MCP (Model Context Protocol): a complete overview — how to connect AI to your data

What MCP is and why Claude, ChatGPT and other assistants support it: how the protocol works, 8 scenarios, a comparison with other ways to give AI access to data, security, limits and server code examples.

Stack and technologies Updated

In short

MCP (Model Context Protocol) is an open standard for connecting AI assistants to data and tools: Claude, ChatGPT, Gemini, VS Code and Cursor speak it. A company writes one MCP server — for its CRM, warehouse, database or documents — and any compatible assistant can read the data and perform actions within the rights it was given, instead of people copying tables into a chat. Anthropic introduced MCP in November 2024; since December 2025 it is developed in the Agentic AI Foundation under the Linux Foundation. The main thing to get right is security: the server decides what the model may see and do, writes need confirmation, and every call goes to the log.

MCP at a glance

The main facts in one table — where the protocol came from, what it consists of and who supports it.

What it is
An open protocol for connecting AI applications to data and tools
Comparison
“USB-C for AI”: one connector instead of a separate integration for each assistant
History
Introduced by Anthropic in November 2024
Governance
Since December 2025 — the Agentic AI Foundation under the Linux Foundation
Parts
Host (the AI application), client (the connection), server (your system)
What a server offers
Tools (actions), resources (data to read), prompts (ready templates)
Messages
JSON-RPC 2.0
Transport
stdio on the same machine, Streamable HTTP over the network
Authorisation
OAuth 2.1 for remote servers
SDKs
TypeScript, Python, Go, Java, Kotlin, C#, Rust, PHP, Ruby, Swift
Supported by
Claude, ChatGPT, Gemini CLI, VS Code, Cursor and many other tools

How MCP works, in plain words

An assistant by itself knows nothing about your company. MCP gives it hands and eyes: a server describes what is available — “find an order by number”, “show stock”, “read the delivery terms” — and the assistant decides during a conversation which of these to use. The model does not get a password to your database; it gets a list of allowed actions.

Because the protocol is the same everywhere, one server works with Claude, ChatGPT and a code editor at once. Before MCP every assistant needed its own integration; now the integration is written once, and the choice of assistant stays free.

  • A list of actions, not a password
  • One server for every assistant
  • The rights are set by you

What MCP is used for: 8 scenarios

From a staff assistant to your own product that other assistants can work with.

  1. 01

    An assistant for staff

    “What is the status of order 1042?”, “How many A-100 are left?” — answers from real data.

    CRMwarehouse

  2. 02

    Questions to the database

    “How many orders came yesterday from ads?” — the assistant builds a read-only query.

    PostgreSQLread-only

  3. 03

    Knowledge base and documents

    Rules, contracts and instructions are found and quoted with a link to the source.

    Google DriveNotion

  4. 04

    Actions in systems

    Create a task in the CRM, draft a reply, update a status — with a person confirming.

    confirmation

  5. 05

    Development

    Claude Code and Cursor read the repository, the database schema and the documentation.

    GitHubClaude Code

  6. 06

    Support

    The assistant sees the customer’s history and orders before suggesting a reply.

    customer history

  7. 07

    Agentic workflows

    An agent goes through several systems step by step using their MCP servers.

    agents

  8. 08

    Your product for other assistants

    A SaaS publishes an MCP server, and its customers work with it from their own Claude or ChatGPT.

    SaaSOAuth

MCP compared with copying into a chat, an API integration and function calling

Four ways to give a model access to company data.

CriterionMCPCopying into a chatOwn integration per assistantFunction calling in your app
Works with any compatible assistant any chat one assistant your own application
Fresh data always current as of copying current current
Control over access rights and a log on the server none: the data has left depends on the integration in your code
Changing the assistant without rework — a new integration code changes
Best for staff and agents working with company systems a one-off question legacy setups an AI feature inside your product

MCP security: what to set up first

An MCP server is a door into your systems. These rules decide who comes in and what they can touch.

  1. 01

    The fewest rights possible

    The server works under its own account with access only to what the task needs.

  2. 02

    Reading by default

    Actions that change data are added consciously, one by one.

  3. 03

    Confirmation for writes

    Payments, sending to customers and deleting only after a person says yes.

  4. 04

    A log of every call

    Who asked, which tool was called, with what arguments and what was returned.

  5. 05

    Distrust of tool results

    Text from a document or an email can contain instructions for the model — prompt injection. The server does not grant extra rights because of them.

  6. 06

    Only trusted servers

    A random MCP server from the internet gets the same access as your own — check the code before connecting.

  7. 07

    Keys on the server side

    Passwords to systems never reach the model — they live in the server’s environment.

  8. 08

    Access you can withdraw

    OAuth tokens with limited scope and a lifetime, revoked in one click.

When MCP is worth it — and when not

Ten typical situations with a verdict.

  • Staff ask about orders and stock

    Best fit

    Answers from real data in a familiar assistant.

  • Questions to the database without SQL

    Best fit

    Read-only access to a prepared view of the data.

  • An internal knowledge base

    Best fit

    Documents are found and quoted with a link to the source.

  • Development with AI tools

    Best fit

    The editor sees the schema, the tasks and the documentation.

