ArticlesAI Platform

MCP: the protocol that plugs your systems into agents, its limits, and what it needs around it

MCP has become the standard for connecting agents to company tools. But the protocol handles neither the catalogue, nor fine-grained rights, nor audit, nor cost: that is the shared foundation’s job.

Updated 1 October 2026

1. MCP in two minutes

MCP (Model Context Protocol) is an open protocol describing how an agent discovers and uses tools. On one side, an “MCP serverMCP serverThe small service that exposes a tool (an application, a document base) to agents through the MCP protocol.See the glossary ” exposes an application’s capabilities: read a ticket, look up a customer, create an order. On the other, the agent connects to that server and immediately knows what it can do, with no custom development.

Tools
Actions the agent can trigger: search, read, create, update.
Resources
Data the agent can look at to build context: documents, records, history.
Prompts
Ready-made instruction templates offered by the server.

Created by Anthropic in November 2024, MCP was handed over in December 2025 to the Agentic AIAgentic AIAI that does more than answer: it chains steps together and acts in tools to reach a goal.See the glossary Foundation, hosted by the Linux Foundation and backed by OpenAI, Google, Microsoft and AWS. The July 2026 version makes the protocol statelessStatelessA service that keeps no memory between requests: each call stands alone, so it can easily be spread across several servers.See the glossary , which finally makes it easier to run behind load balancersLoad balancerThe component that spreads requests across several servers to handle load and avoid outages.See the glossary .

MCP does for agents what RESTRESTThe most common style of web API: data is exchanged through addresses and simple verbs (read, create, update, delete).See the glossary APIs did for applications: a common way to plug in. Not a common way to be governed.

2. Why everyone is adopting it

  • An existing API can be exposed as an MCP server: it becomes usable by every compatible agent.
  • The same connectorConnectorThe link between an agent and a company application (email, tickets, CRM, ERP) that lets it read or write there.See the glossary serves several front ends and agents: no need to redo the integration for each tool.
  • The main assistants on the market (ChatGPT, Claude, Copilot, Le Chat, Gemini) already connect to it.
  • Companies that already run an API management platformAPI managementThe platform that publishes, secures, documents and monitors a company’s APIs (MuleSoft, Kong, Azure API Management…).See the glossary start ahead: their APIs are documented, secured and catalogued.

3. What it is used for: three families of use cases

Once systems are exposed as MCP servers, nearly every use case falls into one of three families. They rely on the same servers and the same foundation: only the use case changes, and that is what makes the investment pay off.

Talk to my dataQuery your data and documents
  • Structured dataCRM, ERP, data platform, reference data
  • DocumentsContracts, specifications, procedures, knowledge bases
  • Real timeLogs, monitoring, IoT streams, events
Examples“What is revenue by region?”“What does contract X say?”
Decision supportAnalyse, compare, recommend
  • Synthesis and reportingSummaries, reports, dashboards
  • Comparison and scoringAssessment, prioritisation, rating
  • Forecast and recommendationForecasts, next best action, anticipation
Examples“Which supplier should we pick?”“What is the trend?”
OptimisationAutomate, speed up, cut costs
  • AutomationData entry, classification, transformation
  • Process accelerationApproval, onboarding, content production
  • Quality and costDefect detection, predictive maintenance, supply chain
Examples“Automate invoices”“Reduce stock-outs”

4. The limits, one by one

The specification says so itself: MCP cannot enforce security principles at the protocol level. It is not a design flaw, it is a choice of scope. But as soon as you go past the prototype, these gaps have to be filled elsewhere.

