How Plugsky MCP works in practice
Everything in this guide runs on Plugskyโs live MCP endpoint (https://plugsky.com/mcp) or the npm bridge (npx -y @plugsky/mcp). A client request flows: JSON-RPC over Streamable-HTTP → auth (API key or OAuth 2.1 + Dynamic Client Registration with fine-grained scopes) → tool router → the service you asked for. Model calls run behind a 7-tier provider failover chain; browsing renders with headless Chromium; transcripts come from real captions and Groq Whisper; images generate on FLUX; code runs in a sandbox with no network; memory persists in your account (Postgres-backed); and every tool call is metered per user on your dashboard.
Relevant live tools for this article: plugsky_models, plugsky_chat โ the catalogue and chat tools this guide connects to.
What is a Model Context Protocol (MCP) server? A plain-English 2026 guide
Direct answer
A Model Context Protocol (MCP) server is a small program that exposes tools, files, and prompt templates to an AI app like ChatGPT, Claude, or Cursor through a single JSON-RPC 2.0 interface. Instead of building a custom integration for every AI client, you ship one MCP server and every MCP-aware client can call it. The current spec is
2026-07-28, published by Anthropic; the ecosystem now covers 80,000+ servers across 14 registries.
Key facts
| Spec version | 2026-07-28 (successor to 2025-11-25) |
| Author | Anthropic (open protocol) |
| Transport | JSON-RPC 2.0 over stdio (local) or Streamable-HTTP (remote) |
| Primitives | Tools, Resources, Prompts |
| Advanced features | Sampling, Elicitation, Roots |
| Auth | OAuth 2.1 + PKCE, Bearer, stdio env |
| Discovery | /.well-known/oauth-protected-resource, /.well-known/mcp |
| Registries indexed | 14 (Official Registry, Smithery, mcp.so, Glama, PulseMCP, mcpservers.org, MCPfinder, mcpmarket, Unyly, Cloudflare Catalog, awesome-mcp-servers, mcp-public, AliveMCP, Product Hunt) |
| Reference client | Claude Desktop |
| Plugsky endpoint | https://plugsky.com/mcp โ 36 models, RAG, tools, free tier |
TL;DR
- MCP is an open protocol from Anthropic โ think "USB-C for AI apps." One socket, many peripherals.
- Servers expose three primitives: Tools (functions the AI calls), Resources (files the AI reads), Prompts (slash-commands the user triggers).
- Clients (ChatGPT, Claude, Cursor, VS Code, Windsurf, Zed, Cline, Vercel AI SDK, LangChain, Bedrock) all speak the same wire format.
- Two transports:
stdiofor local processes,Streamable-HTTPfor hosted servers. WebSockets and plain SSE are deprecated. - Free way to try it in 30 seconds: add
https://plugsky.com/mcpas a remote MCP in Claude Desktop โ get 36 models, RAG, and 145 platform tools with a real free tier.
How it works
Step-by-step:
- User types a prompt in Claude/ChatGPT/Cursor.
- Client sends
tools/listto every configured MCP server on startup to discover what's available. - Model decides โ mid-conversation, the LLM chooses whether to call a tool (like
plugsky_web_search) based on the tool descriptions the server advertised. - Client sends
tools/callwith the arguments the model chose. - Server executes the tool โ could hit an API, run code, query a database, transcribe a video.
- Server returns structured content (text, JSON, image, resource link).
- Model summarizes the tool's result to the user in natural language.
- Repeat โ modern agents make 3โ10 tool calls per turn.
Why MCP matters (and why Anthropic released it as open)
Before MCP, every AI app needed a bespoke integration for every tool. ChatGPT had "custom GPTs," Claude had its own function calling, Cursor had Cursor tools, Windsurf had Cascade โ none of them talked to each other. If you built a Notion connector for one, it did nothing in another.
MCP fixes that with a single spec. Ship one server โ run in every client. It is the same shift that USB brought to peripherals or that HTTP brought to hypertext.
