Model Context Protocol (MCP)
A stateless JSON-RPC protocol letting an LLM application reach external tools, data and prompts through servers over stdio or HTTP. Interviewers ask it as the standard answer to model integration.
part ofAPI stylesoverview, primer and where to startread it →on this pageshowhide
explore
- Hosts, Clients & Servers14 questions
- Host-Client-Server Topology4 questions
- Elicitation5 questions
- Roots5 questions
- Request Metadata and Discovery16 questions
- Per-Request Metadata5 questions
- Server Discovery5 questions
- Revisions and Era Compatibility6 questions
- Server Primitives17 questions
- Interaction Patterns10 questions
- Multi Round-Trip Requests5 questions
- Subscription Streams5 questions
- Transports17 questions
- Stdio Transport6 questions
- Streamable HTTP Transport5 questions
- Statelessness and Scaling6 questions
- Server-Requested Sampling11 questions
- createMessage Flow6 questions
- Human-in-the-Loop Controls5 questions
- Security Model21 questions
- Consent and Trust Model5 questions
- Tool Poisoning and Shadowing5 questions
- Remote Server Authorization6 questions
- Client Registration and Trust5 questions
- Optional Extensions10 questions
- Opt-In Negotiation4 questions
- Asynchronous Tasks6 questions
questions
116 · 8 sectionsIn MCP, what is elicitation and when does a server use it?
basics
~20 sElicitation is MCP's way for a server to ask the human user for structured input while it is handling a request — a missing parameter, a confirmation, a choice between accounts. The client shows the ask and returns the user's answer.
In MCP, what are the host, the client, and the server, and how do they relate?
basics
~10 sThe host is the AI application the user runs. Inside it, one client per server speaks the protocol. Each server exposes one integration's tools, resources and prompts. Clients never talk to each other.
In MCP, what may an elicitation/create requestedSchema contain?
basics
~20 sMCP restricts an elicitation/create requestedSchema to a single flat object whose properties are primitives only — string, number, integer, boolean, or an enum. No nested objects, no arrays. That keeps the form renderable by any client.
Why are MCP roots advisory rather than an enforced sandbox for a server?
basics
~20 sRoots are data the client sends, not a permission the protocol applies. MCP has no mechanism to intercept a server's file access, so a server keeps every byte its operating-system user can reach whether it honours the roots or ignores them.
In MCP 2026-07-28, why is an open stdio connection to a server not a session?
basics
~20 sRevision 2026-07-28 made MCP stateless: every request is self-contained and carries its own protocol version and capabilities. A connection, including a live stdio process, is only a transport channel, so a server must not build context from earlier requests on it.
What must every MCP request carry in params._meta now that initialize is gone?
basics
~10 sEvery MCP request must put io.modelcontextprotocol/protocolVersion and io.modelcontextprotocol/clientCapabilities inside params._meta. An empty capabilities object is legal, but the key itself is not optional. clientInfo is optional and SHOULD be sent.
In MCP, what does server/discover return, and which side is required to implement it?
basics
~10 sserver/discover returns a DiscoverResult holding supportedVersions, the server's capabilities, optional instructions, and the required cache hints ttlMs and cacheScope, with serverInfo in _meta. Servers MUST implement it; clients MAY call it.
In MCP, what does a protocol version like 2026-07-28 mean, and when is it bumped?
basics
~10 sMCP protocol versions are dates in YYYY-MM-DD form naming the day of the last backwards-incompatible change to the specification. The current revision is 2026-07-28. Backwards-compatible additions do not bump the version.
What do modern, legacy and dual-era mean in MCP, and which combinations interoperate?
basics
~20 sModern means the per-request metadata model of MCP 2026-07-28 and later; legacy means the initialize handshake of 2025-11-25 and earlier; dual-era supports both. Era is a property of the server, and only a dual-era server serves clients of both eras.
In MCP, what is the -32022 UnsupportedProtocolVersionError and how should a client react?
basics
~20 sUnsupportedProtocolVersionError, JSON-RPC code -32022, is how an MCP server rejects one request whose declared protocol version it will not serve. Its data carries supported and requested, so the client retries with a listed version rather than disconnecting.
In MCP, what do prompts/list and prompts/get return, and who invokes a prompt?
basics
~20 sprompts/list returns the server's prompt templates with their names, descriptions and declared arguments. prompts/get takes one name plus argument values and returns the filled-in, role-tagged messages. Prompts are user-controlled: a person picks one, the model does not.
