Skip to lesson
supraj.dev THE ENGINEERING HANDBOOKS
LEARN / BUILD / VERIFY2026 edition · checked 06 Oct

CHAPTER 19 / 30 · Connect and coordinate

Connect MCP tools without inheriting blind trust

Understand process and HTTP transports, tool discovery and the authority of a remote server.

4 min read + practiceWorked exerciseInterview practice

The mechanism

MCP connects an agent client to tools hosted by another process or service. Strands can load those tools through an MCP client and present them to the model. The protocol standardizes communication; it does not certify the server’s code, data handling or authorization. Treat each server as a dependency with its own owner and security boundary.

Local stdio transport launches or connects to a process through standard input and output. Streamable HTTP reaches a remote endpoint. A local process may inherit environment and filesystem access; a remote service may receive credentials and request data. The same tool name can therefore carry very different risks depending on deployment.

Strands agent
MCP client + selected transport
Reviewed MCP server
Authorized downstream service

A worked connection shape

Configuration example only. fixture_server.py below is a placeholder for a locally reviewed MCP server you implement or select; it is not included as a runnable server in this book. Do not replace it with an unreviewed package at latest.

from mcp import StdioServerParameters, stdio_client
from strands import Agent
from strands.tools.mcp import MCPClient

client = MCPClient(lambda: stdio_client(
    StdioServerParameters(command="python", args=["fixture_server.py"])
))
# Direct integration lets the SDK manage the connection lifecycle.
agent = Agent(model=model, tools=[client], callback_handler=None)

The current documented managed integration accepts the client directly in the tool list. If you instead use explicit context management and listed tools, keep invocation within the client’s lifetime. A tool object referring to a closed connection can fail even though discovery previously succeeded.

Before connecting a real server, review its package source or vendor, pinned version, launch command, environment, exposed tools and downstream credentials. A server that advertises a read-only description can still execute writes internally. Verify behavior at the destination boundary and expose only the capabilities needed for the task.

Practice: review a server contract

Offline. Create a server card with transport, owner, version, executable or endpoint, authentication method, allowed tools, data sent, downstream permissions and shutdown behavior. Mark unknown fields as blockers to live integration rather than guessing values.

Expected observation: “supports MCP” answers almost none of these operational questions. For the ParcelOps fixture, the desired server exposes one lookup tool with synthetic data, no filesystem browsing and no arbitrary network request tool. That narrow contract makes the first integration test meaningful.

Design cases for a dropped connection, changed tool schema, tool timeout and a malicious tool result. The application should distinguish connection failure from a legitimate “incident not found” result. It should also preserve the lower trust of server-returned text; a remote result cannot approve its own future actions.

Troubleshooting and trade-offs

A stdio server must keep protocol output separate from diagnostic logs. Unexpected plain text on the protocol channel can break communication. A remote endpoint can fail due to authentication, TLS, proxy or transport-version issues; inspect the exact layer before repeatedly invoking the agent.

Tool discovery is convenient but creates change risk when servers add capabilities. Record the discovered contract and review changes as dependencies change. MCP is a useful integration boundary, but a small direct function may be simpler when the tool lives in the same application and needs no interoperability.

Interview practice

Does MCP make a tool safe or read-only?

No. It defines a communication protocol. Safety depends on the server implementation, credentials, tool surface, application policy and downstream authorization.

Why can a discovered tool fail after leaving a context manager?

The tool may depend on the MCP client connection that the context manager closed. Keep execution within the connection lifetime or use the documented managed integration.

Completion check

Complete a server card and a connection-failure test plan. Explain the difference between trusting the protocol format and trusting the tool implementation. Keep the placeholder example labelled until a reviewed server exists.

Sources and version notes

Checked 6 October 2026. Python examples target strands-agents==1.58.0 unless labelled otherwise. Live documentation can change; compare your installed version before adapting an example.

YOUR NEXT STEP

Make the understanding yours.

Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.

Self-assessed reading progress. This does not certify that a lab ran or a system is secure.