The mechanism
MCP supplies a capability interface; an agent framework decides how to select tools, retain context and stop. A server can be useful without any model in its process. The host may use deterministic routing, a model-driven loop or a combination.
Older client features such as roots and sampling remain documented with deprecation status in this edition. Do not build a new architecture around their historical semantics without checking the pinned specification and host support. Explicit tool parameters or server configuration can express required resource boundaries; direct model-provider integration can express inference needs.
A root declaration is not a filesystem sandbox. Even in an older supported flow, the implementation must enforce which paths it accesses. Likewise, a model-generated plan is not a permission grant.
Worked example
This is orchestration pseudocode, intentionally independent of an SDK. It exposes the permission check that a one-line “agent.run” example can hide. The stopping condition limits repeated tool use and prevents a tool result from adding its own authority.
while task is unfinished and budget remains:
proposal = planner(task, approved_evidence)
if proposal is a tool call:
validate arguments and user-authorized effect
call only an approved server capability
label returned content with origin and trust
else:
verify answer against evidence and finish
stop when budget expires or approval is required
Practice: predict, inspect, explain
Offline exercise. Trace one lookup through the loop and count model decisions separately from protocol requests. Then inject a tool result requesting a second, unrelated tool. Explain which gate denies it. Finally remove the model and route INC-104 lookups deterministically.
Expected observation: MCP still provides a useful interface without autonomous planning. Evaluate whether an agent is necessary for the task before adding probabilistic decisions. A smaller orchestration surface is often easier to review, but that is a design trade-off to test rather than a universal performance claim.
Troubleshooting and trade-offs
If the host loops indefinitely, inspect stopping criteria and retry budgets before blaming the protocol. If a server needs access to a directory, configure and enforce that directory explicitly. Avoid describing deprecated sampling or roots examples as the recommended modern architecture. Preserve legacy compatibility only when a concrete supported client requires it.
Interview practice
Is a model required to call an MCP tool?
No. A client can invoke an authorized tool deterministically. Model-driven selection is a host-level design choice.
Do roots enforce filesystem access?
No. A declaration of intended roots is not an operating-system isolation mechanism. The server and runtime must enforce actual access boundaries.
Completion check
Explain how the same server can serve both deterministic and agent-driven clients.
Sources and version notes
This edition targets MCP 2026-07-28, checked 6 October 2026. SDK examples are version-sensitive and labelled when not executed. Synthetic fixtures are learning material, not protocol conformance evidence.
- Official documentation: Deprecated
- Official documentation: Roots
- Official documentation: Sampling
- Official documentation: Index
Make the understanding yours.
Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.
Self-assessed reading progress. This does not certify that a lab ran or a system is secure.