<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Jonathan Blessing</title>
    <description>The latest articles on DEV Community by Jonathan Blessing (@jonathanblessing).</description>
    <link>https://dev.to/jonathanblessing</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3837093%2F1721058f-9b34-4495-bd20-495c65dca73e.png</url>
      <title>DEV Community: Jonathan Blessing</title>
      <link>https://dev.to/jonathanblessing</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/jonathanblessing"/>
    <language>en</language>
    <item>
      <title>How to Choose an MVP Development Partner – and When to Build or Buy Instead</title>
      <dc:creator>Jonathan Blessing</dc:creator>
      <pubDate>Mon, 21 Sep 2026 10:06:23 +0000</pubDate>
      <link>https://dev.to/launchdayadvisors/how-to-choose-an-mvp-development-partner-and-when-to-build-or-buy-instead-42cl</link>
      <guid>https://dev.to/launchdayadvisors/how-to-choose-an-mvp-development-partner-and-when-to-build-or-buy-instead-42cl</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;In brief:&lt;/strong&gt; An MVP development partner is hired to ship the smallest product that tests a business hypothesis – typically a 4–8 week engagement at $15K–$75K. Anything above $150K is a product, not an MVP. Skip user accounts, admin dashboards, payment processing beyond Stripe Checkout, and infrastructure that scales past 50 users – you need 10 good users, not 10,000 mediocre ones. Build internally with technical co-founders, buy with no-code for CRUD-heavy flows, partner when you need production-grade code or polish.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;An MVP development partner is an outside firm you hire to ship the smallest product that will test a business hypothesis – typically a 4–8 week engagement costing $15,000 to $75,000. Engagements above $150,000 are products, not MVPs. Choose one when you need speed and outside perspective more than you need permanent engineering headcount. The MVP itself has become the most misunderstood concept in product development. Founders use it to mean "version 1 of my product." Development agencies use it to mean "the smallest thing we can sell you." Neither definition is useful.&lt;/p&gt;

&lt;p&gt;An MVP is a learning instrument. It exists to test a hypothesis about your market as cheaply and quickly as possible. The output of an MVP is not software – it's validated knowledge about whether your customers will pay for what you're building. If your MVP doesn't produce a clear yes-or-no signal about a specific business hypothesis, it's not an MVP. It's just an underfunded product launch.&lt;/p&gt;

&lt;p&gt;This distinction matters enormously when you're deciding how to build it, who to build it with, and how much to spend. The right approach depends on what you need to learn, not what you want to ship.&lt;/p&gt;

&lt;h2&gt;
  
  
  What an MVP Actually Is
&lt;/h2&gt;

&lt;p&gt;An MVP tests one thing: will customers engage with this product in the way your business model requires? That's it. Everything else is secondary.&lt;/p&gt;

&lt;p&gt;For a SaaS product, that means proving target users will sign up, complete onboarding, and use the core feature repeatedly. You're not testing whether the product is beautiful or feature-complete – you're testing activation and retention. I worked with a productivity tool founder who spent eight weeks building a gorgeous dashboard before testing their core hypothesis (that users would actually adopt the tool daily). They learned in user testing that nobody cared about the dashboard. They cared about whether the core feature worked. Six weeks of polished UI was wasted effort.&lt;/p&gt;

&lt;p&gt;For a marketplace, the test is entirely different. Both sides of the two-sided market have to show up. I've seen marketplace founders build excellent supply-side experiences and then get zero demand, or vice versa. The MVP needs to prove you can achieve liquidity – that you can get enough sellers and buyers interested in using the same platform at the same time. This usually requires manual work on one side (you personally recruiting early sellers, or you as the first buyer) to jump-start the network.&lt;/p&gt;

&lt;p&gt;For an internal tool, the question is adoption. Employees have been using a spreadsheet for five years. Your job isn't to build something technically impressive – it's to build something they'll actually switch to. Many internal tool MVPs fail because they're technically sound but require a behavior change that the organization isn't ready to make. The MVP needs to prove the change is worth it.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Common Failure Mode&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Building a "full product" and calling it an MVP because it doesn't have all the features yet. If your MVP takes 6 months and costs $200K, it's not an MVP. It's a product that launched before it was ready – one of the recurring &lt;a href="https://launchdayadvisors.com/guides/common-mistakes-technology-partner-selection" rel="noopener noreferrer"&gt;decision errors that lead to re-selection&lt;/a&gt; inside the first year. Real MVPs take 4–8 weeks and cost $15K–75K depending on technical complexity.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The specifics depend on what you're testing, but here's what you can almost always skip: user accounts and authentication systems (use magic links or manually onboard people), admin dashboards (manage your MVP users manually via database), payment processing (Stripe Checkout or even manual invoicing), email notifications, mobile apps (responsive web is fine), and infrastructure that scales to thousands of users (you need 10 good ones, not 10,000 mediocre ones).&lt;/p&gt;

&lt;p&gt;What you absolutely need: the core value proposition – that one thing that makes someone choose your product over the status quo. You need enough polish that users evaluate the value, not the janky UX. And you need analytics to measure the specific behavior you're testing. Nothing else. Not "nice to have" features, not architectural elegance, not code quality that would impress your team. Just the core, measurable hypothesis.&lt;/p&gt;

&lt;p&gt;A fintech founder I worked with planned an MVP with full multi-tenant architecture, audit logging, and compliance features. They were planning to spend $200K over six months. The actual hypothesis was: "Do B2B customers prefer this specific approach to settlement?" We cut it down to a functional prototype that answered that one question in six weeks for $25K. They got their answer, iterated the approach based on feedback, and then built the real thing properly. The first MVP would have proven nothing except their perfectionism.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Flaunchdayadvisors.com%2Ffiles%2Fguides%2Fmvp-build-buy-partner.svg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Flaunchdayadvisors.com%2Ffiles%2Fguides%2Fmvp-build-buy-partner.svg" alt="MVP: Build vs. Buy vs. Partner" width="800" height="320"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;Build&lt;/th&gt;
&lt;th&gt;Buy&lt;/th&gt;
&lt;th&gt;Partner&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Best when&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Technical co-founders, straightforward tech, speed matters most&lt;/td&gt;
&lt;td&gt;Simple CRUD app, no-code tools work, accept rebuild later&lt;/td&gt;
&lt;td&gt;Technical complexity, need production code, clear hypotheses&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Cost&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;$0–15K (sweat equity + tools)&lt;/td&gt;
&lt;td&gt;$5K–25K (platform + your time)&lt;/td&gt;
&lt;td&gt;$15K–150K (development firm)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Timeline&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;2–6 weeks&lt;/td&gt;
&lt;td&gt;Days to 2 weeks&lt;/td&gt;
&lt;td&gt;4–16 weeks&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Build vs. Buy vs. Partner
&lt;/h2&gt;

&lt;p&gt;This is the fundamental decision. Each path has wildly different cost structures, timelines, and risk profiles – and each produces different problems downstream.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Build internally&lt;/strong&gt; makes sense when you have technical co-founders or a small engineering team already in place. You get maximum speed (no onboarding, no contracts, no negotiation), maximum control, and the codebase becomes your asset immediately. The technical team knows your product inside and out from day one.&lt;/p&gt;

&lt;p&gt;The trap is real though. If your technical team is also your founding team, building the MVP means those same people aren't talking to customers, closing sales, or validating the business model. Your engineers are spending time on deployment pipelines and database migrations instead of being available to react when customer feedback suggests a pivot. The best technical co-founders I've worked with recognize this tension explicitly and ruthlessly push for the simplest possible MVP – not the most technically elegant one.&lt;/p&gt;

&lt;p&gt;Choose this when you have technical founders with strong product judgment, your MVP doesn't require specialized technical expertise (ML, real-time infrastructure, etc.), and speed matters more than polish.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Buy (no-code/low-code)&lt;/strong&gt; has gotten genuinely good. Tools like Bubble, Webflow, Retool, and Airtable can build functional products in days instead of weeks. For many MVP categories – internal tools, simple marketplaces, landing-page-plus-backend, directory sites – no-code is the fastest path to an answer.&lt;/p&gt;

&lt;p&gt;But here's the reality: no-code works great until it doesn't. You'll hit platform limitations exactly when your product starts succeeding. I watched a marketplace founder validate their model perfectly on Bubble. Three months later, when they wanted to move to custom code and expand their feature set, the migration was painful and expensive – essentially a full rebuild. This is fine if you know going in that success means rebuilding. It's catastrophic if you assumed the no-code version would just evolve.&lt;/p&gt;

&lt;p&gt;Choose this when your MVP is straightforward (CRUD operations, standard workflows), you need to validate fast with zero engineering investment, and you explicitly accept that scaling beyond MVP will require a rewrite.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Partner with a development firm&lt;/strong&gt; makes sense when you need technical expertise you don't have in-house, when you need a level of polish that no-code can't match, or when you need code that can evolve into your real product without a full rewrite.&lt;/p&gt;

&lt;p&gt;The hard truth: most development agencies are not good at MVPs. They're optimized for building fully-scoped products with clear specifications and happy clients. MVP work requires a completely different mindset – the willingness to cut scope ruthlessly, ship imperfect code, and optimize for learning speed over code quality. Agencies that can't make this shift will build you something beautiful and over-engineered that takes three months and costs twice your budget to test one hypothesis.&lt;/p&gt;

&lt;p&gt;Choose this when your MVP requires genuine technical complexity (machine learning, real-time infrastructure, hardware integration – for AI specifically, see &lt;a href="https://launchdayadvisors.com/guides/how-to-select-an-ai-development-partner" rel="noopener noreferrer"&gt;how to select an AI development partner&lt;/a&gt;), when you need production-grade architecture that your team will build on top of, and when you have crystal-clear hypotheses to test.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Key Signal&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Ask potential MVP partners this question: "What would you cut from the scope?" If they agree with everything on your feature list, they're not the right partner. Good MVP developers are aggressive scope cutters. They'll push you to define the one thing your MVP needs to prove and strip out everything else. This is one of the &lt;a href="https://launchdayadvisors.com/guides/how-to-evaluate-a-technology-partner" rel="noopener noreferrer"&gt;evaluation signals that predict delivery&lt;/a&gt; better than portfolios do.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  What MVP Development Actually Costs
&lt;/h2&gt;

&lt;p&gt;Pricing for MVP development is wildly inconsistent because everyone's using "MVP" to mean something different. Here's what the money actually gets you at each tier.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;$5K–15K&lt;/strong&gt; gets you a proof of concept. This is a clickable prototype, a landing page with a signup flow, or a no-code implementation that demonstrates the core idea. It's enough to show to customers and measure interest. It's not a working product – it won't scale, it won't handle real usage, and it probably won't stay running for six months. But it's enough to prove customers care.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;$15K–50K&lt;/strong&gt; is where most startups actually test product-market fit. You get a working application with one core workflow, a basic UI that doesn't win design awards, and infrastructure that can support a few hundred users. The code is pragmatic, not elegant. It'll live for 4–8 weeks and then you'll decide: does this work or not? This is the sweet spot for learning fast.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;$50K–150K&lt;/strong&gt; is production-grade. This is a polished application with authentication, payment integration, responsive design, and architecture that your team can actually build on top of without a complete rewrite. The code will survive beyond MVP. It takes longer (8–16 weeks) because more care goes into sustainability. Choose this when your market expects quality (enterprise, healthcare, fintech), or when the technical requirements genuinely demand it. A SaaS company serving enterprises will need this tier. A marketplace testing liquidity might not.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;$150K+&lt;/strong&gt; is not an MVP – it's a product. If a development firm quotes you $150K to "test a hypothesis," they're building a full product. That might be the right decision for your situation. But be clear about what you're actually doing – and pick the &lt;a href="https://launchdayadvisors.com/guides/fixed-fee-vs-time-and-materials" rel="noopener noreferrer"&gt;pricing model&lt;/a&gt; that matches: fixed-fee makes sense when scope is locked, time-and-materials when the discovery is genuinely open.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Questions to Ask Yourself&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;What is the minimum I need to build to test my riskiest assumption? If the answer involves more than 3 core screens, you're probably building too much. What happens if the MVP succeeds? Do I need to rebuild, or can this codebase evolve? If you need production-grade code, budget accordingly. What happens if the MVP fails? How much am I willing to lose to find out?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Selecting an MVP Development Partner
&lt;/h2&gt;