In MCP, what do resources/list and resources/read return, and how is a resource identified?
basics
~20 sA resource is identified by its URI. resources/list returns descriptors — uri, name, optional description and mimeType — while resources/read takes one uri and returns a contents array carrying the data itself. Both results carry the required resultType field in MCP 2026-07-28.
In MCP, what is a tool's inputSchema and how is it used by client and server?
basics
~20 sinputSchema is the JSON Schema object in a tool's tools/list entry that describes the arguments the tool accepts. The host uses it to shape and check the arguments object sent in tools/call, and the server validates against it again.
How does an MCP prompt declare its arguments, and what does required mean?
basics
~20 sEach entry in a prompt's arguments array is a PromptArgument with a name, an optional title and description, and an optional required boolean. Callers pass values as a flat name-to-string map on prompts/get; omitting a required argument earns a -32602 invalid-params error.
In MCP, when does a tools/call use isError instead of a JSON-RPC error?
basics
~20 sFailures of the tool's own work — an upstream 500, a missing file, a rejected input value — come back as a successful result with isError set to true, so the model can read them. Protocol-level failures such as an unknown tool or invalid params are JSON-RPC error objects.
In MCP 2026-07-28, what replaced server-initiated requests back to the client?
basics
~20 sMulti Round-Trip Requests. A server can no longer send its own JSON-RPC request; it answers the client's call with a result whose resultType is "input_required", listing what it needs, and the client re-sends the original call carrying the answers.
How does an MCP client resume a call after an input_required result?
basics
~20 sThe client re-sends the original method and arguments as a brand-new JSON-RPC request with a new id, adding an inputResponses map keyed exactly like the server's inputRequests and echoing the opaque requestState byte for byte.
What does MCP's subscriptions/listen request do, and what can it filter?
basics
~20 ssubscriptions/listen is one long-lived request whose response stream carries server-to-client change notifications. The client names what it wants in a SubscriptionFilter: toolsListChanged, promptsListChanged, resourcesListChanged, and resourceSubscriptions (a list of resource URIs). Nothing is pushed unless the client opted in.
Which MCP methods can return input_required, and what may they ask for?
basics
~20 sOnly tools/call, prompts/get and resources/read may answer with an input_required result. Each entry in its inputRequests map is one of three request types: a sampling createMessage request, a roots list request, or an elicitation request.
What must an MCP server send first on a subscriptions/listen stream?
basics
~20 sThe server MUST send notifications/subscriptions/acknowledged before any change notification. It confirms the stream is live and the filter accepted. Every notification the server then sends on that stream carries io.modelcontextprotocol/subscriptionId in its _meta so the client can tell its streams apart.
In MCP's stdio transport, how are JSON-RPC messages framed on stdin and stdout?
basics
~10 sMCP stdio framing is newline-delimited JSON: each JSON-RPC message is one line of UTF-8 text ending in a newline, contains no embedded newlines, and stdout carries nothing except MCP messages.
In MCP's Streamable HTTP transport, what does a client POST and what can a server reply?
basics
~20 sMCP's Streamable HTTP transport exposes a single endpoint that accepts POST only. The client POSTs one JSON-RPC message with an Accept header listing both application/json and text/event-stream, and the server answers with either a JSON body or an SSE stream.
In MCP 2026-07-28, what replaced protocol-level sessions and the Mcp-Session-Id header?
basics
~20 sNothing replaced them. MCP revision 2026-07-28 removed protocol sessions entirely: every request is self-contained and carries its own protocol version and capabilities, so a server must not rely on anything an earlier request on the same connection established.
On MCP stdio, where do the protocol version and client capabilities travel?
basics
~10 sInside the message itself. Stdio has no header layer, so every request carries io.modelcontextprotocol/protocolVersion and io.modelcontextprotocol/clientCapabilities in its params._meta object, on every single call.
What headers must an MCP Streamable HTTP POST carry, and what is HeaderMismatchError?
basics
~10 sAn MCP Streamable HTTP request must carry MCP-Protocol-Version, Mcp-Method, and Mcp-Name for tools/call, resources/read and prompts/get. If MCP-Protocol-Version disagrees with the value in params._meta, the server returns HTTP 400 with JSON-RPC error -32020, HeaderMismatchError.
