networks//network protocols//MCP//MCP server
An MCP server is a program that exposes capabilities to AI applications through the Model Context Protocol: tools the model may ask to run, resources it may read and prompt templates it may use, each with a name, a description and a schema for its arguments. It is how one integration (a database, a ticketing system, a plant's historian) becomes usable from any application that speaks MCP, instead of being coded again inside each one.
An MCP server is a program that exposes capabilities to AI applications through the Model Context Protocol: tools the model may ask to run, resources it may read and prompt templates it may use, each with a name, a description and a schema for its arguments. It is how one integration (a database, a ticketing system, a plant's historian) becomes usable from any application that speaks MCP, instead of being coded again inside each one.
Three roles take part, and the names matter. The host is the application the person uses (Claude, an editor such as Cursor) and it runs the model. Inside it, an MCP client holds one connection to one server. The server lists what it offers, receives requests with arguments, executes them against the service behind it and returns a structured result. Messages are JSON-RPC 2.0 (JSON-RPC), carried over standard input and output when the server is a local process, or over HTTP when it runs remotely.
1The person asks for the open incidents2The host's model reads the tool descriptions and requests get_incidents with arguments3The client sends the call to the server4The server validates it and queries the ticketing API5The result returns to the model as context
The choice of tool belongs to the host. A common picture has the server interpreting the request and picking the right endpoint; in the protocol, the host and its model choose among the advertised tools from their descriptions (function calling), and the server executes the call it receives. Its job is to implement operations well and to say clearly what each one does (tool interface).
It sits in front of an API. Behind a server there is still a REST service, a database driver or a file system with its own authentication; MCP standardizes how a model discovers and requests operations, and the service still needs its credentials, permissions and limits (API).
Security is the server's design problem. Give it only the authority its operations need (minimum privilege), validate every argument as untrusted, keep credentials scoped to the server instead of handing it the user's whole account, and put operations with side effects behind confirmation. Tool results are also a channel for prompt injection.
In a plant, a sensible first server exposes read-only queries to the historian and the maintenance records, so an assistant can explain an alarm; a server that writes setpoints to a PLC is a different decision, one that belongs to the control system's safety case and not to convenience.