&lt;p&gt;If you go the partner route, the evaluation criteria are different than selecting a full-scale development firm. Read &lt;a href="https://launchdayadvisors.com/guides/how-to-select-a-technology-partner" rel="noopener noreferrer"&gt;how to select a technology partner&lt;/a&gt; for the comprehensive framework, but here's what actually matters for MVP work.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Look for startup experience, not enterprise experience.&lt;/strong&gt; Enterprise development firms optimize for predictability, documentation, and protecting themselves from scope creep. MVP development is the opposite: speed, adaptability, and comfort with ambiguity. When you talk to a potential partner, ask them to walk through specific products they've taken from concept to market. Not features they've built for existing platforms. Not bespoke software for fortune 500 companies. Products. They should have examples of three to five MVPs they've shipped in the last year.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Evaluate their product judgment, not just their technical skills.&lt;/strong&gt; The best MVP partners will make you uncomfortable. They'll challenge your feature list and suggest simpler ways to test your hypothesis. They'll say "you don't need that yet" more often than "sure, we can build it." A partner who just builds everything you specify is a contractor. You need someone with product sense who'll push back.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Check their delivery pace.&lt;/strong&gt; Ask about their last three MVPs. How long from kick-off to deployed product? If the answer is 4–6 weeks, they know what they're doing. If it's 3–6 months, they're not building MVPs – they're building products slowly. That's a different thing entirely.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Understand the actual team.&lt;/strong&gt; MVP work succeeds with small, senior teams. Two experienced developers and a designer will ship faster and better than six junior developers every time. Ask specifically who will work on your project. Get their resumes. If they describe the team as "a delivery manager, two senior engineers, and four junior engineers," that's not an MVP team. That's overkill.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Clarify the architecture question.&lt;/strong&gt; After the MVP succeeds, what happens to the code? Can your internal team take over development? Is it designed to evolve or is it throwaway? The answer should align with your actual post-MVP plan. Some teams build "throw-it-away" MVPs because they know the learning will change everything. Others build MVPs on production-grade code because they plan to iterate continuously. Both are valid – just make sure you agree with your partner.&lt;/p&gt;

&lt;p&gt;See &lt;a href="https://launchdayadvisors.com/guides/reference-checks-technology-partners" rel="noopener noreferrer"&gt;reference checks for technology partners&lt;/a&gt; for how to validate these claims with real client references.&lt;/p&gt;

&lt;h3&gt;
  
  
  MVP Development Consultant vs. MVP Development Partner
&lt;/h3&gt;

&lt;p&gt;The two titles get used as if they were the same purchase. They are not. An MVP development partner builds: a firm you pay $15K–$75K to ship a working hypothesis test in 4–8 weeks. An MVP development consultant advises: someone who helps you decide what the hypothesis is, what to cut, and which partner to hire – and who is gone before any code is written. Consulting is sold as hourly time or a short scoped engagement; technologists charge &lt;a href="https://launchdayadvisors.com/guides/ai-strategy-consultant" rel="noopener noreferrer"&gt;$150–$300 an hour&lt;/a&gt;, and a search-and-selection engagement runs two to four weeks. It earns its fee when the build is large enough that a wrong bet is expensive – the same $50K line that applies to any &lt;a href="https://launchdayadvisors.com/guides/buyer-side-technology-advisor" rel="noopener noreferrer"&gt;buyer-side technology advisor&lt;/a&gt; – or when you cannot evaluate the partners yourself. It does not when no-code will do. And if the person selling "MVP consulting" also wants to build the MVP, you are talking to a partner with a nicer title.&lt;/p&gt;

&lt;h2&gt;
  
  
  MVP Development Partner Selection Criteria
&lt;/h2&gt;

&lt;p&gt;If the partner route is the right one, the selection is short – six checks, and a good partner clears them in the first call.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;They ask about the hypothesis before they quote.&lt;/strong&gt; An MVP tests one thing. A partner who prices the build without asking what you are trying to learn is pricing a product.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;They have shipped MVPs, at MVP prices, and can name them.&lt;/strong&gt; Four to eight weeks, $15K–$75K, with a founder who will take a call. Enterprise references are not the same evidence.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;They push scope out, not in.&lt;/strong&gt; The right partner's first instinct is to remove the admin dashboard and the user accounts. The wrong partner's instinct is to add a phase two.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The pitch team is the build team.&lt;/strong&gt; Named people, with the seniority to make product calls in a standup rather than a status meeting.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The codebase is yours and is legible.&lt;/strong&gt; Ask what the handoff looks like for a second team – documentation, tests, deployment. An MVP that only its builder can run is a hostage, not an asset.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;They tell you what they would not build.&lt;/strong&gt; A partner with no opinion about what to leave out has not built an MVP before.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;A quote above $150K fails the test before it starts – whatever it is, it is not an MVP.&lt;/p&gt;

&lt;h2&gt;
  
  
  Managing the MVP Engagement
&lt;/h2&gt;

&lt;p&gt;MVP engagements fail for different reasons than product builds. Understanding these patterns will save you from the most common disasters.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Scope creep disguised as "learning."&lt;/strong&gt; You test the MVP with five customers. Customer A wants feature X. Customer B wants feature Y. Customer C wants both plus feature Z. You feel like you're learning, so you build all of it. Now you've spent 12 weeks and $80K to build a product instead of running a focused experiment. The problem: you can't tell if the core hypothesis worked because you added everything else too. Discipline means deciding in advance: what signal will prove or disprove my hypothesis? Only features that directly address that question make it in.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Perfectionism from founders.&lt;/strong&gt; The MVP ships. The button alignment is slightly off. The loading state looks janky. The colors could be better. You want to fix it before showing users. Resist this instinct with everything you have. Real users don't care if your product is beautiful – they care whether it solves their problem. If you spend two weeks perfecting the UI before validating the core idea, you've burned money for nothing. This kind of premature optimization shows up consistently in our analysis of &lt;a href="https://launchdayadvisors.com/guides/why-technology-projects-fail" rel="noopener noreferrer"&gt;why technology projects fail&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Building for scale too early.&lt;/strong&gt; Your MVP needs to handle 10–50 users, not 10,000. If your development partner is discussing caching strategies, microservices, database replication, or performance optimization, they're solving the wrong problem. That work comes later, after you know people want what you're building.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Realistic MVP timeline.&lt;/strong&gt; This is what should actually happen: Week 1, align on the core hypothesis and define the user flow that proves or disproves it. Kick off development. Weeks 2–3, build the core functionality and test it internally. Week 4, put it in front of 5–10 real customers who match your target profile. Get feedback. Weeks 5–6, iterate based on what you learned and ship the improvements. Week 6–8, decision point. You have evidence now. Either the hypothesis holds (persevere), or it doesn't (pivot or kill). Either way, you have an answer.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Key Signal&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;At the end of the MVP engagement, you should be able to answer: "Do we have evidence that customers want this product enough to pay for it?" If the answer is yes, invest in building the real thing. If the answer is no, you've spent $15K–75K to avoid spending $500K on something nobody wants. That's a win.&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h3&gt;
  
  
  Related Guides
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/how-to-select-a-technology-partner" rel="noopener noreferrer"&gt;How to Select a Technology Partner&lt;/a&gt; – full evaluation framework for development partners&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/how-to-select-a-product-development-partner" rel="noopener noreferrer"&gt;How to Select a Product Development Partner&lt;/a&gt; – when you need judgment about what to build, not just build capacity&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/product-development-outsourcing" rel="noopener noreferrer"&gt;Product Development Outsourcing&lt;/a&gt; – the broader category MVPs sit inside&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/outsourcing-software-development-guide" rel="noopener noreferrer"&gt;Outsourcing Software Development&lt;/a&gt; – when and how to outsource&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/software-development-rfp" rel="noopener noreferrer"&gt;Software Development RFP Template&lt;/a&gt; – when the MVP scope is stable enough for a formal RFP&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/technology-vendor-due-diligence-checklist" rel="noopener noreferrer"&gt;Technology Vendor Due Diligence Checklist&lt;/a&gt; – comprehensive evaluation checklist&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/why-technology-projects-fail" rel="noopener noreferrer"&gt;Why Technology Projects Fail&lt;/a&gt; – failure patterns that apply to MVPs too&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/product-design-process" rel="noopener noreferrer"&gt;Product Design Process&lt;/a&gt; – the design thinking that should precede MVP development&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/ai-for-startups" rel="noopener noreferrer"&gt;AI for Startups&lt;/a&gt; – read this before adding AI to your MVP&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;What is an MVP development partner?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;An outside firm you hire to ship the smallest product that will test a business hypothesis – typically a 4–8 week engagement costing $15,000 to $75,000. They're optimized for speed over polish. Engagements above $150,000 are products, not MVPs.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How much should an MVP cost?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;$5,000–$15,000 for a clickable prototype. $15,000–$50,000 for a working app that can find product-market fit. $50,000–$150,000 for production-grade code that survives beyond MVP. Anything above $150,000 is a product, not an MVP.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How long should an MVP take to build?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;4–8 weeks for a real MVP. A clickable prototype in 2–3 weeks. A production-grade MVP in 8–16 weeks. If a partner quotes 3–6 months to build an MVP, they're building a product – which might be the right call, but don't confuse the two.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Build, buy, or partner for an MVP?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Build internally if you have technical co-founders and speed matters more than polish. Buy (no-code) for CRUD-heavy products where you accept a rewrite at scale. Partner when you need technical expertise, production-grade code, or polish that no-code can't match.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What should I skip when building an MVP?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;User accounts (use magic links), admin dashboards (manage users via database), payment processing (Stripe Checkout), email notifications, mobile apps (responsive web is fine), and infrastructure that scales past 50 users. You need 10 good users, not 10,000 mediocre ones.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How do I find a good MVP development partner?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Look for partners with 3–5 recent MVP shipments, not enterprise resumes. Ask what they would cut from your scope – good partners are aggressive scope cutters. Check delivery pace: 4–6 weeks from kickoff to deployed MVP means they know what they're doing.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;When should I not hire an MVP development partner?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;When your scope is vague and you haven't defined the hypothesis you're testing. When no-code could do the job. When you have technical co-founders who can ship in six weeks. When you want polish more than speed. Agency MVPs fail when you haven't decided what you're learning.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How do I choose an MVP development partner?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Six criteria: they ask what hypothesis the MVP tests before they quote; they have shipped MVPs in 4–8 weeks at $15K–$75K and can name them; they push scope out rather than in; the people in the pitch are the people who build; they hand over a codebase a second team could take on; and they tell you what they would not build. A partner who quotes above $150K is quoting a product, not an MVP.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is the difference between an MVP development consultant and an MVP development partner?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A partner builds the MVP – $15K–$75K over 4–8 weeks. A consultant advises on the hypothesis, the scope, and which partner to hire – by the hour ($150–$300 for technologists) or as a two-to-four-week selection engagement – and builds nothing. Worth paying for above roughly $50K of build; not when no-code will do.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://launchdayadvisors.com/guides/mvp-development-partner?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=guides" rel="noopener noreferrer"&gt;launchdayadvisors.com&lt;/a&gt;. Launch Day Advisors is a buyer-side advisory firm: we help companies select AI, software, and design partners, and we are paid only by the buyer.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>productmanagement</category>
      <category>startup</category>
      <category>career</category>
    </item>
    <item>
      <title>MCP App vs MCP Server vs Connector: Definitive Terminology Guide for 2026</title>
      <dc:creator>Jonathan Blessing</dc:creator>
      <pubDate>Fri, 18 Sep 2026 13:05:16 +0000</pubDate>
      <link>https://dev.to/launchdayadvisors/mcp-app-vs-mcp-server-vs-connector-definitive-terminology-guide-for-2026-4mo7</link>
      <guid>https://dev.to/launchdayadvisors/mcp-app-vs-mcp-server-vs-connector-definitive-terminology-guide-for-2026-4mo7</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;In brief:&lt;/strong&gt; MCP server is the engineering term – a JSON-RPC 2.0 process exposing tools, resources, and prompts. MCP app is the product term – the user-installable artifact built on top. Connector is what Claude calls an installed MCP app inside its product. Plugin, integration, and skill are inherited or vendor-specific terms that mean different things in different rooms. Use MCP app as your umbrella term, MCP server for engineering, and the host client's preferred word (connector, Custom GPT app, etc.) on that client's surface.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;An MCP app is the user-installable product built on top of an MCP server. An MCP server is the running process implementing the Model Context Protocol over JSON-RPC 2.0. A connector is what Claude calls an installed MCP app inside its product. These three terms refer to different layers of the same system, and confusing them is the most common cause of stalled MCP roadmaps in 2026. The Model Context Protocol is just over eighteen months old as of this writing – Anthropic introduced it in November 2024 – and the industry has not yet agreed on what to call the things being built on top of it.&lt;/p&gt;

