Custom MCP server development: AI agents securely in your stack

The Model Context Protocol (MCP) has quickly become the de facto standard for connecting AI agents to internal tools, data sources and business systems. Appfront builds custom MCP servers that give Claude, Cursor, Cline and your own agents access to your CRM, ERP, data warehouse, documents and operational actions in a standardised, secure and scalable way, without writing a separate integration for each client.

Model Context Protocol JSON-RPC 2.0 Tools, resources, prompts OAuth 2.1 Python & TypeScript SDK
Schedule an MCP architecture session View use cases
MCP-host Claude / Cursor / Cline MCP-server tools · resources · prompts JSON-RPC CRM ERP Docs DWH

What exactly is an MCP server?

The Model Context Protocol is an open standard that Anthropic published in November 2024. MCP defines how an LLM application (the host) communicates with external systems: in a structured, discoverable way, without the host needing to know how those systems work under the hood.

An MCP server exposes three kinds of capabilities to the host. Tools are actions the model can invoke, such as creating a ticket, running a query or sending an email. Resources are read sources, comparable to REST GET endpoints, such as a document, a table row or a user profile. Prompts are reusable instruction templates that the server offers to the host for common workflows.

The analogy often used within the MCP community is "USB-C for AI tooling": one standardised socket to which hundreds of tools and hundreds of hosts can connect without depending on each other. For organisations, this means a well-built MCP server can serve for years, even if you later move from Claude to another LLM vendor or agent framework. Read more in the official specification at modelcontextprotocol.io.

Communication runs over JSON-RPC 2.0. Local MCP servers usually run over stdio, where the host spawns the server process and communicates through standard input and output. Remote MCP servers use Server-Sent Events (SSE) or streamable HTTP, with OAuth 2.1 for authentication. Capability negotiation at the start of a session ensures the host and server only use the features both support, so backwards compatibility is built into the protocol.

Why MCP, rather than a plain API integration per agent?

Many teams start their AI journey by hard-coding function calling into the prompt or writing a LangChain tool for each integration. That works for a single agent, but becomes unmanageable as soon as you want to support multiple clients or multiple LLM providers.

One integration, many hosts

With MCP, you build your business logic once. Claude Desktop, Cursor, Cline, Continue.dev, Zed and custom agents all talk to the same server. You can let a developer use Cursor and a sales colleague use Claude Desktop, while both see the same tools and data.

No vendor lock-in

Function-calling formats differ between LLM vendors. MCP is independent of the model provider. Are you migrating from Anthropic to another vendor or adding a local open model? Your MCP server keeps running.

Security in one place

Authentication, authorisation, scopes, rate limiting and audit logging live in the server. You don't need to monitor, for each agent, which prompts could trigger which sensitive action; the server guards the gate.

Discoverable capabilities

The host doesn't need to know hard-coded which tools are available. The server publishes its capabilities via list_tools and list_resources, and the host adapts its behaviour automatically. New tools become available immediately without a client update.

Scalable across teams

You can run a separate MCP server per domain — one for finance, one for HR, one for engineering — and let hosts select per user which ones to load. Composable, not monolithic.

Open standard

MCP is open source under the MIT licence. SDKs for Python, TypeScript, C#, Java and Kotlin are official; the community contributes SDKs for Go, Rust and other languages. No proprietary dependency on a single vendor.

Architecture: host, client and server

MCP follows a classic client-server model with a three-part division that is worth understanding before you design an implementation.

The MCP host is the application the end user works with — Claude Desktop, Cursor, Cline or a custom agent. The host manages the LLM, the user interface and the user session. For each MCP server the host wants to use, it instantiates a separate MCP client. That client is the plumbing layer that serialises and deserialises JSON-RPC messages.

The MCP server is what Appfront builds for you. It is a process that publishes tools, resources and prompts and executes them on request. The server is stateless between requests — all context comes with the call — which makes horizontal scaling straightforward.

When a session starts, the host and server carry out a capability negotiation. Both parties state which protocol version and which features they support, such as tools, resources, prompts, sampling, roots or logging. Only then does the actual communication begin.

