[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"portal-settings:stajic:en":3,"public-menus:all":38,"post:mcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits:en":205,"related:post:mcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits:en:1":2356},{"statusCode":4,"data":5,"message":37},200,{"tenantId":6,"lang":7,"defaultLang":8,"siteUrl":9,"contactEmail":10,"brandName":11,"logoUrl":12,"siteName":11,"siteDescription":13,"ogImage":10,"robotsIndex":14,"socialLinks":10,"reservedSlugs":10,"seoPolicy":15},"stajic","en","de","https:\u002F\u002Fstajic.de",null,"Stajic Platform","\u002FLogo_Planet.svg","Stajic Portal",true,{"branding":16,"relatedContent":17,"crossDomainLinks":18},{"logoUrl":12},{"enabled":14},[19,22,25,28,31,34],{"url":20,"label":21,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Ffigure.rocks","figure.rocks",{"url":23,"label":24,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Floving.rocks","loving.rocks",{"url":26,"label":27,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.com","bazify.com",{"url":29,"label":30,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.de","bazify.de",{"url":32,"label":33,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.at","bazify.at",{"url":35,"label":36,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.ba","bazify.ba","Portal settings resolved",[39,45],{"id":40,"name":41,"location":42,"isActive":14,"isDefault":43,"items":44},1,"main-navigation","header",false,[],{"id":46,"name":47,"location":48,"isActive":14,"isDefault":14,"items":49},4,"main-menu","sidebar",[50,66,79,93,103,118,133],{"id":51,"title":52,"url":60,"target":61,"icon":62,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":64,"portfolioId":10,"children":65},"item-18",{"de":53,"en":54,"es":55,"fr":56,"it":54,"ru":57,"sr":58,"zh":59},"Startseite","Home","Inicio","Accueil","Главная","Почетна","首页","\u002Ffull-stack-web-developer-munich-performance-seo-and-maintainable-builds","_self","i-lucide-home","page",111,[],{"id":67,"title":68,"url":75,"target":61,"icon":76,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":77,"portfolioId":10,"children":78},"item-22",{"de":69,"en":69,"es":70,"fr":69,"it":71,"ru":72,"sr":73,"zh":74},"Vision","Visión","Visione","Видение","Визија","想象","\u002Fueber-uns-webdesign-muenchen-webaplikation","i-lucide-eye",113,[],{"id":80,"title":81,"url":89,"target":61,"icon":90,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":91,"portfolioId":10,"children":92},"item-19",{"de":82,"en":83,"es":84,"fr":83,"it":85,"ru":86,"sr":87,"zh":88},"Leistungen","Services","Servicios","Servizi","Услуги","Услуге","服务","\u002Fservices-dienstleistungen-muenchen","i-lucide-wrench",116,[],{"id":94,"title":95,"url":99,"target":61,"icon":100,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":101,"portfolioId":10,"children":102},"item-23",{"de":96,"en":96,"es":96,"fr":96,"it":96,"ru":97,"sr":97,"zh":98},"Blog","Блог","博客","\u002Fblog","i-lucide-book-open",112,[],{"id":104,"title":105,"url":114,"target":61,"icon":115,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":116,"portfolioId":10,"children":117},"item-32",{"de":106,"en":107,"es":108,"fr":109,"it":110,"ru":111,"sr":112,"zh":113},"Neue Technologien","New Technologies","Nuevas tecnologías","Nouvelles technologies","Nuove tecnologie","Новые технологии","Нове технологије","新技术！","\u002Fneue-webtechnologien","i-lucide-sparkles",122,[],{"id":119,"title":120,"url":129,"target":61,"icon":130,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":131,"portfolioId":10,"children":132},"item-20",{"de":121,"en":122,"es":123,"fr":124,"it":125,"ru":126,"sr":127,"zh":128},"Kontakt","Contact us!","Contacto","Contact","Contatto","Контакт","Контактирајте нас","联系我们！","\u002Fcontact","i-lucide-mail",115,[],{"id":134,"title":135,"url":144,"target":61,"icon":145,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":147},"item-21",{"de":136,"en":137,"es":138,"fr":139,"it":140,"ru":141,"sr":142,"zh":143},"Unsere Arbeit","Our Work","Nuestro trabajo","Nos réalisations","I nostri lavori","Наши работы","Наши радови","文件夹","\u002Fportfolio","i-lucide-briefcase",114,[148,161,175,181,193],{"id":149,"title":150,"url":144,"target":61,"icon":159,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":160},"item-24",{"de":151,"en":152,"es":153,"fr":154,"it":155,"ru":156,"sr":157,"zh":158},"Alle Projekte","All Projects","Todos los proyectos","Tous les projets","Tutti i progetti","Все проекты","Сви пројекти","所有项目","i-lucide-grid-3x3",[],{"id":162,"title":163,"url":171,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":174},"item-29",{"de":164,"en":165,"es":166,"fr":167,"it":168,"ru":169,"sr":170,"zh":143},"Local Roots, Global Reach","Local Roots - Global Reach","Empresa local ","Entreprise locale","Azienda locale","Местная компания","Локално предузеће глобално тржиште","\u002Fportfolio\u002Flocal-roots-global-reach-communication-media-systems-for-modern-business","i-lucide-folder","custom",[],{"id":176,"title":177,"url":179,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":180},"item-28",{"de":178,"en":178,"es":178,"fr":178,"it":178,"ru":178,"sr":178,"zh":178},"Solr Suggester","\u002Fportfolio\u002Fsolr-fuzzy-suggester-und-solr-infix-suggester-abfrage-ueber-ajax-und-filterung",[],{"id":182,"title":183,"url":191,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":192},"item-27",{"de":184,"en":185,"es":186,"fr":187,"it":188,"ru":189,"sr":190,"zh":185},"Firmenwebseite SEO","Company Website SEO","Sitio web corporativo SEO","Site web d’entreprise SEO","Sito web aziendale SEO","Корпоративный сайт SEO","Пословна веб-страница SEO","\u002Fportfolio\u002Fseo-sem-branding-mobile-webseite-muenchen",[],{"id":194,"title":195,"url":203,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":204},"item-31",{"de":196,"en":197,"es":198,"fr":199,"it":200,"ru":201,"sr":202,"zh":197},"Digitalisierungsportal","Digitalization Portal","Portal de digitalización","Portail de numérisation","Portale di digitalizzazione","Портал цифровизации","Портал за дигитализацију","\u002Fportfolio\u002Fdigitalisierungsportal-archiv-museum-bibliothek-ead-lido-mets-mods",[],{"statusCode":4,"data":206,"message":2355},{"id":207,"title":208,"slug":209,"content":210,"contentJson":211,"excerpt":1610,"featuredImage":1611,"featuredImageAlt":1612,"featuredImageCaption":10,"featuredImageTitle":10,"featuredImageCopyright":10,"featuredImageAuthor":10,"featuredImageSourceUrl":10,"featuredImageLicense":10,"featuredImageIsAiGenerated":43,"status":1613,"publishedAt":1614,"createdAt":1615,"updatedAt":1616,"seoLocalePaths":1617,"categories":1626,"author":1643,"translations":1648},"492","MCP Explained: What It Connects, What It Does Not Do and Where It Fits","mcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","{\"time\":1791486641380,\"blocks\":[{\"id\":\"intro\",\"type\":\"paragraph\",\"data\":{\"text\":\"The Model Context Protocol (MCP) is an open protocol for connecting AI applications to external capabilities and information through standardized client-server contracts. An MCP server can expose tools, resources and prompts; an MCP-compatible host or client discovers and uses those capabilities on behalf of an AI application. MCP does not require the server to run its own language model, and it does not replace the agent runtime, business authorization, tenant isolation, application APIs or domain architecture behind the exposed capabilities.\"},\"tunes\":{}},{\"id\":\"direct\",\"type\":\"callout\",\"data\":{\"variant\":\"info\",\"title\":\"Direct answer\",\"body\":\"\u003Cstrong>MCP standardizes the boundary between an AI host and external capability providers.\u003C\u002Fstrong>\u003Cbr>\u003Cbr>A useful mental model is:\u003Cbr>\u003Cstrong>User → AI host \u002F agent runtime → MCP client → MCP server → application\u002FAPI\u002Fdata\u002Ftool\u003C\u002Fstrong>.\u003Cbr>\u003Cbr>The model can remain entirely on the host side. The MCP server may be ordinary deterministic software that exposes structured capabilities.\"},\"tunes\":{}},{\"id\":\"server-no-ai\",\"type\":\"callout\",\"data\":{\"variant\":\"success\",\"title\":\"An MCP server does not need its own AI model\",\"body\":\"A filesystem MCP server can list or read files. A database MCP server can run approved queries. A Jira MCP server can expose issue operations. None of those servers needs an LLM to satisfy the MCP contract. If a server internally uses AI, that is an implementation choice behind the protocol boundary, not an MCP requirement.\"},\"tunes\":{}},{\"id\":\"boundary\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"MCP capability is not business authority\",\"body\":\"If an MCP server exposes \u003Ccode>delete_file\u003C\u002Fcode>, \u003Ccode>refund_order\u003C\u002Fcode> or \u003Ccode>deploy_service\u003C\u002Fcode>, that only means the capability exists. The server\u002Fapplication must still enforce identity, permissions, tenant scope, business rules, confirmation requirements and audit controls. Protocol discovery must never silently become authorization.\"},\"tunes\":{}},{\"id\":\"current\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Current-source note — 8 October 2026\",\"body\":\"The current MCP specification revision is \u003Cstrong>2026-07-28\u003C\u002Fstrong>. Its major change is a stateless protocol core with self-describing requests, optional \u003Ccode>server\u002Fdiscover\u003C\u002Fcode>, routable HTTP headers, cacheable list\u002Fresource responses, authorization hardening and a formal extension model. The TypeScript SDK v2 is the current stable SDK line implementing this revision. Older 2025-era clients and servers still exist, so implementation guidance must remain version-aware.\"},\"tunes\":{}},{\"id\":\"toc\",\"type\":\"tableOfContents\",\"data\":{\"title\":\"Contents\",\"minLevel\":2,\"maxLevel\":3},\"tunes\":{}},{\"id\":\"h-meaning\",\"type\":\"header\",\"data\":{\"text\":\"What MCP really standardizes\",\"level\":2},\"tunes\":{}},{\"id\":\"p-meaning-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Before MCP, every AI application could integrate external systems through its own tool schema, plugin format, authentication convention and connection code. The same service could need different adapters for a desktop AI client, an IDE agent and a custom application.\"},\"tunes\":{}},{\"id\":\"p-meaning-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP creates a reusable protocol boundary. The external system exposes capabilities through an MCP server, while compatible AI hosts implement an MCP client. This reduces integration coupling between the AI application and the underlying tool or data provider.\"},\"tunes\":{}},{\"id\":\"p-meaning-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The protocol does not standardize the entire application. It standardizes how capabilities are described, discovered and invoked across that boundary.\"},\"tunes\":{}},{\"id\":\"h-simple\",\"type\":\"header\",\"data\":{\"text\":\"The simplest example\",\"level\":2},\"tunes\":{}},{\"id\":\"p-simple-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Suppose an AI coding application needs access to a local project directory. Without MCP, the application might implement its own filesystem integration directly.\"},\"tunes\":{}},{\"id\":\"p-simple-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"With MCP, a filesystem server can expose capabilities such as listing directories, reading approved files or writing inside an allowed workspace. The AI host connects through an MCP client and presents those capabilities to the model or agent runtime.\"},\"tunes\":{}},{\"id\":\"p-simple-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The server does not need to understand the user's natural-language request. The host\u002Fmodel decides which capability is useful; the MCP server executes the structured request under its own security rules.\"},\"tunes\":{}},{\"id\":\"simple-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"A basic MCP tool call\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Host connects to server\",\"description\":\"The MCP-capable application configures access to the external MCP server.\"},{\"label\":\"2. Capabilities are discovered\",\"description\":\"The client learns which tools, resources or prompts the server exposes.\"},{\"label\":\"3. Model or runtime selects a capability\",\"description\":\"The AI application decides that one exposed capability is needed.\"},{\"label\":\"4. Client sends structured request\",\"description\":\"Arguments are sent through MCP to the server.\"},{\"label\":\"5. Server authorizes and executes\",\"description\":\"The server validates the request and calls its underlying system.\"},{\"label\":\"6. Result returns to host\",\"description\":\"The result becomes an observation or context input.\"},{\"label\":\"7. Host decides what happens next\",\"description\":\"The model\u002Fruntime may answer, call another tool or continue a workflow.\"}]},\"tunes\":{}},{\"id\":\"h-stops\",\"type\":\"header\",\"data\":{\"text\":\"Where the simple example stops\",\"level\":2},\"tunes\":{}},{\"id\":\"p-stops-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP does not define how the host chooses a tool, how an agent plans, how a business workflow is modeled or how a domain object such as an invoice or deployment should behave.\"},\"tunes\":{}},{\"id\":\"p-stops-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A protocol can make the integration interoperable while the underlying application remains incorrect, insecure or badly designed. A perfectly valid MCP request can still call the wrong business capability.\"},\"tunes\":{}},{\"id\":\"p-stops-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The central boundary is: MCP standardizes integration semantics, not application truth or business correctness.\"},\"tunes\":{}},{\"id\":\"h-architecture\",\"type\":\"header\",\"data\":{\"text\":\"The MCP architecture: host, client and server\",\"level\":2},\"tunes\":{}},{\"id\":\"architecture-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Component\",\"Responsibility\"],[\"AI host\",\"User-facing AI application or runtime that owns model interaction, context and overall workflow\"],[\"MCP client\",\"Protocol-side component used by the host to communicate with an MCP server\"],[\"MCP server\",\"Publishes capabilities and handles MCP requests\"],[\"Underlying system\",\"Application, API, database, filesystem, SaaS platform or service behind the MCP server\"],[\"Model\",\"Chooses or reasons about capabilities according to the host\u002Fruntime design; it is not necessarily inside the MCP server\"],[\"Authorization\u002Fbusiness policy\",\"Determines whether a requested operation is actually permitted\"]]},\"tunes\":{}},{\"id\":\"p-architecture-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A host can connect to multiple MCP servers, and one MCP server can front one or several underlying systems. The host remains responsible for integrating MCP results into the broader AI application.\"},\"tunes\":{}},{\"id\":\"p-architecture-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The server can be local to the host, run as a separate process or be remote over a network transport. Hosting topology and model location are independent decisions.\"},\"tunes\":{}},{\"id\":\"h-primitives\",\"type\":\"header\",\"data\":{\"text\":\"The three core server primitives\",\"level\":2},\"tunes\":{}},{\"id\":\"primitives-comparison\",\"type\":\"comparison\",\"data\":{\"title\":\"Tools, resources and prompts solve different needs\",\"layout\":\"table\",\"columns\":[{\"id\":\"tools\",\"label\":\"Tools\"},{\"id\":\"resources\",\"label\":\"Resources\"},{\"id\":\"prompts\",\"label\":\"Prompts\"}],\"rows\":[{\"id\":\"purpose\",\"label\":\"Primary purpose\",\"values\":[\"\",\"\",\"\"]},{\"id\":\"interaction\",\"label\":\"Typical interaction\",\"values\":[\"\",\"\",\"\"]},{\"id\":\"example\",\"label\":\"Example\",\"values\":[\"\",\"\",\"\"]},{\"id\":\"risk\",\"label\":\"Typical risk\",\"values\":[\"\",\"\",\"\"]}]},\"tunes\":{}},{\"id\":\"h-tools\",\"type\":\"header\",\"data\":{\"text\":\"Tools: callable capabilities\",\"level\":2},\"tunes\":{}},{\"id\":\"p-tools-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Tools are structured operations an MCP server makes available to the host. A tool has a name, description and input schema; modern implementations can also provide structured output.\"},\"tunes\":{}},{\"id\":\"p-tools-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Examples include searching a repository, reading a customer record, creating a ticket, running a build or sending a message. Tools can be read-only or have side effects.\"},\"tunes\":{}},{\"id\":\"p-tools-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"A good MCP tool surface should represent coherent user or agent goals rather than mechanically mirror every internal API endpoint. Operations with different permissions, confirmation requirements or blast radius should usually be separate tools.\"},\"tunes\":{}},{\"id\":\"h-resources\",\"type\":\"header\",\"data\":{\"text\":\"Resources: readable context and data\",\"level\":2},\"tunes\":{}},{\"id\":\"p-res-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Resources expose data or content that a client can list or read. They fit naturally when the semantic operation is “give me this artifact or information” rather than “perform this action.”\"},\"tunes\":{}},{\"id\":\"p-res-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A resource URI is not an authorization grant. The server still owns access control and must verify which principal may read the underlying object.\"},\"tunes\":{}},{\"id\":\"p-res-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The 2026-07-28 protocol revision adds cache semantics for list and resource-read responses, including freshness and cache scope, making caching behavior more explicit.\"},\"tunes\":{}},{\"id\":\"h-prompts\",\"type\":\"header\",\"data\":{\"text\":\"Prompts: reusable templates\",\"level\":2},\"tunes\":{}},{\"id\":\"p-prompts-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP prompts let a server publish reusable prompt templates to compatible clients. This can keep domain-specific instructions close to the capability provider.