Field notes · AI Agency

    What Is MCP in AI Agents? The Model Context Protocol Explained.

    MCP (Model Context Protocol) is the open standard that lets AI agents talk to your tools and data. Origins, architecture, real implementations, and how ACA's native MCP server works.

    9 sections
    AI Agency
    9
    What Is MCP in AI Agents? The Model Context Protocol Explained

    MCP (Model Context Protocol) is an open standard introduced by Anthropic in November 2024 that lets AI agents connect to external tools, data sources, and applications through a single shared interface. Think of it as USB-C for AI: instead of every model needing a custom integration for every tool, MCP defines one protocol that any compliant agent can use to call any compliant service. It is fast becoming the default way to give AI agents real capabilities in the real world.

    Short answer: The Model Context Protocol (MCP) is an open standard for connecting AI agents to external tools and data. An MCP server exposes capabilities (functions, files, APIs) and an MCP client (the agent or the model runtime) calls them. It replaces the messy world of custom integrations with one protocol any model can speak. Anthropic shipped it open source in late 2024 and OpenAI, Google, and major dev tools adopted it through 2025.

    The Problem MCP Solves

    Before MCP, every team building with AI agents had the same problem: how do you give the model access to your CRM, your inbox, your file system, your database, your outreach platform? Each tool needed a bespoke integration. Each model provider had its own function-calling format. Switching from Claude to GPT to Gemini meant rewriting your entire tool layer. Maintaining 20 tools across 3 models meant maintaining 60 integrations.

    The same problem existed in hardware before USB. Every peripheral needed its own port. Then USB defined one physical and logical standard, and the industry consolidated. MCP is doing the same thing for AI agents and the services they need to use.

    Model Context Protocol (MCP) is an open specification, released by Anthropic in November 2024, that standardizes how AI applications connect to external systems. It defines a JSON-RPC based protocol with two roles: MCP servers (which expose tools, resources, and prompts) and MCP clients (which the AI agent uses to discover and invoke those capabilities). Any compliant client can use any compliant server, regardless of which underlying model is doing the reasoning.

    Origins and Adoption

    Anthropic open-sourced MCP on November 25, 2024, alongside reference implementations in Python and TypeScript and a set of pre-built servers for Google Drive, Slack, GitHub, Postgres, Puppeteer, and others. The intent was clear from day one: this was not a Claude feature. It was an industry protocol that Anthropic hoped others would adopt.

    That bet paid off quickly. Through 2025, MCP support shipped in Claude Desktop, Cursor, Windsurf, Zed, Cline, and dozens of other AI development environments. OpenAI added MCP compatibility in its Agents SDK. Google's Gemini followed. By mid-2025 there were public registries listing hundreds of community MCP servers covering everything from Figma to Stripe to Kubernetes.

    The reason adoption moved so fast is simple. The protocol is small, the spec is readable in an afternoon, and the upside is huge: a single integration into MCP gives your tool access to every major AI agent runtime at once.

    How MCP Works: Architecture

    MCP follows a client-server architecture built on JSON-RPC 2.0. There are three primitives a server can expose:

    • Tools are functions the agent can call. A tool has a name, a description, and a JSON schema for its inputs. The model picks tools to invoke and the runtime executes them. Example: send_linkedin_message(prospect_id, body).
    • Resources are read-only data the agent can fetch. They behave like files or URLs the model can reference. Example: a CRM contact, a calendar event, the contents of a document.
    • Prompts are reusable templates the server offers to the client. They let a service ship best-practice prompts for its domain so users do not have to write them from scratch.

    The flow looks like this:

    1. The MCP client (Claude Desktop, Cursor, an agent runtime) starts up and connects to one or more configured MCP servers.
    2. The client calls list_tools on each server to discover what is available.
    3. When the user asks the agent to do something, the model sees the available tools in its context and decides which to call.
    4. The client routes the tool call to the right server, gets the result, and passes it back to the model.
    5. The model reasons over the result and either calls another tool or replies to the user.

    Transport is flexible. The protocol supports stdio for local processes, HTTP with Server-Sent Events for remote servers, and WebSockets. A locally running MCP server can read your filesystem. A remote MCP server can manage your cloud SaaS account. Same protocol, different transport.

    MCP vs Function Calling: What Is Different

    Most AI agents already use function calling. So why MCP?

    Function calling is a feature of a specific model provider. OpenAI has its function calling format. Anthropic has tools. Gemini has function declarations. They look similar but they are not interchangeable. If you build a custom tool for one, you wrap it differently for the next.

    MCP sits one layer above. It is a protocol, not a feature of a model. The MCP client handles the translation between MCP tool definitions and whatever format the underlying model expects. The result: you write your integration once, and it works with any model behind any MCP-compatible client.

    Use raw function calling when: you are building a tightly scoped agent against one model, you do not need third-party tool reuse, and you want minimum runtime overhead.

    Use MCP when: you want your tool to work across models and clients, you are building an integration you plan to ship to many users, or you want to leverage the growing ecosystem of community MCP servers without writing each one yourself.

    Real MCP Implementations in the Wild

    By late 2025, the MCP ecosystem covers most of the categories an agent would need to act in the world:

    • Developer tools: GitHub (issues, PRs, repos), GitLab, Linear, Jira, Sentry, filesystem access, git operations, shell execution.
    • Data and analytics: Postgres, MySQL, Snowflake, BigQuery, Supabase, vector stores like Pinecone and Qdrant.
    • Productivity: Google Drive, Notion, Slack, Gmail, Google Calendar, Microsoft 365.
    • Web automation: Puppeteer, Playwright, Browserbase for headless browser control by the agent.
    • Business systems: Stripe, HubSpot, Salesforce, Intercom, and increasingly, full outreach and CRM platforms.

