Chapter 37: Model Context Protocol and Interoperability |
Summary |
The Model Context Protocol, or MCP, represents one of the most consequential infrastructure developments in the recent history of applied artificial intelligence. Originally created by Anthropic and now governed as an open standard under the Linux Foundation, MCP provides a standardized method for connecting artificial intelligence models to external data sources, tools, and services while preserving security, authentication, and licensing governance. Its core significance lies in eliminating the repeated, costly integration work that previously defined enterprise AI deployment. Instead of building custom connections between every AI application and every data source, organizations can expose their systems once through an MCP server and make those capabilities available to any compatible AI client. This chapter examines what MCP is, how it functions, why it matters across industries, and where it is heading. We will explore practical applications in financial services, healthcare, retail, software development, and beyond, with attention to the governance and security considerations that make MCP suitable for regulated environments. |

|
1. The Problem MCP Solves: The Integration Bottleneck |
1.1 The N by M Problem |
Before MCP, connecting an AI model to an external data source required custom integration work. A developer building an AI assistant that needed access to a customer relationship management system would write code specifically for that connection. If the same assistant also needed access to a billing system, that required another integration. If the organization later switched AI vendors, or added a second AI tool for a different department, the integrations often had to be rebuilt. |
This creates what practitioners call the N by M problem. If an organization has N AI applications and M data sources, the theoretical number of point-to-point integrations required is N multiplied by M. A bank with ten AI applications and one hundred internal and external data tools faces a thousand potential integrations to build and maintain . Each integration carries its own authentication logic, error handling, and maintenance burden. The result is slow deployment, duplicated effort, and an AI infrastructure that becomes brittle as it grows. |
1.2 From Custom Code to Standard Protocol |
MCP addresses this by introducing a standardized protocol between AI applications and external systems. Instead of building a direct connection, developers create an MCP server that exposes a system's capabilities in a uniform format. Any AI application that speaks MCP can then connect to that server without additional custom work. This transforms the integration model from a mesh of point-to-point connections into a hub-and-spoke architecture. A system exposes its capabilities once, and any MCP-compatible client can access them . |
The analogy often used is that of USB-C for AI tools. Just as a single port standard eliminated the need for different cables for different devices, MCP provides a single interface standard for AI tool connectivity. A developer writes an MCP server once, and it becomes immediately usable by any AI application that supports the protocol . |
1.3 Why This Matters for Trusted Content Providers |
The value proposition extends beyond technical convenience. When trusted content providers such as financial data vendors, legal databases, or medical reference systems expose their data through MCP, they make that data available natively within AI tools. This means an AI assistant can retrieve and reason over authoritative information without the user needing to manually copy data between systems or the developer needing to build a bespoke connector . |
For a financial data provider, this means an analyst can ask an AI assistant about current market conditions, and the assistant can retrieve live data directly from the provider's systems, with appropriate authentication and licensing controls in place. The reduction in integration friction translates into more reliable outputs, because the AI is working with authoritative data rather than potentially stale or paraphrased information. |

