MCP (Model Context Protocol): a complete overview — how to connect AI to your data
What MCP is and why Claude, ChatGPT and other assistants support it: how the protocol works, 8 scenarios, a comparison with other ways to give AI access to data, security, limits and server code examples.
In short
MCP (Model Context Protocol) is an open standard for connecting AI assistants to data and tools: Claude, ChatGPT, Gemini, VS Code and Cursor speak it. A company writes one MCP server — for its CRM, warehouse, database or documents — and any compatible assistant can read the data and perform actions within the rights it was given, instead of people copying tables into a chat. Anthropic introduced MCP in November 2024; since December 2025 it is developed in the Agentic AI Foundation under the Linux Foundation. The main thing to get right is security: the server decides what the model may see and do, writes need confirmation, and every call goes to the log.
MCP at a glance
The main facts in one table — where the protocol came from, what it consists of and who supports it.
- What it is
- An open protocol for connecting AI applications to data and tools
- Comparison
- “USB-C for AI”: one connector instead of a separate integration for each assistant
- History
- Introduced by Anthropic in November 2024
- Governance
- Since December 2025 — the Agentic AI Foundation under the Linux Foundation
- Parts
- Host (the AI application), client (the connection), server (your system)
- What a server offers
- Tools (actions), resources (data to read), prompts (ready templates)
- Messages
- JSON-RPC 2.0
- Transport
- stdio on the same machine, Streamable HTTP over the network
- Authorisation
- OAuth 2.1 for remote servers
- SDKs
- TypeScript, Python, Go, Java, Kotlin, C#, Rust, PHP, Ruby, Swift
- Supported by
- Claude, ChatGPT, Gemini CLI, VS Code, Cursor and many other tools
How MCP works, in plain words
An assistant by itself knows nothing about your company. MCP gives it hands and eyes: a server describes what is available — “find an order by number”, “show stock”, “read the delivery terms” — and the assistant decides during a conversation which of these to use. The model does not get a password to your database; it gets a list of allowed actions.
Because the protocol is the same everywhere, one server works with Claude, ChatGPT and a code editor at once. Before MCP every assistant needed its own integration; now the integration is written once, and the choice of assistant stays free.
- A list of actions, not a password
- One server for every assistant
- The rights are set by you
What MCP is used for: 8 scenarios
From a staff assistant to your own product that other assistants can work with.
-
01
An assistant for staff
“What is the status of order 1042?”, “How many A-100 are left?” — answers from real data.
-
02
Questions to the database
“How many orders came yesterday from ads?” — the assistant builds a read-only query.
-
03
Knowledge base and documents
Rules, contracts and instructions are found and quoted with a link to the source.
-
04
Actions in systems
Create a task in the CRM, draft a reply, update a status — with a person confirming.
-
05
Development
Claude Code and Cursor read the repository, the database schema and the documentation.
-
06
Support
The assistant sees the customer’s history and orders before suggesting a reply.
-
07
Agentic workflows
An agent goes through several systems step by step using their MCP servers.
-
08
Your product for other assistants
A SaaS publishes an MCP server, and its customers work with it from their own Claude or ChatGPT.
MCP compared with copying into a chat, an API integration and function calling
Four ways to give a model access to company data.
| Criterion | MCP | Copying into a chat | Own integration per assistant | Function calling in your app |
|---|---|---|---|---|
| Works with | any compatible assistant | any chat | one assistant | your own application |
| Fresh data | always current | as of copying | current | current |
| Control over access | rights and a log on the server | none: the data has left | depends on the integration | in your code |
| Changing the assistant | without rework | — | a new integration | code changes |
| Best for | staff and agents working with company systems | a one-off question | legacy setups | an AI feature inside your product |
MCP security: what to set up first
An MCP server is a door into your systems. These rules decide who comes in and what they can touch.
-
01
The fewest rights possible
The server works under its own account with access only to what the task needs.
-
02
Reading by default
Actions that change data are added consciously, one by one.
-
03
Confirmation for writes
Payments, sending to customers and deleting only after a person says yes.
-
04
A log of every call
Who asked, which tool was called, with what arguments and what was returned.
-
05
Distrust of tool results
Text from a document or an email can contain instructions for the model — prompt injection. The server does not grant extra rights because of them.
-
06
Only trusted servers
A random MCP server from the internet gets the same access as your own — check the code before connecting.
-
07
Keys on the server side
Passwords to systems never reach the model — they live in the server’s environment.
-
08
Access you can withdraw
OAuth tokens with limited scope and a lifetime, revoked in one click.
When MCP is worth it — and when not
Ten typical situations with a verdict.
-
Staff ask about orders and stock
Best fitAnswers from real data in a familiar assistant.
-
Questions to the database without SQL
Best fitRead-only access to a prepared view of the data.
-
An internal knowledge base
Best fitDocuments are found and quoted with a link to the source.
-
Development with AI tools
Best fitThe editor sees the schema, the tasks and the documentation.
