Microsoft Agent Framework can connect an agent to tools exposed by a Model Context Protocol (MCP) server. For a local server, use Python’s MCPStdioTool; for a remote server, use MCPStreamableHTTPTool. In both cases, the agent receives the server’s tools and can choose among them while handling a request. Start with the local example below, then choose a transport and security policy that fit your deployment.
How the Agent Framework and MCP fit together
MCP is an open standard for exposing tools and contextual data to AI applications. In an Agent Framework application, an MCP client connects to a server, discovers the tools the server offers, and makes those tools available to an agent. The agent can decide when to call a tool and use its result to answer the user. This is different from writing each tool directly into your application, but it does not remove the need to decide which tools the model is allowed to invoke.
The main options are a local process connected over standard input/output (stdio), a remote server using streamable HTTP, or a language-specific SDK integration. The examples below follow Microsoft’s documented Python pattern. Agent Framework and MCP APIs can change; check the current Microsoft documentation before pinning dependencies or deploying an integration.
Connect a local MCP server from Python
Use MCPStdioTool when your application launches an MCP server as a local process. The context manager manages the server connection’s lifetime: when the block exits, the connection is closed. The example uses a calculator server launched with uvx.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
import asyncio
from agent_framework import Agent, MCPStdioTool
from agent_framework.openai import OpenAIChatClient
async def main():
async with (
MCPStdioTool(
name="calculator",
command="uvx",
args=["mcp-server-calculator"],
) as mcp_server,
Agent(
client=OpenAIChatClient(),
name="MathAgent",
instructions="You are a helpful math assistant.",
) as agent,
):
result = await agent.run("What is 15 * 23 + 45?", tools=mcp_server)
print(result)
asyncio.run(main())
The important pieces are the server process configuration (command and args), the managed MCP connection, and passing the connection to agent.run through tools. The framework can then make the server’s discovered tools available during that run. The exact answer depends on the model and server implementation; the code does not hard-code a calculator result.
Prerequisites and process setup
Install the Agent Framework packages and configure the model client required by your application. Microsoft notes that the optional mcp package may need to be installed with prerelease support for MCPStdioTool, MCPStreamableHTTPTool, or Agent.as_mcp_server(). Confirm the current package guidance for the release you use rather than assuming that a stable MCP package version exposes these APIs.
The executable named in command must be installed and available to the process running your Python application. Here, that executable is uvx, and its argument requests mcp-server-calculator. Use only server packages you trust: a local process still runs with the permissions of your application user.
Pass only the tools the agent needs
For a focused task, do not automatically expose every discovered tool. Microsoft documents using allowed_tools to restrict the remote surface and recommends controls such as approval for sensitive operations. Apply equivalent least-privilege thinking to a local server: expose only the necessary capabilities, and keep destructive actions behind a deliberate approval step.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Connect to a remote MCP server over HTTP
Use MCPStreamableHTTPTool when the MCP server is a network endpoint rather than a process launched on the same machine. The documented pattern supplies the endpoint and may provide authentication through a header_provider or per-run invocation arguments. Choose the credential mechanism supported by the endpoint and the current Agent Framework API.
Rank #2
Keep API keys and OAuth tokens out of prompts, logs that are broadly accessible, and source control. Prefer a secret store or protected runtime configuration, and limit each credential to the tools and resources the agent actually requires. Before connecting, establish what prompts, tool arguments, and results will be sent to the server and what the server retains. Log requests in a way that supports auditing without accidentally recording secrets.
Connection-time versus per-run credentials
A header provider is useful when the same protected connection configuration applies across calls. Per-run invocation arguments can fit cases where credentials or context vary by invocation. The exact argument names or OAuth flow can vary by endpoint; use the server provider’s documented authentication contract and the Agent Framework version’s current API rather than inferring a header format.
Authentication proves that a client may connect; it does not make every tool safe. Pair credentials with a narrow tool allowlist, appropriate approval gates, and server-side authorization. For a third-party endpoint, also verify the operator, retention policy, data location, and whether the endpoint is the server provider itself or a proxy.
Choose between local stdio and remote HTTP
| Approach | Connection model | Useful when | Operational considerations |
|---|---|---|---|
| Local stdio | Agent application launches a local process and exchanges messages over stdio. | The server is installed alongside the application and local process management is appropriate. | Manage executable availability, process permissions, lifecycle, and dependency updates. |
| Remote streamable HTTP | Agent application connects to a remote MCP endpoint. | The server is hosted separately or shared as a network service. | Manage endpoint authentication, network availability, request auditing, and data handling. |
Transport choice is not a security boundary by itself. A local process can be over-privileged, while a remote service can be well-scoped; review the actual tools, permissions, identity controls, and data flows in either case.
Use MCP tools from .NET or Go
.NET
The documented .NET approach uses the official MCP C# SDK. Create an MCP client with the transport appropriate to the server, retrieve the server’s tool list, convert the tools to AIFunction objects, then add those functions to an Agent Framework agent. Use await using for the client so the connection is disposed reliably.
The specific client and transport constructors depend on the MCP C# SDK and the selected transport. Since those details can vary by package release, verify their current signatures in the official SDK documentation instead of copying a constructor from an unrelated version. Keep the same governance principles as in Python: include only required functions and require confirmation where an operation could cause harm.
