[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"portal-settings:stajic:zh":3,"public-menus:all":38,"post:mcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits:zh":205,"related:post:mcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits:zh:1":3525},{"statusCode":4,"data":5,"message":37},200,{"tenantId":6,"lang":7,"defaultLang":8,"siteUrl":9,"contactEmail":10,"brandName":11,"logoUrl":12,"siteName":11,"siteDescription":13,"ogImage":10,"robotsIndex":14,"socialLinks":10,"reservedSlugs":10,"seoPolicy":15},"stajic","zh","de","https:\u002F\u002Fstajic.de",null,"Stajic Platform","\u002FLogo_Planet.svg","Stajic Portal",true,{"branding":16,"relatedContent":17,"crossDomainLinks":18},{"logoUrl":12},{"enabled":14},[19,22,25,28,31,34],{"url":20,"label":21,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Ffigure.rocks","figure.rocks",{"url":23,"label":24,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Floving.rocks","loving.rocks",{"url":26,"label":27,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.com","bazify.com",{"url":29,"label":30,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.de","bazify.de",{"url":32,"label":33,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.at","bazify.at",{"url":35,"label":36,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.ba","bazify.ba","Portal settings resolved",[39,45],{"id":40,"name":41,"location":42,"isActive":14,"isDefault":43,"items":44},1,"main-navigation","header",false,[],{"id":46,"name":47,"location":48,"isActive":14,"isDefault":14,"items":49},4,"main-menu","sidebar",[50,66,79,93,103,118,133],{"id":51,"title":52,"url":60,"target":61,"icon":62,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":64,"portfolioId":10,"children":65},"item-18",{"de":53,"en":54,"es":55,"fr":56,"it":54,"ru":57,"sr":58,"zh":59},"Startseite","Home","Inicio","Accueil","Главная","Почетна","首页","\u002Ffull-stack-web-developer-munich-performance-seo-and-maintainable-builds","_self","i-lucide-home","page",111,[],{"id":67,"title":68,"url":75,"target":61,"icon":76,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":77,"portfolioId":10,"children":78},"item-22",{"de":69,"en":69,"es":70,"fr":69,"it":71,"ru":72,"sr":73,"zh":74},"Vision","Visión","Visione","Видение","Визија","想象","\u002Fueber-uns-webdesign-muenchen-webaplikation","i-lucide-eye",113,[],{"id":80,"title":81,"url":89,"target":61,"icon":90,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":91,"portfolioId":10,"children":92},"item-19",{"de":82,"en":83,"es":84,"fr":83,"it":85,"ru":86,"sr":87,"zh":88},"Leistungen","Services","Servicios","Servizi","Услуги","Услуге","服务","\u002Fservices-dienstleistungen-muenchen","i-lucide-wrench",116,[],{"id":94,"title":95,"url":99,"target":61,"icon":100,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":101,"portfolioId":10,"children":102},"item-23",{"de":96,"en":96,"es":96,"fr":96,"it":96,"ru":97,"sr":97,"zh":98},"Blog","Блог","博客","\u002Fblog","i-lucide-book-open",112,[],{"id":104,"title":105,"url":114,"target":61,"icon":115,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":116,"portfolioId":10,"children":117},"item-32",{"de":106,"en":107,"es":108,"fr":109,"it":110,"ru":111,"sr":112,"zh":113},"Neue Technologien","New Technologies","Nuevas tecnologías","Nouvelles technologies","Nuove tecnologie","Новые технологии","Нове технологије","新技术！","\u002Fneue-webtechnologien","i-lucide-sparkles",122,[],{"id":119,"title":120,"url":129,"target":61,"icon":130,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":131,"portfolioId":10,"children":132},"item-20",{"de":121,"en":122,"es":123,"fr":124,"it":125,"ru":126,"sr":127,"zh":128},"Kontakt","Contact us!","Contacto","Contact","Contatto","Контакт","Контактирајте нас","联系我们！","\u002Fcontact","i-lucide-mail",115,[],{"id":134,"title":135,"url":144,"target":61,"icon":145,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":147},"item-21",{"de":136,"en":137,"es":138,"fr":139,"it":140,"ru":141,"sr":142,"zh":143},"Unsere Arbeit","Our Work","Nuestro trabajo","Nos réalisations","I nostri lavori","Наши работы","Наши радови","文件夹","\u002Fportfolio","i-lucide-briefcase",114,[148,161,175,181,193],{"id":149,"title":150,"url":144,"target":61,"icon":159,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":160},"item-24",{"de":151,"en":152,"es":153,"fr":154,"it":155,"ru":156,"sr":157,"zh":158},"Alle Projekte","All Projects","Todos los proyectos","Tous les projets","Tutti i progetti","Все проекты","Сви пројекти","所有项目","i-lucide-grid-3x3",[],{"id":162,"title":163,"url":171,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":174},"item-29",{"de":164,"en":165,"es":166,"fr":167,"it":168,"ru":169,"sr":170,"zh":143},"Local Roots, Global Reach","Local Roots - Global Reach","Empresa local ","Entreprise locale","Azienda locale","Местная компания","Локално предузеће глобално тржиште","\u002Fportfolio\u002Flocal-roots-global-reach-communication-media-systems-for-modern-business","i-lucide-folder","custom",[],{"id":176,"title":177,"url":179,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":180},"item-28",{"de":178,"en":178,"es":178,"fr":178,"it":178,"ru":178,"sr":178,"zh":178},"Solr Suggester","\u002Fportfolio\u002Fsolr-fuzzy-suggester-und-solr-infix-suggester-abfrage-ueber-ajax-und-filterung",[],{"id":182,"title":183,"url":191,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":192},"item-27",{"de":184,"en":185,"es":186,"fr":187,"it":188,"ru":189,"sr":190,"zh":185},"Firmenwebseite SEO","Company Website SEO","Sitio web corporativo SEO","Site web d’entreprise SEO","Sito web aziendale SEO","Корпоративный сайт SEO","Пословна веб-страница SEO","\u002Fportfolio\u002Fseo-sem-branding-mobile-webseite-muenchen",[],{"id":194,"title":195,"url":203,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":204},"item-31",{"de":196,"en":197,"es":198,"fr":199,"it":200,"ru":201,"sr":202,"zh":197},"Digitalisierungsportal","Digitalization Portal","Portal de digitalización","Portail de numérisation","Portale di digitalizzazione","Портал цифровизации","Портал за дигитализацију","\u002Fportfolio\u002Fdigitalisierungsportal-archiv-museum-bibliothek-ead-lido-mets-mods",[],{"statusCode":4,"data":206,"message":3524},{"id":207,"title":208,"slug":209,"content":210,"contentJson":211,"excerpt":1607,"featuredImage":1608,"featuredImageAlt":1609,"featuredImageCaption":10,"featuredImageTitle":10,"featuredImageCopyright":10,"featuredImageAuthor":10,"featuredImageSourceUrl":10,"featuredImageLicense":10,"featuredImageIsAiGenerated":43,"status":1610,"publishedAt":1611,"createdAt":1612,"updatedAt":1613,"seoLocalePaths":1614,"categories":1623,"author":1640,"translations":1645},"492","MCP 解析：它连接什么、不做什么以及它适用于何处","mcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u003Cp>模型上下文协议（MCP）是一种开放协议，用于通过标准化的客户端-服务器契约将 AI 应用程序连接到外部能力和信息。MCP 服务器可以暴露工具、资源和提示；兼容 MCP 的主机或客户端代表 AI 应用程序发现并使用这些能力。MCP 不要求服务器运行自己的语言模型，也不取代所暴露能力背后的代理运行时、业务授权、租户隔离、应用程序 API 或领域架构。\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--info my-6 rounded-xl border p-5 border-blue-300 bg-blue-50 dark:border-blue-900 dark:bg-blue-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">直接回答\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">\u003Cstrong>MCP 标准化了 AI 主机与外部能力提供者之间的边界。\u003C\u002Fstrong>\u003Cbr>\u003Cbr>一个有用的心智模型是：\u003Cbr>\u003Cstrong>用户 → AI 主机 \u002F 代理运行时 → MCP 客户端 → MCP 服务器 → 应用程序\u002FAPI\u002F数据\u002F工具\u003C\u002Fstrong>。\u003Cbr>\u003Cbr>模型可以完全保留在主机侧。MCP 服务器可以是暴露结构化能力的普通确定性软件。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--success my-6 rounded-xl border p-5 border-emerald-300 bg-emerald-50 dark:border-emerald-900 dark:bg-emerald-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">MCP 服务器不需要自己的 AI 模型\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">文件系统 MCP 服务器可以列出或读取文件。数据库 MCP 服务器可以运行经批准的查询。Jira MCP 服务器可以暴露问题操作。这些服务器都不需要 LLM 来满足 MCP 契约。如果服务器内部使用 AI，那是协议边界背后的实现选择，而不是 MCP 的要求。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--warning my-6 rounded-xl border p-5 border-amber-300 bg-amber-50 dark:border-amber-900 dark:bg-amber-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">MCP 能力不等于业务权限\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">如果 MCP 服务器暴露了 \u003Ccode>delete_file\u003C\u002Fcode>、\u003Ccode>refund_order\u003C\u002Fcode> 或 \u003Ccode>deploy_service\u003C\u002Fcode>，这仅意味着该能力存在。服务器\u002F应用程序仍必须强制执行身份、权限、租户范围、业务规则、确认要求和审计控制。协议发现绝不能悄然变成授权。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">当前来源说明 — 2026 年 10 月 8 日\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">当前 MCP 规范修订版是 \u003Cstrong>2026-07-28\u003C\u002Fstrong>。其主要变化是无状态协议核心，具有自描述请求、可选的 \u003Ccode>server\u002Fdiscover\u003C\u002Fcode>、可路由的 HTTP 头、可缓存的列表\u002F资源响应、授权强化以及正式的扩展模型。TypeScript SDK v2 是实现此修订版的当前稳定 SDK 系列。2025 年时代的旧客户端和服务器仍然存在，因此实现指南必须保持版本感知。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cnav class=\"editorjs-toc\" data-editorjs-toc=\"true\" aria-label=\"目录\">\u003Cstrong class=\"editorjs-toc__title\">目录\u003C\u002Fstrong>\u003Col class=\"editorjs-toc__list editorjs-toc__list--depth-0\">\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-7\" class=\"editorjs-toc__link\">MCP 真正标准化的内容\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-11\" class=\"editorjs-toc__link\">最简单的示例\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-16\" class=\"editorjs-toc__link\">简单示例止步之处\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-20\" class=\"editorjs-toc__link\">MCP 架构：主机、客户端和服务器\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-24\" class=\"editorjs-toc__link\">三个核心服务器原语\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-26\" class=\"editorjs-toc__link\">工具：可调用的能力\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-30\" class=\"editorjs-toc__link\">资源：可读的上下文和数据\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-34\" class=\"editorjs-toc__link\">提示词：可复用模板\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-38\" class=\"editorjs-toc__link\">工具还是资源？\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-40\" class=\"editorjs-toc__link\">AI 模型在哪里？\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-45\" class=\"editorjs-toc__link\">MCP 不会取代 API\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-49\" class=\"editorjs-toc__link\">MCP 与函数调用\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-52\" class=\"editorjs-toc__link\">MCP 不会创建代理循环\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-56\" class=\"editorjs-toc__link\">MCP 与 A2A\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-61\" class=\"editorjs-toc__link\">本地和远程 MCP 使用不同的传输现实\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-65\" class=\"editorjs-toc__link\">为什么 MCP 版本感知很重要\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-69\" class=\"editorjs-toc__link\">MCP 2026-07-28 有哪些变化\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-71\" class=\"editorjs-toc__link\">Roots、采样和日志记录不再是新实现的方向\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-75\" class=\"editorjs-toc__link\">长时间运行的工作与普通的 MCP 工具调用不同\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-79\" class=\"editorjs-toc__link\">MCP Apps 扩展 UI 能力而不重新定义核心协议\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-83\" class=\"editorjs-toc__link\">MCP 授权不是您完整的授权模型\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-88\" class=\"editorjs-toc__link\">身份可以跨越多个边界\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-92\" class=\"editorjs-toc__link\">租户隔离仍处于 MCP 能力发现范围之外\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-96\" class=\"editorjs-toc__link\">MCP 未定义事实来源\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-100\" class=\"editorjs-toc__link\">MCP 与上下文工程\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-104\" class=\"editorjs-toc__link\">围绕结果和风险边界设计 MCP 工具\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-106\" class=\"editorjs-toc__link\">审批属于执行架构\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-110\" class=\"editorjs-toc__link\">MCP 可观测性应将协议调用与领域操作关联起来\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-114\" class=\"editorjs-toc__link\">MCP 无法解决的问题\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-116\" class=\"editorjs-toc__link\">原始实现证据：Aaasaasa AI Client\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-124\" class=\"editorjs-toc__link\">MCP 何时适合使用\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-126\" class=\"editorjs-toc__link\">何时不需要 MCP\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-130\" class=\"editorjs-toc__link\">MCP 安全检查清单\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-132\" class=\"editorjs-toc__link\">常见误解\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-134\" class=\"editorjs-toc__link\">实用的 MCP 设计顺序\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-136\" class=\"editorjs-toc__link\">MCP 架构检查清单\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-138\" class=\"editorjs-toc__link\">边缘情况和限制\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-144\" class=\"editorjs-toc__link\">什么会改变这个答案？\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-148\" class=\"editorjs-toc__link\">相关规范知识\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-153\" class=\"editorjs-toc__link\">常见问题\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-155\" class=\"editorjs-toc__link\">术语表\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-157\" class=\"editorjs-toc__link\">结论\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-161\" class=\"editorjs-toc__link\">主要来源和当前文档\u003C\u002Fa>\u003C\u002Fli>\u003C\u002Fol>\u003C\u002Fnav>\n\u003Ch2 id=\"section-7\">MCP 真正标准化的内容\u003C\u002Fh2>\n\u003Cp>在 MCP 之前，每个 AI 应用程序都可以通过自己的工具模式、插件格式、身份验证约定和连接代码来集成外部系统。同一个服务可能需要为桌面 AI 客户端、IDE 代理和自定义应用程序使用不同的适配器。\u003C\u002Fp>\n\u003Cp>MCP 创建了一个可复用的协议边界。外部系统通过 MCP 服务器暴露能力，而兼容的 AI 主机实现 MCP 客户端。这减少了 AI 应用程序与底层工具或数据提供者之间的集成耦合。\u003C\u002Fp>\n\u003Cp>该协议并不标准化整个应用程序。它标准化的是能力在该边界上如何被描述、发现和调用。\u003C\u002Fp>\n\u003Ch2 id=\"section-11\">最简单的示例\u003C\u002Fh2>\n\u003Cp>假设一个 AI 编码应用程序需要访问本地项目目录。没有 MCP 时，该应用程序可能会直接实现自己的文件系统集成。\u003C\u002Fp>\n\u003Cp>使用 MCP 时，文件系统服务器可以暴露诸如列出目录、读取经批准的文件或在允许的工作区内写入等能力。AI 主机通过 MCP 客户端连接，并将这些能力呈现给模型或代理运行时。\u003C\u002Fp>\n\u003Cp>服务器不需要理解用户的自然语言请求。主机\u002F模型决定哪个能力有用；MCP 服务器根据自身的安全规则执行结构化请求。\u003C\u002Fp>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">一个基本的 MCP 工具调用\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. 主机连接到服务器\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">支持 MCP 的应用程序配置对外部 MCP 服务器的访问。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. 发现能力\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">客户端了解服务器暴露了哪些工具、资源或提示。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. 模型或运行时选择能力\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">AI 应用程序决定需要某个已暴露的能力。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. 客户端发送结构化请求\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">参数通过 MCP 发送到服务器。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. 服务器授权并执行\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">服务器验证请求并调用其底层系统。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. 结果返回主机\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">结果成为观察或上下文输入。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. 主机决定下一步\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">模型\u002F运行时可以回答、调用另一个工具或继续工作流。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-16\">简单示例止步之处\u003C\u002Fh2>\n\u003Cp>MCP 不定义主机如何选择工具、代理如何规划、业务工作流如何建模，或发票、部署等领域对象应如何表现。\u003C\u002Fp>\n\u003Cp>协议可以使集成具有互操作性，而底层应用程序仍然不正确、不安全或设计糟糕。一个完全有效的 MCP 请求仍然可能调用错误的业务能力。\u003C\u002Fp>\n\u003Cp>核心边界是：MCP 标准化的是集成语义，而不是应用真相或业务正确性。\u003C\u002Fp>\n\u003Ch2 id=\"section-20\">MCP 架构：主机、客户端和服务器\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">组件\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">职责\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI 主机\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">面向用户的 AI 应用或运行时，负责模型交互、上下文和整体工作流\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">MCP 客户端\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">主机用于与 MCP 服务器通信的协议侧组件\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">MCP 服务器\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">发布能力并处理 MCP 请求\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">底层系统\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">MCP 服务器背后的应用、API、数据库、文件系统、SaaS 平台或服务\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">根据主机\u002F运行时设计选择或推理能力；它不一定位于 MCP 服务器内部\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">授权\u002F业务策略\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">决定请求的操作是否实际被允许\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>一个主机可以连接多个 MCP 服务器，而一个 MCP 服务器可以对接一个或多个底层系统。主机仍然负责将 MCP 结果集成到更广泛的 AI 应用中。\u003C\u002Fp>\n\u003Cp>服务器可以位于主机本地、作为独立进程运行，或通过网络传输远程运行。托管拓扑和模型位置是相互独立的决策。\u003C\u002Fp>\n\u003Ch2 id=\"section-24\">三个核心服务器原语\u003C\u002Fh2>\n\u003Csection class=\"editorjs-comparison my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">工具、资源和提示词解决不同的需求\u003C\u002Fh3>\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left dark:border-gray-700 dark:bg-gray-900\">\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">工具\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">资源\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">提示词\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">主要目的\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">典型交互\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">示例\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">典型风险\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-26\">工具：可调用的能力\u003C\u002Fh2>\n\u003Cp>工具是 MCP 服务器提供给主机的结构化操作。工具具有名称、描述和输入模式；现代实现还可以提供结构化输出。\u003C\u002Fp>\n\u003Cp>示例包括搜索仓库、读取客户记录、创建工单、运行构建或发送消息。工具可以是只读的，也可以具有副作用。\u003C\u002Fp>\n\u003Cp>良好的 MCP 工具界面应代表连贯的用户或代理目标，而不是机械地镜像每个内部 API 端点。具有不同权限、确认要求或影响范围的操作通常应作为单独的工具。\u003C\u002Fp>\n\u003Ch2 id=\"section-30\">资源：可读的上下文和数据\u003C\u002Fh2>\n\u003Cp>资源暴露客户端可以列出或读取的数据或内容。当语义操作是“给我这个工件或信息”而不是“执行这个动作”时，它们自然适用。\u003C\u002Fp>\n\u003Cp>资源 URI 不是授权许可。服务器仍然拥有访问控制权，并且必须验证哪个主体可以读取底层对象。\u003C\u002Fp>\n\u003Cp>2026-07-28 协议修订版为列表和资源读取响应增加了缓存语义，包括新鲜度和缓存范围，使缓存行为更加明确。\u003C\u002Fp>\n\u003Ch2 id=\"section-34\">提示词：可复用模板\u003C\u002Fh2>\n\u003Cp>MCP 提示词允许服务器向兼容的客户端发布可复用的提示词模板。这可以使特定领域的指令靠近能力提供者。\u003C\u002Fp>\n\u003Cp>MCP 服务器提供的提示词不会自动优先于主机的系统或安全指令。主机决定提示词材料如何进入其上下文层次结构。\u003C\u002Fp>\n\u003Cp>因此，协议提供的提示内容应被视为具有明确信任语义的能力数据，而不是不受限制的指令权限。\u003C\u002Fp>\n\u003Ch2 id=\"section-38\">工具还是资源？\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">需求\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">优先选择\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">使用结构化参数执行操作\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">读取特定的稳定产物\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">资源\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">动态搜索或计算\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">通常为工具\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">修改外部状态\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">打包可复用的提示指令\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">提示\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">长时间运行的异步执行\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具加上应用程序\u002F运行时任务处理或 MCP 扩展\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-40\">AI 模型在哪里？\u003C\u002Fh2>\n\u003Cp>MCP 不要求模型在 MCP 服务器上运行。模型可以托管在云端、本地托管、嵌入桌面应用程序中，或通过其他提供商访问。\u003C\u002Fp>\n\u003Cp>主机通常负责模型交互。MCP 服务器暴露外部能力。因此，本地 MCP 服务器可以被模型运行在云端的主机使用，而远程 MCP 服务器也可以被模型运行在本地的主机使用。\u003C\u002Fp>\n\u003Cp>如果 MCP 服务器本身在内部调用 LLM，该模型是协议边界之后服务器实现的一部分；MCP 并不要求这样做。\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--success my-6 rounded-xl border p-5 border-emerald-300 bg-emerald-50 dark:border-emerald-900 dark:bg-emerald-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">协议位置 ≠ 推理位置\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">\u003Cstrong>本地 MCP 并不意味着本地推理，远程 MCP 也不意味着远程推理。\u003C\u002Fstrong>连接位置、工具执行位置和模型\u002F提供商位置是独立的架构维度。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-45\">MCP 不会取代 API\u003C\u002Fh2>\n\u003Cp>MCP 服务器通常封装现有的 API 或服务。REST、GraphQL、SQL、SDK 调用和内部服务契约可以保持原样。\u003C\u002Fp>\n\u003Cp>MCP 增加了一个面向 AI 的互操作性层。底层领域 API 仍然可以作为普通确定性客户端的权威应用程序契约。\u003C\u002Fp>\n\u003Cp>因此，通常的架构是 API\u002F服务优先，选定的面向 AI 的能力其次——而不是“用 MCP 替换所有 API”。\u003C\u002Fp>\n\u003Ch2 id=\"section-49\">MCP 与函数调用\u003C\u002Fh2>\n\u003Csection class=\"editorjs-comparison my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">函数调用和 MCP 相关但不完全相同\u003C\u002Fh3>\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left dark:border-gray-700 dark:bg-gray-900\">\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">函数调用\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">MCP\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">范围\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">工具定义\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">可移植性\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">它们可以共存吗？\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Cp>OpenAI 目前将远程 MCP 服务器作为一种工具类型，与普通函数调用、网络搜索、shell 和其他工具并列。该实现说明了架构关系：MCP 连接和模型自身的工具调用接口可以组合使用。\u003C\u002Fp>\n\u003Ch2 id=\"section-52\">MCP 不会创建代理循环\u003C\u002Fh2>\n\u003Cp>AI 代理需要一个运行时，能够决策、调用工具、观察结果、更新状态并继续或停止。MCP 可以提供该循环使用的一些工具和数据。\u003C\u002Fp>\n\u003Cp>MCP 服务器不会自动成为规划器、记忆系统或编排器。这些职责通常保留在主机或代理运行时中。\u003C\u002Fp>\n\u003Cp>非代理型应用程序也可以使用 MCP。一次确定性的 MCP 工具调用并不需要自主的多步骤代理。\u003C\u002Fp>\n\u003Ch2 id=\"section-56\">MCP 与 A2A\u003C\u002Fh2>\n\u003Cp>MCP 主要将 AI 主机或代理连接到工具、资源和数据等能力。A2A 则面向独立代理系统之间的协作。\u003C\u002Fp>\n\u003Cp>远程代理可以在内部使用 MCP 访问数据库和工具，同时向其他代理暴露 A2A 接口。因此，这些协议可以分层使用，而不是相互替代。\u003C\u002Fp>\n\u003Cp>现有的协议栈文章负责更广泛的 MCP\u002FA2A\u002FUCP\u002FAP2\u002FA2UI 对比；G02 仍是 MCP 的规范定义。\u003C\u002Fp>\n\u003Caside class=\"editorjs-referral my-6\">\u003Ca href=\"https:\u002F\u002Fstajic.de\u002Fde\u002Fblog\u002Fmcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained\" class=\"flex flex-col sm:flex-row gap-4 rounded-xl border border-gray-200 dark:border-gray-700 p-4 transition hover:border-primary-500\">\u003Cdiv class=\"min-w-0 flex-1\">\u003Cstrong class=\"block text-lg text-gray-900 dark:text-gray-100\">MCP vs A2A vs UCP vs AP2 vs A2UI：代理协议栈详解\u003C\u002Fstrong>\u003Cp class=\"mt-2 text-sm text-gray-600 dark:text-gray-300\">一份更广泛的职责映射，展示 MCP 如何与代理协作、商务、支付授权和代理驱动 UI 协议组合。\u003C\u002Fp>\u003Cspan class=\"mt-3 inline-flex text-sm font-medium text-primary-600 dark:text-primary-400\">阅读协议栈 →\u003C\u002Fspan>\u003C\u002Fdiv>\u003C\u002Fa>\u003C\u002Faside>\n\u003Ch2 id=\"section-61\">本地和远程 MCP 使用不同的传输现实\u003C\u002Fh2>\n\u003Cp>MCP 可以连接到本地和远程服务器。本地桌面集成通常使用进程级传输，例如 stdio；远程服务器则使用面向 HTTP 的传输。\u003C\u002Fp>\n\u003Cp>2026-07-28 修订版使协议核心变为无状态。请求携带协议处理所需的信息，而不再依赖早期的协议级会话模型。\u003C\u002Fp>\n\u003Cp>当前修订版还将方法和能力名称放入 HTTP 头，使网关、WAF、限流器和负载均衡器能够更自然地路由和计量 MCP 流量。\u003C\u002Fp>\n\u003Ch2 id=\"section-65\">为什么 MCP 版本感知很重要\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">协议时代\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">运行特征\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">2025-11-25 及更早\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">面向握手\u002F会话的生命周期和较旧的 Streamable HTTP 行为\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">2026-07-28\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">无状态核心、可选服务器发现、自描述请求、路由头、缓存提示、MRTR 和授权强化\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">扩展\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Tasks 和 MCP Apps 等能力可以独立于基础协议进行版本管理\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>SDK 版本和协议版本也是不同的东西。当前的 TypeScript v2 SDK 是 2026-07-28 修订版的稳定线，而较旧的 v1.x 仍是 2025 时代行为的维护线。\u003C\u002Fp>\n\u003Cp>当互操作性行为依赖于 SDK\u002F库版本和协议修订版时，架构文档应同时记录两者。\u003C\u002Fp>\n\u003Ch2 id=\"section-69\">MCP 2026-07-28 有哪些变化\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">变化\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">为什么重要\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">无状态核心\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">远程服务器可以在普通负载均衡器后扩展，而无需协议级粘性会话\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">server\u002Fdiscover\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">客户端可以在需要时检查服务器能力\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自描述请求\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">协议版本和客户端能力元数据随每个请求传递\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Mcp-Method \u002F Mcp-Name 头\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">网关无需解析正文即可路由、计量和应用策略\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">缓存提示\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">列表\u002F资源读取传达新鲜度和共享范围\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">多轮往返请求\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">服务器可以要求额外输入，而无需旧的双向请求模型\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">授权强化\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">颁发者验证和凭据绑定强化远程认证行为\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">扩展框架\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Tasks、MCP Apps 和其他能力可以独立演进\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-71\">Roots、采样和日志记录不再是新实现的方向\u003C\u002Fh2>\n\u003Cp>2026-07-28 版本将 roots、采样和日志记录标记为已弃用的协议能力，并设定了明确的兼容窗口。\u003C\u002Fp>\n\u003Cp>较旧的教程可能仍将这些功能展示为核心原语。新的实现工作应遵循当前规范，而不是盲目复制旧的生命周期图。\u003C\u002Fp>\n\u003Cp>弃用并不意味着立即移除。它意味着新系统应避免对协议正在淘汰的能力产生不必要的新依赖。\u003C\u002Fp>\n\u003Ch2 id=\"section-75\">长时间运行的工作与普通的 MCP 工具调用不同\u003C\u002Fh2>\n\u003Cp>长时间运行的操作需要超越简单即时工具结果的生命周期语义。在当前生态系统中，Tasks 已移入专门的 MCP 扩展。\u003C\u002Fp>\n\u003Cp>这强化了一个有用的设计原则：基础协议不需要吸收每一个代理运行时关注点。\u003C\u002Fp>\n\u003Cp>应用程序也可以将长时间运行的工作流所有权完全保留在自己的运行时中，并使用普通的 MCP 工具作为底层操作。\u003C\u002Fp>\n\u003Ch2 id=\"section-79\">MCP Apps 扩展 UI 能力而不重新定义核心协议\u003C\u002Fh2>\n\u003Cp>MCP Apps 通过扩展模型将更丰富的交互式 UI 体验与 MCP 工具关联起来。\u003C\u002Fp>\n\u003Cp>宿主仍然控制该 UI 的嵌入、沙箱化和安全保护方式。\u003C\u002Fp>\n\u003Cp>因此，核心能力交换和 UI 渲染应保持为独立的架构职责。\u003C\u002Fp>\n\u003Ch2 id=\"section-83\">MCP 授权不是您完整的授权模型\u003C\u002Fh2>\n\u003Cp>远程 MCP 需要协议级别的身份验证和授权机制，以便客户端和服务器能够建立可信访问。当前规范继续强化 OAuth\u002FOIDC 相关行为。\u003C\u002Fp>\n\u003Cp>该层回答的是客户端是否被允许连接或请求协议范围。它不会自动回答 Alice 是否可以退款订单 123、代理是否可以写入生产配置，或租户 A 是否可以读取租户 B 的数据。\u003C\u002Fp>\n\u003Cp>这些领域决策属于服务器\u002F应用程序授权模型，并且必须在调用底层操作之前强制执行。\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--warning my-6 rounded-xl border p-5 border-amber-300 bg-amber-50 dark:border-amber-900 dark:bg-amber-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">切勿将“已认证的 MCP 客户端”映射为“对所有工具都受信任”\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">连接信任、工具可见性、工具权限、用户授权、租户隔离和业务审批是不同的控制措施。请将它们分开。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-88\">身份可以跨越多个边界\u003C\u002Fh2>\n\u003Cp>一个 MCP 请求可能涉及 MCP 客户端应用程序、已登录的人类用户、代理\u002F会话身份以及下游服务账户。\u003C\u002Fp>\n\u003Cp>服务器需要明确的策略来确定操作代表哪个主体执行。否则，强大的服务凭证可能成为混淆代理路径。\u003C\u002Fp>\n\u003Cp>对于企业使用而言，用户身份、代理身份、MCP 连接与下游授权之间的关联，与协议兼容性同样重要。\u003C\u002Fp>\n\u003Ch2 id=\"section-92\">租户隔离仍处于 MCP 能力发现范围之外\u003C\u002Fh2>\n\u003Cp>多租户 MCP 服务器在读取或更改租户拥有的资源时，必须应用租户范围。返回一个名为 search_documents 的工具，并不能定义哪些租户的文档符合条件。\u003C\u002Fp>\n\u003Cp>租户范围应源自可信身份或成员关系，并传递到数据库、缓存、向量搜索、对象存储和下游 API 中。\u003C\u002Fp>\n\u003Cp>检索跨租户内容，然后要求模型不要使用它，这本身就已经是隔离失败。\u003C\u002Fp>\n\u003Ch2 id=\"section-96\">MCP 未定义事实来源\u003C\u002Fh2>\n\u003Cp>MCP 服务器可以暴露数据库、文档存储库、网络搜索服务或 AI 生成的摘要。协议并未声明哪个来源对某项主张具有权威性。\u003C\u002Fp>\n\u003Cp>事实来源规则属于应用\u002F领域架构。主机或服务器可以通过工具设计、元数据、访问策略或验证来编码权威性，但 MCP 本身并不会让某个能力变得“真实”。\u003C\u002Fp>\n\u003Cp>因此，一个工具可以通过 MCP 完全可调用，却仍然返回过时、次要或非权威的信息。\u003C\u002Fp>\n\u003Ch2 id=\"section-100\">MCP 与上下文工程\u003C\u002Fh2>\n\u003Cp>MCP 可以增加 AI 应用可用的能力和信息，但上下文工程仍然决定什么内容会到达模型。\u003C\u002Fp>\n\u003Cp>在许多主机中，工具目录会消耗模型可见的上下文。工具结果可能很大。资源可能很多。主机需要选择、过滤、动态加载和压缩，而不是在每一轮都暴露所有内容。\u003C\u002Fp>\n\u003Cp>因此，能力可用性和模型可见上下文应被视为不同的层。