-
A SaaS that customers use from their assistants
Best fitA public MCP server with OAuth becomes a new channel.
-
Actions that change data
WorksYes, with confirmation and a log; start with reading.
-
Agents across several systems
WorksYes, with limits on steps and approval of important ones.
-
An AI feature inside your own product
WorksOften plain function calling in your code is simpler.
-
A chatbot for site visitors
Pick anotherVisitors do not bring their own assistants; build the bot into the site.
-
A one-off question
Pick anotherA server is overkill; an export without personal data is enough.
The limits of MCP and common mistakes
-
Giving the model the whole database
A tool “run any SQL” turns one prompt injection into a leak. Prepared queries and views are safer.
-
Too many tools
Dozens of similar tools confuse the model; a few clear ones with good descriptions work better.
-
Vague descriptions
The model chooses a tool by its description — “gets data” tells it nothing.
-
Huge answers
A tool that returns ten thousand rows eats the context and the budget. Filter and paginate on the server.
-
Writes without confirmation
A model can misunderstand. Irreversible actions need a person.
-
No log
Without it you cannot tell what the assistant did and why.
How to bring MCP into a company
Start small and safe, then widen.
-
Choose questions
Which questions staff ask most often and which systems hold the answers.
-
Reading first
A server with a few read-only tools and resources.
-
Rights and log
A service account, a log of calls, keys in the environment.
-
Pilot with a team
A few people use it for real work; the log shows what is asked.
-
Actions with confirmation
Writes are added one by one, each with a confirmation.
What an MCP server looks like: 3 examples
A tool, a resource and connecting the server to an assistant. Written with the official TypeScript SDK, checked by TypeScript 7 and called by a real MCP client.
A tool: stock by SKU
The assistant calls it during a conversation; a wrong argument is rejected by the schema before the code runs.
import { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js';
import { StdioServerTransport } from '@modelcontextprotocol/sdk/server/stdio.js';
import { z } from 'zod';
// stock lives in your system; here it is a small table for the example
const stock: Record<string, number> = { 'A-100': 8, 'B-200': 0 };
const server = new McpServer({ name: 'shop', version: '1.0.0' });
// a tool: the assistant may call it, and the schema checks the arguments
server.registerTool(
'get_stock',
{
title: 'Stock by SKU',
description: 'How many items of a product are in stock',
inputSchema: { sku: z.string().describe('Product SKU, for example A-100') },
annotations: { readOnlyHint: true },
},
async ({ sku }) => {
const qty = stock[sku];
const text = qty === undefined ? `No product ${sku}` : `${sku}: ${qty} pcs`;
return { content: [{ type: 'text', text }] };
},
);
await server.connect(new StdioServerTransport());
A resource: a document to read
Reading without the right to change — the safest thing to start with.
import { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js';
import { StdioServerTransport } from '@modelcontextprotocol/sdk/server/stdio.js';
const server = new McpServer({ name: 'docs', version: '1.0.0' });
// a resource: a document the assistant can read but cannot change
server.registerResource(
'delivery-terms',
'docs://delivery-terms',
{ title: 'Delivery terms', mimeType: 'text/markdown' },
async (uri) => ({
contents: [{ uri: uri.href, text: '# Delivery\nCourier: 1–2 days. Pickup: the same day.' }],
}),
);
await server.connect(new StdioServerTransport());
Connecting the server to an assistant
Settings in the format of Claude Desktop and Claude Code: the key lives in the server’s environment, not in the chat.
{
"mcpServers": {
"shop": {
"command": "node",
"args": ["/srv/mcp/shop.js"],
"env": { "SHOP_API_KEY": "key-for-read-only-access" }
}
}
}
Questions about MCP
What is MCP in simple terms?
A common language in which AI assistants talk to your systems: the server lists what may be done, and the assistant uses it during a conversation.
Does ChatGPT support MCP or only Claude?
Both, as well as Gemini CLI, VS Code, Cursor and many other tools. That is the point of the standard.
Is it safe to connect AI to company data?
As safe as the server is set up: minimal rights, reading by default, confirmation for writes and a log. Copying data into a chat by hand is less safe.
Does the model learn on our data?
MCP itself does not send data for training; it depends on the terms of the assistant’s plan. Business and API plans usually forbid training on customer data.
What language are MCP servers written in?
There are official SDKs for TypeScript, Python, Go, Java, Kotlin, C#, Rust, PHP, Ruby and Swift.
What is the difference between a tool and a resource?
A tool is an action the model decides to call; a resource is data the application gives the model to read.
Local or remote server?
A local server runs on the employee’s computer through stdio; a remote one runs on your server over HTTP with OAuth — better for a team.
Can we connect our CRM and accounting system?
Yes, if they have an API or a database you can read: the MCP server sits between them and the assistant.
Online form
Connect AI
to your data
I build MCP servers: Claude or ChatGPT get access to your orders, stock and documents — with rights, a log of every call and access you can withdraw at any moment. Tell me about the systems — I answer within one working day.