\"},\"tunes\":{}},{\"id\":\"p-prompts-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A prompt supplied by an MCP server does not automatically outrank the host's system or security instructions. The host decides how prompt material enters its context hierarchy.\"},\"tunes\":{}},{\"id\":\"p-prompts-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Protocol-provided prompt content should therefore be treated as capability data with explicit trust semantics, not as unrestricted instruction authority.\"},\"tunes\":{}},{\"id\":\"h-tool-vs-resource\",\"type\":\"header\",\"data\":{\"text\":\"Tool or resource?\",\"level\":2},\"tunes\":{}},{\"id\":\"tool-resource-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Need\",\"Prefer\"],[\"Perform an action with structured arguments\",\"Tool\"],[\"Read a specific stable artifact\",\"Resource\"],[\"Search or calculate dynamically\",\"Usually tool\"],[\"Modify external state\",\"Tool\"],[\"Package reusable prompt instructions\",\"Prompt\"],[\"Long-running asynchronous execution\",\"Tool plus application\u002Fruntime task handling or an MCP extension\"]]},\"tunes\":{}},{\"id\":\"h-model-location\",\"type\":\"header\",\"data\":{\"text\":\"Where is the AI model?\",\"level\":2},\"tunes\":{}},{\"id\":\"p-location-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP does not require the model to run on the MCP server. The model can be cloud-hosted, locally hosted, embedded in the desktop application or reached through another provider.\"},\"tunes\":{}},{\"id\":\"p-location-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The host normally owns the model interaction. The MCP server exposes external capability. A local MCP server can therefore be used by a host whose model runs in the cloud, and a remote MCP server can be used by a host whose model runs locally.\"},\"tunes\":{}},{\"id\":\"p-location-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"If the MCP server itself calls an LLM internally, that model is part of the server's implementation behind the protocol boundary; it is not required by MCP.\"},\"tunes\":{}},{\"id\":\"location-rule\",\"type\":\"callout\",\"data\":{\"variant\":\"success\",\"title\":\"Protocol location ≠ inference location\",\"body\":\"\u003Cstrong>Local MCP does not imply local inference, and remote MCP does not imply remote inference.\u003C\u002Fstrong> Connection location, tool-execution location and model\u002Fprovider location are separate architecture dimensions.\"},\"tunes\":{}},{\"id\":\"h-mcp-vs-api\",\"type\":\"header\",\"data\":{\"text\":\"MCP does not replace APIs\",\"level\":2},\"tunes\":{}},{\"id\":\"p-api-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An MCP server often wraps existing APIs or services. REST, GraphQL, SQL, SDK calls and internal service contracts can remain exactly where they are.\"},\"tunes\":{}},{\"id\":\"p-api-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP adds an AI-facing interoperability layer. The underlying domain API can remain the authoritative application contract for ordinary deterministic clients.\"},\"tunes\":{}},{\"id\":\"p-api-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The usual architecture is therefore API\u002Fservice first, selected AI-facing capability second — not “replace every API with MCP.”\"},\"tunes\":{}},{\"id\":\"h-function-calling\",\"type\":\"header\",\"data\":{\"text\":\"MCP vs function calling\",\"level\":2},\"tunes\":{}},{\"id\":\"function-comparison\",\"type\":\"comparison\",\"data\":{\"title\":\"Function calling and MCP are related but not identical\",\"layout\":\"table\",\"columns\":[{\"id\":\"function\",\"label\":\"Function calling\"},{\"id\":\"mcp\",\"label\":\"MCP\"}],\"rows\":[{\"id\":\"scope\",\"label\":\"Scope\",\"values\":[\"\",\"\"]},{\"id\":\"definition\",\"label\":\"Tool definition\",\"values\":[\"\",\"\"]},{\"id\":\"portability\",\"label\":\"Portability\",\"values\":[\"\",\"\"]},{\"id\":\"coexist\",\"label\":\"Can they coexist?\",\"values\":[\"\",\"\"]}]},\"tunes\":{}},{\"id\":\"p-function-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"OpenAI currently exposes remote MCP servers as one tool type alongside ordinary function calling, web search, shell and other tools. That implementation illustrates the architectural relationship: MCP connectivity and the model's own tool-call interface can be composed.\"},\"tunes\":{}},{\"id\":\"h-agent\",\"type\":\"header\",\"data\":{\"text\":\"MCP does not create the agent loop\",\"level\":2},\"tunes\":{}},{\"id\":\"p-agent-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An AI agent needs a runtime that can decide, invoke tools, observe results, update state and continue or stop. MCP can supply some of the tools and data used by that loop.\"},\"tunes\":{}},{\"id\":\"p-agent-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The MCP server does not automatically become the planner, memory system or orchestrator. Those responsibilities normally remain in the host or agent runtime.\"},\"tunes\":{}},{\"id\":\"p-agent-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"A non-agentic application can also use MCP. One deterministic MCP tool call does not require an autonomous multi-step agent.\"},\"tunes\":{}},{\"id\":\"h-a2a\",\"type\":\"header\",\"data\":{\"text\":\"MCP vs A2A\",\"level\":2},\"tunes\":{}},{\"id\":\"p-a2a-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP primarily connects an AI host or agent to capabilities such as tools, resources and data. A2A targets collaboration between independent agent systems.\"},\"tunes\":{}},{\"id\":\"p-a2a-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A remote agent can internally use MCP to reach databases and tools while exposing an A2A interface to other agents. The protocols can therefore be layered rather than substituted.\"},\"tunes\":{}},{\"id\":\"p-a2a-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The existing protocol-stack article owns the broader MCP\u002FA2A\u002FUCP\u002FAP2\u002FA2UI comparison; G02 remains the canonical MCP definition.\"},\"tunes\":{}},{\"id\":\"ref-protocol-stack\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fde\u002Fblog\u002Fmcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained\",\"title\":\"MCP vs A2A vs UCP vs AP2 vs A2UI: The Agent Protocol Stack Explained\",\"excerpt\":\"A broader responsibility map showing how MCP composes with agent collaboration, commerce, payment authority and agent-driven UI protocols.\",\"ctaLabel\":\"Read the protocol stack\"},\"tunes\":{}},{\"id\":\"h-transport\",\"type\":\"header\",\"data\":{\"text\":\"Local and remote MCP use different transport realities\",\"level\":2},\"tunes\":{}},{\"id\":\"p-transport-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP can connect to local and remote servers. Local desktop integrations commonly use process-level transports such as stdio; remote servers use HTTP-oriented transport.\"},\"tunes\":{}},{\"id\":\"p-transport-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The 2026-07-28 revision makes the protocol core stateless. Requests carry the information needed for protocol handling instead of depending on the earlier protocol-level session model.\"},\"tunes\":{}},{\"id\":\"p-transport-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The current revision also places method and capability names in HTTP headers so gateways, WAFs, rate limiters and load balancers can route and meter MCP traffic more naturally.\"},\"tunes\":{}},{\"id\":\"h-version\",\"type\":\"header\",\"data\":{\"text\":\"Why MCP version awareness matters\",\"level\":2},\"tunes\":{}},{\"id\":\"version-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Protocol era\",\"Operational characteristic\"],[\"2025-11-25 and earlier\",\"Handshake\u002Fsession-oriented lifecycle and older Streamable HTTP behavior\"],[\"2026-07-28\",\"Stateless core, optional server discovery, self-describing requests, routing headers, cache hints, MRTR and authorization hardening\"],[\"Extensions\",\"Capabilities such as Tasks and MCP Apps can version separately from the base protocol\"]]},\"tunes\":{}},{\"id\":\"p-version-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"SDK version and protocol version are also different things. The current TypeScript v2 SDK is the stable line for the 2026-07-28 revision, while older v1.x remains a maintenance line for 2025-era behavior.\"},\"tunes\":{}},{\"id\":\"p-version-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Architecture documentation should record both the SDK\u002Flibrary version and the protocol revision where interoperability behavior depends on them.\"},\"tunes\":{}},{\"id\":\"h-modern\",\"type\":\"header\",\"data\":{\"text\":\"What changed in MCP 2026-07-28\",\"level\":2},\"tunes\":{}},{\"id\":\"modern-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Change\",\"Why it matters\"],[\"Stateless core\",\"Remote servers can scale behind ordinary load balancers without protocol-level sticky sessions\"],[\"server\u002Fdiscover\",\"Clients can inspect server capabilities when needed\"],[\"Self-describing requests\",\"Protocol version and client capability metadata travel per request\"],[\"Mcp-Method \u002F Mcp-Name headers\",\"Gateways can route, meter and apply policy without parsing bodies\"],[\"Cache hints\",\"Lists\u002Fresource reads communicate freshness and sharing scope\"],[\"Multi Round-Trip Requests\",\"Servers can require additional input without the older bidirectional request model\"],[\"Authorization hardening\",\"Issuer validation and credential binding strengthen remote auth behavior\"],[\"Extensions framework\",\"Tasks, MCP Apps and other capabilities can evolve separately\"]]},\"tunes\":{}},{\"id\":\"h-deprecations\",\"type\":\"header\",\"data\":{\"text\":\"Roots, sampling and logging are no longer the direction for new implementations\",\"level\":2},\"tunes\":{}},{\"id\":\"p-dep-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The 2026-07-28 release marks roots, sampling and logging as deprecated protocol capabilities with a defined compatibility window.\"},\"tunes\":{}},{\"id\":\"p-dep-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Older tutorials may still show these features as central primitives. New implementation work should follow the current specification rather than copy older lifecycle diagrams blindly.\"},\"tunes\":{}},{\"id\":\"p-dep-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Deprecation does not mean immediate removal. It means new systems should avoid unnecessary new dependencies on capabilities the protocol is moving away from.\"},\"tunes\":{}},{\"id\":\"h-tasks\",\"type\":\"header\",\"data\":{\"text\":\"Long-running work is not the same as ordinary MCP tool invocation\",\"level\":2},\"tunes\":{}},{\"id\":\"p-task-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Long-running operations need lifecycle semantics beyond a simple immediate tool result. In the current ecosystem, Tasks moved into a dedicated MCP extension.\"},\"tunes\":{}},{\"id\":\"p-task-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"This reinforces a useful design principle: the base protocol does not need to absorb every agent-runtime concern.\"},\"tunes\":{}},{\"id\":\"p-task-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"An application can also keep long-running workflow ownership entirely in its own runtime and use ordinary MCP tools as underlying operations.\"},\"tunes\":{}},{\"id\":\"h-apps\",\"type\":\"header\",\"data\":{\"text\":\"MCP Apps extend UI capability without redefining the core protocol\",\"level\":2},\"tunes\":{}},{\"id\":\"p-apps-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP Apps associate richer interactive UI experiences with MCP tools through the extension model.\"},\"tunes\":{}},{\"id\":\"p-apps-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The host still controls how that UI is embedded, sandboxed and secured.\"},\"tunes\":{}},{\"id\":\"p-apps-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Core capability exchange and UI rendering should therefore remain separate architecture responsibilities.\"},\"tunes\":{}},{\"id\":\"h-auth\",\"type\":\"header\",\"data\":{\"text\":\"MCP authorization is not your complete authorization model\",\"level\":2},\"tunes\":{}},{\"id\":\"p-auth-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Remote MCP needs protocol-level authentication and authorization mechanisms so clients and servers can establish trusted access. The current specification continues to harden OAuth\u002FOIDC-related behavior.\"},\"tunes\":{}},{\"id\":\"p-auth-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"That layer answers whether a client is allowed to connect or request protocol scopes. It does not automatically answer whether Alice may refund order 123, whether an agent may write production configuration or whether Tenant A may read Tenant B data.\"},\"tunes\":{}},{\"id\":\"p-auth-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Those domain decisions belong in the server\u002Fapplication authorization model and must be enforced before invoking the underlying operation.\"},\"tunes\":{}},{\"id\":\"auth-rule\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Never map “authenticated MCP client” to “trusted for every tool”\",\"body\":\"Connection trust, tool visibility, tool permission, user authorization, tenant isolation and business approval are different controls. Keep them separate.\"},\"tunes\":{}},{\"id\":\"h-identity\",\"type\":\"header\",\"data\":{\"text\":\"Identity can cross several boundaries\",\"level\":2},\"tunes\":{}},{\"id\":\"p-id-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An MCP request may involve the MCP client application, the signed-in human, an agent\u002Fsession identity and a downstream service account.\"},\"tunes\":{}},{\"id\":\"p-id-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The server needs an explicit policy for which principal the operation is performed on behalf of. Otherwise a powerful service credential can become a confused-deputy path.\"},\"tunes\":{}},{\"id\":\"p-id-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"For enterprise use, correlation between user identity, agent identity, MCP connection and downstream authorization is as important as protocol compatibility.\"},\"tunes\":{}},{\"id\":\"h-tenant\",\"type\":\"header\",\"data\":{\"text\":\"Tenant isolation remains outside MCP capability discovery\",\"level\":2},\"tunes\":{}},{\"id\":\"p-tenant-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A multi-tenant MCP server must apply tenant scope when it reads or changes tenant-owned resources. Returning a tool named search_documents does not define which tenant's documents are eligible.\"},\"tunes\":{}},{\"id\":\"p-tenant-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Tenant scope should be derived from trusted identity or membership and carried into databases, caches, vector search, object storage and downstream APIs.\"},\"tunes\":{}},{\"id\":\"p-tenant-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Retrieving cross-tenant content and asking the model not to use it is already an isolation failure.\"},\"tunes\":{}},{\"id\":\"h-source\",\"type\":\"header\",\"data\":{\"text\":\"MCP does not define Source of Truth\",\"level\":2},\"tunes\":{}},{\"id\":\"p-source-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An MCP server can expose a database, document repository, web search service or AI-generated summary. The protocol does not declare which source is authoritative for a claim.\"},\"tunes\":{}},{\"id\":\"p-source-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Source-of-Truth rules belong to application\u002Fdomain architecture. The host or server can encode authority through tool design, metadata, access policy or validation, but MCP itself does not make one capability “true.”\"},\"tunes\":{}},{\"id\":\"p-source-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"A tool can therefore be perfectly callable through MCP and still return stale, secondary or non-authoritative information.\"},\"tunes\":{}},{\"id\":\"h-context\",\"type\":\"header\",\"data\":{\"text\":\"MCP and context engineering\",\"level\":2},\"tunes\":{}},{\"id\":\"p-context-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP can increase the capabilities and information available to an AI application, but context engineering still determines what reaches the model.\"},\"tunes\":{}},{\"id\":\"p-context-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Tool catalogs consume model-visible context in many hosts. Tool results can be large. Resources can be numerous. A host needs selection, filtering, dynamic loading and compaction rather than exposing everything on every turn.\"},\"tunes\":{}},{\"id\":\"p-context-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Capability availability and model-visible context should therefore be treated as separate layers.\"},\"tunes\":{}},{\"id\":\"h-tool-design\",\"type\":\"header\",\"data\":{\"text\":\"Design MCP tools around outcomes and risk boundaries\",\"level\":2},\"tunes\":{}},{\"id\":\"tool-design-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Weak tool design\",\"Stronger tool design\"],[\"execute_api(method,url,body)\",\"Narrow domain tools with validated operations\"],[\"One admin tool for all actions\",\"Separate read\u002Fwrite\u002Fapproval operations\"],[\"Raw internal API mirrored 1:1\",\"AI-facing contract around coherent user goals\"],[\"One broad filesystem tool\",\"Workspace-scoped read\u002Fwrite operations\"],[\"Security policy only in description\",\"Server enforces policy in code\"],[\"Unbounded raw response\",\"Structured decision-relevant output\"],[\"Delete\u002Fupdate mixed with read\",\"Separate side-effect tools with confirmation policy\"]]},\"tunes\":{}},{\"id\":\"h-approvals\",\"type\":\"header\",\"data\":{\"text\":\"Approvals belong in the execution architecture\",\"level\":2},\"tunes\":{}},{\"id\":\"p-approve-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A host can require user approval before invoking selected MCP tools. OpenAI's current MCP integration supports automatic or explicit-approval execution patterns.