The Model Context Protocol ( MCP ) is an open standard and open-source framework introduced by Anthropic in November 2024 to standardize the way artificial intelligence (AI) systems like large language models (LLMs) integrate and data with external tools, systems, and data sources. [ 1 ] MCP provides a standardized interface for reading files, executing functions, and handling contextual prompts . [ 2 ] Following its announcement, the protocol was adopted by major AI providers, including OpenAI and Google DeepMind . [ 3 ] [ 4 ] In December 2025, Anthropic donated MCP to the Agentic AI Foundation, a fund under the Linux Foundation .
MCP was announced by Anthropic in November 2024 as an open standard [ 5 ] for connecting AI assistants to data systems such as content repositories , business management tools , and development environments . [ 6 ] The protocol was created at Anthropic by engineers David Soria Parra and Justin Spahr-Summers. [ 6 ] MCP was designed to address information silos and legacy systems . [ 6 ] Before MCP, developers often had to build custom connectors for each data source or tool, resulting in what Anthropic described as an "N×M" data integration problem. [ 6 ] [ 7 ]
Earlier approaches such as OpenAI 's 2023 "function-calling" API and the ChatGPT plug-in framework—solved similar problems but required vendor-specific connectors. [ 7 ] MCP reuses the message-flow ideas of the Language Server Protocol (LSP). [ 8 ]
In December 2025, Anthropic donated MCP to the Agentic AI Foundation (AAIF), a directed fund under the Linux Foundation , co-founded by Anthropic, Block and OpenAI, with support from other companies. [ 9 ] Later that month, Anthropic also published Agent Skills , a companion open standard for packaging task-specific instructions and resources that AI agents load on demand. [ 10 ]
MCP defines a standardized framework for integrating AI systems with external data sources and tools. [ 2 ] Applications include querying structured databases in plain language. [ 8 ]
The protocol distinguishes between MCP hosts , MCP clients and MCP servers. An MCP host is typically an AI agent that interacts with an LLM and requires services from one or more MCP servers. For each of these MCP servers, the MCP host will create a dedicated MCP client that communicates with that server. Client and host will typically run on the same machine, while the MCP servers may be local or remote. [ 11 ]
Each server provides one or more tools or resources. Tools might include database access, calculators, or access to code or repositories; a resource might be a document such as an FAQ. The MCP client asks its server for a list of tools and resources the server provides; the server replies with a natural-language description of the capabilities of each tool and the expected format to call the tool. This information is given to the LLM; if the LLM requires the services of one of these tools, the MCP host will instruct the relevant MCP client to call the tool. The MCP server performs the tool action and returns the results, which the MCP host then injects into the LLM conversation. [ 11 ] Client and server communicate using the JSON-RPC 2.0 messages. [ 8 ]
The protocol was released with software development kits (SDKs) in programming languages including Python , TypeScript , C# and Java and examples of MCP server implementations. [ 8 ] [ 12 ]
The protocol is used in AI-assisted software development tools. Integrated development environments (IDEs), coding platforms such as Replit , and code intelligence tools like Sourcegraph have adopted MCP to grant AI coding assistants real-time access to project context. [ 5 ]
MCP Apps is an official extension to the Model Context Protocol built on mcp-ui. While the base MCP specification is restricted to text and structured data, MCP Apps standardizes the delivery of interactive user interfaces—such as dashboards, forms, and data visualizations—from MCP servers to host applications like Claude and ChatGPT . [ 13 ]
In March 2025, OpenAI officially adopted the MCP, after having integrated the standard across its products, including the ChatGPT desktop app. [ 3 ] [ 2 ] In September 2025, OpenAI added support for MCP to ChatGPT apps. This allows for third-party access inside ChatGPT. [ 14 ]
MCP can be integrated with Microsoft Semantic Kernel, and Azure OpenAI. [ 15 ] MCP servers can be deployed to Cloudflare . [ 16 ]
In April 2026, the AAIF held the MCP Dev Summit North America in New York City, drawing approximately 1,200 attendees. [ 17 ] That same month, Salesforce 's Headless 360 platform began routing customer and agent interactions via MCP; in late May, Salesforce reported 4.5 million MCP calls had been processed since launch. [ 18 ] [ 19 ]
On July 28, 2026, MCP's maintainers finalized a major revision of the specification, described by Anthropic technical staff member David Soria Parra as the most substantial change to the protocol since the addition of authorization. [ 20 ] The revision removes protocol-level session tracking, making MCP stateless at the protocol layer: information protocol version, client identity, and capabilities is instead carried in a _meta parameter with each request. [ 20 ] The change brings MCP's request model closer to that of Anthropic's own Claude Messages API. [ 20 ]
The revision also deprecated several features that had seen limited use, including sampling (allowing a server to request a completion from the client's model) and roots (allowing clients to indicate relevant file-system locations to a server); deprecated features remain functional for a minimum of twelve months. [ 20 ] Some previously core functionality, such as the Tasks feature for long-running operations, was moved out of the base protocol and into optional extensions. [ 20 ] Not all of the changes are backward compatible, and servers implementing the new revision may not interoperate with older clients without a compatibility layer. [ 20 ]
Security risks and vulnerabilities
MCP has been subject to several security vulnerabilities, both in how models handle tool calling and in MCP software itself.
