Glossary
Glossary of MCP and agent-access terms
The 36 terms this directory uses, in plain words: the parts of the Model Context Protocol, how servers are reached and signed in to, what the MCP Registry records, and the files a site can publish for AI systems. Each links to the article or index that goes further.
The protocol
- Model Context Protocol (MCP)
- An open protocol for connecting AI applications to outside tools and data. It defines how an application and a server describe what they can do to each other and exchange requests, so one server works with every application that supports the protocol. It was published by Anthropic in November 2024 and is developed in the open; versions of the specification are named by date, such as 2024-11-05, 2025-03-26 and 2025-06-18. What is an MCP server? →
- MCP server
- A program that offers tools, resources or prompts to AI applications over MCP. It can be remote — run by its publisher and reached at a URL — or local — a program started on the user's own computer. A server usually wraps one service or one kind of data: a booking engine, a map, a code host, a database. MCP Registry servers with a page here →
- MCP client
- The part of an AI application that holds the connection to one MCP server. An application connected to three servers runs three clients, each talking to its own server. How to add a server to an assistant →
- MCP host
- The AI application the user works in — a chat assistant, a desktop app, a code editor, a command-line agent. The host starts the clients, decides which servers they connect to, passes what the servers offer to the language model and asks the user for consent before actions.
- Tool
- A function a server offers for the model to call: it has a name, a description that tells the model when to use it, and a JSON Schema for its input. Search flights, get a departure board and create an issue are tools. The model decides when to call one; hosts usually ask the user to approve a call that changes something.
- Resource
- Data a server makes available to read, each identified by a URI: a file, a database record, a document. The application, not the model, generally decides which resources to read into the conversation.
- Prompt
- A reusable message template a server offers, often with arguments, which the user picks in the application — for example as a slash command — to start a task in a way the server's author has prepared.
- Sampling
- A request from a server to the client to have the application's language model generate text, so a server can use a model without holding its own API key. The host keeps control and can show the request to the user.
- Elicitation
- A request from a server, through the client, for more information from the user — a missing date, a confirmation — answered in a form the application shows. Added in the 2025-06-18 revision of the specification.
- JSON-RPC 2.0
- The message format MCP uses: every request, response and notification is a small JSON object. A connection starts with an initialize exchange in which client and server agree on the protocol version and state the capabilities each supports.
Transports and sign-in
- Transport
- How MCP messages travel between client and server. The specification defines stdio for local servers and Streamable HTTP for remote ones; the earlier HTTP with Server-Sent Events transport is still met. A server's registry entry states which transports it supports. Servers by transport →
- stdio
- The local transport: the client starts the server as a program on the same computer and exchanges messages through its standard input and output, one JSON message per line. Nothing listens on the network, and the program runs with the user's own permissions. Local servers over stdio →
- Streamable HTTP
- The current transport for remote servers, introduced in the 2025-03-26 revision: one HTTPS endpoint that the client sends messages to with POST, and that answers with a single JSON response or a stream of Server-Sent Events. A server can keep a session, named in an Mcp-Session-Id header. Remote servers over Streamable HTTP →
- SSE (HTTP + Server-Sent Events)
- The remote transport of the first revision (2024-11-05): the client keeps a Server-Sent Events stream open to receive messages and posts its own to a second URL the server names. Streamable HTTP replaced it in 2025-03-26; many clients still accept it. MCP transports explained →
- Remote server
- An MCP server run by its publisher and reached at an HTTPS URL. Nothing is installed; the publisher runs and updates it, and what you ask passes through its systems. Remote or local? →
- Local server
- An MCP server installed from a package and started on the user's own computer, usually over stdio. It can reach local files and applications, and its keys stay in the client's configuration. Remote or local? →
- OAuth for MCP (MCP authorization)
- How a remote server asks a user to sign in. The authorization part of the specification, first added in 2025-03-26, builds on OAuth 2.1: the client sends the user to the service's own sign-in page, receives an access token and sends it with each request. Since 2025-06-18 an MCP server is treated as an OAuth resource server that publishes metadata naming its authorization server (RFC 9728). It applies to HTTP transports; a local stdio server takes its credentials from environment variables instead. Before you connect a server →
- Declared headers
- HTTP headers a remote server's registry entry says a client must send, such as Authorization with an API key. The entry marks each as required or optional, and as secret or not.