In MCP, what does sampling/createMessage let a server ask the client to do?
basics
~20 ssampling/createMessage lets an MCP server ask the connecting client to run an LLM completion for it, so the server needs no model credentials of its own. The client picks the model and runs the call. MCP revision 2026-07-28 deprecates the feature.
Which fields does an MCP sampling/createMessage request carry, and which are required?
basics
~10 sOnly messages and maxTokens are required. messages is an array of role-tagged user and assistant content blocks; maxTokens caps the completion. systemPrompt, modelPreferences, stopSequences, temperature and, for tool-enabled sampling, tools and toolChoice are optional.
If a user denies an MCP sampling request, what does the client send back?
basics
~20 sNothing at all. In MCP revision 2026-07-28 a refusal is expressed by simply not retrying the original request. There is no decline message, no error code and no reason string for the server to read.
In MCP sampling, what human review does the spec expect before and after the model call?
basics
~20 sTwo review points. Before the model runs, the client should show the user the prompt the server supplied and let them approve, edit or reject it. After it runs, the user should be able to see and edit the completion before it goes back to the server.
Why is MCP sampling deprecated in revision 2026-07-28, and what should servers do instead?
basics
~20 sRevision 2026-07-28 deprecates sampling and tells servers to integrate directly with an LLM provider API instead. Deprecated features stay in the spec at least twelve months, so the earliest removal is the first revision released on or after 2027-07-28.
In MCP, which component enforces user consent, and why not the protocol itself?
basics
~20 sThe host application enforces consent. MCP is a JSON-RPC wire protocol: it can require fields and reject malformed messages, but it cannot verify that a human approved anything, so the specification states its principles as guidance the host must carry out.
In MCP, what OAuth 2.1 role does a remote server play, and what does it do with a token?
basics
~20 sA remote MCP server is an OAuth 2.1 resource server, never an authorization server. It issues no tokens and runs no login screen: it validates the bearer token presented on every HTTP request and rejects one not issued for itself.
In MCP, why can't a client trust readOnlyHint to decide a tool call is safe?
basics
~20 sToolAnnotations are self-reported labels written by the same server whose behaviour they describe. MCP revision 2026-07-28 requires clients to treat them as untrusted unless the server itself is trusted out of band, so they may shape the UI but never gate a call.
What is a Client ID Metadata Document in MCP's OAuth profile?
basics
~20 sA Client ID Metadata Document lets an MCP client use an HTTPS URL with a path as its client_id. The authorization server dereferences that URL to read the client's metadata — client_name, redirect_uris — with no prior registration.
What are the three key principles of MCP's security model in revision 2026-07-28?
basics
~20 sUser Consent and Control, Data Privacy, and Tool Safety. Revision 2026-07-28 deleted the former fourth principle, LLM Sampling Controls, when Sampling was deprecated. MCP states these principles but cannot enforce any of them at the protocol level.
How do MCP peers declare extension support in the extensions capability map?
basics
~20 sEach side lists supported extensions in the extensions field of its capabilities: a map from a prefixed identifier to a settings object. An empty object means supported with no settings, not unsupported. An extension is live only if both sides list it.
In MCP, what does a server return when a tools/call runs as an asynchronous task?
basics
~20 sThe server answers immediately with a CreateTaskResult: resultType "task" plus a taskId. The work keeps running server-side, and the client polls tasks/get with that taskId until the task reaches a terminal status and yields its result.
In MCP, what must happen when one side does not support a requested extension?
basics
~20 sThe extension simply does not apply. Under MCP revision 2026-07-28 the other side MUST either revert to core protocol behaviour or reject the request outright. Proceeding as though the extension were in effect is not an option.
In MCP, what is an optional extension, and which ones are official?
basics
~10 sAn MCP extension is an optional feature layered on top of the core protocol and used only when both peers declare it. Revision 2026-07-28 names two official ones: io.modelcontextprotocol/tasks (Tasks) and io.modelcontextprotocol/ui (MCP Apps).
In MCP's tasks extension, what task statuses exist and which of them are terminal?
basics
~20 sA task is working, input_required, completed, failed or cancelled. The first two are live states the client keeps polling; completed, failed and cancelled are terminal. Cancellation is cooperative — tasks/cancel requests it, the server decides when the task actually stops.