&lt;p&gt;Walk into any product meeting on this topic and you will hear, in roughly this order: &lt;em&gt;MCP server&lt;/em&gt;, &lt;em&gt;connector&lt;/em&gt;, &lt;em&gt;integration&lt;/em&gt;, &lt;em&gt;plugin&lt;/em&gt;, &lt;em&gt;app&lt;/em&gt;, &lt;em&gt;skill&lt;/em&gt;, &lt;em&gt;tool&lt;/em&gt;, &lt;em&gt;extension&lt;/em&gt;, and increasingly &lt;em&gt;agent&lt;/em&gt; used loosely for any of the above. None of these are wrong. Several are technically correct in different layers. But the ambiguity is not free. Roadmaps stall on vocabulary disagreements that look like product disagreements. RFPs go in circles because each side means something different by the same word. Partner kickoff meetings spend the first hour establishing what the product is actually called.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Key Signal&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The cost of mixed MCP terminology is paid in calendar weeks. We have watched a fifteen-person product team take six weeks to converge on internal vocabulary for an MCP app they had been building for three months. Vocabulary precedes strategy – companies without shared internal language for the artifact they are building produce inconsistent positioning, fragmented marketing, and confused engineering specs.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This guide lays out the three layers of MCP-powered software, surveys the eight terms in circulation, and proposes a working vocabulary product teams can use until the market settles. The rest of our &lt;a href="https://launchdayadvisors.com/guides/mcp-embed-app-ai-clients" rel="noopener noreferrer"&gt;MCP guide series&lt;/a&gt; uses this vocabulary throughout.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Three Layers of MCP-Powered Software
&lt;/h2&gt;

&lt;p&gt;Most of the confusion resolves once you see that MCP-powered software is at least three distinct objects, and the words people use are referring to different ones.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The first layer is the protocol implementation&lt;/strong&gt; – the running MCP server. A process, a binary, a hosted endpoint. It implements the MCP spec, exposes a set of capabilities, and speaks the wire protocol the AI client expects. Engineers care about this layer.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The second layer is the capability surface&lt;/strong&gt; – the set of tools, resources, and prompts the server exposes. &lt;code&gt;create_invoice&lt;/code&gt;, &lt;code&gt;search_inventory&lt;/code&gt;, &lt;code&gt;book_meeting&lt;/code&gt;. This is where product design lives: what the agent can do on the user's behalf, with what parameters, returning what shape of data. Designers care about this layer.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The third layer is the user-installable experience&lt;/strong&gt; – the artifact a buyer adds to their AI client and calls something. Branding, distribution, monetization, the marketplace listing, the support channel. Marketing and product care about this layer.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;MCP server&lt;/em&gt; is a layer-one word. &lt;em&gt;Tool&lt;/em&gt;, &lt;em&gt;resource&lt;/em&gt;, and &lt;em&gt;prompt&lt;/em&gt; are layer-two words. &lt;em&gt;Connector&lt;/em&gt;, &lt;em&gt;plugin&lt;/em&gt;, &lt;em&gt;app&lt;/em&gt;, and &lt;em&gt;integration&lt;/em&gt; are all layer-three words, competing for the same job: name the thing the user installs.&lt;/p&gt;

&lt;h3&gt;
  
  
  What MCP is technically
&lt;/h3&gt;

&lt;p&gt;Before going deeper into terminology, it helps to anchor on what MCP actually is at layer one. MCP is a &lt;a href="https://www.jsonrpc.org/specification" rel="noopener noreferrer"&gt;JSON-RPC 2.0&lt;/a&gt;–based protocol introduced by Anthropic in November 2024 and open-sourced at &lt;a href="https://modelcontextprotocol.io" rel="noopener noreferrer"&gt;modelcontextprotocol.io&lt;/a&gt;. An MCP session begins with a capabilities negotiation between client and server, proceeds with the server advertising what it can do via three primitive types, and continues for the duration of the session with the client invoking server operations as the agent decides.&lt;/p&gt;

&lt;p&gt;The three MCP primitives are:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Tools&lt;/strong&gt; – operations the agent can invoke. Each tool has a &lt;code&gt;name&lt;/code&gt;, a &lt;code&gt;description&lt;/code&gt; (read by the agent at runtime to decide whether to invoke it), and an &lt;code&gt;inputSchema&lt;/code&gt; (a JSON Schema specifying parameters).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Resources&lt;/strong&gt; – data the agent can read. Each resource has a URI, a name, a description, and a MIME type.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Prompts&lt;/strong&gt; – templated user-facing prompts the server can offer. Used much less widely than tools and resources in practice.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;MCP supports three transports: &lt;strong&gt;stdio&lt;/strong&gt; (process-to-process, for local servers), &lt;strong&gt;SSE&lt;/strong&gt; (Server-Sent Events over HTTP), and &lt;strong&gt;streamable HTTP&lt;/strong&gt; (the newer remote transport that consolidated SSE's responsibilities). For remote MCP servers, the spec includes an OAuth 2.1 + PKCE authorization flow with Dynamic Client Registration and authorization-server metadata discovery.&lt;/p&gt;

&lt;p&gt;Once the layers are visible, vocabulary arguments resolve into a question of which layer the speaker means. The engineer saying &lt;em&gt;MCP server&lt;/em&gt; is not wrong; they are referring to layer one. The marketer saying &lt;em&gt;connector&lt;/em&gt; is not wrong; they are referring to layer three through Anthropic's chosen vocabulary. Both can be right; both can also be the wrong word for the room. The discipline is knowing which.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Eight MCP-Related Terms in Circulation
&lt;/h2&gt;

&lt;p&gt;Eight terms are in active use as of mid-2026, and they refer to different things at different layers of the system.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Term&lt;/th&gt;
&lt;th&gt;Layer&lt;/th&gt;
&lt;th&gt;Meaning&lt;/th&gt;
&lt;th&gt;When to use it&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;MCP server&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Engineering&lt;/td&gt;
&lt;td&gt;Process implementing the MCP spec (JSON-RPC 2.0)&lt;/td&gt;
&lt;td&gt;Architecture diagrams, technical docs, contracts&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;MCP app&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Product (umbrella)&lt;/td&gt;
&lt;td&gt;User-installable artifact built on an MCP server&lt;/td&gt;
&lt;td&gt;Roadmaps, investor decks, cross-client positioning&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Connector&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Product (Claude-specific)&lt;/td&gt;
&lt;td&gt;Anthropic's term for an installed MCP app in Claude&lt;/td&gt;
&lt;td&gt;Inside Claude marketing and docs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Plugin&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Product (legacy)&lt;/td&gt;
&lt;td&gt;Inherited from ChatGPT Plugins (2023); pre-MCP framework&lt;/td&gt;
&lt;td&gt;Avoid in new copy – implies older, more constrained model&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Integration&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Product (generic)&lt;/td&gt;
&lt;td&gt;Generic enterprise term for cross-system connection&lt;/td&gt;
&lt;td&gt;Operationally clear in procurement; loses MCP's autonomy signal&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;App&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Product (multi-vendor)&lt;/td&gt;
&lt;td&gt;Used in ChatGPT App Store, Custom GPTs, Claude apps&lt;/td&gt;
&lt;td&gt;When the host client uses it&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Tool&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Capability primitive&lt;/td&gt;
&lt;td&gt;Individual operation an MCP server exposes (&lt;code&gt;create_invoice&lt;/code&gt;)&lt;/td&gt;
&lt;td&gt;Engineering docs and product specs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Resource&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Capability primitive&lt;/td&gt;
&lt;td&gt;Data item an MCP server exposes (a document, a record)&lt;/td&gt;
&lt;td&gt;Engineering docs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Prompt&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Capability primitive&lt;/td&gt;
&lt;td&gt;Templated user-facing prompt the server offers&lt;/td&gt;
&lt;td&gt;Engineering docs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Skill&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Collided&lt;/td&gt;
&lt;td&gt;Claude's separate concept ("Skills") that is &lt;em&gt;not&lt;/em&gt; MCP servers&lt;/td&gt;
&lt;td&gt;Avoid in mixed-vendor rooms&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Extension / add-on&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Product (legacy)&lt;/td&gt;
&lt;td&gt;Browser-era inheritance; underclaims agent autonomy&lt;/td&gt;
&lt;td&gt;Avoid – undersells the product&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  A short tour of the layer-three terms
&lt;/h3&gt;

&lt;p&gt;The marketing decisions live at layer three, so this is where most of the language churn is felt.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Connector&lt;/em&gt; is Anthropic's user-facing term inside Claude. It names the relationship – you connect a thing, then Claude can use it – but other clients do not use it, and copy written entirely in &lt;em&gt;connector&lt;/em&gt; reads as Claude-specific the moment it is read on another surface.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;App&lt;/em&gt; is gaining ground. Custom GPTs are sometimes called &lt;em&gt;apps&lt;/em&gt;; Claude has begun using &lt;em&gt;Claude apps&lt;/em&gt; for installable connector experiences. &lt;em&gt;App&lt;/em&gt; carries the right mental model – something installable, that does a job. The cost is overloading an already-overloaded word.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Plugin&lt;/em&gt; is inherited from the ChatGPT Plugins era of 2023. Still in casual use, but it implies an older, more constrained model in which a third party hooks into a host. MCP-powered software is often neither.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Integration&lt;/em&gt; is the generic enterprise term. Operationally clear inside procurement; flattens the distinction between MCP and the previous generation of webhook-and-Zapier integrations, which is a feature for fast procurement conversations and a bug for accurate strategic positioning.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Skill&lt;/em&gt; is collided with Claude's existing concept of Skills, which are not MCP servers. Avoid in mixed-vendor rooms unless you intend to spend ten minutes disambiguating.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Extension&lt;/em&gt; and &lt;em&gt;add-on&lt;/em&gt; underclaim the autonomy a modern MCP server has when wired into an agent.&lt;/p&gt;