\"},\"tunes\":{}},{\"id\":\"p-approve-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Host approval is useful but should not be the server's only protection because another compatible MCP client may use a different approval model.\"},\"tunes\":{}},{\"id\":\"p-approve-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"For destructive or financially consequential actions, use defense in depth: clear tool contract, runtime approval where appropriate, server-side authorization, business validation and audit.\"},\"tunes\":{}},{\"id\":\"h-observability\",\"type\":\"header\",\"data\":{\"text\":\"MCP observability should connect protocol calls to domain actions\",\"level\":2},\"tunes\":{}},{\"id\":\"p-obs-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An MCP trace is most useful when it can be correlated with the underlying application call, database change or business transaction.\"},\"tunes\":{}},{\"id\":\"p-obs-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The 2026-07-28 ecosystem standardizes W3C Trace Context propagation conventions, making it easier to follow a request across host, client, server and downstream services.\"},\"tunes\":{}},{\"id\":\"p-obs-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Protocol logs alone are not enough for consequential operations. Audit evidence should also record relevant principal, tenant, target resource, approval and resulting state change.\"},\"tunes\":{}},{\"id\":\"h-failure\",\"type\":\"header\",\"data\":{\"text\":\"What MCP cannot fix\",\"level\":2},\"tunes\":{}},{\"id\":\"failure-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Problem\",\"Why MCP does not solve it\"],[\"Bad business API\",\"MCP can expose the bad API more consistently\"],[\"Wrong data\",\"Protocol validity does not create factual correctness\"],[\"Missing tenant isolation\",\"Tool discovery does not enforce resource ownership\"],[\"Excessive privileges\",\"A standardized tool can still be overprivileged\"],[\"Poor agent planning\",\"MCP exposes capabilities; runtime\u002Fmodel still chooses how to use them\"],[\"Bad retry\u002Fidempotency design\",\"Protocol calls do not make side effects safe\"],[\"No Source of Truth\",\"MCP does not decide which system owns a fact\"],[\"Weak evaluation\",\"Interoperability does not prove task success\"],[\"No audit policy\",\"Transport traces do not define retention or accountability\"],[\"Protocol mismatch\",\"Old\u002Fnew versions can still require migration or compatibility handling\"]]},\"tunes\":{}},{\"id\":\"h-implementation\",\"type\":\"header\",\"data\":{\"text\":\"Original implementation evidence: Aaasaasa AI Client\",\"level\":2},\"tunes\":{}},{\"id\":\"impl-note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Implementation evidence\",\"body\":\"Aaasaasa AI Client contains an authenticated local MCP connector\u002Fbroker for approved local directories and integration through Secure MCP Tunnel. This is concrete implementation evidence for the protocol boundary and permission architecture, not a claim of a general-purpose commercial MCP platform.\"},\"tunes\":{}},{\"id\":\"p-impl-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The application can run an authenticated Streamable HTTP MCP endpoint on loopback. The endpoint exposes only directories selected through the central workspace permission broker.\"},\"tunes\":{}},{\"id\":\"p-impl-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The local endpoint and remote route are separate concerns: the local connector can bind only to loopback, while a Secure MCP Tunnel can make the approved MCP service reachable to a permitted external AI client without exposing the whole local machine.\"},\"tunes\":{}},{\"id\":\"p-impl-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The central permission model distinguishes chat-only, read-only, project-write and custom-directory profiles. Direct Chat has no filesystem or shell access; tool-capable agent runtimes use the selected permission profile.\"},\"tunes\":{}},{\"id\":\"p-impl-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"This is a direct implementation of the G02 boundary: MCP provides the standardized capability connection, while the application-owned permission broker decides which directories the server may expose.\"},\"tunes\":{}},{\"id\":\"impl-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Implemented element\",\"Architecture evidence\"],[\"Authenticated local MCP endpoint\",\"MCP server can be a local deterministic capability service\"],[\"Loopback binding\",\"Network exposure and protocol capability are separate decisions\"],[\"Secure MCP Tunnel integration\",\"Private\u002Flocal MCP can be bridged through a controlled route\"],[\"Central permission broker\",\"MCP capability is constrained by application policy\"],[\"Selected directory scope\",\"Filesystem visibility is explicitly bounded\"],[\"Direct Chat without OS tools\",\"Model access does not automatically imply tool access\"]]},\"tunes\":{}},{\"id\":\"impl-boundary\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Evidence boundary\",\"body\":\"The implementation demonstrates MCP connectivity and permission-scoped local directory exposure. It does not imply that every MCP primitive, every 2026-07-28 feature or every enterprise authorization extension is implemented.\"},\"tunes\":{}},{\"id\":\"h-use\",\"type\":\"header\",\"data\":{\"text\":\"When MCP is a good fit\",\"level\":2},\"tunes\":{}},{\"id\":\"use-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"MCP is a strong fit when\",\"A direct integration may be simpler when\"],[\"The same capability should be reusable across multiple AI hosts\",\"One application owns both sides and portability has little value\"],[\"An external system wants to publish discoverable AI-facing tools\u002Fresources\",\"A single stable internal API call is sufficient\"],[\"You want a standard boundary around local tools\u002Fdata\",\"There is no AI-facing interoperability requirement\"],[\"Tool providers and AI clients evolve independently\",\"The integration is intentionally private and tightly coupled\"],[\"You want ecosystem-compatible capability discovery\",\"The capability set is tiny and fixed in application code\"]]},\"tunes\":{}},{\"id\":\"h-not-need\",\"type\":\"header\",\"data\":{\"text\":\"When you do not need MCP\",\"level\":2},\"tunes\":{}},{\"id\":\"p-not-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Do not add MCP merely because the application uses AI. If your backend already calls one internal API and no independent MCP client needs that capability, an ordinary function or service call may be clearer.\"},\"tunes\":{}},{\"id\":\"p-not-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP adds value at an interoperability boundary. Without that boundary, the protocol can become an unnecessary adapter layer.\"},\"tunes\":{}},{\"id\":\"p-not-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architectural question is not “Does this project have AI?” but “Do independently evolving AI hosts and capability providers benefit from a standard contract?”\"},\"tunes\":{}},{\"id\":\"h-security\",\"type\":\"header\",\"data\":{\"text\":\"MCP security checklist\",\"level\":2},\"tunes\":{}},{\"id\":\"security-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Boundary\",\"Question\"],[\"Server identity\",\"Which MCP server am I actually connected to?\"],[\"Client identity\",\"Which application\u002Fclient is requesting access?\"],[\"End-user identity\",\"On whose behalf is the operation performed?\"],[\"Tool allowlist\",\"Which capabilities may this host\u002Fagent discover and call?\"],[\"Business permission\",\"May this principal perform this operation?\"],[\"Tenant scope\",\"Which tenant\u002Fresource boundary applies?\"],[\"Credential isolation\",\"Are credentials bound correctly and kept outside model context?\"],[\"Approval\",\"Which side effects require human confirmation?\"],[\"Input validation\",\"Are tool arguments validated independently of model output?\"],[\"Output trust\",\"Can returned content contain untrusted instructions or sensitive data?\"],[\"Network exposure\",\"Is a local server accidentally exposed beyond intended interfaces?\"],[\"Audit\",\"Can a protocol call be correlated with the downstream action?\"]]},\"tunes\":{}},{\"id\":\"h-misconceptions\",\"type\":\"header\",\"data\":{\"text\":\"Common misconceptions\",\"level\":2},\"tunes\":{}},{\"id\":\"misconceptions-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Misconception\",\"Correction\"],[\"“An MCP server is an AI server.”\",\"It can be ordinary deterministic software exposing capabilities.\"],[\"“I need my own LLM on the MCP server.”\",\"No. The model can live entirely on the host side.\"],[\"“MCP replaces REST APIs.”\",\"MCP often wraps existing APIs for AI-facing interoperability.\"],[\"“MCP is an agent framework.”\",\"MCP supplies capabilities; an agent runtime manages iteration and state.\"],[\"“MCP and function calling compete.”\",\"A host can bridge MCP capabilities into its model tool interface.\"],[\"“MCP replaces A2A.”\",\"MCP focuses on capability integration; A2A focuses on agent collaboration.\"],[\"“If a tool is listed, the user may call it.”\",\"Discovery is not authorization.\"],[\"“OAuth solves business permissions.”\",\"Connection authorization does not replace domain authorization or tenant isolation.\"],[\"“Local MCP means local AI.”\",\"Tool-server location and inference location are independent.\"],[\"“MCP makes tool output trustworthy.”\",\"Data quality, authority and provenance still belong to the source\u002Fapplication.\"],[\"“One giant generic tool is flexible.”\",\"Over-broad tools weaken permissions, validation and observability.\"],[\"“Old tutorials are implementation-current.”\",\"The 2026-07-28 revision materially changed lifecycle and transport behavior.\"]]},\"tunes\":{}},{\"id\":\"h-design\",\"type\":\"header\",\"data\":{\"text\":\"A practical MCP design sequence\",\"level\":2},\"tunes\":{}},{\"id\":\"design-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"Design the boundary before implementing the server\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Identify the interoperability boundary\",\"description\":\"Confirm that independent AI hosts actually need reusable access.\"},{\"label\":\"2. Keep the domain API authoritative\",\"description\":\"Preserve the real application\u002Fservice contract behind MCP.\"},{\"label\":\"3. Choose primitives deliberately\",\"description\":\"Use tools, resources and prompts according to their semantics.\"},{\"label\":\"4. Split by risk and permission\",\"description\":\"Separate read, write, destructive and approval-required operations.\"},{\"label\":\"5. Define identity propagation\",\"description\":\"Know which client, user, agent and downstream principal each call represents.\"},{\"label\":\"6. Enforce business authorization\",\"description\":\"Validate permissions, tenant scope and target ownership.\"},{\"label\":\"7. Choose local or remote transport\",\"description\":\"Match deployment topology to the real need.\"},{\"label\":\"8. Pin protocol\u002FSDK expectations\",\"description\":\"Document 2026-07-28 versus older compatibility.\"},{\"label\":\"9. Add approvals for consequential actions\",\"description\":\"Use risk-appropriate confirmation controls.\"},{\"label\":\"10. Design structured outputs\",\"description\":\"Return concise machine-usable results.\"},{\"label\":\"11. Add tracing and audit correlation\",\"description\":\"Connect MCP calls to downstream service\u002Fbusiness events.\"},{\"label\":\"12. Test portability\",\"description\":\"Verify more than one client where interoperability is a stated requirement.\"}]},\"tunes\":{}},{\"id\":\"h-checklist\",\"type\":\"header\",\"data\":{\"text\":\"MCP architecture checklist\",\"level\":2},\"tunes\":{}},{\"id\":\"checklist-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Question\",\"Expected answer\"],[\"Why is MCP needed?\",\"A real AI-facing interoperability boundary\"],[\"What does the server expose?\",\"Explicit tools\u002Fresources\u002Fprompts\"],[\"Where does the model run?\",\"Independent host\u002Fprovider decision\"],[\"Where does tool execution run?\",\"Named server\u002Fruntime location\"],[\"Which protocol revision is expected?\",\"Version-aware contract\"],[\"Who is the requesting principal?\",\"Client\u002Fuser\u002Fagent identity model\"],[\"Which tools may be discovered?\",\"Allowlist\u002Fcapability policy\"],[\"Which operations may execute?\",\"Server-side business authorization\"],[\"How is tenant\u002Fresource scope enforced?\",\"Trusted tenant\u002Fresource ownership checks\"],[\"Which actions need approval?\",\"Risk-based confirmation policy\"],[\"How are credentials protected?\",\"Trusted runtime storage, not model-visible secrets\"],[\"How is output bounded?\",\"Structured relevant result contract\"],[\"How are calls traced?\",\"Correlation through MCP to downstream action\"],[\"What happens if MCP is unavailable?\",\"Defined fallback\u002Ffailure behavior\"],[\"Can another compatible host use it?\",\"Portability validated where required\"]]},\"tunes\":{}},{\"id\":\"h-edge\",\"type\":\"header\",\"data\":{\"text\":\"Edge cases and limitations\",\"level\":2},\"tunes\":{}},{\"id\":\"p-edge-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A local stdio MCP server can have little network exposure while still be dangerous if the process itself has excessive filesystem or shell permissions.\"},\"tunes\":{}},{\"id\":\"p-edge-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A remote MCP server may expose only public documentation or highly sensitive enterprise actions. “Remote MCP” says little about risk without the capability and authorization context.\"},\"tunes\":{}},{\"id\":\"p-edge-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Some servers may use only tools and ignore resources\u002Fprompts. MCP compatibility does not require every optional primitive to be equally important.\"},\"tunes\":{}},{\"id\":\"p-edge-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"A host can translate between its own internal tool model and MCP. Users may never see the protocol boundary directly, which is acceptable if security and attribution remain clear.\"},\"tunes\":{}},{\"id\":\"p-edge-5\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP continues to evolve rapidly. Extensions, authorization patterns, SDK APIs and ecosystem conventions can change faster than the core architectural distinction.\"},\"tunes\":{}},{\"id\":\"h-change\",\"type\":\"header\",\"data\":{\"text\":\"What would change this answer?\",\"level\":2},\"tunes\":{}},{\"id\":\"p-change-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Future MCP revisions can change lifecycle, transports, authorization and extension mechanisms. The July 2026 revision already demonstrates why implementation-specific claims must be dated.\"},\"tunes\":{}},{\"id\":\"p-change-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The canonical boundary would change only if MCP expanded from an interoperability protocol into an end-to-end application\u002Fagent architecture standard. That is not what the current protocol defines.\"},\"tunes\":{}},{\"id\":\"p-change-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"For implementation work, always check the current specification and exact SDK line instead of copying version-sensitive examples from older tutorials.\"},\"tunes\":{}},{\"id\":\"h-related\",\"type\":\"header\",\"data\":{\"text\":\"Related canonical knowledge\",\"level\":2},\"tunes\":{}},{\"id\":\"p-related-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP belongs downstream of Agentic AI: first understand the agent\u002Fruntime\u002Ftool boundary, then use MCP when external capabilities need a portable protocol contract.\"},\"tunes\":{}},{\"id\":\"p-related-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP also depends on RBAC and tenant isolation because protocol-level capability exposure does not determine application authorization.\"},\"tunes\":{}},{\"id\":\"p-related-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The broader protocol-stack article explains where MCP sits beside A2A, UCP, AP2 and A2UI. G02 remains the canonical source for MCP itself.\"},\"tunes\":{}},{\"id\":\"ref-reliability\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fai-agent-reliability-why-the-final-answer-is-not-enough\",\"title\":\"AI Agent Reliability: Why the Final Answer Is Not Enough\",\"excerpt\":\"MCP tool calls become part of an agent trajectory; reliable systems need to evaluate actions and observations, not only final text.\",\"ctaLabel\":\"Read the agent reliability article\"},\"tunes\":{}},{\"id\":\"h-faq\",\"type\":\"header\",\"data\":{\"text\":\"Frequently asked questions\",\"level\":2},\"tunes\":{}},{\"id\":\"faq\",\"type\":\"faq\",\"data\":{\"title\":\"Model Context Protocol FAQ\",\"items\":[{\"id\":\"faq1\",\"question\":\"What is MCP?\",\"answer\":\"The Model Context Protocol is an open client-server protocol for connecting AI applications to external tools, resources, prompts and capability providers through a standardized contract.\"},{\"id\":\"faq2\",\"question\":\"Does an MCP server need an AI model?\",\"answer\":\"No. An MCP server can be completely deterministic software. The model normally runs in the AI host or agent runtime, although a server may optionally use AI internally.\"},{\"id\":\"faq3\",\"question\":\"What is the difference between an MCP client and server?\",\"answer\":\"The client is the protocol component used by an AI host to communicate with capability providers. The server publishes and executes the capabilities it exposes.\"},{\"id\":\"faq4\",\"question\":\"Does MCP replace function calling?\",\"answer\":\"No. Function\u002Ftool calling is how a model invokes configured capabilities. MCP standardizes discovery and communication with external capability servers. A host can bridge the two.\"},{\"id\":\"faq5\",\"question\":\"Does MCP replace REST APIs?\",\"answer\":\"No. MCP servers frequently wrap existing REST, GraphQL, database or service APIs and provide an AI-facing interoperability layer.