|
2. How MCP Works: Architecture and Core Concepts |
2.1 The Three-Party Architecture |
MCP follows a client-server architecture with three primary roles. The MCP host is the AI application itself, such as a chat interface, an integrated development environment, or an autonomous agent. The MCP client is a component within the host that maintains a connection to one or more MCP servers. The MCP server is a lightweight program that exposes specific capabilities, connecting to databases, application programming interfaces, or file systems on one side and speaking the MCP protocol on the other . |
This separation of concerns is important. The host application does not need to understand how a database query is executed or how an authentication token is validated. It simply discovers what tools are available and invokes them through the standardized interface. The server handles the specifics of connecting to the underlying system. |
2.2 Core Primitives: Tools, Resources, and Prompts |
MCP defines three primary types of capabilities that a server can expose . |
Resources are read-only data that the AI can access. They function similarly to GET requests in a representational state transfer application programming interface. A resource might be a file, a database record, or a document. Resources are identified by uniform resource identifiers, allowing the AI to request specific items by address. |
Tools are executable functions that the AI can invoke. They function similarly to POST requests. A tool might send an email, create a support ticket, execute a database query, or perform a calculation. Each tool declares its input parameters using a schema, which tells the AI what information it needs to provide when calling the tool. |
Prompts are pre-defined templates for common interactions. A server might expose a prompt template for 'summarize a pull request' or 'analyze a customer complaint.' These templates can be reused across different AI applications, ensuring consistent interaction patterns. |
2.3 The Communication Layer |
MCP uses JSON-RPC 2.0 as its underlying messaging format. JSON-RPC is a lightweight remote procedure call protocol that encodes requests and responses as JavaScript Object Notation. This choice makes MCP relatively simple to implement in any programming language and familiar to developers who have worked with web application programming interfaces . |
The protocol supports two primary transport mechanisms. Local MCP servers communicate over standard input and output, which means they run as subprocesses on the same machine as the AI application. Remote MCP servers communicate over HTTP, specifically a transport called streamable HTTP, which allows them to run on separate infrastructure and be accessed over a network . |
2.4 Tool Discovery and Execution |
When an MCP client connects to a server, it performs an initialization handshake. During this handshake, the client and server negotiate a protocol version and exchange information about their capabilities. The client asks what tools, resources, and prompts the server offers. The server responds with a list that includes names, descriptions, and input schemas for each tool . |
When the AI model decides that it needs to use a tool during a conversation, the host application intercepts the tool call, routes it to the appropriate MCP server, executes the function, and returns the result to the model as context. The model never directly executes code or accesses data. It requests actions, and the MCP infrastructure performs them within the security boundaries that have been configured . |

|
3. Governance and Security: Making MCP Enterprise-Ready |
3.1 The Shift to Open Governance |
In December 2025, Anthropic donated MCP to the Agentic AI Foundation, a directed fund under the Linux Foundation. The foundation was co-founded by Anthropic, Block, and OpenAI, with support from Google, Microsoft, Amazon Web Services, Cloudflare, and Bloomberg . This governance structure ensures that MCP remains vendor-neutral and community-driven, which is essential for a protocol that aims to become a universal standard. |
The Linux Foundation has a long track record of stewarding critical open-source projects, including the Linux kernel, Kubernetes, and PyTorch. Bringing MCP under this umbrella signals that the protocol is intended for long-term, transparent development rather than being controlled by a single commercial entity . |
3.2 Authentication and Authorization |
For enterprise deployment, MCP's security model must align with the authentication and authorization practices that organizations already use. The protocol now aligns with OAuth 2.0 and OpenID Connect, the standard frameworks for identity and access management in enterprise environments . |
This alignment means that MCP servers can connect to enterprise identity providers such as Microsoft Entra or Okta without custom workarounds. An administrator can authorize an MCP connector for an entire organization through the identity provider. Users then inherit access through their existing group memberships, and the connector is available on first login . |
The protocol also includes protections against specific attack vectors. The mandatory validation of the issuer parameter, for instance, closes a class of mix-up attacks where a client might be tricked into sending credentials to the wrong server . |
3.3 The Authorization Boundary |
A critical architectural principle for agentic systems is that authorization must occur before execution. If an AI agent is going to perform a side effect, such as transferring funds or modifying a medical record, the authorization evidence must exist before that action takes place. If authorization happens after execution, denial comes too late because the effect has already propagated . |
This principle has implications for how MCP servers are designed. The server should not simply execute any tool call it receives. It should evaluate the request against policy, verify that the requester has the necessary permissions, and only then perform the action. The authorization artifact, a record of the decision, must be generated before the side effect occurs . |
3.4 Audit Trails and Compliance |
For regulated industries such as finance and healthcare, the ability to audit AI actions is not optional. MCP's architecture supports this by centralizing access control and logging at the server layer. Every tool invocation can be logged with information about who requested it, what parameters were provided, and what the result was . |
This centralized governance is a significant advantage over custom integrations, where logging might be implemented inconsistently or not at all. When a healthcare provider uses MCP to connect an AI assistant to patient records, the access logs are generated by the MCP server, not by the individual integration. This makes compliance auditing tractable . |

