On this page9 sections
What is an MCP server? The short answer
An MCP server is a program that gives an AI app tools and data from one system. It speaks the Model Context Protocol (MCP), so any compatible client, such as Claude, ChatGPT or Cursor, can ask what it offers and then call it. A Shopify MCP server, for example, lets an AI read orders and update products.
MCP server meaning, in plain English
An MCP server sits between an AI app and one product. The product might be Shopify, HubSpot, GitHub or a folder on your laptop. The server tells the AI app which actions exist, runs one when asked and hands back the result.
The MCP docs define servers as "programs that expose specific capabilities to AI applications through standardized protocol interfaces" (server concepts).
"Server" here means software. A local MCP server is a small process on your own computer. A remote one runs in the cloud like any web service. You do not buy hardware for it.
It is one of three roles in the protocol (architecture overview). The host is the AI app you use, such as Claude Desktop or VS Code. The host creates one client for each server you add. The server is the program at the other end. You only ever choose the host and the server.
For the protocol itself and why it exists, read What is MCP?.
What does an MCP server do?
A server can offer three kinds of things (server concepts):
| Building block | What it is | Examples from the MCP docs | Who decides when it is used |
|---|---|---|---|
| Tools | Actions the model can call | Search flights, send messages, create calendar events | The model |
| Resources | Read-only data for context | Documents, knowledge bases, calendars | The app |
| Prompts | Ready-made instruction templates | "Plan a vacation", "Summarize my meetings" | The user |
Tools are the part that lets an AI act in your account. A tool is a name, a description and an input schema. The model reads the description and decides when to call it.
Here is the shape of a tool definition. The field names come from the spec. The tool itself is made up.
{
"name": "find_invoices",
"description": "Find invoices by customer and status",
"inputSchema": {
"type": "object",
"properties": {
"customer": { "type": "string", "description": "Customer name or ID" },
"status": { "type": "string", "enum": ["open", "paid", "overdue"] }
},
"required": ["customer"]
}
}When the model calls a tool, the server checks the inputs against that schema, runs the action and returns text or structured data. For a SaaS product, running the action usually means calling the product's API with a credential the server holds.
How an MCP server handles a request
- AI app (host) to MCP servertools/list
- MCP server to AI app (host)Tool names, descriptions, input schemas
- You to AI app (host)Which products sold best last week?
- AI app (host) to MCP servertools/call (orders tool, last 7 days)
- MCP server to Product APIAPI request with the stored credential
- Product API to MCP serverOrder data
- MCP server to AI app (host)Tool result
- AI app (host) to YouAnswer in plain language
The model never reaches the product directly. It sees a tool list and tool results. The server holds the credential and decides which actions exist. That makes the choice of server the main control over what an AI can touch in your account.
The messages are JSON-RPC 2.0, and the current spec revision is 2026-07-28 (spec). You do not need either fact to use a server. If you are building one, Model Context Protocol: how it works has the wire-level detail, and MCP vs API covers how a server relates to the API underneath it.
Types of MCP servers
The spec has no list of server types. Four differences matter when you pick one.
Local or remote
A local server runs on your computer and talks to the AI app over stdio. A remote server runs at a URL and uses Streamable HTTP. Those are the two standard transports in the spec (transports).
Web-based clients need the remote kind. ChatGPT's developer mode connects to remote servers (OpenAI). Claude reaches custom connectors from Anthropic's cloud, not from your device (Claude help center). Remote vs local MCP servers compares the two in full.
Who builds and runs it
- Vendor servers come from the company behind the product. GitHub runs one, hosted by GitHub or run locally (GitHub). Sentry runs a remote one (Sentry).
- Reference servers are maintained by the MCP project to show how the protocol works. Filesystem and Git are two. The repo describes them as educational examples, not production-ready software (servers repo).
- Community servers are built by anyone. Check who maintains one, and when it was last updated, before you install it.