\"},{\"id\":\"faq6\",\"question\":\"Is MCP an agent framework?\",\"answer\":\"No. MCP exposes capabilities. Agent planning, state, memory, context management, retries, orchestration and stopping belong to the surrounding runtime.\"},{\"id\":\"faq7\",\"question\":\"What is the difference between MCP and A2A?\",\"answer\":\"MCP primarily connects an AI host or agent to tools and data providers. A2A connects independent agent systems for collaboration and delegation.\"},{\"id\":\"faq8\",\"question\":\"Does MCP handle authorization?\",\"answer\":\"MCP includes protocol-level authorization mechanisms, especially for remote servers, but the application must still enforce business permissions, resource ownership and tenant isolation.\"},{\"id\":\"faq9\",\"question\":\"Can MCP work with local models?\",\"answer\":\"Yes. Model location is independent of MCP. A local-model host can call local or remote MCP servers, and a cloud-model host can use approved local or remote MCP servers through an appropriate connection architecture.\"},{\"id\":\"faq10\",\"question\":\"What is the current MCP specification version?\",\"answer\":\"As of 8 October 2026, the current specification revision is 2026-07-28. Older 2025-era implementations remain in use, so compatibility must be checked.\"}]},\"tunes\":{}},{\"id\":\"h-glossary\",\"type\":\"header\",\"data\":{\"text\":\"Glossary\",\"level\":2},\"tunes\":{}},{\"id\":\"glossary\",\"type\":\"glossary\",\"data\":{\"title\":\"Key MCP terms\",\"entries\":[{\"term\":\"MCP\",\"definition\":\"Model Context Protocol, an open protocol for interoperable connections between AI hosts\u002Fclients and external capability servers.\",\"anchor\":\"mcp\"},{\"term\":\"MCP host\",\"definition\":\"The AI application or runtime that owns model interaction and uses MCP clients to connect to servers.\",\"anchor\":\"mcp-host\"},{\"term\":\"MCP client\",\"definition\":\"Protocol component on the host side that communicates with an MCP server.\",\"anchor\":\"mcp-client\"},{\"term\":\"MCP server\",\"definition\":\"Capability provider that implements MCP and exposes tools, resources, prompts or supported extensions.\",\"anchor\":\"mcp-server\"},{\"term\":\"Tool\",\"definition\":\"Callable structured capability exposed by an MCP server.\",\"anchor\":\"mcp-tool\"},{\"term\":\"Resource\",\"definition\":\"Readable data or content exposed through MCP resource methods.\",\"anchor\":\"mcp-resource\"},{\"term\":\"Prompt\",\"definition\":\"Reusable prompt template exposed by an MCP server for compatible hosts.\",\"anchor\":\"mcp-prompt\"},{\"term\":\"Streamable HTTP\",\"definition\":\"HTTP-oriented MCP transport used for remote\u002Fnetworked server communication.\",\"anchor\":\"streamable-http\"},{\"term\":\"stdio\",\"definition\":\"Process standard-input\u002Foutput transport commonly used for local MCP server integrations.\",\"anchor\":\"stdio\"},{\"term\":\"server\u002Fdiscover\",\"definition\":\"Modern MCP method that lets a client inspect server capabilities in the 2026-07-28 protocol era.\",\"anchor\":\"server-discover\"},{\"term\":\"MRTR\",\"definition\":\"Multi Round-Trip Requests, a mechanism for obtaining additional input during a request in the 2026-07-28 protocol era.\",\"anchor\":\"mrtr\"},{\"term\":\"MCP extension\",\"definition\":\"Capability that composes with the base protocol and can evolve\u002Fversion separately, such as Tasks or MCP Apps.\",\"anchor\":\"mcp-extension\"}]},\"tunes\":{}},{\"id\":\"h-conclusion\",\"type\":\"header\",\"data\":{\"text\":\"Conclusion\",\"level\":2},\"tunes\":{}},{\"id\":\"p-conclusion-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP is easiest to understand when its boundary stays narrow: it connects AI applications to external capabilities through a standard protocol.\"},\"tunes\":{}},{\"id\":\"p-conclusion-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The model does not have to live on the MCP server. The server does not become the agent runtime. A listed tool does not become an authorized business action. And MCP does not replace the underlying API, Source of Truth, tenant isolation or domain architecture.\"},\"tunes\":{}},{\"id\":\"p-conclusion-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"That narrowness is the protocol's strength. MCP can standardize how AI systems reach tools and data while leaving application ownership, security, business semantics and model choice in the layers that actually own them.\"},\"tunes\":{}},{\"id\":\"h-sources\",\"type\":\"header\",\"data\":{\"text\":\"Primary sources and current documentation\",\"level\":2},\"tunes\":{}},{\"id\":\"p-sources-note\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP is evolving quickly, so version-sensitive claims in this article are tied to the 8 October 2026 state. The Aaasaasa AI Client section is original implementation evidence and is explicitly limited to the verified MCP connector and permission-broker scope.\"},\"tunes\":{}},{\"id\":\"src-mcp-ts\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fts.sdk.modelcontextprotocol.io\u002Fv2\u002F\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Model Context Protocol — TypeScript SDK v2\",\"description\":\"Current stable TypeScript SDK documentation implementing the 2026-07-28 MCP specification and server\u002Fclient primitives.\"}},\"tunes\":{}},{\"id\":\"src-mcp-release\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fblog.modelcontextprotocol.io\u002Fposts\u002F2026-07-28\u002F\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Model Context Protocol — 2026-07-28 Specification Release\",\"description\":\"Official release explanation for the current MCP protocol revision, including stateless core, MRTR, routing, caching, authorization hardening, extensions and deprecations.\"}},\"tunes\":{}},{\"id\":\"src-mcp-migration\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fts.sdk.modelcontextprotocol.io\u002Fv2\u002Fmigration\u002Fsupport-2026-07-28\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"MCP TypeScript SDK — Supporting protocol revision 2026-07-28\",\"description\":\"Version-specific implementation guidance for the current protocol revision and earlier-era compatibility.\"}},\"tunes\":{}},{\"id\":\"src-openai-mcp\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Ftools-connectors-mcp\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — MCP servers\",\"description\":\"Current OpenAI guidance for connecting models to remote MCP servers and local\u002Fprivate MCP servers through Secure MCP Tunnel.\"}},\"tunes\":{}},{\"id\":\"src-openai-agent-mcp\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents-api\u002Ftools\u002Fmcp\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — MCP connections for Agents API\",\"description\":\"Current MCP connection guidance covering service, environment and stdio locations plus allowed-tool controls.\"}},\"tunes\":{}},{\"id\":\"src-openai-tools\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Ftools\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — Tools\",\"description\":\"Current overview placing remote MCP servers alongside function calling, web search, shell and other model tools.\"}},\"tunes\":{}},{\"id\":\"src-openai-plugin-mcp\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fplugins\u002Fconcepts\u002Fmcp-server\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — MCP server concept\",\"description\":\"Current description of MCP servers exposing tools, resources and prompts for external service integrations.\"}},\"tunes\":{}}],\"version\":\"2.31.6\"}",{"time":212,"blocks":213,"version":1609},1791486641380,[214,220,228,235,242,249,257,262,267,272,277,282,287,292,297,326,331,336,341,346,351,378,383,388,393,427,432,437,442,447,452,457,462,467,472,477,482,487,492,517,522,527,532,537,543,548,553,558,563,568,597,602,607,612,617,622,627,632,637,642,651,656,661,666,671,676,693,698,703,708,740,745,750,755,760,765,770,775,780,785,790,795,800,805,810,815,820,826,831,836,841,846,851,856,861,866,871,876,881,886,891,896,901,906,911,940,945,950,955,960,965,970,975,980,985,1023,1028,1034,1039,1044,1049,1054,1080,1086,1091,1114,1119,1124,1129,1134,1139,1183,1188,1232,1237,1279,1284,1336,1341,1346,1351,1356,1361,1366,1371,1376,1381,1386,1391,1396,1401,1406,1414,1419,1465,1470,1515,1520,1525,1530,1535,1540,1545,1555,1564,1573,1582,1591,1600],{"id":215,"data":216,"type":218,"tunes":219},"intro",{"text":217},"The Model Context Protocol (MCP) is an open protocol for connecting AI applications to external capabilities and information through standardized client-server contracts. An MCP server can expose tools, resources and prompts; an MCP-compatible host or client discovers and uses those capabilities on behalf of an AI application. MCP does not require the server to run its own language model, and it does not replace the agent runtime, business authorization, tenant isolation, application APIs or domain architecture behind the exposed capabilities.","paragraph",{},{"id":221,"data":222,"type":226,"tunes":227},"direct",{"body":223,"title":224,"variant":225},"\u003Cstrong>MCP standardizes the boundary between an AI host and external capability providers.\u003C\u002Fstrong>\u003Cbr>\u003Cbr>A useful mental model is:\u003Cbr>\u003Cstrong>User → AI host \u002F agent runtime → MCP client → MCP server → application\u002FAPI\u002Fdata\u002Ftool\u003C\u002Fstrong>.\u003Cbr>\u003Cbr>The model can remain entirely on the host side. The MCP server may be ordinary deterministic software that exposes structured capabilities.","Direct answer","info","callout",{},{"id":229,"data":230,"type":226,"tunes":234},"server-no-ai",{"body":231,"title":232,"variant":233},"A filesystem MCP server can list or read files. A database MCP server can run approved queries. A Jira MCP server can expose issue operations. None of those servers needs an LLM to satisfy the MCP contract. If a server internally uses AI, that is an implementation choice behind the protocol boundary, not an MCP requirement.","An MCP server does not need its own AI model","success",{},{"id":236,"data":237,"type":226,"tunes":241},"boundary",{"body":238,"title":239,"variant":240},"If an MCP server exposes \u003Ccode>delete_file\u003C\u002Fcode>, \u003Ccode>refund_order\u003C\u002Fcode> or \u003Ccode>deploy_service\u003C\u002Fcode>, that only means the capability exists. The server\u002Fapplication must still enforce identity, permissions, tenant scope, business rules, confirmation requirements and audit controls. Protocol discovery must never silently become authorization.","MCP capability is not business authority","warning",{},{"id":243,"data":244,"type":226,"tunes":248},"current",{"body":245,"title":246,"variant":247},"The current MCP specification revision is \u003Cstrong>2026-07-28\u003C\u002Fstrong>. Its major change is a stateless protocol core with self-describing requests, optional \u003Ccode>server\u002Fdiscover\u003C\u002Fcode>, routable HTTP headers, cacheable list\u002Fresource responses, authorization hardening and a formal extension model. The TypeScript SDK v2 is the current stable SDK line implementing this revision. Older 2025-era clients and servers still exist, so implementation guidance must remain version-aware.","Current-source note — 8 October 2026","note",{},{"id":250,"data":251,"type":255,"tunes":256},"toc",{"title":252,"maxLevel":253,"minLevel":254},"Contents",3,2,"tableOfContents",{},{"id":258,"data":259,"type":42,"tunes":261},"h-meaning",{"text":260,"level":254},"What MCP really standardizes",{},{"id":263,"data":264,"type":218,"tunes":266},"p-meaning-1",{"text":265},"Before MCP, every AI application could integrate external systems through its own tool schema, plugin format, authentication convention and connection code. The same service could need different adapters for a desktop AI client, an IDE agent and a custom application.",{},{"id":268,"data":269,"type":218,"tunes":271},"p-meaning-2",{"text":270},"MCP creates a reusable protocol boundary. The external system exposes capabilities through an MCP server, while compatible AI hosts implement an MCP client. This reduces integration coupling between the AI application and the underlying tool or data provider.",{},{"id":273,"data":274,"type":218,"tunes":276},"p-meaning-3",{"text":275},"The protocol does not standardize the entire application. It standardizes how capabilities are described, discovered and invoked across that boundary.",{},{"id":278,"data":279,"type":42,"tunes":281},"h-simple",{"text":280,"level":254},"The simplest example",{},{"id":283,"data":284,"type":218,"tunes":286},"p-simple-1",{"text":285},"Suppose an AI coding application needs access to a local project directory. Without MCP, the application might implement its own filesystem integration directly.",{},{"id":288,"data":289,"type":218,"tunes":291},"p-simple-2",{"text":290},"With MCP, a filesystem server can expose capabilities such as listing directories, reading approved files or writing inside an allowed workspace. The AI host connects through an MCP client and presents those capabilities to the model or agent runtime.",{},{"id":293,"data":294,"type":218,"tunes":296},"p-simple-3",{"text":295},"The server does not need to understand the user's natural-language request. The host\u002Fmodel decides which capability is useful; the MCP server executes the structured request under its own security rules.",{},{"id":298,"data":299,"type":324,"tunes":325},"simple-flow",{"steps":300,"title":322,"orientation":323},[301,304,307,310,313,316,319],{"label":302,"description":303},"1. Host connects to server","The MCP-capable application configures access to the external MCP server.",{"label":305,"description":306},"2. Capabilities are discovered","The client learns which tools, resources or prompts the server exposes.",{"label":308,"description":309},"3. Model or runtime selects a capability","The AI application decides that one exposed capability is needed.",{"label":311,"description":312},"4. Client sends structured request","Arguments are sent through MCP to the server.",{"label":314,"description":315},"5. Server authorizes and executes","The server validates the request and calls its underlying system.",{"label":317,"description":318},"6. Result returns to host","The result becomes an observation or context input.",{"label":320,"description":321},"7. Host decides what happens next","The model\u002Fruntime may answer, call another tool or continue a workflow.","A basic MCP tool call","auto","processFlow",{},{"id":327,"data":328,"type":42,"tunes":330},"h-stops",{"text":329,"level":254},"Where the simple example stops",{},{"id":332,"data":333,"type":218,"tunes":335},"p-stops-1",{"text":334},"MCP does not define how the host chooses a tool, how an agent plans, how a business workflow is modeled or how a domain object such as an invoice or deployment should behave.",{},{"id":337,"data":338,"type":218,"tunes":340},"p-stops-2",{"text":339},"A protocol can make the integration interoperable while the underlying application remains incorrect, insecure or badly designed. A perfectly valid MCP request can still call the wrong business capability.",{},{"id":342,"data":343,"type":218,"tunes":345},"p-stops-3",{"text":344},"The central boundary is: MCP standardizes integration semantics, not application truth or business correctness.",{},{"id":347,"data":348,"type":42,"tunes":350},"h-architecture",{"text":349,"level":254},"The MCP architecture: host, client and server",{},{"id":352,"data":353,"type":376,"tunes":377},"architecture-table",{"content":354,"stretched":43,"withHeadings":14},[355,358,361,364,367,370,373],[356,357],"Component","Responsibility",[359,360],"AI host","User-facing AI application or runtime that owns model interaction, context and overall workflow",[362,363],"MCP client","Protocol-side component used by the host to communicate with an MCP server",[365,366],"MCP server","Publishes capabilities and handles MCP requests",[368,369],"Underlying system","Application, API, database, filesystem, SaaS platform or service behind the MCP server",[371,372],"Model","Chooses or reasons about capabilities according to the host\u002Fruntime design; it is not necessarily inside the MCP server",[374,375],"Authorization\u002Fbusiness policy","Determines whether a requested operation is actually permitted","table",{},{"id":379,"data":380,"type":218,"tunes":382},"p-architecture-1",{"text":381},"A host can connect to multiple MCP servers, and one MCP server can front one or several underlying systems. The host remains responsible for integrating MCP results into the broader AI application.",{},{"id":384,"data":385,"type":218,"tunes":387},"p-architecture-2",{"text":386},"The server can be local to the host, run as a separate process or be remote over a network transport. Hosting topology and model location are independent decisions.",{},{"id":389,"data":390,"type":42,"tunes":392},"h-primitives",{"text":391,"level":254},"The three core server primitives",{},{"id":394,"data":395,"type":425,"tunes":426},"primitives-comparison",{"rows":396,"title":414,"layout":376,"columns":415},[397,402,406,410],{"id":398,"label":399,"values":400},"purpose","Primary purpose",[401,401,401],"",{"id":403,"label":404,"values":405},"interaction","Typical interaction",[401,401,401],{"id":407,"label":408,"values":409},"example","Example",[401,401,401],{"id":411,"label":412,"values":413},"risk","Typical risk",[401,401,401],"Tools, resources and prompts solve different needs",[416,419,422],{"id":417,"label":418},"tools","Tools",{"id":420,"label":421},"resources","Resources",{"id":423,"label":424},"prompts","Prompts","comparison",{},{"id":428,"data":429,"type":42,"tunes":431},"h-tools",{"text":430,"level":254},"Tools: callable capabilities",{},{"id":433,"data":434,"type":218,"tunes":436},"p-tools-1",{"text":435},"Tools are structured operations an MCP server makes available to the host. A tool has a name, description and input schema; modern implementations can also provide structured output.",{},{"id":438,"data":439,"type":218,"tunes":441},"p-tools-2",{"text":440},"Examples include searching a repository, reading a customer record, creating a ticket, running a build or sending a