\u003C\u002Fp>\n\u003Ch2 id=\"section-104\">围绕结果和风险边界设计 MCP 工具\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">较弱的工具设计\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">更强的工具设计\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">execute_api(method,url,body)\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">具有经过验证操作的窄领域工具\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">一个管理工具处理所有操作\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">分离读\u002F写\u002F审批操作\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">原始内部 API 一比一镜像\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">围绕一致用户目标的 AI 面向契约\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">一个宽泛的文件系统工具\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工作区范围的读\u002F写操作\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">安全策略仅存在于描述中\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">服务器在代码中强制执行策略\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">无限制的原始响应\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">结构化的决策相关输出\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">删除\u002F更新与读取混合\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">具有确认策略的独立副作用工具\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-106\">审批属于执行架构\u003C\u002Fh2>\n\u003Cp>主机可以在调用选定的 MCP 工具之前要求用户批准。OpenAI 当前的 MCP 集成支持自动或显式批准的执行模式。\u003C\u002Fp>\n\u003Cp>主机批准很有用，但不应成为服务器的唯一保护，因为另一个兼容的 MCP 客户端可能使用不同的批准模型。\u003C\u002Fp>\n\u003Cp>对于破坏性或具有财务影响的行动，应采用纵深防御：清晰的工具契约、适当的运行时审批、服务端授权、业务校验和审计。\u003C\u002Fp>\n\u003Ch2 id=\"section-110\">MCP 可观测性应将协议调用与领域操作关联起来\u003C\u002Fh2>\n\u003Cp>当 MCP 追踪能够与底层应用调用、数据库变更或业务事务相关联时，其价值最大。\u003C\u002Fp>\n\u003Cp>2026-07-28 生态系统标准化了 W3C Trace Context 传播约定，使得跨主机、客户端、服务端和下游服务跟踪请求变得更加容易。\u003C\u002Fp>\n\u003Cp>仅靠协议日志不足以应对具有重大影响的操怍。审计证据还应记录相关主体、租户、目标资源、审批以及由此产生的状态变更。\u003C\u002Fp>\n\u003Ch2 id=\"section-114\">MCP 无法解决的问题\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">问题\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">MCP 为何无法解决\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">糟糕的业务 API\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">MCP 可以更一致地暴露这个糟糕的 API\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">错误的数据\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">协议有效性并不产生事实正确性\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">缺少租户隔离\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具发现并不强制资源所有权\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">权限过大\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">标准化的工具仍然可能权限过大\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">糟糕的智能体规划\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">MCP 暴露能力；运行时\u002F模型仍然决定如何使用它们\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">糟糕的重试\u002F幂等设计\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">协议调用并不能使副作用变得安全\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">没有单一事实来源\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">MCP 不决定哪个系统拥有某个事实\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">薄弱的评估\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">互操作性并不证明任务成功\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">没有审计策略\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">传输追踪并不定义保留期限或问责机制\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">协议不匹配\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">旧\u002F新版本仍然可能需要迁移或兼容性处理\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-116\">原始实现证据：Aaasaasa AI Client\u003C\u002Fh2>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">实现证据\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">Aaasaasa AI Client 包含一个经过身份验证的本地 MCP 连接器\u002F代理，用于已批准的本地目录，并通过 Secure MCP Tunnel 进行集成。这是协议边界和权限架构的具体实现证据，并非声称其为通用商业 MCP 平台。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cp>该应用可以在回环地址上运行经过身份验证的 Streamable HTTP MCP 端点。该端点仅暴露通过中央工作区权限代理选择的目录。\u003C\u002Fp>\n\u003Cp>本地端点和远程路由是相互独立的关注点：本地连接器可以仅绑定到回环地址，而 Secure MCP Tunnel 可以使已批准的 MCP 服务对获准的外部 AI 客户端可达，同时不暴露整个本地机器。\u003C\u002Fp>\n\u003Cp>中央权限模型区分仅聊天、只读、项目写入和自定义目录配置文件。Direct Chat 没有文件系统或 shell 访问权限；具备工具能力的智能体运行时使用所选的权限配置文件。\u003C\u002Fp>\n\u003Cp>这是 G02 边界的直接实现：MCP 提供标准化的能力连接，而应用自有的权限代理决定服务器可以暴露哪些目录。\u003C\u002Fp>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">已实现的元素\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">架构证据\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">经过身份验证的本地 MCP 端点\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">MCP 服务器可以是本地确定性的能力服务\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">回环绑定\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">网络暴露和协议能力是相互独立的决策\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Secure MCP Tunnel 集成\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">私有\u002F本地 MCP 可以通过受控路由进行桥接\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">中央权限代理\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">MCP 能力受应用策略约束\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">选定的目录范围\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">文件系统可见性被明确限定\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">无操作系统工具的 Direct Chat\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型访问并不自动意味着工具访问\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Caside class=\"editorjs-callout editorjs-callout--warning my-6 rounded-xl border p-5 border-amber-300 bg-amber-50 dark:border-amber-900 dark:bg-amber-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">证据边界\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">该实现展示了 MCP 连接性和权限范围内的本地目录暴露。它并不意味着每个 MCP 原语、每个 2026-07-28 特性或每个企业授权扩展都已实现。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-124\">MCP 何时适合使用\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">MCP 非常适合的情况\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">直接集成可能更简单的情况\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">同一能力应在多个 AI 主机之间可复用\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">一个应用拥有两端，可移植性价值不大\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">外部系统希望发布可发现的面向 AI 的工具\u002F资源\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">单个稳定的内部 API 调用就足够了\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">你希望围绕本地工具\u002F数据建立标准边界\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">没有面向 AI 的互操作性需求\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具提供者和 AI 客户端独立演进\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">集成是有意私有且紧密耦合的\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">你希望实现生态系统兼容的能力发现\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">能力集很小且固定在应用代码中\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-126\">何时不需要 MCP\u003C\u002Fh2>\n\u003Cp>不要仅仅因为应用程序使用了 AI 就添加 MCP。如果你的后端已经调用了一个内部 API，并且没有独立的 MCP 客户端需要该能力，那么普通的函数或服务调用可能更清晰。\u003C\u002Fp>\n\u003Cp>MCP 在互操作性边界处增加价值。没有该边界，协议可能变成一个不必要的适配层。\u003C\u002Fp>\n\u003Cp>架构问题不是“这个项目有 AI 吗？”，而是“独立演进的 AI 主机和能力提供者是否能从标准契约中受益？”\u003C\u002Fp>\n\u003Ch2 id=\"section-130\">MCP 安全检查清单\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">边界\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">问题\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">服务器身份\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">我实际连接的是哪个 MCP 服务器？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">客户端身份\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">哪个应用程序\u002F客户端在请求访问？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">最终用户身份\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">操作是代表谁执行的？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具允许列表\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">此主机\u002F代理可以发现和调用哪些能力？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">业务权限\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">此主体可以执行此操作吗？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">租户范围\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">适用哪个租户\u002F资源边界？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">凭证隔离\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">凭证是否正确绑定并保持在模型上下文之外？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">审批\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">哪些副作用需要人工确认？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">输入验证\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具参数是否独立于模型输出进行验证？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">输出信任\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">返回的内容是否可能包含不受信任的指令或敏感数据？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">网络暴露\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地服务器是否意外暴露在预期接口之外？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">审计\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">协议调用能否与下游操作关联？\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-132\">常见误解\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">误解\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">纠正\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“MCP 服务器是 AI 服务器。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">它可以是暴露能力的普通确定性软件。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“我需要在 MCP 服务器上运行自己的 LLM。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">不。模型可以完全位于主机侧。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“MCP 取代 REST API。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">MCP 通常包装现有 API 以实现面向 AI 的互操作性。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“MCP 是一个代理框架。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">MCP 提供能力；代理运行时管理迭代和状态。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“MCP 和函数调用相互竞争。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">主机可以将 MCP 能力桥接到其模型工具接口中。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“MCP 取代 A2A。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">MCP 专注于能力集成；A2A 专注于代理协作。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“如果工具被列出，用户就可以调用它。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">发现不等于授权。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“OAuth 解决业务权限问题。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">连接授权不能取代域授权或租户隔离。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“本地 MCP 意味着本地 AI。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具服务器位置和推理位置是独立的。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“MCP 使工具输出可信。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据质量、权威性和来源仍然属于源\u002F应用程序。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“一个巨大的通用工具很灵活。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">过于宽泛的工具会削弱权限、验证和可观测性。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“旧教程与当前实现一致。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">2026-07-28 修订版实质性改变了生命周期和传输行为。\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-134\">实用的 MCP 设计顺序\u003C\u002Fh2>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">在实现服务器之前设计边界\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. 确定互操作性边界\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">确认独立的 AI 主机确实需要可重用访问。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. 保持域 API 权威\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在 MCP 背后保留真实的应用程序\u002F服务契约。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. 有意识地选择原语\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">根据语义使用工具、资源和提示。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. 按风险和权限拆分\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">分离读取、写入、破坏性和需要审批的操作。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. 定义身份传播\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">了解每次调用代表哪个客户端、用户、代理和下游主体。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. 执行业务授权\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">验证权限、租户范围和目标所有权。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. 选择本地或远程传输\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">使部署拓扑与实际需求匹配。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">8\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">8. 固定协议\u002FSDK 预期\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">记录 2026-07-28 与旧版本的兼容性。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">9\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">9. 为重要操作添加审批\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">使用与风险相适应的确认控制。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">10\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">10. 设计结构化输出\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">返回简洁的机器可用结果。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">11\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">11. 添加跟踪和审计关联\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">将 MCP 调用连接到下游服务\u002F业务事件。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">12\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">12. 测试可移植性\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在互操作性为明确要求时，验证多个客户端。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-136\">MCP 架构检查清单\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">问题\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">预期答案\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">为什么需要 MCP？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">真实的面向 AI 的互操作性边界\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">服务器暴露什么？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">明确的工具\u002F资源\u002F提示\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型在哪里运行？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">独立的主机\u002F提供者决定\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具执行在哪里运行？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">命名的服务器\u002F运行时位置\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">预期使用哪个协议修订版？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">版本感知的契约\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">请求主体是谁？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">客户端\u002F用户\u002F代理身份模型\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可以发现哪些工具？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">允许列表\u002F能力策略\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可以执行哪些操作？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">服务器端业务授权\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">如何强制执行租户\u002F资源范围？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可信的租户\u002F资源所有权检查\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">哪些操作需要审批？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">基于风险的确认策略\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">如何保护凭证？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可信运行时存储，而非模型可见的机密\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">如何限制输出？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">结构化相关结果契约\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">如何跟踪调用？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">通过 MCP 到下游操作的关联\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">如果 MCP 不可用会发生什么？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">定义的降级\u002F失败行为\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">另一个兼容主机可以使用它吗？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">在需要时验证可移植性\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-138\">边缘情况和限制\u003C\u002Fh2>\n\u003Cp>本地 stdio MCP 服务器可能几乎没有网络暴露，但如果进程本身具有过多的文件系统或 shell 权限，仍然可能很危险。\u003C\u002Fp>\n\u003Cp>远程 MCP 服务器可能只暴露公共文档或高度敏感的企业操作。如果没有能力和授权上下文，“远程 MCP”几乎不能说明风险。\u003C\u002Fp>\n\u003Cp>一些服务器可能只使用工具而忽略资源\u002F提示。MCP 兼容性并不要求每个可选原语都同等重要。\u003C\u002Fp>\n\u003Cp>主机可以在其内部工具模型和 MCP 之间进行转换。用户可能永远不会直接看到协议边界，只要安全性和归属仍然清晰，这是可以接受的。\u003C\u002Fp>\n\u003Cp>MCP 继续快速发展。扩展、授权模式、SDK API 和生态系统约定可能比核心架构区别变化得更快。\u003C\u002Fp>\n\u003Ch2 id=\"section-144\">什么会改变这个答案？\u003C\u002Fh2>\n\u003Cp>未来的 MCP 修订可能会改变生命周期、传输方式、授权和扩展机制。2026 年 7 月的修订已经表明，为什么特定于实现的声明必须注明日期。\u003C\u002Fp>\n\u003Cp>只有当 MCP 从互操作性协议扩展为端到端应用\u002F代理架构标准时，其规范边界才会改变。而当前协议定义的并非如此。\u003C\u002Fp>\n\u003Cp>对于实现工作，应始终检查当前规范和确切的 SDK 版本，而不是从旧教程中复制对版本敏感的示例。\u003C\u002Fp>\n\u003Ch2 id=\"section-148\">相关规范知识\u003C\u002Fh2>\n\u003Cp>MCP 属于 Agentic AI 的下游：首先理解代理\u002F运行时\u002F工具边界，然后当外部能力需要可移植的协议契约时使用 MCP。\u003C\u002Fp>\n\u003Cp>MCP 还依赖于 RBAC 和租户隔离，因为协议级别的能力暴露并不决定应用授权。\u003C\u002Fp>\n\u003Cp>更广泛的协议栈文章解释了 MCP 与 A2A、UCP、AP2 和 A2UI 并列的位置。G02 仍然是 MCP 本身的规范来源。\u003C\u002Fp>\n\u003Caside class=\"editorjs-referral my-6\">\u003Ca href=\"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fai-agent-reliability-why-the-final-answer-is-not-enough\" class=\"flex flex-col sm:flex-row gap-4 rounded-xl border border-gray-200 dark:border-gray-700 p-4 transition hover:border-primary-500\">\u003Cdiv class=\"min-w-0 flex-1\">\u003Cstrong class=\"block text-lg text-gray-900 dark:text-gray-100\">AI 代理可靠性：为什么最终答案还不够\u003C\u002Fstrong>\u003Cp class=\"mt-2 text-sm text-gray-600 dark:text-gray-300\">MCP 工具调用成为代理轨迹的一部分；可靠的系统需要评估动作和观察结果，而不仅仅是最终文本。\u003C\u002Fp>\u003Cspan class=\"mt-3 inline-flex text-sm font-medium text-primary-600 dark:text-primary-400\">阅读代理可靠性文章 →\u003C\u002Fspan>\u003C\u002Fdiv>\u003C\u002Fa>\u003C\u002Faside>\n\u003Ch2 id=\"section-153\">常见问题\u003C\u002Fh2>\n\u003Csection class=\"editorjs-faq my-6 rounded-xl border border-gray-200 p-5 dark:border-gray-700\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">模型上下文协议常见问题\u003C\u002Fh3>\u003Cdiv id=\"faq1\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">什么是 MCP？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">模型上下文协议是一种开放的客户端-服务器协议，用于通过标准化契约将 AI 应用连接到外部工具、资源、提示和能力提供者。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq2\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">MCP 服务器需要 AI 模型吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不需要。MCP 服务器可以是完全确定性的软件。模型通常在 AI 主机或代理运行时中运行，尽管服务器可以选择在内部使用 AI。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq3\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">MCP 客户端和服务器有什么区别？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">客户端是 AI 主机用于与能力提供者通信的协议组件。服务器发布并执行其暴露的能力。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq4\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">MCP 会取代函数调用吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不会。函数\u002F工具调用是模型调用已配置能力的方式。MCP 标准化了与外部能力服务器的发现和通信。主机可以桥接两者。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq5\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">MCP 会取代 REST API 吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不会。MCP 服务器经常包装现有的 REST、GraphQL、数据库或服务 API，并提供面向 AI 的互操作性层。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq6\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">MCP 是代理框架吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不是。MCP 暴露能力。代理规划、状态、记忆、上下文管理、重试、编排和停止属于周围的运行时。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq7\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">MCP 和 A2A 有什么区别？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">MCP 主要将 AI 主机或代理连接到工具和数据提供者。A2A 连接独立的代理系统以进行协作和委托。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq8\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">MCP 处理授权吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">MCP 包含协议级别的授权机制，尤其是对于远程服务器，但应用仍必须执行业务权限、资源所有权和租户隔离。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq9\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">MCP 可以与本地模型一起使用吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">可以。模型位置与 MCP 无关。本地模型主机可以调用本地或远程 MCP 服务器，云模型主机可以通过适当的连接架构使用经批准的本地或远程 MCP 服务器。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq10\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">当前的 MCP 规范版本是什么？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">截至 2026 年 10 月 8 日，当前规范修订版为 2026-07-28。较旧的 2025 时代实现仍在使用，因此必须检查兼容性。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-155\">术语表\u003C\u002Fh2>\n\u003Csection class=\"editorjs-glossary my-6 rounded-xl border border-gray-200 dark:border-gray-700 p-5\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">关键 MCP 术语\u003C\u002Fh3>\u003Cdl>\u003Cdiv id=\"mcp\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">MCP\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">模型上下文协议，一种用于 AI 主机\u002F客户端与外部能力服务器之间互操作连接的开放协议。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"mcp-host\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">MCP 主机\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">拥有模型交互并使用 MCP 客户端连接到服务器的 AI 应用或运行时。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"mcp-client\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">MCP 客户端\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">主机侧与 MCP 服务器通信的协议组件。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"mcp-server\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">MCP 服务器\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">实现 MCP 并暴露工具、资源、提示或受支持扩展的能力提供者。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"mcp-tool\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">工具\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">由 MCP 服务器暴露的可调用结构化能力。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"mcp-resource\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">资源\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">通过 MCP 资源方法暴露的可读数据或内容。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"mcp-prompt\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">提示\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">由 MCP 服务器为兼容主机暴露的可重用提示模板。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"streamable-http\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">可流式 HTTP\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">用于远程\u002F网络服务器通信的面向 HTTP 的 MCP 传输。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"stdio\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">stdio\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">常用于本地 MCP 服务器集成的进程标准输入\u002F输出传输。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"server-discover\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">server\u002Fdiscover\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">现代 MCP 方法，允许客户端在 2026-07-28 协议时代检查服务器能力。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"mrtr\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">MRTR\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">多轮往返请求，一种在 2026-07-28 协议时代在请求期间获取额外输入的机制。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"mcp-extension\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">MCP 扩展\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">与基础协议组合且可以单独演进\u002F版本化的能力，例如 Tasks 或 MCP Apps。\u003C\u002Fdd>\u003C\u002Fdiv>\u003C\u002Fdl>\u003C\u002Fsection>\n\u003Ch2 id=\"section-157\">结论\u003C\u002Fh2>\n\u003Cp>当 MCP 的边界保持狭窄时最容易理解：它通过标准协议将 AI 应用连接到外部能力。\u003C\u002Fp>\n\u003Cp>模型不必位于 MCP 服务器上。服务器不会成为代理运行时。列出的工具不会成为已授权的业务操作。而且 MCP 不会取代底层 API、真相来源、租户隔离或领域架构。\u003C\u002Fp>\n\u003Cp>这种狭窄性正是该协议的优势。MCP 可以标准化 AI 系统访问工具和数据的方式，同时将应用所有权、安全性、业务语义和模型选择留给真正拥有它们的层。\u003C\u002Fp>\n\u003Ch2 id=\"section-161\">主要来源和当前文档\u003C\u002Fh2>\n\u003Cp>MCP 发展迅速，因此本文中对版本敏感的声明均以 2026 年 10 月 8 日的状态为准。Aaasaasa AI Client 部分是原始实现证据，并明确限于已验证的 MCP 连接器和权限代理范围。\u003C\u002Fp>\n\u003Ca href=\"https:\u002F\u002Fts.sdk.modelcontextprotocol.io\u002Fv2\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">模型上下文协议 — TypeScript SDK v2\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">当前稳定的 TypeScript SDK 文档，实现了 2026-07-28 MCP 规范以及服务器\u002F客户端原语。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fblog.modelcontextprotocol.io\u002Fposts\u002F2026-07-28\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">模型上下文协议 — 2026-07-28 规范发布\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">当前 MCP 协议修订版的官方发布说明，包括无状态核心、MRTR、路由、缓存、授权加固、扩展和弃用。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fts.sdk.modelcontextprotocol.io\u002Fv2\u002Fmigration\u002Fsupport-2026-07-28\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">MCP TypeScript SDK — 支持协议修订版 2026-07-28\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">针对当前协议修订版及早期版本兼容性的特定版本实现指南。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Ftools-connectors-mcp\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">OpenAI — MCP 服务器\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">OpenAI 当前关于通过 Secure MCP Tunnel 将模型连接到远程 MCP 服务器以及本地\u002F私有 MCP 服务器的指南。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents-api\u002Ftools\u002Fmcp\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">OpenAI — Agents API 的 MCP 连接\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">当前 MCP 连接指南，涵盖服务、环境和 stdio 位置以及允许工具控制。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Ftools\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">OpenAI — 工具\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">当前概述，将远程 MCP 服务器与函数调用、网络搜索、shell 和其他模型工具并列。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdevelopers.openai.com\u002Fplugins\u002Fconcepts\u002Fmcp-server\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">OpenAI — MCP 服务器概念\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">当前关于 MCP 服务器暴露工具、资源和提示以用于外部服务集成的描述。\u003C\u002Fp>\u003C\u002Fa>",{"time":212,"blocks":213,"version":1606},1791487062190,[214,220,228,235,242,249,257,262,267,272,277,282,287,292,297,326,331,336,341,346,351,378,383,388,393,427,432,437,442,447,452,457,462,467,472,477,482,487,492,515,520,525,530,535,541,546,551,556,561,566,595,600,605,610,615,620,625,630,635,640,649,654,659,664,669,674,691,696,701,706,738,743,748,753,758,763,768,773,778,783,788,793,798,803,808,813,818,824,829,834,839,844,849,854,859,864,869,874,879,884,889,894,899,904,909,938,943,948,953,958,963,968,973,978,983,1021,1026,1032,1037,1042,1047,1052,1078,1084,1089,1112,1117,1122,1127,1132,1137,1180,1185,1229,1234,1276,1281,1333,1338,1343,1348,1353,1358,1363,1368,1373,1378,1383,1388,1393,1398,1403,1411,1416,1462,1467,1512,1517,1522,1527,1532,1537,1542,1552,1561,1570,1579,1588,1597],{"id":215,"data":216,"type":218,"tunes":219},"intro",{"text":217},"模型上下文协议（MCP）是一种开放协议，用于通过标准化的客户端-服务器契约将 AI 应用程序连接到外部能力和信息。MCP 服务器可以暴露工具、资源和提示；兼容 MCP 的主机或客户端代表 AI 应用程序发现并使用这些能力。MCP 不要求服务器运行自己的语言模型，也不取代所暴露能力背后的代理运行时、业务授权、租户隔离、应用程序 API 或领域架构。","paragraph",{},{"id":221,"data":222,"type":226,"tunes":227},"direct",{"body":223,"title":224,"variant":225},"\u003Cstrong>MCP 标准化了 AI 主机与外部能力提供者之间的边界。\u003C\u002Fstrong>\u003Cbr>\u003Cbr>一个有用的心智模型是：\u003Cbr>\u003Cstrong>用户 → AI 主机 \u002F 代理运行时 → MCP 客户端 → MCP 服务器 → 应用程序\u002FAPI\u002F数据\u002F工具\u003C\u002Fstrong>。\u003Cbr>\u003Cbr>模型可以完全保留在主机侧。MCP 服务器可以是暴露结构化能力的普通确定性软件。","直接回答","info","callout",{},{"id":229,"data":230,"type":226,"tunes":234},"server-no-ai",{"body":231,"title":232,"variant":233},"文件系统 MCP 服务器可以列出或读取文件。数据库 MCP 服务器可以运行经批准的查询。Jira MCP 服务器可以暴露问题操作。这些服务器都不需要 LLM 来满足 MCP 契约。如果服务器内部使用 AI，那是协议边界背后的实现选择，而不是 MCP 的要求。","MCP 服务器不需要自己的 AI 模型","success",{},{"id":236,"data":237,"type":226,"tunes":241},"boundary",{"body":238,"title":239,"variant":240},"如果 MCP 服务器暴露了 \u003Ccode>delete_file\u003C\u002Fcode>、\u003Ccode>refund_order\u003C\u002Fcode> 或 \u003Ccode>deploy_service\u003C\u002Fcode>，这仅意味着该能力存在。服务器\u002F应用程序仍必须强制执行身份、权限、租户范围、业务规则、确认要求和审计控制。协议发现绝不能悄然变成授权。","MCP 能力不等于业务权限","warning",{},{"id":243,"data":244,"type":226,"tunes":248},"current",{"body":245,"title":246,"variant":247},"当前 MCP 规范修订版是 \u003Cstrong>2026-07-28\u003C\u002Fstrong>。其主要变化是无状态协议核心，具有自描述请求、可选的 \u003Ccode>server\u002Fdiscover\u003C\u002Fcode>、可路由的 HTTP 头、可缓存的列表\u002F资源响应、授权强化以及正式的扩展模型。TypeScript SDK v2 是实现此修订版的当前稳定 SDK 系列。2025 年时代的旧客户端和服务器仍然存在，因此实现指南必须保持版本感知。","当前来源说明 — 2026 年 10 月 8 日","note",{},{"id":250,"data":251,"type":255,"tunes":256},"toc",{"title":252,"maxLevel":253,"minLevel":254},"目录",3,2,"tableOfContents",{},{"id":258,"data":259,"type":42,"tunes":261},"h-meaning",{"text":260,"level":254},"MCP 真正标准化的内容",{},{"id":263,"data":264,"type":218,"tunes":266},"p-meaning-1",{"text":265},"在 MCP 之前，每个 AI 应用程序都可以通过自己的工具模式、插件格式、身份验证约定和连接代码来集成外部系统。同一个服务可能需要为桌面 AI 客户端、IDE 代理和自定义应用程序使用不同的适配器。",{},{"id":268,"data":269,"type":218,"tunes":271},"p-meaning-2",{"text":270},"MCP 创建了一个可复用的协议边界。外部系统通过 MCP 服务器暴露能力，而兼容的 AI 主机实现 MCP 客户端。这减少了 AI 应用程序与底层工具或数据提供者之间的集成耦合。",{},{"id":273,"data":274,"type":218,"tunes":276},"p-meaning-3",{"text":275},"该协议并不标准化整个应用程序。它标准化的是能力在该边界上如何被描述、发现和调用。",{},{"id":278,"data":279,"type":42,"tunes":281},"h-simple",{"text":280,"level":254},"最简单的示例",{},{"id":283,"data":284,"type":218,"tunes":286},"p-simple-1",{"text":285},"假设一个 AI 编码应用程序需要访问本地项目目录。