technology
Model Context Protocol (MCP)
Also known as MCP
The Model Context Protocol (MCP) is an open-source standard for connecting AI applications to external data sources, tools and workflows.[1] Anthropic introduced it in November 2024,[2] and in December 2025 it became a founding project of the Linux Foundation's Agentic AI Foundation.[3]
Key facts
The Model Context Protocol is plumbing for AI agents. An agent that can only chat is limited; one that can read a company’s files, query a database or open a ticket can do work. MCP standardises those connections so that a tool built once can be used by many AI applications.[1][4]
Origins
Anthropic introduced MCP on 25 November 2024 as an open standard for connecting AI assistants to the systems where data lives, including content repositories, business tools and development environments.[2] It pitched the protocol as a replacement for fragmented, one-off integrations and released it with specifications, software development kits and ready-made servers for systems such as Google Drive, Slack and GitHub.[4]
How it works
MCP has two sides. Developers build servers that expose data and tools, and AI applications act as clients that connect to them.[1] The documentation lists what this makes possible, from agents reaching a user’s calendar and notes to coding tools generating an app from a design file.[1] Its own analogy is a USB-C port: one standard connector instead of a different cable for every device.[1] This fits the way agents work, calling tools and reacting to the results in a loop.[5]
In the protocol’s own terms, an AI application such as Claude Code or Claude Desktop is the host, and it creates one MCP client for each server it connects to.[6] MCP has two layers. The data layer is a JSON-RPC based protocol whose core primitives include tools, resources, prompts and notifications; the transport layer handles connections, message framing and authorization.[7] Servers can run locally, usually over the STDIO transport and serving a single client, or remotely over Streamable HTTP, typically serving many clients.[8]
Adoption and governance
MCP is no longer an Anthropic-only protocol. As of October 2026 it is supported by AI assistants including Claude and OpenAI‘s ChatGPT and by developer tools including Visual Studio Code and Cursor.[9] On 9 December 2025 the Linux Foundation formed the Agentic AI Foundation (AAIF) with MCP, Block’s goose agent framework and OpenAI’s AGENTS.md as founding projects.[3] Its platinum members at launch were AWS, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft and OpenAI.[10] The foundation said more than 10,000 MCP servers had been published by then.[11] The specification is versioned by date; the documentation in October 2026 is organised around version 2026-07-28.[12]
Security risks
Connecting agents to real systems creates new attack surfaces, and the MCP project publishes security best practices alongside its authorization specification.[13] The document warns that local MCP servers may have direct access to the user’s system and be reachable by other processes, which makes them attractive targets.[13] It also describes “confused deputy” attacks, in which attackers exploit MCP proxy servers that connect to third-party APIs.[14]
Why it matters for frontier AI
Agents are judged on long, multi-step tasks such as fixing real software issues on swe-bench or operating a desktop.[15][16] Shared connectors make it easier to give agents the tools those tasks need. They also widen what an agent can touch. Labs now report how well models resist prompt injection, malicious instructions hidden in content an agent reads; OpenAI reported 99.79% robustness on indirect attacks for GPT-6 Astra.[17]
Questions readers ask
What is MCP in simple terms?
An open standard that lets AI apps plug into files, databases, services and tools. Its documentation compares it to a USB-C port for AI applications.[1]
Who controls MCP?
Anthropic created it, but since December 2025 it has been a project of the Linux Foundation's Agentic AI Foundation, alongside OpenAI's AGENTS.md and Block's goose.[2][3]
Is MCP only for Claude?
No. As of October 2026 it is supported by AI assistants including Claude and ChatGPT and by developer tools such as Visual Studio Code and Cursor.[9]
How widely is MCP used?
When the Agentic AI Foundation launched in December 2025, the Linux Foundation said more than 10,000 MCP servers had been published.[11]
Sources
Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.
