Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An MCP host is the AI application that coordinates the conversation and manages connections; an MCP client is the host-managed connection to one server; and an MCP server provides tools, resources, or prompts. One host can connect to many servers by creating a separate client for each. That division determines who handles orchestration, protocol messages, and capabilities.

Host, client, and server: the short version

Role What it is responsible for Typical relationship
MCP host The enclosing AI application or process. It integrates with the model, manages user consent and connection policy, and coordinates context. One host can manage multiple clients.
MCP client The protocol component that negotiates and maintains a connection, and routes messages, for one server. A host creates a distinct client for each server.
MCP server A capability provider that exposes tools, resources, and prompts to a client. A server communicates over its MCP connection with a client managed by a host.

The official MCP architecture guide describes the pattern this way: “The Model Context Protocol (MCP) follows a client-host-server architecture where each host can run multiple client instances.” The host, client, and server are distinct roles, even when software packaging or product labels make them look like one component.

What an MCP host does

The host is the application the user interacts with, or the enclosing process responsible for coordinating MCP. AI applications such as Claude Desktop and Claude Code are examples in the official guide. The host connects MCP to the model and user experience; it decides which configured connections are available and manages their lifecycle, authorization, and consent.

The host also owns the broad conversation context and decides how server results are presented to the model or user. It should not hand every server the entire conversation by default. Instead, it can route relevant requests and results through the appropriate client while enforcing boundaries between servers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is Claude Desktop an MCP host or an MCP client?

In the architecture model, Claude Desktop is an example of an MCP host. It may create MCP client instances to connect to configured servers. Calling the application “the client” in casual conversation is understandable, but it blurs the distinction: the application hosts the client component rather than being just one server-specific protocol connection.

What an MCP client does

An MCP client is the host-managed protocol component associated with one server. It establishes and maintains that connection, negotiates protocol versions and capabilities, sends and receives JSON-RPC messages, and can manage subscriptions where supported. It forwards relevant results to the host, which decides what to do with them.

The one-client-to-one-server relationship is the most useful distinction: if a host connects to several servers, it manages a separate client connection for each. A client is not the whole AI application, and it is not the capability provider at the other end of the connection.

Does every MCP server need its own client?

In the host-client-server architecture, each server connection has its own client instance managed by the host. This lets the host keep protocol state and messages associated with the correct server. It does not mean a user must install a separate application for every server; a single host can manage multiple clients and connections.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What an MCP server provides

An MCP server makes focused capabilities available to clients. It may run as a local process or as a remote service. The core server-side primitives are:

  • Tools: executable functions that a model can use through the host and client, subject to the host’s policies and user permissions.
  • Resources: contextual data that an application can make available to the model.
  • Prompts: reusable interaction templates that a user or application can select.

The server is not automatically given the host’s full conversation or access to other servers’ context. A server can request supported client-side interactions, such as elicitation, but the host and client must support and handle the relevant capability.

How a request moves through the system

  1. The host receives an action. A user asks a question or the model identifies a need for a capability.
  2. The host selects a connection. Its policy and integration determine which server can handle the task.
  3. The corresponding client sends a request. It communicates with that server using MCP’s JSON-RPC message model over the configured transport.
  4. The server responds. It returns a tool result or other protocol response within its advertised and negotiated capabilities.
  5. The client forwards the result. The host incorporates it into the application or model context, subject to its own rules.

Thus, the host is the orchestration and policy layer, the client is the protocol-connection layer, and the server is the capability layer. The protocol message model is shared across transports; choosing another transport does not change those responsibilities.

How transport affects the connection

Transport How it works Common fit
stdio The client launches a server as a subprocess and exchanges newline-delimited JSON-RPC messages through standard input and output. Local process integrations; avoids network overhead.
Streamable HTTP The client communicates with a remote server over HTTP POST, with optional streaming and standard HTTP authentication methods. Hosted or internet-accessible services.

The choice changes how the client reaches the server, not which role owns orchestration, protocol handling, or capability provision. Follow the transport and authentication requirements of the specific server and MCP specification revision you use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Capabilities, negotiation, and control

Servers advertise the capabilities they provide, such as tools, resource subscriptions, or prompt templates. Clients advertise supported client-side capabilities and must honor the feature set negotiated for the connection. A host should not assume that a server or client implements every MCP feature.

The primitive hierarchy also helps explain who normally controls an action: tools are generally model-controlled actions, resources are application-controlled context, and prompts are user-controlled templates. These are broad interaction patterns, not permission to bypass host policy. The host remains responsible for deciding what connections are authorized and what results or actions are allowed.

Security and isolation across servers

Isolation is an architectural boundary, not a guarantee that every implementation is secure by default. The host owns authorization decisions and cross-server policy. A server should receive only the context needed for its task; it should not be able to read the whole conversation or inspect another server’s context. A separate client connection per server helps preserve that separation.

  • Review which servers the host is configured to use and what permissions it grants.
  • Limit context and credentials sent to a server to what its task requires.
  • Check the authentication and transport configuration, especially for remote Streamable HTTP connections.
  • Confirm that the host and server support the capabilities the workflow depends on.

Which role should your code implement?

Decide by the responsibility your software needs to own, not by whether it uses an LLM. If it supplies a capability for an MCP-enabled application, it is server-side software. If it connects to and speaks MCP with a particular server, it is client-side software. If it coordinates the model, user experience, permissions, and multiple client connections, it is host-side software.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Your software needs to… Likely role Key design question
Expose functions, data, or reusable prompt templates to an MCP application. Server Which primitives and capabilities should this service advertise?
Connect to a server and exchange MCP messages. Client Which transport, protocol revision, and negotiated capabilities are supported?
Manage users, model interaction, consent, policy, and several MCP connections. Host How will permissions, context routing, lifecycle, and isolation be enforced?

A product can contain multiple roles internally, but the roles remain conceptually separate. For example, a host process may include client implementations, while a server may use other services behind its own interface. Name each component according to the MCP responsibility it performs.

Version and implementation details to check

MCP evolves, so exact method names, capability details, and SDK support depend on the specification revision and implementation in use. The release announcement dated 2026-07-28 describes a stateless protocol core, multi-round-trip requests, header-based routing, cacheable list results, and updated Tier 1 SDKs. Consult the relevant versioned specification and SDK documentation before relying on an exact method or behavior; do not assume a newer feature is present in an older host, client, or server.

There is no established authoritative statistic comparing host, client, and server performance or adoption. The roles describe architecture, not a measured performance ranking.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your MCP work includes producing website screenshots for an AI agent or developer workflow, ScreenshotNeo provides an MCP server with the tools take_screenshot, get_page_info, and capture_pdf. Its website screenshot API also returns an image or PDF from one GET request. Cookie banners are accepted or removed before capture, along with known consent platforms, newsletter popups, and chat widgets; bot checks, blank pages, timeouts, failed loads, and cache hits are not billed. Responses identify the page verdict and billing status in headers. One thousand screenshots per month are free with no card; paid plans start at $5 for 3,000 shots. See the ScreenshotNeo documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo is made by Yorker Media. Every feature is available on every plan; yearly billing gives two months free. To try it, sign up for 1,000 free screenshots a month, with no card required.

Frequently Asked Questions

Can an MCP server connect directly to a host?

MCP communication is organized through a client connection managed by the host; the server provides capabilities over that connection.

Are tools, resources, and prompts interchangeable?

No. They are distinct MCP primitives with different roles: executable actions, contextual data, and reusable templates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.