|
4. Industry Applications: Finance and Financial Services |
4.1 The Leading Adopter |
Financial services has emerged as the leading adopter of MCP, with a reported adoption rate of forty-five percent among Fortune 500 companies in the sector . This is not surprising given the industry's combination of data complexity, regulatory pressure, and existing investment in application programming interface infrastructure. |
Banks and financial institutions have long dealt with a web of market data feeds, regulatory filing systems, risk databases, and internal transaction ledgers. Connecting AI tools to this ecosystem through traditional integration methods is slow and expensive. MCP offers a standardized approach that maps well to the industry's existing governance practices . |
4.2 Fraud Monitoring and Risk Assessment |
In fraud monitoring, AI agents need to access transaction data, behavioral history, and third-party intelligence simultaneously. An agent might need to check a transaction against the customer's normal spending patterns, query a database of known fraud indicators, and consult external threat intelligence feeds. With MCP, each of these data sources is exposed as an MCP server, and the AI agent can query them in a single session without requiring three separate custom integrations . |
Portfolio risk assessment follows a similar pattern. An AI agent monitoring market conditions can pull from market data feeds, assess the risk profile of a portfolio, and surface investment opportunities, all through standardized MCP connections. The agent can work with live data rather than relying on potentially stale training data . |
4.3 Compliance and Regulatory Work |
Compliance officers in financial institutions often need to retrieve and analyze transaction data for regulatory reporting or investigation. An AI assistant connected through MCP could retrieve transaction records, cross-reference them against sanctions lists, and generate summaries, all within a governed environment where access is authenticated and logged . |
LSEG, the London Stock Exchange Group, has been cited as an example of a trusted content provider using MCP to make data available natively within AI tools. This allows financial professionals to access authoritative market data through their AI assistants without the friction of manual data transfer or the risk of working with non-authoritative sources . |
4.4 Digital Banking and Personal Finance |
The implications extend to retail banking and personal finance management. An AI assistant could use MCP to securely connect to a customer's accounts, retrieve transaction histories, and provide personalized insights or recommendations. The governance model ensures that the customer's data is accessed only with appropriate authorization and that all access is logged . |

|
5. Industry Applications: Healthcare and Life Sciences |
5.1 The Electronic Health Record Integration Challenge |
Healthcare has historically been conservative in adopting new technology, but MCP is seeing significant uptake. A reported adoption rate of thirty-two percent reflects the industry's recognition that the electronic health record integration problem maps well to what MCP solves . |
Healthcare providers have accumulated decades of patient data across incompatible electronic health record systems, laboratory information systems, imaging archives, and medication databases. Building direct integrations between AI tools and each of these systems requires specialized connectors and intensive compliance review for each data type. MCP's standardized approach reduces this burden . |
5.2 Clinical Decision Support |
A physician assistant agent using MCP can pull data from the electronic health record, check medication interactions against a prescription database, and summarize recent visit history in a single interaction. All of this access is logged and controlled through a unified governance layer, which makes compliance with health privacy regulations more tractable . |
The key insight is that MCP does not just solve a technical integration problem in healthcare. It makes compliance auditing feasible for AI workflows that would otherwise require custom logging at every point of data access. When a hospital deploys an AI assistant to help clinicians, the MCP server layer provides a single point of control and oversight . |
5.3 Laboratory and Diagnostic Data |
Laboratory information systems and diagnostic imaging archives are another area where MCP can reduce friction. An AI agent could retrieve lab results, compare them against reference ranges, and flag abnormal values for clinician review. The agent operates within the permissions defined by the MCP server, which can be configured to enforce role-based access controls. |
5.4 Pharmaceutical Research and Development |
In pharmaceutical research, MCP can connect AI tools to compound databases, clinical trial data, and literature repositories. A research assistant might query a compound database for molecules with specific properties, retrieve relevant publications from a literature server, and summarize findings, all within a single AI session. |