┌──────────────────────┐ │ MCP host │ │ (Claude / Cursor) │ │ ┌────────────────┐ │ │ │ MCP client │ │ │ └───────┬────────┘ │ └──────────┼───────────┘ │ JSON-RPC 2.0 stdio / SSE │ ┌──────────┼───────────┐ │ ┌───────▼────────┐ │ │ │ MCP server │ │ │ │ • tools │ │ │ │ • resources │ │ │ │ • prompts │ │ │ └────────────────┘ │ │ │ │ Auth · scopes · │ │ audit · rate-limit │ └──────────┬───────────┘ │ ┌───────┼───────┐ │ │ │ CRM Docs Data warehouse

What a custom MCP server can do for you

A well-designed MCP server is the bridge between your LLM front end and everything already running in your landscape. Below are six typical capability categories we implement for clients.

Querying business data

Read from your CRM, ERP, ticketing system, data warehouse or CMS. With scope-based permissions, query templates and row-level security, an agent can safely query departmental or customer data without the risk of overreach.

Exposing documents

A resource offering that surfaces manuals, contracts, policy documents or Confluence pages. The agent reads them only when relevant, with no pre-filled context and no context-limit problems.

Operational actions

Create tickets in Jira or ServiceNow, schedule emails, book calendar meetings, generate payment links, trigger deployments: write tools that work in line with your approval flow.

Legacy bridge

SOAP services, IBM mainframes, AS/400s and other older systems get a modern, AI-accessible face through a single MCP server. The server translates LLM-friendly calls into legacy protocols.

Workflow templates as prompts

Frequently used instruction patterns, such as an onboarding checklist, an incident response flow or a sales discovery script, are published as MCP prompts. End users are served them in the host UI.

Domain-specific calculations

Premium calculations, valuation models, procurement comparisons, capacity planning: anything you would rather handle in deterministic code than in an LLM prompt is exposed as a tool.

How Appfront builds your MCP server

We work in iterative sprints, with a working prototype within a few weeks and a production deployment with monitoring within one to three months, depending on scope.

01
Use case discovery
In a working session, we inventory the tools, resources and prompts your agents need. We map the source systems, identify authentication patterns and determine which actions are read and which are write.
02
Schema and security design
We define pydantic or zod schemas for each tool, specify OAuth scopes and authorisation rules, and design the audit log format. Rate limits and tool permissions are also settled at this stage.
03
Build and integration
Implementation with the official MCP Python or TypeScript SDK (often FastMCP for a quick bootstrap), connected to your source systems. Includes unit tests, integration tests and end-to-end tests from Claude Desktop.
04
Deployment and monitoring
Container deployment on your cloud (Docker/Kubernetes) or on-premise. Logging via OpenTelemetry, observability in Grafana or Datadog, alerting on tool failures, and handover documentation for your operations team.
Not yet sure about a large project?

Test your idea first: a working prototype in 1 day

With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.

Explore OneDayBuild →

Technology and SDKs

We work with the official MCP stack and additional libraries that cover the operational side of a production-grade server.

MCP server frameworks

MCP Python SDK FastMCP MCP TypeScript SDK Anthropic agent SDK pydantic-ai JSON-RPC 2.0 SSE / streamable HTTP stdio transport

FastMCP (part of the official Python SDK) speeds up server bootstrapping to a few dozen lines of code for a first tool. For TypeScript projects we use the official @modelcontextprotocol/sdk.

Operational stack

Docker Kubernetes OAuth 2.1 PKCE OpenTelemetry Grafana / Datadog PostgreSQL Redis GitHub Actions / GitLab CI FastAPI / Express

For remote MCP servers we use OAuth 2.1 with PKCE, optionally via your existing Identity Provider (Auth0, Okta, Azure AD). We stream audit events to your SIEM or a dedicated logging bucket.

Concrete use cases

Four scenarios we regularly implement, for inspiration for your own MCP roadmap.

Enterprise Claude with internal wiki access

An MCP server on top of Confluence, Notion or a custom DMS, so that Claude Desktop acts as a company-wide AI assistant for your staff with permanent access to policies, processes and manuals. Resources are scoped by department, and write tools are limited to draft creation.

DevOps AI: Kubernetes and GitHub via MCP

Tools for cluster status, pod logs, deployment rollouts and GitHub pull request reviews. Engineers use Cursor or Cline as an operations cockpit. Write actions (deployments, rollbacks) sit behind a human-in-the-loop confirmation flow.

