Key takeaways
- Function calling lets a model ask your code to run something. Every major model API has it.
- MCP packages tools so AI apps you don’t control, such as Claude or Cursor, can find and call them.
- A2A lets an agent hand a whole task to an agent that another team or company runs.
- As of 9 October 2026, Claude Code negotiates MCP 2026-07-28 by default; Cursor speaks 2025-11-25 and earlier.
- Treat tool descriptions and remote agents’ replies as untrusted input, and enforce permissions on the server.
MCP vs A2A vs function calling comes down to who is on the other end of the call. Function calling is the feature in every major model API that lets the model ask your code to run a function. MCP, the Model Context Protocol, puts tools in a server so that AI apps you don’t control, such as Claude, ChatGPT, Cursor and VS Code, can find and call them. A2A, the Agent2Agent protocol, lets one agent hand a whole task to another agent, usually one that a different team or company runs. Most AI products need only function calling. Add an MCP server when outside AI clients should use your product, and A2A when you delegate work to agents you don’t own.
The three overlap more than their names suggest. An MCP client still hands tools to the model through function calling, and the model APIs from OpenAI, Anthropic and Google can now call MCP servers themselves. MCP and A2A also share a home at the Linux Foundation’s Agentic AI Foundation, MCP since December 2025 and A2A since 27 August 2026. MCP’s 2026-07-28 revision made the protocol stateless, and the A2A specification reached 1.0 on 12 March 2026.
The sections below compare the three in a table, show one tool exposed all three ways, and cover the state of play on 9 October 2026, the case for skipping MCP and the security risks. The post ends with a decision rule. We haven’t run benchmarks for it, and every figure links to its source.
What function calling, MCP and A2A each are
Function calling, which OpenAI also calls tool calling and Anthropic calls tool use, is a model feature.12 You send the model a list of functions, each with a name, a description and a JSON Schema for its arguments. When one would help, the model replies with a structured call instead of text. Your application runs the function and sends the result back in the next request, as Google’s Gemini guide spells out.3 Vendors run a few built-in tools themselves, such as web search, but your own functions always run in your code.
MCP is an open protocol for offering tools, along with resources and prompts, to AI applications. An MCP server publishes tools. An MCP client inside a host application, such as Claude, ChatGPT, Cursor or VS Code, lists them with tools/list and calls them with tools/call.4 Messages are JSON-RPC, carried over stdio for a local server that the client starts as a subprocess, or over Streamable HTTP for a remote one.5
A2A is an open protocol for agents that work with other agents. Google introduced it in April 2025 and moved it to the Linux Foundation on 23 June 2025.6 An A2A server publishes an Agent Card at /.well-known/agent-card.json, a JSON document that describes the agent, its skills, its endpoints and how to authenticate. A client agent sends it a message. The remote agent replies directly or opens a task and reports progress on it.7 The specification’s stated goal is for agents to collaborate without access to each other’s internal state, memory or tools.
MCP vs A2A vs function calling at a glance
The table pulls the three together from the specifications and vendor documentation, as of 9 October 2026. The sections after it give the detail and sources.
| Function calling | MCP | A2A | |
|---|---|---|---|
| What it is | A feature of each model API | An open protocol between AI applications and tool servers | An open protocol between agents |
| Who talks to whom | Your application and the model | An MCP client (Claude, ChatGPT, Cursor, VS Code, your own agent) and an MCP server | A client agent and a remote agent, often in another organisation |
| Unit of work | One function call | One tool call, resource read or prompt | A task with a lifecycle, messages and results |
| How capabilities are found | You send the definitions with each request | server/discover and tools/list at runtime |
An Agent Card at /.well-known/agent-card.json |
| Who runs the code | Your application, or the vendor for its built-in tools | The MCP server | The remote agent, out of the caller’s sight |
| Wire format | The vendor’s own HTTP API | JSON-RPC over stdio or Streamable HTTP | JSON-RPC, gRPC or HTTP+JSON |
| State | Conversation history, kept by your application or the vendor’s API | None in the protocol since 2026-07-28; servers return explicit handles | Tasks and contexts held by the remote agent |
| Authentication | Your API key to the vendor; your code holds downstream credentials | OAuth 2.1-based for HTTP servers; credentials from the environment for stdio | Schemes declared in the Agent Card: API key, HTTP auth, OAuth 2.0, OpenID Connect or mutual TLS |
| Long-running work | Up to your application | Tasks extension, polled with tasks/get |
Built in: streaming, polling and push notifications |
| Governance | Each vendor | Agentic AI Foundation since December 2025 | Linux Foundation since June 2025; Agentic AI Foundation since August 2026 |
| Current version | Per vendor | 2026-07-28 | 1.0.1 |
| Main security risk | Injected text steering the calls the model proposes | Poisoned or changed tool descriptions; misused tokens | A malicious or impersonated remote agent |
| Reach for it when | Your application calls your own code | AI clients you don’t control should use your tools | You hand whole tasks to agents someone else runs |
MCP vs function calling: MCP tools reach the model as function calls
An MCP client is a function-calling loop with a standard connector at one end. In the MCP project’s own client tutorial, the client asks the server for its tools, copies each tool’s name, description and input schema into Anthropic’s tool format, and sends them with the request. When Claude replies with a tool_use block, the client forwards the call to the server with call_tool and passes the result back as a tool_result.8 The model never sees MCP. It sees function definitions, the same as if you had written them by hand. Field names differ by vendor, with parameters at OpenAI and Google and input_schema at Anthropic, and the client translates MCP’s inputSchema into whichever the model expects.