|
6. Industry Applications: Retail and E-commerce |
6.1 Customer Experience and Support |
Retail and e-commerce have seen a twenty-seven percent adoption rate for MCP . The applications range from customer service to supply chain management. |
A customer support AI assistant connected through MCP can retrieve order history, check inventory levels, process returns, and update customer records. Instead of building separate integrations for each of these functions, the retailer exposes them through MCP servers, and any compatible AI tool can use them . |
6.2 Walmart's Super Agent Architecture |
Walmart provides a notable case study. The company had deployed dozens of narrow AI agents that worked separately across different departments, leading to inefficiency and confusion. To address this, Walmart consolidated them into four 'super agents' for customers, employees, engineers, and suppliers. These super agents call smaller agents and internal systems through MCP, providing a unified interface and stronger oversight across the AI infrastructure . |
The goal, according to Walmart, is to make the AI ecosystem more scalable and secure by using MCP to connect disparate systems under one governance model. This architectural approach allows the company to add new capabilities without building new point-to-point integrations . |
6.3 Supply Chain and Inventory Management |
In supply chain operations, AI agents can use MCP to access inventory databases, supplier systems, and logistics platforms. An agent monitoring stock levels could detect when inventory is running low, query supplier availability through an MCP server, and initiate a replenishment order, all within a governed workflow. |
6.4 Personalization and Marketing |
Marketing teams can use MCP to connect AI tools to customer data platforms, campaign management systems, and analytics tools. An AI assistant could segment customers based on behavior, generate personalized content recommendations, and measure campaign performance, with all data access governed through the MCP layer. |

|
7. Industry Applications: Software Development and Engineering |
7.1 Developer Productivity |
Software development was one of the earliest domains to adopt MCP. Development environments such as Cursor and Claude Code support MCP natively, allowing developers to connect their AI coding assistants to project files, issue trackers, version control systems, and design tools . |
An AI coding assistant with MCP access can read project documentation, check current issue status, review pull requests, and even run tests, all without the developer manually switching between tools. This context-aware development workflow reduces friction and allows the AI to provide more relevant assistance . |
7.2 Database Access for Analysts |
Devart, a database tooling company, has released a line of MCP servers that connect AI assistants to enterprise databases and cloud platforms. The product line includes specialized servers for Microsoft SQL Server, Oracle, PostgreSQL, MySQL, and other database systems, as well as connectors for Salesforce, Dynamics 365, and NetSuite . |
The value proposition is that analysts and business users can interact with enterprise data in natural language without writing SQL queries or relying on development teams. An analyst could ask an AI assistant about quarterly sales figures, and the assistant would retrieve the data through the MCP server, with appropriate access controls enforced at the server layer . |
7.3 Data Engineering and Analytics |
For data engineers, MCP servers for query engines such as Trino allow AI agents to explore data catalogs, understand table schemas, and execute analytical queries. The mcp-trino project, for example, exposes tools for browsing catalogs, describing tables, and executing SQL queries with semantic context from metadata catalogs . |
The semantic layer is particularly valuable for AI agents. An agent that understands not just the table structure but also which datasets are production-ready, what business terms mean, and which columns contain sensitive data can operate more reliably and with less risk of misinterpretation . |
7.4 Enterprise Integration Platforms |
API gateway vendors are racing to position themselves as the control plane for MCP. Kong launched an MCP registry to enable AI agents to discover MCP-compatible services. Apigee from Google Cloud treats MCP servers as first-class API products, extending existing security protections such as OAuth 2.0 and rate limiting to MCP traffic. Azure API Management unified MCP traffic alongside other API workloads. MuleSoft added AI-specific security features including personally identifiable information detection and prompt-injection blocking . |
This convergence of API management and MCP governance reflects the reality that enterprise AI workloads will route through existing infrastructure. Organizations want to manage MCP servers with the same tools and policies they use for other APIs. |

