STANDARD · §2.4 · ACT · LAST REVIEWED SEPTEMBER 2026

What is MCP, the Model Context Protocol?

The protocol most agents use to call tools and read data from outside services.


Agent Readiness Compare editors · Spec status checked September 2026

Answer

MCP is an open protocol that connects LLM applications to external tools and data using JSON-RPC 2.0 messages between hosts, clients and servers. A server can offer tools (functions the model can call), resources (context and data) and prompts (templates). For a business, an MCP server is how an agent performs API-backed tasks such as checking a plan or creating an account, with user consent.

Maintainer:
Model Context Protocol project
Status:
versioned specification, latest revision 2026-07-28

1.What is MCP?

The Model Context Protocol is an open protocol for integrating LLM applications with external data sources and tools; the specification describes it as 'a standardized way to connect LLMs with the context they need.' It takes inspiration from the Language Server Protocol, which standardised how editors support programming languages. The authoritative requirements are defined in a TypeScript schema; the latest revision in the specification repository is dated 2026-07-28.

2.How does it work?

  • Hosts are the LLM applications that start connections (an assistant or IDE).
  • Clients are connectors inside the host, one per server.
  • Servers provide context and capabilities: resources, prompts and tools.
  • Clients can offer elicitation, where a server asks the user for more information.

Messages use JSON-RPC 2.0. Optional extensions add features such as Tasks for long-running operations and MCP Apps for interactive UI in a conversation.

JSON-RPC request: list a server's tools
{"jsonrpc": "2.0", "id": 1, "method": "tools/list"}

3.What does MCP require from the people who deploy it?

The specification puts consent at the centre: users must explicitly consent to data access and operations, hosts must obtain consent before invoking any tool, and tool descriptions should be treated as untrusted unless they come from a trusted server. MCP itself cannot enforce these principles; implementers are expected to build consent and authorization flows.

4.What does MCP not do?

  • It does not make your website readable. Pages still need server-rendered content, llms.txt or markdown.
  • It does not run in the page. Tools a web page exposes to an in-browser agent are WebMCP's job. See MCP and WebMCP.
  • It does not connect agents to other agents as peers. That is A2A.

5.How do you check an MCP server?

  1. Connect with an MCP client and call tools/list. Confirm names and descriptions say what each tool does and when to use it.
  2. Call each tool with realistic inputs and confirm errors are readable.
  3. Confirm authorization for any tool that touches user data.
  4. ora.ai publishes an MCP server of its own that scans a domain and can rescan after each fix; its readiness scan also looks for MCP endpoints.

6.Where does it sit in the readiness stack?

Layer 3, Act: MCP is how most agents call your product's functions.

Figure 1. The readiness stack: five layers, the standards that address each, and the tools that document support.
Text version of the diagram
Text version of the readiness stack
LayerQuestionStandardsTools that document support
L1 DISCOVERCan an agent find you, and is it allowed in?robots.txt (RFC 9309); Sitemaps; llms.txt; A2A Agent CardCloudflare AI Crawl Control (controls crawler access); ora.ai Scan (checks it); Cloudflare Is It Agent Ready (checks it)
L2 READCan it read and understand what you offer?llms.txt; Markdown negotiation (Accept: text/markdown); JSON-LDCloudflare Markdown for Agents (serves markdown); ora.ai Scan (checks it)
L3 ACTCan it complete a task on your site or API?MCP; WebMCP; agents.json; OpenAPICloudflare (hosts MCP servers); Vercel (hosts MCP servers); nekuda (builds WebMCP tools); ora.ai Journey and WebMCP audit (test it)
L4 PAYCan it pay you?x402; ACP; UCP; MPPCloudflare Pay per crawl (private beta, for crawlers); ora.ai Scan payments layer (checks it)
L5 TRUSTCan you tell which agent it is, and on whose behalf it acts?Web Bot Auth; OAuth 2.0Cloudflare (verifies signed bots); Vercel (verifies signed bots); Forter (links agentic shoppers to verified customer identities)

Frequently asked questions

Does my website need an MCP server?

Only if you want agents to perform tasks through your API, such as checking account data, creating records or starting a trial. A content site with no actions gains more from readable pages and llms.txt.

Who can host an MCP server?

Any server that speaks the protocol. Cloudflare documents remote MCP servers over Streamable HTTP with OAuth, and Vercel documents deploying MCP servers with the mcp-handler package.

Update, July 2026: the 2026-07-28 specification made MCP stateless. See the MCP 2026-07-28 specification explained.

Source: modelcontextprotocol.io specification · Cloudflare MCP docs · Vercel MCP deployment docs · ora.ai docs · Reviewed Sep 2026