Model Context Protocol (MCP)
Model Context Protocol (MCP) explained
An AI application needs product information from another system. It requires a connection, understandable functions and appropriate permissions. MCP can standardise the exchange between the application and a connected service. It does not independently determine which data is accurate or approved for use.
A typical setup includes a host application, a client and a server exposing selected capabilities. These may include readable resources, tools and reusable prompt templates. Actual availability depends on both sides and the supported protocol version.
A connection does not make every task work automatically. Check required fields, error reporting and permitted actions. Searching product data differs from changing a product catalogue.
MCP does not replace permission enforcement in the connected system. A tool described as read-only still needs to be implemented and constrained accordingly. Tool descriptions are hints; their claims alone do not prevent unwanted changes. What matters in practice is a tested connection with clear responsibilities.
Examples
Hypothetical application
An editorial assistant accesses approved product information through an MCP server. It can retrieve facts and prepare drafts. This access cannot modify product data. The team checks that correct versions are used and missing information remains visible.
Key Points
- MCP connects applications, data and tools through a common protocol.
- Availability depends on implementation and supported capabilities.
- Distinguish connectivity from editorial approval.
- Enforce permissions technically rather than merely describing them.
Practical application
Define the task and permitted data access first. Assess whether available MCP capabilities fit. Test correct results, missing permissions, outdated data and failure conditions before using the connection in a production workflow.
Useful measures
Task-suitable results
Whether the connection provides the correct information for the agreed task.
Permission enforcement
Whether forbidden access and actions are rejected in defined tests.
Integration effort
Setup, maintenance and error handling throughout use.
Common mistakes
- Describing MCP as an autonomous agent or model training.
- Treating a connected system as a blanket-approved data source.
- Confusing tool hints with enforced permissions.
Sources and context
- Model Context Protocol: Specification 2026-07-28
Official protocol specification, including security boundaries and optional capabilities.
- MCP: Tool Annotations as Risk Vocabulary
Tool descriptions are hints rather than enforced protections.
Frequently Asked Questions about Model Context Protocol (MCP)
MCP is a protocol for a particular form of integration. An MCP server may use existing APIs or other data access methods. It does not replace their business rules or permissions.
No. Security depends on the application, server, authentication, permissions and operation, among other factors. The specification describes requirements and principles but does not enforce all protections itself.
No. A direct interface or well-defined file import may be sufficient for a bounded task. MCP may help when supported applications and services should use a common integration approach.
Loading related terms…
All TermsArticles about Model Context Protocol (MCP)

AI with Brand DNA: Why Generic Bots Are a Brand Risk
Off-the-shelf AI assistants can dilute your brand. Learn how strategic calibration, guardrails, and red-teaming can transform a generic bot into a powerful, on-brand ambassador that positively impacts business outcomes.

Grok Bot Skills: How to Truly Scale AI in Your Marketing
Reusable task instructions help teams organise AI work consistently. Learn how to connect briefs, data, quality checks and version control, and measure the benefits in your own workflow.

Prompt Ops: The Operating System for AI in Marketing
The uncontrolled use of AI prompts leads to chaos. Prompt Ops provides a structured approach to manage prompts like software, ensuring efficiency, quality, and scalability in marketing.