So the choice between MCP and function calling is a choice about where the tool lives. Function calling keeps the schema and the code inside your application, and only your application can use them. An MCP server holds both behind a protocol that any MCP client can discover at runtime, which is how one server can work in Claude, ChatGPT, Cursor and VS Code.9101112
The model APIs now act as MCP clients too. As of 9 October 2026:
- OpenAI’s Responses API accepts a tool of type
mcpwith aserver_url. It works with Streamable HTTP and the older HTTP/SSE transport, and by default asks for approval before each call to the server.13 - Anthropic’s Messages API has an MCP connector in beta, behind the
mcp-client-2025-11-20header. It supports tool calls only, for servers exposed over public HTTP.14 - Gemini’s Interactions API connects to remote MCP servers over Streamable HTTP and doesn’t support SSE servers.3
In each case the vendor’s infrastructure calls your server, so it must be reachable from there. OpenAI also offers a tunnel for private servers.13
MCP’s advantage over hand-written definitions is distribution, plus a standard sign-in flow for remote servers based on OAuth 2.1.15 In exchange you run and secure another service and pay the same token bill as for any function definitions. If your own application is the only caller, an MCP server adds a process or a network hop and nothing your function-calling loop lacks.
A2A, the agent-to-agent protocol, and where it overlaps with MCP
A2A’s unit of work is a task with a lifecycle. A client agent sends a message with SendMessage. The remote agent answers directly or creates a task, which can pause in an input-required or auth-required state and ends as completed, failed, cancelled or rejected. Clients follow progress over Server-Sent Events, by polling with GetTask, or through push notifications to a webhook.7 The A2A project calls MCP the vertical layer that connects an agent to its own tools and data, and A2A the horizontal layer between agents.16
The A2A documentation’s example is a repair shop whose mechanic agent uses MCP tools, such as a diagnostic scanner, and orders parts from a supplier’s agent over A2A.17 Neither business sees the other’s tools or data, which the specification calls opaque execution.
Long-running, interactive work is where the two protocols overlap most. Since the 2026-07-28 revision, an MCP tool can return an input_required result that asks the user a question, and the Tasks extension lets a server hand back a task handle that the client polls with tasks/get.18 An A2A task can stop in an input-required state for the same reason. From the outside, a slow MCP tool call and a quick A2A task can look much the same.
Wrapping is the other overlap. An agent can sit behind an MCP tool such as ask_billing_agent, and the A2A documentation says an A2A server can expose skills that behave like stateless tools as MCP-compatible resources.17
The 2026-07-28 revision drew the line more sharply. MCP servers no longer send requests to clients at all, and Sampling, the feature that let a server borrow the client’s model, is deprecated, with the advice to call model provider APIs directly.519 An MCP server is now a request-and-response tool provider. When the thing behind your interface has its own model, makes its own decisions, can run for a long time and belongs to someone else, that is the case A2A was designed for.
The same tool exposed three ways
Take one capability, looking up an order’s delivery status, and expose it each way. These are sketches written for this post. They leave out error handling and authentication, which a real version needs. The function itself is plain Python.
# orders.py
def order_status(order_id: str) -> dict:
"""Get the delivery status of one order by its ID."""
