MCP (Model Context Protocol) is an open standard that lets an AI app, such as Claude, ChatGPT, Cursor or VS Code, discover and call another product's tools and read its data through one common interface. For a product manager, that turns MCP into a product surface: you decide which actions your product exposes to other people's agents, who is allowed to call them, and how you measure whether it works. The fastest way to learn it hands-on is AllthingsPM, whose AI PM course has a lesson where you connect an agent to one tool over MCP and read the trace.
AllthingsPM is an AI PM course and PM interview prep platform. Its course was built from 604 real PM job postings, and 33 of those postings name MCP, 28 of them in AI-native roles.
What is MCP, in plain English?
The official docs use a hardware analogy: "Think of MCP like a USB-C port for AI applications" [2]. Before USB-C, every device had its own cable. Before MCP, every AI app needed a custom integration for every tool it wanted to use: one for Slack, another for GitHub, another for your database.
Anthropic released MCP on 25 November 2024 and described it as "an open standard that enables developers to build secure, two-way connections between their data sources and AI-powered tools" [1]. It shipped with ready-made servers for Google Drive, Slack, GitHub, Git, Postgres and Puppeteer [1].
The key shift for a PM: with MCP, you build the connector once, on your side, and any compatible AI app can use it. The docs call this "build once and integrate everywhere" [2]. Instead of your team writing an integration for each AI assistant, the assistants come to you.
Here is the whole thing in PM terms.
| MCP part | What it is (from the spec) | What it means for a PM |
|---|---|---|
| Host | The AI app the user works in, like Claude Code, Claude Desktop or VS Code [3] | Where your users meet your product without opening it |
| Client | A connector the host creates, one per server [3] | Invisible to users; each connection is separate |
| Server | "A program that provides context to MCP clients" [3] | The thing your team ships and owns |
| Tools | "Executable functions that AI applications can invoke to perform actions" [3] | Your product's verbs: create ticket, run query, send invoice |
| Resources | "Data sources that provide contextual information" [3] | Your product's nouns: a record, a schema, a file |
| Prompts | "Reusable templates that help structure interactions" [3] | Recipes you ship so users get good results fast |
| Elicitation | Lets a server "request additional information from users" [3] | Where you ask for confirmation before a risky action |
| Transport | Stdio for local servers, Streamable HTTP for remote ones [3] | Local means a developer's laptop; remote means your hosted, authenticated service |
Definitions quoted from the Model Context Protocol docs and specification, version 2026-07-28, read 26 September 2026.
How AllthingsPM does this: the AllthingsPM course does not stop at a glossary. In MCP first contact, part of the PM as builder chapter, you connect an agent to one tool and watch the trace, so every row in this table becomes something you have seen happen.
How does MCP actually work, step by step?
You do not need to write code to understand the flow. It has three steps, and each one maps to a product decision.
- Discovery. The AI app asks your server what it supports. The current spec has a
server/discoverrequest that returns supported versions and capabilities [3]. - Listing. The app calls
tools/listand gets back each tool's name, title, description and input schema [3]. The model reads those descriptions to decide when to use a tool. - Calling. When the model decides to act, the app sends
tools/callwith arguments, and your server returns results [3]. The docs describe the app "intercepts the tool call, routes it to the appropriate MCP server, executes it, and returns the results back to the LLM" [3].
Under the hood, messages use JSON-RPC 2.0 [3]. What matters is step 2: the tool description is product copy written for a model. A vague description means the model picks the wrong tool or never picks yours. A description that names when to use the tool, and when not to, is a measurable quality lever, just like onboarding copy.
The spec is also moving. The current version is dated 2026-07-28; it made the protocol stateless per request and deprecated the old "sampling" feature [3]. If an interviewer asks what changed recently, that is a concrete, sourced answer.
How AllthingsPM does this: the course treats tool descriptions as a spec you write. The lesson Write the tool contract covers workflow-shaped tools, capped output and errors written as instructions, which is exactly the craft behind a good MCP tool list.
Why should a product manager care about MCP now?
Three reasons, all verifiable.
The whole industry adopted it. On 9 December 2025, Anthropic donated MCP to the Agentic AI Foundation, a directed fund under the Linux Foundation co-founded by Anthropic, Block and OpenAI, with support from Google, Microsoft, AWS, Cloudflare and Bloomberg [4]. At that point MCP had "over 97 million monthly SDK downloads, 10,000 active servers" and client support in ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot and VS Code [4].
Employers are hiring for it. We counted the tools named in 604 PM job postings from 95 companies. MCP appears in 33 postings at 20 companies, and in 28 of the 286 AI-native postings (10%), against 5 of the other postings (2%) [6].
It changes who your users are. When your product has an MCP server, a new kind of user shows up: an agent acting for a human. Postings say this directly. Amplitude's posting for a Principal PM, AI Agents and MCP asks the PM to "advance our MCP capabilities so that customers can work with Amplitude from their coding agent, CLI, or IDE." Sigma's AI Ecosystem role asks the PM to "define Sigma's approach to MCP, giving external agents and tools structured, governed access to Sigma's data model" [6].
