Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Use the transport that matches where the MCP server runs: create an MCPStdioTool for a local process, or an MCPStreamableHTTPTool for a remote endpoint. Pass that tool object to agent.run(), restrict the exposed tools, and keep credentials outside prompts and source code. Microsoft Agent Framework can also expose an agent or workflow as an MCP server.
What the integration does
Model Context Protocol (MCP) is an open standard for exposing tools and contextual data to AI applications. Microsoft Agent Framework supplies the agent loop: it discovers the tools made available by an MCP server, decides when a tool call is useful, sends the call, and incorporates the result into its response.
The connection has three moving parts:
- Transport: stdio for a process on the same machine, or streamable HTTP for a server reached over the network.
- Tool adapter: an Agent Framework MCP tool object that handles discovery and invocation.
- Policy: allowlists, authentication and approval rules that determine what the agent may actually do.
The Python API is the shortest path to a working integration. The APIs are still evolving, and Microsoft notes that the optional mcp package may require prerelease installation when you use MCPStdioTool, MCPStreamableHTTPTool or Agent.as_mcp_server(). Check the package version you install before copying an example into production.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Prerequisites and a safe starting setup
- Install Microsoft Agent Framework and the optional MCP dependency required by your selected integration.
- Have the MCP server’s launch command and arguments (stdio) or its HTTPS endpoint and authentication method (HTTP).
- Choose an Agent Framework chat client, such as the OpenAI chat client used below, and configure its provider credentials through environment variables.
- Decide which tools are read-only and which can mutate data before you connect the server.
Do not paste API keys, OAuth tokens or personal access tokens into prompts. Keep them in environment variables or a secret manager, and review what prompt and tool data is transmitted to a remote provider.
#1 Best Overall
Connect a local MCP server over stdio
Use stdio when Agent Framework should start a local MCP process and communicate with it through standard input and output. The context manager owns the process connection and closes it when the block exits.
Complete Python example
import asyncio
from agent_framework import Agent, MCPStdioTool
from agent_framework.openai import OpenAIChatClient
async def main():
async with (
MCPStdioTool(
name="calculator",
command="uvx",
args=["mcp-server-calculator"],
) as mcp_server,
Agent(
client=OpenAIChatClient(),
name="MathAgent",
instructions="You are a helpful math assistant.",
) as agent,
):
result = await agent.run("What is 15 * 23 + 45?", tools=mcp_server)
print(result)
asyncio.run(main())
Replace command and args with the executable and arguments for your server. For a filesystem or GitHub server, the command, package name and required environment variables come from that server’s own documentation. The important sequence is stable: enter the MCP context, create the agent, pass the MCP object in tools=, run the prompt, then let the context manager clean up.
What happens during a call
- Agent Framework starts the command and establishes the stdio session.
- The MCP server advertises its tools and schemas.
- The model receives those tool definitions along with your instructions.
- If the model selects a tool, Agent Framework sends the structured arguments and returns the server’s result to the model.
- The agent produces a final response, and the context manager shuts down the connection.
Keep the MCP context open while you perform several related runs instead of starting a new process for every prompt. That avoids repeated startup and discovery work. Close it promptly when the job or request scope ends.
Connect a remote MCP server with streamable HTTP
Use MCPStreamableHTTPTool when the server is hosted elsewhere. Supply the endpoint and, when required, a header provider or per-run invocation arguments for authentication.
Python pattern with a bearer token
import asyncio
import os
from agent_framework import Agent, MCPStreamableHTTPTool
from agent_framework.openai import OpenAIChatClient
def auth_headers():
token = os.environ["MCP_TOKEN"]
return {"Authorization": f"Bearer {token}"}
async def main():
async with (
MCPStreamableHTTPTool(
name="remote_tools",
url=os.environ["MCP_ENDPOINT"],
header_provider=auth_headers,
) as mcp_server,
Agent(
client=OpenAIChatClient(),
name="RemoteAgent",
instructions="Use remote tools only when they are necessary.",
) as agent,
):
result = await agent.run(
"Summarize the available project information.",
tools=mcp_server,
)
print(result)
asyncio.run(main())
Set MCP_ENDPOINT and MCP_TOKEN in the process environment. The exact header-provider callable can change with an installed prerelease, so follow the signature exposed by your version. Some integrations instead accept invocation-time arguments; use that route when a token must be selected per tenant or per request.