# Look the order up in your own system and check it belongs to the caller.
return {"order_id": order_id, "status": "in_transit", "eta": "2026-10-14"}
Function calling. Your application sends the schema with every request and runs the function when the model asks for it. This version uses Anthropic’s Messages API. OpenAI’s Responses API and Gemini follow the same loop with different field names.21
import json
import anthropic
from orders import order_status
client = anthropic.Anthropic()
tools = [{
"name": "order_status",
"description": "Get the delivery status of one order by its ID.",
"input_schema": {
"type": "object",
"properties": {"order_id": {"type": "string"}},
"required": ["order_id"],
},
}]
handlers = {"order_status": order_status}
messages = [{"role": "user", "content": "Where is order A1042?"}]
reply = client.messages.create(model="claude-opus-5-5", max_tokens=1024,
tools=tools, messages=messages)
if reply.stop_reason == "tool_use":
results = [{"type": "tool_result", "tool_use_id": block.id,
"content": json.dumps(handlers[block.name](**block.input))}
for block in reply.content if block.type == "tool_use"]
messages += [{"role": "assistant", "content": reply.content},
{"role": "user", "content": results}]
reply = client.messages.create(model="claude-opus-5-5", max_tokens=1024,
tools=tools, messages=messages)
MCP. The same function becomes a tool on a server that any MCP client can discover. With version 2 of the official Python SDK, the input schema comes from the type hints and the description from the docstring.20
from mcp.server import MCPServer
from orders import order_status
mcp = MCPServer("orders")
mcp.tool()(order_status)
if __name__ == "__main__":
mcp.run(transport="streamable-http")
A2A. The caller never sees order_status. It sees an agent that answers questions about orders, described by an Agent Card.
{
"name": "Order support agent",
"description": "Answers questions about orders, deliveries and returns.",
"version": "1.0.0",
"supportedInterfaces": [
{"url": "https://agents.example.com/a2a", "protocolBinding": "JSONRPC", "protocolVersion": "1.0"}
],
"capabilities": {"streaming": true},
"defaultInputModes": ["text/plain"],
"defaultOutputModes": ["text/plain", "application/json"],
"skills": [{
"id": "order-status",
"name": "Order status",
"description": "Finds an order and explains where it is and when it should arrive.",
"tags": ["orders", "delivery"],
"examples": ["Where is order A1042?"]
}]
}
A client agent then sends a request in plain language, with an A2A-Version: 1.0 header and its credentials.
{
"jsonrpc": "2.0",
"id": 1,
"method": "SendMessage",
"params": {
"message": {
"messageId": "9f2c4e1a-7b3d-4c8e-a6f0-2d5b8e1c3a47",
"role": "ROLE_USER",
"parts": [{"text": "Where is order A1042, and can it still go to my office instead?"}]
}
}
}
The remote agent might call order_status through function calling or through an MCP server of its own, ask which office through an input-required state, and put the answer on a completed task.7 A production Agent Card would also declare its security schemes.
In the first two versions the order_id comes from the model, so the code has to check that the order belongs to the signed-in user. OpenAI’s function-calling guide goes further and advises against asking the model for arguments your code already knows, using an order ID as its example.1 The MCP security guidance makes the same point about handles a server issues: holding one is no proof of who you are.21
Where MCP and A2A stand as of 9 October 2026
| As of 9 October 2026 | MCP | A2A |
|---|---|---|
| Current specification | 2026-07-28, stable since 28 July 2026 | 1.0.1, released 28 May 2026; 1.0.0 on 12 March 2026 |
| Governance | Agentic AI Foundation since 9 December 2025, contributed by Anthropic | Linux Foundation since 23 June 2025; Growth Stage project at the Agentic AI Foundation since 27 August 2026 |
| Latest stable official SDKs | TypeScript 2.3.1, Python 2.3.0, Go 1.8.0 and C# 2.2.0, the four Tier 1 SDKs | Python 1.2.2, JavaScript 1.3.0, Go 2.6.0 and Java 1.4.0; .NET at 1.0.0-preview2; Rust on 0.x releases |
| Adoption, as reported by each project | Close to half a billion SDK downloads a month (July 2026); more than 10,000 published servers (December 2025) | More than 150 backing organisations; native support in Google Cloud, AWS Bedrock AgentCore Runtime and Azure AI Foundry (August 2026) |
The versions come from each SDK’s GitHub releases,2223 and the governance and adoption details from the projects and the Linux Foundation.2425616
MCP’s 2026-07-28 revision removed the initialize handshake and protocol-level sessions, so any server instance can answer any request.18 It deprecated Roots, Sampling, Logging and Dynamic Client Registration, none of which can be removed before the first revision released on or after 28 July 2027.19 All four Tier 1 SDKs supported the revision on release day, with Rust in beta.24 Our stateless MCP migration guide covers what breaks and how to migrate.
