Quick Answer: Model Context Protocol (MCP) is the open standard that lets any AI application connect to any external tool through a single universal interface — like USB-C, but for AI agents. Launched by Anthropic in November 2024, it was adopted by OpenAI, Google, and Microsoft within six months and is now governed by the Linux Foundation.
Before MCP, connecting an AI to your database, your GitHub repos, your Slack channels, and your internal docs meant writing four separate, custom integrations — each fragile, each tied to one AI vendor. If you switched models, you started over. If a new data source appeared, you built another connector.
Model Context Protocol ended that. It is a single open standard that any AI application can implement to connect to any tool or data source. Teams using cowork.ink can give their AI agents access to the whole company's toolstack through standard MCP servers — no custom glue code required.
This guide covers everything: the architecture, the five primitives, the security threats, the ecosystem of 6,400+ servers, and the 2026 roadmap. By the end, you will understand not just what MCP is, but why it became the de facto standard for agentic AI in under a year.
What Is Model Context Protocol?
Model Context Protocol (MCP) is an open-source communication standard that defines how AI systems connect to, communicate with, and retrieve context from external tools and data sources. It was created by Anthropic engineers David Soria Parra and Justin Spahr-Summers and open-sourced on November 25, 2024.
The canonical analogy is USB-C. Before USB-C, every device manufacturer used a different port. USB-C created a universal connector: one port, any device, any manufacturer. MCP does the same for AI integrations — one protocol, any AI model, any tool.
The protocol runs over JSON-RPC 2.0 (a simple request/response format) and defines a standard vocabulary for discovery (tools/list), invocation (tools/call), and resource access (resources/read). This vocabulary is implementation-agnostic: an MCP server built today will work with AI clients that don't exist yet.
On December 9, 2025, Anthropic donated MCP to the Agentic AI Foundation (AAIF), a directed fund under the Linux Foundation, co-founded by Anthropic, Block, and OpenAI. This ensures permanent vendor-neutral governance. The spec is no longer owned by any single company.
The Problem MCP Solves: The N×M Integration Crisis
To understand why MCP matters, you need to understand the problem it replaced.
Every AI application that wanted to work with external data had to build custom connectors. With M AI models and N data sources, developers needed M × N custom integrations.
Say 10 AI assistants each needed to connect to 20 data sources (GitHub, Postgres, Slack, Notion, Google Drive, internal APIs...). That's 200 custom integrations. Each with its own API quirks, authentication flow, error handling, and maintenance burden. Each integration was a new security surface. Switching AI vendors meant rebuilding everything.
MCP collapses M×N to M + N:
- Each AI application builds one MCP client.
- Each tool or data source builds one MCP server.
- Any client connects to any server automatically.
Anthropic described this as solving the problem of AI being "trapped behind information silos and legacy systems." That framing resonated — SDK downloads went from ~100,000 in November 2024 to 8 million by April 2025 and reportedly over 97 million monthly downloads by late 2025.
MCP Architecture: Hosts, Clients, and Servers
MCP uses a three-tier client-server architecture. Understanding the three roles is the foundation for everything else.
| Role | What It Is | Examples |
|---|---|---|
| MCP Host | The AI application; orchestrates everything, creates and manages MCP clients | Claude Desktop, VS Code, Cursor, ChatGPT |
| MCP Client | A component inside the host; holds a dedicated 1:1 connection to one MCP server | Created per server by the host application |
| MCP Server | An independent program that exposes tools, resources, and prompts | GitHub server, Postgres server, Brave Search server |
A single host manages many clients simultaneously. VS Code acts as the host, creates one client for Sentry MCP, another for the local filesystem MCP, and another for GitHub MCP — all running concurrently.
Servers can be local (running as a subprocess on the same machine, using stdio transport) or remote (running on a separate host, using HTTP transport). Local servers are common in developer tools; remote servers are the model for enterprise and SaaS deployments.
