What is an MCP server? A guide for marketing teams
An MCP server offers tools to AI assistants such as Claude, ChatGPT or Cursor over the Model Context Protocol. What it is, how it differs from an API, how the spec changed through July 2026, and a real server's tools, read and write.

TL;DR
- An MCP server is a program that offers tools and data to AI assistants over the Model Context Protocol, an open standard Anthropic published on November 25, 2024. An assistant such as Claude, ChatGPT or Cursor reads the server's tool list and calls a tool when a task needs it.
- An MCP server does not replace an API. Many MCP servers sit on top of an existing API and describe each action so a model can pick it: a developer's code calls an API, and an AI assistant calls an MCP server.
- The current MCP revision, dated July 28, 2026, made the protocol stateless: it removed the initialize handshake and protocol-level sessions. The specification tells clients how to detect an older server and fall back to it.
- Before connecting an MCP server to business accounts, give it a key limited to what it needs, start with read-only tools, keep a person approving anything that publishes, and revoke the key when you stop using it.
What an MCP server is
An MCP server is a program that exposes tools, data and prompt templates to AI applications through the Model Context Protocol (MCP), according to the MCP project's guide to understanding MCP servers. The AI application, such as Claude or an AI code editor, connects to the server, learns what it offers, and uses it on the user's behalf. The project's introduction to MCP compares the protocol to a USB-C port: one standard plug in place of a different cable for every device.
Anthropic open-sourced MCP on November 25, 2024, with a specification, SDKs, local server support in the Claude Desktop apps and a repository of example servers, according to its launch announcement. On December 9, 2025, Anthropic donated MCP to the Agentic AI Foundation, a fund under the Linux Foundation co-founded by Anthropic, Block and OpenAI. The Linux Foundation's announcement of the same day names MCP as one of the foundation's founding projects, so no single AI vendor owns the standard.
For a marketing team, the practical meaning is short. An MCP server is how an AI assistant gets hands inside a product the team already uses: it can read that product's data and, if allowed, act in it.
How an MCP server works
An MCP server works by answering structured requests from an MCP client inside an AI application. The MCP specification names three roles: the host is the AI application, the client is the connector inside it, and the server provides context and capabilities. Every message between them is JSON-RPC 2.0, a plain request and response format.
A server can offer three kinds of building block:
| Building block | What it is | Who decides when it is used |
|---|---|---|
| Tools | Actions the model can call, such as searching, sending or creating something | The model |
| Resources | Read-only data for context, such as a document or a database schema | The application |
| Prompts | Ready-made instruction templates for a task | The user |
Tools do most of the work. A client asks for the list with tools/list and gets back each tool's name, a description and a JSON Schema of its inputs. When a request needs a tool, the model picks one and the client sends tools/call with the arguments.
The specification's transports page defines two standard ways to carry those messages. The stdio transport runs the server as a local program the AI app starts on your computer. Streamable HTTP sends each message as an HTTP POST to one web address, which is how a hosted server run by a software company works.
MCP vs an API
An MCP server and an API expose the same kind of capability to different callers: an API is written for a developer's code, and an MCP server is written for an AI model. Many MCP servers are a thin layer over an API. The overads MCP server, for example, is documented as the same publishing, workflow and analytics surface as the overads REST API, offered as tools, and it shares the workspace's API rate budget.
| Question | API | MCP server |
|---|---|---|
| Who calls it | A developer's code | An AI assistant, with the user's consent |
| How the caller learns what exists | A person reads the documentation | The client calls tools/list and gets names, descriptions and input schemas |
| Who chooses the action | The code, written in advance | The model, at the moment a request needs it |
| How it is connected | Written into an integration | Added once to an AI app's MCP settings |
| Sign-in over the web | Whatever the API defines, often a key or OAuth | Optional in the spec; when used, based on OAuth 2.1 |
The MCP authorization page makes authorization optional. A server on Streamable HTTP that uses it should follow the OAuth-based flow in the specification, while a local stdio server should read its credentials from the environment instead. Some hosted servers, overads' included, accept an API key in a request header.