Anthropic released MCP as an open protocol in November 2024 and by mid-2026 the entire industry adopted it โ OpenAI ships Apps SDK on top of MCP, Google's ADK speaks MCP, AWS Bedrock AgentCore speaks MCP, Cloudflare hosts an MCP catalog, Vercel AI SDK has first-class MCP support. Even direct competitors adopted it because the alternative โ fragmented per-vendor SDKs โ was worse for everyone.
What can an MCP server actually do?
The three primitives map to three UX patterns:
- Tools โ the model decides when to call. Example:
plugsky_web_search,plugsky_youtube_transcript,github_create_issue. This is where 90% of MCP traffic happens today. - Resources โ the user or client attaches. Example:
plugsky://collections/onboarding-docsbecomes a clickable attachment in Claude's chat input. - Prompts โ the user triggers with a slash command. Example: typing
/plugsky:pick-cheapest-modelinserts a starter prompt.
On top of that, three advanced features unlock agent-native patterns:
- Sampling โ server asks the client's LLM to complete a sub-prompt for free (e.g., summarize a log before returning it).
- Elicitation โ server asks the user a mid-tool question ("Which collection? Confirm $0.12 cost?").
- Roots โ client tells server "you may only read files under
/Users/me/projects."
MCP vs function calling โ what's the difference?
Function calling is a model capability (Anthropic tools, OpenAI function calling, Gemini function calling) โ the LLM can output a structured JSON that says "call X with args Y." That's the intelligence side.
MCP is a transport + registry โ a standard way for the runtime to expose that function to any model. Function calling is the language; MCP is the wire protocol. You need both.
Which AI clients support MCP in 2026?
| Claude Desktop / Claude.ai / Claude Code | Full (tools + prompts + resources + sampling) | Reference implementation |
| ChatGPT (Business/Enterprise/Edu) | Full via Connectors + Developer Mode; Pro tier = read/fetch only | Apps SDK adds UI |
| Cursor | Full (tools + resources) | .cursor/mcp.json |
| VS Code (Copilot Chat) | Full (tools) | .vscode/mcp.json, top key servers |
| Windsurf (Codeium) | Full (tools + resources) | ~/.codeium/windsurf/mcp_config.json |
| Zed | Full (tools) | Native Rust |
| Cline / Continue / Aider / Roo Code | Full (tools) | Top open-source coding agents |
| Vercel AI SDK / AI Gateway | Full (tools + resources + prompts + human approvals) | 3 lines to wire |
| LangChain / LlamaIndex / OpenAI Agents SDK / Google ADK / AWS Bedrock AgentCore | Full (tools) | Framework-level |
Is MCP secure?
Security comes from three layers:
- Auth โ MCP mandates OAuth 2.1 with PKCE for remote servers. Bearer tokens are allowed but scoped. The spec also standardizes
WWW-Authenticatechallenges via RFC 9728. - Roots โ the client tells the server which filesystem paths (or, by extension, which resources) are in scope. A well-behaved server refuses everything else.
- Human in the loop โ Claude and Cursor pop a permission dialog the first time a tool runs. ChatGPT Enterprise adds admin controls per connector.
Bad servers are still a risk (a compromised MCP server could exfiltrate whatever the user grants it). The mitigations are: use registries that publish security scores (Glama grades servers AโF), pin server versions, prefer OAuth over long-lived bearer tokens, and audit which servers your team installs.
Can I self-host an MCP server?
Yes โ that's the point. Any language works (Anthropic ships SDKs for TypeScript, Python, Kotlin, C#, Swift, Rust, Go). Under 100 lines gets you a working stdio server. To host it publicly, you need to add Streamable-HTTP transport, OAuth 2.1, and publish a server.json manifest to the Official MCP Registry.
Easier: use an existing hosted MCP like Plugsky โ you get 36 models, RAG, and 145 tools instantly without running any code.
