MCP for developers: connect tools through a shared protocol
Understand the host, client, and server roles in Model Context Protocol and how to think about tool boundaries.
On this page
Model Context Protocol (MCP) is an open protocol for connecting AI applications to external tools and context. It gives hosts and servers a common way to discover capabilities and exchange structured messages.
The protocol standardizes the connection. It does not decide whether a particular tool is safe, trustworthy, or appropriate for a user's task.
The three roles
The host is the AI application the person uses. It creates an MCP client for each server connection. The server exposes capabilities such as tools, resources, and prompts through the protocol.
Keeping these roles distinct helps answer practical questions: who starts a process, who sees a capability, and where should access control live?
Tools are capabilities, not permissions
An MCP server can describe a tool and its input schema. The host can show that tool to a model, and a client can send a call to the server. The server still needs to validate arguments and enforce the permissions of the current user.
Choose a transport deliberately
For a local integration, a process-based transport can be convenient because the host launches a server on the same machine. Remote deployments need an appropriate network transport, identity model, and operational controls.
Do not pass secrets in source code or commit them in a server configuration. Use the host's supported secret management and make the server's access needs as small as possible.
Design a useful server
Keep tools focused and their descriptions concrete. Use structured input, return concise results with provenance, and provide actionable errors. Test the server independently before connecting it to a model.
When a task is read-only, expose a read-only capability. When a task changes external state, make the effect clear and consider a human approval step at the host.
A small first integration
Start with one local, read-only tool and a non-sensitive data source. Verify discovery, valid and invalid calls, process shutdown, and error behavior. Then add capabilities one at a time.
MCP helps integrations interoperate. Good tool design and least-privilege access are still the work that makes an integration dependable.
Keep learning with Sri
More practical tutorials and experiments on the channel.