&lt;h2&gt;
  
  
  MCP App vs MCP Server: The Critical Distinction
&lt;/h2&gt;

&lt;p&gt;An MCP server is a technical component; an MCP app is a product. The MCP server runs the protocol and exposes primitives (tools, resources, prompts). The MCP app is the marketed, distributed, supported, monetized package a customer installs – including the server, the auth experience, the marketplace listing, the documentation, and the support workflow.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;MCP server&lt;/th&gt;
&lt;th&gt;MCP app&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Layer&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Engineering&lt;/td&gt;
&lt;td&gt;Product&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;What it is&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Process implementing MCP (JSON-RPC 2.0)&lt;/td&gt;
&lt;td&gt;User-installable product&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Exposes&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Tools, resources, prompts&lt;/td&gt;
&lt;td&gt;A complete buyer experience&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Who cares&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Engineers, devops&lt;/td&gt;
&lt;td&gt;Product, marketing, sales&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Where it lives&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Hosted endpoint or local binary&lt;/td&gt;
&lt;td&gt;Marketplace listing in a host AI client&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Used in&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Architecture diagrams, technical docs&lt;/td&gt;
&lt;td&gt;Roadmaps, investor decks, marketing&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;One MCP app typically contains one MCP server, but an MCP app can package multiple servers when the product spans concerns (a company might ship an MCP app that installs both a "data" server and a "workflow" server under one product brand).&lt;/p&gt;

&lt;h3&gt;
  
  
  What about resources and prompts?
&lt;/h3&gt;

&lt;p&gt;Most public discussion of MCP focuses on tools – the operations an agent can invoke. The other two primitives, resources and prompts, are underused in 2026 but worth understanding because they affect how you should think about your MCP app's surface.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Resources&lt;/strong&gt; let an MCP server expose data the agent can read directly, without invoking a tool. Typical use cases: a knowledge base entry, a document, a database row. For some products – knowledge bases, documentation systems, content-rich CRMs – resources are a more natural fit than tools.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Prompts&lt;/strong&gt; let an MCP server offer templated prompts users can trigger. A "summarize this ticket" prompt, a "draft response in our voice" prompt. Used in roughly 20% of production MCP apps as of mid-2026; tools are used in close to 100%.&lt;/p&gt;

&lt;p&gt;Most product teams designing an MCP app should focus on tools first, resources second (where data exposure matters), and prompts third (where templated workflows matter). The terminology, though, should distinguish them – calling a resource a tool produces design discussions where engineering and product talk past each other.&lt;/p&gt;

&lt;h2&gt;
  
  
  A Working Vocabulary for Product Teams
&lt;/h2&gt;

&lt;p&gt;After eighteen months of vocabulary churn, the stack we use with clients is the following.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;MCP app&lt;/strong&gt; – the umbrella term for the user-installable, distribution-aware product. Used in roadmaps, investor decks, internal naming, and any context where the thing is being discussed across host clients. &lt;em&gt;MCP app&lt;/em&gt; is the word your CEO should be able to say in a board meeting and have everyone in the room understand the same thing.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Connector&lt;/strong&gt;, &lt;strong&gt;app&lt;/strong&gt;, or whatever the host client uses – the surface term in marketing and documentation, matched to where it appears. Inside Claude documentation: &lt;em&gt;connector&lt;/em&gt;. Inside the ChatGPT app store: &lt;em&gt;app&lt;/em&gt;. Inside Microsoft AppSource: whatever the AppSource template prescribes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;MCP server&lt;/strong&gt; – the engineering artifact, used in technical documentation, partner contracts, and architecture diagrams. Not used in customer-facing copy.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Tool / Resource / Prompt&lt;/strong&gt; – individual capabilities an MCP server exposes, used in product specs and developer docs. Never used in marketing.&lt;/p&gt;

&lt;p&gt;The reasoning is that &lt;em&gt;MCP app&lt;/em&gt; carries the right strategic weight – this is a product, not a script – without locking you to any single vendor's vocabulary. The host-specific term handles the language match on each client's surface. &lt;em&gt;MCP server&lt;/em&gt; stays clean as the engineering term, which is what engineering wants.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Recommended Stack&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;MCP app for the umbrella term. Host-specific terms (connector inside Claude, app inside the ChatGPT store) on each client's surface. MCP server for the engineering artifact. Tool, resource, and prompt for individual capabilities. Pick a stack now; revisit when the market consolidates. The cost of waiting is paid in calendar weeks of vocabulary disagreement.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  The objection worth taking seriously
&lt;/h3&gt;

&lt;p&gt;The objection worth taking seriously is that &lt;em&gt;MCP app&lt;/em&gt; overloads &lt;em&gt;app&lt;/em&gt;, which already does too much work. True. But every alternative is worse: &lt;em&gt;MCP server&lt;/em&gt; is the wrong layer; &lt;em&gt;connector&lt;/em&gt; is one vendor's word; &lt;em&gt;integration&lt;/em&gt; loses the autonomy signal; &lt;em&gt;plugin&lt;/em&gt; is dated; &lt;em&gt;skill&lt;/em&gt; is collided; &lt;em&gt;extension&lt;/em&gt; and &lt;em&gt;add-on&lt;/em&gt; undersell. &lt;em&gt;App&lt;/em&gt; is overloaded. The alternatives are wrong. We accept the overload in exchange for the mental model.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Vocabulary Costs Calendar Weeks
&lt;/h2&gt;

&lt;p&gt;The cost of mixed terminology is not abstract. Three concrete patterns we have seen on engagements show how the bill is presented.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The RFP that took six weeks to qualify.&lt;/strong&gt; A buyer issues an RFP for &lt;em&gt;AI integration capabilities&lt;/em&gt;. Three vendors respond – one describes their MCP server's tool surface, one describes their Custom GPT app, one describes a Zapier-style integration. The buyer's procurement team cannot compare the responses because the vendors are answering different questions under the same heading. Six weeks of clarification cycles before the actual evaluation can begin.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The investor deck that confused two stages.&lt;/strong&gt; A series-B startup pitches an &lt;em&gt;MCP server&lt;/em&gt; as their flagship product. Investors who track the category interpret this as a developer-infrastructure play (server = infrastructure). The actual product is a user-installable connector for Claude – a layer-three product that happens to ship with a server. Six weeks of follow-up conversations to re-position the narrative; one investor passes citing the confusion.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The partner contract that misallocated work.&lt;/strong&gt; A company hires a development partner for &lt;em&gt;MCP integration work&lt;/em&gt;. The partner scopes the engineering layer (server implementation, JSON-RPC handling, transport selection). The buyer expected the product layer (marketplace listing, distribution, support workflow). The first invoice exposes the gap; the contract is renegotiated mid-engagement at higher cost. A shared, scope-by-scope view of &lt;a href="https://launchdayadvisors.com/guides/mcp-server-cost" rel="noopener noreferrer"&gt;what an MCP server costs to build&lt;/a&gt; tends to surface that mismatch before the first invoice.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Common Failure Mode&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;In all three cases, the loss was not from any party acting in bad faith. It was from the absence of a shared vocabulary that could distinguish what was actually being discussed. The cheapest fix is a one-page vocabulary document circulated before the project starts. The expensive fix is renegotiating the contract or rebuilding the deck six weeks in.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The market will eventually settle. One term will win, the way &lt;em&gt;app&lt;/em&gt; won over &lt;em&gt;iPhone application&lt;/em&gt;. But if you are building an MCP-powered product in 2026, you cannot wait for that to happen. You need a working vocabulary now – one your engineers, your designers, your sales team, and your partners can all use without translation.&lt;/p&gt;

&lt;p&gt;Pick a stack. Document it. Use it consistently. The rest of &lt;a href="https://launchdayadvisors.com/guides/mcp-embed-app-ai-clients" rel="noopener noreferrer"&gt;our MCP guide series&lt;/a&gt; uses &lt;strong&gt;MCP app&lt;/strong&gt; as the umbrella term, &lt;strong&gt;MCP server&lt;/strong&gt; for the engineering artifact, and host-client-specific terms (&lt;em&gt;connector&lt;/em&gt;, &lt;em&gt;Custom GPT app&lt;/em&gt;) where the host surface demands them.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Guides
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-embed-app-ai-clients" rel="noopener noreferrer"&gt;How to Embed Your App in AI Clients with MCP&lt;/a&gt; – The full strategic framework for product leaders shipping to leading AI clients&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-client-comparison" rel="noopener noreferrer"&gt;MCP Client Comparison: Claude vs ChatGPT vs Cursor vs Copilot vs Gemini&lt;/a&gt; – The eight dimensions that matter when choosing where to ship&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;MCP Embedding Types Explained: Read-Only vs Actions vs Agent-Resident&lt;/a&gt; – Choose the right level for your safety story&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP Build vs Buy&lt;/a&gt; – In-house engineering or development partner, with cost ranges and decision rubric&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Is an MCP server the same as an MCP app?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;No. An MCP server is the engineering artifact – a process implementing the MCP spec via JSON-RPC 2.0. An MCP app is the user-installable product built on top of it, including auth experience, marketplace listing, documentation, and support. One MCP app typically contains one MCP server.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What are the three MCP primitives?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The MCP specification defines three primitive types an MCP server can expose: tools (operations the agent invokes), resources (data the agent reads), and prompts (templated user-facing prompts). Tools are used in nearly all production MCP apps; resources are used where data exposure is central; prompts are used least often.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What protocol does MCP use?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;MCP uses JSON-RPC 2.0 as its wire protocol, transported over stdio (for local servers), SSE (Server-Sent Events over HTTP), or streamable HTTP (the consolidated remote transport). Capabilities are negotiated between client and server during session initialization.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Should I use the term connector or MCP app?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Use connector when you are inside Anthropic's vocabulary – Claude documentation, Claude marketing, conversations with Anthropic. Use MCP app as your cross-client umbrella term – roadmaps, investor decks, internal naming. Other host clients use other words; match the host client on the host client's surface.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is an MCP server a plugin?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;No. Plugin is inherited from the ChatGPT Plugins era of 2023 and implies an older, more constrained extension model. MCP-powered software is not a plugin; it is a protocol-based product surface with much broader capability – multiple primitives, capability negotiation, agent-driven invocation. Avoid plugin in current copy.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is the difference between an MCP tool and an MCP server?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;An MCP server is the package; a tool is one operation inside that package. A single MCP server typically exposes many tools – create_ticket, get_customer, list_invoices – alongside resources and prompts. The server is the install unit; the tool is the call unit.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can I just call my MCP app an AI integration?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;You can, but you lose information by doing so. Integration is a generic enterprise word that flattens the distinction between MCP and the previous generation of webhook-and-Zapier integrations. MCP is meaningfully different – agents reason about which tools to invoke based on natural-language context. Calling an MCP app an integration is operationally clear in procurement and strategically vague in positioning.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What's the difference between resources and tools in MCP?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A tool is an operation the agent decides to invoke (create_invoice, search_customers). A resource is a data item the server exposes for the agent to read (a specific document, a customer record). Tools have side effects or computed responses; resources are content. Tools are invoked; resources are referenced.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://launchdayadvisors.com/guides/mcp-terminology?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=guides" rel="noopener noreferrer"&gt;launchdayadvisors.com&lt;/a&gt;. Launch Day Advisors is a buyer-side advisory firm: we help companies select AI, software, and design partners, and we are paid only by the buyer.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>mcp</category>
      <category>ai</category>
      <category>beginners</category>
      <category>productmanagement</category>
    </item>
    <item>
      <title>Should Your App Be in AI Clients? MCP Strategy Decision Framework</title>
      <dc:creator>Jonathan Blessing</dc:creator>
      <pubDate>Fri, 18 Sep 2026 13:03:44 +0000</pubDate>
      <link>https://dev.to/launchdayadvisors/should-your-app-be-in-ai-clients-mcp-strategy-decision-framework-22d4</link>
      <guid>https://dev.to/launchdayadvisors/should-your-app-be-in-ai-clients-mcp-strategy-decision-framework-22d4</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;In brief:&lt;/strong&gt; Most product teams should ship an MCP app to at least one AI client by end of 2026, but the right posture varies. Run three diagnostics: (1) where is your buyer doing the work, (2) what role does your product play in their workflow, (3) what is the cost of being absent? The answers point to one of four postures: ship aggressively to multiple clients, ship narrowly to one strategic client, ship a defensive read-only MCP app, or don't ship and defend the destination. Each posture commits you to a different cost structure (Posture 1: $1.5–3M annual investment; Posture 2: $500K–1M; Posture 3: $200–500K; Posture 4: zero direct cost but compounding distribution risk).&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Most product teams should ship an MCP app to at least one AI client by end of 2026, but the right posture varies sharply. The strategic question is not &lt;em&gt;whether&lt;/em&gt; MCP matters but &lt;em&gt;what posture you take while it does&lt;/em&gt;. There are four reasonable postures, and choosing the right one is more important than choosing whether to ship. The temptation is to skip directly to &lt;em&gt;which client should we ship to&lt;/em&gt; – the right order is to figure out the posture first and let the client choice fall out of it. Skipping the posture step is how teams end up with three half-built MCP apps on three different clients and nothing in production.&lt;/p&gt;

