What Is MCP? A Practical Introduction to the Model Context Protocol

What the Model Context Protocol is, how hosts, clients and servers fit together, and how to connect your first MCP servers to Claude Code, Cursor and other AI tools safely.

AgentIndex · Published 2026-10-07 · Updated 2026-10-07

If you use an AI coding assistant or chat app today, you have probably seen "MCP support" in its feature list. The Model Context Protocol (MCP) is an open standard, introduced by Anthropic in late 2024, that defines how AI applications connect to external tools and data. Instead of every app inventing its own plugin format, a tool author writes one MCP server, and any MCP-compatible application can use it.

The ecosystem has grown quickly. In the AgentIndex directory, 1,389 of the 2,807 listed open-source tools mention MCP in their name or tags, and 138 of those have more than 1,000 GitHub stars. This guide explains how MCP works, walks through connecting real servers, and covers the security habits worth adopting from day one.

The problem MCP solves

A language model on its own only knows what was in its training data and what you paste into the conversation. To be useful for real work it needs to read today's documentation, look at your repository, query a database or click through a web page. Before MCP, each of these integrations was built separately for each application: a plugin for one editor, a different extension for another chat client.

MCP turns this into a many-to-many standard. Write the integration once as a server, and it works in Claude Code, Cursor, VS Code, Gemini CLI and any other client that speaks the protocol.

How MCP fits together

There are three roles:

  • Host: the application you interact with, such as Claude Desktop, Claude Code, Cursor or VS Code.
  • Client: a connector inside the host. The host creates one client per server it connects to.
  • Server: a program that exposes capabilities to the model. It can run on your machine or as a remote web service.

A server can offer three kinds of capabilities:

  • Tools: functions the model can decide to call, such as "search the docs", "create an issue" or "click this button".
  • Resources: data the application can read and add to the model's context, such as files or records.
  • Prompts: reusable prompt templates the user can pick.

Messages between client and server use JSON-RPC. They travel over one of two transports:

TransportHow it runsTypical use
stdioThe host starts the server as a local process and talks to it over standard input and outputTools that need your local files, browser or command line
Streamable HTTPThe server is a web endpoint the client calls over HTTPSHosted services, shared team servers, SaaS integrations

Knowing which transport a server uses tells you a lot: a local stdio server runs with your user's permissions, while a remote server sees whatever data you send it.

Connecting your first servers

The examples below use three popular servers from the directory. Commands come from each project's own README; check it for the latest options.

A local server: Playwright MCP

Playwright MCP lets the model drive a real browser through Playwright. It runs locally over stdio. In Claude Code you can add it with one command:

claude mcp add playwright npx @playwright/mcp@latest

In clients configured with a JSON file, such as Cursor (~/.cursor/mcp.json or .cursor/mcp.json in a project) or Claude Desktop, the same server looks like this:

{
  "mcpServers": {
    "playwright": {
      "command": "npx",
      "args": ["@playwright/mcp@latest"]
    }
  }
}

A remote server: Context7

Context7 feeds up-to-date, version-specific library documentation into your assistant so it stops inventing APIs. It is available as a remote server at https://mcp.context7.com/mcp, authenticated with an API key sent as a bearer token. In Claude Code:

claude mcp add --transport http context7 https://mcp.context7.com/mcp \
  --header "Authorization: Bearer YOUR_API_KEY"

In a JSON-configured client, a remote server uses url and headers instead of command:

{
  "mcpServers": {
    "context7": {
      "url": "https://mcp.context7.com/mcp",
      "headers": { "Authorization": "Bearer YOUR_API_KEY" }
    }
  }
}

Context7 also offers npx ctx7 setup, which signs you in and writes this configuration for Cursor, Claude Code or OpenCode automatically.

A server with write access: GitHub MCP Server

The official GitHub MCP Server lets an agent read repositories, issues and pull requests, and also create or modify them. GitHub hosts a remote version at https://api.githubcopilot.com/mcp/ that supports OAuth or a personal access token, and you can run it yourself with Docker. Two options from its README are worth knowing:

  • --toolsets limits which groups of GitHub capabilities are exposed, for example only repos,issues,pull_requests. Fewer tools also means less context used and better tool choice by the model.
  • --read-only exposes only read operations, so the agent cannot change repositories, issues or pull requests.

Start with read-only access and add write capabilities once you trust the workflow.

Security habits that matter

MCP servers act with real permissions, so treat installing one like installing any other software.

  1. Know what runs where. A stdio server is a local program with your user's file and network access. Prefer servers from known publishers and pin versions for anything sensitive.
  2. Grant the minimum. Use read-only modes, toolset filters and narrowly scoped tokens. A personal access token with access to every repository is rarely necessary.
  3. Keep secrets out of shared files. Project-level config files are often committed to git. Use environment variables or your client's secret input mechanism for tokens.
  4. Treat tool output as untrusted. Web pages, issues and documents can contain instructions aimed at the model (prompt injection). Review actions that write data or run commands before approving them.
  5. Prune unused servers. Every connected server adds tool descriptions to the model's context. Too many servers make tool selection worse and slow every request.

When MCP is not the best choice

MCP is not the only way to give an agent capabilities. The Playwright team notes in its README that coding agents increasingly prefer command-line tools combined with skills, because a short CLI command uses far fewer tokens than loading large tool schemas and page snapshots into context. Context7 likewise offers a CLI-plus-skill mode that needs no MCP at all.

A reasonable rule: use MCP when you want a capability to work across many clients or when the tool needs structured, interactive access (a browser session, an authenticated API). Use a CLI or skill when a coding agent can get the same result with a few concise commands.

Where to go next

  • Browse the MCP Servers category and community lists such as awesome-mcp-servers to find servers for your stack.
  • Try Chrome DevTools MCP if you want your coding agent to inspect and debug pages in Chrome.
  • If you want to build your own server in Python, FastMCP is a widely used framework for writing MCP servers and clients.

MCP's value grows with each server you connect, but so does the surface you need to trust. Start with one or two well-maintained servers, keep their permissions tight, and expand from there.