Skip to lesson
supraj.dev THE ENGINEERING HANDBOOKS
LEARN / BUILD / VERIFY2026 edition · checked 06 Oct

CHAPTER 22 / 30 · Operate the integration

MCP and the agent loop

Keep model reasoning in the host and recognize deprecated client features.

4 min read + practiceWorked exerciseInterview practice

The mechanism

MCP supplies a capability interface; an agent framework decides how to select tools, retain context and stop. A server can be useful without any model in its process. The host may use deterministic routing, a model-driven loop or a combination.

Older client features such as roots and sampling remain documented with deprecation status in this edition. Do not build a new architecture around their historical semantics without checking the pinned specification and host support. Explicit tool parameters or server configuration can express required resource boundaries; direct model-provider integration can express inference needs.

A root declaration is not a filesystem sandbox. Even in an older supported flow, the implementation must enforce which paths it accesses. Likewise, a model-generated plan is not a permission grant.

User task
Host reasoning
Authorized MCP call
Evidence back to host

Worked example

This is orchestration pseudocode, intentionally independent of an SDK. It exposes the permission check that a one-line “agent.run” example can hide. The stopping condition limits repeated tool use and prevents a tool result from adding its own authority.

while task is unfinished and budget remains:
    proposal = planner(task, approved_evidence)
    if proposal is a tool call:
        validate arguments and user-authorized effect
        call only an approved server capability
        label returned content with origin and trust
    else:
        verify answer against evidence and finish
stop when budget expires or approval is required

Practice: predict, inspect, explain

Offline exercise. Trace one lookup through the loop and count model decisions separately from protocol requests. Then inject a tool result requesting a second, unrelated tool. Explain which gate denies it. Finally remove the model and route INC-104 lookups deterministically.

Expected observation: MCP still provides a useful interface without autonomous planning. Evaluate whether an agent is necessary for the task before adding probabilistic decisions. A smaller orchestration surface is often easier to review, but that is a design trade-off to test rather than a universal performance claim.

Troubleshooting and trade-offs

If the host loops indefinitely, inspect stopping criteria and retry budgets before blaming the protocol. If a server needs access to a directory, configure and enforce that directory explicitly. Avoid describing deprecated sampling or roots examples as the recommended modern architecture. Preserve legacy compatibility only when a concrete supported client requires it.

Interview practice

Is a model required to call an MCP tool?

No. A client can invoke an authorized tool deterministically. Model-driven selection is a host-level design choice.

Do roots enforce filesystem access?

No. A declaration of intended roots is not an operating-system isolation mechanism. The server and runtime must enforce actual access boundaries.

Completion check

Explain how the same server can serve both deterministic and agent-driven clients.

Sources and version notes

This edition targets MCP 2026-07-28, checked 6 October 2026. SDK examples are version-sensitive and labelled when not executed. Synthetic fixtures are learning material, not protocol conformance evidence.

YOUR NEXT STEP

Make the understanding yours.

Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.

Self-assessed reading progress. This does not certify that a lab ran or a system is secure.