- Hosted platforms run servers for many products behind one account. PopMCP is one.
Read-only or read-write
A read-only server can look things up. A read-write server can also create, update or delete.
A tool can label itself with hints such as readOnlyHint. The spec tells clients to treat those hints as untrusted unless they trust the server (tools spec). So read the tool list yourself.
A few tools or hundreds
Some servers expose a handful of tools and others expose hundreds. A longer list covers more jobs, but every tool definition the client loads takes room in the model's context.
The MCP docs point clients that connect to many servers toward progressive tool discovery, which means not loading every tool up front (architecture overview). MCP token limits covers that trade-off.
MCP server examples
Servers you can use today
| Server | Run by | Where it runs | What it lets an AI do |
|---|---|---|---|
| Filesystem | MCP project (reference) | Local | File operations inside the folders you allow |
| Git | MCP project (reference) | Local | Read, search and change Git repositories |
| GitHub | GitHub | Remote or local | Read repositories and code, manage issues and pull requests |
| Sentry | Sentry | Remote | Search errors and triage issues |
Older lists need care. Anthropic's launch post in November 2024 named pre-built servers for Google Drive, Slack, GitHub, Git, Postgres and Puppeteer (Anthropic). The reference versions of GitHub, Google Drive, PostgreSQL, Puppeteer and Slack have since been archived by the MCP project (servers repo), so check a server's README before you rely on it.
What it looks like on business tools
These examples use real tool names from PopMCP's catalog.
A Shopify store. You ask, "Which products had the most orders last week?" The model can call shopify_get_orders for the date range and shopify_get_products for the names, then build the table.
A HubSpot pipeline. You ask, "List open deals over $10,000 with no activity in 14 days." The model can call hubspot_deals_search with those filters. If you then ask for a follow-up task on each deal, it calls hubspot_tasks_create. That second step is a write. It needs a paid plan, and it runs as soon as the model calls it.
Three systems in one question. With Shopify, GA4 and Meta Ads connected, "Which campaigns drove the most revenue this month?" becomes calls to meta_ads_get_campaign_insights, ga4_run_report and shopify_get_orders. Joining those numbers is the model's work, so check the answer against a report you trust the first few times.
Common misconceptions about MCP servers
"Once a server is connected, the AI can do anything"
The model can only call tools the server lists. If there is no delete tool, it cannot delete.
The spec also says a host must get the user's consent before it invokes a tool, and notes that the protocol itself cannot enforce this (spec). It is up to the AI app. Claude, for example, asks you to approve a tool call and offers an "Allow always" option, which its help center says to use only for servers and tools you trust (Claude help center).
"One MCP server covers every tool"
A server usually covers one product. Shopify and HubSpot are two servers. A hosted platform can put both behind one sign-in, but each product still has its own tools and its own connected account.
"The vendor's own server is always the best pick"
It is a sensible default, because the vendor knows its API. The vendor also chooses how much of that API to expose. If your job needs an operation the server leaves out, you need a broader server or the API itself. Compare the tool list to the job before you commit. Best MCP servers lists options by use case.
How to get an MCP server
There are three routes.
- Use the vendor's server. Search the product's docs for "MCP". This fits when you need one product and its tool list covers your job.
- Build your own. This fits internal systems nobody else supports. The MCP project lists official SDKs for ten languages, with TypeScript, Python, C#, Go, Rust and Ruby at Tier 1 (SDKs), and the MCP Inspector for testing. You own hosting, sign-in and upkeep.
- Use a hosted platform. This fits teams that need several business tools and do not want to run servers.
The official MCP Registry is a metadata index of public servers, still in preview, that marketplaces and other aggregators pull from. To browse servers yourself, use one of the directories in MCP server directories compared.
The hosted route with PopMCP
You connect a provider account once from the MCP server catalog, such as Shopify or HubSpot. Then you add one URL, https://app.popmcp.com/mcp, to your AI client, sign in and tick the connectors that client may reach. There is no token to paste.
