Skip to content

Practical guide / Development and agents

What is MCP? Connecting an AI agent to your tools

MCP helps an AI application use tools and retrieve information. For a business, the key decisions are which connections it needs and which actions those connections should permit.

Contrast 3DPublished Updated 2 min read

Ceramic hub with three plugs connected and a fourth violet glass plug set apart on a tray
AI-generated conceptual illustration. Not a screenshot or a photograph.

What Model Context Protocol does

MCP connects AI applications with tools and sources of context. A server might offer a catalogue lookup, while a client lets the application access that function.

The shared interface helps with integration. You still need to decide who has access, which data is returned and which operations are allowed. Agents can also use APIs directly; MCP is one connection option. The connection alone does not make an AI agent reliable in production.

Start with one defined action

“Connect the CRM” is a broad requirement. “Retrieve an order’s status using an authorised identifier” is easier to design and review.

Define inputs, outputs and error cases. Separate queries from operations that change data. Preparing a draft may require different permissions from sending it.

Before connectingQuestion to resolve
IdentityOn whose behalf does the tool act?
ScopeWhich records can it read or change?
ConfirmationWhich actions require human involvement?
TraceabilityHow can activity be reconstructed?
RevocationHow is access removed?

Check versions at both ends

The July 2026 specification moves the core towards stateless operation and changes capability communication and multi-step exchanges.

Clients and servers do not necessarily migrate together. Before upgrading, check supported versions, SDKs and extensions. Test authentication failures, interruptions and retries as well.

A stateless protocol does not prevent your application from maintaining task state.

Review security across the integration

The NSA’s May 2026 guidance highlights access controls, trust between components and unnoticed changes to tools. It predates the July revision and should be read in that context.

Review the server and its tools before connecting it, restrict credentials and treat returned content as external data. A tool description should not be able to grant itself permissions.

Begin with test data and a read operation. Expand access when you can demonstrate both its usefulness and its boundaries.

If you are scoping an integration, tell us which system the agent needs to consult and what result you need. That gives the connection and its controls a concrete starting point.

Sources

Checked on September 20, 2026

All articles