If you have read anything about AI agents in the last year, you have run into the letters MCP. It gets described as "USB-C for AI", which is catchy and almost useless — it tells you there is a connector without telling you what it does for you. So here is the plain version, and more importantly, what it changes for anyone who owns a website rather than builds protocols for a living.
MCP is the reason an assistant can read your content model, check your search rankings and commit a template change in one conversation — instead of being a clever text box that can only describe what someone else should go and do.
What MCP actually is
The Model Context Protocol is an open standard for how an AI application talks to the outside world. Anthropic released it in November 2024 and handed it to a wider community of maintainers; it is now the default way agents reach tools and data, with backing from AWS, Google, Microsoft and Cloudflare among others.
The model itself can only produce text. Everything else — reading a document, writing a field, triggering a deploy — has to be done by software the model is allowed to call. MCP standardises that boundary. A service publishes an MCP server describing the operations it offers; an AI application acts as an MCP client and calls them. Three kinds of things cross that line: tools the agent can invoke, resources it can read, and prompts the server suggests.
The important word is standard. Before it, every pairing of assistant and platform was its own bespoke integration — your CMS, your repo, your analytics, each wired up by hand and each breaking on its own schedule. That is an N-times-M problem, and it is why early AI tools were stuck inside whichever product shipped them.
Why the standard mattered more than the technology
There is nothing exotic in MCP. It is JSON-RPC over HTTP with a schema for describing capabilities — deliberately boring engineering. Its value is entirely in being agreed upon. Once your CMS, your repository host and your analytics provider all describe themselves the same way, an agent that learns the pattern once can work across all of them, and a tool you adopt next year is reachable without anybody rebuilding anything.
That is also why adoption moved so fast. By mid-2026 there were well over ten thousand public MCP servers and the official SDKs were seeing hundreds of millions of downloads a month. Honeycomb reported that nearly 20% of their monthly interactive queries now come from agents rather than people — a good illustration of how quickly "the software uses the software" stopped being hypothetical.
The 2026 spec: the protocol grew up
On 28 July 2026 the maintainers shipped the 2026-07-28 specification, which they describe as the largest revision in the protocol's history. The headline change is that MCP became stateless: the old initialise handshake and session header are gone, and every request now carries its own protocol version, client identity and capabilities.
That sounds like a detail for infrastructure engineers, and mostly it is — but it is the kind of detail that decides whether something is a demo or a dependency. Alongside it came:
Any request landing on any instance behind an ordinary load balancer, with no shared session storage to operate.
Method and tool names travelling in HTTP headers, so gateways can route, meter and authorise without parsing request bodies.
Multi Round-Trip Requests, which let a tool pause mid-call to ask the user for a confirmation or a missing value — approvals, without holding a connection open.
Cacheable tool and resource listings, so an agent is not re-fetching the same catalogue on every reconnect.
Tighter authorisation, including RFC 9207 issuer validation and a shift away from dynamic client registration toward client metadata documents.
A formal deprecation policy with a twelve-month minimum window, so upgrades can be planned rather than reacted to.
Security moved from forum argument to formal policy in the same period: in June 2026 the NSA and CISA jointly published security design guidance for MCP. When national cyber agencies write up your integration standard, it has stopped being a side project.
What it means if you just want your website to work
Here is the part worth caring about. An assistant that can only write prose into a field leaves you holding every other step — the pasting, the cropping, the publishing, the checking. An assistant connected over MCP can hold the whole job: read the schema, create a valid entry, source and compress the image, commit the template change, verify the build, then check whether Google has indexed the result.
Two consequences follow, and they pull in opposite directions.
The good one is that the thing which measures your site can also be the thing that fixes it. A report ending in "forty pages have no meta description" can end instead in forty drafted meta descriptions waiting for your approval, in the same conversation. No ticket, no handover, no queue.
The sobering one is that capability and risk arrive together. The same connection that lets an agent fix forty pages lets it break forty pages. MCP is a transport standard — it defines how a tool is described and called, not who is allowed to call it or what happens when they get it wrong. That part is your platform's job, and it is the part you should interrogate.
Where MCP stops and judgement starts
A connection is not a permission model. When you evaluate anything agentic, the questions that matter sit above the protocol: does a token scope to environments, paths and document types, or does it hold the keys to everything? Does work land as a draft with publishing as a separate, separately permissioned step? Can you see the change on a real URL before your customers do? Is there an append-only log naming who asked, what changed field by field, and who approved it?
Those four answers decide how expensive a mistake is. The protocol just decides whether the agent can reach your tools at all.
If you want the specifics of how we answer them, there are write-ups on roles, permissions and approvals, on staging and previews, and on the full audit history behind every change. If you would rather not run any of it yourself, you can simply outsource website updates entirely.
Frequently asked questions
What does MCP stand for?
Model Context Protocol. It is an open standard, originally released by Anthropic in November 2024 and now maintained by a wider community, that defines how AI applications connect to external tools and data sources.
Do I need to understand MCP to use an AI assistant on my website?
No. MCP is plumbing — it matters the way HTTP matters to running a shop online. What you should ask about is what the assistant is connected to, what it is permitted to do there, and how you review its work before it goes live.
Is MCP secure?
The protocol has hardened considerably — the 2026-07-28 specification tightened authorisation, and the NSA and CISA published joint security design guidance in June 2026. But MCP defines the connection, not your safety: scoped tokens, draft-by-default writes, previews and an audit trail are what actually protect a live site, and those are properties of the platform you choose.
Does my CMS need an MCP server for this to work?
Not necessarily. Many platforms now publish one, but an assistant can also talk to a CMS through its existing API. MCP makes new integrations cheaper and more consistent; it is not a prerequisite for connecting the stack you already have.
The short version
MCP is the agreement that lets AI agents reach the tools you already use, and the 2026 revision is the point at which it became ordinary production infrastructure rather than a promising experiment. It is worth knowing about not because you will ever configure it, but because it explains why assistants stopped being text boxes and started being teammates — and why the questions worth asking now are about permissions, previews and audit rather than about how clever the model is.
See it work on your own site.
Connect your CMS, invite your team, and ship your first change on staging in two minutes.