What is the Model Context Protocol (MCP)?

The Model Context Protocol is an open standard that lets an AI assistant discover and call tools in other systems, such as searching a wiki or querying a database, through a common interface called an MCP server.

Written by Paul Madelénat. Last updated

How the Model Context Protocol works

Anthropic published the Model Context Protocol as an open specification in November 2024, and it has since been adopted by many AI clients and tool vendors. It solves a plumbing problem: before MCP, every assistant needed its own integration with every system it had to reach.

MCP splits the work in two. An MCP server sits in front of a system and describes what it offers as a list of tools, each with a name, a description and the arguments it takes. An MCP client, built into an assistant such as Claude or Cursor, or into an agent you write yourself, reads that list and lets the model call the tools while it works on a request. A server written once works with any client that speaks the protocol, so you can change assistants without changing your systems.

Remote MCP servers are reached over HTTPS, and the specification describes OAuth for signing users in.

The security questions it raises

An MCP server turns an app into something an AI model can act on, so it deserves the same care as any other way into that app. The main questions are simple to state:

  • Who is the assistant acting as? A shared service key gives every user the same broad access. Signing in each person through OAuth keeps their own permissions.
  • What can it change? Read-only tools carry less risk than tools that write, delete or send.
  • Where does the data go? What a tool returns travels to the model behind the client. If that must stay inside your perimeter, the model has to run there too.
  • Who can reach the server, and is every call recorded?

MCP at Pilae

Pilae deploys and operates an MCP server next to each app you choose, on your private network by default. Each person signs in through your identity provider, the assistant can do only what that person can already do in the app, and write tools can be switched off per app. Every tool call is kept in the console’s audit trail and can be exported to your SIEM.

When data must not leave your infrastructure, pair MCP with private AI on your own machines. Talk to an engineer to connect a first app.

Related on this site

Tell us what you need to run.

Thirty minutes with an engineer, a written plan and a fixed price for the first workload.