How MCP works
MCP uses a simple client-server shape. The host is the AI application you are using, such as Claude Desktop or Claude Code. For each external system it wants to reach, the host starts one client, and each client holds a dedicated connection to one server.
What a server offers comes in three kinds: tools (actions the model can call, like "create ticket" or "run query"), resources (data it can read, like a file or a record), and prompts (ready-made templates). The model discovers what is available, then calls it, the same way regardless of what the tool actually does (modelcontextprotocol.io).
A quick example
Hypothetical
A logistics company wants its support assistant to answer "where is my shipment?" Without MCP, someone copies tracking data into the chat by hand. With an MCP server wrapping the carrier's tracking API, the assistant calls a tracking tool directly, reads the result, and replies — inside whatever limits the server allows. The company builds the server once, and any MCP-capable client can use it.
A connection is not access
MCP defines how a client and server talk, but authorization is handled separately. Remote servers typically use OAuth or API tokens, and the standard is explicit that a server must reject tokens that were not issued for it and must verify every request rather than trust that a caller is connected (MCP security guidance).
Security in practice
Tools take real actions, so the usual risks apply:
- A server can return content that tries to steer the model into misusing a tool — the tool-use version of prompt injection.
- An over-broad set of permissions widens the blast radius if anything goes wrong.
- The standard guidance: require user consent before running a local server, grant the least privilege that works, and treat each server as untrusted until you have reason not to.
When is MCP useful?
MCP earns its place when you keep pasting the same external data into a chat, or when an assistant needs to act in a system rather than just talk about it. It is now supported across a range of clients and servers, including Claude, ChatGPT, and editors like VS Code and Cursor, so a server you build is reusable well beyond one app.
Where it fits in a larger system is one layer of how AI agents reach production, and it pairs with the discipline of evaluating what those agents do. For a plainer starting point, see what an AI agent is.