Module
Module 2 of 7Lesson 2 of 2~17 min

Local or remote - transports and authorization

Lesson 2 of the module "What MCP standardizes" in the course "Connect AI to your tools and data with MCP".

Lesson objective

By the end of this lesson, you will be able to say whether an MCP server is local or remote, deduce its transport (stdio or Streamable HTTP) and its risks, and explain how a remote server authenticates its users with OAuth.

Where it fits

What MCP standardizes

Who talks to whom in MCP, what flows between them, and how is access controlled?

Lessons in this module

  1. What MCP standardizes, and what it does not
  2. Local or remote - transports and authorization (this lesson)

What you will learn in the course

This lesson is part of the course Connect AI to your tools and data with MCP

  • Explain what MCP standardizes (host, client, server; tools, resources, prompts; transports; authorization) and what each element implies for a product.
  • Choose between an MCP server, a direct API integration, an in-house tool and a skill for a given need, and justify the choice.
  • Find, evaluate and connect an existing MCP server in a free client, with limited rights, and verify what it actually exposes.
  • Identify the risks specific to MCP (tool poisoning, rug pulls, injection through results, over-broad permissions, confused deputy, supply chain) and specify the matching guardrails.
  • Decide whether to expose your product as an MCP server and, if so, specify its scope (users, tools, rights, authentication, measurement).