In short: the Model Context Protocol (MCP) is an open standard published by Anthropic in November 2024 that lets an AI assistant (Claude, ChatGPT, Cursor) access your tools and data through an intermediate server you control. It's the "USB-C of AI". MAG&Cie pricing: MCP Starter at €890 excl. VAT, MCP Standard at €1,890 excl. VAT, MCP Server for SaaS from €4,900 excl. VAT. Lead time 1 to 4 weeks depending on complexity.
Why MCP is a game changer in 2026
Before MCP, plugging an LLM into your information system was tinkering. Each tool (Claude, ChatGPT, Cursor) had its own API, its own format, its own authorization logic. Result: to expose your Salesforce CRM to Claude AND ChatGPT, you needed two different integrations, two codebases to maintain, two auth models.
Anthropic open-sourced MCP in November 2024 to break that silo. One server-side implementation, compatible with every MCP client. The bet paid off: OpenAI, Google, Microsoft, GitHub, JetBrains and Zapier all adopted MCP in under 12 months.
What exactly does an MCP server expose?
An MCP server exposes three primitives to the AI client:
- Tools — executable actions. Examples: "create a Zendesk ticket", "send a Mailjet email", "insert a row in Salesforce", "trigger a CI build". The LLM calls the tool, the server executes it and returns the result.
- Resources — readable data. Examples: "contents of README.md", "list of active projects", "order history of customer X". The LLM reads, it doesn't modify.
- Prompts — reusable templates. Examples: "write meeting minutes from the transcript", "generate a product brief in our house format". The LLM loads them on demand.
This tools/resources/prompts split is what sets MCP apart from plain function calling: it gives the AI client a structured understanding of what it can do vs read vs reuse.
What's the difference between MCP and function calling?
A recurring trick question. The short answer: MCP uses function calling under the hood, but adds three layers on top.
| Criterion | Function calling | MCP |
|---|---|---|
| Level | API primitive | Full protocol |
| Tool discovery | Declared in every request | Auto-discovery at handshake |
| Multi-client | 1 implementation = 1 client | 1 implementation = N clients |
| State | Stateless (resend on every call) | Stateful (sessions, context) |
| Authentication | Up to the developer | Standardized (OAuth 2.1) |
In one sentence: function calling = a LEGO brick. MCP = an operating system for LLMs.
What is an MCP connector used for in a company?
Four concrete use cases we saw with clients in 2026:
1. AI assistant plugged into the CRM
A salesperson asks Claude: "Which 5 of my deals have been in the Negotiation stage for more than 30 days?". Without MCP: they copy-paste CSV exports. With MCP: Claude queries Salesforce, returns the list and drafts a personalized follow-up email for each.
2. RAG on the internal knowledge base
A newcomer asks: "What's our remote work policy?". MCP exposes Notion/Confluence/Drive. Claude quotes the internal pages directly, with links. No custom RAG to maintain.
3. DevOps automation
A developer asks Cursor: "Open a PR with these 3 fixes, create the matching Linear ticket and notify the #releases Slack channel". MCP chains GitHub → Linear → Slack in a single turn.
4. SaaS product differentiation
A B2B SaaS vendor exposes its product as an MCP server. Its customers use Claude or ChatGPT to query their data directly, without going through the UI. A massive selling point against competitors that stay siloed.
How is an MCP server built?
Three dominant languages in 2026: TypeScript/Node (most mature official SDK), Python (official SDK, data ecosystem), Rust (performance, safety, embedded MCP).
Anatomy of a minimal MCP server with the official TypeScript SDK:
import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
import { StdioServerTransport } from "@modelcontextprotocol/sdk/server/stdio.js";
import { z } from "zod";
const server = new McpServer({ name: "crm-mcp", version: "1.0.0" });
server.tool(
"get_deal",
"Fetch a CRM deal by its ID",
{ dealId: z.string() },
async ({ dealId }) => {
const deal = await fetchFromCrm(dealId);
return { content: [{ type: "text", text: JSON.stringify(deal) }] };
}
);
await server.connect(new StdioServerTransport());
For a complete, production-oriented example in Python, see our tutorial Build an MCP server with FastMCP.