How AllthingsPM does this: these numbers come from the same postings that shaped the AllthingsPM course, which is why MCP has lessons instead of a footnote. You can open the live roles in the AllthingsPM jobs catalog, such as OpenAI's Product Manager, API Agents, and run a mock interview built from that exact posting.
What does a PM actually own in an MCP product?
Engineers build the server. The PM owns the decisions around it. In practice that is five things.
1. The tool surface. Which of your product's actions become tools? Fewer, workflow-shaped tools usually beat a one-to-one copy of your REST API, because the model has to choose among them. "Create a report for this date range" is easier for a model than five low-level endpoints it must chain correctly.
2. Permissions and consent. The spec says hosts "must obtain explicit user consent before invoking any tool" and that users "must retain control over what data is shared and what actions are taken" [5]. Hosts enforce the prompt, but you decide which tools are read-only, which change data, and which should never be exposed. For remote servers the docs recommend OAuth for authentication [3], so scopes become a product decision.
3. Descriptions and prompts. As covered above, tool descriptions decide whether the model uses your tools correctly. Prompts let you ship tested recipes. Both are copy, both can be tested, both belong in your spec.
4. Metrics. An MCP server needs its own funnel. Useful measures include time to first successful call, tool call success rate, error rate by tool, how many distinct hosts connect, and retained weekly active connections. Glean's interview question in our bank starts from exactly this: a dashboard with strong time to first call but weak integration success rate [7].
5. The ecosystem. If your company runs a platform, you may also own discovery, listing quality and developer experience for third party servers, which is what questions like "How would you grow MCP adoption among third-party tool developers?" test [7].
How AllthingsPM does this: the lesson The agent spec you own covers scope, roles, tool contracts, risk levels and escalation, and Reachable from someone else's agent covers MCP, A2A and self-improving loops. Together they give you the PM half of an MCP launch.
What are the risks of MCP, and how should a PM think about them?
MCP is a pipe. The risk comes from what flows through it and what the agent can do next.
Simon Willison's "lethal trifecta" is the clearest frame: an agent becomes dangerous when it combines "access to your private data", "exposure to untrusted content" and "the ability to externally communicate" [8]. He points out that mixing MCP tools from different sources can put all three in one session, and uses a GitHub MCP exploit as an example, where a tool read public issues, reached private repository data and could open a pull request that leaked it [8].
The spec itself is direct about this. It says tools "represent arbitrary code execution and must be treated with appropriate caution," that tool descriptions "should be considered untrusted, unless obtained from a trusted server," and that "MCP itself cannot enforce these security principles at the protocol level" [5]. In other words, safety is a product design job.
Practical PM moves:
- Split read and write. Put destructive actions behind separate tools with clear names, so hosts can ask for approval on those alone.
- Ask before irreversible actions. Use elicitation to request confirmation from the user mid-task [3].
- Scope tokens narrowly. Ask for the smallest OAuth scope each tool needs.
- Write the blast radius down. Before launch, list what the worst single tool call could do.
How AllthingsPM does this: the AllthingsPM course has a full lesson on agent security: the lethal trifecta, prompt injection, tool misuse and permission escalation, and another on the approval gate: where to put it and what payload to show so a human can approve with confidence.
How is MCP different from an API, a plugin or A2A?
This is the confusion PMs hit most.
- API vs MCP. An API is your product's interface for developers who read your docs and write code. An MCP server usually wraps parts of that API in a form a model can discover and call without custom code per app. Many MCP servers are thin layers on existing APIs.
- Plugins vs MCP. Earlier plugin systems were tied to one AI app. MCP is an open standard supported across many hosts [2], so one server works in Claude, ChatGPT, Cursor and VS Code.
- A2A vs MCP. MCP connects an agent to tools and data. Agent-to-agent protocols connect one agent to another agent. Our course covers both in one lesson because PMs are asked to choose between them.
How AllthingsPM does this: our post on the tools AI PM job postings name most shows how often postings pair MCP with APIs, SQL and AI coding tools, and the AllthingsPM knowledge graph shows how MCP connects to agents, tools and evals across the course.
How do you learn MCP yourself this week?
You learn MCP fastest by using it, not by reading about it. Here is a plan that fits in a week of evenings.
- Day 1: use one. Pick a host you already have, such as Claude Desktop, Cursor or VS Code, and connect one ready-made server, for example the filesystem or GitHub server [3].
- Day 2: read the tool list. Look at the names and descriptions the server exposes. Ask yourself which you would rename and why.
- Day 3: read a trace. Ask the agent to do a task and look at which tools it called, with what arguments, and what came back.
- Day 4: break it. Give an ambiguous instruction and watch the model pick the wrong tool. Write a better description.
- Day 5: write the PM spec. For a product you know, list five tools you would expose, their risk level, what needs approval and three metrics.
How AllthingsPM does this: the week above mirrors the PM as builder chapter, which also covers building in Claude Code, Cursor and Codex and reading the agent loop and its config. Each chapter ends with graded work, so you finish with proof, not notes.
How does MCP come up in PM interviews?