没有 MCP 时，该应用程序可能会直接实现自己的文件系统集成。",{},{"id":288,"data":289,"type":218,"tunes":291},"p-simple-2",{"text":290},"使用 MCP 时，文件系统服务器可以暴露诸如列出目录、读取经批准的文件或在允许的工作区内写入等能力。AI 主机通过 MCP 客户端连接，并将这些能力呈现给模型或代理运行时。",{},{"id":293,"data":294,"type":218,"tunes":296},"p-simple-3",{"text":295},"服务器不需要理解用户的自然语言请求。主机\u002F模型决定哪个能力有用；MCP 服务器根据自身的安全规则执行结构化请求。",{},{"id":298,"data":299,"type":324,"tunes":325},"simple-flow",{"steps":300,"title":322,"orientation":323},[301,304,307,310,313,316,319],{"label":302,"description":303},"1. 主机连接到服务器","支持 MCP 的应用程序配置对外部 MCP 服务器的访问。",{"label":305,"description":306},"2. 发现能力","客户端了解服务器暴露了哪些工具、资源或提示。",{"label":308,"description":309},"3. 模型或运行时选择能力","AI 应用程序决定需要某个已暴露的能力。",{"label":311,"description":312},"4. 客户端发送结构化请求","参数通过 MCP 发送到服务器。",{"label":314,"description":315},"5. 服务器授权并执行","服务器验证请求并调用其底层系统。",{"label":317,"description":318},"6. 结果返回主机","结果成为观察或上下文输入。",{"label":320,"description":321},"7. 主机决定下一步","模型\u002F运行时可以回答、调用另一个工具或继续工作流。","一个基本的 MCP 工具调用","auto","processFlow",{},{"id":327,"data":328,"type":42,"tunes":330},"h-stops",{"text":329,"level":254},"简单示例止步之处",{},{"id":332,"data":333,"type":218,"tunes":335},"p-stops-1",{"text":334},"MCP 不定义主机如何选择工具、代理如何规划、业务工作流如何建模，或发票、部署等领域对象应如何表现。",{},{"id":337,"data":338,"type":218,"tunes":340},"p-stops-2",{"text":339},"协议可以使集成具有互操作性，而底层应用程序仍然不正确、不安全或设计糟糕。一个完全有效的 MCP 请求仍然可能调用错误的业务能力。",{},{"id":342,"data":343,"type":218,"tunes":345},"p-stops-3",{"text":344},"核心边界是：MCP 标准化的是集成语义，而不是应用真相或业务正确性。",{},{"id":347,"data":348,"type":42,"tunes":350},"h-architecture",{"text":349,"level":254},"MCP 架构：主机、客户端和服务器",{},{"id":352,"data":353,"type":376,"tunes":377},"architecture-table",{"content":354,"stretched":43,"withHeadings":14},[355,358,361,364,367,370,373],[356,357],"组件","职责",[359,360],"AI 主机","面向用户的 AI 应用或运行时，负责模型交互、上下文和整体工作流",[362,363],"MCP 客户端","主机用于与 MCP 服务器通信的协议侧组件",[365,366],"MCP 服务器","发布能力并处理 MCP 请求",[368,369],"底层系统","MCP 服务器背后的应用、API、数据库、文件系统、SaaS 平台或服务",[371,372],"模型","根据主机\u002F运行时设计选择或推理能力；它不一定位于 MCP 服务器内部",[374,375],"授权\u002F业务策略","决定请求的操作是否实际被允许","table",{},{"id":379,"data":380,"type":218,"tunes":382},"p-architecture-1",{"text":381},"一个主机可以连接多个 MCP 服务器，而一个 MCP 服务器可以对接一个或多个底层系统。主机仍然负责将 MCP 结果集成到更广泛的 AI 应用中。",{},{"id":384,"data":385,"type":218,"tunes":387},"p-architecture-2",{"text":386},"服务器可以位于主机本地、作为独立进程运行，或通过网络传输远程运行。托管拓扑和模型位置是相互独立的决策。",{},{"id":389,"data":390,"type":42,"tunes":392},"h-primitives",{"text":391,"level":254},"三个核心服务器原语",{},{"id":394,"data":395,"type":425,"tunes":426},"primitives-comparison",{"rows":396,"title":414,"layout":376,"columns":415},[397,402,406,410],{"id":398,"label":399,"values":400},"purpose","主要目的",[401,401,401],"",{"id":403,"label":404,"values":405},"interaction","典型交互",[401,401,401],{"id":407,"label":408,"values":409},"example","示例",[401,401,401],{"id":411,"label":412,"values":413},"risk","典型风险",[401,401,401],"工具、资源和提示词解决不同的需求",[416,419,422],{"id":417,"label":418},"tools","工具",{"id":420,"label":421},"resources","资源",{"id":423,"label":424},"prompts","提示词","comparison",{},{"id":428,"data":429,"type":42,"tunes":431},"h-tools",{"text":430,"level":254},"工具：可调用的能力",{},{"id":433,"data":434,"type":218,"tunes":436},"p-tools-1",{"text":435},"工具是 MCP 服务器提供给主机的结构化操作。工具具有名称、描述和输入模式；现代实现还可以提供结构化输出。",{},{"id":438,"data":439,"type":218,"tunes":441},"p-tools-2",{"text":440},"示例包括搜索仓库、读取客户记录、创建工单、运行构建或发送消息。工具可以是只读的，也可以具有副作用。",{},{"id":443,"data":444,"type":218,"tunes":446},"p-tools-3",{"text":445},"良好的 MCP 工具界面应代表连贯的用户或代理目标，而不是机械地镜像每个内部 API 端点。具有不同权限、确认要求或影响范围的操作通常应作为单独的工具。",{},{"id":448,"data":449,"type":42,"tunes":451},"h-resources",{"text":450,"level":254},"资源：可读的上下文和数据",{},{"id":453,"data":454,"type":218,"tunes":456},"p-res-1",{"text":455},"资源暴露客户端可以列出或读取的数据或内容。当语义操作是“给我这个工件或信息”而不是“执行这个动作”时，它们自然适用。",{},{"id":458,"data":459,"type":218,"tunes":461},"p-res-2",{"text":460},"资源 URI 不是授权许可。服务器仍然拥有访问控制权，并且必须验证哪个主体可以读取底层对象。",{},{"id":463,"data":464,"type":218,"tunes":466},"p-res-3",{"text":465},"2026-07-28 协议修订版为列表和资源读取响应增加了缓存语义，包括新鲜度和缓存范围，使缓存行为更加明确。",{},{"id":468,"data":469,"type":42,"tunes":471},"h-prompts",{"text":470,"level":254},"提示词：可复用模板",{},{"id":473,"data":474,"type":218,"tunes":476},"p-prompts-1",{"text":475},"MCP 提示词允许服务器向兼容的客户端发布可复用的提示词模板。这可以使特定领域的指令靠近能力提供者。",{},{"id":478,"data":479,"type":218,"tunes":481},"p-prompts-2",{"text":480},"MCP 服务器提供的提示词不会自动优先于主机的系统或安全指令。主机决定提示词材料如何进入其上下文层次结构。",{},{"id":483,"data":484,"type":218,"tunes":486},"p-prompts-3",{"text":485},"因此，协议提供的提示内容应被视为具有明确信任语义的能力数据，而不是不受限制的指令权限。",{},{"id":488,"data":489,"type":42,"tunes":491},"h-tool-vs-resource",{"text":490,"level":254},"工具还是资源？",{},{"id":493,"data":494,"type":376,"tunes":514},"tool-resource-table",{"content":495,"stretched":43,"withHeadings":14},[496,499,501,503,506,508,511],[497,498],"需求","优先选择",[500,418],"使用结构化参数执行操作",[502,421],"读取特定的稳定产物",[504,505],"动态搜索或计算","通常为工具",[507,418],"修改外部状态",[509,510],"打包可复用的提示指令","提示",[512,513],"长时间运行的异步执行","工具加上应用程序\u002F运行时任务处理或 MCP 扩展",{},{"id":516,"data":517,"type":42,"tunes":519},"h-model-location",{"text":518,"level":254},"AI 模型在哪里？",{},{"id":521,"data":522,"type":218,"tunes":524},"p-location-1",{"text":523},"MCP 不要求模型在 MCP 服务器上运行。模型可以托管在云端、本地托管、嵌入桌面应用程序中，或通过其他提供商访问。",{},{"id":526,"data":527,"type":218,"tunes":529},"p-location-2",{"text":528},"主机通常负责模型交互。MCP 服务器暴露外部能力。因此，本地 MCP 服务器可以被模型运行在云端的主机使用，而远程 MCP 服务器也可以被模型运行在本地的主机使用。",{},{"id":531,"data":532,"type":218,"tunes":534},"p-location-3",{"text":533},"如果 MCP 服务器本身在内部调用 LLM，该模型是协议边界之后服务器实现的一部分；MCP 并不要求这样做。",{},{"id":536,"data":537,"type":226,"tunes":540},"location-rule",{"body":538,"title":539,"variant":233},"\u003Cstrong>本地 MCP 并不意味着本地推理，远程 MCP 也不意味着远程推理。\u003C\u002Fstrong>连接位置、工具执行位置和模型\u002F提供商位置是独立的架构维度。","协议位置 ≠ 推理位置",{},{"id":542,"data":543,"type":42,"tunes":545},"h-mcp-vs-api",{"text":544,"level":254},"MCP 不会取代 API",{},{"id":547,"data":548,"type":218,"tunes":550},"p-api-1",{"text":549},"MCP 服务器通常封装现有的 API 或服务。REST、GraphQL、SQL、SDK 调用和内部服务契约可以保持原样。",{},{"id":552,"data":553,"type":218,"tunes":555},"p-api-2",{"text":554},"MCP 增加了一个面向 AI 的互操作性层。底层领域 API 仍然可以作为普通确定性客户端的权威应用程序契约。",{},{"id":557,"data":558,"type":218,"tunes":560},"p-api-3",{"text":559},"因此，通常的架构是 API\u002F服务优先，选定的面向 AI 的能力其次——而不是“用 MCP 替换所有 API”。",{},{"id":562,"data":563,"type":42,"tunes":565},"h-function-calling",{"text":564,"level":254},"MCP 与函数调用",{},{"id":567,"data":568,"type":425,"tunes":594},"function-comparison",{"rows":569,"title":586,"layout":376,"columns":587},[570,574,578,582],{"id":571,"label":572,"values":573},"scope","范围",[401,401],{"id":575,"label":576,"values":577},"definition","工具定义",[401,401],{"id":579,"label":580,"values":581},"portability","可移植性",[401,401],{"id":583,"label":584,"values":585},"coexist","它们可以共存吗？",[401,401],"函数调用和 MCP 相关但不完全相同",[588,591],{"id":589,"label":590},"function","函数调用",{"id":592,"label":593},"mcp","MCP",{},{"id":596,"data":597,"type":218,"tunes":599},"p-function-1",{"text":598},"OpenAI 目前将远程 MCP 服务器作为一种工具类型，与普通函数调用、网络搜索、shell 和其他工具并列。该实现说明了架构关系：MCP 连接和模型自身的工具调用接口可以组合使用。",{},{"id":601,"data":602,"type":42,"tunes":604},"h-agent",{"text":603,"level":254},"MCP 不会创建代理循环",{},{"id":606,"data":607,"type":218,"tunes":609},"p-agent-1",{"text":608},"AI 代理需要一个运行时，能够决策、调用工具、观察结果、更新状态并继续或停止。MCP 可以提供该循环使用的一些工具和数据。",{},{"id":611,"data":612,"type":218,"tunes":614},"p-agent-2",{"text":613},"MCP 服务器不会自动成为规划器、记忆系统或编排器。这些职责通常保留在主机或代理运行时中。",{},{"id":616,"data":617,"type":218,"tunes":619},"p-agent-3",{"text":618},"非代理型应用程序也可以使用 MCP。一次确定性的 MCP 工具调用并不需要自主的多步骤代理。",{},{"id":621,"data":622,"type":42,"tunes":624},"h-a2a",{"text":623,"level":254},"MCP 与 A2A",{},{"id":626,"data":627,"type":218,"tunes":629},"p-a2a-1",{"text":628},"MCP 主要将 AI 主机或代理连接到工具、资源和数据等能力。A2A 则面向独立代理系统之间的协作。",{},{"id":631,"data":632,"type":218,"tunes":634},"p-a2a-2",{"text":633},"远程代理可以在内部使用 MCP 访问数据库和工具，同时向其他代理暴露 A2A 接口。因此，这些协议可以分层使用，而不是相互替代。",{},{"id":636,"data":637,"type":218,"tunes":639},"p-a2a-3",{"text":638},"现有的协议栈文章负责更广泛的 MCP\u002FA2A\u002FUCP\u002FAP2\u002FA2UI 对比；G02 仍是 MCP 的规范定义。",{},{"id":641,"data":642,"type":647,"tunes":648},"ref-protocol-stack",{"url":643,"title":644,"excerpt":645,"ctaLabel":646},"https:\u002F\u002Fstajic.de\u002Fde\u002Fblog\u002Fmcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained","MCP vs A2A vs UCP vs AP2 vs A2UI：代理协议栈详解","一份更广泛的职责映射，展示 MCP 如何与代理协作、商务、支付授权和代理驱动 UI 协议组合。","阅读协议栈","referralArticle",{},{"id":650,"data":651,"type":42,"tunes":653},"h-transport",{"text":652,"level":254},"本地和远程 MCP 使用不同的传输现实",{},{"id":655,"data":656,"type":218,"tunes":658},"p-transport-1",{"text":657},"MCP 可以连接到本地和远程服务器。本地桌面集成通常使用进程级传输，例如 stdio；远程服务器则使用面向 HTTP 的传输。",{},{"id":660,"data":661,"type":218,"tunes":663},"p-transport-2",{"text":662},"2026-07-28 修订版使协议核心变为无状态。请求携带协议处理所需的信息，而不再依赖早期的协议级会话模型。",{},{"id":665,"data":666,"type":218,"tunes":668},"p-transport-3",{"text":667},"当前修订版还将方法和能力名称放入 HTTP 头，使网关、WAF、限流器和负载均衡器能够更自然地路由和计量 MCP 流量。",{},{"id":670,"data":671,"type":42,"tunes":673},"h-version",{"text":672,"level":254},"为什么 MCP 版本感知很重要",{},{"id":675,"data":676,"type":376,"tunes":690},"version-table",{"content":677,"stretched":43,"withHeadings":14},[678,681,684,687],[679,680],"协议时代","运行特征",[682,683],"2025-11-25 及更早","面向握手\u002F会话的生命周期和较旧的 Streamable HTTP 行为",[685,686],"2026-07-28","无状态核心、可选服务器发现、自描述请求、路由头、缓存提示、MRTR 和授权强化",[688,689],"扩展","Tasks 和 MCP Apps 等能力可以独立于基础协议进行版本管理",{},{"id":692,"data":693,"type":218,"tunes":695},"p-version-1",{"text":694},"SDK 版本和协议版本也是不同的东西。当前的 TypeScript v2 SDK 是 2026-07-28 修订版的稳定线，而较旧的 v1.x 仍是 2025 时代行为的维护线。",{},{"id":697,"data":698,"type":218,"tunes":700},"p-version-2",{"text":699},"当互操作性行为依赖于 SDK\u002F库版本和协议修订版时，架构文档应同时记录两者。",{},{"id":702,"data":703,"type":42,"tunes":705},"h-modern",{"text":704,"level":254},"MCP 2026-07-28 有哪些变化",{},{"id":707,"data":708,"type":376,"tunes":737},"modern-table",{"content":709,"stretched":43,"withHeadings":14},[710,713,716,719,722,725,728,731,734],[711,712],"变化","为什么重要",[714,715],"无状态核心","远程服务器可以在普通负载均衡器后扩展，而无需协议级粘性会话",[717,718],"server\u002Fdiscover","客户端可以在需要时检查服务器能力",[720,721],"自描述请求","协议版本和客户端能力元数据随每个请求传递",[723,724],"Mcp-Method \u002F Mcp-Name 头","网关无需解析正文即可路由、计量和应用策略",[726,727],"缓存提示","列表\u002F资源读取传达新鲜度和共享范围",[729,730],"多轮往返请求","服务器可以要求额外输入，而无需旧的双向请求模型",[732,733],"授权强化","颁发者验证和凭据绑定强化远程认证行为",[735,736],"扩展框架","Tasks、MCP Apps 和其他能力可以独立演进",{},{"id":739,"data":740,"type":42,"tunes":742},"h-deprecations",{"text":741,"level":254},"Roots、采样和日志记录不再是新实现的方向",{},{"id":744,"data":745,"type":218,"tunes":747},"p-dep-1",{"text":746},"2026-07-28 版本将 roots、采样和日志记录标记为已弃用的协议能力，并设定了明确的兼容窗口。",{},{"id":749,"data":750,"type":218,"tunes":752},"p-dep-2",{"text":751},"较旧的教程可能仍将这些功能展示为核心原语。新的实现工作应遵循当前规范，而不是盲目复制旧的生命周期图。",{},{"id":754,"data":755,"type":218,"tunes":757},"p-dep-3",{"text":756},"弃用并不意味着立即移除。它意味着新系统应避免对协议正在淘汰的能力产生不必要的新依赖。",{},{"id":759,"data":760,"type":42,"tunes":762},"h-tasks",{"text":761,"level":254},"长时间运行的工作与普通的 MCP 工具调用不同",{},{"id":764,"data":765,"type":218,"tunes":767},"p-task-1",{"text":766},"长时间运行的操作需要超越简单即时工具结果的生命周期语义。在当前生态系统中，Tasks 已移入专门的 MCP 扩展。",{},{"id":769,"data":770,"type":218,"tunes":772},"p-task-2",{"text":771},"这强化了一个有用的设计原则：基础协议不需要吸收每一个代理运行时关注点。",{},{"id":774,"data":775,"type":218,"tunes":777},"p-task-3",{"text":776},"应用程序也可以将长时间运行的工作流所有权完全保留在自己的运行时中，并使用普通的 MCP 工具作为底层操作。",{},{"id":779,"data":780,"type":42,"tunes":782},"h-apps",{"text":781,"level":254},"MCP Apps 扩展 UI 能力而不重新定义核心协议",{},{"id":784,"data":785,"type":218,"tunes":787},"p-apps-1",{"text":786},"MCP Apps 通过扩展模型将更丰富的交互式 UI 体验与 MCP 工具关联起来。",{},{"id":789,"data":790,"type":218,"tunes":792},"p-apps-2",{"text":791},"宿主仍然控制该 UI 的嵌入、沙箱化和安全保护方式。",{},{"id":794,"data":795,"type":218,"tunes":797},"p-apps-3",{"text":796},"因此，核心能力交换和 UI 渲染应保持为独立的架构职责。",{},{"id":799,"data":800,"type":42,"tunes":802},"h-auth",{"text":801,"level":254},"MCP 授权不是您完整的授权模型",{},{"id":804,"data":805,"type":218,"tunes":807},"p-auth-1",{"text":806},"远程 MCP 需要协议级别的身份验证和授权机制，以便客户端和服务器能够建立可信访问。当前规范继续强化 OAuth\u002FOIDC 相关行为。",{},{"id":809,"data":810,"type":218,"tunes":812},"p-auth-2",{"text":811},"该层回答的是客户端是否被允许连接或请求协议范围。它不会自动回答 Alice 是否可以退款订单 123、代理是否可以写入生产配置，或租户 A 是否可以读取租户 B 的数据。",{},{"id":814,"data":815,"type":218,"tunes":817},"p-auth-3",{"text":816},"这些领域决策属于服务器\u002F应用程序授权模型，并且必须在调用底层操作之前强制执行。",{},{"id":819,"data":820,"type":226,"tunes":823},"auth-rule",{"body":821,"title":822,"variant":240},"连接信任、工具可见性、工具权限、用户授权、租户隔离和业务审批是不同的控制措施。请将它们分开。","切勿将“已认证的 MCP 客户端”映射为“对所有工具都受信任”",{},{"id":825,"data":826,"type":42,"tunes":828},"h-identity",{"text":827,"level":254},"身份可以跨越多个边界",{},{"id":830,"data":831,"type":218,"tunes":833},"p-id-1",{"text":832},"一个 MCP 请求可能涉及 MCP 客户端应用程序、已登录的人类用户、代理\u002F会话身份以及下游服务账户。",{},{"id":835,"data":836,"type":218,"tunes":838},"p-id-2",{"text":837},"服务器需要明确的策略来确定操作代表哪个主体执行。否则，强大的服务凭证可能成为混淆代理路径。",{},{"id":840,"data":841,"type":218,"tunes":843},"p-id-3",{"text":842},"对于企业使用而言，用户身份、代理身份、MCP 连接与下游授权之间的关联，与协议兼容性同样重要。",{},{"id":845,"data":846,"type":42,"tunes":848},"h-tenant",{"text":847,"level":254},"租户隔离仍处于 MCP 能力发现范围之外",{},{"id":850,"data":851,"type":218,"tunes":853},"p-tenant-1",{"text":852},"多租户 MCP 服务器在读取或更改租户拥有的资源时，必须应用租户范围。返回一个名为 search_documents 的工具，并不能定义哪些租户的文档符合条件。",{},{"id":855,"data":856,"type":218,"tunes":858},"p-tenant-2",{"text":857},"租户范围应源自可信身份或成员关系，并传递到数据库、缓存、向量搜索、对象存储和下游 API 中。",{},{"id":860,"data":861,"type":218,"tunes":863},"p-tenant-3",{"text":862},"检索跨租户内容，然后要求模型不要使用它，这本身就已经是隔离失败。",{},{"id":865,"data":866,"type":42,"tunes":868},"h-source",{"text":867,"level":254},"MCP 未定义事实来源",{},{"id":870,"data":871,"type":218,"tunes":873},"p-source-1",{"text":872},"MCP 服务器可以暴露数据库、文档存储库、网络搜索服务或 AI 生成的摘要。协议并未声明哪个来源对某项主张具有权威性。",{},{"id":875,"data":876,"type":218,"tunes":878},"p-source-2",{"text":877},"事实来源规则属于应用\u002F领域架构。主机或服务器可以通过工具设计、元数据、访问策略或验证来编码权威性，但 MCP 本身并不会让某个能力变得“真实”。",{},{"id":880,"data":881,"type":218,"tunes":883},"p-source-3",{"text":882},"因此，一个工具可以通过 MCP 完全可调用，却仍然返回过时、次要或非权威的信息。",{},{"id":885,"data":886,"type":42,"tunes":888},"h-context",{"text":887,"level":254},"MCP 与上下文工程",{},{"id":890,"data":891,"type":218,"tunes":893},"p-context-1",{"text":892},"MCP 可以增加 AI 应用可用的能力和信息，但上下文工程仍然决定什么内容会到达模型。",{},{"id":895,"data":896,"type":218,"tunes":898},"p-context-2",{"text":897},"在许多主机中，工具目录会消耗模型可见的上下文。工具结果可能很大。资源可能很多。主机需要选择、过滤、动态加载和压缩，而不是在每一轮都暴露所有内容。",{},{"id":900,"data":901,"type":218,"tunes":903},"p-context-3",{"text":902},"因此，能力可用性和模型可见上下文应被视为不同的层。",{},{"id":905,"data":906,"type":42,"tunes":908},"h-tool-design",{"text":907,"level":254},"围绕结果和风险边界设计 MCP 工具",{},{"id":910,"data":911,"type":376,"tunes":937},"tool-design-table",{"content":912,"stretched":43,"withHeadings":14},[913,916,919,922,925,928,931,934],[914,915],"较弱的工具设计","更强的工具设计",[917,918],"execute_api(method,url,body)","具有经过验证操作的窄领域工具",[920,921],"一个管理工具处理所有操作","分离读\u002F写\u002F审批操作",[923,924],"原始内部 API 一比一镜像","围绕一致用户目标的 AI 面向契约",[926,927],"一个宽泛的文件系统工具","工作区范围的读\u002F写操作",[929,930],"安全策略仅存在于描述中","服务器在代码中强制执行策略",[932,933],"无限制的原始响应","结构化的决策相关输出",[935,936],"删除\u002F更新与读取混合","具有确认策略的独立副作用工具",{},{"id":939,"data":940,"type":42,"tunes":942},"h-approvals",{"text":941,"level":254},"审批属于执行架构",{},{"id":944,"data":945,"type":218,"tunes":947},"p-approve-1",{"text":946},"主机可以在调用选定的 MCP 工具之前要求用户批准。OpenAI 当前的 MCP 集成支持自动或显式批准的执行模式。",{},{"id":949,"data":950,"type":218,"tunes":952},"p-approve-2",{"text":951},"主机批准很有用，但不应成为服务器的唯一保护，因为另一个兼容的 MCP 客户端可能使用不同的批准模型。",{},{"id":954,"data":955,"type":218,"tunes":957},"p-approve-3",{"text":956},"对于破坏性或具有财务影响的行动，应采用纵深防御：清晰的工具契约、适当的运行时审批、服务端授权、业务校验和审计。",{},{"id":959,"data":960,"type":42,"tunes":962},"h-observability",{"text":961,"level":254},"MCP 可观测性应将协议调用与领域操作关联起来",{},{"id":964,"data":965,"type":218,"tunes":967},"p-obs-1",{"text":966},"当 MCP 追踪能够与底层应用调用、数据库变更或业务事务相关联时，其价值最大。",{},{"id":969,"data":970,"type":218,"tunes":972},"p-obs-2",{"text":971},"2026-07-28 生态系统标准化了 W3C Trace Context 传播约定，使得跨主机、客户端、服务端和下游服务跟踪请求变得更加容易。",{},{"id":974,"data":975,"type":218,"tunes":977},"p-obs-3",{"text":976},"仅靠协议日志不足以应对具有重大影响的操怍。审计证据还应记录相关主体、租户、目标资源、审批以及由此产生的状态变更。",{},{"id":979,"data":980,"type":42,"tunes":982},"h-failure",{"text":981,"level":254},"MCP 无法解决的问题",{},{"id":984,"data":985,"type":376,"tunes":1020},"failure-table",{"content":986,"stretched":43,"withHeadings":14},[987,990,993,996,999,1002,1005,1008,1011,1014,1017],[988,989],"问题","MCP 为何无法解决",[991,992],"糟糕的业务 API","MCP 可以更一致地暴露这个糟糕的 API",[994,995],"错误的数据","协议有效性并不产生事实正确性",[997,998],"缺少租户隔离","工具发现并不强制资源所有权",[1000,1001],"权限过大","标准化的工具仍然可能权限过大",[1003,1004],"糟糕的智能体规划","MCP 暴露能力；运行时\u002F模型仍然决定如何使用它们",[1006,1007],"糟糕的重试\u002F幂等设计","协议调用并不能使副作用变得安全",[1009,1010],"没有单一事实来源","MCP 不决定哪个系统拥有某个事实",[1012,1013],"薄弱的评估","互操作性并不证明任务成功",[1015,1016],"没有审计策略","传输追踪并不定义保留期限或问责机制",[1018,1019],"协议不匹配","旧\u002F新版本仍然可能需要迁移或兼容性处理",{},{"id":1022,"data":1023,"type":42,"tunes":1025},"h-implementation",{"text":1024,"level":254},"原始实现证据：Aaasaasa AI Client",{},{"id":1027,"data":1028,"type":226,"tunes":1031},"impl-note",{"body":1029,"title":1030,"variant":247},"Aaasaasa AI Client 包含一个经过身份验证的本地 MCP 连接器\u002F代理，用于已批准的本地目录，并通过 Secure MCP Tunnel 进行集成。这是协议边界和权限架构的具体实现证据，并非声称其为通用商业 MCP 平台。","实现证据",{},{"id":1033,"data":1034,"type":218,"tunes":1036},"p-impl-1",{"text":1035},"该应用可以在回环地址上运行经过身份验证的 Streamable HTTP MCP 端点。该端点仅暴露通过中央工作区权限代理选择的目录。",{},{"id":1038,"data":1039,"type":218,"tunes":1041},"p-impl-2",{"text":1040},"本地端点和远程路由是相互独立的关注点：本地连接器可以仅绑定到回环地址，而 Secure MCP Tunnel 可以使已批准的 MCP 服务对获准的外部 AI 客户端可达，同时不暴露整个本地机器。",{},{"id":1043,"data":1044,"type":218,"tunes":1046},"p-impl-3",{"text":1045},"中央权限模型区分仅聊天、只读、项目写入和自定义目录配置文件。Direct Chat 没有文件系统或 shell 访问权限；具备工具能力的智能体运行时使用所选的权限配置文件。",{},{"id":1048,"data":1049,"type":218,"tunes":1051},"p-impl-4",{"text":1050},"这是 G02 边界的直接实现：MCP 提供标准化的能力连接，而应用自有的权限代理决定服务器可以暴露哪些目录。",{},{"id":1053,"data":1054,"type":376,"tunes":1077},"impl-table",{"content":1055,"stretched":43,"withHeadings":14},[1056,1059,1062,1065,1068,1071,1074],[1057,1058],"已实现的元素","架构证据",[1060,1061],"经过身份验证的本地 MCP 端点","MCP 服务器可以是本地确定性的能力服务",[1063,1064],"回环绑定","网络暴露和协议能力是相互独立的决策",[1066,1067],"Secure MCP Tunnel 集成","私有\u002F本地 MCP 可以通过受控路由进行桥接",[1069,1070],"中央权限代理","MCP 能力受应用策略约束",[1072,1073],"选定的目录范围","文件系统可见性被明确限定",[1075,1076],"无操作系统工具的 Direct Chat","模型访问并不自动意味着工具访问",{},{"id":1079,"data":1080,"type":226,"tunes":1083},"impl-boundary",{"body":1081,"title":1082,"variant":240},"该实现展示了 MCP 连接性和权限范围内的本地目录暴露。它并不意味着每个 MCP 原语、每个 2026-07-28 特性或每个企业授权扩展都已实现。","证据边界",{},{"id":1085,"data":1086,"type":42,"tunes":1088},"h-use",{"text":1087,"level":254},"MCP 何时适合使用",{},{"id":1090,"data":1091,"type":376,"tunes":1111},"use-table",{"content":1092,"stretched":43,"withHeadings":14},[1093,1096,1099,1102,1105,1108],[1094,1095],"MCP 非常适合的情况","直接集成可能更简单的情况",[1097,1098],"同一能力应在多个 AI 主机之间可复用","一个应用拥有两端，可移植性价值不大",[1100,1101],"外部系统希望发布可发现的面向 AI 的工具\u002F资源","单个稳定的内部 API 调用就足够了",[1103,1104],"你希望围绕本地工具\u002F数据建立标准边界","没有面向 AI 的互操作性需求",[1106,1107],"工具提供者和 AI 客户端独立演进","集成是有意私有且紧密耦合的",[1109,1110],"你希望实现生态系统兼容的能力发现","能力集很小且固定在应用代码中",{},{"id":1113,"data":1114,"type":42,"tunes":1116},"h-not-need",{"text":1115,"level":254},"何时不需要 MCP",{},{"id":1118,"data":1119,"type":218,"tunes":1121},"p-not-1",{"text":1120},"不要仅仅因为应用程序使用了 AI 就添加 MCP。如果你的后端已经调用了一个内部 API，并且没有独立的 MCP 客户端需要该能力，那么普通的函数或服务调用可能更清晰。",{},{"id":1123,"data":1124,"type":218,"tunes":1126},"p-not-2",{"text":1125},"MCP 在互操作性边界处增加价值。没有该边界，协议可能变成一个不必要的适配层。",{},{"id":1128,"data":1129,"type":218,"tunes":1131},"p-not-3",{"text":1130},"架构问题不是“这个项目有 AI 吗？”，而是“独立演进的 AI 主机和能力提供者是否能从标准契约中受益？”",{},{"id":1133,"data":1134,"type":42,"tunes":1136},"h-security",{"text":1135,"level":254},"MCP 安全检查清单",{},{"id":1138,"data":1139,"type":376,"tunes":1179},"security-table",{"content":1140,"stretched":43,"withHeadings":14},[1141,1143,1146,1149,1152,1155,1158,1161,1164,1167,1170,1173,1176],[1142,988],"边界",[1144,1145],"服务器身份","我实际连接的是哪个 MCP 服务器？",[1147,1148],"客户端身份","哪个应用程序\u002F客户端在请求访问？",[1150,1151],"最终用户身份","操作是代表谁执行的？",[1153,1154],"工具允许列表","此主机\u002F代理可以发现和调用哪些能力？",[1156,1157],"业务权限","此主体可以执行此操作吗？",[1159,1160],"租户范围","适用哪个租户\u002F资源边界？",[1162,1163],"凭证隔离","凭证是否正确绑定并保持在模型上下文之外？",[1165,1166],"审批","哪些副作用需要人工确认？",[1168,1169],"输入验证","工具参数是否独立于模型输出进行验证？",[1171,1172],"输出信任","返回的内容是否可能包含不受信任的指令或敏感数据？",[1174,1175],"网络暴露","本地服务器是否意外暴露在预期接口之外？",[1177,1178],"审计","协议调用能否与下游操作关联？",{},{"id":1181,"data":1182,"type":42,"tunes":1184},"h-misconceptions",{"text":1183,"level":254},"常见误解",{},{"id":1186,"data":1187,"type":376,"tunes":1228},"misconceptions-table",{"content":1188,"stretched":43,"withHeadings":14},[1189,1192,1195,1198,1201,1204,1207,1210,1213,1216,1219,1222,1225],[1190,1191],"误解","纠正",[1193,1194],"“MCP 服务器是 AI 服务器。”","它可以是暴露能力的普通确定性软件。",[1196,1197],"“我需要在 MCP 服务器上运行自己的 LLM。”","不。模型可以完全位于主机侧。",[1199,1200],"“MCP 取代 REST API。”","MCP 通常包装现有 API 以实现面向 AI 的互操作性。",[1202,1203],"“MCP 是一个代理框架。”","MCP 提供能力；代理运行时管理迭代和状态。",[1205,1206],"“MCP 和函数调用相互竞争。”","主机可以将 MCP 能力桥接到其模型工具接口中。",[1208,1209],"“MCP 取代 A2A。”","MCP 专注于能力集成；A2A 专注于代理协作。",[1211,1212],"“如果工具被列出，用户就可以调用它。”","发现不等于授权。",[1214,1215],"“OAuth 解决业务权限问题。”","连接授权不能取代域授权或租户隔离。",[1217,1218],"“本地 MCP 意味着本地 AI。”","工具服务器位置和推理位置是独立的。",[1220,1221],"“MCP 使工具输出可信。”","数据质量、权威性和来源仍然属于源\u002F应用程序。",[1223,1224],"“一个巨大的通用工具很灵活。”","过于宽泛的工具会削弱权限、验证和可观测性。",[1226,1227],"“旧教程与当前实现一致。”","2026-07-28 修订版实质性改变了生命周期和传输行为。",{},{"id":1230,"data":1231,"type":42,"tunes":1233},"h-design",{"text":1232,"level":254},"实用的 MCP 设计顺序",{},{"id":1235,"data":1236,"type":324,"tunes":1275},"design-flow",{"steps":1237,"title":1274,"orientation":323},[1238,1241,1244,1247,1250,1253,1256,1259,1262,1265,1268,1271],{"label":1239,"description":1240},"1. 确定互操作性边界","确认独立的 AI 主机确实需要可重用访问。",{"label":1242,"description":1243},"2. 保持域 API 权威","在 MCP 背后保留真实的应用程序\u002F服务契约。",{"label":1245,"description":1246},"3. 有意识地选择原语","根据语义使用工具、资源和提示。",{"label":1248,"description":1249},"4. 按风险和权限拆分","分离读取、写入、破坏性和需要审批的操作。",{"label":1251,"description":1252},"5. 定义身份传播","了解每次调用代表哪个客户端、用户、代理和下游主体。",{"label":1254,"description":1255},"6. 执行业务授权","验证权限、租户范围和目标所有权。",{"label":1257,"description":1258},"7. 选择本地或远程传输","使部署拓扑与实际需求匹配。",{"label":1260,"description":1261},"8. 固定协议\u002FSDK 预期","记录 2026-07-28 与旧版本的兼容性。",{"label":1263,"description":1264},"9. 为重要操作添加审批","使用与风险相适应的确认控制。",{"label":1266,"description":1267},"10. 设计结构化输出","返回简洁的机器可用结果。",{"label":1269,"description":1270},"11. 添加跟踪和审计关联","将 MCP 调用连接到下游服务\u002F业务事件。",{"label":1272,"description":1273},"12. 测试可移植性","在互操作性为明确要求时，验证多个客户端。","在实现服务器之前设计边界",{},{"id":1277,"data":1278,"type":42,"tunes":1280},"h-checklist",{"text":1279,"level":254},"MCP 架构检查清单",{},{"id":1282,"data":1283,"type":376,"tunes":1332},"checklist-table",{"content":1284,"stretched":43,"withHeadings":14},[1285,1287,1290,1293,1296,1299,1302,1305,1308,1311,1314,1317,1320,1323,1326,1329],[988,1286],"预期答案",[1288,1289],"为什么需要 MCP？","真实的面向 AI 的互操作性边界",[1291,1292],"服务器暴露什么？","明确的工具\u002F资源\u002F提示",[1294,1295],"模型在哪里运行？","独立的主机\u002F提供者决定",[1297,1298],"工具执行在哪里运行？","命名的服务器\u002F运行时位置",[1300,1301],"预期使用哪个协议修订版？","版本感知的契约",[1303,1304],"请求主体是谁？","客户端\u002F用户\u002F代理身份模型",[1306,1307],"可以发现哪些工具？","允许列表\u002F能力策略",[1309,1310],"可以执行哪些操作？","服务器端业务授权",[1312,1313],"如何强制执行租户\u002F资源范围？","可信的租户\u002F资源所有权检查",[1315,1316],"哪些操作需要审批？","基于风险的确认策略",[1318,1319],"如何保护凭证？","可信运行时存储，而非模型可见的机密",[1321,1322],"如何限制输出？","结构化相关结果契约",[1324,1325],"如何跟踪调用？","通过 MCP 到下游操作的关联",[1327,1328],"如果 MCP 不可用会发生什么？","定义的降级\u002F失败行为",[1330,1331],"另一个兼容主机可以使用它吗？","在需要时验证可移植性",{},{"id":1334,"data":1335,"type":42,"tunes":1337},"h-edge",{"text":1336,"level":254},"边缘情况和限制",{},{"id":1339,"data":1340,"type":218,"tunes":1342},"p-edge-1",{"text":1341},"本地 stdio MCP 服务器可能几乎没有网络暴露，但如果进程本身具有过多的文件系统或 shell 权限，仍然可能很危险。",{},{"id":1344,"data":1345,"type":218,"tunes":1347},"p-edge-2",{"text":1346},"远程 MCP 服务器可能只暴露公共文档或高度敏感的企业操作。如果没有能力和授权上下文，“远程 MCP”几乎不能说明风险。",{},{"id":1349,"data":1350,"type":218,"tunes":1352},"p-edge-3",{"text":1351},"一些服务器可能只使用工具而忽略资源\u002F提示。MCP 兼容性并不要求每个可选原语都同等重要。",{},{"id":1354,"data":1355,"type":218,"tunes":1357},"p-edge-4",{"text":1356},"主机可以在其内部工具模型和 MCP 之间进行转换。用户可能永远不会直接看到协议边界，只要安全性和归属仍然清晰，这是可以接受的。",{},{"id":1359,"data":1360,"type":218,"tunes":1362},"p-edge-5",{"text":1361},"MCP 继续快速发展。扩展、授权模式、SDK API 和生态系统约定可能比核心架构区别变化得更快。",{},{"id":1364,"data":1365,"type":42,"tunes":1367},"h-change",{"text":1366,"level":254},"什么会改变这个答案？",{},{"id":1369,"data":1370,"type":218,"tunes":1372},"p-change-1",{"text":1371},"未来的 MCP 修订可能会改变生命周期、传输方式、授权和扩展机制。2026 年 7 月的修订已经表明，为什么特定于实现的声明必须注明日期。",{},{"id":1374,"data":1375,"type":218,"tunes":1377},"p-change-2",{"text":1376},"只有当 MCP 从互操作性协议扩展为端到端应用\u002F代理架构标准时，其规范边界才会改变。而当前协议定义的并非如此。",{},{"id":1379,"data":1380,"type":218,"tunes":1382},"p-change-3",{"text":1381},"对于实现工作，应始终检查当前规范和确切的 SDK 版本，而不是从旧教程中复制对版本敏感的示例。",{},{"id":1384,"data":1385,"type":42,"tunes":1387},"h-related",{"text":1386,"level":254},"相关规范知识",{},{"id":1389,"data":1390,"type":218,"tunes":1392},"p-related-1",{"text":1391},"MCP 属于 Agentic AI 的下游：首先理解代理\u002F运行时\u002F工具边界，然后当外部能力需要可移植的协议契约时使用 MCP。",{},{"id":1394,"data":1395,"type":218,"tunes":1397},"p-related-2",{"text":1396},"MCP 还依赖于 RBAC 和租户隔离，因为协议级别的能力暴露并不决定应用授权。",{},{"id":1399,"data":1400,"type":218,"tunes":1402},"p-related-3",{"text":1401},"更广泛的协议栈文章解释了 MCP 与 A2A、UCP、AP2 和 A2UI 并列的位置。G02 仍然是 MCP 本身的规范来源。",{},{"id":1404,"data":1405,"type":647,"tunes":1410},"ref-reliability",{"url":1406,"title":1407,"excerpt":1408,"ctaLabel":1409},"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fai-agent-reliability-why-the-final-answer-is-not-enough","AI 代理可靠性：为什么最终答案还不够","MCP 工具调用成为代理轨迹的一部分；可靠的系统需要评估动作和观察结果，而不仅仅是最终文本。","阅读代理可靠性文章",{},{"id":1412,"data":1413,"type":42,"tunes":1415},"h-faq",{"text":1414,"level":254},"常见问题",{},{"id":1417,"data":1418,"type":1417,"tunes":1461},"faq",{"items":1419,"title":1460},[1420,1424,1428,1432,1436,1440,1444,1448,1452,1456],{"id":1421,"answer":1422,"question":1423},"faq1","模型上下文协议是一种开放的客户端-服务器协议，用于通过标准化契约将 AI 应用连接到外部工具、资源、提示和能力提供者。","什么是 MCP？",{"id":1425,"answer":1426,"question":1427},"faq2","不需要。MCP 服务器可以是完全确定性的软件。模型通常在 AI 主机或代理运行时中运行，尽管服务器可以选择在内部使用 AI。","MCP 服务器需要 AI 模型吗？",{"id":1429,"answer":1430,"question":1431},"faq3","客户端是 AI 主机用于与能力提供者通信的协议组件。服务器发布并执行其暴露的能力。","MCP 客户端和服务器有什么区别？",{"id":1433,"answer":1434,"question":1435},"faq4","不会。函数\u002F工具调用是模型调用已配置能力的方式。MCP 标准化了与外部能力服务器的发现和通信。主机可以桥接两者。","MCP 会取代函数调用吗？",{"id":1437,"answer":1438,"question":1439},"faq5","不会。MCP 服务器经常包装现有的 REST、GraphQL、数据库或服务 API，并提供面向 AI 的互操作性层。","MCP 会取代 REST API 吗？",{"id":1441,"answer":1442,"question":1443},"faq6","不是。MCP 暴露能力。代理规划、状态、记忆、上下文管理、重试、编排和停止属于周围的运行时。","MCP 是代理框架吗？",{"id":1445,"answer":1446,"question":1447},"faq7","MCP 主要将 AI 主机或代理连接到工具和数据提供者。A2A 连接独立的代理系统以进行协作和委托。","MCP 和 A2A 有什么区别？",{"id":1449,"answer":1450,"question":1451},"faq8","MCP 包含协议级别的授权机制，尤其是对于远程服务器，但应用仍必须执行业务权限、资源所有权和租户隔离。","MCP 处理授权吗？",{"id":1453,"answer":1454,"question":1455},"faq9","可以。模型位置与 MCP 无关。本地模型主机可以调用本地或远程 MCP 服务器，云模型主机可以通过适当的连接架构使用经批准的本地或远程 MCP 服务器。","MCP 可以与本地模型一起使用吗？",{"id":1457,"answer":1458,"question":1459},"faq10","截至 2026 年 10 月 8 日，当前规范修订版为 2026-07-28。