Resources · AI

One protocol for model context.

Model Context Protocol is the open standard connecting models to data with persistent context. Mediator treats it as the governed tool-authority plane.

Demos call tools. Production declares authority.

MCP pairs model clients with data servers over JSON-RPC. The client requests context or tool execution, and the server answers with declared schemas. Conversation state persists across steps, so later calls inherit earlier findings without re-proving them. Against generic REST APIs built for data exchange, MCP adds model-oriented primitives: capability discovery, context retention, tool manifests and progress reporting. Against EDI and SOAP-era rigidity, it stays transport-light and schema-flexible while keeping auth, audit and versioning explicit.

Production deployments add the missing half that demos skip. Tool scopes are negotiated before the first call, and secret references resolve only on the owning node. Each call follows an approval policy by risk class, and mutating tools carry idempotency keys. Timeout and retry budgets apply, and a surviving ledger maps every call to its actor, arguments, result hash and receipt.

Client and server

Servers expose data and tools under versioned schemas; clients retrieve with declared scopes.

Capability discovery

Clients enumerate live tools before planning; undeclared tools are unreachable by construction.

Context retention

Conversation and task state persist across calls; resumption replays from receipts.

Ceilings first

Every node declares readable and writable surfaces; writes outside fail closed into HOLD.

Approval policy

Read, propose and execute classes carry distinct approval paths by risk.

Secrets by reference

Handles resolve at execution on the owner node; prompts, logs and transcripts stay redacted.

Idempotency and budgets

Mutating tools carry idempotency keys; timeouts and retries are declared, not improvised.

Ledger survives

Actor, arguments, result hash and receipt persist beyond the session for independent replay.

Proof

No ceiling, no run.

Reviewers inspect the scope table and receipt sample, not the demo recording.