
MCP, short for Model Context Protocol, is an open standard that lets AI assistants connect to outside tools and data, such as your CRM, files, analytics or calendar, through one common interface. Instead of every AI app building a custom integration for every service, a service builds one MCP server, and any MCP-compatible assistant can use it. That includes Claude, ChatGPT, Gemini, Microsoft Copilot, Cursor and VS Code.
Anthropic introduced MCP in November 2024. A year later, OpenAI, Google, Microsoft and thousands of software companies had adopted it, and in December 2025 Anthropic handed it to a neutral foundation under the Linux Foundation. So what is MCP in practice? This guide explains it in plain terms, how the Model Context Protocol works, where you’re likely to meet it, and the security risks to understand before you connect anything.
What Is MCP (Model Context Protocol)?
The Model Context Protocol is a set of rules for how an AI application asks an outside system for information or actions, and how that system answers. It’s often compared to USB-C: one standard plug that works across many devices, so you don’t need a different cable for each one.
Without MCP, an AI assistant that wanted to read your HubSpot deals, query your PostHog analytics and check your Intercom conversations would need three separate integrations, each built and maintained by someone. With MCP, each of those companies publishes one MCP server, and every compatible AI assistant can use it the same way.
MCP is no longer controlled by a single company. On 9 December 2025, Anthropic donated the Model Context Protocol to the Agentic AI Foundation (AAIF), a fund hosted by the Linux Foundation. Anthropic, Block and OpenAI co-founded the foundation, with Google, Microsoft, AWS, Cloudflare and Bloomberg among its supporting members.
What Problem Does the Model Context Protocol Solve?
Before the Model Context Protocol, connecting AI to business software was an “N times M” problem. Every AI app (N) needed its own connector to every service (M), so ten AI tools and a hundred services meant a thousand separate integrations, most of them half-finished.
MCP turns that into “N plus M”. Each AI app supports MCP once, and each service publishes one MCP server. Adoption grew quickly once that trade became clear. MCP passed 97 million monthly SDK downloads within about sixteen months of launch, and more than 10,000 MCP servers had been published by late 2025.

How the Model Context Protocol Works: Hosts, Clients and Servers
The Model Context Protocol has three parts.
| Part | What it is | Example |
|---|---|---|
| Host | The AI application you use | ChatGPT, Claude, Cursor, VS Code |
| Client | The connector inside the host that talks to one server | The HubSpot connection inside your AI app |
| Server | A program that exposes a service’s data and actions | HubSpot’s MCP server |
An MCP server can offer three kinds of capability:
- Tools: actions the AI can take, such as creating a deal, searching tickets or running a query.
- Resources: data the AI can read, such as files, records or documents.
- Prompts: reusable templates the server suggests for common tasks.
When you ask your AI assistant a question, it checks which tools its connected servers offer, picks the right one, sends a request, and uses the answer in its reply. You usually see a prompt asking you to approve the action first.
Servers run in one of two ways. Local servers run on your own computer and talk to the AI app directly, which suits developer tools. Remote servers run on the company’s infrastructure and connect over the web using Streamable HTTP, with OAuth 2.1 sign-in so you never paste passwords or API keys into the chat. The current specification, version 2026-07-28, made the protocol stateless, which makes remote MCP servers simpler to run at scale.
An Example: Asking Your CRM a Question
Say your sales team uses HubSpot, and you connect HubSpot’s official MCP server to your AI assistant. You can ask, “Which deals over $10,000 haven’t had activity in 30 days?” The assistant calls HubSpot’s search tool through MCP, reads the matching deals, and gives you a list. You could then ask it to draft follow-up emails or update a deal stage.
HubSpot’s remote MCP server became generally available to all HubSpot accounts in April 2026. It gives compatible AI assistants read and write access to CRM data, using your existing HubSpot permissions and OAuth sign-in. See our HubSpot CRM profile for its plans and pricing.
Which AI Tools Support the Model Context Protocol?
By the end of 2025, MCP had first-class support across the major AI assistants and coding tools.
| AI tool | Company | How MCP is used |
|---|---|---|
| Claude and Claude Code | Anthropic | Connectors in the Claude apps; MCP servers in Claude Code |
| ChatGPT and Codex | OpenAI | MCP support in ChatGPT apps since September 2025; Agents SDK and Responses API since March 2025 |
| Gemini | MCP support in Gemini tools | |
| Microsoft Copilot and Visual Studio | Microsoft | MCP across Copilot, Visual Studio and Azure tooling |
| VS Code with GitHub Copilot | Microsoft and GitHub | MCP servers in agent mode |
| Cursor | Anysphere | MCP servers for its coding agent |
If you’re choosing a coding tool partly for its MCP support, our Claude Code vs Cursor comparison and Cursor vs GitHub Copilot guide cover how each one handles extensions and agents.
