Skip to content
anavem.com

ExplainerPublished 7 min read

What Is an MCP Server? A Plain-English Guide

An MCP server is a program that gives AI apps tools, data and prompts. Definitions from the MCP docs, local vs remote, Claude examples and cost notes.

By Emanuel DE ALMEIDA · Editor

In this article
  1. How this article was made
  2. What the sources say: the three roles
  3. What the sources say: tools, resources and prompts
  4. What the sources say: local and remote servers
  5. What the sources say: two examples
  6. What the sources say: how an MCP server appears in Claude
  7. What the sources say: MCP server vs API
  8. What the sources say: does an MCP server cost money?
  9. What to consider
  10. Limitations, and when an MCP server is not the right choice
Editorial evidence card for What Is an MCP Server? A Plain-English Guide

Key takeaways

Documented
  • Answer: An MCP server is a program that gives AI apps tools, data and prompts. Definitions from the MCP docs, local vs remote, Claude examples and cost notes.
  • Evidence: Based on 12 dated primary or official sources, most recently checked .
  • Scope: This article does not claim hands-on testing. Performance or safety verdicts require a linked test record.

An MCP server is a program that gives an AI application tools to call, data to read and prompt templates to use. It follows the Model Context Protocol (MCP), which its documentation calls "an open-source standard for connecting AI applications to external systems." A server can run on your computer or on a provider's servers.

How this article was made

Every definition below comes from a page we fetched and read on 2026-10-03: the MCP documentation and specification (revision 2026-07-28), Anthropic's connector documentation, and one server README. Nothing was tested. Anavem has not audited any software named here. Passages are labeled "What the sources say" (facts, each with its source) and "What to consider" (our assessment). Product pages change, so treat each statement as a snapshot dated 2026-10-03.

What the sources say: the three roles

The MCP introduction says AI applications such as Claude or ChatGPT can use MCP to connect to data sources (for example local files and databases), tools (for example search engines and calculators) and workflows (for example specialized prompts). It compares MCP to a USB-C port for AI applications: one standard way to connect to many external systems.

The MCP architecture overview (revision 2026-07-28) names three participants:

  • MCP host: the AI application that coordinates one or more MCP clients.
  • MCP client: a component that keeps a connection to one MCP server and gets context from it for the host to use. The host creates one client for each server.
  • MCP server: a program that provides context to MCP clients.

The same page gives an example. Visual Studio Code acts as a host. When it connects to the Sentry MCP server, it creates one client object. When it then connects to the local filesystem server, it creates a second client object.

Plain-English reading (our wording, not a quote): the host is the chat or coding app you use, the server is the add-on program that offers abilities, and the client is plumbing inside the app that you do not see.

What the sources say: tools, resources and prompts

The page Understanding MCP servers says a server offers functionality through three building blocks.

Building block What the page says Who controls it
Tools Functions the model can call. They can write to databases, call external APIs, modify files or trigger other logic. Model
Resources Read-only data for context, such as file contents, database schemas or API documentation. Application
Prompts Pre-built instruction templates for working with specific tools and resources. User

Source: modelcontextprotocol.io, "Understanding MCP servers," read 2026-10-03.

The specification overview lists the same three features. It adds that the protocol uses JSON-RPC 2.0 messages and that tools are "Functions for the AI model to execute."

Tools can act on the outside world, so the specification's tools page says there should always be a human in the loop with the ability to deny tool invocations. It leaves the exact interface to each application.

What the sources say: local and remote servers

The architecture overview says "MCP server" names the program that serves context, wherever it runs. It describes two standard transports. A transport is the way messages travel between client and server.

  • Stdio: the client launches the server as a subprocess on the same machine. The page calls this a "local" server. Its example is the filesystem server started by Claude Desktop.
  • Streamable HTTP: messages travel over HTTP, which allows remote servers. The page calls this a "remote" server. Its example is the official Sentry server, which runs on the Sentry platform.

