What an MCP server does
An MCP server is the side of an MCP connection that has the capabilities. When an AI assistant connects, the server lists what it offers: tools the model may call, resources it may read, and prompts the user may pick. The assistant decides when to call a tool, the server runs it and returns the result. One server can be used from any MCP-compatible client without changes, which is the whole point of the protocol.
Local and remote servers
A local server runs as a child process of the assistant and talks over stdio. It's typical for developer tools that read files on your machine, and it gets its credentials from the environment. A remote server runs on the internet and talks over Streamable HTTP. It can serve many users, so it needs to know who is calling.
For HTTP servers, the MCP authorization specification builds on OAuth 2.1. The server acts as an OAuth resource server and must publish Protected Resource Metadata (RFC 9728) that points clients at its authorization server. Clients must use PKCE and must name the server they want a token for (RFC 8707 resource indicators), and servers must reject tokens that were issued for anyone else. Passing a user's token straight through to another API is explicitly forbidden.
What to look for before you connect one
- Scopes. Can you grant less than everything? A server that only offers all-or-nothing access asks for more trust than it needs.
- Which actions cost money or change data. Tool names should make it obvious, and the client should ask before it runs them.
- Revocation. You should be able to see connected apps and disconnect one without changing your password.
- Tool output is untrusted input. Text a tool returns goes into the model's context, so a server that relays third-party content can carry prompt-injection attempts.
How Vibely uses it
Vibely runs a remote MCP server at https://api.vibely.sh/mcp over Streamable HTTP. You connect it from Claude, ChatGPT, Cursor, Claude Code, VS Code or Codex and sign in with OAuth 2.1. Clients register themselves dynamically, PKCE is required, and only the S256 method is accepted. The server has 52 tools and 7 scopes, and the consent screen lets you untick scopes before you approve. Only three tools use credits: creating a project, sending a message and approving a plan. Access tokens last an hour and refresh tokens rotate over a 30-day sliding window. Calls are rate-limited to 240 a minute per connection, and 30 a minute for the credit-using tools. Settings → Connected AI apps lists each connection's scopes and recent calls, with a Disconnect button. Workspace admins can allowlist clients and turn off database SQL or publishing for every connection.
Vibely can also build an MCP server for you: agent integrations add one at /mcp to a published web app, with one tool per action the app already supports.
Related terms
Sources
- Understanding MCP servers (modelcontextprotocol.io)
- MCP authorization specification (2025-11-25) (modelcontextprotocol.io)
- MCP transports (2025-11-25) (modelcontextprotocol.io)
- MCP security best practices (modelcontextprotocol.io)