Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

MCP is the protocol; an MCP server is a program that implements that protocol and exposes capabilities to an AI application. The distinction is similar to USB-C versus a USB-C device: one defines the shared connection rules, while the other uses those rules to provide something useful. In practice, an AI host uses an MCP client to connect to one or more MCP servers, which can provide tools, resources and prompts.

The short answer: protocol versus implementation

The Model Context Protocol (MCP) is an open-source standard for connecting AI applications to external systems. It defines how participating software discovers capabilities, exchanges requests and returns results.

An MCP server is a provider-side implementation of that standard. It sits between an MCP client and an external capability such as a database, file system, search service, business workflow or screenshot service. The server describes what it can do and carries out approved requests.

Term What it is What it does
MCP A protocol and specification Defines common communication and capability-discovery rules
MCP host The AI application Manages the user interaction and one or more MCP connections
MCP client A connection component inside the host Connects to a server, discovers capabilities and forwards requests
MCP server A program or service implementing MCP Exposes tools, resources and prompts backed by an external system

Calling all of these pieces “the MCP” hides the boundaries that matter when you design, secure and deploy a system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the host, client and server fit together

The practical chain is:

AI host/application → MCP client → MCP server → external system or capability

Host: the application the user interacts with

The host is an AI application, such as an assistant or coding environment. It presents the conversation, decides which connected servers are available to the model and handles the user-facing result. The host can connect to several servers through separate MCP clients.

Client: the connection managed by the host

An MCP client establishes a connection to a particular server and speaks the protocol on the host’s behalf. It discovers the server’s advertised capabilities and sends requests in the form expected by that server. A host with five configured servers normally has a corresponding client connection for each one, even when the user experiences them as one assistant.

Server: the provider of capabilities

The server owns the integration logic. It may query a database, read files, call an internal API or run a business operation. The protocol does not require a server to be a separate physical machine: “server” describes the logical provider role. A local process and a remotely hosted service can both implement MCP.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What an MCP server can expose

Servers are not limited to model-invoked functions. MCP distinguishes three capability types.

Tools

A tool is an operation the model can call through the client. Each tool has a name, description and input schema; an output schema may also be provided. Examples include searching a ticket system, running a database query or creating a calendar event. The model supplies arguments that match the declared schema, but the host and server still need to apply their own permission and validation rules.

Resources

A resource is content or data that a client can read. A server might expose a database schema, a document, a report or another addressable data item. Resources let the client obtain context without presenting every operation as an action for the model to invoke.

Prompts

A prompt is a reusable template supplied by the server. It can package instructions or examples for a recurring interaction, such as a standard way to investigate an incident or query a particular data set.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

One server can provide all three

The official architecture example uses a database server that exposes a query tool, a resource containing the database schema and a prompt with interaction examples. These capabilities complement one another: the resource explains the data, the prompt helps structure the request and the tool performs the operation.

What happens during a tool call

A normal call follows a predictable sequence:

  1. Discovery: the MCP client retrieves the tools the server provides, including their descriptions and input schemas.
  2. Selection: the model chooses a tool based on the user’s request and prepares arguments that match the schema.
  3. Validation: the server checks the request and its arguments before touching the external system.
  4. Execution: the server performs the operation against the database, API, file store or other backend.
  5. Result: the server returns structured output to the client, and the model uses that result to continue the conversation.

This flow explains two common misconceptions. An MCP server is not automatically an autonomous agent, and exposing a tool does not mean the model will call it on every turn. Tool selection remains part of the host and model interaction.

What the 2026-07-28 specification changes

The current specification reviewed here is dated 2026-07-28. Its protocol core is stateless: each request carries the information needed to process it, and a server must not rely on earlier requests on the same connection to establish context.

An open connection, including a stdio process, is therefore not implicitly a conversation or application session. If work must continue across requests, the client should pass an explicit identifier that the server can use to retrieve the required state.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The July 28, 2026 release announcement also describes Multi Round-Trip Requests, header-based routing, cacheable list results, authorization hardening, a formal extensions framework and updated Tier 1 SDKs. It says the former initialize/initialized exchange and MCP session-ID header were retired in this revision, with optional server/discover capability discovery. Treat those details as revision-specific. A client and server must agree on the specification and SDK behavior they support; do not copy initialization or session examples from an older SDK without checking its version.

Transport and authorization choices

MCP describes communication rules, but deployment still requires a transport and an authentication design.

Local stdio

A local server can communicate over standard input and output. The current specification says stdio implementations should obtain credentials from the environment rather than use the HTTP authorization framework. This approach is convenient for a developer workstation because the host starts a local process, but you must protect environment variables, child-process permissions and local files.

Remote HTTP

For HTTP-based transports, the specification provides an authorization framework. OpenAI’s developer guidance recommends a stable HTTPS endpoint and Streamable HTTP for production MCP servers. Servers that access private data or perform actions for users should be protected by the authorization flow defined by the MCP specification.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Remote” does not mean “more secure” by itself. A remote deployment adds endpoint, certificate, identity, network and logging decisions; a local deployment still needs least-privilege credentials and input validation.

