MCP Server
A lightweight service that exposes tools, resources, and prompts to AI agents through the Model Context Protocol standard. MCP servers act as adapters between AI agents and external systems—a CRM MCP server exposes 'search contacts' and 'create deal' tools, a database MCP server exposes 'run query' and 'list tables.' Any agent that speaks MCP can discover and use these tools without custom integration code. Introduced by Anthropic in November 2024, MCP is now supported by Claude, ChatGPT, Gemini, Cursor, VS Code, JetBrains, and Zed, and the official registry crossed 5,000 servers by mid-2026. **Security note:** every connected MCP server is code you're running and a channel for Indirect Prompt Injection (XPIA) back into your model — see MCP Security, Tool Poisoning, Tool Shadowing (Cross-Server Attack), and our full [MCP security pillar](/blog/mcp-security-2026-attacks-and-defenses/).
Example
A developer builds an MCP server for their company's internal ticketing system, exposing 3 tools: searchTickets, createTicket, and updateStatus. Now any AI agent in the company (support bot, coding assistant, ops agent) can interact with the ticketing system through a standardized interface—no custom integration per agent. In production, that server runs in a container with an egress allowlist, uses MCP OAuth with Resource Indicators, and every tool call is logged with server name, session identity, and output size.
Frequently asked questions
- Do I need to build my own MCP server?
- Usually no. There are thousands of pre-built MCP servers for popular services (Slack, GitHub, PostgreSQL, Salesforce, etc.). Build your own only for internal/proprietary systems. Building an MCP server is straightforward—most are 100-300 lines of code that wrap your existing API endpoints in the MCP tool format.
- Are MCP servers safe to install from arbitrary sources?
- No. Treat MCP servers like npm packages that will run with your privileges — because they do. Real 2025-26 incidents (CVE-2025-49596 Inspector RCE, Nx s1ngularity, poisoned Nx Console) confirm the risk. Use an approved-server list, prefer first-party servers from the upstream vendor, sandbox each server, and enforce least-privilege OAuth with Resource Indicators. See MCP Security for the defense stack.