Rank #2
Remote authentication decisions
- Connection-time credentials: a header provider is convenient for one agent process that talks to one server.
- Per-run credentials: invocation arguments are better when requests represent different users, tenants or scopes.
- OAuth: keep refresh tokens in a secret store and pass only the short-lived access credential required by the server.
- Auditability: record which server, user or service identity and tool name were used, while redacting token values and sensitive arguments.
Remote servers are a larger trust boundary than local processes. Microsoft warns that third-party MCP servers are created by third parties, are not tested or verified by Microsoft, and may receive prompt content or return data to your application. Prefer a provider that hosts its own server over an unknown proxy, and check retention, data location and incident practices before sending confidential information.
Choose the transport deliberately
| Question | stdio | streamable HTTP |
|---|---|---|
| Where does code run? | A process started on the agent host | A remote MCP endpoint |
| Typical authentication | Local process permissions and environment | Headers, OAuth or per-run credentials |
| Primary failure mode | Executable missing, process exit or malformed stdout | DNS, TLS, HTTP status, timeout or server outage |
| Operational advantage | Simple local boundary and no network hop | Centralized service, shared tools and independent scaling |
| Main risk | Local filesystem and process privileges | Network exposure and third-party data handling |
There is no requirement that every server use the same transport. An agent can consume local and remote MCP tools together, provided each adapter is configured and the resulting tool names remain unambiguous.
Recommended Free Tools
.NET and Go integration patterns
.NET with the official MCP C# SDK
The .NET route uses the official MCP C# SDK rather than the Python adapter. The implementation flow is:
- Create an MCP client with the transport appropriate to the server: stdio for a local process or streamable HTTP for a remote endpoint.
- Retrieve the server’s tool list.
- Convert the discovered tools into
AIFunctionobjects. - Add those functions to the Agent Framework agent configuration.
- Dispose the client with
await usingso sockets, streams and child processes close reliably.
Apply the same policy controls as in Python: restrict the list before exposing it to the model, require approval for destructive functions and keep credentials out of source code. The exact C# type names and constructor overloads depend on the SDK version, so pin compatible package versions and compile against the API you install.
Go with mcptool
In Go, Microsoft’s mcptool package connects through the Go MCP SDK, lists the server’s tools and supplies them in the agent configuration. Both streamable HTTP and stdio transports are documented for this path. Treat the tool-list conversion as a boundary: validate names and schemas before making them available to the model, and close the client when the agent finishes.
Control what the agent can do
Allow only the tools needed for the task
Use allowed_tools to restrict a remote server’s surface. A research agent might receive search and read functions but not delete, write or account-management functions. Keep separate agents or separate policies for read and write workloads where possible.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesRequire approval for sensitive operations
Approval settings can require a person to confirm a tool call before it executes. Put a gate in front of destructive changes, external messages, purchases, credential changes and bulk operations. Approval should display the server, tool name and arguments in a form a reviewer can understand.
Use progressive disclosure for large servers
Progressive disclosure exposes loader functions first and loads selected tools later. This reduces the initial tool surface and avoids filling the model context with functions irrelevant to the current request. The loader itself still needs an allowlist and validation; hiding a tool is not the same as revoking permission.
Prevent name collisions
Give tools unique names or configure a prefix. Microsoft notes that ambiguous normalized names can raise ToolExecutionException. Collisions are common when two servers expose functions with generic names such as search, list or get_info. A server-specific prefix makes logs and approval prompts clearer as well as preventing dispatch errors.
Reliability, performance and observability
- Reuse sessions: keep a stdio or HTTP tool context alive for a related batch of runs, then close it deterministically.
- Set bounded timeouts: configure the HTTP client or hosting layer so an unavailable server cannot hold an agent request forever.
- Handle partial failure: tell the agent what to do when a tool is unavailable, and return a clear retry or manual-review state rather than fabricating a result.
- Log the right identifiers: record server identity, tool name, request ID, duration, outcome and approval decision; redact secrets and sensitive payloads.
- Plan for long tasks: Microsoft documents long-running MCP task examples. Use a job identifier, status polling or a callback pattern when a single conversational request is not an appropriate lifetime.