- [1]
The MCP documentation describes MCP as an open-source standard for connecting AI applications to data sources, tools and workflows, comparing it to a USB-C port for AI applications. confirmedas of 2026-10-10
- What is the Model Context Protocol (MCP)? · Model Context Protocol project (retrieved 2026-10-10)
- [2]
Anthropic introduced the Model Context Protocol (MCP) on 25 November 2024 as an open standard for connecting AI assistants to the systems where data lives, such as content repositories, business tools and development environments. confirmedas of 2024-11-25
- Introducing the Model Context Protocol · Anthropic · 2024-11-25 (retrieved 2026-10-10)
- [3]
On 9 December 2025 the Linux Foundation formed the Agentic AI Foundation (AAIF), with Anthropic's MCP, Block's goose and OpenAI's AGENTS.md as founding projects. confirmedas of 2025-12-09
- Linux Foundation Announces the Formation of the Agentic AI Foundation (AAIF) · Linux Foundation · 2025-12-09 · Press release headline and first paragraph (retrieved 2026-10-10)
- [4]
Anthropic said MCP was meant to replace fragmented, custom integrations with a single protocol, and launched it with specifications, SDKs and pre-built servers for systems such as Google Drive, Slack and GitHub. confirmedas of 2024-11-25
- Introducing the Model Context Protocol · Anthropic · 2024-11-25 (retrieved 2026-10-10)
- [5]
Anthropic describes agents as typically language models using tools based on feedback from their environment in a loop, checking results such as tool outputs or code execution at each step. confirmedas of 2024-12-19
- Building effective agents · Anthropic · 2024-12-19 (retrieved 2026-10-10)
- [6]
MCP uses a client-server architecture in which an MCP host, an AI application such as Claude Code or Claude Desktop, creates one MCP client for each MCP server it connects to. confirmedas of 2026-10-10
- MCP architecture overview · Model Context Protocol (retrieved 2026-10-10)
- [7]
MCP has a data layer, a JSON-RPC based protocol with core primitives such as tools, resources, prompts and notifications, and a transport layer that handles connections, message framing and authorization. confirmedas of 2026-10-10
- MCP architecture overview · Model Context Protocol (retrieved 2026-10-10)
- [8]
Local MCP servers using the STDIO transport typically serve a single client, while remote servers using the Streamable HTTP transport typically serve many. confirmedas of 2026-10-10
- MCP architecture overview · Model Context Protocol (retrieved 2026-10-10)
- [9]
As of October 2026 MCP is supported by AI assistants including Claude and ChatGPT and by developer tools including Visual Studio Code and Cursor. confirmedas of 2026-10-10
- What is the Model Context Protocol (MCP)? · Model Context Protocol project · Broad ecosystem support section (retrieved 2026-10-10)
- [10]
The Agentic AI Foundation's platinum members at launch were AWS, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft and OpenAI. confirmedas of 2025-12-09
- Linux Foundation Announces the Formation of the Agentic AI Foundation (AAIF) · Linux Foundation · 2025-12-09 · Membership section (retrieved 2026-10-10)
- [11]
At the Agentic AI Foundation's launch in December 2025, the Linux Foundation said more than 10,000 MCP servers had been published. confirmedas of 2025-12-09
- Linux Foundation Announces the Formation of the Agentic AI Foundation (AAIF) · Linux Foundation · 2025-12-09 · MCP project description (retrieved 2026-10-10)
- [12]
As of October 2026 the MCP documentation is organised around a specification version dated 2026-07-28. confirmedas of 2026-10-10
- What is the Model Context Protocol (MCP)? · Model Context Protocol project · Links to /docs/2026-07-28/ (retrieved 2026-10-10)
- [13]
MCP's security best-practices document warns that local MCP servers may have direct access to the user's system, making them attractive targets for attacks. confirmedas of 2026-10-10
- MCP Security Best Practices · Model Context Protocol (retrieved 2026-10-10)
- [14]
The MCP security document also describes "confused deputy" attacks, in which attackers exploit MCP proxy servers that connect to third-party APIs. confirmedas of 2026-10-10
- MCP Security Best Practices · Model Context Protocol (retrieved 2026-10-10)
- [15]
SWE-bench, published at ICLR 2024, contains 2,294 software engineering problems drawn from real GitHub issues and pull requests across 12 popular Python repositories. confirmedas of 2024-11-11
- SWE-bench: Can Language Models Resolve Real-World GitHub Issues? · arXiv (Jimenez et al.; ICLR 2024) · 2023-10-10 · Abstract (the arXiv page renders the counts in LaTeX as $2,294$ and $12$) (retrieved 2026-10-10)
- SWE-bench Lite · SWE-bench (retrieved 2026-10-10)
- [16]
OSWorld, a 2024 benchmark of 369 real computer tasks across operating systems, found humans succeeded on 72.36% of tasks against 12.24% for the best AI model at the time. confirmedas of 2024-04-11
- OSWorld: Benchmarking Multimodal Agents for Open-Ended Tasks in Real Computer Environments · arXiv (Xie et al.) · 2024-04-11 · Abstract (retrieved 2026-10-10)
- [17]
OpenAI reported 99.79% robustness for GPT-6 Astra against indirect prompt-injection attacks in its evaluations. confirmedas of 2026-09-03
- GPT-6 Astra system card · OpenAI Deployment Safety Hub · 2026-09-03 (retrieved 2026-10-10)
Revision history (2)
Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.
Cite this page
"Model Context Protocol (MCP)." ContentLora, updated Oct 10, 2026. https://contentlora.com/wiki/model-context-protocol
Spotted an error? Suggest a correction or emailcorrections@contentlora.com.
Keep exploring
- ExplainerHow AI agents workWhat an AI agent is and how it works: language models using tools in a loop, computer use, MCP connectors and long tasks.
- ExplainerFrontier AI in 2026: a crash courseA crash course on frontier AI in 2026: how reasoning models and AI agents work, who builds them, and where the frontier stands now.
- AnalysisHow fast are AI agents really improving?AI agents' task horizons are doubling every few months on benchmarks, but real-world gains are harder to measure. The evidence, weighed.
- WikiSWE-benchSWE-bench tests whether AI can fix real GitHub issues. How it works, its Verified subset, and how scores rose from 2% to near 100%.
- WikiTest-time computeTest-time compute is the computing power an AI model spends while answering. Spending more of it is how reasoning models improve.
- ExplainerHow large language models workA plain guide to large language models: the Transformer, scaling laws and human-feedback training, at beginner and expert level.