message. Tools can be read-only or have side effects.",{},{"id":443,"data":444,"type":218,"tunes":446},"p-tools-3",{"text":445},"A good MCP tool surface should represent coherent user or agent goals rather than mechanically mirror every internal API endpoint. Operations with different permissions, confirmation requirements or blast radius should usually be separate tools.",{},{"id":448,"data":449,"type":42,"tunes":451},"h-resources",{"text":450,"level":254},"Resources: readable context and data",{},{"id":453,"data":454,"type":218,"tunes":456},"p-res-1",{"text":455},"Resources expose data or content that a client can list or read. They fit naturally when the semantic operation is “give me this artifact or information” rather than “perform this action.”",{},{"id":458,"data":459,"type":218,"tunes":461},"p-res-2",{"text":460},"A resource URI is not an authorization grant. The server still owns access control and must verify which principal may read the underlying object.",{},{"id":463,"data":464,"type":218,"tunes":466},"p-res-3",{"text":465},"The 2026-07-28 protocol revision adds cache semantics for list and resource-read responses, including freshness and cache scope, making caching behavior more explicit.",{},{"id":468,"data":469,"type":42,"tunes":471},"h-prompts",{"text":470,"level":254},"Prompts: reusable templates",{},{"id":473,"data":474,"type":218,"tunes":476},"p-prompts-1",{"text":475},"MCP prompts let a server publish reusable prompt templates to compatible clients. This can keep domain-specific instructions close to the capability provider.",{},{"id":478,"data":479,"type":218,"tunes":481},"p-prompts-2",{"text":480},"A prompt supplied by an MCP server does not automatically outrank the host's system or security instructions. The host decides how prompt material enters its context hierarchy.",{},{"id":483,"data":484,"type":218,"tunes":486},"p-prompts-3",{"text":485},"Protocol-provided prompt content should therefore be treated as capability data with explicit trust semantics, not as unrestricted instruction authority.",{},{"id":488,"data":489,"type":42,"tunes":491},"h-tool-vs-resource",{"text":490,"level":254},"Tool or resource?",{},{"id":493,"data":494,"type":376,"tunes":516},"tool-resource-table",{"content":495,"stretched":43,"withHeadings":14},[496,499,502,505,508,510,513],[497,498],"Need","Prefer",[500,501],"Perform an action with structured arguments","Tool",[503,504],"Read a specific stable artifact","Resource",[506,507],"Search or calculate dynamically","Usually tool",[509,501],"Modify external state",[511,512],"Package reusable prompt instructions","Prompt",[514,515],"Long-running asynchronous execution","Tool plus application\u002Fruntime task handling or an MCP extension",{},{"id":518,"data":519,"type":42,"tunes":521},"h-model-location",{"text":520,"level":254},"Where is the AI model?",{},{"id":523,"data":524,"type":218,"tunes":526},"p-location-1",{"text":525},"MCP does not require the model to run on the MCP server. The model can be cloud-hosted, locally hosted, embedded in the desktop application or reached through another provider.",{},{"id":528,"data":529,"type":218,"tunes":531},"p-location-2",{"text":530},"The host normally owns the model interaction. The MCP server exposes external capability. A local MCP server can therefore be used by a host whose model runs in the cloud, and a remote MCP server can be used by a host whose model runs locally.",{},{"id":533,"data":534,"type":218,"tunes":536},"p-location-3",{"text":535},"If the MCP server itself calls an LLM internally, that model is part of the server's implementation behind the protocol boundary; it is not required by MCP.",{},{"id":538,"data":539,"type":226,"tunes":542},"location-rule",{"body":540,"title":541,"variant":233},"\u003Cstrong>Local MCP does not imply local inference, and remote MCP does not imply remote inference.\u003C\u002Fstrong> Connection location, tool-execution location and model\u002Fprovider location are separate architecture dimensions.","Protocol location ≠ inference location",{},{"id":544,"data":545,"type":42,"tunes":547},"h-mcp-vs-api",{"text":546,"level":254},"MCP does not replace APIs",{},{"id":549,"data":550,"type":218,"tunes":552},"p-api-1",{"text":551},"An MCP server often wraps existing APIs or services. REST, GraphQL, SQL, SDK calls and internal service contracts can remain exactly where they are.",{},{"id":554,"data":555,"type":218,"tunes":557},"p-api-2",{"text":556},"MCP adds an AI-facing interoperability layer. The underlying domain API can remain the authoritative application contract for ordinary deterministic clients.",{},{"id":559,"data":560,"type":218,"tunes":562},"p-api-3",{"text":561},"The usual architecture is therefore API\u002Fservice first, selected AI-facing capability second — not “replace every API with MCP.”",{},{"id":564,"data":565,"type":42,"tunes":567},"h-function-calling",{"text":566,"level":254},"MCP vs function calling",{},{"id":569,"data":570,"type":425,"tunes":596},"function-comparison",{"rows":571,"title":588,"layout":376,"columns":589},[572,576,580,584],{"id":573,"label":574,"values":575},"scope","Scope",[401,401],{"id":577,"label":578,"values":579},"definition","Tool definition",[401,401],{"id":581,"label":582,"values":583},"portability","Portability",[401,401],{"id":585,"label":586,"values":587},"coexist","Can they coexist?",[401,401],"Function calling and MCP are related but not identical",[590,593],{"id":591,"label":592},"function","Function calling",{"id":594,"label":595},"mcp","MCP",{},{"id":598,"data":599,"type":218,"tunes":601},"p-function-1",{"text":600},"OpenAI currently exposes remote MCP servers as one tool type alongside ordinary function calling, web search, shell and other tools. That implementation illustrates the architectural relationship: MCP connectivity and the model's own tool-call interface can be composed.",{},{"id":603,"data":604,"type":42,"tunes":606},"h-agent",{"text":605,"level":254},"MCP does not create the agent loop",{},{"id":608,"data":609,"type":218,"tunes":611},"p-agent-1",{"text":610},"An AI agent needs a runtime that can decide, invoke tools, observe results, update state and continue or stop. MCP can supply some of the tools and data used by that loop.",{},{"id":613,"data":614,"type":218,"tunes":616},"p-agent-2",{"text":615},"The MCP server does not automatically become the planner, memory system or orchestrator. Those responsibilities normally remain in the host or agent runtime.",{},{"id":618,"data":619,"type":218,"tunes":621},"p-agent-3",{"text":620},"A non-agentic application can also use MCP. One deterministic MCP tool call does not require an autonomous multi-step agent.",{},{"id":623,"data":624,"type":42,"tunes":626},"h-a2a",{"text":625,"level":254},"MCP vs A2A",{},{"id":628,"data":629,"type":218,"tunes":631},"p-a2a-1",{"text":630},"MCP primarily connects an AI host or agent to capabilities such as tools, resources and data. A2A targets collaboration between independent agent systems.",{},{"id":633,"data":634,"type":218,"tunes":636},"p-a2a-2",{"text":635},"A remote agent can internally use MCP to reach databases and tools while exposing an A2A interface to other agents. The protocols can therefore be layered rather than substituted.",{},{"id":638,"data":639,"type":218,"tunes":641},"p-a2a-3",{"text":640},"The existing protocol-stack article owns the broader MCP\u002FA2A\u002FUCP\u002FAP2\u002FA2UI comparison; G02 remains the canonical MCP definition.",{},{"id":643,"data":644,"type":649,"tunes":650},"ref-protocol-stack",{"url":645,"title":646,"excerpt":647,"ctaLabel":648},"https:\u002F\u002Fstajic.de\u002Fde\u002Fblog\u002Fmcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained","MCP vs A2A vs UCP vs AP2 vs A2UI: The Agent Protocol Stack Explained","A broader responsibility map showing how MCP composes with agent collaboration, commerce, payment authority and agent-driven UI protocols.","Read the protocol stack","referralArticle",{},{"id":652,"data":653,"type":42,"tunes":655},"h-transport",{"text":654,"level":254},"Local and remote MCP use different transport realities",{},{"id":657,"data":658,"type":218,"tunes":660},"p-transport-1",{"text":659},"MCP can connect to local and remote servers. Local desktop integrations commonly use process-level transports such as stdio; remote servers use HTTP-oriented transport.",{},{"id":662,"data":663,"type":218,"tunes":665},"p-transport-2",{"text":664},"The 2026-07-28 revision makes the protocol core stateless. Requests carry the information needed for protocol handling instead of depending on the earlier protocol-level session model.",{},{"id":667,"data":668,"type":218,"tunes":670},"p-transport-3",{"text":669},"The current revision also places method and capability names in HTTP headers so gateways, WAFs, rate limiters and load balancers can route and meter MCP traffic more naturally.",{},{"id":672,"data":673,"type":42,"tunes":675},"h-version",{"text":674,"level":254},"Why MCP version awareness matters",{},{"id":677,"data":678,"type":376,"tunes":692},"version-table",{"content":679,"stretched":43,"withHeadings":14},[680,683,686,689],[681,682],"Protocol era","Operational characteristic",[684,685],"2025-11-25 and earlier","Handshake\u002Fsession-oriented lifecycle and older Streamable HTTP behavior",[687,688],"2026-07-28","Stateless core, optional server discovery, self-describing requests, routing headers, cache hints, MRTR and authorization hardening",[690,691],"Extensions","Capabilities such as Tasks and MCP Apps can version separately from the base protocol",{},{"id":694,"data":695,"type":218,"tunes":697},"p-version-1",{"text":696},"SDK version and protocol version are also different things. The current TypeScript v2 SDK is the stable line for the 2026-07-28 revision, while older v1.x remains a maintenance line for 2025-era behavior.",{},{"id":699,"data":700,"type":218,"tunes":702},"p-version-2",{"text":701},"Architecture documentation should record both the SDK\u002Flibrary version and the protocol revision where interoperability behavior depends on them.",{},{"id":704,"data":705,"type":42,"tunes":707},"h-modern",{"text":706,"level":254},"What changed in MCP 2026-07-28",{},{"id":709,"data":710,"type":376,"tunes":739},"modern-table",{"content":711,"stretched":43,"withHeadings":14},[712,715,718,721,724,727,730,733,736],[713,714],"Change","Why it matters",[716,717],"Stateless core","Remote servers can scale behind ordinary load balancers without protocol-level sticky sessions",[719,720],"server\u002Fdiscover","Clients can inspect server capabilities when needed",[722,723],"Self-describing requests","Protocol version and client capability metadata travel per request",[725,726],"Mcp-Method \u002F Mcp-Name headers","Gateways can route, meter and apply policy without parsing bodies",[728,729],"Cache hints","Lists\u002Fresource reads communicate freshness and sharing scope",[731,732],"Multi Round-Trip Requests","Servers can require additional input without the older bidirectional request model",[734,735],"Authorization hardening","Issuer validation and credential binding strengthen remote auth behavior",[737,738],"Extensions framework","Tasks, MCP Apps and other capabilities can evolve separately",{},{"id":741,"data":742,"type":42,"tunes":744},"h-deprecations",{"text":743,"level":254},"Roots, sampling and logging are no longer the direction for new implementations",{},{"id":746,"data":747,"type":218,"tunes":749},"p-dep-1",{"text":748},"The 2026-07-28 release marks roots, sampling and logging as deprecated protocol capabilities with a defined compatibility window.",{},{"id":751,"data":752,"type":218,"tunes":754},"p-dep-2",{"text":753},"Older tutorials may still show these features as central primitives. New implementation work should follow the current specification rather than copy older lifecycle diagrams blindly.",{},{"id":756,"data":757,"type":218,"tunes":759},"p-dep-3",{"text":758},"Deprecation does not mean immediate removal. It means new systems should avoid unnecessary new dependencies on capabilities the protocol is moving away from.",{},{"id":761,"data":762,"type":42,"tunes":764},"h-tasks",{"text":763,"level":254},"Long-running work is not the same as ordinary MCP tool invocation",{},{"id":766,"data":767,"type":218,"tunes":769},"p-task-1",{"text":768},"Long-running operations need lifecycle semantics beyond a simple immediate tool result. In the current ecosystem, Tasks moved into a dedicated MCP extension.",{},{"id":771,"data":772,"type":218,"tunes":774},"p-task-2",{"text":773},"This reinforces a useful design principle: the base protocol does not need to absorb every agent-runtime concern.",{},{"id":776,"data":777,"type":218,"tunes":779},"p-task-3",{"text":778},"An application can also keep long-running workflow ownership entirely in its own runtime and use ordinary MCP tools as underlying operations.",{},{"id":781,"data":782,"type":42,"tunes":784},"h-apps",{"text":783,"level":254},"MCP Apps extend UI capability without redefining the core protocol",{},{"id":786,"data":787,"type":218,"tunes":789},"p-apps-1",{"text":788},"MCP Apps associate richer interactive UI experiences with MCP tools through the extension model.",{},{"id":791,"data":792,"type":218,"tunes":794},"p-apps-2",{"text":793},"The host still controls how that UI is embedded, sandboxed and secured.",{},{"id":796,"data":797,"type":218,"tunes":799},"p-apps-3",{"text":798},"Core capability exchange and UI rendering should therefore remain separate architecture responsibilities.",{},{"id":801,"data":802,"type":42,"tunes":804},"h-auth",{"text":803,"level":254},"MCP authorization is not your complete authorization model",{},{"id":806,"data":807,"type":218,"tunes":809},"p-auth-1",{"text":808},"Remote MCP needs protocol-level authentication and authorization mechanisms so clients and servers can establish trusted access. The current specification continues to harden OAuth\u002FOIDC-related behavior.",{},{"id":811,"data":812,"type":218,"tunes":814},"p-auth-2",{"text":813},"That layer answers whether a client is allowed to connect or request protocol scopes. It does not automatically answer whether Alice may refund order 123, whether an agent may write production configuration or whether Tenant A may read Tenant B data.",{},{"id":816,"data":817,"type":218,"tunes":819},"p-auth-3",{"text":818},"Those domain decisions belong in the server\u002Fapplication authorization model and must be enforced before invoking the underlying operation.",{},{"id":821,"data":822,"type":226,"tunes":825},"auth-rule",{"body":823,"title":824,"variant":240},"Connection trust, tool visibility, tool permission, user authorization, tenant isolation and business approval are different controls. Keep them separate.","Never map “authenticated MCP client” to “trusted for every tool”",{},{"id":827,"data":828,"type":42,"tunes":830},"h-identity",{"text":829,"level":254},"Identity can cross several boundaries",{},{"id":832,"data":833,"type":218,"tunes":835},"p-id-1",{"text":834},"An MCP request may involve the MCP client application, the signed-in human, an agent\u002Fsession identity and a downstream service account.",{},{"id":837,"data":838,"type":218,"tunes":840},"p-id-2",{"text":839},"The server needs an explicit policy for which principal the operation is performed on behalf of. Otherwise a powerful service credential can become a confused-deputy path.",{},{"id":842,"data":843,"type":218,"tunes":845},"p-id-3",{"text":844},"For enterprise use, correlation between user identity, agent identity, MCP connection and downstream authorization is as important as protocol compatibility.",{},{"id":847,"data":848,"type":42,"tunes":850},"h-tenant",{"text":849,"level":254},"Tenant isolation remains outside MCP capability discovery",{},{"id":852,"data":853,"type":218,"tunes":855},"p-tenant-1",{"text":854},"A multi-tenant MCP server must apply tenant scope when it reads or changes tenant-owned resources. Returning a tool named search_documents does not define which tenant's documents are eligible.",{},{"id":857,"data":858,"type":218,"tunes":860},"p-tenant-2",{"text":859},"Tenant scope should be derived from trusted identity or membership and carried into databases, caches, vector search, object storage and downstream APIs.",{},{"id":862,"data":863,"type":218,"tunes":865},"p-tenant-3",{"text":864},"Retrieving cross-tenant content and asking the model not to use it is already an isolation failure.",{},{"id":867,"data":868,"type":42,"tunes":870},"h-source",{"text":869,"level":254},"MCP does not define Source of Truth",{},{"id":872,"data":873,"type":218,"tunes":875},"p-source-1",{"text":874},"An MCP server can expose a database, document repository, web search service or AI-generated summary. The protocol does not declare which source is authoritative for a claim.",{},{"id":877,"data":878,"type":218,"tunes":880},"p-source-2",{"text":879},"Source-of-Truth rules belong to application\u002Fdomain architecture. The host or server can encode authority through tool design, metadata, access policy or validation, but MCP itself does not make one capability “true.”",{},{"id":882,"data":883,"type":218,"tunes":885},"p-source-3",{"text":884},"A tool can therefore be perfectly callable through MCP and still return stale, secondary or non-authoritative information.",{},{"id":887,"data":888,"type":42,"tunes":890},"h-context",{"text":889,"level":254},"MCP and context engineering",{},{"id":892,"data":893,"type":218,"tunes":895},"p-context-1",{"text":894},"MCP can increase the capabilities and information available to an AI application, but context engineering still determines what reaches the model.",{},{"id":897,"data":898,"type":218,"tunes":900},"p-context-2",{"text":899},"Tool catalogs consume model-visible context in many hosts. Tool results can be large. Resources can be numerous. A host needs selection, filtering, dynamic loading and compaction rather than exposing everything on every turn.",{},{"id":902,"data":903,"type":218,"tunes":905},"p-context-3",{"text":904},"Capability availability and model-visible context should therefore be treated as separate layers.",{},{"id":907,"data":908,"type":42,"tunes":910},"h-tool-design",{"text":909,"level":254},"Design MCP tools around