- Pin and test versions: MCP adapters and prerelease Agent Framework APIs can change. Run a startup health check that discovers tools and validates the expected names and schemas.
Or skip the browser setup
If your agent needs screenshots as part of an MCP workflow, ScreenshotNeo provides a website screenshot API and MCP server for developers. A single GET request returns PNG, JPEG, WebP or PDF, so you do not have to install or maintain a browser for that capture step. See the ScreenshotNeo documentation for current parameters.
Rank #4
For example, capture a page with cURL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
The same request in Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
And in Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo accepts cookie and consent banners like a visitor, then removes more than 60 known consent platforms, newsletter popups and chat widgets before capture; each cleanup step can be disabled. Only clean shots are billed: bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits cost nothing, and response headers identify the page verdict and billing status. Its MCP server exposes take_screenshot, get_page_info and capture_pdf to Claude, Cursor and other MCP clients.
Every feature is included on every plan. The Free plan provides 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account to try it without a card.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Expose your Agent Framework agent as an MCP server
The integration works in reverse too. Python agents can call agent.as_mcp_server() so another MCP client can discover and invoke the agent’s capabilities. Microsoft also documents the agent-framework-hosting-mcp package for exposing an Agent Framework agent or workflow through the native MCP SDK.
- Build and test the agent or workflow as usual.
- Define the narrow input and output contract that external MCP clients should see.
- Wrap the agent with
agent.as_mcp_server(), or use the hosting package when you need the native SDK’s server lifecycle. - Expose the chosen transport, authentication and approval policy.
- Test the server from an independent MCP client and verify that errors do not leak secrets or internal prompts.
Do not expose every internal tool merely because the agent can access it. Treat the hosted agent as a new public capability with its own authorization, rate limits, audit trail and shutdown behavior.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Troubleshooting common failures
| Symptom | Likely cause | Fix |
|---|---|---|
| The stdio tool never appears | The command is not on PATH, arguments are wrong or the process exits immediately. |
Run the command manually, verify its environment and inspect stderr. Confirm that stdout is reserved for MCP protocol messages. |
| Tool discovery succeeds but calls fail validation | The model supplied arguments that do not match the server schema. | Inspect the advertised schema, tighten instructions, validate inputs before execution and update the server if its schema is stale. |
| Remote calls return 401 or 403 | Missing, expired or incorrectly formatted credentials. | Check the header provider or per-run arguments, token scope and server clock requirements without printing the token. |
| The HTTP call hangs | Network, TLS or server-side work exceeds the client’s wait period. | Set a bounded timeout, test the endpoint outside the agent, and use a long-running task pattern for work that should not occupy one request. |
ToolExecutionException mentions ambiguity |
Two normalized tool names collide. | Rename tools or configure a server prefix, then update allowlists and approval rules. |
| A dangerous action runs without review | The approval policy is absent or attached to the wrong tool. | Require approval for the specific function, display its arguments and test the deny path before production. |
| The integration breaks after an upgrade | Prerelease Agent Framework or MCP APIs changed. | Pin compatible versions, consult the installed API signature, rerun discovery tests and update the adapter deliberately. |
FAQ
Can one Agent Framework agent use several MCP servers?
Yes. Create an adapter for each server and provide the resulting tools together, but use prefixes or unique names so dispatch remains unambiguous.
Is an MCP server automatically trusted because it is reachable over HTTPS?
No. HTTPS protects transport in transit; it does not verify the server’s code, retention policy or intended use of prompt data. Evaluate the provider and enforce an allowlist independently.
Best Value
Should an exposed agent return raw MCP errors to callers?
Usually not. Return a stable, useful error category and a correlation identifier, while keeping stack traces, credentials and internal prompts in protected logs.
Frequently Asked Questions
Can one Agent Framework agent use several MCP servers?
Yes. Create an adapter for each server and provide the resulting tools together, but use prefixes or unique names so dispatch remains unambiguous.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteIs an MCP server automatically trusted because it is reachable over HTTPS?
No. HTTPS protects transport in transit; it does not verify the server’s code, retention policy or intended use of prompt data. Evaluate the provider and enforce an allowlist independently.
Should an exposed agent return raw MCP errors to callers?
Usually not. Return a stable, useful error category and a correlation identifier, while keeping stack traces, credentials and internal prompts in protected logs.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