Transport Mechanisms: stdio vs. Streamable HTTP
Two transport mechanisms define how hosts and servers actually communicate:
stdio (Standard Input/Output) — For local processes. The host spawns the MCP server as a subprocess and communicates over stdin/stdout. Zero network overhead. Synchronous. Used by Claude Desktop for locally-installed servers. Simple, but cannot scale horizontally.
Streamable HTTP — For remote servers. Uses HTTP POST for client-to-server requests, with optional Server-Sent Events (SSE) for streaming responses. Supports OAuth 2.1 and API key authentication. Introduced in the June 2025 spec (2025-06-18) and is the production-ready transport for cloud-deployed servers.
The Connection Lifecycle
Every MCP session follows a structured lifecycle:
- Initialization — Client sends
initializerequest with protocol version and its capabilities. Server responds with its capabilities. Client confirms withnotifications/initialized. - Discovery — Client calls
tools/list,resources/list, andprompts/listto enumerate what the server offers. - Operation — Client sends requests (
tools/call,resources/read). Server executes and responds. Servers can pushnotificationswithout being polled. - Termination — Either party can end the connection cleanly.
This lifecycle is one of the key advantages over raw function calling — MCP servers can push real-time updates (e.g., "my tool list changed, re-fetch it"), and the session is stateful rather than one-shot.
The Five Core MCP Primitives
MCP defines five primitives — the building blocks every server and client can implement. Three are server-side (what servers offer), two are client-side (what hosts offer back to servers).
Server-Side Primitives
Tools are executable functions the AI can invoke to take actions with real-world effects. Think API calls, database writes, code execution. Each tool has a name, description, and an inputSchema (JSON Schema) defining its parameters. The AI model decides when to invoke a tool based on user intent. Tools are analogous to POST endpoints in REST.
Resources are structured data sources the AI can read for passive context. Think file contents, database schemas, API documentation, calendar events. No side effects — resources are for reading, not acting. Analogous to GET endpoints.
Prompts are reusable templates for structuring LLM interactions. They define standard workflows, few-shot examples, or system prompt stubs that server developers want to standardize. A Postgres MCP server might offer a "write a SQL query for this schema" prompt template.
Client-Side Primitives
Sampling allows servers to request LLM completions from the host's AI model. This enables server-side agentic logic — a server can run its own reasoning loop without needing its own LLM SDK. The server sends a sampling/create request; the host's model generates a completion and returns it. Servers stay model-independent.
Elicitation allows servers to request additional input from users mid-operation. A server can ask for confirmation before a destructive action, request credentials for a protected resource, or ask a clarifying question. This is critical for security: servers can trigger out-of-band credential handling without embedding sensitive tokens in tool responses.
For most MCP servers, Tools and Resources are the core. Sampling and Elicitation appear in more advanced agentic architectures. If you're building your first MCP server, focus on Tools — they're what most MCP clients prioritize. For a detailed breakdown of how each primitive works in practice, see our guide to MCP tools, resources, and prompts.
MCP vs. Function Calling: What's the Difference?
This is the question most developers ask first. The key insight: they are complementary, not competing.
Function calling is how an LLM expresses intent to use a tool. It generates a structured JSON instruction saying "call this function with these parameters." MCP is the infrastructure that handles how those tools are discovered and executed in a standardized way.
| Dimension | Function Calling | Model Context Protocol |
|---|---|---|
| What it is | LLM expresses intent to invoke a tool | Infrastructure for tool discovery and execution |
| Phase | Phase 1: instruction generation | Phase 2: execution infrastructure |
| Standardized? | No — each vendor uses different JSON formats | Yes — universal JSON-RPC 2.0 |
| Session | Single request/response | Stateful session with lifecycle |
| Tool discovery | Defined per-request by the developer | Dynamic via tools/list at runtime |
| Portability | Locked to one LLM provider | Switch LLMs without changing tool code |
| Setup complexity | Low — embed in API call | Higher — requires running MCP server |
| Best for | Prototypes, 2–3 custom tools | Multi-tool ecosystems, enterprise scale |
The mental model: function calling is how the AI says "I want to search the web." MCP is the universal socket that lets it actually do it, regardless of which AI model or which search engine is involved.
