What is MCP?
MCP (Model Context Protocol) is an open protocol that lets AI applications connect to external tools, data sources and services in a standard way. Anthropic introduced it in November 2024, and today Claude Code, Codex and many other coding agents can use MCP servers.
How it works
MCP has two sides: the client, which runs the agent or app, and the server, which offers capabilities. When they connect, the server announces what it provides and the client describes those tools to the model. When the model wants to use one, the client forwards the call to the server and hands the result back to the model. Messages use JSON-RPC 2.0.
What a server provides
Server capabilities fall into three groups, and the connection can be local or remote.
- Tools: actions the model can call, like opening an issue, running a query or clicking on a page.
- Resources: data the model can read, such as files, records or documents.
- Prompts: ready-made prompt templates the server offers.
- Transports: stdio for local processes, HTTP for remote servers. Older servers may still use SSE.
Why it matters
Before MCP, every tool integration had to be written separately for every app. With a shared protocol, a GitHub, Playwright or database server is written once and works in any agent that speaks MCP. Other major providers, including OpenAI and Google, have added MCP support, which has made it the de facto standard for connecting coding agents to tools.
Security and cost
MCP is just a way to connect; how safe it is depends on the servers you install and the access you give them.
- A local MCP server is code running with your user permissions. Only install servers from sources you trust.
- Tool descriptions and tool results land in the model’s context, so malicious content can lead to prompt injection.
- Every server’s tool definitions are added to each request; unused servers inflate context and token spend.
- Don’t put tokens and passwords in config files as plain text.
MCP in AgentVera
The MCP manager (⌘⌥M) lets you add servers once instead of editing every CLI’s config file. Registered servers (stdio, HTTP and SSE) connect when agents start, to all agents or just the ones you pick.
- A catalog of 20 ready servers, including Playwright, GitHub, Context7, Sentry, Linear, Notion and Figma.
- A connection test lists the server’s tools with an approximate token cost for each.
- Secret environment variables and headers are kept in your operating system’s keychain.
- AgentVera adds its own MCP servers too: the shared board (agentvera-board) and the project map (agentvera-map).
- Agents that take MCP: Claude Code, Codex, opencode, Copilot, Qwen Code, Goose and Amp.
FAQ
Is MCP safe?
The protocol is just a way to connect; safety depends on the server. A server runs with your permissions and feeds content to the model. Install only servers you trust, don’t grant more access than needed and require approval for destructive actions.
What’s the difference between MCP and an API?
An API is a service’s own interface. MCP is a common way for AI apps to discover and use such services; an MCP server often calls an API behind the scenes.
Do MCP servers use tokens?
Yes. A server’s tool definitions are added to the context of every request, and tool results go to the model too. Turning off servers you don’t use keeps the context smaller.
What’s the difference between stdio and HTTP MCP servers?
A stdio server runs as a process on your machine and talks over standard input and output. An HTTP server runs remotely, is reached over the network and is usually authorized with OAuth or a token.