Mellow Hub

What is an MCP server, and what is an MCP client?

Short answer

An MCP server is a program that gives an AI application tools and data through one standard protocol; an MCP client is the part of the application that keeps the connection to one server. MCP, the Model Context Protocol, is an open-source standard for connecting AI applications such as Claude or ChatGPT to external systems. The application itself is the host and creates one client for each server. A social-posting server, for example, lets an assistant check a post against each network’s rules and publish it.

The three parts

The MCP documentation names three participants:

PartWhat it isExample
HostThe AI application that coordinates one or more clients, and the one people actually useClaude Desktop, Claude Code, Visual Studio Code
ClientA component inside the host that keeps a connection to one server and gets context from it for the hostOne is created for each server the host connects to
ServerA program that provides context to clients, wherever it runsA filesystem server on your own machine; Sentry’s server, which runs on Sentry’s platform

People say “MCP client” for the application too, but the documentation keeps the words apart: the host is what users interact with, and the clients are the protocol-level pieces that make each server connection.

What a server can offer

A server exposes up to three kinds of building block, and each has a different party in charge:

Building blockWhat it isWho decides to use itExamples from the documentation
ToolsFunctions the model can call, which can write to databases, call external APIs or change filesThe modelSearch flights, send messages, create calendar events
ResourcesRead-only data that gives the model contextThe applicationFile contents, database schemas, a calendar
PromptsReady-made instruction templatesThe user, by explicit invocationPlan a vacation, summarize my meetings

A client finds out what is on offer by asking: it sends tools/list and gets each tool’s name, description and the JSON Schema of its inputs. It runs one with tools/call.

Local and remote servers

“MCP server” names the program, not where it runs. A local server uses the stdio transport, runs on the same machine and usually serves one client. A remote server uses Streamable HTTP, runs on someone else’s platform and usually serves many clients. Remote servers can use ordinary HTTP authentication, and MCP recommends OAuth to obtain the tokens. That is the kind Claude’s custom connectors and ChatGPT’s MCP apps reach: how to add one in Claude.

Example: a server that publishes social media posts

Mellow Hub runs a remote MCP server at https://www.mellow.world/mcp. A client such as Claude connects, signs in through OAuth, and lists its tools. The ones that matter for a post are whoami (what this connection may do), list_channels (the connected accounts), validate_post, create_post, get_post and post_results. What happens when you ask an assistant to post:

  1. The model decides the post should be checked first, and the host sends a tools/call request, shown here in short form: {"method":"tools/call","params":{"name":"validate_post","arguments":{"channels":["spc_example"],"caption":"Our autumn menu starts today"}}}. The spc_ value is a channel ID from list_channels.
  2. The server checks the caption and media against each network’s rules and replies with a result that carries ok, true or false, and every problem at once, naming the network and the field. The model reads it and fixes the input. Nothing has been published.
  3. When the check passes, the model calls create_post with an idempotency key, so a retry after a timeout cannot publish twice. Hub’s instructions to agents tell them to call validate_post first every time.
  4. get_post and post_results read back the outcome on each network.

The server does not decide whether the assistant is allowed to act. That is the host’s job and yours.

Where the human is

The MCP specification says there should always be a human in the loop with the ability to deny tool invocations, and that applications should show which tools are exposed, mark when they are invoked and present confirmation prompts. It does not require any particular interface. In practice the approval comes from three places:

  • The assistant. Claude shows tool approval requests and warns that “Allow always” is for a server and tool you trust to run unsupervised. ChatGPT may ask for confirmation of an action depending on its permissions, and may block especially risky ones.
  • The server’s own delegation. When Claude or ChatGPT connects to Hub, its consent screen asks which accounts, review or autopilot, a daily limit from 1 to 1,000 posts and an expiry. In review mode a post waits for a person in Hub’s Posts screen.
  • The network. Each network’s own rules still apply to what is sent.

Hub is paid: plans start at $19 a month (Solo), after a 7-day trial with a card on file that costs nothing if you cancel before it ends, and a monthly plan's first month is 20% off. Publishing is unlimited on every plan, under a fair-use ceiling that stops automated floods (900 publications a month on Solo). One publication is one post on one account, so a post sent to five networks counts as five. There are no automatic overage charges.

What changed in 2026

The revision of 28 July 2026 made MCP stateless: every request carries the protocol version and the capabilities it needs, instead of relying on a session set up by a handshake. It also deprecated sampling and roots. Hub’s server supports 4 revisions of the protocol, from 2025-03-26 to 2026-07-28, so a client on an older one still connects.

Questions people also ask

Is an MCP server the same as an API?

No, though many MCP servers sit in front of an API. An API is made for programmers who read its documentation. An MCP server describes each of its tools, with the schema of their inputs, so that an AI application can discover them with tools/list and call them with tools/call.

Does MCP only work with Claude?

No. The MCP documentation calls it an open-source standard and lists Claude and ChatGPT among the assistants that support it, with development tools such as Visual Studio Code and Cursor. Anthropic created it.

Do I have to run an MCP server on my own computer?

No. A local server runs on your machine over stdio, but a remote server runs on someone else’s platform and is reached over HTTP. Claude’s custom connectors and ChatGPT’s developer-mode apps take remote servers.

Is it safe to connect any MCP server?

No. Anthropic warns that malicious MCP servers may include hidden instructions meant to make Claude do something unintended, and OpenAI warns that untrusted servers increase exposure to risks including prompt injection. Connect only servers you trust, and read the permissions each one asks for.

What is the difference between tools, resources and prompts?

Tools are actions the model can choose to take, resources are data the application supplies as context, and prompts are templates the user picks. A posting server mostly exposes tools, because publishing is an action.

Sources

  1. Model Context Protocol: What is MCP?
  2. Model Context Protocol: Architecture overview
  3. Model Context Protocol: Understanding MCP servers
  4. Model Context Protocol: Understanding MCP clients
  5. Model Context Protocol specification: Tools
  6. Claude Help Center: Get started with custom connectors using remote MCP
  7. OpenAI Help Center: Developer mode and MCP apps in ChatGPT

Other companies’ features change. Every statement about them rests on these pages, as they read on the date above.

Write to Hub's founder

Every message is read by the founder himself, so you are talking to him directly. Questions, bugs, a feature you miss: write about anything. We are glad to keep making Hub better.

What is it about?

We attach this page's address so we can see what you saw.