|
8. MCP in the Broader Agentic Ecosystem |
8.1 Relationship to RAG and Frameworks |
MCP is often compared with retrieval-augmented generation, or RAG, but the two serve different purposes. RAG helps an AI system find and understand information. It retrieves relevant text from an external database and feeds it into the model's context. MCP allows an AI system to connect and act. It lets the model interact directly with software systems through secure connections . |
The distinction is between knowledge and capability. RAG might help an assistant answer a question about quarterly earnings by retrieving a report. MCP could go further by logging into an analytics system, pulling live data, and updating a dashboard or sending a summary email. The two approaches complement each other. An AI assistant in a bank might use RAG to locate a regulatory document and MCP to apply that rule to a live transaction . |
MCP is also complementary to frameworks such as LangChain and LlamaIndex, which provide scaffolding for building agentic workflows. These frameworks can use MCP servers as tool sources, gaining access to standardized tools without building custom integrations . |
8.2 Extensions: Apps and Tasks |
The MCP specification has introduced an extensions framework that allows capabilities to evolve independently of the core protocol. Two notable extensions are MCP Apps and MCP Tasks . |
MCP Apps allow servers to render interactive user interfaces directly within the AI conversation. A user can see what a connector is doing and work with it inline, without switching to a separate application. This is particularly valuable for complex workflows where users need to review or modify data before an action is taken . |
MCP Tasks address long-running operations that do not complete in a single request-response cycle. Expensive computations, batch jobs, and other time-consuming tool calls can return a durable handle instead of blocking, allowing the client to poll for progress, provide input when needed, and retrieve the result after reconnecting . |
8.3 The Shift to Stateless Architecture |
A significant evolution in the MCP specification is the move to a stateless core. Earlier versions of the protocol maintained session state between clients and servers, which complicated deployment at scale. The 2026-07-28 specification moved MCP to a request-response model, allowing servers to deploy on serverless and edge infrastructure . |
This change makes MCP servers easier to scale, because they can run behind standard load balancers using existing Kubernetes and cloud-native tooling. Organizations can treat MCP servers like ordinary highly scalable HTTP services, removing the operational friction of managing session state . |

|
9. The Competitive Landscape and Alternatives |
9.1 Proprietary Tool Integration Approaches |
MCP is not the only approach to connecting AI models with external tools. OpenAI offers function calling, a proprietary mechanism specific to OpenAI models. Anthropic has its own tool-use format for Claude models. These approaches are tightly integrated with their respective model ecosystems . |
Framework-native tools, such as LangChain tools or LlamaIndex tools, are another alternative. These are designed for use within their specific frameworks and offer advantages such as tight integration and optimized performance for particular use cases . |
9.2 The Case for Open Standards |
The argument for MCP over proprietary alternatives is similar to the argument for any open standard. Proprietary tool definitions create vendor lock-in. If a tool is defined in OpenAI's format, switching to a different model provider requires rewriting the tool definition. With MCP, the tool is defined once, and any compatible client can use it . |
For production systems, the interoperability and future flexibility of MCP generally outweigh the convenience of framework-native tools. Organizations that expect to use multiple AI models or frameworks over time benefit from the standardization that MCP provides . |
9.3 Coexistence with Other Standards |
MCP does not exist in isolation. Anthropic has also released Agent Skills, structured Markdown playbooks that agents load progressively. The company characterizes MCP and Agent Skills as complementary, with MCP handling tool connectivity and Agent Skills handling procedural knowledge . |
Command-line tool interfaces have also gained traction as a lighter-weight alternative to MCP's upfront schema declaration. The ecosystem is still converging on best practices for when to prefer each approach, but MCP's comprehensive tool integration capabilities position it as the foundational layer for enterprise AI connectivity . |