Go
Microsoft’s Go path uses the mcptool package with the Go MCP SDK. It connects to a server, lists its tools, and supplies those tools in agent configuration. Microsoft documents both streamable HTTP and stdio transports for this path. Consult the current package examples for exact setup and configuration fields.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsControl tool access, naming, and disclosure
An MCP server’s tool list is a capability surface, not a harmless menu. Agent Framework supports an allowed_tools restriction for limiting which tools are available. Where a tool can write files, modify accounts, send messages, or trigger other consequential actions, keep that capability separate from read-only access when possible and require human approval before execution.
- Use an allowlist: expose only the tools needed for the task rather than the entire server catalog.
- Require approval for sensitive actions: a person should be able to review consequential operations before they run.
- Use progressive disclosure: expose loader functions first, then load only the selected tools. This can reduce the initial tool surface presented to the agent.
- Resolve name collisions: give tools unique names or configure a prefix. Microsoft warns that ambiguous normalized names can raise
ToolExecutionException. - Treat descriptions and schemas as untrusted: they come from the server and should not be treated as instructions that override your application’s policy.
These controls work together. A unique name helps the framework route a call; it does not authorize the action. An approval gate helps control execution; it does not establish that the server is trustworthy.
Review third-party server and data risks
Microsoft warns that remote third-party MCP servers are created by third parties and are not tested or verified by Microsoft. Such servers may receive prompt content or return data to the application. Treat adding a server as a change to your application’s data flow, not merely a configuration convenience.
Rank #4
- Track each server, its operator, the endpoint or local package, and the tools it exposes.
- Prefer a provider’s own hosted server over a proxy when that choice is available, and assess the provider’s retention and data-location practices.
- Review the data sent in prompts and tool arguments, and the content returned by the server.
- Protect credentials, audit calls, and check whether logs could retain sensitive values.
- Apply least privilege and approval controls before connecting tools that can change data or trigger external actions.
These are operational precautions, not a claim that every MCP server is unsafe. The level of review should reflect the sensitivity of the data and the consequences of the tools you enable.
Recommended Free Tools
Expose an Agent Framework agent as an MCP server
The integration also works in reverse: an Agent Framework agent can be made available to an MCP client. Python examples use agent.as_mcp_server(). Microsoft also documents the agent-framework-hosting-mcp package for exposing an Agent Framework agent or workflow through the native MCP SDK.
This pattern is useful when another MCP-capable application needs to call a capability you have implemented with Agent Framework. Decide which agent or workflow functions are exposed, how the server authenticates clients, and what access those clients receive. Microsoft’s support for the pattern does not by itself specify the deployment, authentication, or hosting configuration for every environment; verify those details for the package and host you choose.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Deployment and reliability considerations
For local stdio, the application is responsible for starting and closing the process and for handling missing executables or process failures. The Python context manager helps close the connection when its block exits. For remote HTTP, account for network failures and endpoint availability, and decide how the application should respond if tool discovery or a later tool call fails. Do not assume that a failed tool call should be retried automatically: a write operation may have completed even if the response was lost.
Microsoft’s .NET MCP overview points to Azure MCP Server and Azure Functions remote MCP resources as Azure ecosystem options. Verify current availability, pricing, region support, and authentication behavior before adopting either for production. Do not infer service guarantees or regional coverage from the existence of an overview page.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Best Value
Troubleshoot common connection and tool errors
The stdio server will not start
Check that the command in command is installed and resolvable in the application’s environment, and that each entry in args is correct. Run the server under the same user and environment as the application, and inspect its startup error output. A command available in an interactive shell may not be available to a service process with a different path.
The MCP tool classes or server method are unavailable
Confirm that the installed Agent Framework package includes the API used by the example and that the optional mcp dependency is installed as required. Microsoft notes prerelease support may be needed for MCPStdioTool, MCPStreamableHTTPTool, and Agent.as_mcp_server(). Check package compatibility and current documentation before changing a production dependency to a prerelease build.
A remote server rejects the connection
Verify the endpoint, network access, required headers or invocation arguments, and the credential’s scope and expiry. Never fix an authentication error by placing a secret in the prompt. If the connection succeeds but tools do not, check the server’s tool-discovery response and whether your allowlist excludes the tool.
A tool call raises ToolExecutionException
Check for ambiguous tool names after normalization. Give tools unique names or use a configured prefix, then ensure the agent is allowed to call the intended name. Also inspect the server’s tool schema and the arguments generated for the call.
The agent skips a tool or returns an unexpected result
Check that the tool is actually included in the current run, that the agent instructions explain when it is appropriate, and that the server returned the expected data. A tool being available does not force the model to call it. If the action is required, structure the application flow so that required work is invoked and validated by the application rather than relying only on model choice.
Or skip the browser setup
If your MCP-enabled agent needs website screenshots, ScreenshotNeo offers an MCP server as well as a direct screenshot API. The API can return a screenshot or PDF from one GET request; the example below saves a Stripe screenshot as WebP. See the ScreenshotNeo documentation for options and MCP setup.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
- Cookie and consent banners, newsletter popups, and chat widgets are removed before capture, with each step configurable.
- Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing; response headers report the page verdict and billing status.
- An MCP server gives AI agents tools for screenshots, page information, and PDF capture.
- The free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots.
Sign up for 1,000 free screenshots a month with no card.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

