Skip to content
ContentLora

    Tip: press / anywhere to search.

    technology

    Model Context Protocol (MCP)

    Also known as MCP

    The Model Context Protocol (MCP) is an open-source standard for connecting AI applications to external data sources, tools and workflows.[1] Anthropic introduced it in November 2024,[2] and in December 2025 it became a founding project of the Linux Foundation's Agentic AI Foundation.[3]

    Editor reviewedUpdated Frontier AIArtificial intelligenceComputing
    Key facts

    The Model Context Protocol is plumbing for AI agents. An agent that can only chat is limited; one that can read a company’s files, query a database or open a ticket can do work. MCP standardises those connections so that a tool built once can be used by many AI applications.[1][4]

    Origins

    Anthropic introduced MCP on 25 November 2024 as an open standard for connecting AI assistants to the systems where data lives, including content repositories, business tools and development environments.[2] It pitched the protocol as a replacement for fragmented, one-off integrations and released it with specifications, software development kits and ready-made servers for systems such as Google Drive, Slack and GitHub.[4]

    How it works

    MCP has two sides. Developers build servers that expose data and tools, and AI applications act as clients that connect to them.[1] The documentation lists what this makes possible, from agents reaching a user’s calendar and notes to coding tools generating an app from a design file.[1] Its own analogy is a USB-C port: one standard connector instead of a different cable for every device.[1] This fits the way agents work, calling tools and reacting to the results in a loop.[5]

    In the protocol’s own terms, an AI application such as Claude Code or Claude Desktop is the host, and it creates one MCP client for each server it connects to.[6] MCP has two layers. The data layer is a JSON-RPC based protocol whose core primitives include tools, resources, prompts and notifications; the transport layer handles connections, message framing and authorization.[7] Servers can run locally, usually over the STDIO transport and serving a single client, or remotely over Streamable HTTP, typically serving many clients.[8]

    Adoption and governance

    MCP is no longer an Anthropic-only protocol. As of October 2026 it is supported by AI assistants including Claude and OpenAI‘s ChatGPT and by developer tools including Visual Studio Code and Cursor.[9] On 9 December 2025 the Linux Foundation formed the Agentic AI Foundation (AAIF) with MCP, Block’s goose agent framework and OpenAI’s AGENTS.md as founding projects.[3] Its platinum members at launch were AWS, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft and OpenAI.[10] The foundation said more than 10,000 MCP servers had been published by then.[11] The specification is versioned by date; the documentation in October 2026 is organised around version 2026-07-28.[12]

    Security risks

    Connecting agents to real systems creates new attack surfaces, and the MCP project publishes security best practices alongside its authorization specification.[13] The document warns that local MCP servers may have direct access to the user’s system and be reachable by other processes, which makes them attractive targets.[13] It also describes “confused deputy” attacks, in which attackers exploit MCP proxy servers that connect to third-party APIs.[14]

    Why it matters for frontier AI

    Agents are judged on long, multi-step tasks such as fixing real software issues on swe-bench or operating a desktop.[15][16] Shared connectors make it easier to give agents the tools those tasks need. They also widen what an agent can touch. Labs now report how well models resist prompt injection, malicious instructions hidden in content an agent reads; OpenAI reported 99.79% robustness on indirect attacks for GPT-6 Astra.[17]

    Questions readers ask

    What is MCP in simple terms?

    An open standard that lets AI apps plug into files, databases, services and tools. Its documentation compares it to a USB-C port for AI applications.[1]

    Who controls MCP?

    Anthropic created it, but since December 2025 it has been a project of the Linux Foundation's Agentic AI Foundation, alongside OpenAI's AGENTS.md and Block's goose.[2][3]

    Is MCP only for Claude?

    No. As of October 2026 it is supported by AI assistants including Claude and ChatGPT and by developer tools such as Visual Studio Code and Cursor.[9]

    How widely is MCP used?

    When the Agentic AI Foundation launched in December 2025, the Linux Foundation said more than 10,000 MCP servers had been published.[11]

    Sources

    Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.

    1. [1]

      The MCP documentation describes MCP as an open-source standard for connecting AI applications to data sources, tools and workflows, comparing it to a USB-C port for AI applications. confirmedas of 2026-10-10

    2. [2]

      Anthropic introduced the Model Context Protocol (MCP) on 25 November 2024 as an open standard for connecting AI assistants to the systems where data lives, such as content repositories, business tools and development environments. confirmedas of 2024-11-25

    3. [3]

      On 9 December 2025 the Linux Foundation formed the Agentic AI Foundation (AAIF), with Anthropic's MCP, Block's goose and OpenAI's AGENTS.md as founding projects. confirmedas of 2025-12-09

    4. [4]

      Anthropic said MCP was meant to replace fragmented, custom integrations with a single protocol, and launched it with specifications, SDKs and pre-built servers for systems such as Google Drive, Slack and GitHub. confirmedas of 2024-11-25

    5. [5]

      Anthropic describes agents as typically language models using tools based on feedback from their environment in a loop, checking results such as tool outputs or code execution at each step. confirmedas of 2024-12-19

    6. [6]

      MCP uses a client-server architecture in which an MCP host, an AI application such as Claude Code or Claude Desktop, creates one MCP client for each MCP server it connects to. confirmedas of 2026-10-10

    7. [7]

      MCP has a data layer, a JSON-RPC based protocol with core primitives such as tools, resources, prompts and notifications, and a transport layer that handles connections, message framing and authorization. confirmedas of 2026-10-10

    8. [8]

      Local MCP servers using the STDIO transport typically serve a single client, while remote servers using the Streamable HTTP transport typically serve many. confirmedas of 2026-10-10

    9. [9]

      As of October 2026 MCP is supported by AI assistants including Claude and ChatGPT and by developer tools including Visual Studio Code and Cursor. confirmedas of 2026-10-10

    10. [10]

      The Agentic AI Foundation's platinum members at launch were AWS, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft and OpenAI. confirmedas of 2025-12-09

    11. [11]

      At the Agentic AI Foundation's launch in December 2025, the Linux Foundation said more than 10,000 MCP servers had been published. confirmedas of 2025-12-09

    12. [12]

      As of October 2026 the MCP documentation is organised around a specification version dated 2026-07-28. confirmedas of 2026-10-10

    13. [13]

      MCP's security best-practices document warns that local MCP servers may have direct access to the user's system, making them attractive targets for attacks. confirmedas of 2026-10-10

    14. [14]

      The MCP security document also describes "confused deputy" attacks, in which attackers exploit MCP proxy servers that connect to third-party APIs. confirmedas of 2026-10-10

    15. [15]

      SWE-bench, published at ICLR 2024, contains 2,294 software engineering problems drawn from real GitHub issues and pull requests across 12 popular Python repositories. confirmedas of 2024-11-11

    16. [16]

      OSWorld, a 2024 benchmark of 369 real computer tasks across operating systems, found humans succeeded on 72.36% of tasks against 12.24% for the best AI model at the time. confirmedas of 2024-04-11

    17. [17]

      OpenAI reported 99.79% robustness for GPT-6 Astra against indirect prompt-injection attacks in its evaluations. confirmedas of 2026-09-03

    Revision history (2)
    1. Page created.
    2. Added MCP's architecture (hosts, clients and servers; data and transport layers; local and remote servers) and the security risks set out in its best-practices document.

    Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.

    Cite this page

    "Model Context Protocol (MCP)." ContentLora, updated Oct 10, 2026. https://contentlora.com/wiki/model-context-protocol

    Spotted an error? Suggest a correction or emailcorrections@contentlora.com.