|
10. Future Trajectories and Conclusion |
10.1 The Road Ahead: Agent Identity and Enterprise Security |
The MCP roadmap identifies agent identity and enterprise-ready security as priority areas. As AI agents increasingly act on behalf of users, sometimes without the user present at the moment of action, the protocol needs a standardized way to handle agent identities and delegation . |
The goal is to allow an agent to act with the authority of a user but with narrower permissions than the user has. Demonstrating Proof of Possession, a security mechanism for binding tokens to specific clients, is being finalized as part of this work. This would prevent stolen tokens from being used by unauthorized parties . |
10.2 Real-Time and Asynchronous Patterns |
The protocol is also evolving to support more sophisticated messaging patterns. The current request-response model works well for many use cases, but agentic workloads increasingly need patterns such as server-initiated events, streaming results, and mid-flight steering of long-running work. The roadmap includes work on triggers, channels, and subscriptions to support these patterns . |
10.3 Caching and Performance |
Caching is another area of active development. The specification has added time-to-live and cache-scope fields to list results and resource reads, allowing clients to cache tool lists and resource content for appropriate durations. The roadmap includes work on extending caching to support versioning of primitive results, which would allow servers to indicate when a cached tool call result is still valid . |
10.4 The Trajectory of Adoption |
MCP has achieved remarkable adoption since its introduction. With more than ten thousand active public MCP servers and support across major AI platforms including , Cursor, Gemini, and Microsoft Copilot, the protocol has become the de facto standard for AI tool connectivity . |
The enterprise trajectory is clear. Organizations that have deployed MCP in production are making architectural decisions that will be difficult to reverse. The API gateway vendors are building MCP governance into their platforms. Cloud providers are offering MCP deployment support. The ecosystem is consolidating around MCP as the standard protocol layer for AI connectivity . |

|
Detailed Summary |
MCP, the Model Context Protocol, solves a fundamental problem in applied artificial intelligence: the repeated, costly integration work required to connect AI models to external data and tools. Originally developed by Anthropic and now governed by the Linux Foundation's Agentic AI Foundation, MCP provides a standardized interface that replaces point-to-point custom integrations with a hub-and-spoke architecture. An organization exposes its systems through an MCP server once, and any MCP-compatible AI client can access those capabilities without additional integration work. |
The protocol defines three core primitives: resources for read-only data access, tools for executable actions, and prompts for reusable interaction templates. Communication uses JSON-RPC over either local standard input-output or remote HTTP transports. The architecture separates the AI host application from the specifics of data access, with MCP servers handling authentication, authorization, and connection management. |
Security and governance are central to MCP's design for enterprise deployment. The protocol aligns with OAuth 2.0 and OpenID Connect, the identity frameworks that organizations already use. Enterprise-managed authorization allows administrators to provision MCP connectors through their identity provider, with users inheriting access through existing group memberships. The authorization boundary principle ensures that policy evaluation occurs before side effects are executed, and centralized logging at the MCP server layer makes compliance auditing tractable. |
Industry adoption spans finance, healthcare, retail, and software development. Financial services leads with a forty-five percent adoption rate among Fortune 500 companies in the sector, using MCP for fraud monitoring, risk assessment, compliance, and market data access. Healthcare has achieved thirty-two percent adoption, driven by the electronic health record integration challenge and the need for HIPAA-compliant AI workflows. Retail and e-commerce see MCP connecting customer service, supply chain, and personalization systems, with Walmart's super agent architecture as a notable case study. Software development was an early adopter, with MCP connecting coding assistants to project files, issue trackers, and databases. |
The protocol has evolved significantly since its introduction. The move to a stateless architecture makes MCP servers deployable on standard HTTP infrastructure, removing the operational complexity of session management. The extensions framework allows MCP Apps and MCP Tasks to evolve independently, supporting interactive user interfaces and long-running asynchronous operations. The roadmap prioritizes agent identity, enterprise security, real-time messaging patterns, and caching improvements. |
MCP is complementary to, rather than competitive with, other approaches. RAG retrieves information for the model to reason over; MCP enables the model to act on external systems. Framework-native tools offer convenience within specific ecosystems; MCP offers interoperability across them. The ecosystem is consolidating around MCP as the standard protocol layer for connecting AI models to external tools and data, with major cloud providers, API gateway vendors, and AI platform companies building support into their products. |