You want Claude to read documents in your Google Drive, or you want an AI to take actions in Slack or GitHub. The common set of rules widely used to "connect AI to external tools and data" like this is MCP (Model Context Protocol). Anthropic released it in November 2024, and today it is supported not only by Claude but by major AI tools including ChatGPT, Gemini, Microsoft Copilot and Cursor. This guide walks through how MCP works, what changed in the latest specification, how to get started and how to use it safely, based on the official specification and each vendor's documentation.
What MCP is
MCP is an open standard (protocol) for connecting AI applications to external systems. In its announcement on November 25, 2024, Anthropic described MCP as "a universal, open standard for connecting AI systems with data sources," one that replaces fragmented integrations with a single protocol.
The official site compares MCP to "a USB-C port for AI applications." Just as USB-C connects all kinds of devices through one standard, MCP connects AI apps to external tools and data in a common way.
- MCP server: the side that provides the capabilities of an external service or data source to AI in MCP format (for example, the gateway to Google Drive, GitHub or an internal database)
- MCP-compatible AI app: the side that connects to MCP servers and uses their capabilities (for example, Claude, ChatGPT or Cursor)
A major advantage is that once you build an MCP server, any MCP-compatible AI app can use it.
Why MCP is needed
However smart an AI becomes, there is only so much it can do if it cannot reach your files, internal systems or the SaaS tools you use at work. In its announcement, Anthropic said AI models are "trapped behind information silos and legacy systems," and pointed out that needing a custom implementation for every new data source makes truly connected systems difficult to scale.
Before MCP, a dedicated integration had to be built for every combination of AI app and service. The more AI apps and the more services there are, the number of integrations multiplies. By putting a common standard in between, MCP lets the two sides connect as long as the AI app "supports MCP" and the service "provides an MCP server."
Anthropic donated MCP to the Agentic AI Foundation under the Linux Foundation in December 2025, so it is now developed under a neutral organization rather than a single company. The foundation's founding members include Anthropic, Block and OpenAI, and AWS, Google and Microsoft also participate.
How it works: hosts, clients and servers
The MCP specification divides the participants into three roles. Communication uses messages in the JSON-RPC 2.0 format.
- Host: the AI app the user interacts with (the Claude app, Claude Code, Cursor and so on)
- Client: the part inside the host that handles the connection to each individual MCP server
- Server: the program that provides external tools and data
There are two standard ways (transports) to connect to a server.
- stdio: the AI app launches the server on your own computer and communicates with it directly. Used for things like working with local files
- Streamable HTTP: connects over HTTP to a server on the internet. Used for integrations with cloud services (remote MCP servers)
The HTTP+SSE method used previously has been deprecated, and migration to Streamable HTTP is expected.
The three capabilities servers provide
An MCP server can mainly provide AI apps with the following three types of capability.
- Tools: functions the AI model can execute. They perform real actions such as "search files," "send an email" or "create a ticket"
- Resources: data and context for the AI or the user to reference, such as file contents or database information
- Prompts: templates for standard messages or workflows that the user invokes
Tools are by far the most widely used. When the AI decides during a conversation that a tool would help it answer, it calls the MCP server's tool and uses the result to answer or take the next step.
In the other direction, there is also Elicitation, which lets a server ask the user for additional information partway through a task. For example, the server might ask for confirmation such as "Which project should this be added to?"
What changed in the latest specification (2026-07-28)
MCP specification versions are identified by date, and as of October 2026 the latest is "2026-07-28," published on July 28, 2026. The official blog calls it the largest revision since launch. The main changes are as follows.
- Stateless design: the initialization procedure on connection (the handshake) and the session mechanism are gone, so each exchange is independent. The change is meant to make large-scale servers easier to operate
- Multi-round-trip requests: when a server needs something such as confirmation from the user, it now responds that more information is required, and the client sends the request again with that information attached
- Deprecation of some features: the client-side features Sampling, Roots and Logging are deprecated. There is a grace period of at least 12 months before removal, and they keep working in the meantime
- Stronger authentication: the OAuth-based authorization procedure has become stricter
- Extensions framework: a mechanism now exists for defining official extensions separately from the core specification. "Tasks," for handling long-running operations, and "MCP Apps," which can display interactive interfaces such as charts and forms inside the chat, are delivered through this framework
Ordinary users generally do not need to change any settings, but if you build or operate your own MCP servers, it is worth checking how well they support the new specification.
Major AI tools that support MCP
The main support status confirmed in each vendor's official documentation is as follows.