较旧的 2025 时代实现仍在使用，因此必须检查兼容性。","当前的 MCP 规范版本是什么？","模型上下文协议常见问题",{},{"id":1463,"data":1464,"type":42,"tunes":1466},"h-glossary",{"text":1465,"level":254},"术语表",{},{"id":1468,"data":1469,"type":1468,"tunes":1511},"glossary",{"title":1470,"entries":1471},"关键 MCP 术语",[1472,1474,1478,1481,1484,1487,1490,1493,1497,1500,1503,1507],{"term":593,"anchor":592,"definition":1473},"模型上下文协议，一种用于 AI 主机\u002F客户端与外部能力服务器之间互操作连接的开放协议。",{"term":1475,"anchor":1476,"definition":1477},"MCP 主机","mcp-host","拥有模型交互并使用 MCP 客户端连接到服务器的 AI 应用或运行时。",{"term":362,"anchor":1479,"definition":1480},"mcp-client","主机侧与 MCP 服务器通信的协议组件。",{"term":365,"anchor":1482,"definition":1483},"mcp-server","实现 MCP 并暴露工具、资源、提示或受支持扩展的能力提供者。",{"term":418,"anchor":1485,"definition":1486},"mcp-tool","由 MCP 服务器暴露的可调用结构化能力。",{"term":421,"anchor":1488,"definition":1489},"mcp-resource","通过 MCP 资源方法暴露的可读数据或内容。",{"term":510,"anchor":1491,"definition":1492},"mcp-prompt","由 MCP 服务器为兼容主机暴露的可重用提示模板。",{"term":1494,"anchor":1495,"definition":1496},"可流式 HTTP","streamable-http","用于远程\u002F网络服务器通信的面向 HTTP 的 MCP 传输。",{"term":1498,"anchor":1498,"definition":1499},"stdio","常用于本地 MCP 服务器集成的进程标准输入\u002F输出传输。",{"term":717,"anchor":1501,"definition":1502},"server-discover","现代 MCP 方法，允许客户端在 2026-07-28 协议时代检查服务器能力。",{"term":1504,"anchor":1505,"definition":1506},"MRTR","mrtr","多轮往返请求，一种在 2026-07-28 协议时代在请求期间获取额外输入的机制。",{"term":1508,"anchor":1509,"definition":1510},"MCP 扩展","mcp-extension","与基础协议组合且可以单独演进\u002F版本化的能力，例如 Tasks 或 MCP Apps。",{},{"id":1513,"data":1514,"type":42,"tunes":1516},"h-conclusion",{"text":1515,"level":254},"结论",{},{"id":1518,"data":1519,"type":218,"tunes":1521},"p-conclusion-1",{"text":1520},"当 MCP 的边界保持狭窄时最容易理解：它通过标准协议将 AI 应用连接到外部能力。",{},{"id":1523,"data":1524,"type":218,"tunes":1526},"p-conclusion-2",{"text":1525},"模型不必位于 MCP 服务器上。服务器不会成为代理运行时。列出的工具不会成为已授权的业务操作。而且 MCP 不会取代底层 API、真相来源、租户隔离或领域架构。",{},{"id":1528,"data":1529,"type":218,"tunes":1531},"p-conclusion-3",{"text":1530},"这种狭窄性正是该协议的优势。MCP 可以标准化 AI 系统访问工具和数据的方式，同时将应用所有权、安全性、业务语义和模型选择留给真正拥有它们的层。",{},{"id":1533,"data":1534,"type":42,"tunes":1536},"h-sources",{"text":1535,"level":254},"主要来源和当前文档",{},{"id":1538,"data":1539,"type":218,"tunes":1541},"p-sources-note",{"text":1540},"MCP 发展迅速，因此本文中对版本敏感的声明均以 2026 年 10 月 8 日的状态为准。Aaasaasa AI Client 部分是原始实现证据，并明确限于已验证的 MCP 连接器和权限代理范围。",{},{"id":1543,"data":1544,"type":1550,"tunes":1551},"src-mcp-ts",{"link":1545,"meta":1546},"https:\u002F\u002Fts.sdk.modelcontextprotocol.io\u002Fv2\u002F",{"image":1547,"title":1548,"description":1549},{"url":401},"模型上下文协议 — TypeScript SDK v2","当前稳定的 TypeScript SDK 文档，实现了 2026-07-28 MCP 规范以及服务器\u002F客户端原语。","linkTool",{},{"id":1553,"data":1554,"type":1550,"tunes":1560},"src-mcp-release",{"link":1555,"meta":1556},"https:\u002F\u002Fblog.modelcontextprotocol.io\u002Fposts\u002F2026-07-28\u002F",{"image":1557,"title":1558,"description":1559},{"url":401},"模型上下文协议 — 2026-07-28 规范发布","当前 MCP 协议修订版的官方发布说明，包括无状态核心、MRTR、路由、缓存、授权加固、扩展和弃用。",{},{"id":1562,"data":1563,"type":1550,"tunes":1569},"src-mcp-migration",{"link":1564,"meta":1565},"https:\u002F\u002Fts.sdk.modelcontextprotocol.io\u002Fv2\u002Fmigration\u002Fsupport-2026-07-28",{"image":1566,"title":1567,"description":1568},{"url":401},"MCP TypeScript SDK — 支持协议修订版 2026-07-28","针对当前协议修订版及早期版本兼容性的特定版本实现指南。",{},{"id":1571,"data":1572,"type":1550,"tunes":1578},"src-openai-mcp",{"link":1573,"meta":1574},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Ftools-connectors-mcp",{"image":1575,"title":1576,"description":1577},{"url":401},"OpenAI — MCP 服务器","OpenAI 当前关于通过 Secure MCP Tunnel 将模型连接到远程 MCP 服务器以及本地\u002F私有 MCP 服务器的指南。",{},{"id":1580,"data":1581,"type":1550,"tunes":1587},"src-openai-agent-mcp",{"link":1582,"meta":1583},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents-api\u002Ftools\u002Fmcp",{"image":1584,"title":1585,"description":1586},{"url":401},"OpenAI — Agents API 的 MCP 连接","当前 MCP 连接指南，涵盖服务、环境和 stdio 位置以及允许工具控制。",{},{"id":1589,"data":1590,"type":1550,"tunes":1596},"src-openai-tools",{"link":1591,"meta":1592},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Ftools",{"image":1593,"title":1594,"description":1595},{"url":401},"OpenAI — 工具","当前概述，将远程 MCP 服务器与函数调用、网络搜索、shell 和其他模型工具并列。",{},{"id":1598,"data":1599,"type":1550,"tunes":1605},"src-openai-plugin-mcp",{"link":1600,"meta":1601},"https:\u002F\u002Fdevelopers.openai.com\u002Fplugins\u002Fconcepts\u002Fmcp-server",{"image":1602,"title":1603,"description":1604},{"url":401},"OpenAI — MCP 服务器概念","当前关于 MCP 服务器暴露工具、资源和提示以用于外部服务集成的描述。",{},"2.31","模型上下文协议通过标准的客户端-服务器边界，将AI应用程序连接到外部工具、资源和提示。了解MCP能做什么、不能做什么，以及它在智能体架构中的定位。","\u002Fuploads\u002F2026\u002F10\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits-1791486640275-7ub1cq.webp","mcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits-1791486640275-7ub1cq","PUBLISHED","2026-10-08T15:09:00.000Z","2026-10-08T19:09:09.976Z","2026-10-08T19:18:07.694Z",{"en":1615,"de":1616,"sr":1617,"es":1618,"fr":1619,"it":1620,"ru":1621,"zh":1622},"\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u002Fde\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u002Fsr\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u002Fes\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u002Ffr\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u002Fit\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u002Fru\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","\u002Fzh\u002Fblog\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits",[1624,1628,1632,1636],{"id":1625,"name":1626,"slug":1627},84,"策略与数据边界","policy-and-data",{"id":1629,"name":1630,"slug":1631},57,"数据边界","data-boundaries",{"id":1633,"name":1634,"slug":1635},48,"能力","capabilities",{"id":1637,"name":1638,"slug":1639},49,"控制与证据","controls",{"id":1641,"login":1642,"email":1643,"displayName":1644},"20","rooth8233","aleksandar@stajic.de","Aleksandar Stajić",[1646,2818],{"lang":1647,"title":1648,"content":1649,"contentJson":1650,"excerpt":2817},"en","MCP Explained: What It Connects, What It Does Not Do and Where It Fits","{\"time\":1791486641380,\"blocks\":[{\"id\":\"intro\",\"type\":\"paragraph\",\"data\":{\"text\":\"The Model Context Protocol (MCP) is an open protocol for connecting AI applications to external capabilities and information through standardized client-server contracts. An MCP server can expose tools, resources and prompts; an MCP-compatible host or client discovers and uses those capabilities on behalf of an AI application. MCP does not require the server to run its own language model, and it does not replace the agent runtime, business authorization, tenant isolation, application APIs or domain architecture behind the exposed capabilities.\"},\"tunes\":{}},{\"id\":\"direct\",\"type\":\"callout\",\"data\":{\"variant\":\"info\",\"title\":\"Direct answer\",\"body\":\"\u003Cstrong>MCP standardizes the boundary between an AI host and external capability providers.\u003C\u002Fstrong>\u003Cbr>\u003Cbr>A useful mental model is:\u003Cbr>\u003Cstrong>User → AI host \u002F agent runtime → MCP client → MCP server → application\u002FAPI\u002Fdata\u002Ftool\u003C\u002Fstrong>.\u003Cbr>\u003Cbr>The model can remain entirely on the host side. The MCP server may be ordinary deterministic software that exposes structured capabilities.\"},\"tunes\":{}},{\"id\":\"server-no-ai\",\"type\":\"callout\",\"data\":{\"variant\":\"success\",\"title\":\"An MCP server does not need its own AI model\",\"body\":\"A filesystem MCP server can list or read files. A database MCP server can run approved queries. A Jira MCP server can expose issue operations. None of those servers needs an LLM to satisfy the MCP contract. If a server internally uses AI, that is an implementation choice behind the protocol boundary, not an MCP requirement.\"},\"tunes\":{}},{\"id\":\"boundary\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"MCP capability is not business authority\",\"body\":\"If an MCP server exposes \u003Ccode>delete_file\u003C\u002Fcode>, \u003Ccode>refund_order\u003C\u002Fcode> or \u003Ccode>deploy_service\u003C\u002Fcode>, that only means the capability exists. The server\u002Fapplication must still enforce identity, permissions, tenant scope, business rules, confirmation requirements and audit controls. Protocol discovery must never silently become authorization.\"},\"tunes\":{}},{\"id\":\"current\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Current-source note — 8 October 2026\",\"body\":\"The current MCP specification revision is \u003Cstrong>2026-07-28\u003C\u002Fstrong>. Its major change is a stateless protocol core with self-describing requests, optional \u003Ccode>server\u002Fdiscover\u003C\u002Fcode>, routable HTTP headers, cacheable list\u002Fresource responses, authorization hardening and a formal extension model. The TypeScript SDK v2 is the current stable SDK line implementing this revision. Older 2025-era clients and servers still exist, so implementation guidance must remain version-aware.\"},\"tunes\":{}},{\"id\":\"toc\",\"type\":\"tableOfContents\",\"data\":{\"title\":\"Contents\",\"minLevel\":2,\"maxLevel\":3},\"tunes\":{}},{\"id\":\"h-meaning\",\"type\":\"header\",\"data\":{\"text\":\"What MCP really standardizes\",\"level\":2},\"tunes\":{}},{\"id\":\"p-meaning-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Before MCP, every AI application could integrate external systems through its own tool schema, plugin format, authentication convention and connection code. The same service could need different adapters for a desktop AI client, an IDE agent and a custom application.\"},\"tunes\":{}},{\"id\":\"p-meaning-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP creates a reusable protocol boundary. The external system exposes capabilities through an MCP server, while compatible AI hosts implement an MCP client. This reduces integration coupling between the AI application and the underlying tool or data provider.\"},\"tunes\":{}},{\"id\":\"p-meaning-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The protocol does not standardize the entire application. It standardizes how capabilities are described, discovered and invoked across that boundary.\"},\"tunes\":{}},{\"id\":\"h-simple\",\"type\":\"header\",\"data\":{\"text\":\"The simplest example\",\"level\":2},\"tunes\":{}},{\"id\":\"p-simple-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Suppose an AI coding application needs access to a local project directory. Without MCP, the application might implement its own filesystem integration directly.\"},\"tunes\":{}},{\"id\":\"p-simple-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"With MCP, a filesystem server can expose capabilities such as listing directories, reading approved files or writing inside an allowed workspace. The AI host connects through an MCP client and presents those capabilities to the model or agent runtime.\"},\"tunes\":{}},{\"id\":\"p-simple-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The server does not need to understand the user's natural-language request. The host\u002Fmodel decides which capability is useful; the MCP server executes the structured request under its own security rules.\"},\"tunes\":{}},{\"id\":\"simple-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"A basic MCP tool call\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Host connects to server\",\"description\":\"The MCP-capable application configures access to the external MCP server.\"},{\"label\":\"2. Capabilities are discovered\",\"description\":\"The client learns which tools, resources or prompts the server exposes.\"},{\"label\":\"3. Model or runtime selects a capability\",\"description\":\"The AI application decides that one exposed capability is needed.\"},{\"label\":\"4. Client sends structured request\",\"description\":\"Arguments are sent through MCP to the server.\"},{\"label\":\"5. Server authorizes and executes\",\"description\":\"The server validates the request and calls its underlying system.\"},{\"label\":\"6. Result returns to host\",\"description\":\"The result becomes an observation or context input.\"},{\"label\":\"7. Host decides what happens next\",\"description\":\"The model\u002Fruntime may answer, call another tool or continue a workflow.\"}]},\"tunes\":{}},{\"id\":\"h-stops\",\"type\":\"header\",\"data\":{\"text\":\"Where the simple example stops\",\"level\":2},\"tunes\":{}},{\"id\":\"p-stops-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP does not define how the host chooses a tool, how an agent plans, how a business workflow is modeled or how a domain object such as an invoice or deployment should behave.\"},\"tunes\":{}},{\"id\":\"p-stops-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A protocol can make the integration interoperable while the underlying application remains incorrect, insecure or badly designed. A perfectly valid MCP request can still call the wrong business capability.\"},\"tunes\":{}},{\"id\":\"p-stops-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The central boundary is: MCP standardizes integration semantics, not application truth or business correctness.\"},\"tunes\":{}},{\"id\":\"h-architecture\",\"type\":\"header\",\"data\":{\"text\":\"The MCP architecture: host, client and server\",\"level\":2},\"tunes\":{}},{\"id\":\"architecture-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Component\",\"Responsibility\"],[\"AI host\",\"User-facing AI application or runtime that owns model interaction, context and overall workflow\"],[\"MCP client\",\"Protocol-side component used by the host to communicate with an MCP server\"],[\"MCP server\",\"Publishes capabilities and handles MCP requests\"],[\"Underlying system\",\"Application, API, database, filesystem, SaaS platform or service behind the MCP server\"],[\"Model\",\"Chooses or reasons about capabilities according to the host\u002Fruntime design; it is not necessarily inside the MCP server\"],[\"Authorization\u002Fbusiness policy\",\"Determines whether a requested operation is actually permitted\"]]},\"tunes\":{}},{\"id\":\"p-architecture-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A host can connect to multiple MCP servers, and one MCP server can front one or several underlying systems. The host remains responsible for integrating MCP results into the broader AI application.\"},\"tunes\":{}},{\"id\":\"p-architecture-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The server can be local to the host, run as a separate process or be remote over a network transport. Hosting topology and model location are independent decisions.\"},\"tunes\":{}},{\"id\":\"h-primitives\",\"type\":\"header\",\"data\":{\"text\":\"The three core server primitives\",\"level\":2},\"tunes\":{}},{\"id\":\"primitives-comparison\",\"type\":\"comparison\",\"data\":{\"title\":\"Tools, resources and prompts solve different needs\",\"layout\":\"table\",\"columns\":[{\"id\":\"tools\",\"label\":\"Tools\"},{\"id\":\"resources\",\"label\":\"Resources\"},{\"id\":\"prompts\",\"label\":\"Prompts\"}],\"rows\":[{\"id\":\"purpose\",\"label\":\"Primary purpose\",\"values\":[\"\",\"\",\"\"]},{\"id\":\"interaction\",\"label\":\"Typical interaction\",\"values\":[\"\",\"\",\"\"]},{\"id\":\"example\",\"label\":\"Example\",\"values\":[\"\",\"\",\"\"]},{\"id\":\"risk\",\"label\":\"Typical risk\",\"values\":[\"\",\"\",\"\"]}]},\"tunes\":{}},{\"id\":\"h-tools\",\"type\":\"header\",\"data\":{\"text\":\"Tools: callable capabilities\",\"level\":2},\"tunes\":{}},{\"id\":\"p-tools-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Tools are structured operations an MCP server makes available to the host. A tool has a name, description and input schema; modern implementations can also provide structured output.\"},\"tunes\":{}},{\"id\":\"p-tools-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Examples include searching a repository, reading a customer record, creating a ticket, running a build or sending a message. Tools can be read-only or have side effects.\"},\"tunes\":{}},{\"id\":\"p-tools-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"A good MCP tool surface should represent coherent user or agent goals rather than mechanically mirror every internal API endpoint. Operations with different permissions, confirmation requirements or blast radius should usually be separate tools.\"},\"tunes\":{}},{\"id\":\"h-resources\",\"type\":\"header\",\"data\":{\"text\":\"Resources: readable context and data\",\"level\":2},\"tunes\":{}},{\"id\":\"p-res-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Resources expose data or content that a client can list or read. They fit naturally when the semantic operation is “give me this artifact or information” rather than “perform this action.”\"},\"tunes\":{}},{\"id\":\"p-res-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A resource URI is not an authorization grant. The server still owns access control and must verify which principal may read the underlying object.\"},\"tunes\":{}},{\"id\":\"p-res-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The 2026-07-28 protocol revision adds cache semantics for list and resource-read responses, including freshness and cache scope, making caching behavior more explicit.\"},\"tunes\":{}},{\"id\":\"h-prompts\",\"type\":\"header\",\"data\":{\"text\":\"Prompts: reusable templates\",\"level\":2},\"tunes\":{}},{\"id\":\"p-prompts-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP prompts let a server publish reusable prompt templates to compatible clients. This can keep domain-specific instructions close to the capability provider.\"},\"tunes\":{}},{\"id\":\"p-prompts-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A prompt supplied by an MCP server does not automatically outrank the host's system or security instructions. The host decides how prompt material enters its context hierarchy.\"},\"tunes\":{}},{\"id\":\"p-prompts-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Protocol-provided prompt content should therefore be treated as capability data with explicit trust semantics, not as unrestricted instruction authority.\"},\"tunes\":{}},{\"id\":\"h-tool-vs-resource\",\"type\":\"header\",\"data\":{\"text\":\"Tool or resource?\",\"level\":2},\"tunes\":{}},{\"id\":\"tool-resource-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Need\",\"Prefer\"],[\"Perform an action with structured arguments\",\"Tool\"],[\"Read a specific stable artifact\",\"Resource\"],[\"Search or calculate dynamically\",\"Usually tool\"],[\"Modify external state\",\"Tool\"],[\"Package reusable prompt instructions\",\"Prompt\"],[\"Long-running asynchronous execution\",\"Tool plus application\u002Fruntime task handling or an MCP extension\"]]},\"tunes\":{}},{\"id\":\"h-model-location\",\"type\":\"header\",\"data\":{\"text\":\"Where is the AI model?\",\"level\":2},\"tunes\":{}},{\"id\":\"p-location-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP does not require the model to run on the MCP server. The model can be cloud-hosted, locally hosted, embedded in the desktop application or reached through another provider.\"},\"tunes\":{}},{\"id\":\"p-location-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The host normally owns the model interaction. The MCP server exposes external capability. A local MCP server can therefore be used by a host whose model runs in the cloud, and a remote MCP server can be used by a host whose model runs locally.\"},\"tunes\":{}},{\"id\":\"p-location-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"If the MCP server itself calls an LLM internally, that model is part of the server's implementation behind the protocol boundary; it is not required by MCP.\"},\"tunes\":{}},{\"id\":\"location-rule\",\"type\":\"callout\",\"data\":{\"variant\":\"success\",\"title\":\"Protocol location ≠ inference location\",\"body\":\"\u003Cstrong>Local MCP does not imply local inference, and remote MCP does not imply remote inference.\u003C\u002Fstrong> Connection location, tool-execution location and model\u002Fprovider location are separate architecture dimensions.\"},\"tunes\":{}},{\"id\":\"h-mcp-vs-api\",\"type\":\"header\",\"data\":{\"text\":\"MCP does not replace APIs\",\"level\":2},\"tunes\":{}},{\"id\":\"p-api-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An MCP server often wraps existing APIs or services. REST, GraphQL, SQL, SDK calls and internal service contracts can remain exactly where they are.\"},\"tunes\":{}},{\"id\":\"p-api-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP adds an AI-facing interoperability layer. The underlying domain API can remain the authoritative application contract for ordinary deterministic clients.\"},\"tunes\":{}},{\"id\":\"p-api-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The usual architecture is therefore API\u002Fservice first, selected AI-facing capability second — not “replace every API with MCP.”\"},\"tunes\":{}},{\"id\":\"h-function-calling\",\"type\":\"header\",\"data\":{\"text\":\"MCP vs function calling\",\"level\":2},\"tunes\":{}},{\"id\":\"function-comparison\",\"type\":\"comparison\",\"data\":{\"title\":\"Function calling and MCP are related but not identical\",\"layout\":\"table\",\"columns\":[{\"id\":\"function\",\"label\":\"Function calling\"},{\"id\":\"mcp\",\"label\":\"MCP\"}],\"rows\":[{\"id\":\"scope\",\"label\":\"Scope\",\"values\":[\"\",\"\"]},{\"id\":\"definition\",\"label\":\"Tool definition\",\"values\":[\"\",\"\"]},{\"id\":\"portability\",\"label\":\"Portability\",\"values\":[\"\",\"\"]},{\"id\":\"coexist\",\"label\":\"Can they coexist?\",\"values\":[\"\",\"\"]}]},\"tunes\":{}},{\"id\":\"p-function-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"OpenAI currently exposes remote MCP servers as one tool type alongside ordinary function calling, web search, shell and other tools. That implementation illustrates the architectural relationship: MCP connectivity and the model's own tool-call interface can be composed.\"},\"tunes\":{}},{\"id\":\"h-agent\",\"type\":\"header\",\"data\":{\"text\":\"MCP does not create the agent loop\",\"level\":2},\"tunes\":{}},{\"id\":\"p-agent-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An AI agent needs a runtime that can decide, invoke tools, observe results, update state and continue or stop. MCP can supply some of the tools and data used by that loop.\"},\"tunes\":{}},{\"id\":\"p-agent-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The MCP server does not automatically become the planner, memory system or orchestrator. Those responsibilities normally remain in the host or agent runtime.\"},\"tunes\":{}},{\"id\":\"p-agent-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"A non-agentic application can also use MCP. One deterministic MCP tool call does not require an autonomous multi-step agent.\"},\"tunes\":{}},{\"id\":\"h-a2a\",\"type\":\"header\",\"data\":{\"text\":\"MCP vs A2A\",\"level\":2},\"tunes\":{}},{\"id\":\"p-a2a-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP primarily connects an AI host or agent to capabilities such as tools, resources and data. A2A targets collaboration between independent agent systems.\"},\"tunes\":{}},{\"id\":\"p-a2a-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A remote agent can internally use MCP to reach databases and tools while exposing an A2A interface to other agents. The protocols can therefore be layered rather than substituted.\"},\"tunes\":{}},{\"id\":\"p-a2a-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The existing protocol-stack article owns the broader MCP\u002FA2A\u002FUCP\u002FAP2\u002FA2UI comparison; G02 remains the canonical MCP definition.\"},\"tunes\":{}},{\"id\":\"ref-protocol-stack\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fde\u002Fblog\u002Fmcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained\",\"title\":\"MCP vs A2A vs UCP vs AP2 vs A2UI: The Agent Protocol Stack Explained\",\"excerpt\":\"A broader responsibility map showing how MCP composes with agent collaboration, commerce, payment authority and agent-driven UI protocols.\",\"ctaLabel\":\"Read the protocol stack\"},\"tunes\":{}},{\"id\":\"h-transport\",\"type\":\"header\",\"data\":{\"text\":\"Local and remote MCP use different transport realities\",\"level\":2},\"tunes\":{}},{\"id\":\"p-transport-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP can connect to local and remote servers. Local desktop integrations commonly use process-level transports such as stdio; remote servers use HTTP-oriented transport.\"},\"tunes\":{}},{\"id\":\"p-transport-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The 2026-07-28 revision makes the protocol core stateless. Requests carry the information needed for protocol handling instead of depending on the earlier protocol-level session model.\"},\"tunes\":{}},{\"id\":\"p-transport-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The current revision also places method and capability names in HTTP headers so gateways, WAFs, rate limiters and load balancers can route and meter MCP traffic more naturally.\"},\"tunes\":{}},{\"id\":\"h-version\",\"type\":\"header\",\"data\":{\"text\":\"Why MCP version awareness matters\",\"level\":2},\"tunes\":{}},{\"id\":\"version-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Protocol era\",\"Operational characteristic\"],[\"2025-11-25 and earlier\",\"Handshake\u002Fsession-oriented lifecycle and older Streamable HTTP behavior\"],[\"2026-07-28\",\"Stateless core, optional server discovery, self-describing requests, routing headers, cache hints, MRTR and authorization hardening\"],[\"Extensions\",\"Capabilities such as Tasks and MCP Apps can version separately from the base protocol\"]]},\"tunes\":{}},{\"id\":\"p-version-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"SDK version and protocol version are also different things. The current TypeScript v2 SDK is the stable line for the 2026-07-28 revision, while older v1.x remains a maintenance line for 2025-era behavior.\"},\"tunes\":{}},{\"id\":\"p-version-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Architecture documentation should record both the SDK\u002Flibrary version and the protocol revision where interoperability behavior depends on them.\"},\"tunes\":{}},{\"id\":\"h-modern\",\"type\":\"header\",\"data\":{\"text\":\"What changed in MCP 2026-07-28\",\"level\":2},\"tunes\":{}},{\"id\":\"modern-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Change\",\"Why it matters\"],[\"Stateless core\",\"Remote servers can scale behind ordinary load balancers without protocol-level sticky sessions\"],[\"server\u002Fdiscover\",\"Clients can inspect server capabilities when needed\"],[\"Self-describing requests\",\"Protocol version and client capability metadata travel per request\"],[\"Mcp-Method \u002F Mcp-Name headers\",\"Gateways can route, meter and apply policy without parsing bodies\"],[\"Cache hints\",\"Lists\u002Fresource reads communicate freshness and sharing scope\"],[\"Multi Round-Trip Requests\",\"Servers can require additional input without the older bidirectional request model\"],[\"Authorization hardening\",\"Issuer validation and credential binding strengthen remote auth behavior\"],[\"Extensions framework\",\"Tasks, MCP Apps and other capabilities can evolve separately\"]]},\"tunes\":{}},{\"id\":\"h-deprecations\",\"type\":\"header\",\"data\":{\"text\":\"Roots, sampling and logging are no longer the direction for new implementations\",\"level\":2},\"tunes\":{}},{\"id\":\"p-dep-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The 2026-07-28 release marks roots, sampling and logging as deprecated protocol capabilities with a defined compatibility window.\"},\"tunes\":{}},{\"id\":\"p-dep-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Older tutorials may still show these features as central primitives. New implementation work should follow the current specification rather than copy older lifecycle diagrams blindly.\"},\"tunes\":{}},{\"id\":\"p-dep-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Deprecation does not mean immediate removal. It means new systems should avoid unnecessary new dependencies on capabilities the protocol is moving away from.\"},\"tunes\":{}},{\"id\":\"h-tasks\",\"type\":\"header\",\"data\":{\"text\":\"Long-running work is not the same as ordinary MCP tool invocation\",\"level\":2},\"tunes\":{}},{\"id\":\"p-task-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Long-running operations need lifecycle semantics beyond a simple immediate tool result. In the current ecosystem, Tasks moved into a dedicated MCP extension.