&lt;p&gt;This is the diagnostic we use with product teams making the call. It assumes the working vocabulary in our &lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;MCP terminology guide&lt;/a&gt; and the landscape view in our &lt;a href="https://launchdayadvisors.com/guides/mcp-client-comparison" rel="noopener noreferrer"&gt;MCP client comparison matrix&lt;/a&gt;. Three diagnostic questions; the answers, taken together, point toward one of four postures.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The MCP-App Decision Is a Commitment Decision&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The MCP-app decision looks like a build decision. It is, more accurately, a commitment decision. Posture 1 is a commitment to staffing a new distribution surface like a product line. Posture 2 is a commitment to depth on one surface and absence on others. Posture 3 is a commitment to a defensive position requiring discipline to hold. Posture 4 is a commitment to a destination strategy you have to keep earning. Half-staffed work that neither side owns produces nothing that compounds.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Three Diagnostics for Whether to Ship
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Diagnostic 1: Where is your buyer doing the work?
&lt;/h3&gt;

&lt;p&gt;Not where they were doing it last year. Not where the CEO of an AI client says they will be doing it next year. Where, today and over the past quarter, has your actual buyer been spending their professional working time?&lt;/p&gt;

&lt;p&gt;Three answers are common, and they imply very different MCP postures:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Primarily on a destination they choose.&lt;/strong&gt; They open a browser and go to your website, your competitor's, or a SaaS tool they bought. The AI client is a tab they sometimes use. Distribution is largely intact.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Inside an AI client as a substitute.&lt;/strong&gt; They open Claude or ChatGPT instead of opening your tool, ask the agent to do the thing your tool does, and accept whatever quality the agent produces. The AI client is a competitor – your product is being disintermediated, with or without an MCP app.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Inside an AI client as a multiplexer.&lt;/strong&gt; They are working in Claude or ChatGPT or Cursor as a hub, reaching out to many tools, including yours, to get the job done. The AI client is a distribution channel, and your presence inside it is presence at the surface where the work happens.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Most product teams cannot answer this question precisely because they are not instrumenting the right signal. The signal is not whether your buyer has used Claude this week. The signal is whether tasks that were happening in your product or its category are now happening in an AI client instead.&lt;/p&gt;

&lt;h4&gt;
  
  
  Concrete signals to instrument
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Support ticket pattern shifts.&lt;/strong&gt; Track whether users are asking &lt;em&gt;can your product also work in Claude/ChatGPT/Cursor&lt;/em&gt;. A baseline rate above 5% of inbound support volume is a multiplexer-pattern signal.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Churn exit-interview themes.&lt;/strong&gt; Track how many former customers cite &lt;em&gt;we use ChatGPT/Claude now&lt;/em&gt; in exit interviews. Above 15% is, in our experience, a substitute-pattern signal and a strategic emergency (a practitioner heuristic – calibrate the threshold to your own base rate).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Inbound demand shape.&lt;/strong&gt; Track the share of new sales conversations where the buyer asks about MCP, AI integrations, or agent compatibility. Above 25% is a strong signal that buyer expectations have shifted.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;API usage from non-human consumers.&lt;/strong&gt; If your existing API has a recognizable bot or agent user-agent footprint, track whether that share is growing.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Search trend for your category + AI client.&lt;/strong&gt; Track Google Trends or your own SEO data for queries like &lt;em&gt;Claude integration with [your category]&lt;/em&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If three or more of these signals are flashing, you are in multiplexer or substitute mode and should be running the rest of this framework with urgency.&lt;/p&gt;

&lt;h3&gt;
  
  
  Diagnostic 2: What is your product's role in your buyer's workflow?
&lt;/h3&gt;

&lt;p&gt;Three rough roles, with very different MCP implications:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Destination product.&lt;/strong&gt; A design tool, a writing app, a creative environment, a workspace they live in. Examples: Figma, Linear (for the user living in Linear UI), Notion, Photoshop. Destination products struggle to embed in AI clients without cannibalizing themselves. Right MCP posture is usually narrow and defensive.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Capability product.&lt;/strong&gt; A scheduling tool, a contract-review service, a document-extraction utility, a vertical data lookup. Examples: Calendly, DocuSign, Apollo, Stripe. Capability products are the natural inhabitants of MCP – the AI client is the new destination, and the capability is invoked from inside it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;System-of-record product.&lt;/strong&gt; A CRM, an issue tracker, a finance system, an HRIS. Examples: Salesforce, Linear (for the user querying Linear data from Claude), Workday, NetSuite. System-of-record products are necessary participants in any MCP-mediated workflow that touches their domain. Cost of being absent is high.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A product can be more than one of these to different buyer segments. Linear is a destination for the user actively triaging issues; it is a system of record for the user asking Claude &lt;em&gt;what's blocked on the 2.0 launch&lt;/em&gt;. Run the diagnostic per segment.&lt;/p&gt;

&lt;h3&gt;
  
  
  Diagnostic 3: What is the cost of being absent from AI clients?
&lt;/h3&gt;

&lt;p&gt;Four cost categories, ordered by severity:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Negligible.&lt;/strong&gt; Your buyer is not in that client, would not invoke your tool from there even if it existed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Soft.&lt;/strong&gt; Your buyer is in that client occasionally; absence costs you small mindshare, small inbound demand. Estimate: 1–3% of growth headwind annually.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Compounding.&lt;/strong&gt; Your buyer is in that client routinely, alternative tools are present, and every quarter you are absent the agent is learning to solve the user's problem without you. Estimate: 5–15% of growth headwind annually, accelerating as time passes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Existential.&lt;/strong&gt; Your category is being absorbed into the AI client itself. The buyer is not even thinking about your tool anymore. Estimate: 20%+ revenue impact within 24 months.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The shape of this cost varies sharply by category. A workflow-collaboration tool with deep entrenchment can absorb a &lt;em&gt;soft&lt;/em&gt; cost for a year. A vertical data provider whose data the agent can synthesize from public sources cannot absorb even a &lt;em&gt;compounding&lt;/em&gt; cost without permanent damage. Most teams in &lt;em&gt;compounding&lt;/em&gt; think they are in &lt;em&gt;soft&lt;/em&gt; – the bias is consistently to underweight the urgency.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Four Strategic Postures
&lt;/h2&gt;

&lt;p&gt;The diagnostics combine into four postures that capture nearly all reasonable answers in 2026:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Posture&lt;/th&gt;
&lt;th&gt;When it applies&lt;/th&gt;
&lt;th&gt;What it requires&lt;/th&gt;
&lt;th&gt;Example product type&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Ship aggressively to multiple clients&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Capability or system-of-record product, multiplexer-mode buyer, compounding/existential absence cost&lt;/td&gt;
&lt;td&gt;Roadmap-level priority, dedicated team, support for at least 2 clients in first ship&lt;/td&gt;
&lt;td&gt;Most B2B SaaS with knowledge-worker buyers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Ship narrowly to one strategic client&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Capability or system-of-record product, single dominant client in audience, real but client-specific absence cost&lt;/td&gt;
&lt;td&gt;Deep ship to one client; first-class connector; deferred others&lt;/td&gt;
&lt;td&gt;Vertical-tool company with concentrated audience&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Ship a defensive read-only MCP app&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Destination product, moat is the experience, full embedding would cannibalize, complete absence lets agents synthesize from elsewhere&lt;/td&gt;
&lt;td&gt;Thin read-only MCP app exposing data only; aggressive destination investment&lt;/td&gt;
&lt;td&gt;Creative tools, complex dashboards&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Don't ship; defend the destination&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Destination product, AI clients are small share of buyer's day, MCP cost exceeds return&lt;/td&gt;
&lt;td&gt;Invest in destination; revisit diagnostic in two quarters&lt;/td&gt;
&lt;td&gt;Some entrenched destination products (rare)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  Posture 1: Ship aggressively to multiple clients
&lt;/h3&gt;

&lt;p&gt;Indicated when you are a capability or system-of-record product, your buyer is in multiplexer mode across two or more AI clients, and the cost of absence is compounding or existential. Most B2B SaaS companies whose buyer is a knowledge worker sit here, and most of them are running it as a side project – which is the visible-from-orbit version of getting this wrong.&lt;/p&gt;

&lt;h3&gt;
  
  
  Posture 2: Ship narrowly to one strategic client
&lt;/h3&gt;

&lt;p&gt;Indicated when one AI client clearly dominates your buyer's working day, you are a capability or system-of-record product, and absence cost is real but client-specific. Vertical-tool companies whose buyer concentrates in a single AI surface fall here. &lt;strong&gt;The temptation to start with two clients is the thing to resist:&lt;/strong&gt; deep on one beats shallow on two, and shallow on two is what teams ship when they fail to make this call.&lt;/p&gt;

&lt;h3&gt;
  
  
  Posture 3: Ship a defensive read-only MCP app
&lt;/h3&gt;

&lt;p&gt;Indicated when you are a destination product whose moat is the experience itself, where full embedding would cannibalize but complete absence would let agents synthesize your data from elsewhere. Creative tools, complex dashboards, and experience-led products often sit here. The discipline is staying read-only; the temptation, after the read-only ship works, is to expand into actions and start cannibalizing the destination from inside your own MCP app.&lt;/p&gt;

&lt;h3&gt;
  