Try a read first. Ask the client to run list_connections so you can see which accounts it reaches, because a write runs as soon as the model calls it. How to connect Claude to your business tools walks through each step, and the Claude setup page has the short version.
Provider credentials stay in PopMCP, encrypted at rest with AES-256-GCM, and are never passed to the AI client.
On catalog size: HubSpot has 1,000+ operations in PopMCP, Klaviyo 308 and Shopify 70. PopMCP loads a curated set for each provider and keeps the rest reachable through a search tool, for example hubspot_search_tools, on every plan.
Where it does not fit: PopMCP covers business tools, so it will not read local files or a Git repo. It is not a workflow builder or an agent framework, and it does not run jobs on a schedule. If a provider you need is missing, request an integration.
Questions to ask before you connect any server
- Who runs it, and when was it last updated?
- Which of its tools write or delete?
- Where does the credential live: in the AI app's config file, on your machine or with the provider?
- How do you cut off access later?
- Does your AI app support its transport? Web clients need a remote server.
MCP security best practices has a fuller checklist.
Frequently asked questions
What is an MCP server in simple terms?
A program that lets an AI app use another system. It lists the actions it offers, runs one when the AI asks and returns the result. A HubSpot MCP server, for example, lets Claude search your deals.
What is the difference between an MCP server and an MCP client?
The server offers tools and data. The client is the piece inside the AI app that talks to one server. An app such as Claude Desktop creates a client for each server you add, so you never set one up yourself.
Is an MCP server the same as an API?
No. An API is a product's interface for developers. An MCP server presents actions to AI apps in a standard format and usually calls that API to carry them out. MCP vs API compares them.
Where do MCP servers run?
On your computer or on the internet. A local server is started by your AI app and talks over stdio. A remote server has a URL and uses Streamable HTTP.
Do I need to run my own MCP server?
Only for internal systems or custom logic that nobody else supports. For common products, use the vendor's server or a hosted platform.
Are MCP servers safe?
It depends on the server. A server is code that acts with your credentials, and the spec says tools should be treated as arbitrary code execution. Use servers from sources you trust, read the tool list and try a read before a write. MCP security best practices covers the known risks.
Which AI apps can use MCP servers?
Anthropic's December 2025 list of products that had adopted MCP names ChatGPT, Cursor, Gemini, Microsoft Copilot and Visual Studio Code, alongside its own Claude apps (Anthropic). Support for local servers varies by app.
How many MCP servers are there?
Anthropic counted more than 10,000 active public MCP servers in December 2025 (Anthropic). We found no newer count from Anthropic or the MCP project, and the official MCP Registry's documentation does not state a total.
Sources
15 references, checked 5 October 2026
- Understanding MCP servers (definition, tools, resources, prompts)modelcontextprotocol.io
- MCP architecture overview (host, client, server, progressive tool discovery)modelcontextprotocol.io
- MCP specification, current revision 2026-07-28 (JSON-RPC, consent principles)modelcontextprotocol.io
- MCP transports, 2026-07-28 (stdio, Streamable HTTP)modelcontextprotocol.io
- MCP tools, 2026-07-28 (input validation, untrusted annotations)modelcontextprotocol.io
- Official MCP SDKs and tiersmodelcontextprotocol.io
- MCP Inspectorgithub.com
- MCP reference servers repo (current and archived servers)github.com
- GitHub MCP Server (remote and local)github.com
- Sentry MCP Servermcp.sentry.dev
- The MCP Registry (preview, metadata for aggregators)modelcontextprotocol.io
- Anthropic, introducing MCP (November 2024, pre-built servers)anthropic.com
- Anthropic, donating MCP to the Agentic AI Foundation (10,000+ servers, adoption list)anthropic.com
- Claude help center, custom connectors using remote MCPsupport.claude.com
- ChatGPT developer modedevelopers.openai.com