Study notes · 2.1% of the exam

MCP Server Development

Build and deploy MCP servers and connect them to Claude applications: choose the right primitive and transport, understand host, client and server roles, secure remote servers, and configure servers in Claude Code, the Agent SDK and the Messages API.

Key points

  1. 1

    An MCP server packages capabilities once so any MCP-capable client (Claude Code, Claude Desktop, Agent SDK apps, the Messages API connector) can use them. It fits when a capability should be reused across applications or maintained independently of them.

  2. 2

    Primitives: tools are model-controlled actions, resources are application-driven data identified by URI, and prompts are user-controlled templates, typically picked from a menu.

  3. 3

    Roles: the host application runs one MCP client per server connection. The client discovers capabilities (for example tools/list) and relays Claude's calls. The model never connects to servers directly.

  4. 4

    stdio transport: the client launches the server as a local subprocess and exchanges JSON-RPC over stdin and stdout. The server must write only MCP messages to stdout, and logs go to stderr.

  5. 5

    Streamable HTTP is the transport for remote servers shared by many clients. Deploy it like a web service with authentication. The standalone SSE transport is deprecated.

  6. 6

    Remote server auth uses OAuth. The MCP server is a resource server that must accept only tokens issued for itself (audience validation), and it must not pass the client's token through to upstream APIs; it gets its own credentials for those.

  7. 7

    Design tools for agent workflows rather than mirroring every API endpoint. Use fewer task-level tools, concise responses with pagination, and actionable errors. Report tool failures with isError: true so the model can self-correct.

  8. 8

    Treat tool annotations (such as read-only hints) from untrusted servers as untrusted. Use servers you wrote or trust, and keep approval decisions in the client's permission system.

  9. 9

    Claude Code scopes: local (the default; private to you, current project, stored in ~/.claude.json), project (shared through a committed .mcp.json at the repo root, approved on first use), and user (private, all your projects). For the same name, local > project > user.

  10. 10

    Add servers with claude mcp add --transport http <name> <url> or claude mcp add --transport stdio <name> -- <command>, plus --scope. Use ${VAR} expansion in .mcp.json to keep secrets out of the repo.

  11. 11

    Admins can control which MCP servers users can add through managed configuration (a fixed managed-mcp.json, or allowlists and denylists in managed settings).

  12. 12

    The Messages API MCP connector (the mcp_servers parameter) connects to remote HTTP servers without client code, but supports only tool calls. Local stdio servers, resources and prompts need your own MCP client.

  13. 13

    The Agent SDK connects to external MCP servers and also defines custom tools as in-process SDK MCP servers (createSdkMcpServer / create_sdk_mcp_server), with no separate deployment.

Test yourself on MCP Server Development

Ten questions, with the answer and explanation after each one.