\"},\"tunes\":{}},{\"id\":\"p-task-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"This reinforces a useful design principle: the base protocol does not need to absorb every agent-runtime concern.\"},\"tunes\":{}},{\"id\":\"p-task-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"An application can also keep long-running workflow ownership entirely in its own runtime and use ordinary MCP tools as underlying operations.\"},\"tunes\":{}},{\"id\":\"h-apps\",\"type\":\"header\",\"data\":{\"text\":\"MCP Apps extend UI capability without redefining the core protocol\",\"level\":2},\"tunes\":{}},{\"id\":\"p-apps-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP Apps associate richer interactive UI experiences with MCP tools through the extension model.\"},\"tunes\":{}},{\"id\":\"p-apps-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The host still controls how that UI is embedded, sandboxed and secured.\"},\"tunes\":{}},{\"id\":\"p-apps-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Core capability exchange and UI rendering should therefore remain separate architecture responsibilities.\"},\"tunes\":{}},{\"id\":\"h-auth\",\"type\":\"header\",\"data\":{\"text\":\"MCP authorization is not your complete authorization model\",\"level\":2},\"tunes\":{}},{\"id\":\"p-auth-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Remote MCP needs protocol-level authentication and authorization mechanisms so clients and servers can establish trusted access. The current specification continues to harden OAuth\u002FOIDC-related behavior.\"},\"tunes\":{}},{\"id\":\"p-auth-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"That layer answers whether a client is allowed to connect or request protocol scopes. It does not automatically answer whether Alice may refund order 123, whether an agent may write production configuration or whether Tenant A may read Tenant B data.\"},\"tunes\":{}},{\"id\":\"p-auth-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Those domain decisions belong in the server\u002Fapplication authorization model and must be enforced before invoking the underlying operation.\"},\"tunes\":{}},{\"id\":\"auth-rule\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Never map “authenticated MCP client” to “trusted for every tool”\",\"body\":\"Connection trust, tool visibility, tool permission, user authorization, tenant isolation and business approval are different controls. Keep them separate.\"},\"tunes\":{}},{\"id\":\"h-identity\",\"type\":\"header\",\"data\":{\"text\":\"Identity can cross several boundaries\",\"level\":2},\"tunes\":{}},{\"id\":\"p-id-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An MCP request may involve the MCP client application, the signed-in human, an agent\u002Fsession identity and a downstream service account.\"},\"tunes\":{}},{\"id\":\"p-id-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The server needs an explicit policy for which principal the operation is performed on behalf of. Otherwise a powerful service credential can become a confused-deputy path.\"},\"tunes\":{}},{\"id\":\"p-id-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"For enterprise use, correlation between user identity, agent identity, MCP connection and downstream authorization is as important as protocol compatibility.\"},\"tunes\":{}},{\"id\":\"h-tenant\",\"type\":\"header\",\"data\":{\"text\":\"Tenant isolation remains outside MCP capability discovery\",\"level\":2},\"tunes\":{}},{\"id\":\"p-tenant-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A multi-tenant MCP server must apply tenant scope when it reads or changes tenant-owned resources. Returning a tool named search_documents does not define which tenant's documents are eligible.\"},\"tunes\":{}},{\"id\":\"p-tenant-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Tenant scope should be derived from trusted identity or membership and carried into databases, caches, vector search, object storage and downstream APIs.\"},\"tunes\":{}},{\"id\":\"p-tenant-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Retrieving cross-tenant content and asking the model not to use it is already an isolation failure.\"},\"tunes\":{}},{\"id\":\"h-source\",\"type\":\"header\",\"data\":{\"text\":\"MCP does not define Source of Truth\",\"level\":2},\"tunes\":{}},{\"id\":\"p-source-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An MCP server can expose a database, document repository, web search service or AI-generated summary. The protocol does not declare which source is authoritative for a claim.\"},\"tunes\":{}},{\"id\":\"p-source-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Source-of-Truth rules belong to application\u002Fdomain architecture. The host or server can encode authority through tool design, metadata, access policy or validation, but MCP itself does not make one capability “true.”\"},\"tunes\":{}},{\"id\":\"p-source-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"A tool can therefore be perfectly callable through MCP and still return stale, secondary or non-authoritative information.\"},\"tunes\":{}},{\"id\":\"h-context\",\"type\":\"header\",\"data\":{\"text\":\"MCP and context engineering\",\"level\":2},\"tunes\":{}},{\"id\":\"p-context-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP can increase the capabilities and information available to an AI application, but context engineering still determines what reaches the model.\"},\"tunes\":{}},{\"id\":\"p-context-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Tool catalogs consume model-visible context in many hosts. Tool results can be large. Resources can be numerous. A host needs selection, filtering, dynamic loading and compaction rather than exposing everything on every turn.\"},\"tunes\":{}},{\"id\":\"p-context-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Capability availability and model-visible context should therefore be treated as separate layers.\"},\"tunes\":{}},{\"id\":\"h-tool-design\",\"type\":\"header\",\"data\":{\"text\":\"Design MCP tools around outcomes and risk boundaries\",\"level\":2},\"tunes\":{}},{\"id\":\"tool-design-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Weak tool design\",\"Stronger tool design\"],[\"execute_api(method,url,body)\",\"Narrow domain tools with validated operations\"],[\"One admin tool for all actions\",\"Separate read\u002Fwrite\u002Fapproval operations\"],[\"Raw internal API mirrored 1:1\",\"AI-facing contract around coherent user goals\"],[\"One broad filesystem tool\",\"Workspace-scoped read\u002Fwrite operations\"],[\"Security policy only in description\",\"Server enforces policy in code\"],[\"Unbounded raw response\",\"Structured decision-relevant output\"],[\"Delete\u002Fupdate mixed with read\",\"Separate side-effect tools with confirmation policy\"]]},\"tunes\":{}},{\"id\":\"h-approvals\",\"type\":\"header\",\"data\":{\"text\":\"Approvals belong in the execution architecture\",\"level\":2},\"tunes\":{}},{\"id\":\"p-approve-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A host can require user approval before invoking selected MCP tools. OpenAI's current MCP integration supports automatic or explicit-approval execution patterns.\"},\"tunes\":{}},{\"id\":\"p-approve-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Host approval is useful but should not be the server's only protection because another compatible MCP client may use a different approval model.\"},\"tunes\":{}},{\"id\":\"p-approve-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"For destructive or financially consequential actions, use defense in depth: clear tool contract, runtime approval where appropriate, server-side authorization, business validation and audit.\"},\"tunes\":{}},{\"id\":\"h-observability\",\"type\":\"header\",\"data\":{\"text\":\"MCP observability should connect protocol calls to domain actions\",\"level\":2},\"tunes\":{}},{\"id\":\"p-obs-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An MCP trace is most useful when it can be correlated with the underlying application call, database change or business transaction.\"},\"tunes\":{}},{\"id\":\"p-obs-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The 2026-07-28 ecosystem standardizes W3C Trace Context propagation conventions, making it easier to follow a request across host, client, server and downstream services.\"},\"tunes\":{}},{\"id\":\"p-obs-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Protocol logs alone are not enough for consequential operations. Audit evidence should also record relevant principal, tenant, target resource, approval and resulting state change.\"},\"tunes\":{}},{\"id\":\"h-failure\",\"type\":\"header\",\"data\":{\"text\":\"What MCP cannot fix\",\"level\":2},\"tunes\":{}},{\"id\":\"failure-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Problem\",\"Why MCP does not solve it\"],[\"Bad business API\",\"MCP can expose the bad API more consistently\"],[\"Wrong data\",\"Protocol validity does not create factual correctness\"],[\"Missing tenant isolation\",\"Tool discovery does not enforce resource ownership\"],[\"Excessive privileges\",\"A standardized tool can still be overprivileged\"],[\"Poor agent planning\",\"MCP exposes capabilities; runtime\u002Fmodel still chooses how to use them\"],[\"Bad retry\u002Fidempotency design\",\"Protocol calls do not make side effects safe\"],[\"No Source of Truth\",\"MCP does not decide which system owns a fact\"],[\"Weak evaluation\",\"Interoperability does not prove task success\"],[\"No audit policy\",\"Transport traces do not define retention or accountability\"],[\"Protocol mismatch\",\"Old\u002Fnew versions can still require migration or compatibility handling\"]]},\"tunes\":{}},{\"id\":\"h-implementation\",\"type\":\"header\",\"data\":{\"text\":\"Original implementation evidence: Aaasaasa AI Client\",\"level\":2},\"tunes\":{}},{\"id\":\"impl-note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Implementation evidence\",\"body\":\"Aaasaasa AI Client contains an authenticated local MCP connector\u002Fbroker for approved local directories and integration through Secure MCP Tunnel. This is concrete implementation evidence for the protocol boundary and permission architecture, not a claim of a general-purpose commercial MCP platform.\"},\"tunes\":{}},{\"id\":\"p-impl-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The application can run an authenticated Streamable HTTP MCP endpoint on loopback. The endpoint exposes only directories selected through the central workspace permission broker.\"},\"tunes\":{}},{\"id\":\"p-impl-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The local endpoint and remote route are separate concerns: the local connector can bind only to loopback, while a Secure MCP Tunnel can make the approved MCP service reachable to a permitted external AI client without exposing the whole local machine.\"},\"tunes\":{}},{\"id\":\"p-impl-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The central permission model distinguishes chat-only, read-only, project-write and custom-directory profiles. Direct Chat has no filesystem or shell access; tool-capable agent runtimes use the selected permission profile.\"},\"tunes\":{}},{\"id\":\"p-impl-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"This is a direct implementation of the G02 boundary: MCP provides the standardized capability connection, while the application-owned permission broker decides which directories the server may expose.\"},\"tunes\":{}},{\"id\":\"impl-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Implemented element\",\"Architecture evidence\"],[\"Authenticated local MCP endpoint\",\"MCP server can be a local deterministic capability service\"],[\"Loopback binding\",\"Network exposure and protocol capability are separate decisions\"],[\"Secure MCP Tunnel integration\",\"Private\u002Flocal MCP can be bridged through a controlled route\"],[\"Central permission broker\",\"MCP capability is constrained by application policy\"],[\"Selected directory scope\",\"Filesystem visibility is explicitly bounded\"],[\"Direct Chat without OS tools\",\"Model access does not automatically imply tool access\"]]},\"tunes\":{}},{\"id\":\"impl-boundary\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Evidence boundary\",\"body\":\"The implementation demonstrates MCP connectivity and permission-scoped local directory exposure. It does not imply that every MCP primitive, every 2026-07-28 feature or every enterprise authorization extension is implemented.\"},\"tunes\":{}},{\"id\":\"h-use\",\"type\":\"header\",\"data\":{\"text\":\"When MCP is a good fit\",\"level\":2},\"tunes\":{}},{\"id\":\"use-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"MCP is a strong fit when\",\"A direct integration may be simpler when\"],[\"The same capability should be reusable across multiple AI hosts\",\"One application owns both sides and portability has little value\"],[\"An external system wants to publish discoverable AI-facing tools\u002Fresources\",\"A single stable internal API call is sufficient\"],[\"You want a standard boundary around local tools\u002Fdata\",\"There is no AI-facing interoperability requirement\"],[\"Tool providers and AI clients evolve independently\",\"The integration is intentionally private and tightly coupled\"],[\"You want ecosystem-compatible capability discovery\",\"The capability set is tiny and fixed in application code\"]]},\"tunes\":{}},{\"id\":\"h-not-need\",\"type\":\"header\",\"data\":{\"text\":\"When you do not need MCP\",\"level\":2},\"tunes\":{}},{\"id\":\"p-not-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Do not add MCP merely because the application uses AI. If your backend already calls one internal API and no independent MCP client needs that capability, an ordinary function or service call may be clearer.\"},\"tunes\":{}},{\"id\":\"p-not-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP adds value at an interoperability boundary. Without that boundary, the protocol can become an unnecessary adapter layer.\"},\"tunes\":{}},{\"id\":\"p-not-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architectural question is not “Does this project have AI?” but “Do independently evolving AI hosts and capability providers benefit from a standard contract?”\"},\"tunes\":{}},{\"id\":\"h-security\",\"type\":\"header\",\"data\":{\"text\":\"MCP security checklist\",\"level\":2},\"tunes\":{}},{\"id\":\"security-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Boundary\",\"Question\"],[\"Server identity\",\"Which MCP server am I actually connected to?\"],[\"Client identity\",\"Which application\u002Fclient is requesting access?\"],[\"End-user identity\",\"On whose behalf is the operation performed?\"],[\"Tool allowlist\",\"Which capabilities may this host\u002Fagent discover and call?\"],[\"Business permission\",\"May this principal perform this operation?\"],[\"Tenant scope\",\"Which tenant\u002Fresource boundary applies?\"],[\"Credential isolation\",\"Are credentials bound correctly and kept outside model context?\"],[\"Approval\",\"Which side effects require human confirmation?\"],[\"Input validation\",\"Are tool arguments validated independently of model output?\"],[\"Output trust\",\"Can returned content contain untrusted instructions or sensitive data?\"],[\"Network exposure\",\"Is a local server accidentally exposed beyond intended interfaces?\"],[\"Audit\",\"Can a protocol call be correlated with the downstream action?\"]]},\"tunes\":{}},{\"id\":\"h-misconceptions\",\"type\":\"header\",\"data\":{\"text\":\"Common misconceptions\",\"level\":2},\"tunes\":{}},{\"id\":\"misconceptions-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Misconception\",\"Correction\"],[\"“An MCP server is an AI server.”\",\"It can be ordinary deterministic software exposing capabilities.\"],[\"“I need my own LLM on the MCP server.”\",\"No. The model can live entirely on the host side.\"],[\"“MCP replaces REST APIs.”\",\"MCP often wraps existing APIs for AI-facing interoperability.\"],[\"“MCP is an agent framework.”\",\"MCP supplies capabilities; an agent runtime manages iteration and state.\"],[\"“MCP and function calling compete.”\",\"A host can bridge MCP capabilities into its model tool interface.\"],[\"“MCP replaces A2A.”\",\"MCP focuses on capability integration; A2A focuses on agent collaboration.\"],[\"“If a tool is listed, the user may call it.”\",\"Discovery is not authorization.\"],[\"“OAuth solves business permissions.”\",\"Connection authorization does not replace domain authorization or tenant isolation.\"],[\"“Local MCP means local AI.”\",\"Tool-server location and inference location are independent.\"],[\"“MCP makes tool output trustworthy.”\",\"Data quality, authority and provenance still belong to the source\u002Fapplication.\"],[\"“One giant generic tool is flexible.”\",\"Over-broad tools weaken permissions, validation and observability.\"],[\"“Old tutorials are implementation-current.”\",\"The 2026-07-28 revision materially changed lifecycle and transport behavior.\"]]},\"tunes\":{}},{\"id\":\"h-design\",\"type\":\"header\",\"data\":{\"text\":\"A practical MCP design sequence\",\"level\":2},\"tunes\":{}},{\"id\":\"design-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"Design the boundary before implementing the server\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Identify the interoperability boundary\",\"description\":\"Confirm that independent AI hosts actually need reusable access.\"},{\"label\":\"2. Keep the domain API authoritative\",\"description\":\"Preserve the real application\u002Fservice contract behind MCP.\"},{\"label\":\"3. Choose primitives deliberately\",\"description\":\"Use tools, resources and prompts according to their semantics.\"},{\"label\":\"4. Split by risk and permission\",\"description\":\"Separate read, write, destructive and approval-required operations.\"},{\"label\":\"5. Define identity propagation\",\"description\":\"Know which client, user, agent and downstream principal each call represents.\"},{\"label\":\"6. Enforce business authorization\",\"description\":\"Validate permissions, tenant scope and target ownership.\"},{\"label\":\"7. Choose local or remote transport\",\"description\":\"Match deployment topology to the real need.\"},{\"label\":\"8. Pin protocol\u002FSDK expectations\",\"description\":\"Document 2026-07-28 versus older compatibility.\"},{\"label\":\"9. Add approvals for consequential actions\",\"description\":\"Use risk-appropriate confirmation controls.\"},{\"label\":\"10. Design structured outputs\",\"description\":\"Return concise machine-usable results.\"},{\"label\":\"11. Add tracing and audit correlation\",\"description\":\"Connect MCP calls to downstream service\u002Fbusiness events.\"},{\"label\":\"12. Test portability\",\"description\":\"Verify more than one client where interoperability is a stated requirement.\"}]},\"tunes\":{}},{\"id\":\"h-checklist\",\"type\":\"header\",\"data\":{\"text\":\"MCP architecture checklist\",\"level\":2},\"tunes\":{}},{\"id\":\"checklist-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Question\",\"Expected answer\"],[\"Why is MCP needed?\",\"A real AI-facing interoperability boundary\"],[\"What does the server expose?\",\"Explicit tools\u002Fresources\u002Fprompts\"],[\"Where does the model run?\",\"Independent host\u002Fprovider decision\"],[\"Where does tool execution run?\",\"Named server\u002Fruntime location\"],[\"Which protocol revision is expected?\",\"Version-aware contract\"],[\"Who is the requesting principal?\",\"Client\u002Fuser\u002Fagent identity model\"],[\"Which tools may be discovered?\",\"Allowlist\u002Fcapability policy\"],[\"Which operations may execute?\",\"Server-side business authorization\"],[\"How is tenant\u002Fresource scope enforced?\",\"Trusted tenant\u002Fresource ownership checks\"],[\"Which actions need approval?\",\"Risk-based confirmation policy\"],[\"How are credentials protected?\",\"Trusted runtime storage, not model-visible secrets\"],[\"How is output bounded?\",\"Structured relevant result contract\"],[\"How are calls traced?\",\"Correlation through MCP to downstream action\"],[\"What happens if MCP is unavailable?\",\"Defined fallback\u002Ffailure behavior\"],[\"Can another compatible host use it?\",\"Portability validated where required\"]]},\"tunes\":{}},{\"id\":\"h-edge\",\"type\":\"header\",\"data\":{\"text\":\"Edge cases and limitations\",\"level\":2},\"tunes\":{}},{\"id\":\"p-edge-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A local stdio MCP server can have little network exposure while still be dangerous if the process itself has excessive filesystem or shell permissions.\"},\"tunes\":{}},{\"id\":\"p-edge-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A remote MCP server may expose only public documentation or highly sensitive enterprise actions. “Remote MCP” says little about risk without the capability and authorization context.\"},\"tunes\":{}},{\"id\":\"p-edge-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Some servers may use only tools and ignore resources\u002Fprompts. MCP compatibility does not require every optional primitive to be equally important.\"},\"tunes\":{}},{\"id\":\"p-edge-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"A host can translate between its own internal tool model and MCP. Users may never see the protocol boundary directly, which is acceptable if security and attribution remain clear.\"},\"tunes\":{}},{\"id\":\"p-edge-5\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP continues to evolve rapidly. Extensions, authorization patterns, SDK APIs and ecosystem conventions can change faster than the core architectural distinction.\"},\"tunes\":{}},{\"id\":\"h-change\",\"type\":\"header\",\"data\":{\"text\":\"What would change this answer?\",\"level\":2},\"tunes\":{}},{\"id\":\"p-change-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Future MCP revisions can change lifecycle, transports, authorization and extension mechanisms. The July 2026 revision already demonstrates why implementation-specific claims must be dated.\"},\"tunes\":{}},{\"id\":\"p-change-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The canonical boundary would change only if MCP expanded from an interoperability protocol into an end-to-end application\u002Fagent architecture standard. That is not what the current protocol defines.\"},\"tunes\":{}},{\"id\":\"p-change-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"For implementation work, always check the current specification and exact SDK line instead of copying version-sensitive examples from older tutorials.\"},\"tunes\":{}},{\"id\":\"h-related\",\"type\":\"header\",\"data\":{\"text\":\"Related canonical knowledge\",\"level\":2},\"tunes\":{}},{\"id\":\"p-related-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP belongs downstream of Agentic AI: first understand the agent\u002Fruntime\u002Ftool boundary, then use MCP when external capabilities need a portable protocol contract.\"},\"tunes\":{}},{\"id\":\"p-related-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP also depends on RBAC and tenant isolation because protocol-level capability exposure does not determine application authorization.\"},\"tunes\":{}},{\"id\":\"p-related-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The broader protocol-stack article explains where MCP sits beside A2A, UCP, AP2 and A2UI. G02 remains the canonical source for MCP itself.\"},\"tunes\":{}},{\"id\":\"ref-reliability\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fai-agent-reliability-why-the-final-answer-is-not-enough\",\"title\":\"AI Agent Reliability: Why the Final Answer Is Not Enough\",\"excerpt\":\"MCP tool calls become part of an agent trajectory; reliable systems need to evaluate actions and observations, not only final text.\",\"ctaLabel\":\"Read the agent reliability article\"},\"tunes\":{}},{\"id\":\"h-faq\",\"type\":\"header\",\"data\":{\"text\":\"Frequently asked questions\",\"level\":2},\"tunes\":{}},{\"id\":\"faq\",\"type\":\"faq\",\"data\":{\"title\":\"Model Context Protocol FAQ\",\"items\":[{\"id\":\"faq1\",\"question\":\"What is MCP?\",\"answer\":\"The Model Context Protocol is an open client-server protocol for connecting AI applications to external tools, resources, prompts and capability providers through a standardized contract.\"},{\"id\":\"faq2\",\"question\":\"Does an MCP server need an AI model?\",\"answer\":\"No. An MCP server can be completely deterministic software. The model normally runs in the AI host or agent runtime, although a server may optionally use AI internally.\"},{\"id\":\"faq3\",\"question\":\"What is the difference between an MCP client and server?\",\"answer\":\"The client is the protocol component used by an AI host to communicate with capability providers. The server publishes and executes the capabilities it exposes.\"},{\"id\":\"faq4\",\"question\":\"Does MCP replace function calling?\",\"answer\":\"No. Function\u002Ftool calling is how a model invokes configured capabilities. MCP standardizes discovery and communication with external capability servers. A host can bridge the two.\"},{\"id\":\"faq5\",\"question\":\"Does MCP replace REST APIs?\",\"answer\":\"No. MCP servers frequently wrap existing REST, GraphQL, database or service APIs and provide an AI-facing interoperability layer.\"},{\"id\":\"faq6\",\"question\":\"Is MCP an agent framework?\",\"answer\":\"No. MCP exposes capabilities. Agent planning, state, memory, context management, retries, orchestration and stopping belong to the surrounding runtime.\"},{\"id\":\"faq7\",\"question\":\"What is the difference between MCP and A2A?\",\"answer\":\"MCP primarily connects an AI host or agent to tools and data providers. A2A connects independent agent systems for collaboration and delegation.\"},{\"id\":\"faq8\",\"question\":\"Does MCP handle authorization?\",\"answer\":\"MCP includes protocol-level authorization mechanisms, especially for remote servers, but the application must still enforce business permissions, resource ownership and tenant isolation.\"},{\"id\":\"faq9\",\"question\":\"Can MCP work with local models?\",\"answer\":\"Yes. Model location is independent of MCP. A local-model host can call local or remote MCP servers, and a cloud-model host can use approved local or remote MCP servers through an appropriate connection architecture.\"},{\"id\":\"faq10\",\"question\":\"What is the current MCP specification version?\",\"answer\":\"As of 8 October 2026, the current specification revision is 2026-07-28. Older 2025-era implementations remain in use, so compatibility must be checked.\"}]},\"tunes\":{}},{\"id\":\"h-glossary\",\"type\":\"header\",\"data\":{\"text\":\"Glossary\",\"level\":2},\"tunes\":{}},{\"id\":\"glossary\",\"type\":\"glossary\",\"data\":{\"title\":\"Key MCP terms\",\"entries\":[{\"term\":\"MCP\",\"definition\":\"Model Context Protocol, an open protocol for interoperable connections between AI hosts\u002Fclients and external capability servers.\",\"anchor\":\"mcp\"},{\"term\":\"MCP host\",\"definition\":\"The AI application or runtime that owns model interaction and uses MCP clients to connect to servers.\",\"anchor\":\"mcp-host\"},{\"term\":\"MCP client\",\"definition\":\"Protocol component on the host side that communicates with an MCP server.