What Is MCP? The Model Context Protocol Explained
MCP, the Model Context Protocol, is an open standard for connecting AI assistants to tools and data. How it works, a worked example, and the security basics.
Mythex Team · · 5 min read
MCP, the Model Context Protocol, is an open standard for connecting AI assistants to the tools and data they need — files, databases, business apps, developer platforms. Instead of every AI app building a custom integration for every service, a service offers one "MCP server", and any AI app that speaks MCP can use it. Anthropic introduced MCP in November 2024, and in December 2025 donated it to the Agentic AI Foundation under the Linux Foundation.
Why it matters when you build with AI
An AI agent is only as useful as the tools it can reach. A model that can't see your project files, your database or your calendar can only talk about them. MCP is the plumbing that lets an agent actually use those things, with your permission.
For people building with AI, that matters in two ways. First, it lets you use the AI assistant you already like — Claude, Cursor, and others — with more of your tools, instead of switching between apps. Second, if you build a product, offering an MCP server means AI assistants can work with it directly. You'll increasingly see "connect via MCP" alongside "connect via API" in product settings.
An everyday analogy
Think of power plugs when travelling. Every country has its own socket, so you carry a bag of adapters, one per trip. Before MCP, connecting AI apps to services was like that: each pairing of AI app and service needed its own custom adapter.
MCP is like agreeing on one socket shape. Service makers build one plug (an MCP server); AI app makers build one socket (an MCP client). Anything with the plug works in any socket. The electricity — the actual data and actions — still comes from the service, and you still decide what gets plugged in.
How MCP works
MCP has three roles:
| Role | What it is | Example |
|---|---|---|
| Host | The AI application you use | Claude, Cursor, an AI app builder |
| Client | The part of the host that talks to one MCP server | Claude's connection to your project tool |
| Server | A program that exposes a service's abilities in MCP format | A server for GitHub, a database, or an app builder |
A server can offer three main kinds of things:
- Tools — actions the AI can take, like
create_project,search_filesorsend_message. Each tool has a name, a description and a defined set of inputs, so the AI knows when and how to use it. - Resources — data the AI can read, like files or records.
- Prompts — ready-made instruction templates the server suggests.
When you connect a server, the host asks it what it offers. The AI model then sees a list of available tools with their descriptions, and during a conversation it can decide to call one. The host sends the call to the server, the server does the work, and the result comes back to the model.
Servers can run in two ways. A local server runs on your own computer and is launched by the AI app. A remote server runs on the internet and is reached through a URL; remote servers usually ask you to sign in and approve access using OAuth, the same kind of "Allow access?" screen you see when you connect an app to your Google account.
A worked example: building an app from your AI assistant
Say you use Claude and want it to build and publish a small app on a hosting platform that offers a remote MCP server.
- Connect. In Claude's connector settings you add the platform's MCP URL. A browser tab opens on the platform's consent page; you sign in and click Allow access.
- Discover. Claude now sees the platform's tools: create a project, write a file, run a command, start a preview, publish.
- Ask. You type: "Create a simple tip calculator app and publish it."
- Act. Claude calls
create_project, thenwrite_fileseveral times for the app's code, thenstart_preview, checks the preview works, and callspublish. - Report. It gives you the live link.
You never copied code between windows or learned the platform's API. Claude used standard MCP tool calls, and the platform did the work under your account and its rules. The same platform server would work with other MCP-compatible hosts in the same way.
Key terms explained
| Term | What it means |
|---|---|
| MCP | Model Context Protocol — the open standard for connecting AI apps to tools and data. |
| MCP server | A program that exposes a service's tools and data over MCP. |
| MCP client / host | The AI app side that connects to servers and uses their tools. |
| Tool | One action a server offers, with a name, description and inputs. |
| Resource | Readable data a server offers, like a file or a record. |
| Remote vs local server | Reached over the internet by URL, or run on your own machine. |
| OAuth | A standard way to grant an app access to your account without sharing your password. |
| Connector | What many AI apps call an added integration, often an MCP server. |
| Prompt injection | Text in data an agent reads that tries to make it do something you didn't ask. |
Common mistakes and misconceptions
- "MCP is a Claude-only thing." Anthropic created it, but it's an open standard now governed by the Agentic AI Foundation, and many AI apps and developer tools support it.
- "MCP replaces APIs." It sits on top of them. Most MCP servers call a service's normal API behind the scenes. MCP standardises how AI apps discover and use those features.
- "Connecting a server is harmless." A server's tools can read and change real things. Connect servers you trust, from the service itself where possible.
- Granting more access than needed. If a server offers read-only access or narrower scopes, start there.
- Ignoring what the agent reads. An email, web page or document fetched through MCP can contain instructions aimed at the AI. Keep approval on for actions like sending, deleting or paying.
- Pasting secrets into chat to "help" the connection. Remote servers should use a sign-in flow or a securely stored token, not keys pasted into a conversation. See how to keep API keys safe.
What to ask your AI builder (or assistant)
- "Which MCP servers are connected right now, and what tools does each one give you?"
- "Before you use a tool that changes or deletes anything, ask me."
- "Use only the read-only tools for this task."
- "What account is this server acting as?"
- "Add an MCP server to my app so AI assistants can [look up orders]. Require sign-in, and only expose read access to the signed-in user's own data."
MCP and Mythex
Mythex works with MCP in both directions. It runs its own remote MCP server at https://mcp.mythex.ai/mcp: add that URL as a custom connector in Claude, Cursor or Codex, approve access on Mythex, and the assistant can create projects, edit files, run commands, preview and publish in your Mythex cloud sandbox. Anyone can connect, but tool calls need a Pro plan and credits, and the external assistant's own usage is billed by its provider. In the other direction, Mythex's own agent can use outside MCP servers: Connectors → Custom MCP takes any server's URL, up to ten per account. For the bigger picture, see what is an API and what is an AI agent.
Questions
What does MCP stand for?
MCP stands for Model Context Protocol. It is an open standard that defines how AI applications connect to external tools and data sources, so a tool built once can work with many different AI assistants.
Who created MCP?
Anthropic introduced and open-sourced MCP in November 2024. In December 2025 Anthropic donated it to the Agentic AI Foundation, a fund under the Linux Foundation, so the standard is now governed by a neutral body.
What is the difference between MCP and an API?
An API is how one specific service exposes its features, and each API works differently. MCP is a common layer on top: an MCP server wraps a service's features as tools described in a standard way, so any MCP-compatible AI app can discover and use them without custom integration code.
Is MCP safe?
MCP itself is a protocol; safety depends on which servers you connect and what they can do. Only connect servers from sources you trust, grant the smallest access that works, approve risky actions yourself, and be aware that data an agent reads can contain instructions meant to mislead it.
Do I need to be a developer to use MCP?
Not to use it. Many AI apps let you add a remote MCP server by pasting its URL and signing in to approve access. Building your own MCP server does require programming.