Glossary · term

Model Context Protocol

Model Context Protocol (MCP) is an open protocol for connecting AI applications to external capabilities and context through a common client-server interface. An MCP host runs one or more clients, while MCP servers expose resources, prompts, and tools using JSON-RPC messages. MCP standardizes how these elements are described and invoked; it does not decide which model to use or make a tool invocation safe by itself.

Agents2024-11-25Wave 1 · 2023Maturity: 4/5

Origin and context

Anthropic announced MCP in November 2024 and released specifications and SDKs as an open-source project. The announcement named David Soria Parra and Justin Spahr-Summers as its creators and described early integrations by developer-tool and data-platform companies. In December 2025, Anthropic donated MCP to the Agentic AI Foundation under the Linux Foundation, moving stewardship toward a neutral, multi-project governance structure. The protocol has continued to evolve through dated specification revisions.

Sources: s1, s2, s3

Why it matters

Without a shared interface, each AI application must build and maintain custom connectors for every data source or action. MCP separates the host's orchestration and permission decisions from servers that describe reusable capabilities. That can reduce duplicated integration work, make connectors portable across compatible hosts, and give platform teams a consistent place to inventory tools. The boundary is also operationally important: a host can present consent controls, enforce policy, and decide what context reaches a model instead of treating every integration as an opaque plugin.

Sources: s1, s2, s3

Example

Consider a coding assistant that needs repository files, an issue tracker, and a database schema. Each system can be exposed by a separate MCP server. The assistant's host creates clients for those servers, lists the available resources or tools, and asks the user to authorize consequential actions. A read-only schema resource can inform a query, while a tool can create an issue after approval. The same servers may be reusable from another compatible host. This does not remove application-specific authorization, validation, logging, or secret management.

Sources: s1, s2

How it differs

Agent2Agent Protocol

MCP primarily connects an AI application to context and capabilities exposed by servers. Agent2Agent (A2A) addresses communication and task coordination between autonomous agents, including discovery and task state. The protocols can complement one another: an A2A agent may use MCP-connected tools while collaborating with another agent, but an MCP server is not automatically an autonomous peer agent.

Maturity and evidence

Maturity is rated 4. MCP has a public specification, multiple official SDKs, an active contributor ecosystem, production integrations, and neutral foundation governance. Those signals make it more than a vendor-specific experiment. The rating stops below 5 because the specification still changes, implementation coverage varies, and secure authorization patterns remain the responsibility of hosts, servers, and deployers rather than a solved property of protocol conformance.

Sources: s1, s2, s3

Limits and open questions

Protocol compatibility does not establish trust. A malicious or over-privileged server can expose dangerous tools, and descriptions supplied to a model can influence its choices. Hosts still need user consent, least privilege, input validation, credential isolation, logging, and controls against confused-deputy behavior. Version differences and optional capabilities can also limit interoperability, so teams should test the exact clients and servers they deploy.

Sources: s2

Related terms

References

Last updated: 2026-09-07

In the Skills Atlas

This term is also covered in the Skills Atlas as model context protocol skill.

In the Skills Atlas

This term is also covered in the Skills Atlas as llm function calling skill.