Model Context Protocol
MCP is an open standard that lets an AI model talk to your tools and data through one interface instead of a bespoke integration per app. Below: what the protocol's three primitives actually do, and a directory of the servers that implement them.
Tools, resources and prompts
MCP servers expose three kinds of capability. They are easy to confuse and the distinction decides how you build, because each is controlled by someone different.
Tools
Model-controlled
Functions the model can decide to call on its own — send the message, create the issue, run the query. Tools take arguments and cause effects, so they are the primitive that needs real authorization thinking.
Browse tools →Resources
Application-controlled
Data the server can hand over — a file, a record, a schema — addressed by URI. Resources are meant to be read, not to act. The host application decides which ones enter the context, which is what keeps them safe to expose broadly.
Browse resources →Prompts
User-controlled
Reusable templates a server offers the user — the slash commands and canned workflows that appear in a client's menu. A model does not invoke these on its own; a person picks one, which is exactly why they carry the least risk.
Browse the prompt library →The short version: the model chooses tools, the application supplies resources, and the user picks prompts. If you are deciding where a capability belongs, ask who should be allowed to trigger it.
Going further
- What MCP is and why it matters — the concepts, without the spec.
- How to build an MCP server — a working server end to end.
- How to design tools your AI agent can actually use — naming and schemas that models get right.