Practical guide / Development and agents
What is MCP? Connecting an AI agent to your tools
MCP helps an AI application use tools and retrieve information. For a business, the key decisions are which connections it needs and which actions those connections should permit.
What Model Context Protocol does
MCP connects AI applications with tools and sources of context. A server might offer a catalogue lookup, while a client lets the application access that function.
The shared interface helps with integration. You still need to decide who has access, which data is returned and which operations are allowed. Agents can also use APIs directly; MCP is one connection option. The connection alone does not make an AI agent reliable in production.
Start with one defined action
“Connect the CRM” is a broad requirement. “Retrieve an order’s status using an authorised identifier” is easier to design and review.
Define inputs, outputs and error cases. Separate queries from operations that change data. Preparing a draft may require different permissions from sending it.
| Before connecting | Question to resolve |
|---|---|
| Identity | On whose behalf does the tool act? |
| Scope | Which records can it read or change? |
| Confirmation | Which actions require human involvement? |
| Traceability | How can activity be reconstructed? |
| Revocation | How is access removed? |
Check versions at both ends
The July 2026 specification moves the core towards stateless operation and changes capability communication and multi-step exchanges.
Clients and servers do not necessarily migrate together. Before upgrading, check supported versions, SDKs and extensions. Test authentication failures, interruptions and retries as well.
A stateless protocol does not prevent your application from maintaining task state.
Review security across the integration
The NSA’s May 2026 guidance highlights access controls, trust between components and unnoticed changes to tools. It predates the July revision and should be read in that context.
Review the server and its tools before connecting it, restrict credentials and treat returned content as external data. A tool description should not be able to grant itself permissions.
Begin with test data and a read operation. Expand access when you can demonstrate both its usefulness and its boundaries.
If you are scoping an integration, tell us which system the agent needs to consult and what result you need. That gives the connection and its controls a concrete starting point.
Sources
Checked on September 20, 2026