Skip to content
Module
AI

MCP (Model Context Protocol)

Introduced by Anthropic in November 2024, MCP (Model Context Protocol) is an open specification that defines how AI applications connect to external tools and data sources. An MCP server exposes capabilities, mainly tools, resources and prompts, and any compatible client (an AI assistant, an IDE, an agent) can use them without a custom integration. It is often compared to a universal port: one connector instead of one integration per pair of app and tool.

Why it matters for a PM

MCP raises two product questions. As a user of AI tools, you decide which servers your team may connect, with what access, and how to vet them. As a product owner, you may consider exposing your own product as an MCP server so that assistants can act on it, which is a distribution and security decision as much as a technical one.

Example

A product team connects its AI assistant to the ticketing system through an MCP server in read-only mode. PMs can ask “which bugs tagged checkout were reported this week?” and get answers from live data, while creating or closing tickets stays out of reach until the team has reviewed the risks.

Key points

  • MCP standardizes the connection between a client and a server; it does not decide what the model does with the tools.
  • Servers run locally (stdio transport) or remotely over HTTP, with OAuth-based authorization for remote access.
  • An MCP server often wraps an existing API, so it does not replace good API design.
  • Starting read-only, with least privilege, limits the damage of a misbehaving server or model.

Common mistakes

  • Installing community servers without checking who maintains them and what they can access.
  • Assuming MCP handles authorization and data filtering for you.
  • Overlooking tool poisoning: malicious instructions hidden in tool descriptions or results.
  • Building an MCP server before knowing which user tasks it should serve.

Go further with Module

The courses and lessons that cover this concept: