Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Model Context Protocol (MCP) is an open protocol that lets an AI application connect to external tools and data through a consistent interface. It defines how context is exchanged and how capabilities are discovered and invoked; it is not an AI model, database, or complete agent framework. The host application still decides how to use model output, request permission, and orchestrate work.

The current reference point is the 2026-07-28 MCP specification. That revision makes the protocol stateless at the protocol layer, so requests carry the metadata they need instead of relying on hidden connection state.

What MCP means in practical terms

Think of MCP as a shared connector contract. An AI application can connect to many independent MCP servers, even when those servers were built by different teams. Each server publishes a defined set of capabilities, and the application invokes them using common protocol messages.

MCP standardizes communication and capability exchange. It does not decide which tool to call, whether an answer is correct, or whether a user should approve an action. Those responsibilities remain with the host application and its model-orchestration logic.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The three roles: host, client and server

Host

The host is the AI application the user interacts with. It coordinates model calls, manages permissions and consent, aggregates context, and controls connection lifecycles. A desktop AI app, coding assistant, or other model-powered product can act as a host.

Client

A client is the host-managed MCP component that speaks to one server. The relationship is one client to one server: a host using three servers generally maintains three corresponding client connections. The host may decide what conversation data or files cross each boundary; a server does not automatically receive the host’s entire conversation.

Server

An MCP server is a local process or remote service exposing focused capabilities. It may provide tools, resources, prompts, or only a subset of those features. MCP does not require every server to implement all three.

How an MCP interaction works

  1. Connection: The host starts or reaches a server and creates the appropriate client.
  2. Optional discovery: The client can call server/discover to learn supported protocol versions and capabilities. Discovery is useful for up-front knowledge, but it is not required before every operation.
  3. Request: The client sends a JSON-RPC request. In the current revision, the request includes the protocol version and client capability metadata needed for that operation.
  4. Execution: The server validates the request, performs the operation, and returns a result or an error.
  5. Orchestration: The host supplies the result to the model or presents it to the user, then decides whether another tool call or response is appropriate.

For example, a database server might expose a tool that runs an approved query, a resource containing the database schema, and a prompt template that helps a user formulate a request. These are separate capabilities with separate purposes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Tools, resources and prompts

Tools: operations and actions

Tools are operations a model can invoke through the host, such as searching, querying a service, or taking an action. A tool definition includes a name, description, and structured input schema. The server validates the supplied arguments, executes the operation, and returns structured or textual results.

Because tools can change data or trigger external effects, hosts should apply explicit consent and permission rules rather than treating every tool call as harmless.

Resources: readable context

Resources expose data for a client to read and use as context. Examples include a database schema, a file, or generated documentation. A resource is not automatically an instruction to perform an action; it is a way to make information available to the host and model.

Prompts: reusable interaction templates

Prompts are reusable templates that help a client or user form a structured interaction. A prompt can guide the model toward a particular workflow while leaving execution of any tools to the host.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Transport choices: STDIO or Streamable HTTP

Transport controls how MCP messages move. It does not change the meaning of the protocol operations. Both transports use the same JSON-RPC semantics.

Transport How messages move Typical fit Operational considerations
STDIO Newline-delimited messages over the standard input and output streams of a locally launched subprocess A server running on the same machine as the host Credentials should come from the environment; no network endpoint is required
Streamable HTTP HTTP POST requests to one MCP endpoint; a response can be JSON or a request-scoped Server-Sent Events stream A remote or centrally deployed service Requires endpoint, network, and HTTP authorization decisions

Choose based on locality, deployment, credential handling, and whether the server needs network exposure. A remote server is not inherently more capable, and a local server is not inherently safer.

What changed in the 2026-07-28 specification

Stateless requests

The current revision makes MCP stateless at the protocol layer. A server must not infer required context from an earlier request or connection. If an operation needs continuity, the server should return an explicit identifier and the model or client should send that identifier in later requests. The MCP maintainers describe the pattern this way: “If your server needs to carry state across calls, mint an explicit handle from a tool and have the model pass it back as an argument.”

Other revision-level changes

  • Multi Round-Trip Requests support cases where a server needs client input during an operation.
  • HTTP header-based routing details were added.
  • List and read responses became cache-aware.
  • Roots, Sampling, Logging, and legacy HTTP+SSE are deprecated, with at least a twelve-month deprecation window announced for the latter changes.

Older tutorials may describe connection-session state or legacy HTTP+SSE behavior. Check the host and SDK version you are deploying before relying on a newer feature or migrating an existing server.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Security, authorization and trust boundaries

MCP standardizes messages; it does not make a server trustworthy or make a tool safe automatically. Evaluate each server according to the files, credentials, network access, and actions it can reach. The host should show meaningful consent prompts, restrict available tools, and pass only the context needed for a task.

