AI Agent Concepts

What Is the Model Context Protocol (MCP)?

The Model Context Protocol (MCP) is an open standard that defines how AI applications connect to external tools, data sources, and systems through a common interface. Often described as "a USB-C port for AI," it lets any MCP-compatible model use any MCP server, replacing one-off custom integrations with a reusable, standardized connection.

  • Protocols & Interop
  • 11 min read
  • Updated September 27, 2026
  • VDF AI Team
01
In short

The Model Context Protocol (MCP) is an open standard that defines how AI applications connect to external tools, data sources, and systems through a common interface. Often described as "a USB-C port for AI," it lets any MCP-compatible model use any MCP server, replacing one-off custom integrations with a reusable, standardized connection.

Key takeaways

  • 01 MCP is an open standard for connecting AI models to tools and data via a common protocol.
  • 02 It replaces brittle, bespoke integrations with reusable MCP servers any compatible client can use.
  • 03 It separates the AI application (the host and its clients) from the capability (the MCP server), improving portability and reuse.
  • 04 An MCP server exposes tools, resources and prompts over stdio for local use or Streamable HTTP for remote use, with OAuth 2.1 defined for HTTP authorization.
  • 05 For enterprises, MCP must be wrapped in governance — authentication, permissions, and audit on every server.
02

MCP, defined

The Model Context Protocol is a specification for how AI systems talk to the outside world. It standardizes the way a model or agent discovers and invokes external capabilities — reading a file, querying a database, calling an API — so the connection looks the same regardless of which model or which tool is involved.

The common analogy is a universal port. Before USB, every device needed its own connector; afterward, one standard worked everywhere. MCP aims to do the same for AI integrations: build a capability once as an MCP server, and any MCP-aware client can use it without custom glue code.

03

How MCP works: hosts, clients and servers

At run time the flow is short. The AI application connects to one or more MCP servers, asks each one what it offers, and hands the resulting tool descriptions to the model. When the model decides to use a tool, the application routes the call to the right server, receives the result and adds it to the model’s context. Servers can offer readable resources and reusable prompt templates alongside their tools.

Because the interface is standardized, the model does not need to know the internals of each integration. It asks the server what tools exist and calls them through the protocol. This is closely related to tool use and function calling — MCP is, in effect, a standard transport and discovery layer for tools.

04

What is an MCP server?

An MCP server is a program that exposes capabilities to AI applications through the Model Context Protocol. According to the specification, it can offer any mix of three primitives: tools, functions the model may ask to run; resources, data and context for the user or model to read; and prompts, templated messages and workflows. A repository server, for instance, might publish “create issue” as a tool and a README file as a resource.

The specification names three roles. The host is the AI application the person works in, such as a chat app, an IDE or an agent, and it enforces consent and security policy. Inside the host, each client is a connector that talks to exactly one server. The server provides a focused set of capabilities and, by design, should not be able to read the whole conversation or see into other servers; the host controls anything that passes between them (MCP architecture). A server can be a local process or a remote service.

Two standard transports carry the JSON-RPC 2.0 messages. With stdio, the client launches the server as a subprocess and exchanges newline-delimited messages over standard input and output, which suits tools on the same machine. With Streamable HTTP, each message is an HTTP POST to a single MCP endpoint and replies arrive as a JSON object or a request-scoped server-sent-events stream, which suits shared and remote servers (transport spec). The revision current in September 2026, dated 2026-07-28, also makes the protocol stateless: every request carries its own protocol version and client capabilities.

Authorization is optional in MCP but specified in detail for HTTP transports. A protected server acts as an OAuth 2.1 resource server, must publish OAuth Protected Resource Metadata (RFC 9728) so clients can find its authorization server, and must accept only access tokens issued with it as the audience, never accepting or passing through tokens meant for anything else. A server on stdio should take its credentials from the environment instead (authorization spec). None of this decides which agent may call which tool. That policy is left to the host and to the organization running it.

05

Official MCP servers and where to find MCP documentation

The canonical documentation lives at modelcontextprotocol.io: the dated specification revisions, the architecture and security pages, and guides for building servers and clients. When a tutorial and the specification disagree, the specification wins, so check which revision a server claims to implement before relying on a feature.

The modelcontextprotocol/servers repository holds a small set of reference servers maintained by the MCP steering group: Everything, Fetch, Filesystem, Git, Memory, Sequential Thinking and Time. Its README states that they are educational reference implementations rather than production-ready solutions, and it sends readers looking for other servers to the official MCP Registry, which lists published servers and their versions.