LimitWhat can happenWhat we put in place
Untrusted contentA document or ticket contains hidden instructions that the agent follows (prompt injectionPrompt injectionInstructions hidden in content (a document, email, ticket) that the agent reads and may follow as if they came from the user.See the glossary ).Separate read and write, human approvalHuman approvalA person reviews and approves before the agent’s action is carried out (also called human in the loop).See the glossary for any action, content filtering.
Poisoned tool descriptionsA server slips instructions into its tool descriptions, or changes them after approval.Catalogue of approved servers, pinned versions, review of every change.
Unofficial serversIn 2025, a popular MCP package was altered to secretly copy every email sent.Internal hosting, verified images, dependency scanning.
Optional authorizationAuthentication is not mandatory in the spec, and fine-grained per-tool rights are not part of it.MCP gatewayMCP gatewayThe mandatory path between agents and MCP servers: authentication, per-tool rights, rate limits, filtering and logging.See the glossary with per-tool and per-group rights, identity propagationIdentity propagationThe agent acts on behalf of the person using it, with their rights: it only sees what they are allowed to see.See the glossary , never passing tokensTokenTwo meanings. For a model: a piece of a word, the unit that measures processed text and therefore cost. In security: a temporary key proving an access right.See the glossary through.
Too many toolsAccording to Anthropic, 58 tools take about 55,000 tokens before the first question, and accuracy drops.Expose tools by domain, tool search, per-agent sub-catalogues.
No enterprise catalogueThe official registry lists public servers; it does not say which ones are allowed in your company.An internal registry: approved agents, MCP servers, promptsPromptThe written instructions given to the AI model to steer its answer.See the glossary and skillsSkillA reusable know-how for an agent: a folder of instructions, templates and sometimes scripts, loaded only when needed.See the glossary .
No audit, no costThe protocol defines neither an audit logAudit logThe record of who did what, when and with which data. It lets you check and explain every action.See the glossary nor cost tracking: only tracing conventions.Central observability: every call traced and attributed to an agent and a team.
Agent to tool onlyMCP links an agent to a tool. For two agents to work together, another protocol is needed: A2AA2A (Agent2Agent)The open protocol that lets agents talk to each other and share work. MCP links an agent to a tool; A2A links two agents.See the glossary .A2A gateway and orchestrationOrchestrationCoordinating several agents and tools to run an end-to-end process: who does what, in which order, with which checks.See the glossary between agents.

5. The foundation around MCP

The market’s answer is the same everywhere: agents do not talk to MCP servers directly. A single checkpoint sits between them, which knows who is calling what, with which rights and at what cost.

Agents
Front ends and assistantsBusiness agentsVendor agents
AI Platform foundation
RegistryMCP gatewayLLM gatewayA2A gateway
Identity · per-tool rights · quotas · audit · cost
MCP servers
TicketsCRMERPDocumentation
Existing
Company APIs, databases and applications
Registry
The catalogue of everything that is allowed: agents, MCP servers, prompts, skills, models. Each item has an owner, a version and an approval status.
MCP gateway
The mandatory path between agents and MCP servers: authentication, per-tool rights, rate limits, filtering, logging.
LLM gateway
The mandatory path to models: model choice, quotas, cost per team, freedom to switch provider.
A2A gateway
The same control applied to exchanges between agents: which agent may call another, and for what.
Policies
Rules applied to every exchange: personal data masking, rate limits, compliance checks.
Observability
An overview of the agent network: who calls whom, volumes, response times, errors and cost.

Controls sit in two complementary places: in the gateways, for every agent at once, and in each agent’s middlewareMiddlewareA component that slots into an agent’s loop (before or after the model, around a tool) to add a control without changing the agent itself.See the glossary , closest to its decisions (human approval, caps, data masking).

6. Identity: four ways to link the user to the MCP server

Between the user and the target application, the request goes through an AI gateway, the agent, then an MCP gateway. The real question is: with which identity does the MCP server act, and who checks the rights? Four patterns come up, from the simplest to the finest-grained.

UserAI gatewayidentity, rightsAgentMCP gatewayper-tool rights, quotas, auditMCP serverApplications
Identity provider↔ token exchange (3)? = token received by the MCP server: 1 technical · 2 user · 3 exchanged · 4 second token
PatternWhat the MCP server receivesWhen to use itWatch out for
1. Technical account plus user contextA technical token issued to the gateway, with a signed user context. The gateway has already checked identity, per-tool rights and quotas.Internal applications without fine per-user rights; quick start.The MCP server must trust user context only from the gateway; the application itself sees a technical account.
2. User token passed onThe user’s token, which the MCP server validates itself, rights included.Same identity providerIdentity providerThe service that authenticates users and issues their access tokens (Microsoft Entra ID, Okta, Keycloak…).See the glossary everywhere, token issued for this MCP server.The MCP spec forbids accepting a token that was not issued for the server: never pass a token through “as is”.
3. Token exchangeToken exchangeThe gateway swaps the user’s token for a new one, issued for a specific service with reduced rights (OAuth standard, RFC 8693, also called “on-behalf-of”).See the glossary A new token, obtained by the gateway from the identity provider on the user’s behalf, limited to this server and these rights.The default choice for sensitive data: the application sees the real user, with reduced rights.The identity provider must support token exchange (OAuthOAuth 2.1The standard for giving an application limited access to a service without handing over your password.See the glossary standard, RFC 8693).
4. In-task authorizationA second token, obtained when the user signs in to the target system during the task.Systems with their own identity provider: SaaSSaaSSoftware as a Service: software used online, hosted and maintained by the vendor, paid by subscription.See the glossary , partners, subsidiaries.An interruption for the user; tokens to store and revoke properly.