In April 2025, Invariant Labs described "tool poisoning attacks" in which malicious instructions are hidden in MCP tool descriptions that the AI model can read but users cannot see. [ 21 ] The vulnerability comes from the assumption that tool descriptions are trustworthy. These problems are not specific to MCP and can occur whenever an LLM has access to tools with untrusted input. Tool poisoning is a form of prompt injection . [ 22 ]
Several vulnerabilities have also been found in MCP software itself. In July 2025, JFrog disclosed CVE-2025-6514, a critical flaw (CVSS 9.6) in mcp-remote, a tool that connects MCP clients to remote servers. The flaw allowed a malicious server to run arbitrary commands on the user's machine. [ 23 ] The vulnerability affected versions 0.0.5 through 0.1.15 and was fixed in version 0.1.16. [ 23 ] Around the same time, researchers reported CVE-2025-49596 in Anthropic's MCP Inspector developer tool. Because the Inspector required no authentication by default, attackers could use it to run code on a user's computer. [ 24 ]
The MCP specification has since added security requirements. The specification now requires implementations to follow OAuth 2.1 security best practices. [ 25 ] Its security guidance describes " confused deputy " risks in MCP proxy servers and states that token passthrough is forbidden. [ 25 ] In a May 2026 report, the U.S National Security Agency stated that MCP's "rapid proliferation has outpaced the development of its security model". [ 26 ]
The Verge reported that MCP addresses a growing demand for AI agents that are contextually aware and capable of pulling from diverse sources. [ 5 ]
MCP has been likened to OpenAPI , a similar specification that aims to describe APIs. [ 27 ] [ 28 ]
Agent2Agent – Open protocol for communication between AI agents
Application programming interface – Connection between computers or programs
LangChain – Language model application development framework
Machine learning – Subset of artificial intelligence
Software agent – Computer program acting for a user
Retrieval-augmented generation
↑ David, Emilia (November 25, 2024). "Anthropic releases Model Context Protocol to standardize AI-data integration" . VentureBeat . Retrieved 2025-05-12 .
1 2 3 Kumar, Vinay (March 26, 2025). "The open source Model Context Protocol was just updated — here's why it's a big deal" . VentureBeat . Retrieved 2025-05-12 .
1 2 Wiggers, Kyle (March 25, 2025). "OpenAI adopts rival Anthropic's standard for connecting AI models to data" . TechCrunch .
↑ Wiggers, Kyle (April 9, 2025). "Google to embrace Anthropic's standard for connecting AI models to data" . TechCrunch . Retrieved 2025-05-12 .
1 2 3 Roth, Emma (November 25, 2024). "Anthropic launches tool to connect AI systems directly to datasets" . The Verge .
1 2 3 4 "Introducing the Model Context Protocol" . Anthropic. November 25, 2024 . Retrieved 2025-05-12 .
1 2 Edwards, Benj (1 April 2025). "MCP: The new "USB-C for AI" that's bringing fierce rivals together" . Ars Technica . Retrieved 2025-05-24 .
1 2 3 4 Ouellette, Michael (2025-05-09). "Model context protocol: the big step in generating value from AI" . Engineering.com . Retrieved 2025-06-23 .
↑ Bellan, Rebecca (2025-12-09). "OpenAI, Anthropic, and Block join new Linux Foundation effort to standardize the AI agent era" . TechCrunch . Retrieved 2025-12-10 .
↑ Deutscher, Maria (2025-12-18). "Anthropic makes agent Skills an open standard" . SiliconANGLE . Retrieved 2026-08-12 .
1 2 "Architecture overview" . Model Context Protocol . Retrieved 2026-06-22 .
↑ "Model Context Protocol" . GitHub . Retrieved 2025-06-20 .
↑ "MCP Apps, the Model Context Protocol's first official extension, turns AI responses into interactive interfaces" . the decoder . 2026-01-26. Archived from the original on 2026-01-26.
↑ "OpenAI adds 'powerful but dangerous' support for MCP in ChatGPT dev mode" . VentureBeat. September 11, 2025 . Retrieved 2026-04-09 .
↑ "Using the Model Context Protocol in Azure and beyond" . InfoWorld . 2025-05-01 . Retrieved 2026-06-14 .
↑ "Cloudflare Outlines MCP Architecture as Enterprises Confront Security and Governance Risks" . InfoQ . 2026-04-22 . Retrieved 2026-06-14 .
↑ "AAIF's MCP Dev Summit: Gateways, gRPC, and Observability Signal Protocol Hardening" . InfoQ. 2026-04-14 . Retrieved 20 April 2026 .
↑ Johnson, O'Ryan (28 May 2026). "Salesforce waves bye-bye to UI in 'headless' embrace" . The Register . Retrieved 9 July 2026 .