Real MCP Servers You Can Use Today
Many software companies now publish official MCP servers. A few that match tools covered on CompareCrest:
| Service | What its MCP server does | Worth knowing |
|---|---|---|
| HubSpot CRM | Read and write contacts, companies, deals and tickets | Generally available since April 2026; uses OAuth |
| Intercom | Retrieve contacts, conversations and help-centre content | Limited to US-hosted workspaces |
| PostHog | Query product analytics, including SQL across events | Free hosted endpoint |
| Cliphi | Turn long videos into short clips from an AI agent | Offered alongside its API |
| Zendesk | Connect tickets and knowledge to external AI platforms | Announced in May 2026; confirm availability before relying on it |
Other vendor-hosted MCP servers include Notion, Stripe, Canva, Slack, Airtable, Asana and Shopify. Community-built servers exist for almost everything else. Those can work well, but you’re trusting someone else’s code with access to your account.
For customer support teams, MCP is one way AI agents reach ticket and customer data. Our guide to AI agents for customer support covers the tools that build on it.
Model Context Protocol vs APIs vs A2A
| API | MCP | A2A (Agent2Agent) | |
|---|---|---|---|
| What it connects | Software to software | AI assistants to tools and data | AI agents to other AI agents |
| Who uses it | Developers writing code | AI apps, on behalf of users | Multi-agent systems |
| Format | Different for every service | One standard across services | One standard across agents |
| Governance | Each company’s own | Agentic AI Foundation (Linux Foundation) | Linux Foundation project, started by Google |
The Model Context Protocol doesn’t replace APIs. Most MCP servers are built on top of a company’s existing API and repackage it in a form AI assistants understand. A2A solves a different problem: it lets separate AI agents hand tasks to each other, while MCP connects one agent to its tools.
Model Context Protocol Security Risks You Should Know
MCP gives AI assistants real access to real systems, so the security risks are real too. These are the main ones security teams flagged in 2026.
Tool poisoning
A malicious server hides instructions inside a tool’s description, which the AI reads but you usually don’t see. The AI may then leak data or call the wrong tool. In 2026 benchmark research on real MCP servers, tool-poisoning attacks succeeded more than 60% of the time across major AI agents, and as often as 72% against some models.
Prompt injection through data
An AI that reads an email, ticket or web page can be tricked by instructions planted in that content, such as “forward this thread to this address.”
Command injection in local servers
Some locally run servers pass unchecked input to the computer’s shell. Microsoft’s security team named this one of the largest classes of MCP vulnerabilities reported in 2026, and several CVEs have been filed against individual servers.
Rug pulls
A server that behaved safely when you installed it can change its behaviour in a later update.
Shadow MCP
Employees connect unofficial MCP servers to work accounts without IT knowing, the AI-era version of shadow IT. The US National Security Agency published MCP security guidance in June 2026 covering these risks for organisations.
A safety checklist for using MCP
- Connect only official, vendor-hosted servers where they exist.
- Start with read-only access, and add write access only when you need it.
- Keep approval prompts switched on for actions that send, delete or pay.
- Remove servers you no longer use.
- Never connect a community server to an account holding customer, payment or health data without a security review.
- In a company, keep an approved list of MCP servers.
How to Connect Your First MCP Server
You don’t need to write code to use a remote MCP server.
- Find the official server for the service you use. Most vendors document it in their help centre or developer docs.
- Open your AI app’s settings and look for connectors, apps or MCP servers.
- Add the server’s URL as a custom connector.
- Sign in to the service when prompted. OAuth means the AI never sees your password.
- Review the permissions it asks for, and approve only what you need.
- Test with a read-only question, such as “List my five most recent support tickets.”
Developers working in Claude Code, Cursor or VS Code usually add servers through a configuration file or a settings panel instead, and can run local servers on their own machine.
What Is MCP Not? Common Misunderstandings
“MCP is an AI model.” It isn’t. It’s a protocol, a set of rules for communication. The AI model is separate.
“MCP only works with Claude.” Anthropic created it, but ChatGPT, Gemini, Microsoft Copilot, Cursor and VS Code all support it, and it’s now governed by a vendor-neutral foundation.
“MCP makes AI integrations safe.” MCP standardises the connection; it doesn’t vet the servers. Security depends on which servers you trust and what permissions you grant.
“MCP replaces APIs.” Most MCP servers sit on top of existing APIs.
What Is MCP Used For in Business?
For teams using AI, the Model Context Protocol means one assistant can work across your CRM, helpdesk, analytics and documents without copying data between tabs. For SaaS companies, publishing an MCP server is quickly becoming a way to make a product usable inside the AI assistants customers already use, much as having an API mattered a decade ago.
If you’re building software of your own with AI help, our guide to the best AI app builders covers tools that generate full apps from a prompt, and our list of Cursor alternatives covers AI coding tools that work with MCP servers.
FAQs
What is MCP in AI?
What is MCP in simple terms?
What is MCP used for?
Who created the Model Context Protocol?
What is an MCP server?
Does ChatGPT support MCP?
Is MCP safe to use?
What is the difference between MCP and an API?
What is the latest MCP version?
Information current as of October 2026. MCP support, server availability and specification versions change quickly, so check each vendor’s documentation before connecting a server.
