The Model Context Protocol (MCP) is an open protocol through which an application running an MCP client connects a model to MCP servers, which can expose tools the model calls, resources the application attaches as context, and prompt templates the user invokes. Messages are JSON-RPC 2.0, carried over stdio for a local server or Streamable HTTP for a remote one, and a remote server that needs authorization acts as an resource server (MCP specification, authorization). The lesson calls any service that exposes tools to an a tool server; MCP is a standard way to build one.

In FDE interviews

Postings name it: Anthropic’s postings list MCP servers, sub-agents and agent skills among the technical artifacts FDEs deliver for customers, and Notion’s describe building custom agents and AI workflows with MCP. Source 1Forward Deployed Engineer (New York City, NY; San Francisco, CA; Seattle, WA)PublisherAnthropic (Greenhouse job board)Source typecompany job postingSource 2Forward Deployed Engineer, GTM, AMER @ NotionPublisherNotion (Ashby job board)Source typecompany job posting One candidate reported, in a repo created in August 2026 and described as a Duvo FDE task assessment, building an MCP server that lets an agent check store stock and raise replenishment orders against a stubbed system, and wrote in its README that the task stated the integration plumbing was not what was being tested. Source 3StoreLink MCP serverPublisherAlexHumpert (GitHub)Source typecandidate’s take-home repository

A strong answer goes past the plumbing to the trust boundary. The spec requires a server to accept only tokens issued for it and forbids passing the client’s token through to an upstream API (MCP specification, authorization security considerations), so when the server calls the customer’s system it uses a separate token issued for that system, scoped to what the tools need. Treat every tool result as untrusted input that can carry a prompt injection, write each tool description as carefully as a prompt, because the model reads it as one, put a person’s confirmation in front of any tool that writes, and log every call for an audit. Then say when you would skip MCP: if one agent you own calls one system, a plain function call is less to run; a server pays off when several clients, such as the customer’s own assistant, reuse the same tools.

Related: agent, OAuth, idempotency key.

GlossaryOAuthA standard for granting an application limited, revocable access to resources on a user’s behalf without sharing passwords.More on OAuthGlossaryAgentA system in which a model chooses steps and tool calls to complete a task, within limits the design sets.More on AgentGlossaryForward deployed engineerA software engineer who builds and ships production systems inside a customer’s problem and environment, accountable to that customer’s outcome.More on Forward deployed engineer