- Environment variables
- Named values, often API keys, that a local server reads when the client starts it. The registry entry lists the ones its package expects; the client's configuration sets them.
The MCP Registry
- MCP Registry
- The official public catalogue of MCP servers at registry.modelcontextprotocol.io, run by the MCP project and launched in preview in September 2025. It holds metadata only — names, descriptions, versions, endpoints and packages — with an open read-only API, and expects catalogues built on it, such as this directory, to add their own curation. What is the official MCP Registry? →
- Namespace
- The part of a registry name before the slash, in reverse-DNS form. io.github.<account> is granted to whoever signs in as that GitHub user or as a member of that organisation; a reversed domain such as com.example to whoever proves control of example.com by a DNS record or a file served over HTTP. It shows who published an entry, not that the entry is endorsed by the product it works with. Servers by publisher →
- server.json
- The file a publisher submits to the registry describing a server: its name, description, version, optional title, website and repository, and how to reach it — remotes and packages.
- Package types
- The package registries a local server can be published to, named in its registry entry: npm (Node.js), PyPI (Python), OCI images (Docker and other container registries), NuGet (.NET), Cargo (Rust crates) and MCP Bundles. The type tells the client which runtime it needs. Servers by package registry →
- npm package
- A Node.js package from the npm registry. Clients usually start it with npx, which downloads it on first use; Node.js must be installed. npm servers →
- PyPI package
- A Python package from PyPI. Clients usually start it with uvx, from the uv tool, which runs it in an isolated environment, or after installing it with pip. PyPI servers →
- OCI image
- A container image in an OCI registry such as Docker Hub or GitHub Container Registry, started with docker run. The server runs inside the container rather than directly on the computer. Container-image servers →
- MCP Bundle (.mcpb)
- A single archive holding a local MCP server and a manifest.json that describes it, so a client that supports bundles can install it in one step. The format was formerly called Desktop Extensions (.dxt). MCP Bundle servers →
- Version and status
- Each publish to the registry adds a version that does not change afterwards; the newest is marked latest. An entry's status is active, deprecated or deleted. This directory reads the latest version and leaves out deprecated and deleted entries.
Files and descriptions on a service's own site
- llms.txt
- A Markdown file at a site's root, /llms.txt, proposed in September 2024 at llmstxt.org, that tells language models what the site is and links its most useful pages, each with a short note. It grants and refuses nothing; it is a map. This directory counts it as present only when the site answers with a real text file, not an HTML page. What goes in an llms.txt file →
- OpenAPI
- A standard, machine-readable format for describing an HTTP API — its endpoints, parameters, responses and authentication — in JSON or YAML, formerly known as Swagger. Agent frameworks can turn its operations into tools. OpenAPI for AI agents →
- ai-plugin.json
- A manifest at /.well-known/ai-plugin.json introduced in 2023 for ChatGPT plugins: it names the service, describes it for the model and points to an OpenAPI description. The plugin system has since been retired, but some sites still serve the file. OpenAPI for AI agents →
- /.well-known/mcp.json
- A file some sites serve to describe their MCP server — its endpoint, transport and sign-in — so clients and catalogues can find it from the domain alone. It is not part of a published revision of the specification, and the files met in practice differ in shape; this directory records whether a site answers with a JSON object there.
- agents.json
- A proposed JSON file, served at /agents.json, that describes an API's operations and the multi-step flows an agent can carry out with them, building on OpenAPI. Few sites publish one; this directory records whether a site answers with a JSON object there.
- ChatGPT app
- An app a service publishes inside ChatGPT. Apps are built with OpenAI's Apps SDK, which is based on MCP, and can show interactive results in the chat; the user connects an app before ChatGPT can call it. Services with a ChatGPT app →
- Claude connector
- A remote MCP server added to Claude, from Anthropic's directory of connectors or by URL, so Claude can read from or act in that service once the user connects it. Services with a Claude connector →
- Public API
- A documented API that anyone can sign up to call, usually with a key from the service. It is how custom-built agents reach a service that has no MCP server. Services with a public API →
Further reading
All Learn articles · MCP Registry servers · Publishers · Editorial policy