Guide
MCP, the Model Context Protocol: how AI assistants connect to your company's tools and data
The Model Context Protocol (MCP) is an open-source standard for connecting AI applications such as Claude or ChatGPT to external systems: your files, databases, business tools and workflows. A company exposes what the AI may use through an MCP server (tools it can call, data it can read, prompt templates), and each AI application connects to it; done well, your team can ask their AI assistant to look up a client or file a task in your own system, with access rules and a log of every call.
What MCP is, in one paragraph
The official MCP documentation compares it to a USB-C port for AI applications: just as USB-C gives a standard way to connect devices, MCP gives a standard way to connect AI applications to external systems. Its examples include an assistant reaching your calendar and notes, a coding agent building an app from a design file, and company chatbots connected to several internal databases. The documentation lists support in AI assistants such as Claude and ChatGPT and in development tools such as Visual Studio Code and Cursor, so one server can serve many AI applications.
The three participants
A server can run locally, on the same machine as the AI application, using the stdio transport; or remotely, over the Streamable HTTP transport, typically serving many clients. For remote servers, the documentation says MCP supports standard HTTP authentication and recommends OAuth to obtain tokens.
| Participant | What it is | Example |
|---|---|---|
| MCP host | The AI application that coordinates one or more connections | Claude Code, Claude Desktop, an IDE |
| MCP client | The component inside the host that keeps one connection to one server | One client per connected server |
| MCP server | The program that provides context and actions to clients | Your CRM's MCP server, a filesystem server |
What a server can offer: tools, resources, prompts
Servers can also ask the user for more information or for confirmation of an action, through what the specification calls elicitation. The protocol itself uses JSON-RPC 2.0 messages. It evolves: the current documentation describes protocol version 2026-07-28, a stateless design in which each request carries its own version and capabilities, and marks some older features as deprecated. Check the version your tools support.
- Tools: functions the AI application can invoke to perform actions, such as an API call or a database query. For a business: “find this client”, “create a task”, “draft a quote”.
- Resources: data sources that give the AI context, such as file contents or database records. For a business: a product catalogue, a policy document.
- Prompts: reusable templates that structure interactions with the model. For a business: “weekly client summary”, “answer in our support tone”.
Connecting Claude to an MCP server
In Claude Code, Anthropic's documentation shows servers being added with the claude mcp add command, using a remote HTTP server (recommended), a local stdio server, or older transports. Servers can be configured for one project only, shared with the team through a .mcp.json file committed to the project, or for all of a user's projects. Many cloud MCP servers use OAuth 2.0: you add the server, then sign in through the browser.
Anthropic's documentation also carries a clear warning: verify you trust each server before connecting it, because servers that fetch external content can expose you to prompt injection risk.
Security rules that matter
The MCP project publishes security best practices. Several translate directly into business rules:
- Least privilege: grant minimal scopes first and ask for more only when a privileged action is needed; avoid wildcard or “full access” scopes.
- No token passthrough: an MCP server must not accept tokens that were not issued for it, nor forward a client's token unchanged to another service.
- Consent for local servers: before a one-click local server runs, the client must show the exact command and get explicit approval, since local servers run with the user's privileges.
- Never treat a handle as identity: servers that keep state must verify every request and must not treat possession of a state identifier as authentication.
- Trust and review: connect only servers you trust, and review what they can do.
Is it useful for a small business?
| Situation | MCP worth it? |
|---|---|
| Your team already uses an AI assistant daily and copies data into it by hand | Yes: a server can give it direct, controlled access |
| You have an internal system (CRM, task list, catalogue) with an API | Yes: an MCP server can expose a few safe tools on top of it |
| You want the AI to act in your tools (create, update) | Yes, with narrow tools, confirmations and logs |
| Your data lives only in spreadsheets on one laptop | Not yet: organise the data first |
What we built at Takat
We built an MCP server that lets our whole team plug their own Claude into our company operating system: each person connects their assistant, and every call is logged. It is the same pattern we offer to clients: a small set of well-named tools on top of your existing systems, access per person, confirmation for anything that changes data, and a full log. See Claude & MCP integrations and API integrations.
Questions we get
Is MCP only for Claude?
No. The official documentation describes MCP as an open protocol supported by AI assistants such as Claude and ChatGPT and by development tools such as Visual Studio Code and Cursor.
What is the difference between a tool and a resource?
A tool is an action the AI can call, such as querying a database or creating a record. A resource is data it can read for context, such as a file or a database record.
Is connecting an MCP server safe?
It depends on the server. Anthropic advises verifying that you trust each server before connecting it, because servers that fetch external content can expose you to prompt injection. Least-privilege access, confirmations and logs reduce the risk.
Can my team share the same MCP setup?
Yes. In Claude Code, a project-scoped configuration is stored in a .mcp.json file that can be committed so the whole team gets the same servers, while each person signs in with their own access.
Sources
- Model Context Protocol: What is MCP? (checked 2026-10-06)
- Model Context Protocol: Architecture overview (checked 2026-10-06)
- Model Context Protocol: Security best practices (checked 2026-10-06)
- Claude Code Docs: Connect Claude Code to tools via MCP (checked 2026-10-06)