
An MCP server is a small program that gives AI applications access to one system, such as a database, an ERP, a file store or GitHub, through the Model Context Protocol. The server tells the AI app which tools, data and prompt templates it offers, runs the tool calls the app makes, and returns the results in a standard format. Any AI app that speaks MCP can use any MCP server, so each system is connected once instead of once per app.
Anthropic released MCP as an open standard on November 25, 2024. In December 2025 it was donated to the Agentic AI Foundation, a Linux Foundation project co-founded by Anthropic, Block and OpenAI, and the current revision of the specification is dated July 28, 2026.
MCP stands for Model Context Protocol. The protocol is the specification: the message format, the methods a client can call and the rules for authorization and transport. An MCP server is one running program that implements it for one system. The relationship is the same as between HTTP and a web server: HTTP defines how browsers and servers talk, and Nginx is one server that speaks it.
The problem MCP solves is the integration count. Without a shared protocol, every AI app needs its own connector to every system, and every connector breaks on its own schedule. With MCP, each app implements the protocol once and each system gets one server.
An MCP setup has three roles. The names matter, because security and setup questions always come down to which of the three holds what.
| Role | What it is | Examples |
|---|---|---|
| MCP host | The AI application the user works in. It runs the model and decides when a request needs outside data or an action | Claude, ChatGPT, an IDE such as Cursor, an n8n agent |
| MCP client | The part of the host that talks to one MCP server: it sends requests and passes results back to the model | Built into the host, one per connected server |
| MCP server | The program that wraps one system, holds its credentials and runs the actual queries or actions | A GitHub server, a Postgres server, a server for your ERP |
One host can connect to many servers at once, so a single chat can read a ticket from the helpdesk server and check an order in the ERP server. The model never sees the ERP's API keys. The server holds those and decides what it will do on the model's behalf.
A server offers three kinds of capability, and the specification says who controls each one.
| Primitive | What it is | Who decides when it is used | Example |
|---|---|---|---|
| Tools | Functions that do something: query, calculate, create, update, send | The model | get_po_status, create_ticket |
| Resources | Data the app can read into context, such as files, records or schemas | The application | A product catalogue, a database schema |
| Prompts | Reusable templates for a recurring task | The user | Summarise this account, review this pull request |
Tools are where most of the value and most of the risk sit, because a tool can change data in a real system. That is why a well-built server exposes a short list of narrow tools, such as get_po_status, rather than a single tool that runs any query.
Messages between client and server use JSON-RPC 2.0. Here is one question travelling from a buyer to an ERP and back. Step through it to see which component does what.
Two transports carry those messages. Standard input and output (stdio) connects a host to a server running on the same machine, which is how most developer tools start. Streamable HTTP connects to a server over the network, which is what a company runs in production. Streamable HTTP replaced the older HTTP with server-sent events transport in the March 2025 revision, so guides that describe MCP servers as SSE endpoints are out of date.
An MCP server usually sits on top of an API rather than replacing it. The ERP keeps its REST API; the MCP server calls that API and presents a few of its operations as tools a model can understand.
| REST API | MCP server | |
|---|---|---|
| Built for | Any software client a developer writes | AI apps and agents |
| How the client learns what is available | Documentation, read by a developer, then hardcoded | The server lists its tools, with descriptions and input schemas, when asked |
| Connecting a new AI app | New connector code for each app | None, if the app speaks MCP |
| Credentials | Held by whichever client calls the API | Held by the server, with the user signing in through OAuth |
| Typical scope | Every endpoint the product offers | A few task-shaped tools chosen for the AI use case |
The practical difference is discovery. A model can ask an MCP server what it can do and read the answer, so adding a tool to the server makes it available to every connected app without a client update.
MCP does not replace retrieval-augmented generation (RAG). RAG searches a vector index of documents for the passages most relevant to a question, which suits policies, contracts and past tickets. An MCP server queries live systems, which suits a current account balance or today's stock level. Most production agents use both, and a search over the document index can itself be exposed as an MCP tool.
MCP is also not an agent framework. LangGraph, CrewAI or an n8n workflow decide how an agent plans and which step comes next; MCP only defines how that agent reaches tools and data. Our post on how agents connect to your ERP, CRM and data shows where MCP sits in a five-layer architecture.
MCP started in Anthropic's Claude apps, and the other large AI vendors adopted it within months. OpenAI added MCP support to its Agents SDK in March 2025 and to the Responses API that May, and ChatGPT apps are built on it. Microsoft made MCP generally available in Copilot Studio on May 29, 2025, and Google added it to the Gemini API and SDK. On the automation side, n8n shipped an MCP Server Trigger node and an MCP Client Tool node in version 1.88.0 in April 2025, so an n8n workflow can act as an MCP server or call one.
An official MCP Registry, a public catalogue of servers, has been in preview since September 2025. Treat it as a directory, not as a security review: anyone can publish a server.
The last two are where most enterprise work happens, because the systems are your own and the tools follow your rules. That rule layer is what our enterprise context layer builds, and the business rules post shows how rules reach an agent through MCP.
You need one when an AI app or agent has to read from or act in a system it cannot reach today, and more than one app will need that access. A single workflow calling a single API may not need MCP at all, and a direct API call can be simpler.
Before any server goes near company data, decide which tools it exposes, whose credentials it runs on and which actions wait for a person. Our guide to MCP security in the enterprise covers authorization, MCP gateways and the incidents that shaped both.
It is a connector that lets AI apps use one system, such as a database or an ERP, through a shared standard. It lists what it can do, runs the actions the AI asks for within the limits it was given, and returns the results.
Yes. It is a running program that listens for requests and answers them. It can run on your own machine, connected over standard input and output, or as a network service reached over Streamable HTTP.
MCP is the open specification that defines how AI apps and servers talk. An MCP server is one program that implements it for a particular system, in the way Nginx is one web server that implements HTTP.
An API is a general interface for any software, documented for developers. An MCP server usually wraps an API and presents a few of its operations as tools an AI model can discover and call, so any MCP-compatible app can use them without new connector code.
Yes. OpenAI added MCP to its Agents SDK and Responses API in 2025, and apps in ChatGPT are built on the protocol. Claude, Microsoft Copilot Studio, Gemini and many coding tools support it as well.
Not always. Official SDKs exist for several languages, and n8n can expose a workflow as an MCP server through its MCP Server Trigger node. Connecting a business system safely still takes design work on tools, permissions and logging.
Ovidius builds MCP servers and agents on n8n inside your own systems, with the permissions and logs set before launch. If you have a system your AI tools need to reach, book a discovery call and we will look at which tools it should expose.