MCP does not replace function calling — the MCP host uses function calling internally to let the LLM invoke tools. MCP standardizes how those tool definitions are discovered and how results flow back. They are layers in the same stack.
For a deeper look at how AI agents use tools, see our guide to AI agent tool calling.
The MCP Ecosystem: Clients and Servers
Clients Supporting MCP
As of early 2026, 300+ applications support MCP as clients. Major ones include:
- Claude Desktop (Anthropic) — the original MCP host
- VS Code with GitHub Copilot — Microsoft's IDE integration
- Cursor — the leading AI coding editor
- ChatGPT Desktop (OpenAI) — adopted MCP in March 2025
- JetBrains IDEs (IntelliJ, PyCharm, etc.)
- Amazon Q Developer
- Zed editor
- Windsurf (Codeium)
Enterprise AI platforms from AWS, Azure, and Google Cloud also support MCP through their respective agent frameworks.
Major MCP Servers by Category
The official MCP Registry holds 6,400+ verified servers. Here's a map of the major categories:
| Category | Notable Servers |
|---|---|
| Development | GitHub, GitLab, Docker, Playwright, Context7, E2B |
| Cloud / Infra | Cloudflare (Workers, KV, R2, D1), AWS, Azure (40+ services), Supabase |
| Databases | Postgres, SQLite, MongoDB, BigQuery, Snowflake |
| Productivity | Notion, Slack, Zapier, Google Calendar, Linear, Jira |
| Search / Web | Brave Search, Firecrawl, Tavily, Browserbase |
| AI / ML | Hugging Face, Replicate |
| Files | Filesystem (local), Google Drive, OneDrive |
Anthropic launched with 11 reference implementations at open-source day in November 2024: GitHub, Google Drive, Slack, Git, Postgres, Puppeteer, Brave Search, Memory (knowledge graph), Filesystem, SQLite, and Fetch. These remain the most widely used servers.
For a curated breakdown, see our best MCP servers guide.
MCP Security: What You Need to Know
MCP's power comes with real security risks. Because MCP servers can execute code, access databases, and trigger real-world actions, they create attack surfaces that prompt-only AI systems did not have.
Researchers at arxiv.org published a formal taxonomy of MCP threats in March 2025 (updated October 2025), identifying 16 distinct threat scenarios across 4 attacker categories. Multiple real-world incidents have already occurred. Treat every MCP server as code you are running on your system.
The Main Attack Vectors
Prompt Injection — Malicious content embedded in tool responses (web pages, database records, documents) hijacks the AI's behavior. The AI processes the malicious instruction as if it came from the user. This is OWASP's #1 LLM security risk and is particularly dangerous in MCP because tool invocations can have irreversible side effects.
Tool Poisoning — Attackers embed hidden instructions inside MCP tool descriptions — the metadata the AI reads but users typically don't see. The AI gets fooled into executing unauthorized actions. Invariant Labs demonstrated this with a WhatsApp MCP server that exfiltrated conversation history by hiding instructions in the tool's description field.
Rug Pull Attacks — A legitimate MCP server changes its tool descriptions after gaining user trust. The user previously approved the tool; now it does something different. This attack exploits the gap between when a user reviews a server and when they use it.
Supply Chain Attacks — The 2025 Postmark MCP breach: attackers inserted one line of malicious code into an npm package dependency. Every MCP server using that package silently blind-copied every outgoing email to the attackers.
CVE-2025-6514 — A critical CVSS 9.6 vulnerability in mcp-remote enabling arbitrary OS command execution when MCP clients connect to untrusted servers. The first documented RCE in real-world MCP deployments.
