Guide · AI and your data
What is MCP (Model Context Protocol)?
Everyone is plugging Claude and ChatGPT into their tools with MCP. What it is, how the pieces fit, and the question almost nobody asks before installing a server.
Short answer: MCP (Model Context Protocol) is an open standard for connecting AI applications like Claude or ChatGPT to outside systems: files, databases, work tools or your ad accounts. Anthropic published it in November 2024, and since December 2025 it has been governed by a foundation under the Linux Foundation.
What is MCP, in one sentence?
The official documentation puts it with an analogy that lands the first time:
“Think of MCP like a USB-C port for AI applications.”
Model Context Protocol documentation, What is the Model Context Protocol, read on 28 September 2026.
Before MCP, every assistant needed its own integration with every tool. With MCP a connection is built once, and any assistant that speaks the protocol can use it. That is the whole trick, and it is why the term turned up everywhere at once.
Want your Google Ads account in there? The options, and what each one can changeWhat is an MCP server?
MCP has three parts. The host is the AI application you use: Claude, ChatGPT or a code editor. Inside it, a client holds the connection to each server. And the MCP server is the program that provides the context: your files, a database, or your Google Ads account.
A server can offer three kinds of thing, which the specification calls primitives:
- Tools: functions the assistant can run. Pulling last week’s campaigns is one; pausing a campaign is another.
- Resources: data the assistant can read for context, like a file or a database schema.
- Prompts: ready-made templates for tasks you repeat.
When you connect a server, the assistant asks for its list of tools, reads what each one is for, and picks which to call based on what you asked. You see the answer; the call happens behind it.
How does MCP work under the hood?
An MCP server can run on your computer or on the internet. A local server talks to the assistant over standard input and output (stdio) and usually serves one application. A remote server lives at a web address, talks over HTTP and serves many clients at once. To get in it asks you to sign in, and the specification recommends OAuth.
Underneath, the messages are JSON-RPC 2.0. You do not need to know that to use it, but it explains why a server can be written in almost any language. The current version of the specification is dated 28 July 2026.
On Meta instead? The Meta Ads MCP options, and which ones can spend budgetWhich AI assistants support MCP?
Claude was first, because MCP came out of Anthropic. Since 2025 it has been picked up by ChatGPT, Gemini, Microsoft Copilot, Cursor and VS Code, among others. When the Linux Foundation announced the foundation that now runs it, it gave this number:
“more than 10,000 published MCP servers”
Linux Foundation, Agentic AI Foundation press release, 9 December 2025.
In practice, you add a remote server to Claude or ChatGPT as a connector, using its web address. A local one goes into the configuration of the desktop app or the editor.
What can an MCP server do to your account?
What an MCP server can do to your account is the question almost nobody asks before installing one. The protocol does not decide what the assistant can touch. Each server does, through the tools it offers and the permissions it asks for when you connect.
A server whose tools only read cannot change anything, whatever the model does. One whose tools write can edit, delete or spend. On an ad account that has a price: if the model raises a budget by mistake, the mistake shows up on the invoice.
Before you connect one, check three things:
- Its tools, one by one. If any of them write, which ones, and with what limit.
- The permission it asks for at sign-in. Google Ads has no read-only permission: if a server only reads, the server guarantees it, not Google.
- Whether anything stands between the model and your account. A person who approves each change, or nothing.
| Way to connect your ad account | What can it do there? | Best for |
|---|---|---|
| The platform’s official server | Depends: Google Ads’ only reads; Meta’s also writes | Teams that want the vendor route and will set it up |
| A third-party server | Usually reads and writes, sometimes with an agent that acts alone | Teams that want automation and trust the vendor |
| Your own server | Whatever you build, with the API access you can get | Teams with engineers who will read the code |
| Climent Ads Assistant | Proposes, then waits for a person to approve each change | Client accounts, and any account where a mistake costs real money |
The last row is ours, and it sits in the table so you can hold it against the others. Building your own server against Google Ads or Meta needs API access first: Google Ads API access and Meta Marketing API access walk through both, and connecting your AI to your ad data compares the routes end to end.
Reading GA4 instead: the Google Analytics MCP, and what it can touchQuestions people actually ask
What does MCP stand for?
Model Context Protocol. The context is the information a model needs to answer well, and the protocol is the standard way to hand it over from outside: a file, a database, a work tool or an ad account.
Who created MCP, and who owns it now?
Anthropic, the company behind Claude, released it as an open standard in November 2024. On 9 December 2025 it donated MCP to the Agentic AI Foundation, a fund under the Linux Foundation whose members include OpenAI, Google and Microsoft. No single company controls it now.
Is MCP free?
The protocol is: it is open, and the official SDKs are open source. What can cost money is the server, since some are free and others are sold as a service, and the assistant that uses it, which has its own plans.
What is the difference between MCP and an API?
An API is the door to one service, and each one works its own way. MCP sits on top: an MCP server usually calls an API underneath, the Google Ads API for example, and offers it to any assistant in the same format. What can be done is still decided by the API and the permission you grant.
Is MCP safe to connect to my accounts?
That depends on what the server can do, not on the protocol. A server that only reads cannot spend your money; one that writes can, and then what matters is whether anything stands between the model and your account. Check who hosts it too: a remote server sees your data.
Do I need to code to use MCP?
Not to use a ready-made server: in Claude or ChatGPT you add it as a connector and sign in. A local one means editing a configuration file. Building your own does take code, with the official SDKs, and against Google Ads or Meta you also need access to their API.
Related reading
- Connect your AI to your ad data. The routes to get an assistant to your numbers, including the ones that are not ours.
- Google Ads MCP: the options. The official server only reads; what the others do.
- Google Ads API access. What your own MCP needs from Google now that the developer token is gone.
- Qué es MCP. This guide, written for people searching in Spanish.
Last updated:
Who wrote this
I’m Manu. I’m a media buyer, and I built Climent Ads Assistant because no ads software I paid for was worth it. It has its own MCP server: it reads Meta, Google Ads, GA4 and Search Console one client at a time, and changes a campaign only through a proposal that a person signs in the product.