MCP does not make an API unnecessary. A scheduled report, a dashboard or a sync between two systems still runs best on the API directly, because none of those needs a model to decide what to call.
How the MCP specification changed from 2024 to 2026
The MCP specification has had five revisions, each named for the date of its last backwards-incompatible change, according to the versioning page. The current revision is 2026-07-28. This table is assembled from the changelog published with each revision.
| Revision | Main changes | Source |
|---|---|---|
| 2024-11-05 | The first published revision. Anthropic announced MCP on November 25, 2024, with local servers in Claude Desktop. | Anthropic launch post |
| 2025-03-26 | An authorization framework based on OAuth 2.1; Streamable HTTP replaces the older HTTP plus SSE transport; tool annotations, such as read-only or destructive; JSON-RPC batching added. | 2025-03-26 changelog |
| 2025-06-18 | Batching removed; structured tool output; servers treated as OAuth resource servers; elicitation, so a server can ask the user for information; an MCP-Protocol-Version header on HTTP requests. | 2025-06-18 changelog |
| 2025-11-25 | OpenID Connect discovery for authorization servers; icons for tools and prompts; URL-mode elicitation; Client ID Metadata Documents for registering clients; experimental tasks for long-running work. | 2025-11-25 changelog |
| 2026-07-28 (current) | Stateless: no initialize handshake and no protocol-level sessions; a required server/discover method; tasks moved to an extension; Roots, Sampling and Logging deprecated. | 2026-07-28 changelog |
The 2026-07-28 revision is the largest change for anyone running or choosing a hosted server. Its changelog removes the session header, Mcp-Session-Id, from Streamable HTTP, and every request now carries its own protocol version and client capabilities. A server that needs to remember something between calls must hand the client an explicit handle, passed as an ordinary tool argument.
Older servers keep working with clients that choose to support them. The versioning page lets a server support both the handshake-based revisions and the stateless one, and it describes how a client can detect an older server on either transport and fall back. The same revision adopted a deprecation policy: a deprecated feature stays in the specification for at least twelve months before it can be removed, apart from an expedited exception.
The practical question for a buyer is which revision a server speaks, and whether the AI app in use still supports it. Both answers can change after a release, so check them on the day.
Which AI apps can connect to an MCP server
AI assistants including Claude and ChatGPT, and development tools including Visual Studio Code, Cursor and MCPJam, support MCP, according to the MCP project's introduction. When Anthropic donated the protocol in December 2025, it listed ChatGPT, Cursor, Gemini, Microsoft Copilot and Visual Studio Code among the products that had adopted it. The same post counted more than 10,000 active public MCP servers and over 75 connectors in Claude's directory at that date.
Support is not uniform: apps differ in which transports they connect to and in how a key is supplied. overads, for example, documents a separate setup for Claude Desktop, which reaches a hosted server through the mcp-remote package, and for Claude Code, Cursor, VS Code, Codex, Windsurf, n8n and Zapier. Check an app's own MCP documentation before planning around it.
What an MCP server can do for a marketing team
An MCP server lets a marketing team ask an AI assistant to work inside its tools in plain language, instead of copying data into a chat. What the assistant can do is limited to the tools the server offers and the permissions its key carries. Typical jobs:
- Answer questions from live data, such as last week's ad spend by account, without an export.
- Draft posts for several networks from one brief, saved as drafts for a person to check.
- Schedule approved posts, or queue them for a teammate's sign-off.
- Upload images or video for those posts.
- Start an automation, such as a weekly report, and read back what it did.
- Check a tracked competitor page for recent pricing or copy changes.
The work an MCP server does not remove is judgement. A model picks tools from their descriptions, and it can pick the wrong one or pass the wrong argument, so the jobs that publish or spend belong behind an approval step.