Clients are moving at different speeds. Claude Code has negotiated 2026-07-28 by default with direct HTTP servers on every install type since version 2.1.274 on 17 September, and with local stdio servers since 2.1.292 on 6 October. Since 2.1.295 on 8 October it does the same for claude.ai connectors on installs that fetch no feature flags.26 Cursor’s staff said on 21 September that Cursor speaks 2025-11-25 and earlier, and on 25 September that there was no timeline for the new revision.27 We found no OpenAI documentation that names the revision ChatGPT negotiates. A remote MCP server should keep answering 2025-11-25 clients for now.
Of the official A2A SDKs, Go shipped support for the 1.0 specification first, on 17 March, followed by Python on 20 April, Java on 10 June and JavaScript on 22 July.2823 A2A joined the Agentic AI Foundation on 27 August as a Growth Stage project, alongside MCP, goose and AGENTS.md. The adoption figures in the table come from that announcement, so read them as the project’s own claims.16
The “do you even need MCP?” debate
The sharpest criticism of MCP comes from people who build and use coding agents. A model with a shell already knows many command-line tools, can read --help when it needs to, and can pipe one tool’s output into the next without the data passing through its context. Armin Ronacher argued in July 2025 that MCP isn’t truly composable, demands too much context, and is less repeatable than having the model write code.29 Simon Willison wrote in October 2025 that almost anything he could do with an MCP server could be done with a CLI tool, and that a skill costs a few dozen tokens until it’s used.30 In November 2025 Mario Zechner replaced browser MCP servers with a few Node.js scripts and a README that his agent reads on demand.31
Zechner and Anthropic both measured what tool definitions cost before a conversation starts.
| Loaded before the first message | Tokens | Measured by |
|---|---|---|
| README for Zechner’s own browser scripts | 225 | Mario Zechner, November 2025 |
| Playwright MCP server, 21 tools | 13,700 | Mario Zechner, November 2025 |
| Chrome DevTools MCP server, 26 tools | 18,000 | Mario Zechner, November 2025 |
| GitHub MCP server, 35 tools | About 26,000 | Anthropic, November 2025 |
| GitHub, Slack, Sentry, Grafana and Splunk servers, 58 tools | About 55,000 | Anthropic, November 2025 |
The servers have changed since these were measured, so treat them as orders of magnitude.3132 Function calling itself adds little. When tools are present, Anthropic adds a 286-token system prompt for Claude Opus 5.5 as of 9 October 2026, and both OpenAI and Anthropic bill the definitions as input tokens.21 OpenAI suggests keeping fewer than 20 functions available at the start of a turn, and Google’s guide says 10 to 20 tools at most.13 One browser MCP server on its own is already past that.
Most of the MCP side’s answer has come from clients loading tools lazily. By the vendors’ own figures, Anthropic’s tool search cut token use by 85% in its example, and Cursor’s dynamic context discovery cut total agent tokens by 46.9% in an A/B test of runs that called an MCP tool.3233 OpenAI’s Responses API can defer MCP tools behind tool search on gpt-5.4 and later models, and Claude Code does the same for a server whose config sets alwaysLoad: false.13126
Code execution is the other answer. Cloudflare’s Code Mode turns MCP tools into a TypeScript API and has the model write code against it, on the argument that models are better at writing code that calls MCP than at calling MCP directly. Cloudflare still credits MCP with a uniform way to connect to an API, learn about it and get authorised.34 Anthropic described the same pattern, with an example workflow falling from 150,000 tokens to 2,000, and noted that agent-written code needs a sandbox with resource limits and monitoring.35
The case for MCP is strongest where there is no shell. A user in claude.ai, ChatGPT or a mobile app can’t install a CLI, and a hosted service used by many people needs per-user sign-in, permissions checked on the server and an audit trail. Ben Lorica’s July 2026 summary of the debate lands there. It also points out that giving an agent raw shell access without sandboxing, credential isolation and approval gates is the CLI approach’s own security problem.36 Even Ronacher wrote that MCP is “actually pretty great when it works”.29
The same reasoning answers MCP vs API. An MCP server is usually a thin layer over an API you already run, and it replaces neither the API nor its permission checks. It adds descriptions written for models, discovery at runtime and an OAuth flow that Claude, ChatGPT, Cursor and VS Code already implement. The 2026-07-28 revision also copies the method and tool name into HTTP headers, which InfoQ framed as letting gateways apply the controls they use for other APIs.37 If your own agent is the only caller and has a shell or an HTTP client, a CLI or the plain API is usually cheaper.