The page adds that a local stdio server typically serves a single client, while a remote server typically serves many.

Sign-in is a separate question. The authorization section says authorization is optional. HTTP-based servers should follow its OAuth-based flow. Servers that use stdio should instead get credentials from the environment.

What the sources say: two examples

The filesystem server. The README in the modelcontextprotocol/servers repository describes a Node.js server for filesystem operations. It restricts operations to allowed directories, which you pass as arguments or which the client provides through the MCP Roots feature. The sample tools include read_text_file, write_file, create_directory and search_files. For Docker mounts, the README says you can add the "ro" flag to make a directory read-only to the server.

The Sentry server. The architecture page names it as a remote example. We did not read Sentry's own documentation, so we say nothing more about what it does.

The MCP introduction also lists what MCP can enable, for example agents that reach Google Calendar and Notion. That is the project's own statement. We did not test it.

What the sources say: how an MCP server appears in Claude

Anthropic's page Connectors, skills, and plugins says each connector is a connection to an MCP server, which the service runs so Claude can reach it. The connectors overview adds these points, as read on 2026-10-03:

  • You add a connector under Customize > Connectors in claude.ai or the Claude desktop app.
  • Each directory listing carries a Verified or Community label.
  • After connecting, you choose per conversation whether Claude may use the connector.
  • Under the connector's tool permissions you can set each tool, or each group of tools, to Always allow, Needs approval or Blocked.
  • Most connectors are remote services. A local connector is a desktop extension, packaged as an MCP Bundle (MCPB), that runs on your computer in the desktop app.

The page Add a connector that isn't in the directory covers connectors added by server URL. It warns that custom connectors allow connections to unverified services.

What the sources say: MCP server vs API

The pages we read do not compare MCP servers with APIs. They do list "call external APIs" among the things a tool can do (Understanding MCP servers, 2026-10-03).

What to consider: an API is the interface a service already offers to programs. An MCP server presents abilities in the MCP format, with named tools, descriptions and input schemas, so any MCP-capable app can discover and call them. The sources do not say that every MCP server wraps an API, so check the specific server's documentation.

What the sources say: does an MCP server cost money?

The MCP introduction calls the protocol open-source. The pages we read state no price for the protocol itself. They also do not state what any specific server costs.

Anthropic's connector overview says the service a connector reaches is run by its provider, which may require its own account or paid plan. Its page on unlisted connectors lists adding a connector by URL for Free, Pro, Max, Team and Enterprise plans, and says that on the Free plan you can add one custom connector (both read 2026-10-03). Check the provider's own pricing page before you connect a service.

What to consider

  • A server is software someone else wrote and runs. "Local" or "remote" tells you where the code runs. It does not tell you who is responsible for it.
  • The specification says tool-behavior descriptions, such as annotations, should be treated as untrusted unless they come from a trusted server. Read a server's tool list as a claim, not a guarantee.
  • Start with one server and one narrow task. Turn the connector off in conversations that do not need it.
  • Never paste passwords, API keys or tokens into a chat to "set up" a server.

For documented risks and a checklist, see are MCP servers safe.

Limitations, and when an MCP server is not the right choice

  • Moving target. This guide follows revision 2026-07-28. The architecture page says that revision is stateless and deprecates the sampling feature. The transports page says earlier revisions used a connection session with an initialize handshake. Older articles and servers may describe the older design.
  • Scope. We did not read OpenAI's or other vendors' documentation for this page. See the terminology map for the other names.
  • Not the right tool for every job. Anthropic's page on creating skills says live data from another service is what a connector provides. For a task done the same way every time, a skill may fit better. For a one-off task, the page suggests describing it in the conversation. For instructions that apply to every conversation, it points to personal preferences or project instructions.

To browse listings that Anavem profiles, see the MCP server index. Anavem has not audited any listed software.

Sources

Get new guides by email

New verified tool profiles, tested workflows and pricing changes. Sponsored items are labelled.