MCP vs Custom REST Tooling: Security and the Latest MCP Architecture
A simple guide to understand how MCP works, what has changed in the latest architecture, and how to build more secure AI agent systems. AI agents are becoming more useful because they can do more than just generate text. They can access databases, call APIs, read files, work with GitHub, and perform other actions through external tools. For a small project, connecting an AI application to one or…
Title: MCP vs Custom REST Tooling: Security and the Latest MCP Architecture
The Model Context Protocol (MCP) is an open standard that simplifies AI applications' connection to external tools, data, and services. It standardizes communication without providing inherent security. Authentication, authorization, least-privilege access, validation, and monitoring are still necessary for secure AI agent systems. MCP supports three main capabilities: tools, resources, and prompts.
In the past, developers often used custom REST tooling to connect AI applications to external services. However, using MCP, tools can be defined using the @mcp.tool() decorator, making integration more manageable. For instance, a Python function can be exposed as an MCP tool, which allows AI applications to communicate with external services consistently.
The latest MCP architecture includes several changes, such as a stateless protocol design, server/discover mechanism, streamable HTTP transport, multi-round-trip requests, and tasks extension. The architecture can be summarized as follows: local applications use stdio, while remote MCP servers use Streamable HTTP.
MCP does not determine the AI's allowed actions. For instance, an MCP server might expose a SQL tool that allows dangerous operations like DELETE FROM customers. In such cases, security must come from the application and backend, not just MCP. Remote MCP servers can enforce authorization using OAuth and bearer-token verification. Additionally, indirect prompt injection can occur through various external sources, making it crucial to consider the entire content read by the AI agent for potential security threats.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.