Three letters have been turning up in nearly every AI launch this year. A voice company ships "an MCP server". A payments giant makes its merchants "MCP-ready". Your developer mentions it twice in a stand-up and you nod along. Nobody stops to say what it is.

So here it is, without the diagrams. MCP stands for Model Context Protocol, and it is the reason an AI assistant can now do something in your actual tools rather than just describe how you might do it yourself. This guide covers what MCP is, how it works, how to switch one on this afternoon, and the security question that most explainers skip.

The problem MCP was built to solve

A language model on its own is a very well read colleague locked in a room with no phone. It can reason about your calendar. It cannot open it.

For the first few years, every company solved that separately. Anthropic built a Google Drive integration. OpenAI built a different Google Drive integration. Cursor built a third. Then Notion, Slack, Stripe and everyone else needed the same treatment, from every assistant. The maths is brutal: ten assistants and a hundred services means a thousand bespoke integrations, each one maintained by somebody who would rather be doing something else.

Anthropic published MCP as an open standard in November 2024 to collapse that grid. Build one server for your service and every MCP-speaking assistant can use it. Build one client into your assistant and it can reach every MCP server ever written. The usual analogy is USB-C, and for once the analogy earns its place: one connector, many devices, nobody arguing about cables.

How MCP actually works

Hosts, clients and servers

Three pieces, and the naming is unhelpful, so take it slowly.

The host is the app you are looking at: Claude Desktop, ChatGPT, Cursor, VS Code. Inside that host sits an MCP client, the bit that speaks the protocol. At the other end, an MCP server sits in front of a service and describes what it can do in a format the client understands.

The word "server" causes most of the confusion. An MCP server is usually not a machine in a data centre. It is often a small program running on your own laptop, or a URL a vendor hosts for you. The GitHub MCP server is not GitHub. It is a translator that stands next to GitHub and explains it to models.

Tools, resources and prompts

A server can offer three things. Tools are actions the model can take, such as sending a message or creating a file. Resources are things it can read, such as a document or a database row. Prompts are pre-written instructions the server suggests for common jobs.

When you open a chat, the client asks each connected server what it offers. The server sends back a list with plain-language descriptions. Those descriptions land in the model's context, which is exactly why the security section below matters. The model then decides which tool fits your request, calls it, and reads the result. You approve the ones that change something.

The short version: MCP is a menu format. Servers publish menus of what they can do, clients read those menus, and the model orders from them. Everything else is plumbing.

Who backs MCP now, and why that matters

Open standards published by one company usually die quietly. This one did not.

OpenAI shipped full MCP client support in ChatGPT in late 2025. Google followed with official support across its own services and a managed remote server for Gemini in mid-2026. Microsoft, AWS, Salesforce, Snowflake and most of the API gateway vendors are in. In late 2025 Anthropic handed the protocol to the Agentic AI Foundation under the Linux Foundation, with OpenAI and Block as co-founders and the rest as supporting members.

That governance move is the part worth registering. It means MCP is no longer a Claude feature that competitors tolerate. It is neutral infrastructure with rivals sitting on the same committee, which is roughly how HTTP and USB ended up everywhere.

The usage numbers say the same thing more bluntly. The official TypeScript and Python SDKs have each passed a billion cumulative downloads, with close to half a billion a month across the main SDKs. Wiz Research found MCP servers running in at least 80 per cent of the cloud environments it observed in early 2026. Reported enterprise adoption figures vary a lot by who is doing the counting, so treat any single percentage with suspicion, but the direction is not in doubt.

You can watch it hardening into commercial plumbing in the daily news. In August, ElevenLabs shipped an MCP server that manages voice agents from inside Claude, and a day later Alipay used MCP as the merchant integration surface for its agentic commerce platform, with KFC, Luckin Coffee and 16 carmakers already wired in. When a payments network picks your protocol as the way shops talk to shopping agents, the standards argument is over.

How to turn an MCP server on today, without writing code

This is the part people assume is out of reach. It is not.

In Claude Desktop, click the plus button beside the chat input and choose Connectors. You get a directory of pre-built servers: Google Drive, GitHub, Notion, Slack and a long tail of others. Install one, restart, and check the tool icon at the bottom of a new chat. A number next to it means the tools loaded. Click it to see exactly what the assistant can now do. Claude also supports packaged extensions that install with a double click, which removed the config-file editing that used to put people off.

In ChatGPT, the equivalent lives under connectors in settings, with a similar directory of vendor-built options.

Start with a service where a mistake is cheap and the payoff is obvious. Connecting a read-only document store is a good first move. Connecting anything that can send messages to customers or move money is not, at least not on day one.

Then ask for something that genuinely needs the connection. "Find the three most recent contract drafts in my Drive and tell me where the payment terms differ" is a real test. "What can you do now?" is not, because the model will happily read its own menu back to you and you will learn nothing.