outcomes and risk boundaries",{},{"id":912,"data":913,"type":376,"tunes":939},"tool-design-table",{"content":914,"stretched":43,"withHeadings":14},[915,918,921,924,927,930,933,936],[916,917],"Weak tool design","Stronger tool design",[919,920],"execute_api(method,url,body)","Narrow domain tools with validated operations",[922,923],"One admin tool for all actions","Separate read\u002Fwrite\u002Fapproval operations",[925,926],"Raw internal API mirrored 1:1","AI-facing contract around coherent user goals",[928,929],"One broad filesystem tool","Workspace-scoped read\u002Fwrite operations",[931,932],"Security policy only in description","Server enforces policy in code",[934,935],"Unbounded raw response","Structured decision-relevant output",[937,938],"Delete\u002Fupdate mixed with read","Separate side-effect tools with confirmation policy",{},{"id":941,"data":942,"type":42,"tunes":944},"h-approvals",{"text":943,"level":254},"Approvals belong in the execution architecture",{},{"id":946,"data":947,"type":218,"tunes":949},"p-approve-1",{"text":948},"A host can require user approval before invoking selected MCP tools. OpenAI's current MCP integration supports automatic or explicit-approval execution patterns.",{},{"id":951,"data":952,"type":218,"tunes":954},"p-approve-2",{"text":953},"Host approval is useful but should not be the server's only protection because another compatible MCP client may use a different approval model.",{},{"id":956,"data":957,"type":218,"tunes":959},"p-approve-3",{"text":958},"For destructive or financially consequential actions, use defense in depth: clear tool contract, runtime approval where appropriate, server-side authorization, business validation and audit.",{},{"id":961,"data":962,"type":42,"tunes":964},"h-observability",{"text":963,"level":254},"MCP observability should connect protocol calls to domain actions",{},{"id":966,"data":967,"type":218,"tunes":969},"p-obs-1",{"text":968},"An MCP trace is most useful when it can be correlated with the underlying application call, database change or business transaction.",{},{"id":971,"data":972,"type":218,"tunes":974},"p-obs-2",{"text":973},"The 2026-07-28 ecosystem standardizes W3C Trace Context propagation conventions, making it easier to follow a request across host, client, server and downstream services.",{},{"id":976,"data":977,"type":218,"tunes":979},"p-obs-3",{"text":978},"Protocol logs alone are not enough for consequential operations. Audit evidence should also record relevant principal, tenant, target resource, approval and resulting state change.",{},{"id":981,"data":982,"type":42,"tunes":984},"h-failure",{"text":983,"level":254},"What MCP cannot fix",{},{"id":986,"data":987,"type":376,"tunes":1022},"failure-table",{"content":988,"stretched":43,"withHeadings":14},[989,992,995,998,1001,1004,1007,1010,1013,1016,1019],[990,991],"Problem","Why MCP does not solve it",[993,994],"Bad business API","MCP can expose the bad API more consistently",[996,997],"Wrong data","Protocol validity does not create factual correctness",[999,1000],"Missing tenant isolation","Tool discovery does not enforce resource ownership",[1002,1003],"Excessive privileges","A standardized tool can still be overprivileged",[1005,1006],"Poor agent planning","MCP exposes capabilities; runtime\u002Fmodel still chooses how to use them",[1008,1009],"Bad retry\u002Fidempotency design","Protocol calls do not make side effects safe",[1011,1012],"No Source of Truth","MCP does not decide which system owns a fact",[1014,1015],"Weak evaluation","Interoperability does not prove task success",[1017,1018],"No audit policy","Transport traces do not define retention or accountability",[1020,1021],"Protocol mismatch","Old\u002Fnew versions can still require migration or compatibility handling",{},{"id":1024,"data":1025,"type":42,"tunes":1027},"h-implementation",{"text":1026,"level":254},"Original implementation evidence: Aaasaasa AI Client",{},{"id":1029,"data":1030,"type":226,"tunes":1033},"impl-note",{"body":1031,"title":1032,"variant":247},"Aaasaasa AI Client contains an authenticated local MCP connector\u002Fbroker for approved local directories and integration through Secure MCP Tunnel. This is concrete implementation evidence for the protocol boundary and permission architecture, not a claim of a general-purpose commercial MCP platform.","Implementation evidence",{},{"id":1035,"data":1036,"type":218,"tunes":1038},"p-impl-1",{"text":1037},"The application can run an authenticated Streamable HTTP MCP endpoint on loopback. The endpoint exposes only directories selected through the central workspace permission broker.",{},{"id":1040,"data":1041,"type":218,"tunes":1043},"p-impl-2",{"text":1042},"The local endpoint and remote route are separate concerns: the local connector can bind only to loopback, while a Secure MCP Tunnel can make the approved MCP service reachable to a permitted external AI client without exposing the whole local machine.",{},{"id":1045,"data":1046,"type":218,"tunes":1048},"p-impl-3",{"text":1047},"The central permission model distinguishes chat-only, read-only, project-write and custom-directory profiles. Direct Chat has no filesystem or shell access; tool-capable agent runtimes use the selected permission profile.",{},{"id":1050,"data":1051,"type":218,"tunes":1053},"p-impl-4",{"text":1052},"This is a direct implementation of the G02 boundary: MCP provides the standardized capability connection, while the application-owned permission broker decides which directories the server may expose.",{},{"id":1055,"data":1056,"type":376,"tunes":1079},"impl-table",{"content":1057,"stretched":43,"withHeadings":14},[1058,1061,1064,1067,1070,1073,1076],[1059,1060],"Implemented element","Architecture evidence",[1062,1063],"Authenticated local MCP endpoint","MCP server can be a local deterministic capability service",[1065,1066],"Loopback binding","Network exposure and protocol capability are separate decisions",[1068,1069],"Secure MCP Tunnel integration","Private\u002Flocal MCP can be bridged through a controlled route",[1071,1072],"Central permission broker","MCP capability is constrained by application policy",[1074,1075],"Selected directory scope","Filesystem visibility is explicitly bounded",[1077,1078],"Direct Chat without OS tools","Model access does not automatically imply tool access",{},{"id":1081,"data":1082,"type":226,"tunes":1085},"impl-boundary",{"body":1083,"title":1084,"variant":240},"The implementation demonstrates MCP connectivity and permission-scoped local directory exposure. It does not imply that every MCP primitive, every 2026-07-28 feature or every enterprise authorization extension is implemented.","Evidence boundary",{},{"id":1087,"data":1088,"type":42,"tunes":1090},"h-use",{"text":1089,"level":254},"When MCP is a good fit",{},{"id":1092,"data":1093,"type":376,"tunes":1113},"use-table",{"content":1094,"stretched":43,"withHeadings":14},[1095,1098,1101,1104,1107,1110],[1096,1097],"MCP is a strong fit when","A direct integration may be simpler when",[1099,1100],"The same capability should be reusable across multiple AI hosts","One application owns both sides and portability has little value",[1102,1103],"An external system wants to publish discoverable AI-facing tools\u002Fresources","A single stable internal API call is sufficient",[1105,1106],"You want a standard boundary around local tools\u002Fdata","There is no AI-facing interoperability requirement",[1108,1109],"Tool providers and AI clients evolve independently","The integration is intentionally private and tightly coupled",[1111,1112],"You want ecosystem-compatible capability discovery","The capability set is tiny and fixed in application code",{},{"id":1115,"data":1116,"type":42,"tunes":1118},"h-not-need",{"text":1117,"level":254},"When you do not need MCP",{},{"id":1120,"data":1121,"type":218,"tunes":1123},"p-not-1",{"text":1122},"Do not add MCP merely because the application uses AI. If your backend already calls one internal API and no independent MCP client needs that capability, an ordinary function or service call may be clearer.",{},{"id":1125,"data":1126,"type":218,"tunes":1128},"p-not-2",{"text":1127},"MCP adds value at an interoperability boundary. Without that boundary, the protocol can become an unnecessary adapter layer.",{},{"id":1130,"data":1131,"type":218,"tunes":1133},"p-not-3",{"text":1132},"The architectural question is not “Does this project have AI?” but “Do independently evolving AI hosts and capability providers benefit from a standard contract?”",{},{"id":1135,"data":1136,"type":42,"tunes":1138},"h-security",{"text":1137,"level":254},"MCP security checklist",{},{"id":1140,"data":1141,"type":376,"tunes":1182},"security-table",{"content":1142,"stretched":43,"withHeadings":14},[1143,1146,1149,1152,1155,1158,1161,1164,1167,1170,1173,1176,1179],[1144,1145],"Boundary","Question",[1147,1148],"Server identity","Which MCP server am I actually connected to?",[1150,1151],"Client identity","Which application\u002Fclient is requesting access?",[1153,1154],"End-user identity","On whose behalf is the operation performed?",[1156,1157],"Tool allowlist","Which capabilities may this host\u002Fagent discover and call?",[1159,1160],"Business permission","May this principal perform this operation?",[1162,1163],"Tenant scope","Which tenant\u002Fresource boundary applies?",[1165,1166],"Credential isolation","Are credentials bound correctly and kept outside model context?",[1168,1169],"Approval","Which side effects require human confirmation?",[1171,1172],"Input validation","Are tool arguments validated independently of model output?",[1174,1175],"Output trust","Can returned content contain untrusted instructions or sensitive data?",[1177,1178],"Network exposure","Is a local server accidentally exposed beyond intended interfaces?",[1180,1181],"Audit","Can a protocol call be correlated with the downstream action?",{},{"id":1184,"data":1185,"type":42,"tunes":1187},"h-misconceptions",{"text":1186,"level":254},"Common misconceptions",{},{"id":1189,"data":1190,"type":376,"tunes":1231},"misconceptions-table",{"content":1191,"stretched":43,"withHeadings":14},[1192,1195,1198,1201,1204,1207,1210,1213,1216,1219,1222,1225,1228],[1193,1194],"Misconception","Correction",[1196,1197],"“An MCP server is an AI server.”","It can be ordinary deterministic software exposing capabilities.",[1199,1200],"“I need my own LLM on the MCP server.”","No. The model can live entirely on the host side.",[1202,1203],"“MCP replaces REST APIs.”","MCP often wraps existing APIs for AI-facing interoperability.",[1205,1206],"“MCP is an agent framework.”","MCP supplies capabilities; an agent runtime manages iteration and state.",[1208,1209],"“MCP and function calling compete.”","A host can bridge MCP capabilities into its model tool interface.",[1211,1212],"“MCP replaces A2A.”","MCP focuses on capability integration; A2A focuses on agent collaboration.",[1214,1215],"“If a tool is listed, the user may call it.”","Discovery is not authorization.",[1217,1218],"“OAuth solves business permissions.”","Connection authorization does not replace domain authorization or tenant isolation.",[1220,1221],"“Local MCP means local AI.”","Tool-server location and inference location are independent.",[1223,1224],"“MCP makes tool output trustworthy.”","Data quality, authority and provenance still belong to the source\u002Fapplication.",[1226,1227],"“One giant generic tool is flexible.”","Over-broad tools weaken permissions, validation and observability.",[1229,1230],"“Old tutorials are implementation-current.”","The 2026-07-28 revision materially changed lifecycle and transport behavior.",{},{"id":1233,"data":1234,"type":42,"tunes":1236},"h-design",{"text":1235,"level":254},"A practical MCP design sequence",{},{"id":1238,"data":1239,"type":324,"tunes":1278},"design-flow",{"steps":1240,"title":1277,"orientation":323},[1241,1244,1247,1250,1253,1256,1259,1262,1265,1268,1271,1274],{"label":1242,"description":1243},"1. Identify the interoperability boundary","Confirm that independent AI hosts actually need reusable access.",{"label":1245,"description":1246},"2. Keep the domain API authoritative","Preserve the real application\u002Fservice contract behind MCP.",{"label":1248,"description":1249},"3. Choose primitives deliberately","Use tools, resources and prompts according to their semantics.",{"label":1251,"description":1252},"4. Split by risk and permission","Separate read, write, destructive and approval-required operations.",{"label":1254,"description":1255},"5. Define identity propagation","Know which client, user, agent and downstream principal each call represents.",{"label":1257,"description":1258},"6. Enforce business authorization","Validate permissions, tenant scope and target ownership.",{"label":1260,"description":1261},"7. Choose local or remote transport","Match deployment topology to the real need.",{"label":1263,"description":1264},"8. Pin protocol\u002FSDK expectations","Document 2026-07-28 versus older compatibility.",{"label":1266,"description":1267},"9. Add approvals for consequential actions","Use risk-appropriate confirmation controls.",{"label":1269,"description":1270},"10. Design structured outputs","Return concise machine-usable results.",{"label":1272,"description":1273},"11. Add tracing and audit correlation","Connect MCP calls to downstream service\u002Fbusiness events.",{"label":1275,"description":1276},"12. Test portability","Verify more than one client where interoperability is a stated requirement.","Design the boundary before implementing the server",{},{"id":1280,"data":1281,"type":42,"tunes":1283},"h-checklist",{"text":1282,"level":254},"MCP architecture checklist",{},{"id":1285,"data":1286,"type":376,"tunes":1335},"checklist-table",{"content":1287,"stretched":43,"withHeadings":14},[1288,1290,1293,1296,1299,1302,1305,1308,1311,1314,1317,1320,1323,1326,1329,1332],[1145,1289],"Expected answer",[1291,1292],"Why is MCP needed?","A real AI-facing interoperability boundary",[1294,1295],"What does the server expose?","Explicit tools\u002Fresources\u002Fprompts",[1297,1298],"Where does the model run?","Independent host\u002Fprovider decision",[1300,1301],"Where does tool execution run?","Named server\u002Fruntime location",[1303,1304],"Which protocol revision is expected?","Version-aware contract",[1306,1307],"Who is the requesting principal?","Client\u002Fuser\u002Fagent identity model",[1309,1310],"Which tools may be discovered?","Allowlist\u002Fcapability policy",[1312,1313],"Which operations may execute?","Server-side business authorization",[1315,1316],"How is tenant\u002Fresource scope enforced?","Trusted tenant\u002Fresource ownership checks",[1318,1319],"Which actions need approval?","Risk-based confirmation policy",[1321,1322],"How are credentials protected?","Trusted runtime storage, not model-visible secrets",[1324,1325],"How is output bounded?","Structured relevant result contract",[1327,1328],"How are calls traced?","Correlation through MCP to downstream action",[1330,1331],"What happens if MCP is unavailable?","Defined fallback\u002Ffailure behavior",[1333,1334],"Can another compatible host use it?","Portability validated where required",{},{"id":1337,"data":1338,"type":42,"tunes":1340},"h-edge",{"text":1339,"level":254},"Edge cases and limitations",{},{"id":1342,"data":1343,"type":218,"tunes":1345},"p-edge-1",{"text":1344},"A local stdio MCP server can have little network exposure while still be dangerous if the process itself has excessive filesystem or shell permissions.",{},{"id":1347,"data":1348,"type":218,"tunes":1350},"p-edge-2",{"text":1349},"A remote MCP server may expose only public documentation or highly sensitive enterprise actions. “Remote MCP” says little about risk without the capability and authorization context.",{},{"id":1352,"data":1353,"type":218,"tunes":1355},"p-edge-3",{"text":1354},"Some servers may use only tools and ignore resources\u002Fprompts. MCP compatibility does not require every optional primitive to be equally important.",{},{"id":1357,"data":1358,"type":218,"tunes":1360},"p-edge-4",{"text":1359},"A host can translate between its own internal tool model and MCP. Users may never see the protocol boundary directly, which is acceptable if security and attribution remain clear.",{},{"id":1362,"data":1363,"type":218,"tunes":1365},"p-edge-5",{"text":1364},"MCP continues to evolve rapidly. Extensions, authorization patterns, SDK APIs and ecosystem conventions can change faster than the core architectural distinction.",{},{"id":1367,"data":1368,"type":42,"tunes":1370},"h-change",{"text":1369,"level":254},"What would change this answer?",{},{"id":1372,"data":1373,"type":218,"tunes":1375},"p-change-1",{"text":1374},"Future MCP revisions can change lifecycle, transports, authorization and extension mechanisms. The July 2026 revision already demonstrates why implementation-specific claims must be dated.",{},{"id":1377,"data":1378,"type":218,"tunes":1380},"p-change-2",{"text":1379},"The canonical boundary would change only if MCP expanded from an interoperability protocol into an end-to-end application\u002Fagent architecture standard. That is not what the current protocol defines.",{},{"id":1382,"data":1383,"type":218,"tunes":1385},"p-change-3",{"text":1384},"For implementation work, always check the current specification and exact SDK line instead of copying version-sensitive examples from older tutorials.",{},{"id":1387,"data":1388,"type":42,"tunes":1390},"h-related",{"text":1389,"level":254},"Related canonical knowledge",{},{"id":1392,"data":1393,"type":218,"tunes":1395},"p-related-1",{"text":1394},"MCP belongs downstream of Agentic AI: first understand the agent\u002Fruntime\u002Ftool boundary, then use MCP when external capabilities need a portable protocol contract.",{},{"id":1397,"data":1398,"type":218,"tunes":1400},"p-related-2",{"text":1399},"MCP also depends on RBAC and tenant isolation because protocol-level capability exposure does not determine application authorization.",{},{"id":1402,"data":1403,"type":218,"tunes":1405},"p-related-3",{"text":1404},"The broader protocol-stack article explains where MCP sits beside A2A, UCP, AP2 and A2UI. G02 remains the