Learning Hub
Lesson #57 of 70
Agentic AI & RAG7 min readAdvanced
Model Context Protocol (MCP): Building Secure Tool & Resource Servers
Learn the open standard for connecting AI assistants to local databases, file systems, and enterprise APIs using JSON-RPC, tools, resources, and prompts.
Works with:Model Context Protocol (MCP SDK)TypeScript / PythonJSON-RPC 2.0
Key Takeaways
- MCP standardizes how LLM clients discover and invoke external tools, fetch context resources, and execute pre-configured prompt templates
- The protocol runs over JSON-RPC 2.0 via standard input/output (stdio) for local tools or Server-Sent Events (SSE) for remote servers
- MCP separates capabilities into three primitives: Resources (static context/files), Tools (executable actions), and Prompts (reusable templates)
- Security boundaries require strict scoping of file paths, read-only permissions, and human approval prompts for write/delete tools
The Diagnostic Context
Instead of writing bespoke, proprietary tool integrations for every LLM provider, Anthropic open-sourced the Model Context Protocol (MCP)—the universal USB-C standard for AI applications to connect with databases, git repos, and internal systems.
The Core Technique
Building an MCP Server in Python
PYTHON
from mcp.server.fastmcp import FastMCP
import sqlite3
# Initialize MCP Server
mcp = FastMCP("Enterprise Inventory Server")
@mcp.resource("inventory://metrics")
def get_inventory_metrics() -> str:
"""Provides read-only inventory metrics for context grounding."""
return "Total SKUs: 14,200 | Out of stock: 12 | Warehouse load: 88%"
@mcp.tool()
def search_product(sku: str) -> dict:
"""Look up product details and warehouse bin location by SKU."""
# Strict validation prevents SQL injection
if not sku.isalnum() or len(sku) > 12:
return {"error": "Invalid SKU format"}
return {
"sku": sku,
"name": "Industrial Sensor Model X",
"quantity_available": 450,
"warehouse_bin": "Zone-B-14",
"unit_price_usd": 129.99
}
if __name__ == "__main__":
mcp.run(transport="stdio")
Transport Protocols: Stdio vs SSE
- Stdio (Standard I/O): Ideal for local development environments, desktop agents (e.g. IDE extensions), and containerized CLI tools.
- SSE (Server-Sent Events) over HTTP: Required for centralized enterprise microservices, multi-tenant agent platforms, and cloud deployments.
5-Minute Activation Challenge
Try This Right Now
Write a simple FastMCP tool in Python that accepts a database table name and returns column names and row counts in JSON format with strict input sanitization!
Tip: Knowledge only becomes capability once you run the prompt yourself.
Comprehension Check
Test Your Instincts (1 Questions)
1