Skip to lesson
supraj.dev THE ENGINEERING HANDBOOKS
LEARN / BUILD / VERIFY2026 edition · checked 06 Oct

CHAPTER 09 / 30 · Design useful capabilities

Resources: named context with a boundary

Expose useful context without turning a resource URI into arbitrary filesystem access.

4 min read + practiceWorked exerciseInterview practice

The mechanism

Resources make context addressable. A server can list resources or templates and read a requested URI. The URI identifies an application resource; it does not imply that the client may read a corresponding local file or arbitrary network destination.

ParcelOps exposes a synthetic incident summary under parcelops://incidents/INC-104. Its resolver parses the scheme and identifier, authorizes the object and returns an approved representation. Never implement a resolver by passing an untrusted URI directly to a filesystem or HTTP client.

A resource is not automatically inserted into every model prompt. The host controls selection and presentation. That allows a user to inspect which data will be shared, and it prevents a resource server from unilaterally expanding the model’s context.

Resource URI
Allowlisted resolver
Object policy
Bounded content

Worked example

This complete resource-read response fixture includes current cache hints. Private scope prevents reuse across authorization contexts. The synthetic data changes only when the fixture changes; a real incident service should choose a freshness policy appropriate to operational data.

{
  "jsonrpc": "2.0",
  "id": 3,
  "result": {
    "resultType": "complete",
    "ttlMs": 0,
    "cacheScope": "private",
    "contents": [
      {
        "uri": "parcelops://incidents/INC-104",
        "mimeType": "application/json",
        "text": "{\"id\":\"INC-104\",\"status\":\"delayed\",\"revision\":7}"
      }
    ]
  }
}

Practice: predict, inspect, explain

Offline exercise. Make a resolver decision table for the allowed URI, an unknown scheme, an extra path segment and another user’s valid incident. Define the maximum result size and permitted fields. Then put instruction-like text inside the incident description and decide how the host should label it.

Expected observation: URI parsing, object authorization and content trust are distinct checks. A well-formed URI may still be forbidden. A successfully read resource may still contain misleading or adversarial prose. No host file should be opened during this paper exercise.

Troubleshooting and trade-offs

If a resource suddenly appears stale, inspect its cache hints and authorization context before blaming the model. If the client cannot display it, verify MIME type and representation support. If a template exposes broad wildcards, narrow its resolver contract. Do not rely on a friendly URI scheme as proof that the implementation cannot access other destinations.

Interview practice

How does a resource differ from a tool?

A resource provides addressable context; a tool describes an operation the client may invoke. Their application effects and selection patterns differ, but both require authorization and careful content handling.

Why use a custom URI scheme?

It expresses application identity without promising direct filesystem or network access. The resolver must still enforce its parsing and authorization rules.

Completion check

Trace an invalid and an unauthorized URI through separate rejection gates.

Sources and version notes

This edition targets MCP 2026-07-28, checked 6 October 2026. SDK examples are version-sensitive and labelled when not executed. Synthetic fixtures are learning material, not protocol conformance evidence.

YOUR NEXT STEP

Make the understanding yours.

Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.

Self-assessed reading progress. This does not certify that a lab ran or a system is secure.