Security risks at each layer
Function calling
The model only proposes calls, and your code decides whether to run them. Treat the function name and arguments as untrusted input, because any text the model reads, such as a web page, an email or a tool result, can steer what it proposes. Validate arguments against the schema, and use the vendors’ schema enforcement where it exists: strict: true at OpenAI and Anthropic, and the validated mode in Gemini.123 Then check authorisation in code, as the order example above does. Keep downstream credentials in your application and out of the model’s context.
MCP
MCP brings in a third party whose text the model trusts. Invariant Labs described tool poisoning in April 2025, where instructions hidden in a tool description are followed by the model and never shown to the user. The same write-up described rug pulls, where a server changes its descriptions after you approve it, and shadowing, where one server’s description changes how the agent uses another server’s tools.38 The pattern has since appeared in the wild. On 10 August 2026 one GitHub account opened 23 pull requests in 74 minutes that added an MCP server whose descriptions, after its third tool call, told agents to look for SSH keys and cloud credentials and to keep this from the user. None was merged.39 The defence is to fingerprint tool definitions when a person approves them and to ask again when they change. Our write-up on agent containment has the code.
Authentication is the other half. A remote MCP server is an OAuth resource server. It must accept only tokens issued for it, and must not pass a client’s token through to the APIs behind it.15 The security guidance also covers confused-deputy attacks through proxy servers, SSRF during OAuth discovery, and local servers that run with the user’s privileges.21 Clients must treat tool annotations, such as a read-only hint, as untrusted unless the server itself is trusted, so enforce permissions on the server.4 OpenAI’s Responses API asks for approval before each MCP call by default and recommends official servers run by the service provider.13 Our post on one MCP server across Claude, ChatGPT, Cursor and VS Code covers the OAuth details client by client.
A2A
An A2A peer is opaque by design. You can’t read its tools or prompts, so there are no descriptions to pin, and trust rests on identity, authorisation and what you let its replies do. The specification requires encrypted transport in production and authentication on every request. It lets an agent sign its Agent Card with a JSON Web Signature, says cards shouldn’t contain credentials, and tells agents that send push notifications to validate webhook URLs against SSRF.7
Palo Alto Networks’ Unit 42 showed in October 2025 what a malicious peer can do. In a proof of concept built with Google’s Agent Development Kit, a remote agent used harmless-looking follow-up questions to extract a client agent’s system instructions and tool schemas. It then got the client agent to make an unauthorised stock trade with its own tools. Unit 42 called this agent session smuggling and said it exploits implicit trust between agents, with no vulnerability in A2A itself.40 Its mitigations suit any agent that talks to outsiders. Confirm sensitive actions through a channel the model can’t influence, verify remote agents, check that the session still serves the user’s original request, and show users what remote agents asked for.
Which one your product needs: a decision rule
Answer each question in turn. Most products stop at the first.
- Is your own application the only caller of your tools? Use function calling, with the schemas in your code. Keep the active set small, at fewer than 20 functions per turn by OpenAI’s guidance and 10 to 20 by Google’s.
- Should people use your product from Claude, ChatGPT, Cursor or VS Code, or should customers’ agents call it? Build a remote MCP server over Streamable HTTP with OAuth, and keep answering 2025-11-25 clients until your own logs show they’re gone.
- Does your agent need many third-party tools, or tools that change without a redeploy? Make it an MCP client or use your model vendor’s MCP connector, and switch on tool search or deferred loading once the list passes about 20 tools.
- Is it a coding agent with a shell in a sandbox? Try CLI tools and a short README first. Add MCP for services that need per-user OAuth or have no CLI.
- Do you hand whole tasks to an agent that another team or company runs, with its own model and data? Use A2A, with signed Agent Cards and authentication on every request. If both agents live in your own codebase, call one from the other as a function and skip the protocol.