    This is what "AI agents that actually do things" looks like in practice. The agent runtime stays small. The capabilities come from the constellation of MCP servers it connects to.

    ACA's Native MCP Server

    ACA ships a native MCP server. Any MCP-compatible agent (Claude Desktop, Cursor, a custom agent built with the OpenAI Agents SDK, or anything else) can connect to ACA and operate the platform programmatically.

    What that means in practice: instead of you logging into a dashboard to send a LinkedIn message or update a CRM record, you tell an agent what you want, and the agent calls ACA through MCP to do it. The agent has tools for:

    • Outreach: create campaigns, add prospects to sequences, send messages across LinkedIn, email, WhatsApp, Instagram, Telegram, and SMS, pause or branch sequences based on responses.
    • CRM: query contacts, score leads against your ICP, move deals through pipeline stages, attach notes and signals to records.
    • Content: generate posts, carousels, newsletters, and video scripts using your brand voice, schedule them across channels, pull performance metrics back into the agent's context.
    • Inbox: read incoming messages across all 6 channels in one unified feed, draft replies, hand off to a human when an agent's confidence is low.

    The architectural point: ACA stops being a SaaS dashboard you log into and becomes a capability surface your agents drive. Build a sales agent that runs your outreach overnight. Build a content agent that publishes for 30 clients on Monday morning. Build an inbox triage agent that filters replies and books meetings only with qualified leads. The platform does the heavy lifting. The agent does the orchestration.

    Why this matters for agencies: a single AI agency operator using MCP-driven workflows can manage outreach, content, and CRM across 10 to 20 clients without proportionally adding hours. The agent handles routine operations through the MCP server. The human handles strategy, edge cases, and client conversations. This is the operating model that lets a solo founder scale to multiple six figures of monthly recurring revenue without hiring a team.

    Building Your Own MCP Server

    If you have an internal tool, API, or database you want your AI agents to use, building an MCP server is straightforward. Anthropic publishes SDKs in Python and TypeScript with a few dozen lines getting you a working server.

    The pattern:

    1. Define your tools as functions with typed inputs and a clear description. The description is what the model reads to decide whether to call your tool, so write it for an LLM, not a human developer.
    2. Register the tools with the SDK's server object.
    3. Run the server over stdio (for local agents) or HTTP/SSE (for remote agents).
    4. Add the server to your MCP client's config and the tools appear automatically in the next session.

    The discipline is in two areas: tool descriptions and security. Models pick tools based on descriptions, so a fuzzy description gets your tool ignored or misused. And because tools can do real things (send money, send emails, write to databases), you need to think hard about authentication, scoping, and confirmation flows for destructive actions.

    What MCP Changes About AI Agent Strategy

    MCP shifts the center of gravity in AI agent development. Two years ago, the question was "which model do I use?" The answer mattered a lot because each model had its own tool ecosystem. Now the question is "which capabilities does my agent need?" The model is becoming a swappable reasoning engine. The MCP servers are where the real value lives.

    For people building AI businesses, the practical takeaway is this: do not over-invest in any single model's proprietary tooling. Build against MCP. Use an agent runtime that speaks MCP. Choose platforms that ship MCP servers natively. When the next model release shifts the price-performance curve, you swap the model and your stack keeps working.

    This is also why the agencies that win in 2026 are not the ones with the cleverest prompts. They are the ones with the deepest capability surface. An agency that connects an agent to outreach + CRM + content + inbox through one MCP-compatible platform can deliver outcomes that competitors stitching together 9 separate tools cannot match.

    Frequently Asked Questions

    Who created MCP and when?

    Anthropic released MCP as an open standard on November 25, 2024. The reference implementations, the specification, and the initial set of MCP servers were all open source from day one. Anthropic deliberately positioned MCP as an industry protocol rather than a Claude feature, and through 2025 most major AI runtimes and IDEs adopted it.

    Is MCP only for Claude?

    No. MCP is model-agnostic. It is a protocol that sits between the AI client (the runtime hosting the model) and the tools or data the agent needs. Claude Desktop was the first MCP client, but OpenAI's Agents SDK, Google's Gemini tooling, Cursor, Windsurf, Cline, Zed, and many others now speak MCP. Any model can be the brain behind an MCP-driven agent.

    What is the difference between MCP and an API?

    An API is a way for software to call a service. MCP is a way for an AI agent to discover what an API can do and call it without prior hardcoding. An MCP server typically wraps one or more underlying APIs and exposes them in a format the agent's model can reason about. You still need APIs underneath. MCP just makes them accessible to AI agents in a standardized way.

    Is MCP secure?

    The protocol itself is transport-agnostic and supports authenticated, encrypted connections. The security risk in practice comes from what tools you expose and to what agent. A tool that can send money or delete records needs careful scoping, authentication, and ideally human confirmation steps for destructive actions. Treat your MCP server like any production API: authenticate every connection, audit every call, and never expose more than the agent needs.

    How does ACA use MCP?

    ACA ships a native MCP server that exposes the platform's outreach, CRM, content, and inbox functionality as MCP tools. Any MCP-compatible agent can connect and drive ACA programmatically: create campaigns, send messages across 6 channels, score leads, generate content, and triage replies. This makes ACA function as a capability surface for AI agents rather than just a dashboard a human logs into.

    Do I need to know how to code to use MCP?

    To use existing MCP servers through an MCP client like Claude Desktop, no. You install the client, configure the server in a JSON file, and the tools show up. To build your own MCP server, yes - basic familiarity with Python or TypeScript is enough to get a working server in an afternoon using the official SDKs.