What is MCP (Model Context Protocol)?
How Claude, ChatGPT and Cursor learn to use your product, and what has to be true before you let them.
In short
The Model Context Protocol (MCP) is an open standard for connecting AI assistants to external tools and data. An application exposes an MCP server, and any assistant that speaks MCP, such as Claude, ChatGPT or Cursor, can discover and call its tools on a user's behalf. Anthropic introduced MCP in November 2024; it uses JSON-RPC 2.0 messages.
Also called: MCP
Why it matters when your prototype goes to production
MCP turns your product into something an AI assistant can use, not only something a person clicks through. Your customers can ask their assistant to create a ticket, update a record or pull a report from your app. That is a feature customers increasingly ask for, and a new way in to their data.
The engineering question is the same as for any integration, with higher stakes: an agent must never be able to do more than the person who connected it, whatever the model decides to try.
What it looks like in practice
Looph's MCP server, live since 29 September 2026, is a separate app with its own OAuth sign-in and consent screen. For every request it mints a sixty-second database token for that person, so their own row-level security decides every row. It offers 28 tools, 12 read and 16 write, logs and attributes every action, and the workspace owner can switch agents off at any time.
Common questions
What is the difference between MCP and an API?
An API is designed for developers who write code against it. MCP is a standard way to describe tools so AI assistants can discover and call them. An MCP server usually sits in front of your API.
Is MCP secure?
The protocol leaves permissions to the server. It is as safe as its authentication, the scopes a user grants, and the checks on every tool call.
Related terms
Read next
Sources
More on this: Production architecture & security · All glossary terms
Built something in Lovable you want people to rely on?
We are the engineers who take it the rest of the way — secured, tested, released and supported.