In every case the gateway remains the checkpoint: it validates identity, applies quotas and rate limits, and traces every call.

7. Three protocols, three links

MCP is only one of an agent’s three links. The other two are being standardised too, with open protocols that complement rather than compete with each other.

UsersAG-UIAgentMCPTools and dataA2AOther agents
LinkProtocolRole
Agent ↔ userAG-UIAG-UIThe open protocol connecting an agent to the application the user sees: live answers, visible actions, approval requests.See the glossary (Agent–User Interaction)Connects an agent to the application the user sees: live answers, visible tool calls, approval requests. Started by CopilotKit.
Agent ↔ tools and dataMCP (Model Context Protocol)Connects an agent to company applications and data. Started by Anthropic.
Agent ↔ agentA2A (Agent2Agent)Lets agents from different frameworksFrameworkA development toolkit that provides an application’s structure; for agents: LangGraph, Strands, CrewAI…See the glossary or vendors find each other and hand off tasks. Started by Google.

With A2A, each agent publishes an “agent cardAgent cardA small file published by an A2A agent describing what it can do, where to reach it and how to authenticate.See the glossary ”: a small file describing what it can do, where to reach it and how to authenticate. Delegated tasks have a lifecycle (submitted, working, waiting for input, completed…), which supports long-running work with a human in the loop. For governance this is good news: these cards belong in the registry, just like MCP servers.

8. The market

Integration vendors, clouds and open-sourceOpen sourceSoftware whose code is public and reusable under a licence. It can be audited, self-hosted and modified.See the glossary projects all offer a version of this foundation. The right choice mostly depends on what you already run.

SolutionTypeKey point
MuleSoft Agent FabricIntegration platform (Salesforce)Agent registry, MCP and A2A connectors, orchestrator, agent network map, policies through the API gateway
Kong AI GatewayAPI gatewayMCP proxyReverse proxyA server placed in front of others that receives every request and forwards it while applying rules.See the glossary , OAuth authentication, per-tool rights
Azure API ManagementMicrosoft cloudExposes managed APIs as MCP servers, AI gateway policies
AWS Bedrock AgentCore GatewayAWS cloudTurns APIs and functions into MCP tools behind a single endpoint
Cloudflare MCP Server PortalsZero TrustZero TrustA security model where nothing is trusted by default: every access is checked, even inside the network.See the glossary Several MCP servers behind one portal, per-user policies, logging
Gravitee Agent MeshAPI gatewayLLMLLMLarge Language Model: a model such as those from Mistral, OpenAI or Anthropic, able to understand and produce text.See the glossary , MCP and A2A proxies, agent catalogue
LiteLLMOpen sourceLLM, MCP and A2A gateway: keys, team rights, quotas, spend tracking
IBM ContextForgeOpen sourceGateway and registry federating MCP, REST and A2A
Docker MCP GatewayOpen sourceMCP servers isolated in containersContainerAn isolated package holding an application and everything it needs to run, identically on any server.See the glossary , verified catalogue
Microsoft MCP GatewayOpen sourceKubernetesKubernetesThe leading open-source platform for running and managing containers at scale.See the glossary reverse proxy: routing, authorization, server lifecycle

If you already manage your APIs with an integration platform, start there: adding MCP to an existing API foundation is often the shortest path. Otherwise, an open-source gateway is enough to get going.

9. Where to start

  • Pick two or three useful systems and expose their APIs as MCP servers, read-only first.
  • Register these servers, the agents and the models in a registry, with an owner for each.
  • Route every call through a gateway: identity, per-tool rights, quotas, logging.
  • Observe the agent network, and only then orchestrate several agents across an end-to-end process.

Further reading