Standard development lead times:
- MCP Starter (read-only REST API, up to 5 tools): 1 to 2 weeks — €890 excl. VAT.
- MCP Standard (read + write, OAuth, 5-15 tools): 2 to 4 weeks — €1,890 excl. VAT.
- Custom MCP (multi-system, business logic, advanced security): on quote — from €3,500 excl. VAT.
- MCP Server for a SaaS vendor (production-ready, multi-tenant, billing): 6 to 10 weeks — from €4,900 excl. VAT.
What pitfalls should you avoid?
Four frequent pitfalls:
- Exposing too many tools. An MCP server with 50 tools overloads the LLM's context. 5 to 15 well-named tools beat 50 redundant ones. Principle: one tool = one complete business action.
- Forgetting the audit log. The LLM acts on behalf of the user. Without logs, you can't trace who did what. Log EVERY MCP call with user_id + tool + payload + result + timestamp.
- Mixing read and write. Put destructive actions (delete, send, transfer) behind explicit confirmation. The LLM can hallucinate — the primitive can't.
- Underestimating rate limiting. An AI agent can generate 1,000 MCP calls per minute. Without server-side rate limiting, you kill your backend. Standard pattern: a token bucket per user_id.
Which AI clients support MCP in 2026?
State of the ecosystem as of June 2026:
| Client | MCP support | Since |
|---|---|---|
| Claude Desktop | Native | Nov. 2024 |
| Claude.ai (web) | Native | April 2025 |
| Cursor (IDE) | Native | v0.42 (March 2025) |
| Continue (VS Code/JetBrains) | Native | Feb. 2025 |
| Cline | Native | March 2025 |
| OpenAI ChatGPT | Partial | March 2025 |
| Microsoft Copilot Studio | Native | May 2025 |
| n8n | Plugin | June 2025 |
| Zapier | Plugin | Sept. 2025 |
| Google Gemini | Announced | Q3 2026 |
Is MCP secure for business data?
Yes, under three technical conditions:
- Strict authentication. OAuth 2.1 for servers exposed to several clients. Rotating API keys for internal use. mTLS for highly sensitive servers (healthcare, finance, defense).
- Least privilege. Each tool should only access the data it strictly needs. No "do_anything" tool. Fine granularity = smaller attack surface.
- Exhaustive audit log. Every MCP call logged and kept for at least 12 months. Anomaly detection (volume, patterns). Alerts on destructive actions.
Key advantage over ChatGPT Plugins: the MCP server runs in YOUR infrastructure (private cloud, on-premise). Business data NEVER transits through Anthropic, OpenAI or Microsoft. That's what makes MCP compatible with GDPR, HDS, NIS2 and ISO 27001.
How long does it take for an MCP to pay off?
Three typical ROI cases seen with our clients:
- MCP Starter at €890 to plug Claude into a CRM in read-only mode: 4-6 hours a week of copy-paste saved for one salesperson. ROI = 1-2 months.
- MCP Standard at €1,890 to plug Cursor into GitHub + Linear + Sentry for a 5-developer team. 30 min/day/developer saved. ROI = 3 weeks.
- MCP Server for SaaS at €4,900 as product differentiation for a B2B vendor. A closing argument in 30% of sales cycles. ROI = the first signed contract.
Conclusion
MCP isn't hype: in 18 months it became the de facto standard for connecting LLMs to external systems. SaaS vendors that don't expose their product over MCP in 2026 are losing ground to those that do.
The entry cost is modest (€890 excl. VAT for an MCP Starter), the lead time short (1-2 weeks), and the client ecosystem mature (Claude, Cursor, ChatGPT, Copilot — they all support MCP).
👉 Discuss your MCP project with MAG&Cie — free questionnaire, quote within 48 hours. Our Microsoft To Do MCP server is open source (github.com/MAG-Cie/mcp-microsoft-todo) as proof of expertise.