\",\"anchor\":\"mcp-client\"},{\"term\":\"MCP server\",\"definition\":\"Capability provider that implements MCP and exposes tools, resources, prompts or supported extensions.\",\"anchor\":\"mcp-server\"},{\"term\":\"Tool\",\"definition\":\"Callable structured capability exposed by an MCP server.\",\"anchor\":\"mcp-tool\"},{\"term\":\"Resource\",\"definition\":\"Readable data or content exposed through MCP resource methods.\",\"anchor\":\"mcp-resource\"},{\"term\":\"Prompt\",\"definition\":\"Reusable prompt template exposed by an MCP server for compatible hosts.\",\"anchor\":\"mcp-prompt\"},{\"term\":\"Streamable HTTP\",\"definition\":\"HTTP-oriented MCP transport used for remote\u002Fnetworked server communication.\",\"anchor\":\"streamable-http\"},{\"term\":\"stdio\",\"definition\":\"Process standard-input\u002Foutput transport commonly used for local MCP server integrations.\",\"anchor\":\"stdio\"},{\"term\":\"server\u002Fdiscover\",\"definition\":\"Modern MCP method that lets a client inspect server capabilities in the 2026-07-28 protocol era.\",\"anchor\":\"server-discover\"},{\"term\":\"MRTR\",\"definition\":\"Multi Round-Trip Requests, a mechanism for obtaining additional input during a request in the 2026-07-28 protocol era.\",\"anchor\":\"mrtr\"},{\"term\":\"MCP extension\",\"definition\":\"Capability that composes with the base protocol and can evolve\u002Fversion separately, such as Tasks or MCP Apps.\",\"anchor\":\"mcp-extension\"}]},\"tunes\":{}},{\"id\":\"h-conclusion\",\"type\":\"header\",\"data\":{\"text\":\"Conclusion\",\"level\":2},\"tunes\":{}},{\"id\":\"p-conclusion-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP is easiest to understand when its boundary stays narrow: it connects AI applications to external capabilities through a standard protocol.\"},\"tunes\":{}},{\"id\":\"p-conclusion-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The model does not have to live on the MCP server. The server does not become the agent runtime. A listed tool does not become an authorized business action. And MCP does not replace the underlying API, Source of Truth, tenant isolation or domain architecture.\"},\"tunes\":{}},{\"id\":\"p-conclusion-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"That narrowness is the protocol's strength. MCP can standardize how AI systems reach tools and data while leaving application ownership, security, business semantics and model choice in the layers that actually own them.\"},\"tunes\":{}},{\"id\":\"h-sources\",\"type\":\"header\",\"data\":{\"text\":\"Primary sources and current documentation\",\"level\":2},\"tunes\":{}},{\"id\":\"p-sources-note\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP is evolving quickly, so version-sensitive claims in this article are tied to the 8 October 2026 state. The Aaasaasa AI Client section is original implementation evidence and is explicitly limited to the verified MCP connector and permission-broker scope.\"},\"tunes\":{}},{\"id\":\"src-mcp-ts\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fts.sdk.modelcontextprotocol.io\u002Fv2\u002F\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Model Context Protocol — TypeScript SDK v2\",\"description\":\"Current stable TypeScript SDK documentation implementing the 2026-07-28 MCP specification and server\u002Fclient primitives.\"}},\"tunes\":{}},{\"id\":\"src-mcp-release\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fblog.modelcontextprotocol.io\u002Fposts\u002F2026-07-28\u002F\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Model Context Protocol — 2026-07-28 Specification Release\",\"description\":\"Official release explanation for the current MCP protocol revision, including stateless core, MRTR, routing, caching, authorization hardening, extensions and deprecations.\"}},\"tunes\":{}},{\"id\":\"src-mcp-migration\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fts.sdk.modelcontextprotocol.io\u002Fv2\u002Fmigration\u002Fsupport-2026-07-28\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"MCP TypeScript SDK — Supporting protocol revision 2026-07-28\",\"description\":\"Version-specific implementation guidance for the current protocol revision and earlier-era compatibility.\"}},\"tunes\":{}},{\"id\":\"src-openai-mcp\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Ftools-connectors-mcp\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — MCP servers\",\"description\":\"Current OpenAI guidance for connecting models to remote MCP servers and local\u002Fprivate MCP servers through Secure MCP Tunnel.\"}},\"tunes\":{}},{\"id\":\"src-openai-agent-mcp\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents-api\u002Ftools\u002Fmcp\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — MCP connections for Agents API\",\"description\":\"Current MCP connection guidance covering service, environment and stdio locations plus allowed-tool controls.\"}},\"tunes\":{}},{\"id\":\"src-openai-tools\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Ftools\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — Tools\",\"description\":\"Current overview placing remote MCP servers alongside function calling, web search, shell and other model tools.\"}},\"tunes\":{}},{\"id\":\"src-openai-plugin-mcp\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fplugins\u002Fconcepts\u002Fmcp-server\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — MCP server concept\",\"description\":\"Current description of MCP servers exposing tools, resources and prompts for external service integrations.\"}},\"tunes\":{}}],\"version\":\"2.31.6\"}",{"time":1651,"blocks":1652,"version":2816},1791486641380,[1653,1657,1662,1667,1672,1677,1681,1685,1689,1693,1697,1701,1705,1709,1713,1739,1743,1747,1751,1755,1759,1784,1788,1792,1796,1820,1824,1828,1832,1836,1840,1844,1848,1852,1856,1860,1864,1868,1872,1896,1900,1904,1908,1912,1917,1921,1925,1929,1933,1937,1958,1962,1966,1970,1974,1978,1982,1986,1990,1994,2000,2004,2008,2012,2016,2020,2035,2039,2043,2047,2077,2081,2085,2089,2093,2097,2101,2105,2109,2113,2117,2121,2125,2129,2133,2137,2141,2146,2150,2154,2158,2162,2166,2170,2174,2178,2182,2186,2190,2194,2198,2202,2206,2210,2214,2241,2245,2249,2253,2257,2261,2265,2269,2273,2277,2314,2318,2323,2327,2331,2335,2339,2364,2369,2373,2395,2399,2403,2407,2411,2415,2458,2462,2505,2509,2550,2554,2605,2609,2613,2617,2621,2625,2629,2633,2637,2641,2645,2649,2653,2657,2661,2668,2672,2707,2711,2743,2747,2751,2755,2759,2763,2767,2774,2781,2788,2795,2802,2809],{"id":215,"data":1654,"type":218,"tunes":1656},{"text":1655},"The Model Context Protocol (MCP) is an open protocol for connecting AI applications to external capabilities and information through standardized client-server contracts. An MCP server can expose tools, resources and prompts; an MCP-compatible host or client discovers and uses those capabilities on behalf of an AI application. MCP does not require the server to run its own language model, and it does not replace the agent runtime, business authorization, tenant isolation, application APIs or domain architecture behind the exposed capabilities.",{},{"id":221,"data":1658,"type":226,"tunes":1661},{"body":1659,"title":1660,"variant":225},"\u003Cstrong>MCP standardizes the boundary between an AI host and external capability providers.\u003C\u002Fstrong>\u003Cbr>\u003Cbr>A useful mental model is:\u003Cbr>\u003Cstrong>User → AI host \u002F agent runtime → MCP client → MCP server → application\u002FAPI\u002Fdata\u002Ftool\u003C\u002Fstrong>.\u003Cbr>\u003Cbr>The model can remain entirely on the host side. The MCP server may be ordinary deterministic software that exposes structured capabilities.","Direct answer",{},{"id":229,"data":1663,"type":226,"tunes":1666},{"body":1664,"title":1665,"variant":233},"A filesystem MCP server can list or read files. A database MCP server can run approved queries. A Jira MCP server can expose issue operations. None of those servers needs an LLM to satisfy the MCP contract. If a server internally uses AI, that is an implementation choice behind the protocol boundary, not an MCP requirement.","An MCP server does not need its own AI model",{},{"id":236,"data":1668,"type":226,"tunes":1671},{"body":1669,"title":1670,"variant":240},"If an MCP server exposes \u003Ccode>delete_file\u003C\u002Fcode>, \u003Ccode>refund_order\u003C\u002Fcode> or \u003Ccode>deploy_service\u003C\u002Fcode>, that only means the capability exists. The server\u002Fapplication must still enforce identity, permissions, tenant scope, business rules, confirmation requirements and audit controls. Protocol discovery must never silently become authorization.","MCP capability is not business authority",{},{"id":243,"data":1673,"type":226,"tunes":1676},{"body":1674,"title":1675,"variant":247},"The current MCP specification revision is \u003Cstrong>2026-07-28\u003C\u002Fstrong>. Its major change is a stateless protocol core with self-describing requests, optional \u003Ccode>server\u002Fdiscover\u003C\u002Fcode>, routable HTTP headers, cacheable list\u002Fresource responses, authorization hardening and a formal extension model. The TypeScript SDK v2 is the current stable SDK line implementing this revision. Older 2025-era clients and servers still exist, so implementation guidance must remain version-aware.","Current-source note — 8 October 2026",{},{"id":250,"data":1678,"type":255,"tunes":1680},{"title":1679,"maxLevel":253,"minLevel":254},"Contents",{},{"id":258,"data":1682,"type":42,"tunes":1684},{"text":1683,"level":254},"What MCP really standardizes",{},{"id":263,"data":1686,"type":218,"tunes":1688},{"text":1687},"Before MCP, every AI application could integrate external systems through its own tool schema, plugin format, authentication convention and connection code. The same service could need different adapters for a desktop AI client, an IDE agent and a custom application.",{},{"id":268,"data":1690,"type":218,"tunes":1692},{"text":1691},"MCP creates a reusable protocol boundary. The external system exposes capabilities through an MCP server, while compatible AI hosts implement an MCP client. This reduces integration coupling between the AI application and the underlying tool or data provider.",{},{"id":273,"data":1694,"type":218,"tunes":1696},{"text":1695},"The protocol does not standardize the entire application. It standardizes how capabilities are described, discovered and invoked across that boundary.",{},{"id":278,"data":1698,"type":42,"tunes":1700},{"text":1699,"level":254},"The simplest example",{},{"id":283,"data":1702,"type":218,"tunes":1704},{"text":1703},"Suppose an AI coding application needs access to a local project directory. Without MCP, the application might implement its own filesystem integration directly.",{},{"id":288,"data":1706,"type":218,"tunes":1708},{"text":1707},"With MCP, a filesystem server can expose capabilities such as listing directories, reading approved files or writing inside an allowed workspace. The AI host connects through an MCP client and presents those capabilities to the model or agent runtime.",{},{"id":293,"data":1710,"type":218,"tunes":1712},{"text":1711},"The server does not need to understand the user's natural-language request. The host\u002Fmodel decides which capability is useful; the MCP server executes the structured request under its own security rules.",{},{"id":298,"data":1714,"type":324,"tunes":1738},{"steps":1715,"title":1737,"orientation":323},[1716,1719,1722,1725,1728,1731,1734],{"label":1717,"description":1718},"1. Host connects to server","The MCP-capable application configures access to the external MCP server.",{"label":1720,"description":1721},"2. Capabilities are discovered","The client learns which tools, resources or prompts the server exposes.",{"label":1723,"description":1724},"3. Model or runtime selects a capability","The AI application decides that one exposed capability is needed.",{"label":1726,"description":1727},"4. Client sends structured request","Arguments are sent through MCP to the server.",{"label":1729,"description":1730},"5. Server authorizes and executes","The server validates the request and calls its underlying system.",{"label":1732,"description":1733},"6. Result returns to host","The result becomes an observation or context input.",{"label":1735,"description":1736},"7. Host decides what happens next","The model\u002Fruntime may answer, call another tool or continue a workflow.","A basic MCP tool call",{},{"id":327,"data":1740,"type":42,"tunes":1742},{"text":1741,"level":254},"Where the simple example stops",{},{"id":332,"data":1744,"type":218,"tunes":1746},{"text":1745},"MCP does not define how the host chooses a tool, how an agent plans, how a business workflow is modeled or how a domain object such as an invoice or deployment should behave.",{},{"id":337,"data":1748,"type":218,"tunes":1750},{"text":1749},"A protocol can make the integration interoperable while the underlying application remains incorrect, insecure or badly designed. A perfectly valid MCP request can still call the wrong business capability.",{},{"id":342,"data":1752,"type":218,"tunes":1754},{"text":1753},"The central boundary is: MCP standardizes integration semantics, not application truth or business correctness.",{},{"id":347,"data":1756,"type":42,"tunes":1758},{"text":1757,"level":254},"The MCP architecture: host, client and server",{},{"id":352,"data":1760,"type":376,"tunes":1783},{"content":1761,"stretched":43,"withHeadings":14},[1762,1765,1768,1771,1774,1777,1780],[1763,1764],"Component","Responsibility",[1766,1767],"AI host","User-facing AI application or runtime that owns model interaction, context and overall workflow",[1769,1770],"MCP client","Protocol-side component used by the host to communicate with an MCP server",[1772,1773],"MCP server","Publishes capabilities and handles MCP requests",[1775,1776],"Underlying system","Application, API, database, filesystem, SaaS platform or service behind the MCP server",[1778,1779],"Model","Chooses or reasons about capabilities according to the host\u002Fruntime design; it is not necessarily inside the MCP server",[1781,1782],"Authorization\u002Fbusiness policy","Determines whether a requested operation is actually permitted",{},{"id":379,"data":1785,"type":218,"tunes":1787},{"text":1786},"A host can connect to multiple MCP servers, and one MCP server can front one or several underlying systems. The host remains responsible for integrating MCP results into the broader AI application.",{},{"id":384,"data":1789,"type":218,"tunes":1791},{"text":1790},"The server can be local to the host, run as a separate process or be remote over a network transport. Hosting topology and model location are independent decisions.",{},{"id":389,"data":1793,"type":42,"tunes":1795},{"text":1794,"level":254},"The three core server primitives",{},{"id":394,"data":1797,"type":425,"tunes":1819},{"rows":1798,"title":1811,"layout":376,"columns":1812},[1799,1802,1805,1808],{"id":398,"label":1800,"values":1801},"Primary purpose",[401,401,401],{"id":403,"label":1803,"values":1804},"Typical interaction",[401,401,401],{"id":407,"label":1806,"values":1807},"Example",[401,401,401],{"id":411,"label":1809,"values":1810},"Typical risk",[401,401,401],"Tools, resources and prompts solve different needs",[1813,1815,1817],{"id":417,"label":1814},"Tools",{"id":420,"label":1816},"Resources",{"id":423,"label":1818},"Prompts",{},{"id":428,"data":1821,"type":42,"tunes":1823},{"text":1822,"level":254},"Tools: callable capabilities",{},{"id":433,"data":1825,"type":218,"tunes":1827},{"text":1826},"Tools are structured operations an MCP server makes available to the host. A tool has a name, description and input schema; modern implementations can also provide structured output.",{},{"id":438,"data":1829,"type":218,"tunes":1831},{"text":1830},"Examples include searching a repository, reading a customer record, creating a ticket, running a build or sending a message. Tools can be read-only or have side effects.",{},{"id":443,"data":1833,"type":218,"tunes":1835},{"text":1834},"A good MCP tool surface should represent coherent user or agent goals rather than mechanically mirror every internal API endpoint. Operations with different permissions, confirmation requirements or blast radius should usually be separate tools.",{},{"id":448,"data":1837,"type":42,"tunes":1839},{"text":1838,"level":254},"Resources: readable context and data",{},{"id":453,"data":1841,"type":218,"tunes":1843},{"text":1842},"Resources expose data or content that a client can list or read. They fit naturally when the semantic operation is “give me this artifact or information” rather than “perform this action.”",{},{"id":458,"data":1845,"type":218,"tunes":1847},{"text":1846},"A resource URI is not an authorization grant. The server still owns access control and must verify which principal may read the underlying object.",{},{"id":463,"data":1849,"type":218,"tunes":1851},{"text":1850},"The 2026-07-28 protocol revision adds cache semantics for list and resource-read responses, including freshness and cache scope, making caching behavior more explicit.",{},{"id":468,"data":1853,"type":42,"tunes":1855},{"text":1854,"level":254},"Prompts: reusable templates",{},{"id":473,"data":1857,"type":218,"tunes":1859},{"text":1858},"MCP prompts let a server publish reusable prompt templates to compatible clients. This can keep domain-specific instructions close to the capability provider.",{},{"id":478,"data":1861,"type":218,"tunes":1863},{"text":1862},"A prompt supplied by an MCP server does not automatically outrank the host's system or security instructions. The host decides how prompt material enters its context hierarchy.",{},{"id":483,"data":1865,"type":218,"tunes":1867},{"text":1866},"Protocol-provided prompt content should therefore be treated as capability data with explicit trust semantics, not as unrestricted instruction authority.",{},{"id":488,"data":1869,"type":42,"tunes":1871},{"text":1870,"level":254},"Tool or resource?",{},{"id":493,"data":1873,"type":376,"tunes":1895},{"content":1874,"stretched":43,"withHeadings":14},[1875,1878,1881,1884,1887,1889,1892],[1876,1877],"Need","Prefer",[1879,1880],"Perform an action with structured arguments","Tool",[1882,1883],"Read a specific stable artifact","Resource",[1885,1886],"Search or calculate dynamically","Usually tool",[1888,1880],"Modify external state",[1890,1891],"Package reusable prompt instructions","Prompt",[1893,1894],"Long-running asynchronous execution","Tool plus application\u002Fruntime task handling or an MCP extension",{},{"id":516,"data":1897,"type":42,"tunes":1899},{"text":1898,"level":254},"Where is the AI model?",{},{"id":521,"data":1901,"type":218,"tunes":1903},{"text":1902},"MCP does not require the model to run on the MCP server. The model can be cloud-hosted, locally hosted, embedded in the desktop application or reached through another provider.",{},{"id":526,"data":1905,"type":218,"tunes":1907},{"text":1906},"The host normally owns the model interaction. The MCP server exposes external capability. A local MCP server can therefore be used by a host whose model runs in the cloud, and a remote MCP server can be used by a host whose model runs locally.",{},{"id":531,"data":1909,"type":218,"tunes":1911},{"text":1910},"If the MCP server itself calls an LLM internally, that model is part of the server's implementation behind the protocol boundary; it is not required by MCP.",{},{"id":536,"data":1913,"type":226,"tunes":1916},{"body":1914,"title":1915,"variant":233},"\u003Cstrong>Local MCP does not imply local inference, and remote MCP does not imply remote inference.\u003C\u002Fstrong> Connection location, tool-execution location and model\u002Fprovider location are separate architecture dimensions.","Protocol location ≠ inference location",{},{"id":542,"data":1918,"type":42,"tunes":1920},{"text":1919,"level":254},"MCP does not replace APIs",{},{"id":547,"data":1922,"type":218,"tunes":1924},{"text":1923},"An MCP server often wraps existing APIs or services. REST, GraphQL, SQL, SDK calls and internal service contracts can remain exactly where they are.",{},{"id":552,"data":1926,"type":218,"tunes":1928},{"text":1927},"MCP adds an AI-facing interoperability layer. The underlying domain API can remain the authoritative application contract for ordinary deterministic clients.",{},{"id":557,"data":1930,"type":218,"tunes":1932},{"text":1931},"The usual architecture is therefore API\u002Fservice first, selected AI-facing capability second — not “replace every API with MCP.”",{},{"id":562,"data":1934,"type":42,"tunes":1936},{"text":1935,"level":254},"MCP vs function calling",{},{"id":567,"data":1938,"type":425,"tunes":1957},{"rows":1939,"title":1952,"layout":376,"columns":1953},[1940,1943,1946,1949],{"id":571,"label":1941,"values":1942},"Scope",[401,401],{"id":575,"label":1944,"values":1945},"Tool definition",[401,401],{"id":579,"label":1947,"values":1948},"Portability",[401,401],{"id":583,"label":1950,"values":1951},"Can they coexist?",[401,401],"Function calling and MCP are related but not identical",[1954,1956],{"id":589,"label":1955},"Function calling",{"id":592,"label":593},{},{"id":596,"data":1959,"type":218,"tunes":1961},{"text":1960},"OpenAI currently exposes remote MCP servers as one tool type alongside ordinary function calling, web search, shell and other tools. That implementation illustrates the architectural relationship: MCP connectivity and the model's own tool-call interface can be composed.",{},{"id":601,"data":1963,"type":42,"tunes":1965},{"text":1964,"level":254},"MCP does not create the agent loop",{},{"id":606,"data":1967,"type":218,"tunes":1969},{"text":1968},"An AI agent needs a runtime that can decide, invoke tools, observe results, update state and continue or stop. MCP can supply some of the tools and data used by that loop.",{},{"id":611,"data":1971,"type":218,"tunes":1973},{"text":1972},"The MCP server does not automatically become the planner, memory system or orchestrator. Those responsibilities normally remain in the host or agent runtime.",{},{"id":616,"data":1975,"type":218,"tunes":1977},{"text":1976},"A non-agentic application can also use MCP. One deterministic MCP tool call does not require an autonomous multi-step agent.",{},{"id":621,"data":1979,"type":42,"tunes":1981},{"text":1980,"level":254},"MCP vs A2A",{},{"id":626,"data":1983,"type":218,"tunes":1985},{"text":1984},"MCP primarily connects an AI host or agent to capabilities such as tools, resources and data. A2A targets collaboration between independent agent systems.",{},{"id":631,"data":1987,"type":218,"tunes":1989},{"text":1988},"A remote agent can internally use MCP to reach databases and tools while exposing an A2A interface to other agents. The protocols can therefore be layered rather than substituted.",{},{"id":636,"data":1991,"type":218,"tunes":1993},{"text":1992},"The existing protocol-stack article owns the broader MCP\u002FA2A\u002FUCP\u002FAP2\u002FA2UI comparison; G02 remains the canonical MCP definition.",{},{"id":641,"data":1995,"type":647,"tunes":1999},{"url":643,"title":1996,"excerpt":1997,"ctaLabel":1998},"MCP vs A2A vs UCP vs AP2 vs A2UI: The Agent Protocol Stack Explained","A broader responsibility map showing how MCP composes with agent collaboration, commerce, payment authority and agent-driven UI protocols.","Read the protocol stack",{},{"id":650,"data":2001,"type":42,"tunes":2003},{"text":2002,"level":254},"Local and remote MCP use different transport realities",{},{"id":655,"data":2005,"type":218,"tunes":2007},{"text":2006},"MCP can connect to local and remote servers. Local desktop integrations commonly use process-level transports such as stdio; remote servers use HTTP-oriented transport.",{},{"id":660,"data":2009,"type":218,"tunes":2011},{"text":2010},"The 2026-07-28 revision makes the protocol core stateless. Requests carry the information needed for protocol handling instead of depending on the earlier protocol-level session model.",{},{"id":665,"data":2013,"type":218,"tunes":2015},{"text":2014},"The current revision also places method and capability names in HTTP headers so gateways, WAFs, rate limiters and load balancers can route and meter MCP traffic more naturally.",{},{"id":670,"data":2017,"type":42,"tunes":2019},{"text":2018,"level":254},"Why MCP version awareness matters",{},{"id":675,"data":2021,"type":376,"tunes":2034},{"content":2022,"stretched":43,"withHeadings":14},[2023,2026,2029,2031],[2024,2025],"Protocol era","Operational characteristic",[2027,2028],"2025-11-25 and earlier","Handshake\u002Fsession-oriented lifecycle and older Streamable HTTP behavior",[685,2030],"Stateless core, optional server discovery, self-describing requests, routing headers, cache hints, MRTR and authorization hardening",[2032,2033],"Extensions","Capabilities such as Tasks and MCP Apps can version separately from the base protocol",{},{"id":692,"data":2036,"type":218,"tunes":2038},{"text":2037},"SDK version and protocol version are also different things. The current TypeScript v2 SDK is the stable line for the 2026-07-28 revision, while older v1.x remains a maintenance line for 2025-era behavior.",{},{"id":697,"data":2040,"type":218,"tunes":2042},{"text":2041},"Architecture documentation should record both the SDK\u002Flibrary version and the protocol revision where interoperability behavior depends on them.",{},{"id":702,"data":2044,"type":42,"tunes":2046},{"text":2045,"level":254},"What changed in MCP 2026-07-28",{},{"id":707,"data":2048,"type":376,"tunes":2076},{"content":2049,"stretched":43,"withHeadings":14},[2050,2053,2056,2058,2061,2064,2067,2070,2073],[2051,2052],"Change","Why it matters",[2054,2055],"Stateless core","Remote servers can scale behind ordinary load balancers without protocol-level sticky sessions",[717,2057],"Clients can inspect server capabilities when needed",[2059,2060],"Self-describing requests","Protocol version and client capability metadata travel per request",[2062,2063],"Mcp-Method \u002F Mcp-Name headers","Gateways can route, meter and apply policy without parsing bodies",[2065,2066],"Cache hints","Lists\u002Fresource reads communicate freshness and sharing scope",[2068,2069],"Multi Round-Trip Requests","Servers can require additional input without the older bidirectional request model",[2071,2072],"Authorization hardening","Issuer validation and credential binding strengthen remote auth behavior",[2074,2075],"Extensions framework","Tasks, MCP Apps and other capabilities can evolve separately",{},{"id":739,"data":2078,"type":42,"tunes":2080},{"text":2079,"level":254},"Roots, sampling and logging are no longer the direction for new implementations",{},{"id":744,"data":2082,"type":218,"tunes":2084},{"text":2083},"The 2026-07-28 release marks roots, sampling and logging as deprecated protocol capabilities with a defined compatibility window.",{},{"id":749,"data":2086,"type":218,"tunes":2088},{"text":2087},"Older tutorials may still show these features as central primitives. New implementation work should follow the current specification rather than copy older lifecycle diagrams blindly.",{},{"id":754,"data":2090,"type":218,"tunes":2092},{"text":2091},"Deprecation does not mean immediate removal. It means new systems should avoid unnecessary new dependencies on capabilities the protocol is moving away from.",{},{"id":759,"data":2094,"type":42,"tunes":2096},{"text":2095,"level":254},"Long-running work is not the same as ordinary MCP tool invocation",{},{"id":764,"data":2098,"type":218,"tunes":2100},{"text":2099},"Long-running operations need lifecycle semantics beyond a simple