jnachi
Learning Hub
Agentic AI & RAG7 min readAdvanced

Model Context Protocol (MCP): Building Secure Tool & Resource Servers

Learn the open standard for connecting AI assistants to local databases, file systems, and enterprise APIs using JSON-RPC, tools, resources, and prompts.

Works with:Model Context Protocol (MCP SDK)TypeScript / PythonJSON-RPC 2.0

Key Takeaways

  • MCP standardizes how LLM clients discover and invoke external tools, fetch context resources, and execute pre-configured prompt templates
  • The protocol runs over JSON-RPC 2.0 via standard input/output (stdio) for local tools or Server-Sent Events (SSE) for remote servers
  • MCP separates capabilities into three primitives: Resources (static context/files), Tools (executable actions), and Prompts (reusable templates)
  • Security boundaries require strict scoping of file paths, read-only permissions, and human approval prompts for write/delete tools

The Diagnostic Context

Instead of writing bespoke, proprietary tool integrations for every LLM provider, Anthropic open-sourced the Model Context Protocol (MCP)—the universal USB-C standard for AI applications to connect with databases, git repos, and internal systems.

The Core Technique

Building an MCP Server in Python

PYTHON
from mcp.server.fastmcp import FastMCP
import sqlite3

# Initialize MCP Server
mcp = FastMCP("Enterprise Inventory Server")

@mcp.resource("inventory://metrics")
def get_inventory_metrics() -> str:
    """Provides read-only inventory metrics for context grounding."""
    return "Total SKUs: 14,200 | Out of stock: 12 | Warehouse load: 88%"

@mcp.tool()
def search_product(sku: str) -> dict:
    """Look up product details and warehouse bin location by SKU."""
    # Strict validation prevents SQL injection
    if not sku.isalnum() or len(sku) > 12:
        return {"error": "Invalid SKU format"}
        
    return {
        "sku": sku,
        "name": "Industrial Sensor Model X",
        "quantity_available": 450,
        "warehouse_bin": "Zone-B-14",
        "unit_price_usd": 129.99
    }

if __name__ == "__main__":
    mcp.run(transport="stdio")

Transport Protocols: Stdio vs SSE

  • Stdio (Standard I/O): Ideal for local development environments, desktop agents (e.g. IDE extensions), and containerized CLI tools.
  • SSE (Server-Sent Events) over HTTP: Required for centralized enterprise microservices, multi-tenant agent platforms, and cloud deployments.
5-Minute Activation Challenge

Try This Right Now

Write a simple FastMCP tool in Python that accepts a database table name and returns column names and row counts in JSON format with strict input sanitization!

Tip: Knowledge only becomes capability once you run the prompt yourself.

Comprehension Check

Test Your Instincts (1 Questions)

1

Which protocol message standard does the Model Context Protocol (MCP) utilize for client-server communication?