Customer service agent: tickets and CRM combined

A single MCP server connects Zendesk or Freshdesk to your CRM. The agent sees ticket history, customer status and contractual agreements in one call, and can suggest personalised replies or create structured escalations.

Data warehouse MCP for analysts

An MCP server on top of Snowflake, BigQuery or Postgres, with read-only query tools, schema resources and saved query prompts. Business analysts ask Claude questions in natural language, which generates safe SQL within the permitted scope.

Security and governance

An MCP server gives an AI agent access to production data. That warrants a security baseline on the same level as your other critical integrations: no less, and certainly no less rigorous.

Authentication and authorisation

OAuth 2.1 with PKCE for remote servers, optionally via your Identity Provider. A separate scope per tool and row-level or attribute-based access control per resource. Tokens expire automatically, and refresh flows follow the specification.

Audit logging

Every tool call and resource read is logged with user ID, scope, timestamp, parameters (redacted where necessary) and outcome. Logs stream to your SIEM. Establishing who did what and when can be forensically reproduced.

Human-in-the-loop for write tools

Write actions with irreversible consequences receive a confirmation step in the host by default. The LLM can make suggestions, and the user confirms. For some flows we also provide asynchronous approval via a second channel.

Data residency and GDPR

MCP servers run by default in EU regions or on your own infrastructure. Where possible, PII fields are only decrypted at the point of use. Data processing agreements and DPIA input are provided as standard at handover.

Frequently asked questions about MCP servers

What exactly is the Model Context Protocol (MCP)?
MCP is an open protocol that Anthropic published in November 2024. It standardises how LLM applications (so-called MCP hosts) connect in a structured way to external tools, data and knowledge sources via MCP servers. Communication runs over JSON-RPC 2.0, via stdio or Server-Sent Events. You can think of it as a USB-C standard for AI tooling: one protocol, many clients.
Why build an MCP server instead of direct API integrations for each AI agent?
With an MCP server you build a single integration that works for any MCP-compatible host. Claude Desktop, Cursor, Cline, Continue.dev and custom agents all gain access to the same tools, resources and prompts without you integrating again for each client. This avoids vendor lock-in and fragmented authentication.
Which programming language does Appfront use for MCP servers?
We work mainly with the official Python SDK (mcp and FastMCP) and the TypeScript SDK. The best choice depends on your existing stack: a data warehouse MCP often runs more comfortably in Python with pydantic typing, while a Node microservice integration fits more naturally in TypeScript.
How is an MCP server secured?
An MCP server should never grant unauthenticated access to business data. We implement OAuth 2.1 or API key flows, scope-based permissions per tool, audit logging of all calls, and rate limiting. For remote MCP servers we use TLS and optionally mutual TLS. Tool permissions are separate from resource permissions, so you can protect read-only and write actions independently.
Can an MCP server both read from and write to our systems?
Yes. MCP defines three primitives: tools (carry out actions, including writes), resources (read data, similar to a REST GET) and prompts (reusable instruction templates). You decide which authorisation applies to each primitive. A common pattern is broad read access to resources, with tightly scoped write tools behind explicit user confirmation.
Does an MCP server only work with Claude, or with other LLMs too?
The Model Context Protocol is open and LLM-agnostic. Alongside Anthropic's Claude (Desktop and the API with the agent SDK), Cursor, Cline, Continue.dev, Zed and a growing number of open-source agent frameworks support MCP clients, among others. You build one server and connect it to several LLM front ends.
How does MCP compare with OpenAI function calling or LangChain tools?
Function calling and LangChain tools are vendor- or framework-specific. MCP is a transport and discovery protocol that is independent of any particular LLM provider. An MCP server can call function-calling handlers internally, but it exposes them in a standardised way so that they appear in any MCP host.
How long does an MCP server implementation take?
A proof of concept with a few tools and a read resource typically takes one to two weeks. A production-grade MCP server with OAuth, audit logging, monitoring and integrations across multiple systems typically takes six to twelve weeks, depending on the number of tools and the complexity of the underlying systems.

Ready to have an MCP server built for your stack?

Discuss your use case with our AI engineers. Together we will outline which tools, resources and prompts your agents need, and which architecture and security baseline suit them. No obligation and no commitment.

Schedule an MCP architecture consultation

Edit content