Model Context Protocol (MCP)

An open-source standard for connecting AI applications (Claude, ChatGPT, VS Code, Cursor and others) to external data sources, tools and workflows; the official docs compare it to a “USB-C port for AI applications”. Created by Anthropic and open-sourced in November 2024. Note the expansion: Model Context Protocol (not “Control” or “Connector”).

Governance

  • On 2025-12-09 Anthropic donated MCP to the Agentic AI Foundation (agentic-ai-foundation), a directed fund under the Linux Foundation, alongside goose and AGENTS.md.
  • Technical direction stays with the project’s maintainers and the SEP (spec enhancement proposal) process; the foundation’s board covers strategic/financial matters and “will not dictate the technical direction” (MCP blog, Dec 2025).
  • The Dec 2025 announcement cited roughly 97 million monthly SDK downloads and 10,000 active servers (vendor-reported).

Spec versions

Versions are date strings marking the last backwards-incompatible change. Current: 2026-07-28.

VersionMain changes
2024-11-05First release: JSON-RPC 2.0, tools/resources/prompts, stdio + HTTP+SSE
2025-03-26OAuth 2.1 authorization, Streamable HTTP replaces HTTP+SSE, tool annotations
2025-06-18Structured tool output, elicitation, resource links, servers as OAuth resource servers
2025-11-25OIDC discovery, Client ID Metadata Documents, icons, experimental tasks, JSON Schema 2020-12 default
2026-07-28 (released 2026-07-28)See below

Version dates for the first four come from a secondary timeline; the 2026-07-28 changes are from the official changelog.

What changed in 2026-07-28

  • Stateless core: no initialize handshake, no Mcp-Session-Id; every request carries protocol version and client capabilities in _meta. New mandatory server/discover RPC.
  • Multi Round-Trip Requests: servers return input_required results instead of initiating requests (replaces server-initiated sampling/elicitation/roots calls).
  • Extensions framework: extensions capability field; Tasks moved out of core into the official io.modelcontextprotocol/tasks extension; MCP Apps and Enterprise Managed Authorization are also extensions.
  • Auth hardening: RFC 9207 iss validation; Dynamic Client Registration deprecated in favour of Client ID Metadata Documents; credentials bound to the issuing authorization server.
  • Transport/caching: Mcp-Method/Mcp-Name headers, ttlMs/cacheScope on list results, SSE resumability removed, subscriptions/listen.
  • Deprecations: Roots, Sampling, Logging, HTTP+SSE; new 12-month minimum deprecation policy.
  • Tier 1 SDKs updated: TypeScript, Python, Go, C#; Rust in beta.

Architecture

  • Transports (standard): stdio (local subprocess) and Streamable HTTP (POST to one endpoint, JSON or SSE reply). HTTP+SSE is deprecated.
  • Server primitives: tools, resources, prompts. Client features (roots, sampling) are deprecated as of 2026-07-28.
  • Registry: the official MCP Registry (server catalogue) launched in preview 2025-09-08; its README still describes it as preview with a frozen v0.1 API (may be stale).

Relations

  • a2a-protocol covers agent-to-agent; MCP covers agent-to-tool. ag-ui covers agent-to-user.
  • Supported by openai-agents-sdk, claude-agent-sdk, google-adk, langgraph and microsoft-agent-framework.
  • Server catalogues: mcp-server-directories. Browser variant: webmcp.

Sources

Merged from laptop copy (2026-10-01)

Source: owner’s laptop note KB-AI/ai-agentic-systems/model-context-protocol.md (author CarineB, published 2024-12-15, modified 2025-12-30, share:true). Its spec version history is superseded by the table above (it stops at 2025-11-25); the conceptual material and the Nov 2025 ecosystem snapshot are kept below. Dated claims come from the laptop copy’s sources (listed at the end), not re-verified.

Components

  • Host: the AI application (for example Claude Desktop, Claude Code) that coordinates one or more MCP clients.
  • Client: keeps a 1:1 connection to one MCP server, handles capability negotiation and passes context to the host.
  • Server: exposes tools, resources and prompts; local (stdio) or remote (HTTP).
  • Two layers: a data layer (JSON-RPC 2.0: lifecycle, server primitives, client primitives, notifications) and a transport layer (stdio; HTTP POST with optional SSE; OAuth, bearer tokens, API keys). Note: the 2026-07-28 spec changes above (stateless core, no initialize handshake) change the lifecycle described here.