- Claude (web and desktop apps): connects to MCP servers as "connectors." Custom connectors, which add remote MCP servers, are available even on the free plan, limited to one. In the desktop app, MCP servers that run locally can be installed as extensions
- Claude Code: connects to external tools and data sources via MCP, and a server can be added with a single command
- ChatGPT: turning on Developer mode lets you use MCP tools, including both read and write actions. Available on the web for the Plus, Pro, Business, Enterprise and Education plans
- OpenAI API: tools on remote MCP servers can be called from the Responses API and the Agents SDK
- Gemini: Gemini CLI supports MCP servers, and managed agents in the Gemini API can also connect to remote MCP servers
- Microsoft: GitHub Copilot in VS Code and Copilot Studio support MCP. On Windows, a mechanism for managing MCP servers is available as a prerelease
- Cursor: connects to external tools and data sources via MCP
On the server side, more and more service providers, such as Notion and GitHub, publish their own official MCP servers. There is also the "MCP Registry," an official catalog for finding public MCP servers, but as of October 2026 it is in preview and positioned mainly as a foundation from which other catalog services pull their data.
Getting started
Using MCP with Claude
The easiest way is to enable connectors in the Claude app. According to Claude's help center, you open "Connectors" from "Customize" in the left-hand menu, pick the service you want from the list, connect it and log in to that service. Even if a service is not on the list, you can add it by entering its URL under "Add custom connector," as long as the provider publishes a remote MCP server URL. On the Team and Enterprise plans, an organization admin adds the connector and each member then connects with their own account.
Using MCP with ChatGPT
In ChatGPT, you can connect MCP servers you set up yourself by turning on Developer mode under "Security and login" in settings. However, OpenAI presents this as a feature for developers, so it is safer to start with the officially provided integrations.
For developers
To build your own MCP server, use an official SDK. SDKs are available in 10 languages: TypeScript, Python, C#, Go, Rust, Ruby, Java, Swift, PHP and Kotlin. In Claude Code, Cursor and VS Code, you can register a server with a configuration file or a command and check that it works right away.
For the idea of using MCP to hand multiple tasks to AI, see also What are AI agents?.
Security considerations
MCP gives AI "the power to actually take actions in the outside world," so while it is convenient, misuse can lead to data leaks or unintended actions. The MCP specification itself states that tools amount to arbitrary code execution and must be treated with caution, and that security cannot be enforced at the protocol level.
- Use only servers from trusted providers: Claude's help center warns that malicious servers may attempt prompt injection (attacks that slip unauthorized instructions to the AI), and urges users to connect only to trusted servers
- Be especially careful with local servers: an MCP server running on your computer can execute arbitrary code on it. The VS Code documentation also cautions to add only servers from trusted sources
- Information given to the AI may leave your environment: OpenAI lists as risks that a malicious server could exfiltrate sensitive information that has entered the AI's context, and that a server could change a tool's behavior without notice
- Use settings that confirm before actions: the specification recommends letting users deny tool execution and asking for confirmation before important operations. It is safer not to let actions that are hard to undo, such as sending email or deleting data, run automatically
- Limit permissions to what is needed: keep the permissions granted on the connected service (read-only, or write access too) to the minimum required for the task
For business use, it is reassuring to have administrators decide on a list of approved MCP servers so individuals cannot add servers freely.
Pricing
MCP is an open-source standard, and the specification and SDKs are published under the Apache 2.0 license. Using the standard itself costs nothing.
In practice, however, the following costs may apply.
- AI app fees: the price of your Claude or ChatGPT plan. For the API, OpenAI says you are billed only for the tokens used to load tool definitions and make calls, with no additional fee per tool call
- Connected service fees: the cost of the SaaS or cloud services you use through MCP servers
Summary
MCP is a common plug that connects AI apps to external tools and data. With the major AI tools all supporting it, an MCP server set up once can be used from multiple AIs, laying the groundwork for handing AI work that goes beyond "looking things up" to "actually taking action."
At the same time, an MCP server gives AI permission to act in the outside world. A realistic first step is to master the basics before widening how you use it: start with official connectors from clearly identified providers, put a confirmation step in front of actions that are hard to undo, and limit permissions to what is needed.
Sources: Introducing the Model Context Protocol (Anthropic), official MCP site, MCP specification 2026-07-28, MCP 2026-07-28 release announcement (official MCP blog), donation to the Agentic AI Foundation (Anthropic), security best practices (official MCP), getting started with custom connectors using remote MCP (Claude help center), ChatGPT Developer mode (OpenAI). This article reflects public information verified on October 4, 2026.