MCP is a specialized layer for AI agents to consume services, translating traditional APIs (like REST) into a format Large Language Models can better utilize. It doesn't replace existing APIs but rather wraps them, acting as an adapter for a new type of consumer.
Instead of embedding MCP endpoints directly into an application, run them as a separate "sidecar" service. This isolates bursty, experimental AI agent traffic, allowing independent scaling, resource capping, and lifecycle management without risking the core application.
Effective MCP tools abstract complexity by mapping to a complete user task, not a single API call. Create a high-level tool like "look_up_order_status" that joins data server-side, rather than exposing multiple low-level endpoints for the AI to orchestrate.
An MCP server must not run with its own powerful credentials. To prevent a "confused deputy" attack, the end-user's identity must be passed through the agent to the MCP server, which then authorizes every action against that specific user's permissions, not the server's.