  
  Posture 4: Don't ship; defend the destination
&lt;/h3&gt;

&lt;p&gt;Indicated when your product is a destination, AI clients are a small share of your buyer's day, and the cost of an MCP app exceeds its return. The right move is to invest in the destination and revisit the diagnostic in two quarters. &lt;strong&gt;This is the right answer less often than teams hope.&lt;/strong&gt; &lt;em&gt;Not yet&lt;/em&gt; on this question converts to &lt;em&gt;too late&lt;/em&gt; faster than it converts to &lt;em&gt;now&lt;/em&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Each Posture Actually Costs
&lt;/h2&gt;

&lt;p&gt;The annual investment commitment for each posture, including build, maintenance, and supporting work (DevRel, marketing, customer education):&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Posture&lt;/th&gt;
&lt;th&gt;Year-1 build cost&lt;/th&gt;
&lt;th&gt;Year-2+ annual run rate&lt;/th&gt;
&lt;th&gt;Headcount equivalent&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Posture 1: Aggressive multi-client&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;$1.5–3M (2–3 clients shipped)&lt;/td&gt;
&lt;td&gt;$1–2M (maintenance, expansion, support)&lt;/td&gt;
&lt;td&gt;6–10 FTE-equivalent&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Posture 2: Narrow strategic&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;$500K–1M (1 client shipped well)&lt;/td&gt;
&lt;td&gt;$300K–600K&lt;/td&gt;
&lt;td&gt;2–4 FTE-equivalent&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Posture 3: Defensive read-only&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;$200–500K (lightweight read-only)&lt;/td&gt;
&lt;td&gt;$100–300K&lt;/td&gt;
&lt;td&gt;1–2 FTE-equivalent&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Posture 4: Don't ship&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;$0 direct&lt;/td&gt;
&lt;td&gt;$0 direct, but compounding distribution risk&lt;/td&gt;
&lt;td&gt;0&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;These costs assume hybrid in-house + partner staffing and are heavier toward the partner side in year 1, shifting to in-house in year 2+. The per-app build cost underneath these posture budgets is broken down by scope in &lt;a href="https://launchdayadvisors.com/guides/mcp-server-cost" rel="noopener noreferrer"&gt;what an MCP server costs to build&lt;/a&gt;; see &lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP build vs buy&lt;/a&gt; for the in-house vs partner decision.&lt;/p&gt;

&lt;p&gt;The honest accounting: Posture 1 is a meaningful capital allocation. Most teams that need it are running it as a side project at Posture-3 budget, which is the visible-from-orbit version of getting this wrong.&lt;/p&gt;

&lt;h3&gt;
  
  
  MCP strategy decision tree
&lt;/h3&gt;

&lt;p&gt;A simplified decision tree using the diagnostics:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Is your buyer doing meaningful work inside AI clients today?
├── No → Posture 4 (revisit in 2 quarters)
└── Yes
    │
    └── What is your product's primary role?
        │
        ├── Destination product
        │   └── Will full embedding cannibalize the destination?
        │       ├── Yes → Posture 3 (defensive read-only)
        │       └── No → Posture 2 (narrow strategic ship)
        │
        ├── Capability product
        │   └── Buyer concentrated in one AI client or many?
        │       ├── One → Posture 2 (deep ship to that client)
        │       └── Many → Posture 1 (aggressive multi-client)
        │
        └── System-of-record product
            └── What is the cost of being absent?
                ├── Soft → Posture 2 (narrow strategic)
                └── Compounding/existential → Posture 1 (aggressive multi-client)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This is a simplification; the full diagnostic is richer than the tree suggests. But for a quick first read, the tree gets most teams to within one posture of the right answer.&lt;/p&gt;

&lt;h2&gt;
  
  
  Sequencing if You Ship
&lt;/h2&gt;

&lt;p&gt;For postures 1 and 2 (the ship postures), the order of operations matters more than teams expect. The compressed sequence:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Pick the &lt;em&gt;one&lt;/em&gt; client where you will ship first, even if you intend to support multiple. Optimize the entire first ship for that client's distribution model, auth model, and design idioms.&lt;/li&gt;
&lt;li&gt;Choose your embedding depth deliberately using &lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;MCP embedding types&lt;/a&gt;. Read-only is the right starting point unless you have a high-confidence safety story for actions.&lt;/li&gt;
&lt;li&gt;Get the auth design right using &lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP auth and security&lt;/a&gt; &lt;em&gt;before&lt;/em&gt; the first tool definition. Scope shape determines tool shape.&lt;/li&gt;
&lt;li&gt;Decide build vs buy using &lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP build vs buy&lt;/a&gt; before staffing.&lt;/li&gt;
&lt;li&gt;Ship narrowly. Instrument heavily. Expand by evidence.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The temptation to abstract across clients from day one produces an MCP app that is mediocre on every surface. Better to be excellent on one and port what works.&lt;/p&gt;

&lt;h2&gt;
  
  
  Worked Example and the Wrong Reasons to Ship
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Worked example: a Series-B SaaS company
&lt;/h3&gt;

&lt;p&gt;To make the framework concrete, a representative example based on patterns we see in client engagements (details abstracted).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Company:&lt;/strong&gt; A Series-B project-management SaaS with $40M ARR, primarily mid-market and enterprise customers, prosumer + knowledge-worker buyer.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Diagnostic 1 (where is the buyer working?):&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;18% of new support tickets in Q1 2026 mention Claude or ChatGPT&lt;/li&gt;
&lt;li&gt;Churn analysis shows 11% of departing customers cite &lt;em&gt;we just use ChatGPT now&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;Sales conversations: 31% of new opportunities now ask about MCP support&lt;/li&gt;
&lt;li&gt;Inbound demand: API usage from agent user-agents grew 4× in past 6 months&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;→ &lt;strong&gt;Pattern: multiplexer with substitute-mode emerging.&lt;/strong&gt; Urgency is real.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Diagnostic 2 (product role):&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;For active users in the UI: destination product&lt;/li&gt;
&lt;li&gt;For users querying project status from Claude: system-of-record product&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;→ &lt;strong&gt;Mixed: destination + system-of-record.&lt;/strong&gt; The system-of-record dimension is the more strategically important for MCP purposes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Diagnostic 3 (cost of absence):&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Buyers spend significant time in Claude and ChatGPT&lt;/li&gt;
&lt;li&gt;Competitors have shipped MCP apps in the past 6 months&lt;/li&gt;
&lt;li&gt;Agent-led project-status queries are happening today, with the agent often unable to answer because no MCP server is exposed&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;→ &lt;strong&gt;Compounding cost.&lt;/strong&gt; Without MCP presence in the next 2 quarters, alternatives will fill the gap.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Posture: Aggressive multi-client (Posture 1).&lt;/strong&gt; Ship to Claude and ChatGPT in year 1, expand to Microsoft Copilot in year 2 (matches the enterprise customer base).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Year-1 commitment:&lt;/strong&gt; ~$2M, 8 FTE-equivalent across product, engineering, design, partnerships.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Sequencing:&lt;/strong&gt; Claude first (deepest connector experience, prosumer-strong audience), ChatGPT second (largest raw audience), defer Copilot to year 2 (heavier implementation overhead). Level-2 actions on both, with audit log surface as a parallel track.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Questions to Pressure-Test the Posture&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Does the engineering leader and the product leader read the diagnostics the same way? If they disagree, the disagreement is about an underlying assumption (how strategic this is, how fast the team can move) that needs to surface before the build starts. Is the company prepared to staff this like a product line, or like a side project? Posture 1 at side-project budget is the most expensive way to get MCP wrong.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  The wrong reasons to ship
&lt;/h3&gt;

&lt;p&gt;Three reasons appear repeatedly and should not survive a serious decision review.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Because everyone else is.&lt;/strong&gt; MCP-app FOMO is real and currently expensive. The cost of shipping a half-built MCP app to the wrong client to look serious is higher than the cost of waiting one quarter and shipping a real one to the right client.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Because a board member or investor told us to.&lt;/strong&gt; The strategic question is whose buyer is moving where, not whose investor is excited about which protocol. If diagnostics point to Posture 4, the right answer is Posture 4. Investor pressure to ship anyway is investor pressure to make a worse strategic decision.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Because our competitor shipped one.&lt;/strong&gt; A competitor's MCP app is evidence that they made a decision; it is not evidence that the decision was correct, and it is not evidence that the same decision is correct for you. Run diagnostics on your buyer, not theirs.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Common Failure Mode&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Most product teams that get MCP wrong got it wrong by skipping the framework, picking the easiest client to ship to, and producing something that was neither the aggressive ship of Posture 1 nor the deep ship of Posture 2. The work compounds when it is committed work. Half-staffed work neither side owns produces nothing that compounds and a year of calendar time you do not get back.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Pick the posture. Document the reasoning. Then build. If the strategic question is broader than MCP – questions about which AI investments are worth making at all – our &lt;a href="https://launchdayadvisors.com/guides/ai-strategy-consultant" rel="noopener noreferrer"&gt;AI strategy consultant guide&lt;/a&gt; covers the wider decision frame.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Guides
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;What to Call MCP Apps: Terminology Guide&lt;/a&gt; – Working vocabulary&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-embed-app-ai-clients" rel="noopener noreferrer"&gt;How to Embed Your App in AI Clients with MCP&lt;/a&gt; – The full strategic playbook&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-client-comparison" rel="noopener noreferrer"&gt;MCP Client Comparison Matrix&lt;/a&gt; – Eight dimensions across leading clients&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;MCP Embedding Types Explained&lt;/a&gt; – Read-only, actions, agent-resident&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP Build vs Buy&lt;/a&gt; – Cost ranges and the in-house vs partner decision&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/ai-strategy-consultant" rel="noopener noreferrer"&gt;Do You Need an AI Strategy Consultant?&lt;/a&gt; – When the strategic question is broader than a single protocol&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Is MCP worth it for my product?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;For most products with knowledge-worker, prosumer, developer, or enterprise-software buyers in 2026, yes. The exceptions are pure destination products with limited AI-client overlap among their buyers. Run the three diagnostics in this guide to get a defensible answer.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How do I know if my buyer is using AI clients?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The signal is not whether they have used an AI client; it is whether tasks that previously happened in your product are now happening in an AI client. Concrete signals to instrument: support tickets mentioning AI clients (&amp;gt;5% is multiplexer-pattern), churn exit interviews citing AI clients (&amp;gt;15% is substitute-pattern), sales conversations asking about MCP (&amp;gt;25% is buyer-expectation shift).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How long do I have to decide?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The window for being early is closing through 2026 and 2027. By 2028, the buyer expectation will be that meaningful B2B software is reachable through MCP, much the way the buyer expectation in 2016 was that meaningful software had a mobile app. Companies that decide in 2026 are deciding from a position of choice; companies that decide in 2028 are deciding from a position of catch-up.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What if I'm wrong about the posture?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Postures are revisitable. The decision is binding for the duration of one ship cycle (one to two quarters), not forever. Ship under Posture 2 with one client, learn, and revisit whether to expand to Posture 1. The wrong move is paralysis.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Should I ship to all AI clients at once?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;No. Pick one strategic client and ship there first. The temptation to abstract across clients from day one produces an MCP app that is mediocre on every surface. Excellent on one and port what works is the durable strategy.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How much does an MCP strategy cost?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Posture 1 (aggressive multi-client): $1.5–3M year 1, $1–2M run rate annually. Posture 2 (narrow strategic): $500K–1M year 1, $300–600K annually. Posture 3 (defensive read-only): $200–500K year 1, $100–300K annually. See MCP build vs buy for full line-item breakdowns.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can my MCP app strategy change as MCP evolves?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Yes, and it should. Revisit the strategy quarterly. The auth models will change, monetization paths will mature, agent-led routing will reshape discovery. A strategy that does not revisit is a strategy that decays.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is shipping a defensive read-only MCP app the same as not shipping?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;No. A defensive read-only MCP app is an active position – you are deciding to give agents access to your data without giving them write capability. Not shipping is a passive position. The defensive read-only ship is meaningful work; the no-ship requires no work but bears different long-term costs.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://launchdayadvisors.com/guides/mcp-strategy-decision-framework?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=guides" rel="noopener noreferrer"&gt;launchdayadvisors.com&lt;/a&gt;. Launch Day Advisors is a buyer-side advisory firm: we help companies select AI, software, and design partners, and we are paid only by the buyer.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>mcp</category>
      <category>ai</category>
      <category>productmanagement</category>
      <category>startup</category>
    </item>
    <item>
      <title>MCP Embedding Types Explained: Read-Only vs Actions vs Agent-Resident</title>
      <dc:creator>Jonathan Blessing</dc:creator>
      <pubDate>Fri, 18 Sep 2026 13:00:44 +0000</pubDate>
      <link>https://dev.to/launchdayadvisors/mcp-embedding-types-explained-read-only-vs-actions-vs-agent-resident-20io</link>
      <guid>https://dev.to/launchdayadvisors/mcp-embedding-types-explained-read-only-vs-actions-vs-agent-resident-20io</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;In brief:&lt;/strong&gt; MCP apps embed in AI clients at one of three levels. Read-only exposes data the agent can read but cannot change (lowest risk, fastest to ship; ~1 quarter; $100K–$300K). Actions exposes mutations the agent can execute (create, update, delete, send) – requires idempotency keys, reversibility patterns, intent-preview interfaces, and per-action audit logs (~2 quarters; $300K–$700K). Agent-resident treats the agent as a first-class user of the product, with its own identity, accumulated state, and participation in internal mechanisms – almost no products are at this level (multi-quarter program; $1M+). Most teams should ship read-only first, expand to actions when the safety story is real, and consider agent-resident only when the company is rebuilding around it.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;MCP apps embed in AI clients at one of three levels – read-only, actions, or agent-resident – distinguished by what the agent can do with the underlying product. Each level has different security models, design demands, costs, and value to the user. The level you ship at is one of the highest-leverage product calls in an MCP roadmap, and it is routinely made by default rather than deliberately – usually by an engineer reading the spec on a Friday and shipping whatever the docs make easiest.&lt;/p&gt;