HTTP deployments

HTTP-based MCP implementations should follow the protocol’s authorization framework. The July 2026 guidance describes hardening such as issuer validation and issuer-bound client credentials, with a move toward Client ID Metadata Documents from Dynamic Client Registration. For production remote servers that access private data or act for a user, use a stable HTTPS endpoint and authorization.

STDIO deployments

STDIO integrations should obtain credentials from the environment rather than assuming the HTTP authorization flow applies. Keep secrets out of prompts, logs, and tool results. Peer identity and capability metadata are self-reported, so they should not be used as the sole basis for security decisions.

Designing an MCP server

  1. Define a narrow capability: Decide whether the server needs an action (tool), readable context (resource), reusable workflow (prompt), or a combination.
  2. Publish schemas: Give every tool a precise name, description, and input schema. Reject unknown or malformed arguments server-side.
  3. Select transport: Use STDIO for a host-launched local process; use Streamable HTTP when clients need a remote endpoint.
  4. Make state explicit: Return a handle from a tool when later calls need continuity, and require that handle as an argument on subsequent requests.
  5. Set permissions: Limit filesystem paths, network destinations, database operations, and destructive actions. Require user approval where consequences are material.
  6. Test failure paths: Return actionable JSON-RPC errors, handle timeouts, and ensure a failed external call cannot leave an unsafe partial operation.

Performance and reliability considerations

  • Discovery: Cache stable capability information when appropriate, but refresh it after server upgrades or configuration changes.
  • Latency: Local STDIO avoids a network hop; remote HTTP adds DNS, TLS, routing, and service latency. Keep tool schemas and returned context focused to reduce model and transport overhead.
  • Timeouts: Set client-side deadlines for slow tools and return a clear error. A host should not wait indefinitely for a server that has stopped responding.
  • Retries: Retry only operations known to be safe or idempotent. Repeating a payment, deletion, or other side effect can be dangerous.
  • Observability: Log request identifiers, durations, and error classes without recording secrets or unnecessary user content.
  • Compatibility: Verify protocol and SDK support on both sides, especially when using features introduced in the 2026-07-28 revision or migrating away from deprecated behavior.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common errors and fixes

“Server not found” or immediate process exit

For STDIO, check the executable path, working directory, permissions, and environment variables. Run the server directly and inspect stderr. For HTTP, verify the endpoint URL, DNS, TLS certificate, firewall, and whether the server actually accepts POST requests at that path.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Unsupported protocol version”

The host and server advertise incompatible revisions. Upgrade the older SDK where possible, or configure both sides to a mutually supported version. Do not assume a tutorial written before 2026-07-28 reflects current behavior.

Tool arguments rejected

Compare the model-generated JSON with the published input schema. Check required properties, data types, enum values, and nesting. Keep validation on the server even if the host performs client-side validation.

Unauthorized HTTP request

Confirm that the access token is present, unexpired, intended for the correct issuer and resource, and sent using the server’s documented authorization mechanism. Do not copy an HTTP OAuth setup into a local STDIO integration without checking its credential requirements.

Later calls lose context

This is expected if the implementation relied on hidden connection state. Return an explicit operation handle and require the client or model to send it on every subsequent call.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Action runs twice after a retry

Treat the tool as non-idempotent, disable automatic retries, or add an application-level idempotency key and server-side deduplication before allowing retries.

MCP and ScreenshotNeo

ScreenshotNeo is a website screenshot API and MCP server. Its MCP tools include take_screenshot, get_page_info, and capture_pdf, allowing Claude, Cursor, or another MCP client to request page captures through an AI host. This is a concrete example of MCP’s tool model: the host decides when to invoke a screenshot capability, and the server performs the capture.

ScreenshotNeo also accepts one GET request for a PNG, JPEG, WebP, or PDF. Its cleaner accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing result.

Or skip the browser setup

For a direct capture, use the API documented at https://screenshotneo.com/docs/:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Cookie banners, popups, and chat widgets are removed before the shot. Bot checks, blank pages, and failed loads are never billed. The MCP server lets AI agents take screenshots, 1,000 screenshots each month are free with no card, and paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

How MCP differs from related concepts

  • Not an AI model: MCP carries messages and capabilities; the host supplies the model.
  • Not a database: A server may expose database data, but MCP itself stores none of it.
  • Not a complete agent framework: Planning, memory policy, approvals, and orchestration remain host responsibilities.
  • Not an authorization guarantee: Protocol compatibility says nothing by itself about whether a server deserves access to your data.

Frequently Asked Questions

Does every MCP server need tools, resources and prompts?

No. A server implements the capabilities its application requires; it may expose one category or several.

Can one MCP client connect to multiple servers?

The usual model is one client connection per server, managed by a host that can run multiple clients.

Is MCP limited to cloud services?

No. STDIO is designed for a locally launched subprocess, while Streamable HTTP supports remote services.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should I check before upgrading an MCP integration?

Verify host and SDK support for the target specification, review the 2026-07-28 stateless behavior and deprecations, and retest authorization, retries, and state handling.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.