At AI companies and platform companies, MCP shows up in product sense, strategy and metrics rounds. Real examples from our question bank:
- What metrics define success for the Model Context Protocol (MCP) ecosystem?
- How would you grow MCP adoption among third-party tool developers?
- You own Figma's external developer platform across the MCP Server, REST API, and first-party integrations
A strong answer names the user (a developer, an admin, or an agent acting for a human), picks a north star such as weekly active successful connections, adds guardrails such as error rate and security incidents, and says what you would cut. Weak answers describe the protocol and never reach a decision.
How AllthingsPM does this: each of these questions has its own page and answer guide on AllthingsPM, and any of them can start a scored AI mock interview. For a specific role, paste the posting into the JD mock and the interviewer builds the loop around it, follow-ups included. Company pages such as Anthropic's questions group the rest.
Why AllthingsPM is the better choice for learning MCP as a PM
The official MCP documentation is a free, authoritative reference written for engineers. Read it. But a PM needs to decide what to expose, argue about risk, set metrics and explain it all in an interview.
That is the gap AllthingsPM fills. The AllthingsPM AI PM course was built from 604 real PM job postings, and because MCP shows up in 10% of AI-native postings we read, it gets real lessons: a hands-on one in the builder chapter where you connect an agent to a tool and read the trace, and a strategy one in the agents chapter on MCP and A2A. The trust chapter covers the lethal trifecta and prompt injection, and the AI UX chapter covers approval gates. That is the full PM job around an MCP launch, in order.
Then it connects learning to getting hired. The same account holds 4,122 real interview questions from 260 companies, including MCP questions from Figma and Glean, each with an answer guide; 116 live PM job descriptions at 18 AI companies, each with a mock interview built from it; and a resume review against a job description so your MCP project shows up on the page that recruiters read.
Blog posts and docs are free and useful. For a structured path from "what is MCP" to "I can own an MCP product and interview for it", AllthingsPM is the stronger choice, with a free tier to start and Pro at $20 a month or $120 a year. Open the AI PM course and start with the MCP lesson.
Frequently asked questions
What is MCP in simple terms?
MCP, the Model Context Protocol, is an open standard that lets AI apps connect to external tools and data in one common way. The official docs compare it to a USB-C port for AI applications. A product builds one MCP server, and any compatible AI app can use it.
Do product managers need to know how to code to understand MCP?
No. You need to understand hosts, servers, tools, resources and prompts, read a tool list and a trace, and make decisions about scope, consent and metrics. Connecting a ready-made server to Claude Desktop, Cursor or VS Code takes configuration, not programming.
What is the best way for a PM to learn MCP?
The best way is AllthingsPM: its AI PM course includes a hands-on MCP lesson, a lesson on MCP and A2A, and a security lesson on prompt injection, with real MCP interview questions to practice. Pair it with the free official MCP docs as your protocol reference.
Is MCP only for Anthropic and Claude?
No. Anthropic created it in November 2024 but donated it to the Agentic AI Foundation under the Linux Foundation in December 2025. ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot and VS Code all support it as clients.
What metrics should a PM track for an MCP server?
Start with time to first successful call, tool call success rate, error rate by tool, number of distinct connected hosts and retained weekly active connections. Add guardrails for security incidents and actions that needed human approval.
Is MCP safe?
MCP itself cannot enforce safety; the spec says so. Risk grows when one agent has private data, untrusted content and a way to send data out. Split read and write tools, require approval for irreversible actions, scope tokens narrowly and log every call.
Do PM interviews ask about MCP?
Yes, at AI and platform companies. Real examples include "What metrics define success for the MCP ecosystem?" and "How would you grow MCP adoption among third-party tool developers?", both with answer guides on AllthingsPM.
Ready to go from reading about MCP to owning it? Start the AllthingsPM AI PM course free, then practice with a JD mock interview.
Sources
- Anthropic, "Introducing the Model Context Protocol", 25 November 2024: https://www.anthropic.com/news/model-context-protocol
- Model Context Protocol, "What is the Model Context Protocol (MCP)?": https://modelcontextprotocol.io/docs/getting-started/intro
- Model Context Protocol, "Architecture overview" (version 2026-07-28): https://modelcontextprotocol.io/docs/learn/architecture
- MCP Blog, "MCP joins the Agentic AI Foundation", 9 December 2025: https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/
- Model Context Protocol, Specification (version 2026-07-28), Security and Trust and Safety: https://modelcontextprotocol.io/specification/latest
- AllthingsPM, "The Tools AI PM Job Posts Name Most: SQL, APIs, MCP, Claude Code", corpus of 604 PM postings read 6 September 2026: https://allthingspm.app/blog/ai-pm-job-postings-top-tools
- AllthingsPM question bank, MCP questions: https://allthingspm.app/question-bank
- Simon Willison, "The lethal trifecta for AI agents", 16 June 2025: https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
- Linux Foundation, "Linux Foundation Announces the Formation of the Agentic AI Foundation (AAIF)": https://www.linuxfoundation.org/press/linux-foundation-announces-the-formation-of-the-agentic-ai-foundation