immediate tool result. In the current ecosystem, Tasks moved into a dedicated MCP extension.",{},{"id":769,"data":2102,"type":218,"tunes":2104},{"text":2103},"This reinforces a useful design principle: the base protocol does not need to absorb every agent-runtime concern.",{},{"id":774,"data":2106,"type":218,"tunes":2108},{"text":2107},"An application can also keep long-running workflow ownership entirely in its own runtime and use ordinary MCP tools as underlying operations.",{},{"id":779,"data":2110,"type":42,"tunes":2112},{"text":2111,"level":254},"MCP Apps extend UI capability without redefining the core protocol",{},{"id":784,"data":2114,"type":218,"tunes":2116},{"text":2115},"MCP Apps associate richer interactive UI experiences with MCP tools through the extension model.",{},{"id":789,"data":2118,"type":218,"tunes":2120},{"text":2119},"The host still controls how that UI is embedded, sandboxed and secured.",{},{"id":794,"data":2122,"type":218,"tunes":2124},{"text":2123},"Core capability exchange and UI rendering should therefore remain separate architecture responsibilities.",{},{"id":799,"data":2126,"type":42,"tunes":2128},{"text":2127,"level":254},"MCP authorization is not your complete authorization model",{},{"id":804,"data":2130,"type":218,"tunes":2132},{"text":2131},"Remote MCP needs protocol-level authentication and authorization mechanisms so clients and servers can establish trusted access. The current specification continues to harden OAuth\u002FOIDC-related behavior.",{},{"id":809,"data":2134,"type":218,"tunes":2136},{"text":2135},"That layer answers whether a client is allowed to connect or request protocol scopes. It does not automatically answer whether Alice may refund order 123, whether an agent may write production configuration or whether Tenant A may read Tenant B data.",{},{"id":814,"data":2138,"type":218,"tunes":2140},{"text":2139},"Those domain decisions belong in the server\u002Fapplication authorization model and must be enforced before invoking the underlying operation.",{},{"id":819,"data":2142,"type":226,"tunes":2145},{"body":2143,"title":2144,"variant":240},"Connection trust, tool visibility, tool permission, user authorization, tenant isolation and business approval are different controls. Keep them separate.","Never map “authenticated MCP client” to “trusted for every tool”",{},{"id":825,"data":2147,"type":42,"tunes":2149},{"text":2148,"level":254},"Identity can cross several boundaries",{},{"id":830,"data":2151,"type":218,"tunes":2153},{"text":2152},"An MCP request may involve the MCP client application, the signed-in human, an agent\u002Fsession identity and a downstream service account.",{},{"id":835,"data":2155,"type":218,"tunes":2157},{"text":2156},"The server needs an explicit policy for which principal the operation is performed on behalf of. Otherwise a powerful service credential can become a confused-deputy path.",{},{"id":840,"data":2159,"type":218,"tunes":2161},{"text":2160},"For enterprise use, correlation between user identity, agent identity, MCP connection and downstream authorization is as important as protocol compatibility.",{},{"id":845,"data":2163,"type":42,"tunes":2165},{"text":2164,"level":254},"Tenant isolation remains outside MCP capability discovery",{},{"id":850,"data":2167,"type":218,"tunes":2169},{"text":2168},"A multi-tenant MCP server must apply tenant scope when it reads or changes tenant-owned resources. Returning a tool named search_documents does not define which tenant's documents are eligible.",{},{"id":855,"data":2171,"type":218,"tunes":2173},{"text":2172},"Tenant scope should be derived from trusted identity or membership and carried into databases, caches, vector search, object storage and downstream APIs.",{},{"id":860,"data":2175,"type":218,"tunes":2177},{"text":2176},"Retrieving cross-tenant content and asking the model not to use it is already an isolation failure.",{},{"id":865,"data":2179,"type":42,"tunes":2181},{"text":2180,"level":254},"MCP does not define Source of Truth",{},{"id":870,"data":2183,"type":218,"tunes":2185},{"text":2184},"An MCP server can expose a database, document repository, web search service or AI-generated summary. The protocol does not declare which source is authoritative for a claim.",{},{"id":875,"data":2187,"type":218,"tunes":2189},{"text":2188},"Source-of-Truth rules belong to application\u002Fdomain architecture. The host or server can encode authority through tool design, metadata, access policy or validation, but MCP itself does not make one capability “true.”",{},{"id":880,"data":2191,"type":218,"tunes":2193},{"text":2192},"A tool can therefore be perfectly callable through MCP and still return stale, secondary or non-authoritative information.",{},{"id":885,"data":2195,"type":42,"tunes":2197},{"text":2196,"level":254},"MCP and context engineering",{},{"id":890,"data":2199,"type":218,"tunes":2201},{"text":2200},"MCP can increase the capabilities and information available to an AI application, but context engineering still determines what reaches the model.",{},{"id":895,"data":2203,"type":218,"tunes":2205},{"text":2204},"Tool catalogs consume model-visible context in many hosts. Tool results can be large. Resources can be numerous. A host needs selection, filtering, dynamic loading and compaction rather than exposing everything on every turn.",{},{"id":900,"data":2207,"type":218,"tunes":2209},{"text":2208},"Capability availability and model-visible context should therefore be treated as separate layers.",{},{"id":905,"data":2211,"type":42,"tunes":2213},{"text":2212,"level":254},"Design MCP tools around outcomes and risk boundaries",{},{"id":910,"data":2215,"type":376,"tunes":2240},{"content":2216,"stretched":43,"withHeadings":14},[2217,2220,2222,2225,2228,2231,2234,2237],[2218,2219],"Weak tool design","Stronger tool design",[917,2221],"Narrow domain tools with validated operations",[2223,2224],"One admin tool for all actions","Separate read\u002Fwrite\u002Fapproval operations",[2226,2227],"Raw internal API mirrored 1:1","AI-facing contract around coherent user goals",[2229,2230],"One broad filesystem tool","Workspace-scoped read\u002Fwrite operations",[2232,2233],"Security policy only in description","Server enforces policy in code",[2235,2236],"Unbounded raw response","Structured decision-relevant output",[2238,2239],"Delete\u002Fupdate mixed with read","Separate side-effect tools with confirmation policy",{},{"id":939,"data":2242,"type":42,"tunes":2244},{"text":2243,"level":254},"Approvals belong in the execution architecture",{},{"id":944,"data":2246,"type":218,"tunes":2248},{"text":2247},"A host can require user approval before invoking selected MCP tools. OpenAI's current MCP integration supports automatic or explicit-approval execution patterns.",{},{"id":949,"data":2250,"type":218,"tunes":2252},{"text":2251},"Host approval is useful but should not be the server's only protection because another compatible MCP client may use a different approval model.",{},{"id":954,"data":2254,"type":218,"tunes":2256},{"text":2255},"For destructive or financially consequential actions, use defense in depth: clear tool contract, runtime approval where appropriate, server-side authorization, business validation and audit.",{},{"id":959,"data":2258,"type":42,"tunes":2260},{"text":2259,"level":254},"MCP observability should connect protocol calls to domain actions",{},{"id":964,"data":2262,"type":218,"tunes":2264},{"text":2263},"An MCP trace is most useful when it can be correlated with the underlying application call, database change or business transaction.",{},{"id":969,"data":2266,"type":218,"tunes":2268},{"text":2267},"The 2026-07-28 ecosystem standardizes W3C Trace Context propagation conventions, making it easier to follow a request across host, client, server and downstream services.",{},{"id":974,"data":2270,"type":218,"tunes":2272},{"text":2271},"Protocol logs alone are not enough for consequential operations. Audit evidence should also record relevant principal, tenant, target resource, approval and resulting state change.",{},{"id":979,"data":2274,"type":42,"tunes":2276},{"text":2275,"level":254},"What MCP cannot fix",{},{"id":984,"data":2278,"type":376,"tunes":2313},{"content":2279,"stretched":43,"withHeadings":14},[2280,2283,2286,2289,2292,2295,2298,2301,2304,2307,2310],[2281,2282],"Problem","Why MCP does not solve it",[2284,2285],"Bad business API","MCP can expose the bad API more consistently",[2287,2288],"Wrong data","Protocol validity does not create factual correctness",[2290,2291],"Missing tenant isolation","Tool discovery does not enforce resource ownership",[2293,2294],"Excessive privileges","A standardized tool can still be overprivileged",[2296,2297],"Poor agent planning","MCP exposes capabilities; runtime\u002Fmodel still chooses how to use them",[2299,2300],"Bad retry\u002Fidempotency design","Protocol calls do not make side effects safe",[2302,2303],"No Source of Truth","MCP does not decide which system owns a fact",[2305,2306],"Weak evaluation","Interoperability does not prove task success",[2308,2309],"No audit policy","Transport traces do not define retention or accountability",[2311,2312],"Protocol mismatch","Old\u002Fnew versions can still require migration or compatibility handling",{},{"id":1022,"data":2315,"type":42,"tunes":2317},{"text":2316,"level":254},"Original implementation evidence: Aaasaasa AI Client",{},{"id":1027,"data":2319,"type":226,"tunes":2322},{"body":2320,"title":2321,"variant":247},"Aaasaasa AI Client contains an authenticated local MCP connector\u002Fbroker for approved local directories and integration through Secure MCP Tunnel. This is concrete implementation evidence for the protocol boundary and permission architecture, not a claim of a general-purpose commercial MCP platform.","Implementation evidence",{},{"id":1033,"data":2324,"type":218,"tunes":2326},{"text":2325},"The application can run an authenticated Streamable HTTP MCP endpoint on loopback. The endpoint exposes only directories selected through the central workspace permission broker.",{},{"id":1038,"data":2328,"type":218,"tunes":2330},{"text":2329},"The local endpoint and remote route are separate concerns: the local connector can bind only to loopback, while a Secure MCP Tunnel can make the approved MCP service reachable to a permitted external AI client without exposing the whole local machine.",{},{"id":1043,"data":2332,"type":218,"tunes":2334},{"text":2333},"The central permission model distinguishes chat-only, read-only, project-write and custom-directory profiles. Direct Chat has no filesystem or shell access; tool-capable agent runtimes use the selected permission profile.",{},{"id":1048,"data":2336,"type":218,"tunes":2338},{"text":2337},"This is a direct implementation of the G02 boundary: MCP provides the standardized capability connection, while the application-owned permission broker decides which directories the server may expose.",{},{"id":1053,"data":2340,"type":376,"tunes":2363},{"content":2341,"stretched":43,"withHeadings":14},[2342,2345,2348,2351,2354,2357,2360],[2343,2344],"Implemented element","Architecture evidence",[2346,2347],"Authenticated local MCP endpoint","MCP server can be a local deterministic capability service",[2349,2350],"Loopback binding","Network exposure and protocol capability are separate decisions",[2352,2353],"Secure MCP Tunnel integration","Private\u002Flocal MCP can be bridged through a controlled route",[2355,2356],"Central permission broker","MCP capability is constrained by application policy",[2358,2359],"Selected directory scope","Filesystem visibility is explicitly bounded",[2361,2362],"Direct Chat without OS tools","Model access does not automatically imply tool access",{},{"id":1079,"data":2365,"type":226,"tunes":2368},{"body":2366,"title":2367,"variant":240},"The implementation demonstrates MCP connectivity and permission-scoped local directory exposure. It does not imply that every MCP primitive, every 2026-07-28 feature or every enterprise authorization extension is implemented.","Evidence boundary",{},{"id":1085,"data":2370,"type":42,"tunes":2372},{"text":2371,"level":254},"When MCP is a good fit",{},{"id":1090,"data":2374,"type":376,"tunes":2394},{"content":2375,"stretched":43,"withHeadings":14},[2376,2379,2382,2385,2388,2391],[2377,2378],"MCP is a strong fit when","A direct integration may be simpler when",[2380,2381],"The same capability should be reusable across multiple AI hosts","One application owns both sides and portability has little value",[2383,2384],"An external system wants to publish discoverable AI-facing tools\u002Fresources","A single stable internal API call is sufficient",[2386,2387],"You want a standard boundary around local tools\u002Fdata","There is no AI-facing interoperability requirement",[2389,2390],"Tool providers and AI clients evolve independently","The integration is intentionally private and tightly coupled",[2392,2393],"You want ecosystem-compatible capability discovery","The capability set is tiny and fixed in application code",{},{"id":1113,"data":2396,"type":42,"tunes":2398},{"text":2397,"level":254},"When you do not need MCP",{},{"id":1118,"data":2400,"type":218,"tunes":2402},{"text":2401},"Do not add MCP merely because the application uses AI. If your backend already calls one internal API and no independent MCP client needs that capability, an ordinary function or service call may be clearer.",{},{"id":1123,"data":2404,"type":218,"tunes":2406},{"text":2405},"MCP adds value at an interoperability boundary. Without that boundary, the protocol can become an unnecessary adapter layer.",{},{"id":1128,"data":2408,"type":218,"tunes":2410},{"text":2409},"The architectural question is not “Does this project have AI?” but “Do independently evolving AI hosts and capability providers benefit from a standard contract?”",{},{"id":1133,"data":2412,"type":42,"tunes":2414},{"text":2413,"level":254},"MCP security checklist",{},{"id":1138,"data":2416,"type":376,"tunes":2457},{"content":2417,"stretched":43,"withHeadings":14},[2418,2421,2424,2427,2430,2433,2436,2439,2442,2445,2448,2451,2454],[2419,2420],"Boundary","Question",[2422,2423],"Server identity","Which MCP server am I actually connected to?",[2425,2426],"Client identity","Which application\u002Fclient is requesting access?",[2428,2429],"End-user identity","On whose behalf is the operation performed?",[2431,2432],"Tool allowlist","Which capabilities may this host\u002Fagent discover and call?",[2434,2435],"Business permission","May this principal perform this operation?",[2437,2438],"Tenant scope","Which tenant\u002Fresource boundary applies?",[2440,2441],"Credential isolation","Are credentials bound correctly and kept outside model context?",[2443,2444],"Approval","Which side effects require human confirmation?",[2446,2447],"Input validation","Are tool arguments validated independently of model output?",[2449,2450],"Output trust","Can returned content contain untrusted instructions or sensitive data?",[2452,2453],"Network exposure","Is a local server accidentally exposed beyond intended interfaces?",[2455,2456],"Audit","Can a protocol call be correlated with the downstream action?",{},{"id":1181,"data":2459,"type":42,"tunes":2461},{"text":2460,"level":254},"Common misconceptions",{},{"id":1186,"data":2463,"type":376,"tunes":2504},{"content":2464,"stretched":43,"withHeadings":14},[2465,2468,2471,2474,2477,2480,2483,2486,2489,2492,2495,2498,2501],[2466,2467],"Misconception","Correction",[2469,2470],"“An MCP server is an AI server.”","It can be ordinary deterministic software exposing capabilities.",[2472,2473],"“I need my own LLM on the MCP server.”","No. The model can live entirely on the host side.",[2475,2476],"“MCP replaces REST APIs.”","MCP often wraps existing APIs for AI-facing interoperability.",[2478,2479],"“MCP is an agent framework.”","MCP supplies capabilities; an agent runtime manages iteration and state.",[2481,2482],"“MCP and function calling compete.”","A host can bridge MCP capabilities into its model tool interface.",[2484,2485],"“MCP replaces A2A.”","MCP focuses on capability integration; A2A focuses on agent collaboration.",[2487,2488],"“If a tool is listed, the user may call it.”","Discovery is not authorization.",[2490,2491],"“OAuth solves business permissions.”","Connection authorization does not replace domain authorization or tenant isolation.",[2493,2494],"“Local MCP means local AI.”","Tool-server location and inference location are independent.",[2496,2497],"“MCP makes tool output trustworthy.”","Data quality, authority and provenance still belong to the source\u002Fapplication.",[2499,2500],"“One giant generic tool is flexible.”","Over-broad tools weaken permissions, validation and observability.",[2502,2503],"“Old tutorials are implementation-current.”","The 2026-07-28 revision materially changed lifecycle and transport behavior.",{},{"id":1230,"data":2506,"type":42,"tunes":2508},{"text":2507,"level":254},"A practical MCP design sequence",{},{"id":1235,"data":2510,"type":324,"tunes":2549},{"steps":2511,"title":2548,"orientation":323},[2512,2515,2518,2521,2524,2527,2530,2533,2536,2539,2542,2545],{"label":2513,"description":2514},"1. Identify the interoperability boundary","Confirm that independent AI hosts actually need reusable access.",{"label":2516,"description":2517},"2. Keep the domain API authoritative","Preserve the real application\u002Fservice contract behind MCP.",{"label":2519,"description":2520},"3. Choose primitives deliberately","Use tools, resources and prompts according to their semantics.",{"label":2522,"description":2523},"4. Split by risk and permission","Separate read, write, destructive and approval-required operations.",{"label":2525,"description":2526},"5. Define identity propagation","Know which client, user, agent and downstream principal each call represents.",{"label":2528,"description":2529},"6. Enforce business authorization","Validate permissions, tenant scope and target ownership.",{"label":2531,"description":2532},"7. Choose local or remote transport","Match deployment topology to the real need.",{"label":2534,"description":2535},"8. Pin protocol\u002FSDK expectations","Document 2026-07-28 versus older compatibility.",{"label":2537,"description":2538},"9. Add approvals for consequential actions","Use risk-appropriate confirmation controls.",{"label":2540,"description":2541},"10. Design structured outputs","Return concise machine-usable results.",{"label":2543,"description":2544},"11. Add tracing and audit correlation","Connect MCP calls to downstream service\u002Fbusiness events.",{"label":2546,"description":2547},"12. Test portability","Verify more than one client where interoperability is a stated requirement.","Design the boundary before implementing the server",{},{"id":1277,"data":2551,"type":42,"tunes":2553},{"text":2552,"level":254},"MCP architecture checklist",{},{"id":1282,"data":2555,"type":376,"tunes":2604},{"content":2556,"stretched":43,"withHeadings":14},[2557,2559,2562,2565,2568,2571,2574,2577,2580,2583,2586,2589,2592,2595,2598,2601],[2420,2558],"Expected answer",[2560,2561],"Why is MCP needed?","A real AI-facing interoperability boundary",[2563,2564],"What does the server expose?","Explicit tools\u002Fresources\u002Fprompts",[2566,2567],"Where does the model run?","Independent host\u002Fprovider decision",[2569,2570],"Where does tool execution run?","Named server\u002Fruntime location",[2572,2573],"Which protocol revision is expected?","Version-aware contract",[2575,2576],"Who is the requesting principal?","Client\u002Fuser\u002Fagent identity model",[2578,2579],"Which tools may be discovered?","Allowlist\u002Fcapability policy",[2581,2582],"Which operations may execute?","Server-side business authorization",[2584,2585],"How is tenant\u002Fresource scope enforced?","Trusted tenant\u002Fresource ownership checks",[2587,2588],"Which actions need approval?","Risk-based confirmation policy",[2590,2591],"How are credentials protected?","Trusted runtime storage, not model-visible secrets",[2593,2594],"How is output bounded?","Structured relevant result contract",[2596,2597],"How are calls traced?","Correlation through MCP to downstream action",[2599,2600],"What happens if MCP is unavailable?","Defined fallback\u002Ffailure behavior",[2602,2603],"Can another compatible host use it?","Portability validated where required",{},{"id":1334,"data":2606,"type":42,"tunes":2608},{"text":2607,"level":254},"Edge cases and limitations",{},{"id":1339,"data":2610,"type":218,"tunes":2612},{"text":2611},"A local stdio MCP server can have little network exposure while still be dangerous if the process itself has excessive filesystem or shell permissions.",{},{"id":1344,"data":2614,"type":218,"tunes":2616},{"text":2615},"A remote MCP server may expose only public documentation or highly sensitive enterprise actions. “Remote MCP” says little about risk without the capability and authorization context.",{},{"id":1349,"data":2618,"type":218,"tunes":2620},{"text":2619},"Some servers may use only tools and ignore resources\u002Fprompts. MCP compatibility does not require every optional primitive to be equally important.",{},{"id":1354,"data":2622,"type":218,"tunes":2624},{"text":2623},"A host can translate between its own internal tool model and MCP. Users may never see the protocol boundary directly, which is acceptable if security and attribution remain clear.",{},{"id":1359,"data":2626,"type":218,"tunes":2628},{"text":2627},"MCP continues to evolve rapidly. Extensions, authorization patterns, SDK APIs and ecosystem conventions can change faster than the core architectural distinction.",{},{"id":1364,"data":2630,"type":42,"tunes":2632},{"text":2631,"level":254},"What would change this answer?",{},{"id":1369,"data":2634,"type":218,"tunes":2636},{"text":2635},"Future MCP revisions can change lifecycle, transports, authorization and extension mechanisms. The July 2026 revision already demonstrates why implementation-specific claims must be dated.",{},{"id":1374,"data":2638,"type":218,"tunes":2640},{"text":2639},"The canonical boundary would change only if MCP expanded from an interoperability protocol into an end-to-end application\u002Fagent architecture standard. That is not what the current protocol defines.",{},{"id":1379,"data":2642,"type":218,"tunes":2644},{"text":2643},"For implementation work, always check the current specification and exact SDK line instead of copying version-sensitive examples from older tutorials.",{},{"id":1384,"data":2646,"type":42,"tunes":2648},{"text":2647,"level":254},"Related canonical knowledge",{},{"id":1389,"data":2650,"type":218,"tunes":2652},{"text":2651},"MCP belongs downstream of Agentic AI: first understand the agent\u002Fruntime\u002Ftool boundary, then use MCP when external capabilities need a portable protocol contract.",{},{"id":1394,"data":2654,"type":218,"tunes":2656},{"text":2655},"MCP also depends on RBAC and tenant isolation because protocol-level capability exposure does not determine application authorization.",{},{"id":1399,"data":2658,"type":218,"tunes":2660},{"text":2659},"The broader protocol-stack article explains where MCP sits beside A2A, UCP, AP2 and A2UI. G02 remains the canonical source for MCP itself.",{},{"id":1404,"data":2662,"type":647,"tunes":2667},{"url":2663,"title":2664,"excerpt":2665,"ctaLabel":2666},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fai-agent-reliability-why-the-final-answer-is-not-enough","AI Agent Reliability: Why the Final Answer Is Not Enough","MCP tool calls become part of an agent trajectory; reliable systems need to evaluate actions and observations, not only final text.","Read the agent reliability article",{},{"id":1412,"data":2669,"type":42,"tunes":2671},{"text":2670,"level":254},"Frequently asked questions",{},{"id":1417,"data":2673,"type":1417,"tunes":2706},{"items":2674,"title":2705},[2675,2678,2681,2684,2687,2690,2693,2696,2699,2702],{"id":1421,"answer":2676,"question":2677},"The Model Context Protocol is an open client-server protocol for connecting AI applications to external tools, resources, prompts and capability providers through a standardized contract.","What is MCP?",{"id":1425,"answer":2679,"question":2680},"No. An MCP server can be completely deterministic software. The model normally runs in the AI host or agent runtime, although a server may optionally use AI internally.","Does an MCP server need an AI model?",{"id":1429,"answer":2682,"question":2683},"The client is the protocol component used by an AI host to communicate with capability providers. The server publishes and executes the capabilities it exposes.","What is the difference between an MCP client and server?",{"id":1433,"answer":2685,"question":2686},"No. Function\u002Ftool calling is how a model invokes configured capabilities. MCP standardizes discovery and communication with external capability servers. A host can bridge the two.","Does MCP replace function calling?",{"id":1437,"answer":2688,"question":2689},"No. MCP servers frequently wrap existing REST, GraphQL, database or service APIs and provide an AI-facing interoperability layer.","Does MCP replace REST APIs?",{"id":1441,"answer":2691,"question":2692},"No. MCP exposes capabilities. Agent planning, state, memory, context management, retries, orchestration and stopping belong to the surrounding runtime.","Is MCP an agent framework?",{"id":1445,"answer":2694,"question":2695},"MCP primarily connects an AI host or agent to tools and data providers. A2A connects independent agent systems for collaboration and delegation.","What is the difference between MCP and A2A?",{"id":1449,"answer":2697,"question":2698},"MCP includes protocol-level authorization mechanisms, especially for remote servers, but the application must still enforce business permissions, resource ownership and tenant isolation.","Does MCP handle authorization?",{"id":1453,"answer":2700,"question":2701},"Yes. Model location is independent of MCP. A local-model host can call local or remote MCP servers, and a cloud-model host can use approved local or remote MCP servers through an appropriate connection architecture.","Can MCP work with local models?",{"id":1457,"answer":2703,"question":2704},"As of 8 October 2026, the current specification revision is 2026-07-28. Older 2025-era implementations remain in use, so compatibility must be checked.","What is the current MCP specification version?","Model Context Protocol FAQ",{},{"id":1463,"data":2708,"type":42,"tunes":2710},{"text":2709,"level":254},"Glossary",{},{"id":1468,"data":2712,"type":1468,"tunes":2742},{"title":2713,"entries":2714},"Key MCP terms",[2715,2717,2720,2722,2724,2726,2728,2730,2733,2735,2737,2739],{"term":593,"anchor":592,"definition":2716},"Model Context Protocol, an open protocol for interoperable connections between AI hosts\u002Fclients and external capability servers.",{"term":2718,"anchor":1476,"definition":2719},"MCP host","The AI application or runtime that owns model interaction and uses MCP clients to connect to servers.",{"term":1769,"anchor":1479,"definition":2721},"Protocol component on the host side that communicates with an MCP server.",{"term":1772,"anchor":1482,"definition":2723},"Capability provider that implements MCP and exposes tools, resources, prompts or supported extensions.",{"term":1880,"anchor":1485,"definition":2725},"Callable structured capability exposed by an MCP server.",{"term":1883,"anchor":1488,"definition":2727},"Readable data or content exposed