canonical source for MCP itself.",{},{"id":1407,"data":1408,"type":649,"tunes":1413},"ref-reliability",{"url":1409,"title":1410,"excerpt":1411,"ctaLabel":1412},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fai-agent-reliability-why-the-final-answer-is-not-enough","AI Agent Reliability: Why the Final Answer Is Not Enough","MCP tool calls become part of an agent trajectory; reliable systems need to evaluate actions and observations, not only final text.","Read the agent reliability article",{},{"id":1415,"data":1416,"type":42,"tunes":1418},"h-faq",{"text":1417,"level":254},"Frequently asked questions",{},{"id":1420,"data":1421,"type":1420,"tunes":1464},"faq",{"items":1422,"title":1463},[1423,1427,1431,1435,1439,1443,1447,1451,1455,1459],{"id":1424,"answer":1425,"question":1426},"faq1","The Model Context Protocol is an open client-server protocol for connecting AI applications to external tools, resources, prompts and capability providers through a standardized contract.","What is MCP?",{"id":1428,"answer":1429,"question":1430},"faq2","No. An MCP server can be completely deterministic software. The model normally runs in the AI host or agent runtime, although a server may optionally use AI internally.","Does an MCP server need an AI model?",{"id":1432,"answer":1433,"question":1434},"faq3","The client is the protocol component used by an AI host to communicate with capability providers. The server publishes and executes the capabilities it exposes.","What is the difference between an MCP client and server?",{"id":1436,"answer":1437,"question":1438},"faq4","No. Function\u002Ftool calling is how a model invokes configured capabilities. MCP standardizes discovery and communication with external capability servers. A host can bridge the two.","Does MCP replace function calling?",{"id":1440,"answer":1441,"question":1442},"faq5","No. MCP servers frequently wrap existing REST, GraphQL, database or service APIs and provide an AI-facing interoperability layer.","Does MCP replace REST APIs?",{"id":1444,"answer":1445,"question":1446},"faq6","No. MCP exposes capabilities. Agent planning, state, memory, context management, retries, orchestration and stopping belong to the surrounding runtime.","Is MCP an agent framework?",{"id":1448,"answer":1449,"question":1450},"faq7","MCP primarily connects an AI host or agent to tools and data providers. A2A connects independent agent systems for collaboration and delegation.","What is the difference between MCP and A2A?",{"id":1452,"answer":1453,"question":1454},"faq8","MCP includes protocol-level authorization mechanisms, especially for remote servers, but the application must still enforce business permissions, resource ownership and tenant isolation.","Does MCP handle authorization?",{"id":1456,"answer":1457,"question":1458},"faq9","Yes. Model location is independent of MCP. A local-model host can call local or remote MCP servers, and a cloud-model host can use approved local or remote MCP servers through an appropriate connection architecture.","Can MCP work with local models?",{"id":1460,"answer":1461,"question":1462},"faq10","As of 8 October 2026, the current specification revision is 2026-07-28. Older 2025-era implementations remain in use, so compatibility must be checked.","What is the current MCP specification version?","Model Context Protocol FAQ",{},{"id":1466,"data":1467,"type":42,"tunes":1469},"h-glossary",{"text":1468,"level":254},"Glossary",{},{"id":1471,"data":1472,"type":1471,"tunes":1514},"glossary",{"title":1473,"entries":1474},"Key MCP terms",[1475,1477,1481,1484,1487,1490,1493,1496,1500,1503,1506,1510],{"term":595,"anchor":594,"definition":1476},"Model Context Protocol, an open protocol for interoperable connections between AI hosts\u002Fclients and external capability servers.",{"term":1478,"anchor":1479,"definition":1480},"MCP host","mcp-host","The AI application or runtime that owns model interaction and uses MCP clients to connect to servers.",{"term":362,"anchor":1482,"definition":1483},"mcp-client","Protocol component on the host side that communicates with an MCP server.",{"term":365,"anchor":1485,"definition":1486},"mcp-server","Capability provider that implements MCP and exposes tools, resources, prompts or supported extensions.",{"term":501,"anchor":1488,"definition":1489},"mcp-tool","Callable structured capability exposed by an MCP server.",{"term":504,"anchor":1491,"definition":1492},"mcp-resource","Readable data or content exposed through MCP resource methods.",{"term":512,"anchor":1494,"definition":1495},"mcp-prompt","Reusable prompt template exposed by an MCP server for compatible hosts.",{"term":1497,"anchor":1498,"definition":1499},"Streamable HTTP","streamable-http","HTTP-oriented MCP transport used for remote\u002Fnetworked server communication.",{"term":1501,"anchor":1501,"definition":1502},"stdio","Process standard-input\u002Foutput transport commonly used for local MCP server integrations.",{"term":719,"anchor":1504,"definition":1505},"server-discover","Modern MCP method that lets a client inspect server capabilities in the 2026-07-28 protocol era.",{"term":1507,"anchor":1508,"definition":1509},"MRTR","mrtr","Multi Round-Trip Requests, a mechanism for obtaining additional input during a request in the 2026-07-28 protocol era.",{"term":1511,"anchor":1512,"definition":1513},"MCP extension","mcp-extension","Capability that composes with the base protocol and can evolve\u002Fversion separately, such as Tasks or MCP Apps.",{},{"id":1516,"data":1517,"type":42,"tunes":1519},"h-conclusion",{"text":1518,"level":254},"Conclusion",{},{"id":1521,"data":1522,"type":218,"tunes":1524},"p-conclusion-1",{"text":1523},"MCP is easiest to understand when its boundary stays narrow: it connects AI applications to external capabilities through a standard protocol.",{},{"id":1526,"data":1527,"type":218,"tunes":1529},"p-conclusion-2",{"text":1528},"The model does not have to live on the MCP server. The server does not become the agent runtime. A listed tool does not become an authorized business action. And MCP does not replace the underlying API, Source of Truth, tenant isolation or domain architecture.",{},{"id":1531,"data":1532,"type":218,"tunes":1534},"p-conclusion-3",{"text":1533},"That narrowness is the protocol's strength. MCP can standardize how AI systems reach tools and data while leaving application ownership, security, business semantics and model choice in the layers that actually own them.",{},{"id":1536,"data":1537,"type":42,"tunes":1539},"h-sources",{"text":1538,"level":254},"Primary sources and current documentation",{},{"id":1541,"data":1542,"type":218,"tunes":1544},"p-sources-note",{"text":1543},"MCP is evolving quickly, so version-sensitive claims in this article are tied to the 8 October 2026 state. The Aaasaasa AI Client section is original implementation evidence and is explicitly limited to the verified MCP connector and permission-broker scope.",{},{"id":1546,"data":1547,"type":1553,"tunes":1554},"src-mcp-ts",{"link":1548,"meta":1549},"https:\u002F\u002Fts.sdk.modelcontextprotocol.io\u002Fv2\u002F",{"image":1550,"title":1551,"description":1552},{"url":401},"Model Context Protocol — TypeScript SDK v2","Current stable TypeScript SDK documentation implementing the 2026-07-28 MCP specification and server\u002Fclient primitives.","linkTool",{},{"id":1556,"data":1557,"type":1553,"tunes":1563},"src-mcp-release",{"link":1558,"meta":1559},"https:\u002F\u002Fblog.modelcontextprotocol.io\u002Fposts\u002F2026-07-28\u002F",{"image":1560,"title":1561,"description":1562},{"url":401},"Model Context Protocol — 2026-07-28 Specification Release","Official release explanation for the current MCP protocol revision, including stateless core, MRTR, routing, caching, authorization hardening, extensions and deprecations.",{},{"id":1565,"data":1566,"type":1553,"tunes":1572},"src-mcp-migration",{"link":1567,"meta":1568},"https:\u002F\u002Fts.sdk.modelcontextprotocol.io\u002Fv2\u002Fmigration\u002Fsupport-2026-07-28",{"image":1569,"title":1570,"description":1571},{"url":401},"MCP TypeScript SDK — Supporting protocol revision 2026-07-28","Version-specific implementation guidance for the current protocol revision and earlier-era compatibility.",{},{"id":1574,"data":1575,"type":1553,"tunes":1581},"src-openai-mcp",{"link":1576,"meta":1577},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Ftools-connectors-mcp",{"image":1578,"title":1579,"description":1580},{"url":401},"OpenAI — MCP servers","Current OpenAI guidance for connecting models to remote MCP servers and local\u002Fprivate MCP servers through Secure MCP Tunnel.",{},{"id":1583,"data":1584,"type":1553,"tunes":1590},"src-openai-agent-mcp",{"link":1585,"meta":1586},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents-api\u002Ftools\u002Fmcp",{"image":1587,"title":1588,"description":1589},{"url":401},"OpenAI — MCP connections for Agents API","Current MCP connection guidance covering service, environment and stdio locations plus allowed-tool controls.",{},{"id":1592,"data":1593,"type":1553,"tunes":1599},"src-openai-tools",{"link":1594,"meta":1595},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Ftools",{"image":1596,"title":1597,"description":1598},{"url":401},"OpenAI — Tools","Current overview placing remote MCP servers alongside function calling, web search, shell and other model tools.",{},{"id":1601,"data":1602,"type":1553,"tunes":1608},"src-openai-plugin-mcp",{"link":1603,"meta":1604},"https:\u002F\u002Fdevelopers.openai.com\u002Fplugins\u002Fconcepts\u002Fmcp-server",{"image":1605,"title":1606,"description":1607},{"url":401},"OpenAI — MCP server concept","Current description of MCP servers exposing tools, resources and prompts for external service integrations.",{},"2.31.6","Model Context Protocol connects AI applications to external tools, resources and prompts through a standard client-server boundary. Learn what MCP does, what it does not do, and where it fits in agent architecture.","\u002Fuploads\u002F2026\u002F10\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits-1791486640275-7ub1cq.webp","mcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits-1791486640275-7ub1cq","PUBLISHED","2026-10-08T15:09:00.000Z","2026-10-08T19:09:09.976Z","2026-10-08T19:18:07.694Z",{"en":1618,"de":1619,"sr":1620,"es":1621,"fr":1622,"it":1623,"ru":1624,"zh":1625},"\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u002Fde\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u002Fsr\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u002Fes\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u002Ffr\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u002Fit\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u002Fru\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u002Fzh\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits",[1627,1631,1635,1639],{"id":1628,"name":1629,"slug":1630},84,"Policy & Data Boundaries","policy-and-data",{"id":1632,"name":1633,"slug":1634},57,"Data Boundaries","data-boundaries",{"id":1636,"name":1637,"slug":1638},48,"Capabilities","capabilities",{"id":1640,"name":1641,"slug":1642},49,"Controls & Evidence","controls",{"id":1644,"login":1645,"email":1646,"displayName":1647},"20","rooth8233","aleksandar@stajic.de","Aleksandar Stajić",[1649],{"lang":7,"title":208,"content":210,"contentJson":1650,"excerpt":1610},{"time":212,"blocks":1651,"version":1609},[1652,1655,1658,1661,1664,1667,1670,1673,1676,1679,1682,1685,1688,1691,1694,1705,1708,1711,1714,1717,1720,1731,1734,1737,1740,1756,1759,1762,1765,1768,1771,1774,1777,1780,1783,1786,1789,1792,1795,1806,1809,1812,1815,1818,1821,1824,1827,1830,1833,1836,1851,1854,1857,1860,1863,1866,1869,1872,1875,1878,1881,1884,1887,1890,1893,1896,1904,1907,1910,1913,1926,1929,1932,1935,1938,1941,1944,1947,1950,1953,1956,1959,1962,1965,1968,1971,1974,1977,1980,1983,1986,1989,1992,1995,1998,2001,2004,2007,2010,2013,2016,2019,2022,2025,2028,2040,2043,2046,2049,2052,2055,2058,2061,2064,2067,2082,2085,2088,2091,2094,2097,2100,2111,2114,2117,2127,2130,2133,2136,2139,2142,2159,2162,2179,2182,2198,2201,2221,2224,2227,2230,2233,2236,2239,2242,2245,2248,2251,2254,2257,2260,2263,2266,2269,2283,2286,2302,2305,2308,2311,2314,2317,2320,2325,2330,2335,2340,2345,2350],{"id":215,"data":1653,"type":218,"tunes":1654},{"text":217},{},{"id":221,"data":1656,"type":226,"tunes":1657},{"body":223,"title":224,"variant":225},{},{"id":229,"data":1659,"type":226,"tunes":1660},{"body":231,"title":232,"variant":233},{},{"id":236,"data":1662,"type":226,"tunes":1663},{"body":238,"title":239,"variant":240},{},{"id":243,"data":1665,"type":226,"tunes":1666},{"body":245,"title":246,"variant":247},{},{"id":250,"data":1668,"type":255,"tunes":1669},{"title":252,"maxLevel":253,"minLevel":254},{},{"id":258,"data":1671,"type":42,"tunes":1672},{"text":260,"level":254},{},{"id":263,"data":1674,"type":218,"tunes":1675},{"text":265},{},{"id":268,"data":1677,"type":218,"tunes":1678},{"text":270},{},{"id":273,"data":1680,"type":218,"tunes":1681},{"text":275},{},{"id":278,"data":1683,"type":42,"tunes":1684},{"text":280,"level":254},{},{"id":283,"data":1686,"type":218,"tunes":1687},{"text":285},{},{"id":288,"data":1689,"type":218,"tunes":1690},{"text":290},{},{"id":293,"data":1692,"type":218,"tunes":1693},{"text":295},{},{"id":298,"data":1695,"type":324,"tunes":1704},{"steps":1696,"title":322,"orientation":323},[1697,1698,1699,1700,1701,1702,1703],{"label":302,"description":303},{"label":305,"description":306},{"label":308,"description":309},{"label":311,"description":312},{"label":314,"description":315},{"label":317,"description":318},{"label":320,"description":321},{},{"id":327,"data":1706,"type":42,"tunes":1707},{"text":329,"level":254},{},{"id":332,"data":1709,"type":218,"tunes":1710},{"text":334},{},{"id":337,"data":1712,"type":218,"tunes":1713},{"text":339},{},{"id":342,"data":1715,"type":218,"tunes":1716},{"text":344},{},{"id":347,"data":1718,"type":42,"tunes":1719},{"text":349,"level":254},{},{"id":352,"data":1721,"type":376,"tunes":1730},{"content":1722,"stretched":43,"withHeadings":14},[1723,1724,1725,1726,1727,1728,1729],[356,357],[359,360],[362,363],[365,366],[368,369],[371,372],[374,375],{},{"id":379,"data":1732,"type":218,"tunes":1733},{"text":381},{},{"id":384,"data":1735,"type":218,"tunes":1736},{"text":386},{},{"id":389,"data":1738,"type":42,"tunes":1739},{"text":391,"level":254},{},{"id":394,"data":1741,"type":425,"tunes":1755},{"rows":1742,"title":414,"layout":376,"columns":1751},[1743,1745,1747,1749],{"id":398,"label":399,"values":1744},[401,401,401],{"id":403,"label":404,"values":1746},[401,401,401],{"id":407,"label":408,"values":1748},[401,401,401],{"id":411,"label":412,"values":1750},[401,401,401],[1752,1753,1754],{"id":417,"label":418},{"id":420,"label":421},{"id":423,"label":424},{},{"id":428,"data":1757,"type":42,"tunes":1758},{"text":430,"level":254},{},{"id":433,"data":1760,"type":218,"tunes":1761},{"text":435},{},{"id":438,"data":1763,"type":218,"tunes":1764},{"text":440},{},{"id":443,"data":1766,"type":218,"tunes":1767},{"text":445},{},{"id":448,"data":1769,"type":42,"tunes":1770},{"text":450,"level":254},{},{"id":453,"data":1772,"type":218,"tunes":1773},{"text":455},{},{"id":458,"data":1775,"type":218,"tunes":1776},{"text":460},{},{"id":463,"data":1778,"type":218,"tunes":1779},{"text":465},{},{"id":468,"data":1781,"type":42,"tunes":1782},{"text":470,"level":254},{},{"id":473,"data":1784,"type":218,"tunes":1785},{"text":475},{},{"id":478,"data":1787,"type":218,"tunes":1788},{"text":480},{},{"id":483,"data":1790,"type":218,"tunes":1791},{"text":485},{},{"id":488,"data":1793,"type":42,"tunes":1794},{"text":490,"level":254},{},{"id":493,"data":1796,"type":376,"tunes":1805},{"content":1797,"stretched":43,"withHeadings":14},[1798,1799,1800,1801,1802,1803,1804],[497,498],[500,501],[503,504],[506,507],[509,501],[511,512],[514,515],{},{"id":518,"data":1807,"type":42,"tunes":1808},{"text":520,"level":254},{},{"id":523,"data":1810,"type":218,"tunes":1811},{"text":525},{},{"id":528,"data":1813,"type":218,"tunes":1814},{"text":530},{},{"id":533,"data":1816,"type":218,"tunes":1817},{"text":535},{},{"id":538,"data":1819,"type":226,"tunes":1820},{"body":540,"title":541,"variant":233},{},{"id":544,"data":1822,"type":42,"tunes":1823},{"text":546,"level":254},{},{"id":549,"data":1825,"type":218,"tunes":1826},{"text":551},{},{"id":554,"data":1828,"type":218,"tunes":1829},{"text":556},{},{"id":559,"data":1831,"type":218,"tunes":1832},{"text":561},{},{"id":564,"data":1834,"type":42,"tunes":1835},{"text":566,"level":254},{},{"id":569,"data":1837,"type":425,"tunes":1850},{"rows":1838,"title":588,"layout":376,"columns":1847},[1839,1841,1843,1845],{"id":573,"label":574,"values":1840},[401,401],{"id":577,"label":578,"values":1842},[401,401],{"id":581,"label":582,"values":1844},[401,401],{"id":585,"label":586,"values":1846},[401,401],[1848,1849],{"id":591,"label":592},{"id":594,"label":595},{},{"id":598,"data":1852,"type":218,"tunes":1853},{"text":600},{},{"id":603,"data":1855,"type":42,"tunes":1856},{"text":605,"level":254},{},{"id":608,"data":1858,"type":218,"tunes":1859},{"text":610},{},{"id":613,"data":1861,"type":218,"tunes":1862},{"text":615},{},{"id":618,"data":1864,"type":218,"tunes":1865},{"text":620},{},{"id":623,"data":1867,"type":42,"tunes":1868},{"text":625,"level":254},{},{"id":628,"data":1870,"type":218,"tunes":1871},{"text":630},{},{"id":633,"data":1873,"type":218,"tunes":1874},{"text":635},{},{"id":638,"data":1876,"type":218,"tunes":1877},{"text":640},{},{"id":643,"data":1879,"type":649,"tunes":1880},{"url":645,"title":646,"excerpt":647,"ctaLabel":648},{},{"id":652,"data":1882,"type":42,"tunes":1883},{"text":654,"level":254},{},{"id":657,"data":1885,"type":218,"tunes":1886},{"text":659},{},{"id":662,"data":1888,"type":218,"tunes":1889},{"text":664},{},{"id":667,"data":1891,"type":218,"tunes":1892},{"text":669},{},{"id":672,"data":1894,"type":42,"tunes":1895},{"text":674,"level":254},{},{"id":677,"data":1897,"type":376,"tunes":1903},{"content":1898,"stretched":43,"withHeadings":14},[1899,1900,1901,1902],[681,682],[684,685],[687,688],[690,691],{},{"id":694,"data":1905,"type":218,"tunes":1906},{"text":696},{},{"id":699,"data":1908,"type":218,"tunes":1909