Questions to settle before choosing

  • Does the client support the transport and exact specification revision your server implements?
  • Will the server run only on a developer machine, inside a private network or on a public HTTPS endpoint?
  • Which credentials are needed, where are they stored and how are they rotated?
  • Which operations are read-only, and which can change data or act on behalf of a user?
  • How will you pass an explicit state or job identifier when work spans requests?

Building or integrating: a practical decision framework

Build a server when your system is the source of truth

Build an MCP server when you control a data source or workflow and want multiple AI hosts to use it through one consistent interface. Keep backend-specific authentication, validation and error handling in the server rather than duplicating them in every host integration.

Integrate an existing server when the capability already exists

Use an existing server when it already supports the operation you need. Check its advertised tools, resources and prompts; transport; authorization behavior; specification and SDK version; documentation; and maintenance status. A server that exposes only a tool may still be appropriate, but it will not provide the contextual resources or reusable prompts that another implementation offers.

Keep the boundary narrow

Expose task-oriented operations with precise schemas instead of a single unrestricted “run anything” tool. Validate arguments at the server boundary, return useful structured errors and make destructive operations explicit. These are implementation practices, not guarantees supplied by MCP itself.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A concrete MCP server example: ScreenshotNeo

ScreenshotNeo is a website screenshot API and MCP server for developers. Its MCP integration provides the tools take_screenshot, get_page_info and capture_pdf, illustrating how one service can expose concrete operations to an AI client. Its HTTP API is also available at https://api.screenshotneo.com/v1/shot.

For screenshot work, its capture pipeline accepts cookie or consent banners before taking the shot and removes more than 60 known consent platforms, newsletter popups and chat widgets; each step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and each response reports the outcome through the X-Page-Verdict and X-Billed headers.

The service supports full-page captures with lazy images loaded, CSS-selector element captures, dark mode, 12 device presets or a custom viewport, retina scale, PDF paper size/margins/landscape/page ranges, HTML/CSS-to-image, custom CSS and JavaScript, pre-capture clicks, hidden selectors, waits for a selector/delay/network idle, blocking ads/trackers/requests/resource types, custom headers/cookies/user agents/Authorization, timezone and geolocation, transparent backgrounds, image resizing, user-selected cache TTLs, signed links, asynchronous jobs with signed webhooks, up to 100 URLs per bulk call, a usage API and an OpenAPI specification. Parameter names used by other screenshot APIs also work for easier migration.

One-call API examples

See the ScreenshotNeo documentation for request details. Replace YOUR_API_KEY with a key and change the target URL as needed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

Plans include 1,000 shots per month free with no card, then Starter at $5 for 3,000, Growth at $15 for 15,000, Pro at $39 for 60,000, Scale at $99 for 250,000 and Business at $249 for 1,000,000. Yearly billing gives two months free, and every feature is included on every plan.

If you need an MCP server that lets an AI client request screenshots or PDFs while filtering common page clutter, sign up for the free ScreenshotNeo plan to get 1,000 screenshots a month without a card.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting MCP integrations

The client cannot discover the server

Confirm that the process starts successfully or that the HTTPS endpoint is reachable, then check that client and server support the same transport and specification revision. A configuration copied from an older SDK may reference retired initialization or session behavior.

Authentication succeeds locally but fails remotely

For HTTP, verify the authorization flow, HTTPS certificate, required headers and token audience. For stdio, verify that the host process receives the expected environment variables. Never assume credentials available to your interactive shell are also available to a service process.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The server loses context between calls

That behavior is expected if the implementation relies on connection continuity. Under the 2026-07-28 specification, include an explicit state, job or resource identifier in each request that needs prior context, and have the server retrieve state by that identifier.

The model calls the wrong tool or supplies invalid arguments

Improve names, descriptions and input schemas; make required fields unambiguous; and reject invalid or unsafe values on the server. Discovery makes a capability available, but it does not guarantee correct model selection.

A tool returns a backend error

Separate protocol errors from external-system failures in logs and responses. Check backend credentials, permissions, rate limits and resource availability, then return an actionable error without exposing secrets or unnecessary internal details.

FAQ

Is MCP an API?

MCP is a protocol for connecting AI applications to external systems. An MCP server may call APIs internally, but MCP itself is the shared interaction contract between host-side clients and servers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does an MCP server have to use a particular programming language?

No language requirement is established by the protocol concept. What matters is that the implementation follows the supported MCP specification and transport behavior of the client you target.

Can one AI host connect to several MCP servers?

Yes. The architecture defines the host as connecting to one or more servers through MCP clients. Each server can represent a different data source or workflow.

Is a long-lived connection the same as a user session?

No. The 2026-07-28 specification explicitly treats MCP as stateless and requires relevant context to be carried in each request or referenced explicitly.

Frequently Asked Questions

Can an MCP server expose only resources and no tools?

Yes. Tools, resources and prompts are distinct capability types, so a server can provide the subset that fits its purpose.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who decides whether a capability is safe to run?

MCP defines communication, discovery and exchange patterns; authorization, user consent, validation and operational policy remain responsibilities of the host, server and deployment.

Should I deploy every MCP server over HTTPS?

No universal transport is required. Local stdio can fit workstation integrations, while OpenAI guidance recommends stable HTTPS with Streamable HTTP for production deployments; choose based on topology, client support and authorization needs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.