through MCP resource methods.",{"term":1891,"anchor":1491,"definition":2729},"Reusable prompt template exposed by an MCP server for compatible hosts.",{"term":2731,"anchor":1495,"definition":2732},"Streamable HTTP","HTTP-oriented MCP transport used for remote\u002Fnetworked server communication.",{"term":1498,"anchor":1498,"definition":2734},"Process standard-input\u002Foutput transport commonly used for local MCP server integrations.",{"term":717,"anchor":1501,"definition":2736},"Modern MCP method that lets a client inspect server capabilities in the 2026-07-28 protocol era.",{"term":1504,"anchor":1505,"definition":2738},"Multi Round-Trip Requests, a mechanism for obtaining additional input during a request in the 2026-07-28 protocol era.",{"term":2740,"anchor":1509,"definition":2741},"MCP extension","Capability that composes with the base protocol and can evolve\u002Fversion separately, such as Tasks or MCP Apps.",{},{"id":1513,"data":2744,"type":42,"tunes":2746},{"text":2745,"level":254},"Conclusion",{},{"id":1518,"data":2748,"type":218,"tunes":2750},{"text":2749},"MCP is easiest to understand when its boundary stays narrow: it connects AI applications to external capabilities through a standard protocol.",{},{"id":1523,"data":2752,"type":218,"tunes":2754},{"text":2753},"The model does not have to live on the MCP server. The server does not become the agent runtime. A listed tool does not become an authorized business action. And MCP does not replace the underlying API, Source of Truth, tenant isolation or domain architecture.",{},{"id":1528,"data":2756,"type":218,"tunes":2758},{"text":2757},"That narrowness is the protocol's strength. MCP can standardize how AI systems reach tools and data while leaving application ownership, security, business semantics and model choice in the layers that actually own them.",{},{"id":1533,"data":2760,"type":42,"tunes":2762},{"text":2761,"level":254},"Primary sources and current documentation",{},{"id":1538,"data":2764,"type":218,"tunes":2766},{"text":2765},"MCP is evolving quickly, so version-sensitive claims in this article are tied to the 8 October 2026 state. The Aaasaasa AI Client section is original implementation evidence and is explicitly limited to the verified MCP connector and permission-broker scope.",{},{"id":1543,"data":2768,"type":1550,"tunes":2773},{"link":1545,"meta":2769},{"image":2770,"title":2771,"description":2772},{"url":401},"Model Context Protocol — TypeScript SDK v2","Current stable TypeScript SDK documentation implementing the 2026-07-28 MCP specification and server\u002Fclient primitives.",{},{"id":1553,"data":2775,"type":1550,"tunes":2780},{"link":1555,"meta":2776},{"image":2777,"title":2778,"description":2779},{"url":401},"Model Context Protocol — 2026-07-28 Specification Release","Official release explanation for the current MCP protocol revision, including stateless core, MRTR, routing, caching, authorization hardening, extensions and deprecations.",{},{"id":1562,"data":2782,"type":1550,"tunes":2787},{"link":1564,"meta":2783},{"image":2784,"title":2785,"description":2786},{"url":401},"MCP TypeScript SDK — Supporting protocol revision 2026-07-28","Version-specific implementation guidance for the current protocol revision and earlier-era compatibility.",{},{"id":1571,"data":2789,"type":1550,"tunes":2794},{"link":1573,"meta":2790},{"image":2791,"title":2792,"description":2793},{"url":401},"OpenAI — MCP servers","Current OpenAI guidance for connecting models to remote MCP servers and local\u002Fprivate MCP servers through Secure MCP Tunnel.",{},{"id":1580,"data":2796,"type":1550,"tunes":2801},{"link":1582,"meta":2797},{"image":2798,"title":2799,"description":2800},{"url":401},"OpenAI — MCP connections for Agents API","Current MCP connection guidance covering service, environment and stdio locations plus allowed-tool controls.",{},{"id":1589,"data":2803,"type":1550,"tunes":2808},{"link":1591,"meta":2804},{"image":2805,"title":2806,"description":2807},{"url":401},"OpenAI — Tools","Current overview placing remote MCP servers alongside function calling, web search, shell and other model tools.",{},{"id":1598,"data":2810,"type":1550,"tunes":2815},{"link":1600,"meta":2811},{"image":2812,"title":2813,"description":2814},{"url":401},"OpenAI — MCP server concept","Current description of MCP servers exposing tools, resources and prompts for external service integrations.",{},"2.31.6","Model Context Protocol connects AI applications to external tools, resources and prompts through a standard client-server boundary. Learn what MCP does, what it does not do, and where it fits in agent architecture.",{"lang":7,"title":208,"content":210,"contentJson":2819,"excerpt":1607},{"time":212,"blocks":2820,"version":1606},[2821,2824,2827,2830,2833,2836,2839,2842,2845,2848,2851,2854,2857,2860,2863,2874,2877,2880,2883,2886,2889,2900,2903,2906,2909,2925,2928,2931,2934,2937,2940,2943,2946,2949,2952,2955,2958,2961,2964,2975,2978,2981,2984,2987,2990,2993,2996,2999,3002,3005,3020,3023,3026,3029,3032,3035,3038,3041,3044,3047,3050,3053,3056,3059,3062,3065,3073,3076,3079,3082,3095,3098,3101,3104,3107,3110,3113,3116,3119,3122,3125,3128,3131,3134,3137,3140,3143,3146,3149,3152,3155,3158,3161,3164,3167,3170,3173,3176,3179,3182,3185,3188,3191,3194,3197,3209,3212,3215,3218,3221,3224,3227,3230,3233,3236,3251,3254,3257,3260,3263,3266,3269,3280,3283,3286,3296,3299,3302,3305,3308,3311,3328,3331,3348,3351,3367,3370,3390,3393,3396,3399,3402,3405,3408,3411,3414,3417,3420,3423,3426,3429,3432,3435,3438,3452,3455,3471,3474,3477,3480,3483,3486,3489,3494,3499,3504,3509,3514,3519],{"id":215,"data":2822,"type":218,"tunes":2823},{"text":217},{},{"id":221,"data":2825,"type":226,"tunes":2826},{"body":223,"title":224,"variant":225},{},{"id":229,"data":2828,"type":226,"tunes":2829},{"body":231,"title":232,"variant":233},{},{"id":236,"data":2831,"type":226,"tunes":2832},{"body":238,"title":239,"variant":240},{},{"id":243,"data":2834,"type":226,"tunes":2835},{"body":245,"title":246,"variant":247},{},{"id":250,"data":2837,"type":255,"tunes":2838},{"title":252,"maxLevel":253,"minLevel":254},{},{"id":258,"data":2840,"type":42,"tunes":2841},{"text":260,"level":254},{},{"id":263,"data":2843,"type":218,"tunes":2844},{"text":265},{},{"id":268,"data":2846,"type":218,"tunes":2847},{"text":270},{},{"id":273,"data":2849,"type":218,"tunes":2850},{"text":275},{},{"id":278,"data":2852,"type":42,"tunes":2853},{"text":280,"level":254},{},{"id":283,"data":2855,"type":218,"tunes":2856},{"text":285},{},{"id":288,"data":2858,"type":218,"tunes":2859},{"text":290},{},{"id":293,"data":2861,"type":218,"tunes":2862},{"text":295},{},{"id":298,"data":2864,"type":324,"tunes":2873},{"steps":2865,"title":322,"orientation":323},[2866,2867,2868,2869,2870,2871,2872],{"label":302,"description":303},{"label":305,"description":306},{"label":308,"description":309},{"label":311,"description":312},{"label":314,"description":315},{"label":317,"description":318},{"label":320,"description":321},{},{"id":327,"data":2875,"type":42,"tunes":2876},{"text":329,"level":254},{},{"id":332,"data":2878,"type":218,"tunes":2879},{"text":334},{},{"id":337,"data":2881,"type":218,"tunes":2882},{"text":339},{},{"id":342,"data":2884,"type":218,"tunes":2885},{"text":344},{},{"id":347,"data":2887,"type":42,"tunes":2888},{"text":349,"level":254},{},{"id":352,"data":2890,"type":376,"tunes":2899},{"content":2891,"stretched":43,"withHeadings":14},[2892,2893,2894,2895,2896,2897,2898],[356,357],[359,360],[362,363],[365,366],[368,369],[371,372],[374,375],{},{"id":379,"data":2901,"type":218,"tunes":2902},{"text":381},{},{"id":384,"data":2904,"type":218,"tunes":2905},{"text":386},{},{"id":389,"data":2907,"type":42,"tunes":2908},{"text":391,"level":254},{},{"id":394,"data":2910,"type":425,"tunes":2924},{"rows":2911,"title":414,"layout":376,"columns":2920},[2912,2914,2916,2918],{"id":398,"label":399,"values":2913},[401,401,401],{"id":403,"label":404,"values":2915},[401,401,401],{"id":407,"label":408,"values":2917},[401,401,401],{"id":411,"label":412,"values":2919},[401,401,401],[2921,2922,2923],{"id":417,"label":418},{"id":420,"label":421},{"id":423,"label":424},{},{"id":428,"data":2926,"type":42,"tunes":2927},{"text":430,"level":254},{},{"id":433,"data":2929,"type":218,"tunes":2930},{"text":435},{},{"id":438,"data":2932,"type":218,"tunes":2933},{"text":440},{},{"id":443,"data":2935,"type":218,"tunes":2936},{"text":445},{},{"id":448,"data":2938,"type":42,"tunes":2939},{"text":450,"level":254},{},{"id":453,"data":2941,"type":218,"tunes":2942},{"text":455},{},{"id":458,"data":2944,"type":218,"tunes":2945},{"text":460},{},{"id":463,"data":2947,"type":218,"tunes":2948},{"text":465},{},{"id":468,"data":2950,"type":42,"tunes":2951},{"text":470,"level":254},{},{"id":473,"data":2953,"type":218,"tunes":2954},{"text":475},{},{"id":478,"data":2956,"type":218,"tunes":2957},{"text":480},{},{"id":483,"data":2959,"type":218,"tunes":2960},{"text":485},{},{"id":488,"data":2962,"type":42,"tunes":2963},{"text":490,"level":254},{},{"id":493,"data":2965,"type":376,"tunes":2974},{"content":2966,"stretched":43,"withHeadings":14},[2967,2968,2969,2970,2971,2972,2973],[497,498],[500,418],[502,421],[504,505],[507,418],[509,510],[512,513],{},{"id":516,"data":2976,"type":42,"tunes":2977},{"text":518,"level":254},{},{"id":521,"data":2979,"type":218,"tunes":2980},{"text":523},{},{"id":526,"data":2982,"type":218,"tunes":2983},{"text":528},{},{"id":531,"data":2985,"type":218,"tunes":2986},{"text":533},{},{"id":536,"data":2988,"type":226,"tunes":2989},{"body":538,"title":539,"variant":233},{},{"id":542,"data":2991,"type":42,"tunes":2992},{"text":544,"level":254},{},{"id":547,"data":2994,"type":218,"tunes":2995},{"text":549},{},{"id":552,"data":2997,"type":218,"tunes":2998},{"text":554},{},{"id":557,"data":3000,"type":218,"tunes":3001},{"text":559},{},{"id":562,"data":3003,"type":42,"tunes":3004},{"text":564,"level":254},{},{"id":567,"data":3006,"type":425,"tunes":3019},{"rows":3007,"title":586,"layout":376,"columns":3016},[3008,3010,3012,3014],{"id":571,"label":572,"values":3009},[401,401],{"id":575,"label":576,"values":3011},[401,401],{"id":579,"label":580,"values":3013},[401,401],{"id":583,"label":584,"values":3015},[401,401],[3017,3018],{"id":589,"label":590},{"id":592,"label":593},{},{"id":596,"data":3021,"type":218,"tunes":3022},{"text":598},{},{"id":601,"data":3024,"type":42,"tunes":3025},{"text":603,"level":254},{},{"id":606,"data":3027,"type":218,"tunes":3028},{"text":608},{},{"id":611,"data":3030,"type":218,"tunes":3031},{"text":613},{},{"id":616,"data":3033,"type":218,"tunes":3034},{"text":618},{},{"id":621,"data":3036,"type":42,"tunes":3037},{"text":623,"level":254},{},{"id":626,"data":3039,"type":218,"tunes":3040},{"text":628},{},{"id":631,"data":3042,"type":218,"tunes":3043},{"text":633},{},{"id":636,"data":3045,"type":218,"tunes":3046},{"text":638},{},{"id":641,"data":3048,"type":647,"tunes":3049},{"url":643,"title":644,"excerpt":645,"ctaLabel":646},{},{"id":650,"data":3051,"type":42,"tunes":3052},{"text":652,"level":254},{},{"id":655,"data":3054,"type":218,"tunes":3055},{"text":657},{},{"id":660,"data":3057,"type":218,"tunes":3058},{"text":662},{},{"id":665,"data":3060,"type":218,"tunes":3061},{"text":667},{},{"id":670,"data":3063,"type":42,"tunes":3064},{"text":672,"level":254},{},{"id":675,"data":3066,"type":376,"tunes":3072},{"content":3067,"stretched":43,"withHeadings":14},[3068,3069,3070,3071],[679,680],[682,683],[685,686],[688,689],{},{"id":692,"data":3074,"type":218,"tunes":3075},{"text":694},{},{"id":697,"data":3077,"type":218,"tunes":3078},{"text":699},{},{"id":702,"data":3080,"type":42,"tunes":3081},{"text":704,"level":254},{},{"id":707,"data":3083,"type":376,"tunes":3094},{"content":3084,"stretched":43,"withHeadings":14},[3085,3086,3087,3088,3089,3090,3091,3092,3093],[711,712],[714,715],[717,718],[720,721],[723,724],[726,727],[729,730],[732,733],[735,736],{},{"id":739,"data":3096,"type":42,"tunes":3097},{"text":741,"level":254},{},{"id":744,"data":3099,"type":218,"tunes":3100},{"text":746},{},{"id":749,"data":3102,"type":218,"tunes":3103},{"text":751},{},{"id":754,"data":3105,"type":218,"tunes":3106},{"text":756},{},{"id":759,"data":3108,"type":42,"tunes":3109},{"text":761,"level":254},{},{"id":764,"data":3111,"type":218,"tunes":3112},{"text":766},{},{"id":769,"data":3114,"type":218,"tunes":3115},{"text":771},{},{"id":774,"data":3117,"type":218,"tunes":3118},{"text":776},{},{"id":779,"data":3120,"type":42,"tunes":3121},{"text":781,"level":254},{},{"id":784,"data":3123,"type":218,"tunes":3124},{"text":786},{},{"id":789,"data":3126,"type":218,"tunes":3127},{"text":791},{},{"id":794,"data":3129,"type":218,"tunes":3130},{"text":796},{},{"id":799,"data":3132,"type":42,"tunes":3133},{"text":801,"level":254},{},{"id":804,"data":3135,"type":218,"tunes":3136},{"text":806},{},{"id":809,"data":3138,"type":218,"tunes":3139},{"text":811},{},{"id":814,"data":3141,"type":218,"tunes":3142},{"text":816},{},{"id":819,"data":3144,"type":226,"tunes":3145},{"body":821,"title":822,"variant":240},{},{"id":825,"data":3147,"type":42,"tunes":3148},{"text":827,"level":254},{},{"id":830,"data":3150,"type":218,"tunes":3151},{"text":832},{},{"id":835,"data":3153,"type":218,"tunes":3154},{"text":837},{},{"id":840,"data":3156,"type":218,"tunes":3157},{"text":842},{},{"id":845,"data":3159,"type":42,"tunes":3160},{"text":847,"level":254},{},{"id":850,"data":3162,"type":218,"tunes":3163},{"text":852},{},{"id":855,"data":3165,"type":218,"tunes":3166},{"text":857},{},{"id":860,"data":3168,"type":218,"tunes":3169},{"text":862},{},{"id":865,"data":3171,"type":42,"tunes":3172},{"text":867,"level":254},{},{"id":870,"data":3174,"type":218,"tunes":3175},{"text":872},{},{"id":875,"data":3177,"type":218,"tunes":3178},{"text":877},{},{"id":880,"data":3180,"type":218,"tunes":3181},{"text":882},{},{"id":885,"data":3183,"type":42,"tunes":3184},{"text":887,"level":254},{},{"id":890,"data":3186,"type":218,"tunes":3187},{"text":892},{},{"id":895,"data":3189,"type":218,"tunes":3190},{"text":897},{},{"id":900,"data":3192,"type":218,"tunes":3193},{"text":902},{},{"id":905,"data":3195,"type":42,"tunes":3196},{"text":907,"level":254},{},{"id":910,"data":3198,"type":376,"tunes":3208},{"content":3199,"stretched":43,"withHeadings":14},[3200,3201,3202,3203,3204,3205,3206,3207],[914,915],[917,918],[920,921],[923,924],[926,927],[929,930],[932,933],[935,936],{},{"id":939,"data":3210,"type":42,"tunes":3211},{"text":941,"level":254},{},{"id":944,"data":3213,"type":218,"tunes":3214},{"text":946},{},{"id":949,"data":3216,"type":218,"tunes":3217},{"text":951},{},{"id":954,"data":3219,"type":218,"tunes":3220},{"text":956},{},{"id":959,"data":3222,"type":42,"tunes":3223},{"text":961,"level":254},{},{"id":964,"data":3225,"type":218,"tunes":3226},{"text":966},{},{"id":969,"data":3228,"type":218,"tunes":3229},{"text":971},{},{"id":974,"data":3231,"type":218,"tunes":3232},{"text":976},{},{"id":979,"data":3234,"type":42,"tunes":3235},{"text":981,"level":254},{},{"id":984,"data":3237,"type":376,"tunes":3250},{"content":3238,"stretched":43,"withHeadings":14},[3239,3240,3241,3242,3243,3244,3245,3246,3247,3248,3249],[988,989],[991,992],[994,995],[997,998],[1000,1001],[1003,1004],[1006,1007],[1009,1010],[1012,1013],[1015,1016],[1018,1019],{},{"id":1022,"data":3252,"type":42,"tunes":3253},{"text":1024,"level":254},{},{"id":1027,"data":3255,"type":226,"tunes":3256},{"body":1029,"title":1030,"variant":247},{},{"id":1033,"data":3258,"type":218,"tunes":3259},{"text":1035},{},{"id":1038,"data":3261,"type":218,"tunes":3262},{"text":1040},{},{"id":1043,"data":3264,"type":218,"tunes":3265},{"text":1045},{},{"id":1048,"data":3267,"type":218,"tunes":3268},{"text":1050},{},{"id":1053,"data":3270,"type":376,"tunes":3279},{"content":3271,"stretched":43,"withHeadings":14},[3272,3273,3274,3275,3276,3277,3278],[1057,1058],[1060,1061],[1063,1064],[1066,1067],[1069,1070],[1072,1073],[1075,1076],{},{"id":1079,"data":3281,"type":226,"tunes":3282},{"body":1081,"title":1082,"variant":240},{},{"id":1085,"data":3284,"type":42,"tunes":3285},{"text":1087,"level":254},{},{"id":1090,"data":3287,"type":376,"tunes":3295},{"content":3288,"stretched":43,"withHeadings":14},[3289,3290,3291,3292,3293,3294],[1094,1095],[1097,1098],[1100,1101],[1103,1104],[1106,1107],[1109,1110],{},{"id":1113,"data":3297,"type":42,"tunes":3298},{"text":1115,"level":254},{},{"id":1118,"data":3300,"type":218,"tunes":3301},{"text":1120},{},{"id":1123,"data":3303,"type":218,"tunes":3304},{"text":1125},{},{"id":1128,"data":3306,"type":218,"tunes":3307},{"text":1130},{},{"id":1133,"data":3309,"type":42,"tunes":3310},{"text":1135,"level":254},{},{"id":1138,"data":3312,"type":376,"tunes":3327},{"content":3313,"stretched":43,"withHeadings":14},[3314,3315,3316,3317,3318,3319,3320,3321,3322,3323,3324,3325,3326],[1142,988],[1144,1145],[1147,1148],[1150,1151],[1153,1154],[1156,1157],[1159,1160],[1162,1163],[1165,1166],[1168,1169],[1171,1172],[1174,1175],[1177,1178],{},{"id":1181,"data":3329,"type":42,"tunes":3330},{"text":1183,"level":254},{},{"id":1186,"data":3332,"type":376,"tunes":3347},{"content":3333,"stretched":43,"withHeadings":14},[3334,3335,3336,3337,3338,3339,3340,3341,3342,3343,3344,3345,3346],[1190,1191],[1193,1194],[1196,1197],[1199,1200],[1202,1203],[1205,1206],[1208,1209],[1211,1212],[1214,1215],[1217,1218],[1220,1221],[1223,1224],[1226,1227],{},{"id":1230,"data":3349,"type":42,"tunes":3350},{"text":1232,"level":254},{},{"id":1235,"data":3352,"type":324,"tunes":3366},{"steps":3353,"title":1274,"orientation":323},[3354,3355,3356,3357,3358,3359,3360,3361,3362,3363,3364,3365],{"label":1239,"description":1240},{"label":1242,"description":1243},{"label":1245,"description":1246},{"label":1248,"description":1249},{"label":1251,"description":1252},{"label":1254,"description":1255},{"label":1257,"description":1258},{"label":1260,"description":1261},{"label":1263,"description":1264},{"label":1266,"description":1267},{"label":1269,"description":1270},{"label":1272,"description":1273},{},{"id":1277,"data":3368,"type":42,"tunes":3369},{"text":1279,"level":254},{},{"id":1282,"data":3371,"type":376,"tunes":3389},{"content":3372,"stretched":43,"withHeadings":14},[3373,3374,3375,3376,3377,3378,3379,3380,3381,3382,3383,3384,3385,3386,3387,3388],[988,1286],[1288,1289],[1291,1292],[1294,1295],[1297,1298],[1300,1301],[1303,1304],[1306,1307],[1309,1310],[1312,1313],[1315,1316],[1318,1319],[1321,1322],[1324,1325],[1327,1328],[1330,1331],{},{"id":1334,"data":3391,"type":42,"tunes":3392},{"text":1336,"level":254},{},{"id":1339,"data":3394,"type":218,"tunes":3395},{"text":1341},{},{"id":1344,"data":3397,"type":218,"tunes":3398},{"text":1346},{},{"id":1349,"data":3400,"type":218,"tunes":3401},{"text":1351},{},{"id":1354,"data":3403,"type":218,"tunes":3404},{"text":1356},{},{"id":1359,"data":3406,"type":218,"tunes":3407},{"text":1361},{},{"id":1364,"data":3409,"type":42,"tunes":3410},{"text":1366,"level":254},{},{"id":1369,"data":3412,"type":218,"tunes":3413},{"text":1371},{},{"id":1374,"data":3415,"type":218,"tunes":3416},{"text":1376},{},{"id":1379,"data":3418,"type":218,"tunes":3419},{"text":1381},{},{"id":1384,"data":3421,"type":42,"tunes":3422},{"text":1386,"level":254},{},{"id":1389,"data":3424,"type":218,"tunes":3425},{"text":1391},{},{"id":1394,"data":3427,"type":218,"tunes":3428},{"text":1396},{},{"id":1399,"data":3430,"type":218,"tunes":3431},{"text":1401},{},{"id":1404,"data":3433,"type":647,"tunes":3434},{"url":1406,"title":1407,"excerpt":1408,"ctaLabel":1409},{},{"id":1412,"data":3436,"type":42,"tunes":3437},{"text":1414,"level":254},{},{"id":1417,"data":3439,"type":1417,"tunes":3451},{"items":3440,"title":1460},[3441,3442,3443,3444,3445,3446,3447,3448,3449,3450],{"id":1421,"answer":1422,"question":1423},{"id":1425,"answer":1426,"question":1427},{"id":1429,"answer":1430,"question":1431},{"id":1433,"answer":1434,"question":1435},{"id":1437,"answer":1438,"question":1439},{"id":1441,"answer":1442,"question":1443},{"id":1445,"answer":1446,"question":1447},{"id":1449,"answer":1450,"question":1451},{"id":1453,"answer":1454,"question":1455},{"id":1457,"answer":1458,"question":1459},{},{"id":1463,"data":3453,"type":42,"tunes":3454},{"text":1465,"level":254},{},{"id":1468,"data":3456,"type":1468,"tunes":3470},{"title":1470,"entries":3457},[3458,3459,3460,3461,3462,3463,3464,3465,3466,3467,3468,3469],{"term":593,"anchor":592,"definition":1473},{"term":1475,"anchor":1476,"definition":1477},{"term":362,"anchor":1479,"definition":1480},{"term":365,"anchor":1482,"definition":1483},{"term":418,"anchor":1485,"definition":1486},{"term":421,"anchor":1488,"definition":1489},{"term":510,"anchor":1491,"definition":1492},{"term":1494,"anchor":1495,"definition":1496},{"term":1498,"anchor":1498,"definition":1499},{"term":717,"anchor":1501,"definition":1502},{"term":1504,"anchor":1505,"definition":1506},{"term":1508,"anchor":1509,"definition":1510},{},{"id":1513,"data":3472,"type":42,"tunes":3473},{"text":1515,"level":254},{},{"id":1518,"data":3475,"type":218,"tunes":3476},{"text":1520},{},{"id":1523,"data":3478,"type":218,"tunes":3479},{"text":1525},{},{"id":1528,"data":3481,"type":218,"tunes":3482},{"text":1530},{},{"id":1533,"data":3484,"type":42,"tunes":3485},{"text":1535,"level":254},{},{"id":1538,"data":3487,"type":218,"tunes":3488},{"text":1540},{},{"id":1543,"data":3490,"type":1550,"tunes":3493},{"link":1545,"meta":3491},{"image":3492,"title":1548,"description":1549},{"url":401},{},{"id":1553,"data":3495,"type":1550,"tunes":3498},{"link":1555,"meta":3496},{"image":3497,"title":1558,"description":1559},{"url":401},{},{"id":1562,"data":3500,"type":1550,"tunes":3503},{"link":1564,"meta":3501},{"image":3502,"title":1567,"description":1568},{"url":401},{},{"id":1571,"data":3505,"type":1550,"tunes":3508},{"link":1573,"meta":3506},{"image":3507,"title":1576,"description":1577},{"url":401},{},{"id":1580,"data":3510,"type":1550,"tunes":3513},{"link":1582,"meta":3511},{"image":3512,"title":1585,"description":1586},{"url":401},{},{"id":1589,"data":3515,"type":1550,"tunes":3518},{"link":1591,"meta":3516},{"image":3517,"title":1594,"description":1595},{"url":401},{},{"id":1598,"data":3520,"type":1550,"tunes":3523},{"link":1600,"meta":3521},{"image":3522,"title":1603,"description":1604},{"url":401},{},"Post erfolgreich abgerufen",{"items":3526,"source":3611,"manualIds":3612,"manualMatchedIds":3613},[3527,3534,3541,3548,3555,3562,3569,3576,3583,3590,3597,3604],{"id":3528,"slug":3529,"title":3530,"excerpt":3531,"featuredImage":3532,"publishedAt":3533},"471","how-to-know-whether-an-ai-agent-actually-used-the-right-evidence","如何判断一个AI智能体是否真正使用了正确的证据","AI代理可以引用来源，却仍然使用错误的证据。本文介绍一种实用方法，用于核查主张支持、来源权威性、适用性、出处，以及证据是否实际影响了答案。","\u002Fuploads\u002F2026\u002F09\u002Fhow-to-know-whether-an-ai-agent-actually-used-the-right-evidence-1790351317188-o5z9ve.webp","2026-09-25T11:47:00.000Z",{"id":3535,"slug":3536,"title":3537,"excerpt":3538,"featuredImage":3539,"publishedAt":3540},"470","what-should-an-ai-agent-remember-forget-recompute-or-retrieve-again","AI代理应该记住、遗忘、重新计算还是再次检索什么？","长时间运行的代理不应记住所有内容。本文提供了一个实用的生命周期模型，用于决定哪些内容应属于持久记忆、哪些内容应重新检索、哪些内容重新计算更安全，以及哪些内容应过期或被取代。","\u002Fuploads\u002F2026\u002F09\u002Fwhat-should-an-ai-agent-remember-forget-recompute-or-retrieve-again-1790351131087-iehz28.webp","2026-09-25T09:43:00.000Z",{"id":3542,"slug":3543,"title":3544,"excerpt":3545,"featuredImage":3546,"publishedAt":3547},"495","sovereign-ai-control-of-models-data-infrastructure-and-dependencies","主权人工智能：模型、数据、基础设施与依赖关系的控制","主权人工智能关乎对模型、数据、基础设施、软件、运营和战略依赖的有效控制——而不仅仅是人工智能模型托管在哪里。","\u002Fuploads\u002F2026\u002F10\u002Fsovereign-ai-control-of-models-data-infrastructure-and-dependencies-1791488833132-niy85x.webp","2026-10-08T15:45:00.000Z",{"id":3549,"slug":3550,"title":3551,"excerpt":3552,"featuredImage":3553,"publishedAt":3554},"490","rbac-vs-tenant-isolation-two-different-security-boundaries","RBAC与租户隔离：两种不同的安全边界","RBAC 控制用户可以做什么；租户隔离控制该操作可以触及哪个租户的资源。了解为什么多租户 SaaS 安全需要这两道边界。","\u002Fuploads\u002F2026\u002F10\u002Frbac-vs-tenant-isolation-two-different-security-boundaries-1791485111528-qqtzby.webp","2026-10-08T14:43:00.000Z",{"id":3556,"slug":3557,"title":3558,"excerpt":3559,"featuredImage":3560,"publishedAt":3561},"382","a-practical-monorepo-architecture-next-js-platform-admin-fastify-api-prisma-and-nginx","基于Next.js、Fastify、Prisma和NGINX的实用单体仓库架构","探索一种实用的单体仓库架构，结合Next.js、Fastify、Prisma与NGINX，重点展示实际集成与工作流程。","\u002Fuploads\u002F2026\u002F01\u002Fa-practical-monorepo-architecture-next-js-platform-admin-fastify-api-prisma-and-nginx-1769885526116-q1100n.webp","2026-01-31T08:18:00.000Z",{"id":3563,"slug":3564,"title":3565,"excerpt":3566,"featuredImage":3567,"publishedAt":3568},"487","vector-databases-embeddings-and-reranking-three-different-parts-of-retrieval","向量数据库、嵌入和重排序：检索的三个不同部分","嵌入表示含义，向量数据库检索候选结果，重排序器则精炼结果。了解这三个检索层在RAG中如何不同并协同工作。","\u002Fuploads\u002F2026\u002F10\u002Fvector-databases-embeddings-and-reranking-three-different-parts-of-retrieval-1791480129884-9dtasz.webp","2026-10-08T11:21:00.000Z",{"id":3570,"slug":3571,"title":3572,"excerpt":3573,"featuredImage":3574,"publishedAt":3575},"466","the-gpu-is-not-the-product-future-proof-private-ai-architecture","GPU 不是产品：面向未来的私有 AI 架构","私有 AI 基础设施不应围绕单一 GPU 或单一模型来设计。更具韧性的做法是将快速推理 GPU、内存充裕的 AI 系统、物理 AI 节点以及可选的前沿云模型，统一置于一个具备能力感知的路由层之后。","\u002Fuploads\u002F2026\u002F09\u002Fthe-gpu-is-not-the-product-future-proof-private-ai-architecture-1790140878812-8hsl39.webp","2026-09-23T01:19:00.000Z",{"id":3577,"slug":3578,"title":3579,"excerpt":3580,"featuredImage":3581,"publishedAt":3582},"494","air-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","气隙AI：AI系统如何在没有互联网或云访问的情况下工作","气隙AI在隔离的安全域内运行模型、RAG和AI应用，无需互联网或云依赖。了解模型、数据、更新和工具如何离线运行。","\u002Fuploads\u002F2026\u002F10\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access-1791487983978-e6xqf0.webp","2026-10-08T11:32:00.000Z",{"id":3584,"slug":3585,"title":3586,"excerpt":3587,"featuredImage":3588,"publishedAt":3589},"483","what-is-an-ai-solution-architect-system-boundaries-responsibilities-and-trade-offs","什么是AI解决方案架构师？系统边界、职责与权衡","AI解决方案架构师将业务需求转化为生产就绪的AI系统，涵盖数据、模型、工具、安全、运行时、评估和运维。","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-solution-architect-system-boundaries-responsibilities-and-trade-offs-1791476643267-1st5xz.webp","2026-10-08T12:23:00.000Z",{"id":3591,"slug":3592,"title":3593,"excerpt":3594,"featuredImage":3595,"publishedAt":3596},"381","enterprise-grade-multi-tenant-architecture-for-an-international-platform","企业级多租户架构，适用于国际平台","Loving Rocks 是一款企业级婚礼平台，采用真正的多租户架构设计，实现租户间数据库隔离，并内置国际化支持，以确保全球可扩展性、安全性及长期运营稳定性。","\u002Fuploads\u002F2026\u002F01\u002Fenterprise-grade-multi-tenant-architecture-for-an-international-platform-1769789121298-b6v7ak.webp","2026-01-30T12:04:00.000Z",{"id":3598,"slug":3599,"title":3600,"excerpt":3601,"featuredImage":3602,"publishedAt":3603},"486","source-of-truth-in-ai-systems-where-reliable-knowledge-actually-comes-from","AI系统中的真相来源：可靠知识究竟从何而来","事实来源（Source of Truth）定义了对于特定事实或状态，哪个来源具有权威性。了解它与RAG、溯源、记忆、上下文、向量数据库和记录系统有何不同。","\u002Fuploads\u002F2026\u002F10\u002Fsource-of-truth-in-ai-systems-where-reliable-knowledge-actually-comes-from-1791479103235-6bq9em.webp","2026-10-08T13:02:00.000Z",{"id":3605,"slug":3606,"title":3607,"excerpt":3608,"featuredImage":3609,"publishedAt":3610},"484","what-is-an-ai-platform-architect-models-data-runtime-security-and-operations","什么是AI平台架构师？模型、数据、运行时、安全与运维","AI平台架构师负责跨模型、提供商、检索、智能体、身份、安全、评估、可观测性和运营设计可复用的AI基础。","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations-1791477229171-ou3zcc.webp","2026-10-08T12:32:00.000Z","fallback",[],[]]