MCP server
An MCP server exposes data and functions to an AI assistant through the Model Context Protocol. How it works, how it differs from an API, and what to check first.
What is an MCP server?
An MCP server is a service that exposes data and functions to an AI assistant through the Model Context Protocol. The server tells the assistant which tools exist and how to call them, runs the call, and returns the result. The protocol is open source and not tied to one model vendor.
How does an MCP server work?
Three roles divide the work. The host is the application holding the language model, such as a chat client or a development environment. The client sits inside the host and holds one connection each. The server supplies content and functions. The specification, revision 2026-07-28, names three things a server can offer: "Resources: Context and data, for the user or the AI model to use", "Prompts: Templated messages and workflows for users", and "Tools: Functions for the AI model to execute". The runtime sequence is short. On connecting, the server announces its catalogue of tools. The host puts those descriptions in front of the model. When the model needs one, the client calls it, the server runs it and answers, and the result goes back into the conversation. Messages travel as JSON-RPC 2.0, described by its own specification as "a stateless, light-weight remote procedure call (RPC) protocol", which is why an MCP server can be a few hundred lines of code rather than a platform.
Where did the Model Context Protocol come from?
From Anthropic. The Wikipedia entry dates the announcement to 25 November 2024 and credits the Anthropic engineers David Soria Parra and Justin Spahr-Summers with creating it. It describes MCP as "an open standard and open-source framework introduced by Anthropic in November 2024 to standardize the way artificial intelligence (AI) systems like large language models (LLMs) integrate and share data with external tools, systems, and data sources".
Two facts from that entry matter for a buying decision. The protocol is no longer governed by one company: in December 2025 Anthropic donated MCP to the Agentic AI Foundation, a directed fund under the Linux Foundation co-founded by Anthropic, Block and OpenAI. And adoption spread beyond its origin, including OpenAI and Google DeepMind. Building against MCP is therefore not a bet on a single vendor.
What is the difference between an API and an MCP server?
Both expose functions, but they are written for different readers. A conventional API addresses developers: a person reads the documentation and writes code that fits that one interface. An MCP server addresses a language model: it describes its tools in a form the model reads at runtime, so a new assistant does not need a new hand-built connector.
In practice an MCP server usually sits in front of an existing API and translates between the two. It does not replace the API. It adds a second door that an assistant can walk through, and the wiring behind that door is the same code the API already uses.
Where does an MCP server run?
In two places. Locally on the user's machine, started by the host and connected over standard input and output, which suits files and local tools. Or remotely as a web service over HTTP, which suits systems several people share. The remote form is the more interesting one for an organisation, because access rights, credentials and logging then live in one place rather than on each laptop.
What should you check before connecting an MCP server?
The specification puts the answer at the top of its own security section, and it is worth quoting rather than paraphrasing. The first principle reads: "Users must explicitly consent to and understand all data access and operations." Two further lines belong in any review: "Hosts must obtain explicit user consent before exposing user data to servers", and, on tools, "descriptions of tool behavior such as annotations should be considered untrusted, unless obtained from a trusted server".
The open question is the attack surface, and pretending otherwise would be dishonest. The Wikipedia entry records that in April 2025 security researchers published an analysis concluding there are "multiple outstanding security issues with MCP", including prompt injection and poisoned tools that allow data to be pulled out through other connected tools. An organisation letting MCP servers near its systems needs an allowlist of approved servers, separate credentials per server rather than a shared admin token, and a log of which tool did what and when. None of that is exotic. It is the same discipline any integration deserves, applied to a component that a model, rather than a person, decides to call.
Does tchop run an MCP server?
tchop runs its own MCP server, currently in beta, so that an AI assistant can read and create content in a tchop app without anyone writing a bespoke integration. Access follows the roles that already exist in the app, and data can be hosted in the EU. Funke Digital uses tchop as the platform behind its own reader offering. One limit belongs here: the tchop MCP server exposes tchop content and is not a general gateway to other company systems.
More on integrations at tchop.
FAQs: MCP server
What exactly is MCP?
MCP stands for Model Context Protocol. It is a shared language between AI applications and the systems they read from or act on. Without a shared language, every pairing of assistant and system needs its own connector, which is the problem the protocol was written to remove.
Is an MCP server a real server?
Not necessarily. The word names a role in the protocol, not a machine in a data centre. An MCP server can be a small program that starts on a laptop and lives only as long as the application is open. It can equally be a permanently reachable web service with authentication and logging in front of it.
What is the difference between MCP and an MCP server?
MCP is the protocol, meaning the rules for how messages are shaped and exchanged. An MCP server is one participant that speaks it, the side that offers resources, prompts and tools. The host application and its clients are the other participants. Saying "we support MCP" without saying which role is being played leaves the useful part unsaid.
Does ChatGPT use MCP?
OpenAI is among the adopters recorded in the Wikipedia entry, and it co-founded the foundation that now stewards the protocol. Support differs by product and by plan, and it changes quickly, so the current documentation of whichever assistant you use is the only reliable answer at any given moment.
Sources
Model Context Protocol, specification revision 2026-07-28, sections "Overview", "Key Details" and "Security and Trust & Safety"
Wikipedia, "Model Context Protocol", as at 5 September 2026