↑ Martin, Henry (15 April 2026). "Salesforce Headless 360 and Agentforce Vibes 2.0 Revealed at TDX 2026" . Salesforce Ben . Retrieved 9 July 2026 .
1 2 3 4 5 6 7 Jackson, Joab (23 July 2026). "Model Context Protocol prepares to break with its stateful past" . The Register . Retrieved 20 August 2026 .
↑ Beurer-Kellner, Luca; Fischer, Marc (2025-04-01). "MCP Security Notification: Tool Poisoning Attacks" . invariantlabs.ai . Retrieved 2026-10-02 .
↑ Willison, Simon (2025-04-09). "Model Context Protocol has prompt injection security problems" . Simon Willison’s Weblog . Retrieved 2026-10-02 .
1 2 "Critical RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients" . jfrog.com . 2025-07-09 . Retrieved 2026-10-02 .
↑ Ravie, Lakshmanan (2025-07-10). "Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads" . The Hacker News . Retrieved 2026-10-02 .
1 2 "Security Best Practices" . Model Context Protocol . Retrieved 2026-10-02 .
↑ "Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation" (PDF) . National Security Agency . May 2026.
↑ MacManus, Richard (13 March 2025). "MCP: The Missing Link Between AI Agents and APIs" . The New Stack . Retrieved 29 May 2025 .
↑ Fanelli, Alessio. "Why MCP Won" . . Retrieved 29 May 2025 .
Hou, Xinyi; Zhao, Yanjie; Wang, Shenao; Wang, Haoyu (2025). "Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions". arXiv : 2503.23278 [ cs.CR ].
Edwards, Benj (April 1, 2025). "MCP: The new "USB-C for AI" that's bringing fierce rivals together" . Ars Technica .
Jackson, Fiona (March 28, 2025). "OpenAI Agents Now Support Rival Anthropic's Protocol, Making Data Access 'Simpler, More Reliable' " . TechRepublic .
Model Context Protocol on GitHub
Generative adversarial network
Generative pre-trained transformer
Model Context Protocol
Reinforcement learning from human feedback
Retrieval-augmented generation
Self-supervised learning
Variational autoencoder
Invisible Technologies
Meta Superintelligence Labs
Safe Superintelligence
Thinking Machines Lab
Generative AI pornography Deepfake pornography on Grok of Taylor Swift
Deepfake pornography on Grok of Taylor Swift
Pause Giant AI Experiments
Removal of Sam Altman from OpenAI
Théâtre D'opéra Spatial
Voiceverse NFT plagiarism
Lists Algorithms Companies Institutions Projects Software Open-source Proprietary
Software Open-source Proprietary
Constraint satisfaction
Knowledge representation
Parameter Hyperparameter
Regression Bias–variance tradeoff Double descent Overfitting
Bias–variance tradeoff
Gradient descent SGD Quasi-Newton method Conjugate gradient method
Conjugate gradient method
Normalization Batchnorm
Activation Softmax Sigmoid Rectifier
Weight initialization
Datasets Augmentation
Reinforcement learning Q-learning SARSA Imitation Policy gradient
Latent diffusion model
Self-supervised learning
Recursive self-improvement
Actor-critic algorithm
Automated theorem proving
Machine learning In-context learning
Artificial neural network Deep learning
Language model Large NMT Reasoning
Model Context Protocol
Intelligent agent AI agent
Artificial human companion
Lethal autonomous weapons (LAWs)
Hypothetical Artificial general intelligence (AGI) Artificial superintelligence (ASI)
Artificial general intelligence (AGI)
Artificial superintelligence (ASI)
Human image synthesis
Speech synthesis 15.ai ElevenLabs
Speech recognition Whisper
Text-to-image models Aurora DALL-E Firefly Flux GPT Image Ideogram Imagen Midjourney Recraft Stable Diffusion
Text-to-video models Dream Machine Runway Gen Hailuo AI Kling Sora Seedance Veo
Music generation Riffusion Suno Udio
World models Genie Oasis
List of large language models
IBM Watson IBM Watsonx
Action selection AutoGPT
Deductive classifiers
Knowledge-based systems
Procedural reasoning systems
Warren Sturgis McCulloch
Christopher D. Manning
Neural Turing machine
Differentiable neural computer
Transformer Vision transformer (ViT)
Vision transformer (ViT)
Recurrent neural network (RNN)
Long short-term memory (LSTM)
Gated recurrent unit (GRU)
Multilayer perceptron (MLP)
Convolutional neural network (CNN)
Residual neural network (RNN)
Variational autoencoder (VAE)
Generative adversarial network (GAN)
Graph neural network (GNN)
AI safety ( Alignment )
Precautionary principle
Opposition to AI data centers
Generative engine optimization
In healthcare Chatbot psychosis
Military applications AI warfare
Application layer protocols
Linux Foundation projects
Articles with short description
Short description is different from Wikidata
Pages displaying short descriptions of redirect targets via Module:Annotated link
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
