What is an MCP server?
The piece you build if you want AI assistants to use your product. Here is what goes in it.
In short
An MCP server is the part of an application that speaks the Model Context Protocol: it describes what AI assistants may do in the app and carries out their requests. It offers three building blocks: tools the assistant can call, resources it can read for context, and prompts a user can pick.
Also called: Model Context Protocol server
Why it matters when your prototype goes to production
An MCP server is a new front door to your data, used by software that follows instructions from text it reads. It needs everything any public API needs, and a little more, because the caller is an AI model acting on a person's behalf.
What a production MCP server needs
- Proper sign-in and consent, usually OAuth, so a person chooses what the agent may do.
- Every call checked against that person's own permissions, never broader ones.
- Rate and spending limits on tools that write or cost money.
- An audit log that attributes every action to the agent and the person behind it.
- A way for the owner to switch agents off.
Inkwave's AI-assistant server never takes a publication from the request: the credential decides it, with consent and a budget on every write. Looph's runs every call under the connecting person's own row-level security.
Common questions
Do I need an MCP server?
If your customers use AI assistants and would benefit from acting in your product through them, it is worth planning. Build it on top of the permissions you already enforce.
Is an MCP server an AI agent?
No. The agent is the assistant calling it. The MCP server is your side: it defines the tools and enforces the rules.
Related terms
Read next
Sources
More on this: Production architecture & security · All glossary terms
Built something in Lovable you want people to rely on?
We are the engineers who take it the rest of the way — secured, tested, released and supported.