&lt;p&gt;This guide lays out the three levels, what each one entails, and how to decide which one to ship at. It uses the working vocabulary in our &lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;MCP terminology guide&lt;/a&gt;.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Match Level to What the Product Can Defend&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The level you ship at is not a measure of ambition. It is a measure of what the product can defend, and what the company is committed to becoming. A read-only MCP app says "the agent should know what we know." An actions MCP app says "the agent should be able to act on what we hold." An agent-resident MCP app says "the agent is part of how this product operates." Three different commitments, three different costs, three different futures.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  The Three Embedding Levels
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Level&lt;/th&gt;
&lt;th&gt;What the agent can do&lt;/th&gt;
&lt;th&gt;Risk&lt;/th&gt;
&lt;th&gt;Time to ship&lt;/th&gt;
&lt;th&gt;Typical cost (partner-built)&lt;/th&gt;
&lt;th&gt;Best for&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Read-only&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Query and read data; cannot change anything&lt;/td&gt;
&lt;td&gt;Low&lt;/td&gt;
&lt;td&gt;~1 quarter&lt;/td&gt;
&lt;td&gt;$100K–$300K&lt;/td&gt;
&lt;td&gt;First MCP ship; defensive presence; data-rich products&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Actions&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Read + execute mutations (create, update, delete, send)&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;td&gt;~2 quarters&lt;/td&gt;
&lt;td&gt;$300K–$700K&lt;/td&gt;
&lt;td&gt;Capability products; system-of-record products with mature safety story&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Agent-resident&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Operates as a first-class user with identity, state, and internal participation&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;td&gt;Multi-quarter rebuild&lt;/td&gt;
&lt;td&gt;$1M+&lt;/td&gt;
&lt;td&gt;Companies whose strategic premise is agent-first&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The cost gap between levels is driven less by the server than by the safety surface each one requires: the jump from read-only to actions roughly doubles the build because every write tool needs idempotency, reversibility, and a per-action audit trail. The full breakdown by scope – line items, ongoing costs, and worked examples – is in &lt;a href="https://launchdayadvisors.com/guides/mcp-server-cost" rel="noopener noreferrer"&gt;what an MCP server costs to build&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Read-Only MCP Apps
&lt;/h2&gt;

&lt;p&gt;A read-only MCP app is an MCP app whose tools only query data and never modify it. The agent can answer questions and reason against your system – your customers, your tickets, your inventory, your documents – but cannot change anything inside it.&lt;/p&gt;

&lt;p&gt;Concretely, the tools exposed at this level are all queries: &lt;code&gt;search_customers&lt;/code&gt;, &lt;code&gt;get_ticket&lt;/code&gt;, &lt;code&gt;list_invoices&lt;/code&gt;, &lt;code&gt;find_in_knowledge_base&lt;/code&gt;. There are no &lt;code&gt;create_&lt;/code&gt;, &lt;code&gt;update_&lt;/code&gt;, or &lt;code&gt;delete_&lt;/code&gt; verbs. Resources may also be exposed for direct data reads.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Read-only is the lowest-risk, fastest-to-ship version of MCP presence.&lt;/strong&gt; For some products it is the right ceiling, not a stepping stone – particularly destination products that benefit from exposing their data to agents without rebuilding the destination experience inside the AI client.&lt;/p&gt;

&lt;h3&gt;
  
  
  Sample read-only tool definition
&lt;/h3&gt;

&lt;p&gt;A representative read-only tool exposes a clear query with informative parameters and citation-friendly response shape:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"name"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"search_customers"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"description"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Search the customer database by name, email, or company. Returns up to 50 matching customers with their basic info. Use when the user asks about a specific customer or wants to find customers matching criteria."&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"inputSchema"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"object"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"properties"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"query"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"string"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"description"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Search query – name, email address, or company name"&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"limit"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"integer"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"description"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Maximum results to return (1-50)"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"default"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;20&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"minimum"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"maximum"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;50&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"include_inactive"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"boolean"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"description"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Whether to include inactive/archived customers"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"default"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"required"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"query"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The response should include enough metadata for the agent to cite – record IDs, links to the canonical record in your product, last-updated timestamps. This lets the user verify the answer and click through to the source.&lt;/p&gt;

&lt;h3&gt;
  
  
  Read-only design problems
&lt;/h3&gt;

&lt;p&gt;Three product problems matter at this level:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Retrieval quality.&lt;/strong&gt; Are tools well-named so the agent picks the right one? Do they return the right shape of data so the agent does not need three calls when one would do?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Reasoning legibility.&lt;/strong&gt; Does the data include enough metadata for the agent to cite – record IDs, links to canonical records, timestamps – so the user can verify the answer?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Pagination.&lt;/strong&gt; Are large result sets paginated in a way the agent can iterate over without confusion? Cursor-based pagination tends to work better than offset-based for agents.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Read-only security
&lt;/h3&gt;

&lt;p&gt;The security story is comparatively simple. The user grants read access at install. The agent reads. Mutations cannot happen by accident because the surface does not allow them. Enterprise procurement teams approve faster for read-only MCP apps.&lt;/p&gt;

&lt;h3&gt;
  
  
  When to ship at level 1
&lt;/h3&gt;

&lt;p&gt;Ship at level 1 (read-only) when:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Your product holds data the agent benefits from reading&lt;/li&gt;
&lt;li&gt;Your buyer's primary unmet need is &lt;em&gt;I want the agent to know what we know&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;Your safety, audit, or auth story is not yet mature enough to defend writes&lt;/li&gt;
&lt;li&gt;You want the fastest path to MCP presence with the lowest procurement friction&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Actions-Level MCP Apps
&lt;/h2&gt;

&lt;p&gt;An actions MCP app is an MCP app whose tools include mutations – create, update, delete, and send operations the agent can execute on the user's behalf. The agent can draft and send the email, file the ticket, update the record, schedule the meeting, post the invoice, charge the card.&lt;/p&gt;

&lt;p&gt;The tool surface at this level includes both queries and verbs: &lt;code&gt;create_ticket&lt;/code&gt;, &lt;code&gt;update_customer&lt;/code&gt;, &lt;code&gt;send_invoice&lt;/code&gt;, &lt;code&gt;book_meeting&lt;/code&gt;. The agent reads to understand what the user wants and writes to do it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The design demands jump sharply from read-only to actions.&lt;/strong&gt; Four problems become real product surface that did not exist at level 1.&lt;/p&gt;

&lt;h3&gt;
  
  
  Idempotency
&lt;/h3&gt;

&lt;p&gt;The agent will retry. Sometimes because the network glitched, sometimes because it second-guessed itself, sometimes because the user said &lt;em&gt;do that again&lt;/em&gt;. Write tools must tolerate retries without producing duplicates.&lt;/p&gt;

&lt;p&gt;The standard pattern is idempotency keys. The client (the AI client or the agent runtime) generates a unique idempotency key for each logical operation. The server stores recent keys with their results, and repeat calls with the same key return the cached result rather than re-executing.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"name"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"send_invoice"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"description"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Send an invoice to a customer via email. Use when the user wants to bill a customer. Returns the sent invoice ID and a confirmation that it was delivered."&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"inputSchema"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"object"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"properties"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"customer_id"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"string"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"description"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Customer to invoice"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"amount_cents"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"integer"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"description"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Amount in cents"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"minimum"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"currency"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"string"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"default"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"USD"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"idempotency_key"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"string"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"description"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Unique key for this invoice operation. If the same key is provided twice within 24 hours, only one invoice is sent and the original result is returned. The agent should generate a new UUID per logical operation."&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"required"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"customer_id"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"amount_cents"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"idempotency_key"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://docs.stripe.com/api/idempotent_requests" rel="noopener noreferrer"&gt;Stripe's API&lt;/a&gt; is the reference implementation for idempotency keys. The cost of getting idempotency wrong: the user discovers they sent the same invoice three times, or charged the customer twice for one purchase.&lt;/p&gt;

&lt;h3&gt;
  
  
  Reversibility
&lt;/h3&gt;

&lt;p&gt;Some writes are reversible (&lt;code&gt;update_customer&lt;/code&gt;, where the previous state is restorable). Some are not (&lt;code&gt;send_email&lt;/code&gt;, &lt;code&gt;charge_card&lt;/code&gt;, &lt;code&gt;delete_*&lt;/code&gt; without soft-delete).&lt;/p&gt;

&lt;p&gt;The product should make reversible writes obviously reversible. Three patterns work:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Soft delete with undo window.&lt;/strong&gt; &lt;code&gt;delete_customer&lt;/code&gt; doesn't actually delete; it marks the record as deleted with a 30-day restoration window. Returns an &lt;code&gt;undo_token&lt;/code&gt; the agent can pass to &lt;code&gt;restore_customer&lt;/code&gt; if the user changes their mind in the same conversation.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Update with revision history.&lt;/strong&gt; &lt;code&gt;update_customer&lt;/code&gt; writes a new revision, preserving the previous state. The agent can describe what changed and offer to revert.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Two-phase commit for high-stakes operations.&lt;/strong&gt; &lt;code&gt;prepare_charge&lt;/code&gt; returns a token; &lt;code&gt;execute_charge&lt;/code&gt; actually runs. The agent must show the prepared charge to the user before calling execute.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Irreversible writes deserve heavier confirmation, both from the agent (&lt;em&gt;are you sure you want to send this?&lt;/em&gt;) and from the system (rate limits, two-step confirms for high-stakes operations).&lt;/p&gt;

