Module
Back to courses
AI & ProductAdvanced

Connect AI to your tools and data with MCP

Decide when MCP serves your product, connect an existing server read-only, counter its risks and decide whether to expose your own.

40 steps~2 hr 30 minLevel: Advanced · Regular practice: you already use the tools or work on this topic.

Decide when the Model Context Protocol (MCP) serves your product, and use it without opening a breach: understand what the protocol standardizes (host, client, server; tools, resources, prompts; transports and authorization), choose between an MCP server, an API integration, an in-house tool and a skill, evaluate then connect an existing server read-only in a free client, counter the risks specific to MCP, and settle the question that comes sooner or later: should you expose your product as an MCP server? You leave with a reasoned "use / expose" decision and a server that is connected, restricted and verified.

What you will be able to do

  • Explain what MCP standardizes (host, client, server; tools, resources, prompts; transports; authorization) and what each element implies for a product.
  • Choose between an MCP server, a direct API integration, an in-house tool and a skill for a given need, and justify the choice.
  • Find, evaluate and connect an existing MCP server in a free client, with limited rights, and verify what it actually exposes.
  • Identify the risks specific to MCP (tool poisoning, rug pulls, injection through results, over-broad permissions, confused deputy, supply chain) and specify the matching guardrails.
  • Decide whether to expose your product as an MCP server and, if so, specify its scope (users, tools, rights, authentication, measurement).

Prerequisites

  • Know what an API is and what a model's tool call is, at the "I know what it is" level
  • Have used an AI assistant (Claude, ChatGPT, Copilot…) for a work task
  • Recommended course: Build an AI assistant for your product (its lesson on tools introduces MCP in one page; this course goes deeper).
  • Recommended course: Design reliable agents and tool calling (tool cards, injection through tool outputs).
  • The practice requires no code; it does require Node.js. Guaranteed free path: MCP Inspector; Claude Desktop if your plan shows the Developer tab.

Syllabus

What will I decide and connect in this course, and in what order?

  1. Objective · By the end of this overview, you will know what you are going to produce (your "use / expose an MCP server" decision and an existing server that is connected, restricted and verified) and in what order the six modules get you there.

Who talks to whom in MCP, what flows between them, and how is access controlled?

  1. Objective · By the end of this lesson, you will be able to describe an MCP connection by naming the host, the client and the server, to say who controls each primitive (tools, resources, prompts) and to explain what the protocol does not decide for you.

  2. Objective · By the end of this lesson, you will be able to say whether an MCP server is local or remote, deduce its transport (stdio or Streamable HTTP) and its risks, and explain how a remote server authenticates its users with OAuth.

For this need, do you want an MCP server, an API integration, an in-house tool or a skill?

  1. Objective · By the end of this lesson, you will be able to choose between an MCP server, a direct API integration, an in-house tool and a skill for a given need, based on four questions (who is the host, is the flow fixed, how many integrations, access or know-how) and on the context cost.

How do you pick an existing server, and connect it without giving it more than it needs?

  1. Objective · By the end of this lesson, you will be able to find candidate MCP servers for a need, fill in their evaluation card (provenance, maintenance, transport, authentication, tools, rights, data) and keep or reject each one with a written reason.

  2. Objective · By the end of this lesson, you will be able to connect an existing MCP server in a free client, restricted to a read-only folder and at a pinned version, then verify with the Inspector and five tests what it can and cannot do.

What can an MCP server get wrong, and what stops it?

  1. Objective · By the end of this lesson, you will be able to recognize the seven risks specific to MCP (tool poisoning, rug pulls, injection through results, over-broad permissions, confused deputy, token passthrough, supply chain) and match each one with a structural guardrail and a detection signal.

Should you offer an MCP server to your customers, with what scope, and how will you know it was a good idea?

  1. Objective · By the end of this lesson, you will be able to decide whether to expose your product as an MCP server and, if so, write its exposure card - target users and hosts, use cases, v1 tools, rights and authentication, security, metrics and launch conditions.

What is your "use / expose" decision, and does your connected server hold up in review?

  1. Objective · By the end of this lesson, you will be able to assemble the MCP decision for your product (mechanisms chosen, server evaluated and connected with its evidence, risk table, exposure decision), self-assess it with the kit's checklist and plan its application over 7 and 30 days.