Many vendors now maintain their own servers. GitHub’s github-mcp-server can be used as a GitHub-hosted remote endpoint or run locally in Docker, signs in with OAuth or a personal access token, and supports toolset selection and a read-only mode. Microsoft keeps a catalog of its official MCP servers spanning Azure, Microsoft Learn, Microsoft 365, Fabric, SQL and security products. The enterprise MCP server roundup compares the servers teams ask about most (verified September 2026).

Before connecting any server, read its documentation for three things: which tools can write or delete, how it authenticates and where tokens are stored, and whether it can run inside your own network. A server that exists only as a vendor-hosted endpoint sends every tool call, and the data in it, to that vendor. The MCP gateway page explains how to register and restrict servers centrally.

06

Why MCP matters

Before standards like MCP, every model-to-tool connection was bespoke: N models times M tools meant a combinatorial explosion of custom integrations, each maintained separately. MCP collapses that to N + M — build each server and client once against the protocol.

The payoff is portability and reuse. Tools built for one agent work with another; swapping the underlying model does not break integrations; and an ecosystem of shared MCP servers reduces the work of connecting AI to real systems. For agent builders, it means less plumbing and more time on actual behavior.

07

MCP in the enterprise: governance required

MCP standardizes connection, not control. An MCP server can expose powerful actions — and a manipulated agent that can reach it could do real damage. So in enterprise settings, MCP must be wrapped in authentication, least-privilege permissions, input validation, and audit logging on every server.

The deployment question also matters: connecting agents to internal systems via MCP means those connections, and the data flowing through them, should stay inside controlled infrastructure. MCP is a powerful enabler, but the responsibility for who can call what — and proving it afterward — sits with the platform around it.

08

Custom Integrations vs MCP

MCP turns N×M bespoke connectors into reusable, standardized servers and clients.

DimensionCustom IntegrationsMCP (Model Context Protocol)
ConnectionBespoke per model and toolOne standard interface
ReuseLow — rebuilt each timeHigh — servers shared across clients
Model portabilityIntegrations break on model swapModel-agnostic by design
MaintenanceN×M connectorsN clients + M servers
DiscoveryHard-codedServers advertise their capabilities
GovernancePer-integration, ad hocStill required — auth, scope, audit per server
09
How VDF AI fits

From concept to a governed, on-premise reality

VDF AI embraces open standards like MCP while adding the governance enterprises need. Agents can connect to MCP tools and data sources, but every connection runs under scoped permissions, authentication, and full audit on infrastructure you control.

On VDF AI Networks, standardized tool access via MCP is combined with policy enforcement and observability — the practical way to get the interoperability benefits of MCP without exposing internal systems to ungoverned agents. See the MCP integration playbook.

10

Frequently asked questions

What is the Model Context Protocol (MCP)?

An open standard that defines how AI models and agents connect to external tools, data, and systems through a common interface — so any compatible model can use any compatible tool without custom integration code.

Why is MCP compared to a USB-C port?

Because it is a universal connector. Just as USB-C lets any device connect through one standard, MCP lets any AI client connect to any MCP server, replacing bespoke per-tool integrations with one reusable interface.

How does MCP work?

MCP servers expose capabilities — tools, resources, and prompts. An MCP client inside an AI application connects to servers, discovers what they offer, and invokes them on the model's behalf, all through the standardized protocol.

What is an MCP server?

An MCP server is a program that makes tools, data and prompt templates available to AI applications through the Model Context Protocol. The AI application, called the host, connects to it through a client, discovers what it offers and calls its tools on the model’s behalf. Servers run locally over stdio or remotely over Streamable HTTP, where OAuth 2.1 handles authorization.

Where can I find MCP server documentation?

Start with modelcontextprotocol.io, which hosts the dated specification, architecture and security guidance. The modelcontextprotocol/servers repository on GitHub contains the reference servers, and the official MCP Registry lists published servers. Vendor-maintained servers, such as GitHub’s and Microsoft’s, document their own tools, authentication and deployment options in their repositories.

What is the difference between MCP and function calling?

Function calling is a model's ability to request a tool be run. MCP standardizes how those tools are discovered and connected across applications, acting as a common transport and discovery layer so tools are reusable rather than hard-wired.

Is MCP secure for enterprises?

MCP standardizes connection, not control. It is secure when wrapped in authentication, least-privilege permissions, input validation, and audit on every server, and when connections stay on controlled infrastructure — the model VDF AI applies.

Do I need MCP to build agents?

No, but it dramatically reduces integration work and improves portability. Building tools as MCP servers lets them be reused across agents and survive model changes, which is why adoption is growing quickly.

From protocol to platform

Validate Your Enterprise AI Use Case

Bring one workflow you want to connect through MCP and we will map the servers, permissions, and audit controls it needs to run safely on infrastructure you control.