Model Context Protocol (MCP)
An open-source standard for connecting AI applications (Claude, ChatGPT, VS Code, Cursor and others) to external data sources, tools and workflows; the official docs compare it to a “USB-C port for AI applications”. Created by Anthropic and open-sourced in November 2024. Note the expansion: Model Context Protocol (not “Control” or “Connector”).
Governance
- On 2025-12-09 Anthropic donated MCP to the Agentic AI Foundation (agentic-ai-foundation), a directed fund under the Linux Foundation, alongside goose and AGENTS.md.
- Technical direction stays with the project’s maintainers and the SEP (spec enhancement proposal) process; the foundation’s board covers strategic/financial matters and “will not dictate the technical direction” (MCP blog, Dec 2025).
- The Dec 2025 announcement cited roughly 97 million monthly SDK downloads and 10,000 active servers (vendor-reported).
Spec versions
Versions are date strings marking the last backwards-incompatible change. Current: 2026-07-28.
| Version | Main changes |
|---|---|
| 2024-11-05 | First release: JSON-RPC 2.0, tools/resources/prompts, stdio + HTTP+SSE |
| 2025-03-26 | OAuth 2.1 authorization, Streamable HTTP replaces HTTP+SSE, tool annotations |
| 2025-06-18 | Structured tool output, elicitation, resource links, servers as OAuth resource servers |
| 2025-11-25 | OIDC discovery, Client ID Metadata Documents, icons, experimental tasks, JSON Schema 2020-12 default |
| 2026-07-28 (released 2026-07-28) | See below |
Version dates for the first four come from a secondary timeline; the 2026-07-28 changes are from the official changelog.
What changed in 2026-07-28
- Stateless core: no
initializehandshake, noMcp-Session-Id; every request carries protocol version and client capabilities in_meta. New mandatoryserver/discoverRPC. - Multi Round-Trip Requests: servers return
input_requiredresults instead of initiating requests (replaces server-initiated sampling/elicitation/roots calls). - Extensions framework:
extensionscapability field; Tasks moved out of core into the officialio.modelcontextprotocol/tasksextension; MCP Apps and Enterprise Managed Authorization are also extensions. - Auth hardening: RFC 9207
issvalidation; Dynamic Client Registration deprecated in favour of Client ID Metadata Documents; credentials bound to the issuing authorization server. - Transport/caching:
Mcp-Method/Mcp-Nameheaders,ttlMs/cacheScopeon list results, SSE resumability removed,subscriptions/listen. - Deprecations: Roots, Sampling, Logging, HTTP+SSE; new 12-month minimum deprecation policy.
- Tier 1 SDKs updated: TypeScript, Python, Go, C#; Rust in beta.
Architecture
- Transports (standard): stdio (local subprocess) and Streamable HTTP (POST to one endpoint, JSON or SSE reply). HTTP+SSE is deprecated.
- Server primitives: tools, resources, prompts. Client features (roots, sampling) are deprecated as of 2026-07-28.
- Registry: the official MCP Registry (server catalogue) launched in preview 2025-09-08; its README still describes it as preview with a frozen v0.1 API (may be stale).
Relations
- a2a-protocol covers agent-to-agent; MCP covers agent-to-tool. ag-ui covers agent-to-user.
- Supported by openai-agents-sdk, claude-agent-sdk, google-adk, langgraph and microsoft-agent-framework.
- Server catalogues: mcp-server-directories. Browser variant: webmcp.
Sources
- https://modelcontextprotocol.io/specification/versioning (2026-09-30)
- https://modelcontextprotocol.io/specification/2026-07-28/changelog (2026-09-30)
- https://modelcontextprotocol.io/specification/2026-07-28/basic/transports (2026-09-30)
- https://modelcontextprotocol.io/docs/getting-started/intro (2026-09-30)
- https://blog.modelcontextprotocol.io/posts/2026-07-28/ (2026-09-30)
- https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/ (2026-09-30)
- https://github.com/modelcontextprotocol/registry (2026-09-30)
- https://hidekazu-konishi.com/entry/mcp_specification_version_timeline.html (secondary; 2026-09-30)
Merged from laptop copy (2026-10-01)
Source: owner’s laptop note KB-AI/ai-agentic-systems/model-context-protocol.md (author CarineB, published 2024-12-15, modified 2025-12-30, share:true). Its spec version history is superseded by the table above (it stops at 2025-11-25); the conceptual material and the Nov 2025 ecosystem snapshot are kept below. Dated claims come from the laptop copy’s sources (listed at the end), not re-verified.
Components
- Host: the AI application (for example Claude Desktop, Claude Code) that coordinates one or more MCP clients.
