Workshop Studio
participantPublic visitor

MCP

The first three systems — agents, skills, and hooks — all operate within Claude Code's local environment. MCP (Model Context Protocol) is the bridge to the outside world. It is a standardized protocol that lets Claude interact with external services — Jira, Slack, GitHub, databases, CI/CD systems, custom internal APIs — through a consistent tool interface.

Think of MCP as USB-C for AI tools. Before USB-C, every device had its own connector. Before MCP, every AI-tool integration required custom code. MCP provides a standard interface: any service that implements the MCP protocol becomes a tool Claude can discover and use automatically.

MCP servers are configured at three scopes, each with different visibility and security implications:

IconScopeDescription
📁Local (default)Stored in .claude/. Personal to you and this project. This is the default when you run claude mcp add. Not committed to git.
📦Project: .mcp.jsonAt project root. Committed to git. Every team member gets the same MCP servers. The primary method for team-shared configuration.
👤User (cross-project)In your home directory. Personal MCP servers that apply across all your projects. Useful for personal tools like calendar or notes.

.mcp.json at project root

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
{
  "mcpServers": {
    "github": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-github"],
      "env": {
        "GITHUB_TOKEN": "${GITHUB_TOKEN}"
      }
    },
    "postgres": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-postgres"],
      "env": {
        "DATABASE_URL": "${DATABASE_URL}"
      }
    },
    "jira": {
      "url": "https://jira.yourcompany.com/mcp",
      "headers": {
        "Authorization": "Bearer ${JIRA_TOKEN}"
      }
    }
  }
}

Notice the ${VARIABLE} syntax. The .mcp.json file is committed to git, but secrets like GITHUB_TOKEN and DATABASE_URL are resolved from your shell environment at runtime — they come from your .bashrc, .zshrc, .env files loaded by your shell, or whatever mechanism your system uses to set environment variables. This keeps the configuration shareable without exposing credentials. You can also add MCP servers quickly with the CLI: claude mcp add github --command npx -- -y @modelcontextprotocol/server-github.

An MCP server exposes three types of capabilities to Claude:

IconCapabilityDescription
🔧ToolsFunctions Claude can call. Example: create_issue, query_database, post_message. These appear as available tools in Claude's tool palette.
📄ResourcesData Claude can read via @ mentions. Example: project README, database schema, API documentation. Claude can browse and reference resources in conversation.
💬PromptsPre-built prompt templates that appear as slash commands. Example: "Summarize this PR", "Generate migration SQL". MCP prompts integrate with Claude's /command system.

When Claude connects to a GitHub MCP server, it discovers tools like create_issue, list_pull_requests, and read_file_contents. Claude can then use these tools naturally in conversation — "Create a GitHub issue for this bug" triggers the MCP tool, not a bash command.

The MCP ecosystem has evolved with several powerful features beyond basic tool serving:

  • OAuth 2.0 authentication — MCP servers can authenticate via OAuth flows, supporting enterprise SSO and token refresh without manual credential management.
  • MCP Tool Search — when a project has many MCP tools (more than 10% of context), Claude dynamically searches for relevant tools on-demand rather than loading them all upfront. This prevents tool overload.
  • Resource browsing — use @ mentions to browse and reference MCP resources directly in conversation. Claude can pull in database schemas, API docs, or config files from MCP servers as needed.
  • Claude as MCP server — claude mcp serve exposes Claude Code itself as an MCP server that other tools can connect to.
  • Managed MCP (managed-mcp.json) — enterprise admins can define allowlists and denylists for MCP servers that developers cannot override.

MCP servers run outside Claude Code's sandbox. This is both their power and their risk:

  • MCP servers execute with your local user permissions — they can access your file system, network, and credentials
  • Always vet MCP servers before adding them to .mcp.json, especially stdio servers that run as local processes
  • Use environment variables for credentials — never hardcode tokens in .mcp.json
  • Enterprise teams should audit and allowlist approved MCP servers via managed-mcp.json
  • MCP server outputs are injected into Claude's context — a compromised server could attempt prompt injection
Treat third-party MCP servers like third-party npm packages

MCP is an open ecosystem. Anyone can publish an MCP server. Treat third-party MCP servers with the same caution you would treat third-party npm packages — review the source, check the publisher, and understand what permissions it requires.