Chapter 1: Introduction
In this chapter, we lay the foundation for understanding MCP (Model Context Protocol). Why do we need it in the first place, and how have LLMs learned to communicate with the outside world?
What Is an LLM?
Large Language Models (LLMs) such as GPT-4, Claude, or Llama are essentially statistical models trained to predict the next word in a sequence. They possess impressive knowledge about the world (from their training data), but by design they are fundamentally "isolated". A standalone LLM cannot send emails, query real-time stock quotes, or read files from your local disk.
The Evolution of Tool Calls

The "Early Days": Manual Copy-Paste
Initially, users had to copy API results manually into the chat interface. The model provided instructions ("Please look up X"), the human executed them, and pasted the output back into the conversation.
The Era of Plugins & Function Calling
OpenAI introduced "Function Calling" in 2023. Developers could describe which functions (APIs) were available to the model. The model no longer responded with plain prose, but with a structured JSON object: "I want to call the function get_weather with the parameter city: Berlin."
The drawback: every vendor built their own siloed system. A plugin written for one platform did not work on another.
The Era of Agentic Skills & Progressive Disclosure (Today)
The latest development moves away from static, monolithic tool lists towards modular Agent Skills. Here, the model knows which expert capabilities are available, but loads their detailed instructions and specialized tools strictly on demand. This principle of Progressive Disclosure preserves the AI's context window and enables complex workflows without overwhelming the model.
What Is MCP?
The Model Context Protocol (MCP) is the universal, open industry standard for this connectivity. Instead of building custom interfaces for every model and host platform, developers build a single MCP server.
Every compatible client (such as Claude Desktop, modern agentic IDEs, coding assistants, or testing tools) can connect to this server and immediately leverage its executable functions (Tools), contextual data sources (Resources), and pre-built templates (Prompts). MCP is to artificial intelligence what USB is to hardware or HTTP is to the web: one universal connector for everything.

Why Build and Run Your Own MCP Servers?
Many developers and teams initially ask: „There are already hundreds of off-the-shelf MCP servers on the internet – why should I invest time in building and running my own?“
In production, three fundamental reasons make custom MCP servers the ultimate lever for reliable, enterprise-grade AI systems:
1. Curated, Secure Access to Sensitive & Local Data (e.g. Databases)
An LLM should never have direct, unconstrained access to a production SQL database or internal file systems (SELECT * FROM users, schema internals, passwords, customer PII).
- A custom MCP server acts as a secure gatekeeper: it encapsulates the database and offers the AI strictly scoped, semantic tools (e.g.
get_customer_order_status(customer_id)). - The database internals (table names, SQL dialects, connection credentials) remain completely hidden from the model.
- Local enterprise databases (SQLite, PostgreSQL behind firewalls) can be securely accessed by AI assistants without exporting sensitive raw data into an external cloud.
2. Deterministically Bypassing LLM Weaknesses: „Compute Instead of Guessing“
Large Language Models are probabilistic language models – not calculators, parsers, or compilers. When a model attempts to solve complex mathematical formulas, currency conversions, regex filtering, or data aggregation purely through linguistic „reasoning“:
- It burns through thousands of expensive reasoning tokens,
- It introduces noticeable latency of 10–30 seconds,
- And it frequently hallucinates subtle calculation errors.
A custom MCP server solves this via deterministic offloading: the model formulates the computation or transformation logic, and the server executes it in a native, secure sandbox in under two milliseconds.
This exact principle is demonstrated by our open-source server wollmilchsau (github.com/hmsoft0815/wollmilchsau · mlcgo.eu/products/wollmilchsau): it equips the model with an isolated TypeScript/V8 sandbox, enabling the LLM to compute, parse, and filter with 100% mathematical precision rather than guessing in the prompt.
3. Integrating Proprietary Business Logic & Legacy Systems
Every organization possesses custom APIs, internal CLI utilities, or unique infrastructure (from ERP systems to IoT sensors and specialized Git workflows). A custom MCP server wraps this existing machinery into a standardized tool suite with minimal code, instantly making it accessible to Claude Desktop, Cursor, VS Code, or autonomous agents like Antigravity.
Goals of This Handbook & Continuous Alignment
This book provides a hands-on, architecturally sound introduction to the MCP ecosystem. Across 24 chapters, it guides you step by step from your first "Hello-World" server to production-grade enterprise deployments.
A Living Document (Living Handbook)
The MCP ecosystem and its formal specification are progressing at a rapid pace:
- Streamable HTTP has replaced legacy dual-connection SSE architectures,
- OAuth 2.1 with PKCE defines the mandatory security standard for network-accessible servers,
- Tasks (SEP-2663) and agentic servers turn MCP servers into fully asynchronous sub-agents,
- Skills over MCP (SEP-2640) standardizes the distribution of entire expert workflows over the wire.
For this reason, this handbook is not a static, one-time publication, but a living document. We maintain and update this work continuously, adapting it to the latest official standards (modelcontextprotocol.io), newly ratified SEPs (Specification Enhancement Proposals), and battle-tested best practices from leading production implementations.
Strict Specification Compliance
A core focus when building MCP systems is strict adherence to the official specification. Because a wide variety of clients, frameworks, and models interact with your server, even minute deviations in JSON-RPC handling or handshakes cause subtle failures. That is why we developed the open-source mcp-tester (github.com/hmsoft0815/mlc_mcptester): it enables you to validate your server directly against the specification, detect specification changes early, and systematically optimize server readiness using an actionable Quality Score (see Chapter 14: Quality Assurance).
📋 Meta & Status
- Last updated: September 27, 2026
- Version: 2.2.0 (Streamable HTTP, OAuth 2.1 / PKCE, Tasks extension / SEP-2663, agentic servers as sub-agents, Elicitation, Skills over MCP / SEP-2640)
- Status: Actively and continuously maintained (Living Document)
- Author: Michael Lechner
← Table of Contents | Next Chapter: How LLMs Communicate →
Copyright Michael Lechner – 2026-09-27 (Continuously maintained MCP Handbook)