Is it safe to connect an MCP server to your accounts
Connecting an MCP server is as safe as the permissions it is given and the checks kept around it. The MCP specification says tools represent arbitrary code execution, and that hosts must get the user's explicit consent before invoking any tool. The tools page adds that there should always be a human in the loop who can deny a tool call, and that a tool's self-description, such as a read-only label, must be treated as untrusted unless the server is trusted.
The project's security best practices name attacks that server builders must guard against, including the confused deputy problem and token passthrough, where a server accepts a token issued for another service and forwards it. A buyer cannot audit that code, so the controls on the buyer's side matter most:
- Use the product vendor's own server, or an open-source one you have read. A third-party server holds your credentials.
- Give the server a key or sign-in scoped to what the job needs, and to one workspace or account.
- Start with read-only tools. Add write tools once the setup has run as expected for a while.
- Keep the AI app's confirmation prompt on for tool calls that write.
- Keep an approval step in the product itself for anything that publishes or spends money, so a wrong tool call ends as a draft.
- Treat the key like a password. The setup for many AI apps puts it in plain text in a settings file, so set an expiry where the product allows one, and revoke the key when you stop using the server.
A real example: the overads MCP server
The overads MCP server is a hosted server on Streamable HTTP that offers tools only, not resources or prompts. A client connects with a workspace API key sent as a bearer token, and the server is included on paid overads plans. The overads backend on September 30, 2026 defines 24 tools, and speaks MCP revision 2025-06-18, which opens with the initialize handshake and a session that expires after 30 minutes idle.
| Group | Read-only tools | Write tools |
|---|---|---|
| Publishing | list_connections, list_posts, get_post, get_best_times, post_stats, profile_stats | create_post, update_post, delete_post, get_upload_url, complete_media, delete_media |
| Workflows and the Gloofy assistant | list_workflows, get_workflow_run, ask_gloofy | run_workflow |
| Analytics | list_ad_accounts, get_metrics_summary, list_daily_metrics, list_crawled_sites, list_crawled_pages, get_page_timeline, list_page_changes, list_instagram_profiles | None |
That is 17 read-only tools and 7 write tools. One of the analytics tools, list_instagram_profiles, is listed only on a deployment that enables platform-derived data sources. The ad tools only read: none of them can change a campaign.
The key decides what an assistant sees. Each overads key carries scopes chosen when it is created, and the authentication docs list eight. On the MCP server the same scopes filter tools/list, so a tool outside the key's scopes is neither listed nor callable. A key with only connections:read, posts:read and analytics:read gives an assistant a read-only view.
The MCP tools reference records three behaviours that show how a server can protect the team using it:
- Approval holds. When a post needs approval,
create_poststill succeeds, but the post waits as pending with anAPPROVAL_REQUIREDwarning until a member approves it in the app. An assistant can also setrequireApprovalto queue any post, as the scheduling and approvals guide describes. - Missing is not zero. An analytics counter that was not measured comes back as null, with a provenance note the model is told to read before drawing a conclusion.
- Retries are safe. Every write tool accepts an idempotency key, and a retry with the same key and arguments returns the first result instead of creating a second post.
On September 30, 2026, an initialize request sent to the production endpoint without a key was refused with HTTP 401, and the public setup document, which holds the client snippets, answered normally.
Where overads fits
overads fits a team that wants an AI assistant to draft, schedule and report across its social publishing and ad accounts, with approvals kept in the product. It does not fit every MCP use, and it has limits worth knowing before you connect it:
- Posts publish to X, LinkedIn, Bluesky, Mastodon and Pinterest through overads Publish. Instagram and Facebook are built but await Meta's approval, so an assistant cannot publish there through overads today.
- overads Ads manager reads Meta, Google and Snapchat ad accounts read-only, and so do the MCP ad tools. Changes are proposed, and a person applies them in each platform's own ads manager.
- The server speaks MCP revision 2025-06-18, not the stateless 2026-07-28 revision, and connects with an API key pasted into the AI app's settings rather than through an OAuth sign-in screen.
- The MCP server and API keys are included on paid plans only.
overads Workflows start out asking for approval before anything goes out, and an assistant can run them over MCP with the workflows:run scope. For a server that edits live ad campaigns, or for local jobs such as reading files on your own computer, another MCP server fits better than overads.
