What Is an MCP Server, and When Does a Business Need One?

What Is an MCP Server, and When Does a Business Need One?

An MCP server is a program that gives AI applications access to tools, data and prompt templates through the Model Context Protocol (MCP), an open standard for connecting AI applications to external systems. A business needs one when it wants the same systems, such as its CRM, database or product API, to be usable from several AI applications without building a separate integration for each. If one application of your own calls a few of your own functions, plain tool calling is usually enough.

This guide follows the MCP specification and official documentation at modelcontextprotocol.io, whose current protocol version is 2026-07-28. All pages were read on October 5, 2026.

What is the Model Context Protocol?

MCP is an open protocol that standardizes how AI applications discover and use outside tools and data. The official introduction calls it "an open-source standard for connecting AI applications to external systems" and offers an analogy: "Think of MCP like a USB-C port for AI applications."

Anthropic released MCP on November 25, 2024 to address a specific problem: "Every new data source requires its own custom implementation, making truly connected systems difficult to scale." On December 9, 2025, Anthropic donated MCP to the Linux Foundation's new Agentic AI Foundation. That announcement reported "more than 10,000 active public MCP servers" and "97M+ monthly SDK downloads across Python and TypeScript."

The protocol is supported outside Anthropic's products. The official introduction lists Claude, ChatGPT, Visual Studio Code and Cursor among the applications that support MCP.

How does an MCP server work?

An MCP server answers structured requests from an MCP client that runs inside an AI application. The application asks the server what it offers, shows those capabilities to the model, and forwards the model's chosen calls to the server.

The architecture overview defines three participants:

  • MCP host: "The AI application that coordinates and manages one or multiple MCP clients"
  • MCP client: "A component that maintains a connection to an MCP server and obtains context from an MCP server for the MCP host to use"
  • MCP server: "A program that provides context to MCP clients"

Messages use JSON-RPC 2.0. They travel over one of two transports. The stdio transport connects a client to a server running as a local process on the same machine. The Streamable HTTP transport "enables remote server communication and supports standard HTTP authentication methods including bearer tokens, API keys, and custom headers."

A typical exchange runs in four steps:

  1. The client may call server/discover to learn the server's supported versions and capabilities.
  2. The client calls tools/list and receives each tool's name, description and input schema.
  3. The model decides to use a tool, and the client sends tools/call with the arguments.
  4. The server runs the tool and returns the result, which the application adds to the model's context.

Since version 2026-07-28, the protocol is stateless. The architecture page explains that every request carries the protocol version and the capabilities relevant to it, "so the server can process each request on its own." A server that needs to remember something between calls, such as a shopping cart, returns an explicit handle that the model passes back.

What can an MCP server expose?

An MCP server can offer three kinds of capability: tools, resources and prompts. The specification describes them in one line each.

Capability Specification description Example for a business system
Tools "Functions for the AI model to execute" create_ticket, refund_order, query_sales
Resources "Context and data, for the user or the AI model to use" A customer record, a database schema, a policy document
Prompts "Templated messages and workflows for users" "Summarize this account before a renewal call"

Clients can offer a feature back to servers. Elicitation lets a server ask the user for more information or a confirmation in the middle of a task. Sampling, which let a server request a model completion from the client, is deprecated as of version 2026-07-28; the documentation advises that "New implementations should integrate directly with LLM provider APIs."

Optional extensions sit on top of the core. The specification names Tasks, for long-running operations with durable handles, and MCP Apps, for "Interactive UI elements (charts, forms, video players) rendered inline within conversations."

When does a business need an MCP server, and when is plain tool calling enough?

Use plain tool calling when one application you control calls your own functions. Build an MCP server when the same capabilities must work across several AI applications, including ones you do not control.

Tool calling, which OpenAI's function calling guide describes as a way for models "to interface with external systems and access data outside their training data", is defined by each model provider's API. Your application sends tool definitions with each request, runs the tool when the model asks, and returns the result. That is the simplest design when there is one app and one team.

MCP adds a standard way to publish those tools once, so that any compatible host can find and call them.

Situation Plain tool calling MCP server
One internal app calls a few of your own functions Fits Adds a layer you do not need
Customers want to use your product from the AI assistants and coding tools they already use Each assistant needs its own integration One server works with every compatible host
Several internal agents and assistants need the same CRM or database Each team repeats the integration One server, with one set of permissions and logs
You expect to change model provider Tool definitions may need rewriting The server stays the same
A local tool must read files on a user's machine Possible, but custom The stdio transport is designed for this

The two also meet. OpenAI's API lets models use "remote MCP servers" alongside ordinary function calls, per its MCP and connectors guide.