- Client: keeps a 1:1 connection to one MCP server, handles capability negotiation and passes context to the host.
- Server: exposes tools, resources and prompts; local (stdio) or remote (HTTP).
- Two layers: a data layer (JSON-RPC 2.0: lifecycle, server primitives, client primitives, notifications) and a transport layer (stdio; HTTP POST with optional SSE; OAuth, bearer tokens, API keys). Note: the 2026-07-28 spec changes above (stateless core, no
initializehandshake) change the lifecycle described here.
Primitives (pre-2026-07-28 description)
- Tools (
tools/list,tools/call): executable functions (file ops, API calls, DB queries, code execution). - Resources (
resources/list,resources/read): application-controlled contextual data (files, records, docs). - Prompts (
prompts/list,prompts/get): reusable templates (system prompts, few-shot examples). - Client side: sampling (
sampling/createMessage), elicitation (user input via out-of-band flows), logging. Sampling and logging are deprecated as of 2026-07-28 (see above). - Notifications:
notifications/tools|resources|prompts/list_changedlet servers push capability changes.
Ecosystem snapshot, Nov 2025 (laptop copy)
- 58 maintainers (9 core/lead), 2,900+ Discord contributors, SEPs and working groups; events: MCP Dev Summit, MCP Night, MCP Dev Days.
- MCP Registry: “nearly 2,000” server entries (407% growth since Sept 2025); adopters named: Notion, Stripe, GitHub, Hugging Face, Postman. Client list: pulsemcp.com.
- 2025-11-25 anniversary release highlights: Tasks (SEP-1686), URL-based client registration (Client ID Metadata Documents), authorization extensions (machine-to-machine, Cross App Access), URL-mode elicitation (SEP-1036), sampling with tools (SEP-1577).
- Design principles listed: simplicity, extensibility, model-agnostic, backward compatibility, community-driven (SEPs).
- Typical uses: multi-agent coordination, enterprise integration (SSO, remote servers with OAuth), IDE/dev tools, data access.
Sources (from the laptop copy, not re-fetched)
- http://blog.modelcontextprotocol.io/posts/2025-11-25-first-mcp-anniversary/
- https://modelcontextprotocol.io/specification/2025-11-25
- https://modelcontextprotocol.io/docs/learn/architecture
- https://workos.com/blog/mcp-2025-11-25-spec-update
Merged from “Model Context Protocol — overview & support in Goose, Claude, Gemini, Amp, Codex CLI” (2026-10-02)
Source: owner’s note of 2025-12-21 (author carine, share:true), merged here. Its research was done in Dec 2025 against vendor docs; the platform details below are attributed to that note and were not re-verified. Its protocol description (HTTP+SSE transport, initialize handshake, sampling) predates the 2026-07-28 spec described above.
MCP support in agent tools (as of the Dec 2025 note)
- Goose (Block): treats MCP servers as “extensions”; recipes and sub-recipes declare required extensions with
env_keysfor secrets (e.g.GITHUB_TOKEN); both local stdio and remote servers are usable. See goose. - Claude (Anthropic): originator of MCP; Anthropic published the spec, SDKs, reference servers (Google Drive, Slack, GitHub, Postgres, Puppeteer) and the MCP Inspector; Claude Desktop loads local MCP servers.
- Gemini (Google): official samples and docs show MCP servers with the Gemini SDK (
@google/genaiplus@modelcontextprotocol/sdkin Node/TypeScript, and Go). - Amp (ampcode.com): servers are configured through the
amp.mcpServerssetting;amp mcp add <name> <url>registers a server andamp mcp oauth login <name>runs an OAuth flow; auth by HTTP headers, environment-variable interpolation or OAuth 2.0;amp.tools.disableturns off unneeded MCP tools. Source cited by the note: ampcode.com/docs. - Codex CLI:
codex mcp add|list|get;~/.codex/config.tomltakes stdio and HTTP servers, env injection, bearer tokens,enabled_tools/disabled_toolsand timeouts; Codex can also run as an MCP server (toolscodexandcodex-reply).
Practice notes (from the same note)
- Use tool and provider allowlists, mark tools read-only or destructive and require approval for destructive ones; prefer stdio for sensitive local data; validate server binaries (supply chain); keep audit logs and human checkpoints for high-risk actions.
- Start with a small server exposing 2-3 tools with precise JSON Schema inputs; add timeouts and retries; use a tool gateway (for example HyperTool MCP) to limit the tool set per agent.
- Further reading named in that note: Anthropic’s Skilljar course “Introduction to Model Context Protocol”, the Hugging Face MCP course (huggingface.co/learn/mcp-course), ampcode.com/docs.