  • A SaaS that customers use from their assistants

    Best fit

    A public MCP server with OAuth becomes a new channel.

  • Actions that change data

    Works

    Yes, with confirmation and a log; start with reading.

  • Agents across several systems

    Works

    Yes, with limits on steps and approval of important ones.

  • An AI feature inside your own product

    Works

    Often plain function calling in your code is simpler.

  • A chatbot for site visitors

    Pick another

    Visitors do not bring their own assistants; build the bot into the site.

  • A one-off question

    Pick another

    A server is overkill; an export without personal data is enough.

The limits of MCP and common mistakes

  1. Giving the model the whole database

    A tool “run any SQL” turns one prompt injection into a leak. Prepared queries and views are safer.

  2. Too many tools

    Dozens of similar tools confuse the model; a few clear ones with good descriptions work better.

  3. Vague descriptions

    The model chooses a tool by its description — “gets data” tells it nothing.

  4. Huge answers

    A tool that returns ten thousand rows eats the context and the budget. Filter and paginate on the server.

  5. Writes without confirmation

    A model can misunderstand. Irreversible actions need a person.

  6. No log

    Without it you cannot tell what the assistant did and why.

How to bring MCP into a company

Start small and safe, then widen.

  1. Choose questions

    Which questions staff ask most often and which systems hold the answers.

  2. Reading first

    A server with a few read-only tools and resources.

  3. Rights and log

    A service account, a log of calls, keys in the environment.

  4. Pilot with a team

    A few people use it for real work; the log shows what is asked.

  5. Actions with confirmation

    Writes are added one by one, each with a confirmation.

What an MCP server looks like: 3 examples

A tool, a resource and connecting the server to an assistant. Written with the official TypeScript SDK, checked by TypeScript 7 and called by a real MCP client.

A tool: stock by SKU

The assistant calls it during a conversation; a wrong argument is rejected by the schema before the code runs.

shop.ts
import { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js';
import { StdioServerTransport } from '@modelcontextprotocol/sdk/server/stdio.js';
import { z } from 'zod';

// stock lives in your system; here it is a small table for the example
const stock: Record<string, number> = { 'A-100': 8, 'B-200': 0 };

const server = new McpServer({ name: 'shop', version: '1.0.0' });

// a tool: the assistant may call it, and the schema checks the arguments
server.registerTool(
  'get_stock',
  {
    title: 'Stock by SKU',
    description: 'How many items of a product are in stock',
    inputSchema: { sku: z.string().describe('Product SKU, for example A-100') },
    annotations: { readOnlyHint: true },
  },
  async ({ sku }) => {
    const qty = stock[sku];
    const text = qty === undefined ? `No product ${sku}` : `${sku}: ${qty} pcs`;
    return { content: [{ type: 'text', text }] };
  },
);

await server.connect(new StdioServerTransport());

A resource: a document to read

Reading without the right to change — the safest thing to start with.

docs.ts
import { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js';
import { StdioServerTransport } from '@modelcontextprotocol/sdk/server/stdio.js';

const server = new McpServer({ name: 'docs', version: '1.0.0' });

// a resource: a document the assistant can read but cannot change
server.registerResource(
  'delivery-terms',
  'docs://delivery-terms',
  { title: 'Delivery terms', mimeType: 'text/markdown' },
  async (uri) => ({
    contents: [{ uri: uri.href, text: '# Delivery\nCourier: 1–2 days. Pickup: the same day.' }],
  }),
);

await server.connect(new StdioServerTransport());

Connecting the server to an assistant

Settings in the format of Claude Desktop and Claude Code: the key lives in the server’s environment, not in the chat.

claude_desktop_config.json
{
  "mcpServers": {
    "shop": {
      "command": "node",
      "args": ["/srv/mcp/shop.js"],
      "env": { "SHOP_API_KEY": "key-for-read-only-access" }
    }
  }
}

Questions about MCP

What is MCP in simple terms?

A common language in which AI assistants talk to your systems: the server lists what may be done, and the assistant uses it during a conversation.

Does ChatGPT support MCP or only Claude?

Both, as well as Gemini CLI, VS Code, Cursor and many other tools. That is the point of the standard.

Is it safe to connect AI to company data?

As safe as the server is set up: minimal rights, reading by default, confirmation for writes and a log. Copying data into a chat by hand is less safe.

Does the model learn on our data?

MCP itself does not send data for training; it depends on the terms of the assistant’s plan. Business and API plans usually forbid training on customer data.

What language are MCP servers written in?

There are official SDKs for TypeScript, Python, Go, Java, Kotlin, C#, Rust, PHP, Ruby and Swift.

What is the difference between a tool and a resource?

A tool is an action the model decides to call; a resource is data the application gives the model to read.

Local or remote server?

A local server runs on the employee’s computer through stdio; a remote one runs on your server over HTTP with OAuth — better for a team.

Can we connect our CRM and accounting system?

Yes, if they have an API or a database you can read: the MCP server sits between them and the assistant.

Online form

Connect AI
to your data

I build MCP servers: Claude or ChatGPT get access to your orders, stock and documents — with rights, a log of every call and access you can withdraw at any moment. Tell me about the systems — I answer within one working day.

Or write to [email protected]