Primitives (pre-2026-07-28 description)

  • Tools (tools/list, tools/call): executable functions (file ops, API calls, DB queries, code execution).
  • Resources (resources/list, resources/read): application-controlled contextual data (files, records, docs).
  • Prompts (prompts/list, prompts/get): reusable templates (system prompts, few-shot examples).
  • Client side: sampling (sampling/createMessage), elicitation (user input via out-of-band flows), logging. Sampling and logging are deprecated as of 2026-07-28 (see above).
  • Notifications: notifications/tools|resources|prompts/list_changed let servers push capability changes.

Ecosystem snapshot, Nov 2025 (laptop copy)

  • 58 maintainers (9 core/lead), 2,900+ Discord contributors, SEPs and working groups; events: MCP Dev Summit, MCP Night, MCP Dev Days.
  • MCP Registry: “nearly 2,000” server entries (407% growth since Sept 2025); adopters named: Notion, Stripe, GitHub, Hugging Face, Postman. Client list: pulsemcp.com.
  • 2025-11-25 anniversary release highlights: Tasks (SEP-1686), URL-based client registration (Client ID Metadata Documents), authorization extensions (machine-to-machine, Cross App Access), URL-mode elicitation (SEP-1036), sampling with tools (SEP-1577).
  • Design principles listed: simplicity, extensibility, model-agnostic, backward compatibility, community-driven (SEPs).
  • Typical uses: multi-agent coordination, enterprise integration (SSO, remote servers with OAuth), IDE/dev tools, data access.

Sources (from the laptop copy, not re-fetched)

Merged from “Model Context Protocol — overview & support in Goose, Claude, Gemini, Amp, Codex CLI” (2026-10-02)

Source: owner’s note of 2025-12-21 (author carine, share:true), merged here. Its research was done in Dec 2025 against vendor docs; the platform details below are attributed to that note and were not re-verified. Its protocol description (HTTP+SSE transport, initialize handshake, sampling) predates the 2026-07-28 spec described above.

MCP support in agent tools (as of the Dec 2025 note)

  • Goose (Block): treats MCP servers as “extensions”; recipes and sub-recipes declare required extensions with env_keys for secrets (e.g. GITHUB_TOKEN); both local stdio and remote servers are usable. See goose.
  • Claude (Anthropic): originator of MCP; Anthropic published the spec, SDKs, reference servers (Google Drive, Slack, GitHub, Postgres, Puppeteer) and the MCP Inspector; Claude Desktop loads local MCP servers.
  • Gemini (Google): official samples and docs show MCP servers with the Gemini SDK (@google/genai plus @modelcontextprotocol/sdk in Node/TypeScript, and Go).
  • Amp (ampcode.com): servers are configured through the amp.mcpServers setting; amp mcp add <name> <url> registers a server and amp mcp oauth login <name> runs an OAuth flow; auth by HTTP headers, environment-variable interpolation or OAuth 2.0; amp.tools.disable turns off unneeded MCP tools. Source cited by the note: ampcode.com/docs.
  • Codex CLI: codex mcp add|list|get; ~/.codex/config.toml takes stdio and HTTP servers, env injection, bearer tokens, enabled_tools/disabled_tools and timeouts; Codex can also run as an MCP server (tools codex and codex-reply).

Practice notes (from the same note)

  • Use tool and provider allowlists, mark tools read-only or destructive and require approval for destructive ones; prefer stdio for sensitive local data; validate server binaries (supply chain); keep audit logs and human checkpoints for high-risk actions.
  • Start with a small server exposing 2-3 tools with precise JSON Schema inputs; add timeouts and retries; use a tool gateway (for example HyperTool MCP) to limit the tool set per agent.
  • Further reading named in that note: Anthropic’s Skilljar course “Introduction to Model Context Protocol”, the Hugging Face MCP course (huggingface.co/learn/mcp-course), ampcode.com/docs.