Home / Chapter 5 · Agents
    Last edited · 11 min read

    Use with AI

    MCP

    MCP (Model Context Protocol) is an open standard for connecting tools and data to model-powered applications. You write an integration once, as an MCP server, and use it in Claude, ChatGPT, an IDE or your own agent. The model knows nothing about MCP: it still sees tool definitions in the prompt and writes calls.

    In plain wordsA wall socket. The kettle maker doesn’t know your wiring, and the electrician doesn’t know the kettle: a shared plug shape is enough. But the socket doesn’t check what you plug into it, so connecting faulty equipment is on you.

    Connect MCP servers and watch what lands in the model’s context before the user types anything

    number of tools in the context
    definition tokens in every request
    of a 200k window used before the first question
    for definitions alone per 1,000 requests

    The definitions in the prompt, i.e. what the model reads. Tools marked “write” change data.

    GitHub as in Anthropic’s example: 35 tools, about 26k tokens (only a few are listed here). The other servers and the system prompt are illustrative. The host here loads every definition up front. Cost at $3 per million input tokens, without prompt caching (a cache hit costs about a tenth of that).

    Why a standard: M + N instead of M × N

    Host, client, server

    Step through an exchange with a calendar server. Watch which part is the MCP protocol and which is ordinary function calling

    Messages are shortened. Every request must carry _meta with the protocol version and client capabilities, and a server rejects one without it; to save space it is shown only in the server/discover step, as in the specification’s own examples. The call format in the model API is generic; every provider names the fields slightly differently.

    Every server costs tokens

    Someone else’s server, code and text

    When you don’t need MCP

    Check yourself

    What is MCP, and when would you use it instead of plain function calling?

    MCP is an open JSON-RPC protocol that standardises the application side of function calling: the host discovers a server’s tools with tools/list and invokes them with tools/call. The model notices nothing; it still sees tool definitions in the prompt and emits calls. The gain is M + N integrations instead of M × N: a server is written once and works in Claude, ChatGPT or an IDE. The cost is the connected servers’ definitions in the context (all of them on every request, unless the host defers them through tool search), and a new trust boundary, because a third-party server is foreign code and foreign text in the prompt. For one app with a few internal tools, plain function calling is enough.

    Po polsku

    MCP to otwarty protokół na JSON-RPC, który standaryzuje stronę aplikacji w function calling: host odkrywa narzędzia serwera przez tools/list i wywołuje je przez tools/call. Model nic nie zauważa, nadal widzi definicje w prompcie i wypisuje wywołania. Zysk to M + N integracji zamiast M × N: serwer pisze się raz i działa w Claude, ChatGPT czy IDE. Cena to definicje podłączonych serwerów w kontekście (wszystkie w każdym requeście, chyba że host odracza je przez wyszukiwanie narzędzi) i nowa granica zaufania, bo obcy serwer to obcy kod i obcy tekst w prompcie. Dla jednej aplikacji z kilkoma własnymi narzędziami wystarczy zwykłe function calling.

    Follow-up questions (5)
    You have 30 MCP servers and the agent starts picking the wrong tools. What do you do?
    Measure how many tokens the definitions take and which tools overlap. Keep only the tools the task needs, and load the rest through tool search or split them between sub-agents with their own sets. Don’t reorder or remove tools mid-conversation, so as not to break the prompt cache.
    How do you allow MCP servers in a company without opening a path to data leaks?
    An allowlist of approved servers with pinned versions and a diff of the definitions on every update, local servers in a sandbox, and minimally scoped OAuth tokens issued for a specific server. Write and send actions are approved by a human in the host, and every call goes to an audit log.
    How do tools, resources and prompts differ?
    In who decides to use them. The model chooses tools, the application attaches resources, e.g. a file or a database schema as context, and the user picks prompts, usually as a slash command. Not every host supports all three: the MCP connector in the Anthropic API supports only tools.
    Why did version 2026-07-28 remove sessions and initialize?
    So that a remote server scales like an ordinary API. Every request carries the protocol version and the client’s capabilities, so it can hit any instance behind a load balancer with no shared state. The server passes state between calls explicitly: a tool returns a handle, and the model passes it in the next call.
    You are building an MCP server on top of an existing REST API. How do you approach it?
    Don’t map endpoints one to one. Pick a few tasks the agent actually performs and turn them into tools that combine several API calls themselves. Return only the fields needed, filter and paginate on the server side, and send validation errors back as a result with isError and a hint on how to fix the arguments.

    Sources

    Report an error · Suggest a fix