MCP has a token cost to plan for. Anthropic wrote on November 4, 2025 that "Tool definitions overload the context window" when an agent loads many servers at once. Its example of a different design cut usage from 150,000 tokens to 2,000, a 98.7% reduction. Expose a small, well-described set of tools, and the model bill stays smaller. Our article on AI agent development cost shows how tokens turn into monthly spend.

What are the security risks of an MCP server?

The main risks are tools that act without real consent, instructions hidden in tool descriptions or tool results, misused access tokens, and untrusted servers running on users' machines. The specification sets the principles, and the official security guidance sets concrete requirements.

The specification states that "Tools represent arbitrary code execution and must be treated with appropriate caution" and that "Hosts must obtain explicit user consent before invoking any tool." The tools section adds that "there SHOULD always be a human in the loop with the ability to deny tool invocations", and that servers must "Validate all tool inputs", "Implement proper access controls", "Rate limit tool invocations" and "Sanitize tool outputs."

Published research and guidance describe the attacks:

  • Tool poisoning. Invariant Labs reported on April 1, 2025 attacks in which "malicious instructions are embedded within MCP tool descriptions that are invisible to users but visible to AI models." It recommends pinning server versions and checking them with hashes.
  • Malicious servers. OpenAI's MCP guide warns that "A malicious server can exfiltrate sensitive data from anything that enters the model's context."
  • Risky combinations. Simon Willison wrote on June 16, 2025 that the problem with MCP "is that it encourages users to mix and match tools from different sources that can do different things." His "lethal trifecta" is an agent with access to private data, exposure to untrusted content and the ability to communicate externally.
  • Token misuse. The authorization specification requires that servers "validate that access tokens were issued specifically for them as the intended audience" and states: "MCP servers MUST NOT accept or transit any other tokens."
  • Local server compromise. The security best practices require clients that offer one-click local setup to "Show the exact command that will be executed, without truncation" and to get explicit approval.

The same page covers confused deputy attacks, server-side request forgery and scope design, and recommends a "progressive, least-privilege scope model." The OWASP Gen AI Security Project has published two practical guides: a cheat sheet for using third-party MCP servers (November 4, 2025) and a guide to secure MCP server development (February 16, 2026). The second notes that MCP servers "operate with delegated user permissions, dynamic tool-based architectures, and chained tool calls, increasing the potential impact of a single vulnerability."

What does MCP server development involve?

Building an MCP server takes seven steps, from choosing the tools to operating the server. The protocol work is small, because official SDKs handle it. Most of the effort goes into scope, permissions and testing.

  1. Choose the capabilities. List the tasks the AI should perform and expose only those, read-only first. Write tool names, descriptions and input schemas carefully, because the model chooses tools from them.
  2. Pick an SDK. The SDK page lists Tier 1 SDKs for TypeScript, Python, C#, Go, Rust and Ruby, Tier 2 for Java, and Tier 3 for Swift, PHP and Kotlin.
  3. Choose the transport. Use stdio for a server that runs on the user's machine and Streamable HTTP for a hosted server that many users reach.
  4. Add authorization. Authorization is optional in the protocol, but a remote server that touches business data needs it. The specification bases it on OAuth 2.1 and requires servers to implement OAuth 2.0 Protected Resource Metadata (RFC 9728). Local stdio servers "retrieve credentials from the environment" instead.
  5. Harden the tools. Validate inputs, enforce per-user permissions on every call, rate-limit, sanitize outputs, and require confirmation for actions that change data or spend money.
  6. Test. The MCP Inspector is "the reference developer tool for testing and debugging MCP servers", with web, command-line and terminal clients. Test with the hosts your users will use as well.
  7. Publish and operate. Public servers can be listed in the MCP Registry, which "is currently in preview" and "does not support private servers." Log every tool call. For stdio servers, the build tutorial warns: "Never write to stdout. Writing to stdout will corrupt the JSON-RPC messages and break your server."

Plan for protocol changes too. The versioning page explains that version identifiers mark "the last date backwards incompatible changes were made", and that deprecated features remain in the specification "for at least twelve months" before they can be removed.

Key takeaways

  • An MCP server exposes tools, resources and prompts to AI applications through an open protocol that ChatGPT, Claude, Visual Studio Code and Cursor support.
  • Plain tool calling fits one app calling your own functions; an MCP server fits when several AI applications, including your customers', need the same capabilities.
  • The current specification, version 2026-07-28, is stateless and runs over stdio for local servers or Streamable HTTP for remote ones.
  • The main risks are tool poisoning, malicious servers, token misuse and over-broad permissions; the specification requires consent, input validation, audience-checked tokens and rate limits.
  • Building one is mostly scoping, authorization and testing, because official SDKs handle the protocol.

