---
topic: system-design
author: Crashtech Editorial
date: Oct 7, 2026 · read: 2 min
updated: October 8, 2026
---

Model Context Protocol: Hosts, Tools and Stateful or Stateless HTTP

MCP standardizes how AI apps discover and call external capabilities. Streamable HTTP can support sessions; interoperability does not replace authorization.

– –

Model Context Protocol architecture and primitives

Conceptual architecture; arrows show relationships, not measured latency, energy or safety guarantees.

Host, client and server

The host coordinates the user experience, model interaction and policy. A client manages a connection to a server. The server exposes capabilities from a particular domain, such as repository inspection or document search. Capability negotiation lets the participants describe what they support. [1]

A common protocol can reduce repeated adapter work across hosts. Clients may still differ in supported capabilities, interface choices and approval behavior; one server is not guaranteed to behave identically in every application.

Transport does not determine every state boundary

The referenced 2025-11-25 specification defines stdio and Streamable HTTP. A stdio server communicates through a local subprocess’s standard streams. Streamable HTTP uses HTTP requests and can return JSON or use Server-Sent Events. It replaced the earlier HTTP-plus-SSE transport. [2]

That specification explicitly permits a server to create a session and return an MCP-Session-Id. HTTP deployment therefore does not imply that MCP is universally stateless. Load balancing and serverless deployment need to match the chosen session and streaming design.

There is no basis here for a supposed July 2026 change from mandatory WebSockets to mandatory stateless HTTP. This article describes the identified specification version rather than inventing a protocol revision.

Tools, resources and prompts

Tools expose callable actions, resources expose contextual data, and prompts expose reusable interaction templates. A tool call uses a method such as tools/call with a name and arguments. A schema can reject malformed arguments, but it cannot determine whether the user is allowed to act on the requested record. [1]

For a database tool, enforce read or write permissions with database roles and server checks. Do not rely on the model to notice that an arbitrary SQL string performs a mutation.

Security stays with the implementation

Validate origins for applicable HTTP connections, scope credentials and permissions, and treat descriptions and returned content as untrusted input. Session identifiers require protection; they are not substitutes for authorization. The protocol’s security guidance discusses risks including confused-deputy behavior and session hijacking. [3]

Local stdio also does not guarantee that data stays on the machine: the host may send returned content to a remote model, and the server may call external services. Trace the complete data path before making a privacy claim.

Advertisement

Frequently asked questions

Is MCP inherently stateless?

No. The referenced 2025-11-25 specification permits stateful Streamable HTTP sessions using MCP-Session-Id. Servers can also be designed without that session state.

Does MCP automatically secure an exposed tool?

No. The host and server still need authentication, scoped authorization, input validation and appropriate action approval. A tool schema describes arguments, not permission to execute them.

Sources & further reading

/* Comments */