Getting useful answers out of a connected assistant is still mostly a prompting problem, and the habits carry over unchanged from ordinary chat. Our guide to prompt engineering basics covers the techniques that matter most once a model can actually act on what you ask.

What changed in the July 2026 specification

The specification is versioned by date, and the 2026-07-28 release was the biggest revision so far. The headline change is a stateless protocol core, which sounds like an implementation detail and is actually the thing that makes MCP deployable at scale.

Earlier versions assumed a long-lived connection between client and server. That is fine on a laptop and awkward on the internet, where requests get load-balanced across machines that know nothing about each other. Going stateless means MCP servers can run behind ordinary web infrastructure like any other HTTP service.

Alongside it came multi round-trip requests, header-based routing, cacheable list results, a formal extensions framework, and hardening of the authorisation model. The practical translation: MCP stopped being a clever desktop trick and became something a company can put in production without inventing its own scaffolding.

The security part, which you should not skip

Here is the honest bit that vendor explainers tend to bury. MCP standardises how tools are described and called. It deliberately leaves authentication, authorisation and transport security to whoever builds each host, client and server. That is a reasonable design choice and it means the safety of any given setup depends entirely on the people who wrote it.

The attack that matters most is tool poisoning, a form of indirect prompt injection. Remember that a server's tool descriptions and responses land directly in the model's context. A malicious or compromised server can hide instructions in that text. The model reads them as trusted input and may act on them, calling other tools, leaking data from a different connector, or working around its own system prompt. The user sees a normal-looking answer.

The scanning data is not comforting. Security researchers looking at large samples of public servers this year found tool poisoning in roughly five per cent of them, command injection weaknesses in a much larger share of those tested, and some security finding in the clear majority. OWASP now carries a dedicated MCP tool poisoning entry, and US government security agencies published design guidance for the protocol in June 2026. Wiz also found that about five per cent of environments running MCP had at least one server exposed directly to the internet, which is almost never what anyone intended.

Four rules that cover most of the risk:

What MCP is not

It is not an agent. MCP gives a model hands. Deciding what to do with them is the agent framework's job, or yours.

It is not a replacement for APIs. Nearly every MCP server is a thin layer in front of an existing API. The API still does the work. MCP just makes it legible to a model.

It is not a model feature. Nothing about MCP requires a smarter model. A capable one uses tools better, but the protocol is indifferent to which model is on the other end.

It is not automatically a productivity win. Connecting six servers to an assistant that you were already struggling to prompt gives you a well connected disappointment. Pick tools that map to jobs you actually repeat, the same discipline we argue for in the guide to AI tools for product managers.

Frequently asked questions

What is MCP in simple terms?

MCP, the Model Context Protocol, is an open standard that lets an AI assistant use tools and data that live outside the chat window: your files, your calendar, a database, a design tool. Instead of every AI product building a bespoke integration for every service, both sides speak one shared protocol.

Is MCP only for Claude?

No. Anthropic created it in November 2024, but it is now governed by the Agentic AI Foundation under the Linux Foundation, with OpenAI, Google, Microsoft, AWS and others supporting it. ChatGPT, Gemini, Copilot, Cursor and most agent frameworks can act as MCP clients.

Do I need to be a developer to use MCP?

Not any more. Claude Desktop and ChatGPT both ship directories of pre-built connectors you install with a click, and Claude supports packaged extensions that install like an app. Writing your own server needs code. Using someone else's usually does not.

What is the difference between MCP and an API?

An API is one company's door into one service, and each has its own shape. MCP is a standard way for a model to discover what doors exist, read what each one does, and knock on the right one. Most MCP servers are thin wrappers sitting in front of an existing API.

Is MCP safe to use at work?

It depends entirely on which server you install. The protocol standardises how tools are described and called, but leaves authentication and transport security to whoever built the server. Install from official vendor sources, give each server the narrowest permissions that work, and get IT to look before you connect anything to company data.

Does MCP cost anything?

The protocol is free and open source, and most public servers are free to run. What you pay for is the AI subscription that hosts the client and the underlying service the server connects to. Running agents against tools also burns more tokens than plain chat.

What to take from this

MCP is not a product you buy, it is the wiring that decides whether your AI assistant is a writing tool or a coworker with access. The interesting question is no longer whether the standard wins, because that argument closed some time around the Linux Foundation handover. It is which two or three of your systems are worth connecting first, and whether you trust the server sitting in front of them. Start with one read-only connector, ask it something you genuinely need, and pay attention to what it gets wrong.

The protocol war is over. The interesting bit starts now.

We track what actually ships, connector by connector, every weekday morning before 8am. No hype, no thread summaries, just what changed and whether it matters.

You're in. First issue lands tomorrow morning.