Model Context Protocol

MCP is an open standard that lets an AI model talk to your tools and data through one interface instead of a bespoke integration per app. Below: what the protocol's three primitives actually do, and a directory of the servers that implement them.

Tools, resources and prompts

MCP servers expose three kinds of capability. They are easy to confuse and the distinction decides how you build, because each is controlled by someone different.

Tools

Model-controlled

Functions the model can decide to call on its own — send the message, create the issue, run the query. Tools take arguments and cause effects, so they are the primitive that needs real authorization thinking.

Browse tools →

Resources

Application-controlled

Data the server can hand over — a file, a record, a schema — addressed by URI. Resources are meant to be read, not to act. The host application decides which ones enter the context, which is what keeps them safe to expose broadly.

Browse resources →

Prompts

User-controlled

Reusable templates a server offers the user — the slash commands and canned workflows that appear in a client's menu. A model does not invoke these on its own; a person picks one, which is exactly why they carry the least risk.

Browse the prompt library →

The short version: the model chooses tools, the application supplies resources, and the user picks prompts. If you are deciding where a capability belongs, ask who should be allowed to trigger it.

Going further