How to Stay Safe
- Only connect to MCP servers from sources you have audited or that come from vendors you trust
- Run MCP servers in sandboxed environments (Docker containers, restricted VMs)
- Review tool descriptions, not just tool names — the description is what the AI reads
- Pin dependency versions in MCP servers you operate
- For enterprise deployments: require code review of all MCP servers before adoption
For a complete security framework, see our MCP security best practices guide.
MCP's Rise: From Launch to Industry Standard
The adoption trajectory of MCP is arguably the fastest of any developer protocol in recent memory.
November 2024 — Launch
Anthropic open-sourced MCP on November 25, 2024, with SDKs in Python, TypeScript, Java, Kotlin, and C#. Claude Desktop became the first MCP host. Eleven pre-built server reference implementations were released the same day. Early adopters included Block (Square), Apollo, Zed, Replit, Codeium, and Sourcegraph.
Early 2025 — Industry Adoption
SDK downloads grew from ~100,000 at launch to 8 million by April 2025. The defining moment came in March 2025: OpenAI officially adopted MCP, integrating it into the Agents SDK, Responses API, and ChatGPT desktop app. Google DeepMind's Demis Hassabis confirmed MCP support for Gemini the following month. Microsoft adopted MCP across Semantic Kernel, Azure OpenAI, and VS Code Copilot.
Three of the four largest AI companies had adopted a protocol originally created by the fourth — within six months of launch. This was not a market battle; it was convergence.
Mid-2025 — Security Incidents and Spec Updates
The July 2025 Replit incident (an MCP-enabled agent deleted an entire database) and multiple disclosed vulnerabilities prompted the community to prioritize security guidance. The June 2025 spec (version 2025-06-18) introduced Streamable HTTP transport with OAuth 2.1 authentication, replacing the older HTTP+SSE transport for remote deployments.
Late 2025 — Institutionalization
The official MCP Registry launched in September 2025 with ~2,000 initial entries. On the first anniversary (November 25, 2025), a major spec update added Tasks, elicitation URL mode, sampling with tools, and simplified authorization. The project had grown to 58 active spec maintainers, 2,900+ Discord members, and 100+ new contributors per week.
On December 9, 2025, Anthropic donated MCP to the Linux Foundation's Agentic AI Foundation (AAIF). The protocol is now co-governed by Anthropic, Block, OpenAI, AWS, Google Cloud, Microsoft, Okta, Hugging Face, GitHub, and others.
2026 — Enterprise Maturity
By early 2026: 6,400+ registered servers, 300+ client applications, an estimated 97 million monthly SDK downloads. MCP is the de facto standard for AI-to-tool connectivity. No competing standard has emerged with comparable adoption.
The 2026 MCP Roadmap
The AAIF published the 2026 MCP roadmap with four enterprise-readiness priorities:
Stateless and scalable transport — The current Streamable HTTP transport has gaps around horizontal scaling and stateless operation behind load balancers. The next-gen transport is being designed to work cleanly in cloud-native, ephemeral container environments.
Audit trails and observability — Standardized event logging and observability hooks so organizations can audit what MCP servers do, when, and on whose behalf. This is currently left to server implementers. See our AI agent observability guide for the broader picture.
Enterprise SSO integration — Formal integration with enterprise identity providers (Okta, Azure AD, Google Workspace) via OAuth 2.1 and SAML. MCP Server Cards will provide a standard .well-known URL for capability advertisement.
MCP Server Cards — A discovery mechanism letting AI clients find and evaluate MCP servers programmatically. This will enable marketplaces and automated server selection — the DNS of the MCP ecosystem.
Google's Agent-to-Agent (A2A) protocol works alongside MCP. Where MCP handles tool and data access, A2A handles communication between AI agents. The two protocols are designed to be complementary. See our MCP vs. A2A comparison for details.
How MCP Fits Into AI Agent Architecture
MCP is a tools and context layer — it solves the "how does the agent access things" problem. But an agent is more than just tool access.
