SHORT ANSWER
Model Context Protocol (MCP) is an open standard that connects AI applications to tools, data and business systems through one common interface. Anthropic introduced it in November 2024 and donated it to the Agentic AI Foundation under the Linux Foundation in December 2025. The current specification, dated 2026-07-28, makes the protocol stateless and hardens OAuth-based authorization for remote servers.
You want your AI assistants to work with your CRM, your data warehouse and your document store, without building a new connector for every model vendor. Model Context Protocol (MCP) is an open standard for exactly that. You expose a system once as an MCP server, and any MCP-compatible client (an assistant, a copilot or an agent) can discover what it offers and use it. People often call it a USB-C port for AI.
Who created MCP, and who governs it now?
Anthropic introduced MCP as an open-source protocol in November 2024. In December 2025, Anthropic donated it to the Agentic AI Foundation (AAIF), a new foundation under the Linux Foundation, alongside Block’s goose agent framework and OpenAI’s AGENTS.md. Platinum members include Amazon Web Services, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft and OpenAI, so no single vendor controls the standard.
The specification is versioned by date. Key releases so far:
Version | Notable changes |
|---|---|
2024-11-05 | First public release: tools, resources, prompts, local and HTTP transports |
2025-03-26 and 2025-06-18 | OAuth-based authorization for HTTP servers, Streamable HTTP transport, structured tool output |
2025-11-25 | Improved client registration, incremental scope consent, machine-to-machine (client credentials) flows, experimental tasks |
2026-07-28 (current) | Stateless protocol core without sessions, a formal extensions framework, authorization hardening, deprecation of roots, sampling and logging |
The 2026-07-28 release matters for enterprises because a stateless protocol can run behind a standard load balancer. That makes remote MCP servers easier to scale and operate like any other web service.
How does MCP work?
MCP has three roles. The host is the AI application the user works in, for example a chat assistant or an IDE. The client is the component inside the host that talks to servers. The server exposes capabilities from a system, such as a CRM, a data warehouse or a document store. A server can offer:
Tools: actions the model can call, such as search_orders or create_ticket, each with a typed input schema.
Resources: read-only content, such as files, records or schemas, that the application can load as context.
Prompts: reusable templates that guide the model through a task.
Messages use JSON-RPC. The client lists what a server offers, the model chooses a tool, the client calls it and the result goes back to the model.
How does MCP compare with plain APIs and function calling?
| Direct API calls | Model function calling | MCP |
|---|---|---|---|
What it is | Your code calls a REST or GraphQL API | Model returns a structured request to call a function you defined | Standard protocol for exposing tools and data to any AI client |
Portability | One connector per application | Tool definitions tied to one vendor’s format | Build once, use in any MCP-compatible client |
Discovery | Read the docs | Tools hard-coded in each app | Clients list tools and resources at runtime |
Authorization | Whatever the API uses | Handled by your application | OAuth-based flow defined for remote servers |
Best for | Deterministic application logic | A single app with a few tools | Many AI clients sharing the same enterprise systems |
MCP doesn’t replace APIs. An MCP server usually wraps existing APIs, and function calling is still how the model inside the client decides which tool to call. MCP standardises the layer in between.
What is the difference between local and remote MCP servers?
Local servers run on the user’s machine and talk to the client over standard input and output (stdio). They suit developer tools and access to local files. They run with the user’s own permissions, so installing one is similar to installing software.
Remote servers run as web services over HTTP and serve many users. They use the specification’s OAuth-based authorization, where the MCP server acts as an OAuth resource server and your identity provider issues tokens. For enterprises, remote servers are usually the right default because they can be approved, secured and monitored centrally.
Who supports MCP?
Adoption is broad. Anthropic’s Claude applications, OpenAI’s Agents SDK and ChatGPT, Google’s Gemini tooling, Microsoft products such as Copilot Studio and GitHub Copilot, and AWS services all support MCP clients or servers. Many SaaS vendors now publish official MCP servers for their products. Check each vendor’s documentation for the specification version and features it supports, because support for the 2026-07-28 release is still rolling out.
How do enterprises use MCP?
Giving assistants governed access to internal data, for example a server over a semantic layer so answers use approved metric definitions.
Standardising tools for agents, so the same ERP or ticketing tools serve several enterprise agents.
Connecting knowledge sources, such as document stores or a knowledge graph, to chat assistants.
Developer productivity, connecting coding assistants to repositories, issue trackers and CI/CD.
What we learned building a knowledge-graph assistant
We built a GraphRAG chatbot that lets leadership at a multi-team enterprise ask questions such as who owns the at-risk deliverables this sprint. The model translates each question into a graph query. Straightforward questions translated reliably once we gave the model the exact graph schema as context at query time. Ambiguous, compound questions sometimes produced wrong queries, and that stayed the area with the most room for improvement.
Two lessons carry over to MCP. Narrow, well-described tools beat broad ones like run_sql, because the model has less room to guess. And people trust the answers when they can see the work: we added a transparency mode that shows the generated query behind every response, which is what won over leadership.
What should you control for MCP security?
Authorization. Use OAuth for remote servers, short-lived tokens scoped to each server, and act on behalf of the signed-in user rather than a shared super-user account.
Tool permissions. Expose narrow tools (get_invoice) rather than broad ones (run_sql). Require user confirmation for tools that write or send data.
Prompt injection. Tool results can contain hostile instructions. Treat them as data, and limit what an agent can do after reading untrusted content. See what is prompt injection.
Server supply chain. Maintain an allow-list of approved servers, pin versions and review tool descriptions for changes.
Logging and monitoring. Log every tool call with user, inputs and outcome, and alert on unusual volumes.
The specification changes quickly, so check the official MCP specification and each vendor’s documentation before you build. This guide is general information, not legal advice.
How RUBICON helps with MCP
We design and build MCP servers over enterprise systems and data platforms, including authorization, tool design, evaluation and monitoring, and connect them to the assistants and agents your teams already use. See our AI agent development services.
We’re about 55 people, 40+ engineers, ISO 27001:2022 certified and a Microsoft Solutions Partner for Cloud & AI Platforms. If you’re planning your first MCP server, our architects can review the design with you.
Frequently asked questions
Who created Model Context Protocol?
Anthropic created MCP and released it as an open standard in November 2024. In December 2025 it was contributed to the Agentic AI Foundation, a Linux Foundation project whose founding contributions also included Block's goose and OpenAI's AGENTS.md. The specification and official SDKs are now developed under vendor-neutral, community governance.
Is MCP the same as an API?
No. An MCP server usually sits in front of existing APIs. The API does the actual work, while MCP describes the available tools, resources and prompts in a standard way that any MCP-compatible AI client can discover and call. You build the connection once as an MCP server instead of once per AI application or model vendor.
Is MCP secure enough for enterprise use?
It can be, with the right controls. Remote MCP servers should use the OAuth-based authorization defined in the specification, short-lived scoped tokens, least-privilege tools and logging of every call. The main risks are over-permissioned tools, prompt injection through tool results and untrusted third-party servers, so approve servers centrally and review tool descriptions when they change.
What is the difference between a local and a remote MCP server?
A local server runs on the user's machine and talks to the client over standard input and output, which suits developer tools and file access. A remote server runs as a web service over HTTP, serves many users and uses OAuth for authorization. Enterprises usually prefer remote servers because they can manage, secure and monitor them centrally.
Related case study

Enterprise GraphRAG Chatbot with Neo4j | Case Study
How RUBICON's Two Layer Fixed Entity Architecture eliminated data bottlenecks for a multi team enterprise, delivering a conversational AI system that gives leadership instant project clarity, without hallucinations.
More resources
