Concept · Chapter 13: Agents
Model Context Protocol
MCP defines how host applications connect to servers exposing tools, resources and prompts.
The problem
Every custom integration can introduce a different way to discover and exchange capabilities.
The solution
Use a shared client-host-server protocol for connecting those capabilities.
The consequence
Interoperability does not supply planning, permission or trustworthy server behavior.
You should understand first
- Text as Data
- Probability and Distributions
- Conditional Probability and Bayes' Theorem
- Probability of Sequences
- Language Modeling
- Vectors
- Dot Product
- Embeddings
- Attention
- Softmax
- Self-Attention
- Causal Masking
- Entropy
- Loss Functions
- Cross-Entropy Loss
- Autoregressive Next-Token Prediction
- Pretraining at Scale
- GPT-1 → GPT-2 → GPT-3
- In-Context Learning
- The Turing Test
- Symbolic AI
- Logic and Rules
- Expert Systems
- Knowledge Representation
- The Knowledge-Acquisition Bottleneck
- From Rules to Learning
- Supervised, Unsupervised and Self-Supervised Learning
- Expected Value and Variance
- Reinforcement Learning
- MDPs, Policies and Value
- Decoding: Greedy, Temperature, Top-k, Top-p
- One-Hot Encoding
- Tokenization
- Chat Templates
- System Prompts and Instructions
- Structured Outputs and Constrained Decoding
- Tool Calling
- LLM Agents
- Agent Runtime
- Tool Execution in Agents
- Model Context Protocol
Where the connector fits
The host is the application using the model. It manages clients connected to servers. A server can expose callable tools, contextual resources and prompt templates. These roles come from the 2025-11-25 architecture specification, checked October 5, 2026.
For the cart bug, a repository server can expose a read operation. The model selects a proposed call, the host checks it and the client carries the request and response. MCP standardizes the connection; the agent runtime still decides what to do with the observation.
Discovery does not grant authority
A listed tool can be inappropriate for the task. A tool's description is not permission to invoke it. The host must apply authorization and context boundaries. See the tools specification.
MCP is not a model architecture or a training method. An ordinary workflow can use it, and an agent can use tools without it.
What to remember
- MCP defines how host applications connect to servers exposing tools, resources and prompts.
- Use a shared client-host-server protocol for connecting those capabilities.
- Interoperability does not supply planning, permission or trustworthy server behavior.