The MCP Handbook

Chapter 24: Glossary - The Language of MCP

To navigate the world of the Model Context Protocol with confidence, a clear understanding of the terminology helps. Here are the most important terms summarized:

MCP-Host (Host)

The application that drives the LLM and manages the connections to the MCP servers. Examples: state-of-the-art desktop clients, IDEs (Cursor, VS Code), mcp-tester.

MCP-Client (Client)

The component inside the host that handles the actual communication with the server (via Stdio or SSE). The terms host and client are often used synonymously.

MCP-Server (Server)

A standalone process or web service that provides tools, resources, and prompts. It implements the MCP protocol.

Transport (Transport Layer)

The technical layer over which client and server exchange data.

  • Stdio: Communication via standard input/output (local pipes).
  • Streamable HTTP: The modern standard for remote MCP. A single endpoint (usually /mcp) receives JSON-RPC via POST; the server replies either with plain JSON or streams an SSE response. Stateless since 2026-07-28: no sessions, mandatory headers MCP-Protocol-Version, Mcp-Method, Mcp-Name (Chapter 16).
  • SSE (Server-Sent Events): The historical two-endpoint approach "HTTP+SSE" (one open stream connection plus a separate POST URL), replaced by Streamable HTTP and deprecated. Within Streamable HTTP, SSE is only one possible response format.

Tool

An executable function of the server with a defined input schema. Tools allow the LLM to perform actions in the outside world - from simple API calls to complex database operations.

Resource

Data sources (texts, images, files, blobs) that the server makes available to the model. They are identified by URIs and can be read (resources/read) or subscribed to (resources/subscribe) by the client.

Tool Annotation

Optional metadata that deliberately marks a tool - for example readOnlyHint (read-only, changes nothing) or destructiveHint (destroys data). Clients can use these hints to prepend a safety prefix to the prompt before execution, reducing destructive actions.

Prompt

Predefined text snippets or system instructions delivered by the server to steer the model's behavior.

Elicitation

A mechanism in which the server asks the user (via the client) for information. There is form mode (for structured data) and URL mode (for credentials, OAuth and payments in the browser). Since 2026-07-28 delivered via multi round-trip requests.

Multi Round-Trip Requests (MRTR)

Since 2026-07-28 the way a server requests input from the client during a call (elicitation, sampling, roots): it responds with resultType: "input_required" and inputRequests, and the client retries the call with inputResponses and the unchanged requestState (SEP-2322, Chapter 21).

Sampling

A procedure in which the server requests the client to let the LLM generate a response. This enables "agentic" servers that use the AI for their own workflows. Deprecated since 2026-07-28 (SEP-2577); servers should integrate an LLM directly instead.

Task

An asynchronous, long-running operation. Tasks turn synchronous tool calls into state machines (working, input_required, completed, failed, cancelled) to avoid timeouts. Since 2026-07-28 an extension (io.modelcontextprotocol/tasks, SEP-2663).

Sub-Agent

A delegated agent that works on a subtask on its own and returns the result to the main agent. In MCP: an agentic server with its own LLM loop whose lifecycle is represented by a task (Chapters 19 and 20).

Cancellation

The ability of client or server to terminate an in-flight request early (notifications/cancelled) to save resources.

Ping

A simple health-check request to verify that the connection between client and server is still active and responsive.

Icon

Visual metadata (URLs or Base64 data) that allows clients to display tools, resources, and prompts with graphics.

YAML Frontmatter

A structured data block at the top of a Markdown file (between --- lines). It contains metadata such as ID, description, or keywords that systems use for indexing (discovery).

Token

The smallest unit of text (words, word parts, or characters) that an LLM can process. The number of tokens determines costs and space usage in the context window.

Context Injection

The dynamic insertion of information (e.g. skill instructions or file contents) into the ongoing chat flow. This allows the model to acquire new knowledge "on the fly".

Agent Skill

A modular container for expert knowledge, best practices, and optional helper scripts (standardized directory format via agentskills.io with SKILL.md). Skills are not kept permanently in the system prompt, but are loaded on demand to conserve the context window.

Skills over MCP (`io.modelcontextprotocol/skills`)

An official MCP extension (SEP-2640, spec revision 2026-07-28) allowing MCP servers to expose Agent Skills over the wire protocol. It uses skills/list for discovery (Level 1) and MCP Resources with the skill:// URI scheme to deliver SKILL.md and supporting assets (Levels 2 & 3).

Progressive Disclosure

A design pattern for LLM and agentic systems in which detailed information (e.g. skill instructions or complex schemas) is only loaded into the context when it is relevant to the current task. This prevents tool overload and reduces token costs.

Logging Level

Logging severities based on RFC 5424 (debug, info, warning, error, etc.). Clients can control the verbosity via logging/setLevel.

URI (Uniform Resource Identifier)

A unique identifier for resources (e.g. file:///logs/today.txt).

Context Window

The maximum amount of information (tokens) that an LLM can process at once. MCP information takes up space in this window.

RPC (Remote Procedure Call)

A technical concept in which a function in another process is invoked. MCP uses JSON-RPC 2.0 for this exchange.

Handshake (Initialization)

The first data exchange, in which versions and capabilities are negotiated.

Base64

A method to convert binary data (such as images) into an encoded text string. This allows graphics to be embedded directly in a JSON file or a prompt ("Data-URI") instead of having to ship them as a separate file.

Mcp-Session-Id

Session header of Streamable HTTP in versions 2025-03-26 through 2025-11-25, issued in the initialize response. Removed since 2026-07-28 (SEP-2567): MCP is stateless and servers ignore the header. If a flow needs state, the server issues its own handle as a tool argument.

Last-Event-ID

SSE header for resuming a broken stream. No longer used by MCP since 2026-07-28: if a stream breaks, the client re-sends the request; long-running work belongs in tasks (Chapter 19).

PKCE (Proof Key for Code Exchange)

An extension of the OAuth Authorization Code Flow (RFC 7636) that protects public clients (e.g. MCP clients in the browser) from authorization interception attacks. The client generates a random challenge, derives the verifier from it, and sends both; the token endpoint checks the two values against each other. Mandatory in OAuth 2.1.

OAuth 2.1

The revised security recommendations based on RFC 6749, which deprecate outdated flows (Implicit, Native Client) and mandate PKCE for all public clients. MCP remote servers can use a separate authorization server; the MCP client assumes the role of the OAuth "Resource Owner" client.

← Back to Table of Contents


Copyright Michael Lechner - 2026-04-26

Licence: CC BY-NC 4.0