Understanding where MCP fits in the full picture helps you design better systems:
Tool discovery and invocation, resource access, prompt templates, server-to-client sampling, user elicitation. The integration layer between agent and world.
Agent reasoning loop (ReAct, plan-and-execute), memory and context management, multi-agent orchestration, error handling and retries, observability.
MCP servers expose capabilities. Agent frameworks — like LangChain, LangGraph, or cowork.ink's orchestration layer — decide how to use those capabilities and when. The protocol and the framework are separate concerns.
For a deeper look at the full stack, see our AI agent architecture guide, our AI agent protocol stack breakdown, and our agent orchestration guide.
Getting Started with MCP
If You Want to Use Existing MCP Servers
- Install a supported MCP client — Claude Desktop or VS Code with Copilot are the easiest starting points.
- Browse the official MCP Registry or check our curated list of the best MCP servers.
- Follow the server's installation instructions — most are a single
npm installordocker runcommand. - Add the server config to your MCP client's settings file.
If You Want to Build an MCP Server
The official SDKs handle all protocol boilerplate. You define your tools (name, description, input schema, handler function) and the SDK manages the rest.
import { Server } from "@modelcontextprotocol/sdk/server/index.js";
import { StdioServerTransport } from "@modelcontextprotocol/sdk/server/stdio.js";
const server = new Server({ name: "my-server", version: "1.0.0" });
server.tool("get_weather", { city: z.string() }, async ({ city }) => {
const data = await fetchWeather(city);
return { content: [{ type: "text", text: data.summary }] };
});
await server.connect(new StdioServerTransport());
For a full walkthrough — including resources, prompts, remote deployment with Streamable HTTP, and testing — see our complete guide to building an MCP server.
What MCP Means for AI Teams
For engineering teams, MCP changes the economics of AI tooling in three ways.
No more bespoke integrations. Any MCP-compatible AI platform can use your existing MCP servers. Write the integration once; run it everywhere.
Composable agent systems. When your agents connect to tools via MCP, the tools are decoupled from the agents. You can swap AI models, upgrade servers independently, and compose complex workflows without rebuilding from scratch. This is the infrastructure layer that makes multi-agent systems practical at scale.
Shared capability layer. In a team context, MCP servers become shared infrastructure. The GitHub MCP server, the internal Postgres MCP server, the company knowledge base MCP server — all of it is available to every agent your team runs, through the same standardized interface. No one person hoards a prompt that connects to the database.
cowork.ink is built for exactly this model — a shared workspace where your team's AI agents run on top of a common set of configured tools and context, including MCP servers. Setup takes minutes. No prompt engineering required.
Conclusion
Model Context Protocol arrived at exactly the right moment. AI models had become powerful enough to take real actions in the world, but the infrastructure connecting them to tools was a fragmented mess of custom code.
MCP solved the N×M problem with a clean standard: three-tier architecture, five primitives, JSON-RPC 2.0. Every major AI platform adopted it within months. The Linux Foundation now governs it. The ecosystem has over 6,400 servers.
In 2026, the important question is no longer "should we use MCP?" — it is "how do we use MCP safely and at scale?" The 2026 roadmap (stateless transport, audit trails, enterprise SSO, Server Cards) is answering that question.
If your team is building AI workflows, MCP is the integration layer you should be building on. Start with the official docs, explore the server ecosystem, and understand the security landscape before deploying to production.
Get Started with cowork.ink
cowork.ink gives engineering teams a shared AI workspace with built-in support for MCP servers — so your whole team's agents connect to the same tools, with no per-person configuration.
Create your workspace, add your MCP servers once, and give every team member's AI agents access to your full toolstack. No credit card required.
For solo developers who prefer self-hosted, GoGogot offers a lightweight, open-source AI agent with 27 built-in tools — no MCP setup needed to get started, one Docker command to deploy.