Before you ship any of them:
- Enforce permissions in the code that runs the tool, and treat model-chosen arguments, tool descriptions and remote agents’ replies as untrusted.
- Fingerprint MCP tool definitions at approval and ask again when they change.
- Require a person’s confirmation for anything that writes, pays, deletes or sends.
- Log every call with the identity and credentials it used.
-
OpenAI, “Function calling”, https://developers.openai.com/api/docs/guides/function-calling ↩↩↩↩↩↩↩
-
Anthropic, “Tool use with Claude”, https://platform.claude.com/docs/en/agents-and-tools/tool-use/overview ↩↩↩↩
-
Google, “Function calling with the Gemini API”, https://ai.google.dev/gemini-api/docs/function-calling ↩↩↩↩
-
MCP specification 2026-07-28, “Tools”, https://modelcontextprotocol.io/specification/2026-07-28/server/tools ↩↩
-
MCP specification 2026-07-28, “Transports”, https://modelcontextprotocol.io/specification/2026-07-28/basic/transports ↩↩
-
Linux Foundation, “Linux Foundation Launches the Agent2Agent Protocol Project to Enable Secure, Intelligent Communication Between AI Agents”, 23 June 2025, https://linuxfoundation.org/press/linux-foundation-launches-the-agent2agent-protocol-project-to-enable-secure-intelligent-communication-between-ai-agents ↩↩
-
A2A Protocol, “Agent2Agent (A2A) Protocol Specification”, version 1.0, https://a2a-protocol.org/latest/specification/ ↩↩↩↩
-
Model Context Protocol, “Build an MCP client”, https://modelcontextprotocol.io/docs/develop/build-client ↩
-
Anthropic, “Authentication for connectors”, https://claude.com/docs/connectors/building/authentication ↩
-
OpenAI, “Authentication”, Apps SDK documentation, https://developers.openai.com/apps-sdk/build/auth ↩
-
Cursor, “Model Context Protocol (MCP)”, https://cursor.com/docs/context/mcp ↩
-
Visual Studio Code, “Add and manage MCP servers in VS Code”, https://code.visualstudio.com/docs/agent-customization/mcp-servers ↩
-
OpenAI, “MCP servers”, https://developers.openai.com/api/docs/guides/tools-connectors-mcp ↩↩↩↩
-
Anthropic, “MCP connector”, https://platform.claude.com/docs/en/agents-and-tools/mcp-connector ↩
-
MCP specification 2026-07-28, “Authorization”, https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization ↩↩
-
A2A Protocol blog, “A New Chapter for A2A: Joining the Agentic AI Foundation”, 27 August 2026, https://a2a-protocol.org/latest/blog/2026/08/27/a-new-chapter-for-a2a-joining-the-agentic-ai-foundation/ ↩↩↩
-
A2A Protocol, “A2A and MCP”, https://a2a-protocol.org/latest/topics/a2a-and-mcp/ ↩↩
-
MCP specification 2026-07-28, “Key Changes”, https://modelcontextprotocol.io/specification/2026-07-28/changelog ↩↩
-
MCP specification 2026-07-28, “Deprecated Features”, https://modelcontextprotocol.io/specification/2026-07-28/deprecated ↩↩
-
MCP Python SDK, README for v2.3.0, https://github.com/modelcontextprotocol/python-sdk ↩
-
MCP specification 2026-07-28, “Security Best Practices”, https://modelcontextprotocol.io/specification/2026-07-28/basic/security_best_practices ↩↩
-
GitHub release pages of the official MCP SDKs, checked on 9 October 2026, https://github.com/modelcontextprotocol ↩
-
GitHub release pages of the official A2A SDKs, checked on 9 October 2026, https://github.com/a2aproject ↩↩
-
Model Context Protocol blog, “The 2026-07-28 Specification”, 28 July 2026, https://blog.modelcontextprotocol.io/posts/2026-07-28/ ↩↩
-
Linux Foundation, “Linux Foundation Announces the Formation of the Agentic AI Foundation”, 9 December 2025, https://www.linuxfoundation.org/press/linux-foundation-announces-the-formation-of-the-agentic-ai-foundation ↩
-
Claude Code changelog, entries for versions 2.1.274, 2.1.287, 2.1.292 and 2.1.295, https://code.claude.com/docs/en/changelog ↩↩
-
Cursor community forum, “MCP client cannot connect to modern-only 2026-07-28 Streamable HTTP servers”, 21 to 25 September 2026, https://forum.cursor.com/t/mcp-client-cannot-connect-to-modern-only-2026-07-28-streamable-http-servers-legacy-initialize-rejected/172536 ↩
-
