agentic AI Foundation, a directed fund under the Linux Foundation co-founded with Block and OpenAI, so MCP is now governed as a neutral, community-driven standard.
What is an MCP server?
An MCP server is a program that exposes a system’s capabilities to AI applications through the Model Context Protocol. The server offers tools the AI can call, resources it can read, and prompts it can reuse, and any MCP client can connect to it. Servers exist for databases, file stores, developer tools, and thousands of other systems.
What is the difference between MCP and an API?
An API is an interface developers write code against, one integration per application and service. MCP is a protocol AI applications speak, so a server built once for a system works with every MCP-capable client. Most MCP servers wrap an existing API rather than replacing it.
Is MCP secure?
MCP is a protocol, so its security depends on the deployment. The protocol does not by itself prevent prompt injection, tool poisoning, or token theft, so a safe deployment gives each agent and server a verified identity, least-privilege access, and a full audit trail. Remote MCP servers authorize access with OAuth 2.1.
Which AI providers support MCP?
Anthropic built MCP support into Claude from the start, OpenAI adopted the protocol across its products in March 2025, and Google DeepMind announced support in 2025. Adoption across IDEs, agent runtimes, and enterprise software followed, which is why MCP has become the default way AI applications connect to tools.