Frequently asked questions

Is an MCP server the same as an API?

No. An MCP server usually sits in front of an existing API and describes its functions in a form AI applications can discover and call. Your API stays as it is, and the MCP server adds tool descriptions, schemas and the protocol's authorization flow.

Who maintains MCP?

Anthropic created MCP and released it in November 2024. In December 2025 it donated the protocol to the Agentic AI Foundation, a fund under the Linux Foundation co-founded with Block and OpenAI.

Do I need an MCP server to build an AI agent?

No. An agent can call your functions through its model provider's tool calling. An MCP server becomes useful when several agents or AI applications need the same tools, or when you want users to connect your product to the assistants they already use.

What is the difference between a local and a remote MCP server?

A local server runs on the user's machine and talks to the AI application over stdio, typically serving one client. A remote server runs on the web over Streamable HTTP, serves many clients and needs authorization.

Is it safe to install third-party MCP servers?

Only after review. A server can run code with the client's privileges and can place text in the model's context. Pin versions, read the exact launch command, limit permissions and require approval for tools that change data.

Easital Technologies Ltd. designs and builds MCP servers and the agents that use them, from tool design and authorization to testing and monitoring. See AI agent development, LLM development, AI automation services, hire AI developers and our work.

Sources

All sources were opened and checked on October 5, 2026.

  1. Model Context Protocol, "What is the Model Context Protocol (MCP)?", documentation for protocol version 2026-07-28. https://modelcontextprotocol.io/docs/2026-07-28/getting-started/intro
  2. Model Context Protocol, "Architecture overview", documentation for protocol version 2026-07-28. https://modelcontextprotocol.io/docs/2026-07-28/learn/architecture
  3. Model Context Protocol, "Specification", version 2026-07-28. https://modelcontextprotocol.io/specification/2026-07-28
  4. Model Context Protocol, "Tools", specification version 2026-07-28. https://modelcontextprotocol.io/specification/2026-07-28/server/tools
  5. Model Context Protocol, "Authorization", specification version 2026-07-28. https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization
  6. Model Context Protocol, "Security Best Practices", documentation. https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices
  7. Model Context Protocol, "SDKs", documentation. https://modelcontextprotocol.io/docs/2026-07-28/sdk
  8. Model Context Protocol, "MCP Inspector", documentation for protocol version 2026-07-28. https://modelcontextprotocol.io/docs/2026-07-28/tools/inspector
  9. Model Context Protocol, "Build an MCP server", documentation for protocol version 2026-07-28. https://modelcontextprotocol.io/docs/2026-07-28/develop/build-server
  10. Model Context Protocol, "The MCP Registry", documentation. https://modelcontextprotocol.io/registry/about
  11. Model Context Protocol, "Versioning", documentation for protocol version 2026-07-28. https://modelcontextprotocol.io/docs/2026-07-28/learn/versioning
  12. Anthropic, "Introducing the Model Context Protocol", November 25, 2024. https://www.anthropic.com/news/model-context-protocol
  13. Anthropic, "Donating the Model Context Protocol and establishing the Agentic AI Foundation", December 9, 2025. https://www.anthropic.com/news/donating-the-model-context-protocol-and-establishing-of-the-agentic-ai-foundation
  14. Anthropic, "Code execution with MCP", November 4, 2025. https://www.anthropic.com/engineering/code-execution-with-mcp
  15. OpenAI, "Function calling", OpenAI API documentation, read October 5, 2026. https://developers.openai.com/api/docs/guides/function-calling
  16. OpenAI, "MCP and connectors", OpenAI API documentation, read October 5, 2026. https://developers.openai.com/api/docs/guides/tools-connectors-mcp
  17. Invariant Labs, "MCP Security Notification: Tool Poisoning Attacks", April 1, 2025. https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks
  18. Simon Willison, "The lethal trifecta for AI agents", June 16, 2025. https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
  19. OWASP Gen AI Security Project, "CheatSheet: A Practical Guide for Securely Using Third-Party MCP Servers 1.0", November 4, 2025. https://genai.owasp.org/resource/cheatsheet-a-practical-guide-for-securely-using-third-party-mcp-servers-1-0/
  20. OWASP Gen AI Security Project, "A Practical Guide for Secure MCP Server Development", February 16, 2026. https://genai.owasp.org/resource/a-practical-guide-for-secure-mcp-server-development/

Further reading

Work with Easital on an AI or SaaS project

Send a short description of the product or the problem you want solved. We reply by email with questions and a proposed next step.

Discuss your project