},{"text":701},{},{"id":704,"data":1911,"type":42,"tunes":1912},{"text":706,"level":254},{},{"id":709,"data":1914,"type":376,"tunes":1925},{"content":1915,"stretched":43,"withHeadings":14},[1916,1917,1918,1919,1920,1921,1922,1923,1924],[713,714],[716,717],[719,720],[722,723],[725,726],[728,729],[731,732],[734,735],[737,738],{},{"id":741,"data":1927,"type":42,"tunes":1928},{"text":743,"level":254},{},{"id":746,"data":1930,"type":218,"tunes":1931},{"text":748},{},{"id":751,"data":1933,"type":218,"tunes":1934},{"text":753},{},{"id":756,"data":1936,"type":218,"tunes":1937},{"text":758},{},{"id":761,"data":1939,"type":42,"tunes":1940},{"text":763,"level":254},{},{"id":766,"data":1942,"type":218,"tunes":1943},{"text":768},{},{"id":771,"data":1945,"type":218,"tunes":1946},{"text":773},{},{"id":776,"data":1948,"type":218,"tunes":1949},{"text":778},{},{"id":781,"data":1951,"type":42,"tunes":1952},{"text":783,"level":254},{},{"id":786,"data":1954,"type":218,"tunes":1955},{"text":788},{},{"id":791,"data":1957,"type":218,"tunes":1958},{"text":793},{},{"id":796,"data":1960,"type":218,"tunes":1961},{"text":798},{},{"id":801,"data":1963,"type":42,"tunes":1964},{"text":803,"level":254},{},{"id":806,"data":1966,"type":218,"tunes":1967},{"text":808},{},{"id":811,"data":1969,"type":218,"tunes":1970},{"text":813},{},{"id":816,"data":1972,"type":218,"tunes":1973},{"text":818},{},{"id":821,"data":1975,"type":226,"tunes":1976},{"body":823,"title":824,"variant":240},{},{"id":827,"data":1978,"type":42,"tunes":1979},{"text":829,"level":254},{},{"id":832,"data":1981,"type":218,"tunes":1982},{"text":834},{},{"id":837,"data":1984,"type":218,"tunes":1985},{"text":839},{},{"id":842,"data":1987,"type":218,"tunes":1988},{"text":844},{},{"id":847,"data":1990,"type":42,"tunes":1991},{"text":849,"level":254},{},{"id":852,"data":1993,"type":218,"tunes":1994},{"text":854},{},{"id":857,"data":1996,"type":218,"tunes":1997},{"text":859},{},{"id":862,"data":1999,"type":218,"tunes":2000},{"text":864},{},{"id":867,"data":2002,"type":42,"tunes":2003},{"text":869,"level":254},{},{"id":872,"data":2005,"type":218,"tunes":2006},{"text":874},{},{"id":877,"data":2008,"type":218,"tunes":2009},{"text":879},{},{"id":882,"data":2011,"type":218,"tunes":2012},{"text":884},{},{"id":887,"data":2014,"type":42,"tunes":2015},{"text":889,"level":254},{},{"id":892,"data":2017,"type":218,"tunes":2018},{"text":894},{},{"id":897,"data":2020,"type":218,"tunes":2021},{"text":899},{},{"id":902,"data":2023,"type":218,"tunes":2024},{"text":904},{},{"id":907,"data":2026,"type":42,"tunes":2027},{"text":909,"level":254},{},{"id":912,"data":2029,"type":376,"tunes":2039},{"content":2030,"stretched":43,"withHeadings":14},[2031,2032,2033,2034,2035,2036,2037,2038],[916,917],[919,920],[922,923],[925,926],[928,929],[931,932],[934,935],[937,938],{},{"id":941,"data":2041,"type":42,"tunes":2042},{"text":943,"level":254},{},{"id":946,"data":2044,"type":218,"tunes":2045},{"text":948},{},{"id":951,"data":2047,"type":218,"tunes":2048},{"text":953},{},{"id":956,"data":2050,"type":218,"tunes":2051},{"text":958},{},{"id":961,"data":2053,"type":42,"tunes":2054},{"text":963,"level":254},{},{"id":966,"data":2056,"type":218,"tunes":2057},{"text":968},{},{"id":971,"data":2059,"type":218,"tunes":2060},{"text":973},{},{"id":976,"data":2062,"type":218,"tunes":2063},{"text":978},{},{"id":981,"data":2065,"type":42,"tunes":2066},{"text":983,"level":254},{},{"id":986,"data":2068,"type":376,"tunes":2081},{"content":2069,"stretched":43,"withHeadings":14},[2070,2071,2072,2073,2074,2075,2076,2077,2078,2079,2080],[990,991],[993,994],[996,997],[999,1000],[1002,1003],[1005,1006],[1008,1009],[1011,1012],[1014,1015],[1017,1018],[1020,1021],{},{"id":1024,"data":2083,"type":42,"tunes":2084},{"text":1026,"level":254},{},{"id":1029,"data":2086,"type":226,"tunes":2087},{"body":1031,"title":1032,"variant":247},{},{"id":1035,"data":2089,"type":218,"tunes":2090},{"text":1037},{},{"id":1040,"data":2092,"type":218,"tunes":2093},{"text":1042},{},{"id":1045,"data":2095,"type":218,"tunes":2096},{"text":1047},{},{"id":1050,"data":2098,"type":218,"tunes":2099},{"text":1052},{},{"id":1055,"data":2101,"type":376,"tunes":2110},{"content":2102,"stretched":43,"withHeadings":14},[2103,2104,2105,2106,2107,2108,2109],[1059,1060],[1062,1063],[1065,1066],[1068,1069],[1071,1072],[1074,1075],[1077,1078],{},{"id":1081,"data":2112,"type":226,"tunes":2113},{"body":1083,"title":1084,"variant":240},{},{"id":1087,"data":2115,"type":42,"tunes":2116},{"text":1089,"level":254},{},{"id":1092,"data":2118,"type":376,"tunes":2126},{"content":2119,"stretched":43,"withHeadings":14},[2120,2121,2122,2123,2124,2125],[1096,1097],[1099,1100],[1102,1103],[1105,1106],[1108,1109],[1111,1112],{},{"id":1115,"data":2128,"type":42,"tunes":2129},{"text":1117,"level":254},{},{"id":1120,"data":2131,"type":218,"tunes":2132},{"text":1122},{},{"id":1125,"data":2134,"type":218,"tunes":2135},{"text":1127},{},{"id":1130,"data":2137,"type":218,"tunes":2138},{"text":1132},{},{"id":1135,"data":2140,"type":42,"tunes":2141},{"text":1137,"level":254},{},{"id":1140,"data":2143,"type":376,"tunes":2158},{"content":2144,"stretched":43,"withHeadings":14},[2145,2146,2147,2148,2149,2150,2151,2152,2153,2154,2155,2156,2157],[1144,1145],[1147,1148],[1150,1151],[1153,1154],[1156,1157],[1159,1160],[1162,1163],[1165,1166],[1168,1169],[1171,1172],[1174,1175],[1177,1178],[1180,1181],{},{"id":1184,"data":2160,"type":42,"tunes":2161},{"text":1186,"level":254},{},{"id":1189,"data":2163,"type":376,"tunes":2178},{"content":2164,"stretched":43,"withHeadings":14},[2165,2166,2167,2168,2169,2170,2171,2172,2173,2174,2175,2176,2177],[1193,1194],[1196,1197],[1199,1200],[1202,1203],[1205,1206],[1208,1209],[1211,1212],[1214,1215],[1217,1218],[1220,1221],[1223,1224],[1226,1227],[1229,1230],{},{"id":1233,"data":2180,"type":42,"tunes":2181},{"text":1235,"level":254},{},{"id":1238,"data":2183,"type":324,"tunes":2197},{"steps":2184,"title":1277,"orientation":323},[2185,2186,2187,2188,2189,2190,2191,2192,2193,2194,2195,2196],{"label":1242,"description":1243},{"label":1245,"description":1246},{"label":1248,"description":1249},{"label":1251,"description":1252},{"label":1254,"description":1255},{"label":1257,"description":1258},{"label":1260,"description":1261},{"label":1263,"description":1264},{"label":1266,"description":1267},{"label":1269,"description":1270},{"label":1272,"description":1273},{"label":1275,"description":1276},{},{"id":1280,"data":2199,"type":42,"tunes":2200},{"text":1282,"level":254},{},{"id":1285,"data":2202,"type":376,"tunes":2220},{"content":2203,"stretched":43,"withHeadings":14},[2204,2205,2206,2207,2208,2209,2210,2211,2212,2213,2214,2215,2216,2217,2218,2219],[1145,1289],[1291,1292],[1294,1295],[1297,1298],[1300,1301],[1303,1304],[1306,1307],[1309,1310],[1312,1313],[1315,1316],[1318,1319],[1321,1322],[1324,1325],[1327,1328],[1330,1331],[1333,1334],{},{"id":1337,"data":2222,"type":42,"tunes":2223},{"text":1339,"level":254},{},{"id":1342,"data":2225,"type":218,"tunes":2226},{"text":1344},{},{"id":1347,"data":2228,"type":218,"tunes":2229},{"text":1349},{},{"id":1352,"data":2231,"type":218,"tunes":2232},{"text":1354},{},{"id":1357,"data":2234,"type":218,"tunes":2235},{"text":1359},{},{"id":1362,"data":2237,"type":218,"tunes":2238},{"text":1364},{},{"id":1367,"data":2240,"type":42,"tunes":2241},{"text":1369,"level":254},{},{"id":1372,"data":2243,"type":218,"tunes":2244},{"text":1374},{},{"id":1377,"data":2246,"type":218,"tunes":2247},{"text":1379},{},{"id":1382,"data":2249,"type":218,"tunes":2250},{"text":1384},{},{"id":1387,"data":2252,"type":42,"tunes":2253},{"text":1389,"level":254},{},{"id":1392,"data":2255,"type":218,"tunes":2256},{"text":1394},{},{"id":1397,"data":2258,"type":218,"tunes":2259},{"text":1399},{},{"id":1402,"data":2261,"type":218,"tunes":2262},{"text":1404},{},{"id":1407,"data":2264,"type":649,"tunes":2265},{"url":1409,"title":1410,"excerpt":1411,"ctaLabel":1412},{},{"id":1415,"data":2267,"type":42,"tunes":2268},{"text":1417,"level":254},{},{"id":1420,"data":2270,"type":1420,"tunes":2282},{"items":2271,"title":1463},[2272,2273,2274,2275,2276,2277,2278,2279,2280,2281],{"id":1424,"answer":1425,"question":1426},{"id":1428,"answer":1429,"question":1430},{"id":1432,"answer":1433,"question":1434},{"id":1436,"answer":1437,"question":1438},{"id":1440,"answer":1441,"question":1442},{"id":1444,"answer":1445,"question":1446},{"id":1448,"answer":1449,"question":1450},{"id":1452,"answer":1453,"question":1454},{"id":1456,"answer":1457,"question":1458},{"id":1460,"answer":1461,"question":1462},{},{"id":1466,"data":2284,"type":42,"tunes":2285},{"text":1468,"level":254},{},{"id":1471,"data":2287,"type":1471,"tunes":2301},{"title":1473,"entries":2288},[2289,2290,2291,2292,2293,2294,2295,2296,2297,2298,2299,2300],{"term":595,"anchor":594,"definition":1476},{"term":1478,"anchor":1479,"definition":1480},{"term":362,"anchor":1482,"definition":1483},{"term":365,"anchor":1485,"definition":1486},{"term":501,"anchor":1488,"definition":1489},{"term":504,"anchor":1491,"definition":1492},{"term":512,"anchor":1494,"definition":1495},{"term":1497,"anchor":1498,"definition":1499},{"term":1501,"anchor":1501,"definition":1502},{"term":719,"anchor":1504,"definition":1505},{"term":1507,"anchor":1508,"definition":1509},{"term":1511,"anchor":1512,"definition":1513},{},{"id":1516,"data":2303,"type":42,"tunes":2304},{"text":1518,"level":254},{},{"id":1521,"data":2306,"type":218,"tunes":2307},{"text":1523},{},{"id":1526,"data":2309,"type":218,"tunes":2310},{"text":1528},{},{"id":1531,"data":2312,"type":218,"tunes":2313},{"text":1533},{},{"id":1536,"data":2315,"type":42,"tunes":2316},{"text":1538,"level":254},{},{"id":1541,"data":2318,"type":218,"tunes":2319},{"text":1543},{},{"id":1546,"data":2321,"type":1553,"tunes":2324},{"link":1548,"meta":2322},{"image":2323,"title":1551,"description":1552},{"url":401},{},{"id":1556,"data":2326,"type":1553,"tunes":2329},{"link":1558,"meta":2327},{"image":2328,"title":1561,"description":1562},{"url":401},{},{"id":1565,"data":2331,"type":1553,"tunes":2334},{"link":1567,"meta":2332},{"image":2333,"title":1570,"description":1571},{"url":401},{},{"id":1574,"data":2336,"type":1553,"tunes":2339},{"link":1576,"meta":2337},{"image":2338,"title":1579,"description":1580},{"url":401},{},{"id":1583,"data":2341,"type":1553,"tunes":2344},{"link":1585,"meta":2342},{"image":2343,"title":1588,"description":1589},{"url":401},{},{"id":1592,"data":2346,"type":1553,"tunes":2349},{"link":1594,"meta":2347},{"image":2348,"title":1597,"description":1598},{"url":401},{},{"id":1601,"data":2351,"type":1553,"tunes":2354},{"link":1603,"meta":2352},{"image":2353,"title":1606,"description":1607},{"url":401},{},"Post erfolgreich abgerufen",{"items":2357,"source":2442,"manualIds":2443,"manualMatchedIds":2444},[2358,2365,2372,2379,2386,2393,2400,2407,2414,2421,2428,2435],{"id":2359,"slug":2360,"title":2361,"excerpt":2362,"featuredImage":2363,"publishedAt":2364},"468","ai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context","AI Agent Memory Is Not RAG: How to Separate Memory, Retrieval, State and Context","Agent memory, RAG, state, and context are often used as if they were interchangeable. They are not. This practical architecture model separates the four layers, shows where each belongs, and explains what breaks when systems collapse them into one.","\u002Fuploads\u002F2026\u002F09\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context-1790350560308-np0xy6.webp","2026-09-25T11:34:00.000Z",{"id":2366,"slug":2367,"title":2368,"excerpt":2369,"featuredImage":2370,"publishedAt":2371},"494","air-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","Air-Gapped AI: How AI Systems Work Without Internet or Cloud Access","Air-gapped AI runs models, RAG and AI applications inside an isolated security domain without internet or cloud dependencies. Learn how models, data, updates and tools operate offline.","\u002Fuploads\u002F2026\u002F10\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access-1791487983978-e6xqf0.webp","2026-10-08T11:32:00.000Z",{"id":2373,"slug":2374,"title":2375,"excerpt":2376,"featuredImage":2377,"publishedAt":2378},"484","what-is-an-ai-platform-architect-models-data-runtime-security-and-operations","What Is an AI Platform Architect? Models, Data, Runtime, Security and Operations","An AI Platform Architect designs reusable AI foundations across models, providers, retrieval, agents, identity, security, evaluation, observability and operations.","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations-1791477229171-ou3zcc.webp","2026-10-08T12:32:00.000Z",{"id":2380,"slug":2381,"title":2382,"excerpt":2383,"featuredImage":2384,"publishedAt":2385},"485","enterprise-ai-architecture-what-changes-when-ai-enters-a-company","Enterprise AI Architecture: What Changes When AI Enters a Company","Enterprise AI architecture explains how AI changes company systems across data authority, identity, permissions, providers, risk, governance, evaluation, compliance and operations.","\u002Fuploads\u002F2026\u002F10\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company-1791478161363-czrwaq.webp","2026-10-08T10:48:00.000Z",{"id":2387,"slug":2388,"title":2389,"excerpt":2390,"featuredImage":2391,"publishedAt":2392},"487","vector-databases-embeddings-and-reranking-three-different-parts-of-retrieval","Vector Databases, Embeddings and Reranking: Three Different Parts of Retrieval","Embeddings represent meaning, vector databases retrieve candidates, and rerankers refine results. Learn how these three retrieval layers differ and work together in RAG.","\u002Fuploads\u002F2026\u002F10\u002Fvector-databases-embeddings-and-reranking-three-different-parts-of-retrieval-1791480129884-9dtasz.webp","2026-10-08T11:21:00.000Z",{"id":2394,"slug":2395,"title":2396,"excerpt":2397,"featuredImage":2398,"publishedAt":2399},"470","what-should-an-ai-agent-remember-forget-recompute-or-retrieve-again","What Should an AI Agent Remember, Forget, Recompute or Retrieve Again?","Long-running agents should not remember everything. This article provides a practical lifecycle model for deciding what belongs in durable memory, what should be retrieved again, what is safer to recompute, and what should expire or be superseded.","\u002Fuploads\u002F2026\u002F09\u002Fwhat-should-an-ai-agent-remember-forget-recompute-or-retrieve-again-1790351131087-iehz28.webp","2026-09-25T09:43:00.000Z",{"id":2401,"slug":2402,"title":2403,"excerpt":2404,"featuredImage":2405,"publishedAt":2406},"467","the-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers","The Answer Validity Boundary: The Missing Layer Between Relevance and Reliable AI Answers","A source can be relevant, authoritative and still be wrong for the question being asked. The missing layer is applicability: the conditions under which an answer holds, and the changes that force it to be reconsidered. This article introduces the Answer Validity Boundary as a source-design pattern for humans, AI search and RAG systems.","\u002Fuploads\u002F2026\u002F09\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers-1790272901306-1g5jly.webp","2026-09-24T11:59:00.000Z",{"id":2408,"slug":2409,"title":2410,"excerpt":2411,"featuredImage":2412,"publishedAt":2413},"483","what-is-an-ai-solution-architect-system-boundaries-responsibilities-and-trade-offs","What Is an AI Solution Architect? System Boundaries, Responsibilities and Trade-offs","An AI Solution Architect turns business requirements into a production-ready AI system across data, models, tools, security, runtime, evaluation and operations.","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-solution-architect-system-boundaries-responsibilities-and-trade-offs-1791476643267-1st5xz.webp","2026-10-08T12:23:00.000Z",{"id":2415,"slug":2416,"title":2417,"excerpt":2418,"featuredImage":2419,"publishedAt":2420},"489","agentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act","Agentic AI Explained: When an AI System Can Plan, Use Tools and Act","Agentic AI uses models inside multi-step execution loops where they can choose tools, observe results, update state and adapt their next action within explicit runtime and permission boundaries.","\u002Fuploads\u002F2026\u002F10\u002Fagentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act-1791481499084-wnji2a.webp","2026-10-08T11:43:00.000Z",{"id":2422,"slug":2423,"title":2424,"excerpt":2425,"featuredImage":2426,"publishedAt":2427},"473","openai-agents-api-vs-agents-sdk-vs-responses-api-what-should-you-build-on-in-2026","OpenAI Agents API vs Agents SDK vs Responses API: What Should You Build On in 2026?","OpenAI’s agent stack changed in September 2026. This architecture guide separates the Agents API, Agents SDK, Responses API, and Codex SDK by runtime ownership—so teams can choose the right control boundary instead of comparing product names.","\u002Fuploads\u002F2026\u002F09\u002Fopenai-agents-api-vs-agents-sdk-vs-responses-api-what-should-you-build-on-in-2026-1790351846714-zi7lus.webp","2026-09-25T11:56:00.000Z",{"id":2429,"slug":2430,"title":2431,"excerpt":2432,"featuredImage":2433,"publishedAt":2434},"495","sovereign-ai-control-of-models-data-infrastructure-and-dependencies","Sovereign AI: Control of Models, Data, Infrastructure and Dependencies","Sovereign AI is about effective control over models, data, infrastructure, software, operations and strategic dependencies — not simply where an AI model is hosted.","\u002Fuploads\u002F2026\u002F10\u002Fsovereign-ai-control-of-models-data-infrastructure-and-dependencies-1791488833132-niy85x.webp","2026-10-08T15:45:00.000Z",{"id":2436,"slug":2437,"title":2438,"excerpt":2439,"featuredImage":2440,"publishedAt":2441},"481","generative-ai-explained-models-retrieval-tools-and-applications-are-not-the-same-thing","Generative AI Explained: Models, Retrieval, Tools and Applications Are Not the Same Thing","Generative AI is more than a model. Learn how models, retrieval, tools, context, runtimes and applications fit together in production AI systems.","\u002Fuploads\u002F2026\u002F10\u002Fgenerative-ai-explained-models-retrieval-tools-and-applications-are-not-the-same-thing-1791475411822-pp0dvz.webp","2026-10-08T12:00:00.000Z","fallback",[],[]]