What matters in AI.

Subscribe

Learn / AI agents

Definition · AI agents

Model Context Protocol (MCP)

The Model Context Protocol (MCP) is an open standard for connecting AI applications to outside tools and data. A client inside a host application, such as a chat app or code editor, talks to an MCP server that offers tools, resources and prompts. Anthropic released MCP in 2024; the Linux Foundation's Agentic AI Foundation now hosts it.

Last reviewed

Key points

  • MCP is a shared plug shape for AI applications. Build a tool once as an MCP server and any MCP-capable app can use it.
  • Anthropic released MCP in 2024 and gave it to the Linux Foundation's Agentic AI Foundation in December 2025. Its maintainers still run the specification.
  • A server offers tools the model can call, resources to read, and prompt templates.
  • The protocol treats tool descriptions and results as data, but the model reads them and can obey instructions hidden inside.
  • The specification says MCP cannot enforce its own security principles. Checking and consent fall to the application.

How it works

MCP has three parties. The host is the AI application a person uses, such as a chat app or code editor. Inside it, each client holds a connection to exactly one MCP server, a program on the same machine or across the internet. They exchange JSON-RPC 2.0 messages. A server can offer:

  • Tools: functions the model can decide to call, such as “send an email”.
  • Resources: data to read, such as a file or a database row.
  • Prompts: message templates the user can pick.

The host keeps the full conversation. A server sees only what the host sends it, and cannot see into other servers.

What MCP treats as data, and what the model does with it

To the protocol, a tool is a record: a name, a description, an input schema, and optional annotations, hints such as “read-only”. A result is data sent back. Nothing marks some text as instruction and other text as content to leave alone.

The language model reads the description to decide when to call a tool, and reads the result to decide what to do next. An instruction written in either place can be obeyed. That is the gap MCP tool poisoning uses, a form of indirect prompt injection.

The specification pushes the checks to the ends. Clients must treat annotations from an untrusted server as untrusted and should validate results before the model sees them. Servers must sanitise their outputs. Hosts must get the user’s consent before a tool runs. The specification also says plainly that MCP cannot enforce any of this at the protocol level.

Why it matters

Anthropic launched MCP to replace one-off connectors between each AI application and each data source with a single protocol. The same property moves the trust decision: connecting a server is quick, and each one adds text the model reads and functions it can call. The protocol guarantees the shape of the messages, not what is in them.

In practice

The specification is published at modelcontextprotocol.io and versioned by date. The current revision is 2026-07-28. It dropped the opening handshake earlier revisions used: each request now carries its own protocol version and capabilities, and revisions up to 2025-11-25 are classed as legacy.

Anthropic released MCP in November 2024. In December 2025 it donated the protocol to the Agentic AI Foundation, a directed fund under the Linux Foundation co-founded by Anthropic, Block and OpenAI. Both Anthropic and the maintainers said governance would not change: the maintainers still decide what goes into the specification, through the project’s Specification Enhancement Proposal (SEP) process.

Where definitions disagree

Sources disagree on what MCP’s trust model assumes about tool descriptions. Since revision 2025-03-26 the specification has said that “descriptions of tool behavior such as annotations should be considered untrusted, unless obtained from a trusted server.” Its hard requirement names only annotations, the structured hints, not the free-text description field. Invariant Labs, disclosing tool poisoning in April 2025, wrote that “MCP’s security model assumes that tool descriptions are trustworthy and benign.” Both readings have support. The specification does warn, but its one MUST covers annotations, while the text a model reads and acts on is mostly the description, which the specification’s tool requirements do not single out.

Questions and answers

Who owns the Model Context Protocol?

Anthropic created MCP and released it in November 2024. In December 2025 Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation. The protocol's maintainers still decide changes to the specification.

Is an MCP tool description trusted?

Not by default. The MCP specification tells clients to treat tool annotations as untrusted unless they come from a trusted server. The model still reads the description, so a hostile server can use it to carry instructions.

Is MCP the same as an MCP server?

No. MCP is the protocol, the agreed message format. An MCP server is one program that speaks it and offers tools, resources or prompts to AI applications.

Sources

  1. Introducing the Model Context ProtocolAnthropic, 25 Nov 2024
  2. MCP joins the Agentic AI FoundationModel Context Protocol (maintainers' blog), 9 Dec 2025
  3. Donating the Model Context Protocol and establishing the Agentic AI FoundationAnthropic, 9 Dec 2025
  4. Model Context Protocol Specification, 2026-07-28, OverviewModel Context Protocol, 28 Jul 2026
  5. Model Context Protocol Specification, 2026-07-28, ToolsModel Context Protocol, 28 Jul 2026
  6. Model Context Protocol Specification, 2026-07-28, ArchitectureModel Context Protocol, 28 Jul 2026
  7. Model Context Protocol Specification, 2025-03-26, Overview and ToolsModel Context Protocol, 26 Mar 2025
  8. Model Context Protocol Specification, 2026-07-28, Versioning and CompatibilityModel Context Protocol, 28 Jul 2026
  9. MCP Security Notification: Tool Poisoning AttacksInvariant Labs, 1 Apr 2025

Guides that use this term

In the news