For more on using one assistant with overads, the guide to Claude Opus 5.5 for marketers walks through connecting Claude and what it can and cannot do in a workspace.
Frequently asked questions
Do I need to write code to use an MCP server?
No. Using a server usually means pasting a URL or a short configuration snippet into the AI app and adding a key. Building a new server takes code, and the MCP project publishes official SDKs for that.
Does an MCP server cost money?
The protocol itself is open source and free to use. A company that runs a server may charge for access to its product, and the AI assistant's own usage is billed by that assistant's provider.
Is a Claude connector the same thing as an MCP server?
Largely, yes. Anthropic describes the connectors in Claude's directory as powered by MCP, so adding one connects Claude to an MCP server that someone has listed there.
Can an MCP server read everything in my AI chat?
No. The MCP specification says the host app must get your consent before it exposes your data to a server. A server receives the arguments of the tool calls sent to it, plus whatever its own credentials let it reach.
Sources
- Specification, version 2026-07-28. Model Context Protocol. Accessed Sep 30, 2026.
- Key Changes (2026-07-28). Model Context Protocol. Accessed Sep 30, 2026.
- Versioning and Compatibility. Model Context Protocol. Accessed Sep 30, 2026.
- Tools. Model Context Protocol. Accessed Sep 30, 2026.
- Authorization. Model Context Protocol. Accessed Sep 30, 2026.
- Transports overview. Model Context Protocol. Accessed Sep 30, 2026.
- What is the Model Context Protocol (MCP)?. Model Context Protocol. Accessed Sep 30, 2026.
- Understanding MCP servers. Model Context Protocol. Accessed Sep 30, 2026.
- Security Best Practices. Model Context Protocol. Accessed Sep 30, 2026.
- Key Changes (2025-03-26). Model Context Protocol. Accessed Sep 30, 2026.
- Key Changes (2025-06-18). Model Context Protocol. Accessed Sep 30, 2026.
- Key Changes (2025-11-25). Model Context Protocol. Accessed Sep 30, 2026.
- Introducing the Model Context Protocol. Anthropic, Nov 25, 2024. Accessed Sep 30, 2026.
- Donating the Model Context Protocol and establishing the Agentic AI Foundation. Anthropic, Dec 9, 2025. Accessed Sep 30, 2026.
- Linux Foundation Announces the Formation of the Agentic AI Foundation (AAIF), Anchored by New Project Contributions Including Model Context Protocol (MCP), goose and AGENTS.md. The Linux Foundation, Dec 9, 2025. Accessed Sep 30, 2026.
- MCP server. overads. Accessed Sep 30, 2026.
- MCP tools. overads. Accessed Sep 30, 2026.
- Authentication. overads. Accessed Sep 30, 2026.
Drafted with AI assistance, then checked against primary sources and the product itself by the overads team.
Keep reading
Claude Opus 5.5 for marketers: what changed, what it costs, which jobs it suits
Anthropic priced Opus 5.5 20% below Opus 5 per token and says it works at Fable 5.1's level. What changed for people who run ads, posts and reports, how it compares with GPT-6, and what Claude can and cannot do in overads.
12 min readGPT-6 Sol and Luna for marketers: what they change
OpenAI's two new GPT-6 models cost half or less of GPT-5.6's promotional API prices. Here is what that means for people who run ads, posts and reports, which model fits which job, and how to use them with the channels you already publish to.
7 min readThe best cross-platform ad management tool in 2026, ranked honestly
Seven tools and one editorial opinion: the category has fractured. Here is what is actually worth paying for if you run paid media across more than two channels in 2026.
8 min readGive your AI assistant a scoped key to your publishing
The overads MCP server lets Claude, Cursor, Codex and other MCP clients draft and schedule posts for X, LinkedIn, Bluesky, Mastodon and Pinterest, and read ad metrics read-only. It is included on paid plans.
Start free