A2A specification releases on GitHub, https://github.com/a2aproject/A2A/releases ↩
-
Armin Ronacher, “Tools: Code Is All You Need”, 3 July 2025, https://lucumr.pocoo.org/2025/7/3/tools/ ↩↩
-
Simon Willison, “Claude Skills are awesome, maybe a bigger deal than MCP”, 16 October 2025, https://simonwillison.net/2025/Oct/16/claude-skills/ ↩
-
Mario Zechner, “What if you don’t need MCP at all?”, 2 November 2025, https://mariozechner.at/posts/2025-11-02-what-if-you-dont-need-mcp/ ↩↩
-
Anthropic, “Introducing advanced tool use on the Claude Developer Platform”, 24 November 2025, https://www.anthropic.com/engineering/advanced-tool-use ↩↩
-
Cursor, “Dynamic context discovery”, 6 January 2026, https://cursor.com/blog/dynamic-context-discovery ↩
-
Cloudflare, “Code Mode: the better way to use MCP”, 26 September 2025, https://blog.cloudflare.com/code-mode/ ↩
-
Anthropic, “Code execution with MCP: Building more efficient agents”, 4 November 2025, https://www.anthropic.com/engineering/code-execution-with-mcp ↩
-
Ben Lorica, Gradient Flow, “What happens when your agent can touch money”, 7 July 2026, https://gradientflow.substack.com/p/i-changed-my-mind-about-how-agents ↩
-
InfoQ, “MCP Goes Stateless, and Developers Ask Whether That Just Makes it an API Again”, 12 August 2026, https://www.infoq.com/news/2026/08/mcp-stateless-gateway/ ↩
-
Invariant Labs, “MCP Security Notification: Tool Poisoning Attacks”, 1 April 2025, https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks ↩
-
Pillar Security, “Deadbugz: Currently Active MCP Supply-Chain Campaign”, 12 August 2026, https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign ↩
-
Unit 42, Palo Alto Networks, “When AI Agents Go Rogue: Agent Session Smuggling Attack in A2A Systems”, 31 October 2025, https://unit42.paloaltonetworks.com/agent-session-smuggling-in-agent2agent-systems/ ↩
Frequently asked questions
What is the difference between MCP and A2A?
MCP connects an AI application to tools and data. A client lists a server’s tools and calls them one at a time. A2A connects agents to each other, so one agent can send another a task that the remote agent completes with its own model and tools. The A2A project describes them as complementary, and one system can use both.
What is the A2A protocol?
A2A (Agent2Agent) is an open protocol that Google introduced in April 2025 and that now belongs to the Agentic AI Foundation at the Linux Foundation. Agents publish an Agent Card describing their skills, then exchange messages and tasks over JSON-RPC, gRPC or HTTP. Version 1.0 was released on 12 March 2026.
What is the difference between MCP and function calling?
Function calling is a model API feature: the model returns a structured request and your code runs it. MCP is a protocol for putting tools in a server that any MCP client, such as Claude, ChatGPT, Cursor or VS Code, can discover and call. The MCP client still passes those tools to the model through function calling.
Do I need MCP if I already have an API?
Only if AI clients you don’t control should use it. An MCP server usually wraps an existing API and adds tool descriptions written for models, discovery at runtime and a standard OAuth sign-in. If your own application is the only caller, function calling against your API is enough.
Can CLI tools replace MCP for AI agents?
For coding agents with a shell, often yes. In Mario Zechner’s measurements a README for his browser scripts cost 225 tokens, against 13,700 for the Playwright MCP server’s tool list. CLIs don’t help users in chat apps without a shell, or hosted services that need per-user OAuth and server-side permission checks.
Does A2A replace MCP?
No. A2A covers agents handing tasks to other agents, and MCP covers an agent’s access to tools and data. Both are projects of the Agentic AI Foundation at the Linux Foundation, A2A since 27 August 2026.
Building something like this?
9io is a small team of senior engineers with a fractional CTO, and we work by the hour. Send us a note about your product. The reply comes from the person who'd do the work.