MCP server

Definition
An MCP server is a small service that exposes a tool, a dataset or an action to an AI model through one consistent interface.

Why it matters

Without a server, an assistant works from what is in the conversation. Ask it how many hours a project used and it can only guess. With a server connected to the time-tracking data, it queries the real figure. That moves an assistant from giving advice to checking facts and doing work.

A server is also where access is controlled. It decides which actions exist, which records are visible and whether the connection can write. A badly scoped server is the same as handing out a master key.

How to apply it

  • Expose the smallest set of actions the job needs, not everything the system's API allows.
  • Begin read-only. Write actions come later, behind approval.
  • Use a dedicated account or token with limited rights, never an owner login.
  • Install servers only from sources you trust. A server runs code and sees whatever the assistant sends it.
  • Remove servers nobody uses. Each one is one more thing to keep secure.

What it is

An MCP server sits between an AI assistant and one system. On one side it speaks the Model Context Protocol. On the other it talks to the real thing: a database, a project tracker, a billing tool, a folder of documents. It tells the assistant what it can do, such as "list overdue invoices" or "create a task", and carries out the call when the assistant asks.

Servers come in two kinds. A local server runs on the user's own computer and starts when the assistant does. A remote server runs on the internet, usually run by the tool's vendor, and the user signs in to approve access. Local ones suit files and personal tools. Remote ones suit shared business systems.

Common mistakes

  • Mirroring the whole API. Expose the few actions the job needs, not everything the system allows.
  • Giving the server an admin token. If the server is compromised or the assistant is misled, the token decides how much damage is done.
  • Skipping the source check. A server from an unknown author runs code on your machine or sees your data.
  • Leaving unused servers connected. Each one is one more thing to keep secure and up to date.
  • Putting write actions and read actions together. Keep them apart, so approval can be required for writes only.
Worked example

Suppose a Dutch consultancy wants its assistant to answer which invoices are overdue, and for whom, without guessing. The team builds a small MCP server in front of its Moneybird account. The server offers three actions: list overdue invoices, look up one customer's open items and draft a reminder. It does not expose everything the accounting interface allows. It runs under a dedicated user with limited rights, not the owner's login. The first version is read-only. For two weeks the assistant's list matches the Moneybird screen every time, so the team adds the reminder draft. Sending stays a human action, and anything outside the three actions is simply not reachable from the assistant.

Tools in the example

Some links are affiliate links: we may earn a commission at no cost to you. It never decides a ranking. How we work with partners

  1. Article

    MCP (Model Context Protocol)

    The standard a server implements.

  2. Article

    Tool use

    What an assistant does when it calls a server.

  3. Article

    Function calling

    The model feature that lets it request a specific action.

  4. Article

    Webhook

    The opposite direction, where a system pushes events out.