Comparison โ MCP vs the alternatives
| MCP | โ Anthropic-published, industry-adopted | โ 20+ clients | โ OAuth 2.1 + PKCE | โ 14 registries | ๐ Explosive |
| OpenAI function calling (alone) | โ Vendor-specific format | โ OpenAI-only surface | โ Per-app | โ None | Legacy โ now wraps MCP via Apps SDK |
| LangChain tools | โ ๏ธ De-facto within LangChain | โ LangChain-only | โ Per-tool | โ None | Being replaced by MCP under the hood |
| Zapier / Make webhooks | โ Product-specific | โ ๏ธ Some SDKs | โ | โ ๏ธ Zapier catalog | Now also exposes MCP endpoint |
| Custom REST + OpenAPI | โ OpenAPI 3 | โ Per-client wrapper | โ | โ | Complementary โ many MCPs wrap REST |
FAQ
Q: What does MCP stand for?
A: Model Context Protocol โ an open protocol from Anthropic that standardizes how AI apps talk to external tools, files, and prompt templates over JSON-RPC 2.0.
Q: Is MCP an Anthropic-only thing?
A: No. Anthropic authored the spec but it is open and industry-adopted. OpenAI's Apps SDK wraps MCP, Google ADK speaks MCP, AWS Bedrock AgentCore speaks MCP, Cloudflare and Vercel host MCP catalogs. Every major AI framework now speaks MCP.
Q: What's the difference between MCP and function calling?
A: Function calling is a model capability (LLM outputs a JSON call). MCP is the transport that lets any client run that call against any server. You need both.
Q: What's the current MCP spec version?
A: 2026-07-28 as of September 2026. It replaces 2025-11-25. Streamable-HTTP is now the mandatory remote transport; plain SSE and WebSockets are deprecated.
Q: How many MCP servers exist today?
A: Over 80,000 aggregated across the 14 registries (Unyly meta-catalog count, September 2026). The Official MCP Registry alone has thousands of verified entries.
Q: Can I try MCP without writing code?
A: Yes โ add https://plugsky.com/mcp as a remote MCP in Claude Desktop or Cursor. You get 36 models, managed RAG, and 145 tools instantly, with a real free tier.
Q: Is MCP secure enough for enterprise?
A: When paired with OAuth 2.1, scoped tokens, per-workspace keys, audit logs, IP allowlists, and a residency-tagged endpoint (like eu.plugsky.com/mcp), yes. Enterprise deployments should require SOC 2 or ISO 27001 readiness from the provider.
Q: What are Prompts and Resources in MCP?
A: Prompts are user-triggered slash-command templates (e.g., /plugsky:pick-cheapest). Resources are URIs the client can attach as first-class context (e.g., plugsky://collections/onboarding). Most servers only implement Tools โ Prompts and Resources are free surface area that improve discoverability.
Trust & sources
- Author: Mustafa Hasan โ PhD Computer Science, ex-CTO Faceki, Founding Partner Valu.vc, founder Plugsky.
- Reviewed by: Plugsky Engineering.
- Last updated: {DATE}.
- References: MCP spec, RFC 9728 Protected Resource Metadata, RFC 8414 Authorization Server Metadata, RFC 7591 Dynamic Client Registration, Anthropic MCP announcement, OpenAI Apps SDK, Cloudflare MCP guide.
- Related reading: [How to add an MCP server to ChatGPT](/blog/add-mcp-to-chatgpt) ยท [How to add an MCP server to Claude Desktop](/blog/add-mcp-to-claude) ยท [Best free MCP servers 2026](/blog/best-free-mcp-servers-2026).
Plugsky (2026). “What is a Model Context Protocol (MCP) server? A plain-English 2026 guide”. Plugsky. Available at: https://plugsky.com/articles/what-is-model-context-protocol-mcp-server-2026 (last updated 2026-09-30).