&lt;h3&gt;
  
  
  Intent preview
&lt;/h3&gt;

&lt;p&gt;Before the agent executes a write, the user should be able to see and approve what is about to happen. This is partly the host client's job – Claude, Copilot, and the more mature clients have intent-preview UI built in – but it is also yours: tool parameters need to be expressive enough that the preview is informative.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Bad:&lt;/strong&gt; &lt;code&gt;execute_send_email(payload: {...})&lt;/code&gt;. The preview can only say &lt;em&gt;the agent wants to call execute_send_email&lt;/em&gt;. The user has no idea what the email contains.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Good:&lt;/strong&gt; &lt;code&gt;send_email(to: "alice@acme.com", subject: "Re: contract review", body: "Hi Alice, ...", attachments: [...])&lt;/code&gt;. The preview shows the user exactly what is about to be sent, and the user can edit before approving.&lt;/p&gt;

&lt;p&gt;The principle: parameters should be human-meaningful, not opaque blobs. Pass structured data (recipient, subject, body) rather than serialized payloads.&lt;/p&gt;

&lt;h3&gt;
  
  
  Audit trail
&lt;/h3&gt;

&lt;p&gt;Every write through the MCP app should be attributable. Per-invocation logs that capture: user identity, host AI client, session identifier, tool invoked, parameters passed, result, timestamp.&lt;/p&gt;

&lt;p&gt;Enterprise buyers will require this. Consumer buyers will appreciate it the first time something goes wrong. The audit log should be queryable by the customer's admin, not just by your support team. See &lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP auth and security&lt;/a&gt; for the customer-facing audit log surface bar.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Common Failure Mode&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The most common failure mode in MCP work is shipping &lt;code&gt;delete_*&lt;/code&gt; and &lt;code&gt;send_*&lt;/code&gt; tools without reversibility or audit, then watching the first incident erode trust faster than the feature earned it. The second-most-common failure is shipping level 2 with the audit log built but not exposed to customer admins – the audit exists technically and not procedurally, which is the worst of both worlds. If you cannot expose the audit log to customer admins on day one, you are not ready for level 2.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  When to ship at level 2
&lt;/h3&gt;

&lt;p&gt;Ship at level 2 (actions) when:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The user's job-to-be-done in the AI client requires changing your system, not just reading it&lt;/li&gt;
&lt;li&gt;You have built (or are committed to building) idempotency keys, soft-delete or revision-history reversibility, intent-preview-friendly parameter shapes, and per-invocation audit logs&lt;/li&gt;
&lt;li&gt;The business value of writes clearly exceeds the cost of doing them properly&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Agent-Resident MCP Apps
&lt;/h2&gt;

&lt;p&gt;The deepest level is the one almost no product team is at today, and the few who are have rebuilt themselves around it.&lt;/p&gt;

&lt;p&gt;An agent-resident MCP app does not just let the agent invoke tools. It treats the agent as a first-class user of the product, with its own identity, its own audit trail, its own relationships with other entities, and its operation across time. Your product is not being read or written by the agent; it is being inhabited by the agent.&lt;/p&gt;

&lt;p&gt;Concretely, the difference between level 2 and level 3 is the difference between exposing &lt;code&gt;create_ticket&lt;/code&gt; (a single operation) and exposing a tool surface rich enough that the agent can run an entire support triage workflow – read the ticket, draft a response, escalate to a specialist if needed, mark resolved if it can, follow up tomorrow if it can't, and accumulate context across all of that as a coherent participant in the support queue.&lt;/p&gt;

&lt;h3&gt;
  
  
  Three structural changes
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;The agent has its own identity in your system&lt;/strong&gt;, separate from any human user. There is a row in your &lt;code&gt;users&lt;/code&gt; or &lt;code&gt;service_accounts&lt;/code&gt; table for the agent.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="s"&gt;service_accounts&lt;/span&gt;
  &lt;span class="s"&gt;id&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s"&gt;srv_acct_42&lt;/span&gt;
  &lt;span class="s"&gt;type&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;agent"&lt;/span&gt;
  &lt;span class="na"&gt;human_principal_user_id&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;usr_178      // user the agent acts on behalf of&lt;/span&gt;
  &lt;span class="na"&gt;host_client&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;claude.ai"&lt;/span&gt;
  &lt;span class="na"&gt;permissions_envelope&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;...&lt;/span&gt; &lt;span class="pi"&gt;}&lt;/span&gt;
  &lt;span class="na"&gt;created_at&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;2026-01-15&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;The agent participates in your product's internal mechanisms&lt;/strong&gt; – assignments, notifications, escalations, status changes – alongside human users. A ticket can be assigned to an agent. A workflow can be triggered by an agent's action.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="s"&gt;tickets&lt;/span&gt;
  &lt;span class="s"&gt;id&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s"&gt;tkt_91&lt;/span&gt;
  &lt;span class="s"&gt;assigned_to&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s"&gt;srv_acct_42       // assigned to an agent&lt;/span&gt;
  &lt;span class="s"&gt;status&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;in_progress"&lt;/span&gt;
  &lt;span class="na"&gt;agent_metadata&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;{&lt;/span&gt;
    &lt;span class="nv"&gt;confidence_score&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="nv"&gt;0.84&lt;/span&gt;&lt;span class="pi"&gt;,&lt;/span&gt;
    &lt;span class="nv"&gt;escalation_threshold&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="nv"&gt;0.6&lt;/span&gt;
  &lt;span class="pi"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;The agent accumulates state across sessions.&lt;/strong&gt; It is not amnesiac between calls. It remembers what it tried last week, who it has been working with, which approaches have worked. This requires a persistent memory store the agent can read and write across sessions, scoped to the agent's identity.&lt;/p&gt;

&lt;h3&gt;
  
  
  Architectural commitment
&lt;/h3&gt;

&lt;p&gt;Level 3 requires rethinking the product's permission model, identity model, audit model, notification model, and often the underlying data model. It requires designing for an actor that does not have a coffee cup, does not get tired, and is operating in parallel sessions on behalf of multiple users.&lt;/p&gt;

&lt;h3&gt;
  
  
  When to ship at level 3
&lt;/h3&gt;

&lt;p&gt;Ship at level 3 (agent-resident) when the strategic premise of the company is that agents are a primary user class, not a guest, and the product is being built or rebuilt around that premise. Do &lt;em&gt;not&lt;/em&gt; ship at level 3 when the company has not made that strategic commitment – level 3 attempted as a product extension fails, because it requires changes to identity, permissions, audit, notification, and often data models that retrofits cannot supply.&lt;/p&gt;

&lt;h2&gt;
  
  
  Choosing and Sequencing Levels
&lt;/h2&gt;

&lt;p&gt;Most product teams should ship level 1 first, expand to level 2 when the safety story is mature, and consider level 3 only if the company is rebuilding around an agent-first thesis.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Your situation&lt;/th&gt;
&lt;th&gt;Recommended level&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;First MCP ship, no prior MCP experience&lt;/td&gt;
&lt;td&gt;Level 1 (read-only)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Have shipped read-only, ready for writes, have safety infrastructure&lt;/td&gt;
&lt;td&gt;Level 2 (actions)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Agent-first startup; product designed for agents from inception&lt;/td&gt;
&lt;td&gt;Level 2 or 3 (depending on architectural readiness)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Established product wanting to extend into MCP&lt;/td&gt;
&lt;td&gt;Level 1 first; level 2 by quarter three&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Destination product with cannibalization risk&lt;/td&gt;
&lt;td&gt;Level 1 only; do not expand&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;System of record with deep agent-mediated workflows in your audience&lt;/td&gt;
&lt;td&gt;Level 2 within first year; level 3 only with explicit strategic commitment&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  Progression versus leap
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Most teams should progress: level 1 first, learn, level 2 when ready, level 3 only with strategic commitment.&lt;/strong&gt; A small minority – usually agent-first startups – should leap directly to level 2 or 3 because the product is being designed for that level from inception.&lt;/p&gt;

&lt;p&gt;The progression model is both a defensive strategy and a learning strategy. Read-only MCP apps generate the data – what users actually ask for, where the agent gets stuck, what tools get invoked – that informs actions design. Level 2 generates the safety and audit infrastructure that informs agent-resident design. Skip levels and the next level is built on instinct rather than evidence.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Questions Before Picking a Level&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;What is the user's job-to-be-done that requires more than reading? If you cannot answer in one sentence, level 1 is correct. What is the worst write the agent can do, and what is the recovery path? If the answer is "we'd lose data" or "we'd send something we cannot take back," level 2 safety infrastructure is non-negotiable. What is your audit story for agent-mediated actions? If you cannot produce a per-action audit log on day one, level 2 is premature. What changes about our product if the agent is a first-class user? If the answer is "very little," you are not at level 3.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The level you ship at is not a measure of ambition. It is a measure of what the product can defend. Most teams' honest answer is level 1 first, level 2 by quarter three, level 3 only if the company is rebuilding around it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Guides
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;What to Call MCP Apps: Terminology Guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-embed-app-ai-clients" rel="noopener noreferrer"&gt;How to Embed Your App in AI Clients with MCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-strategy-decision-framework" rel="noopener noreferrer"&gt;MCP Strategy Decision Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP Auth and Security&lt;/a&gt; – Auth design that supports the level you ship at&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP Build vs Buy&lt;/a&gt; – Cost ranges per embedding level&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;What is the difference between read-only and actions in MCP?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Read-only MCP apps expose only query tools (the agent can read data but cannot change it). Actions MCP apps expose query and mutation tools (the agent can create, update, delete, send). Actions require idempotency keys, reversibility patterns (soft delete, revision history, two-phase commit), intent-preview-friendly parameter shapes, and per-action audit logs that read-only does not.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is read-only MCP enough for most products?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;For first ships, almost always yes. Read-only is the right starting point unless the product team has prior MCP experience and a defensible safety story for writes. For some destination products, read-only is the permanent right level, not a stepping stone.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is agent-resident MCP?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;An agent-resident MCP app treats the agent as a first-class user of the product, with its own identity in your data model, accumulated state across sessions, and participation in the product's internal mechanisms (assignments, notifications, escalations). Almost no products are at this level in 2026; those that are have rebuilt around the agent-first thesis.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can I ship MCP write tools without idempotency?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;You can ship them, but you should not. Agents will retry, and write tools without idempotency produce duplicate records, duplicate emails, or duplicate charges – incidents that erode trust faster than the feature earned it. Idempotency keys (UUID-based, with server-side caching of recent results) are non-negotiable for level 2.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is an idempotency key in an MCP tool?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;An idempotency key is a unique identifier the agent passes with each write operation. The server stores recent keys with their results; if the same key is sent twice within a window (typically 24 hours), the server returns the original result rather than re-executing the operation. This makes retries safe and prevents duplicate writes. Stripe's API is the reference implementation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How do you implement reversibility in MCP write tools?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Three patterns: soft delete with undo window (operations don't immediately destroy data; they mark records and offer restoration tokens), update with revision history (writes preserve previous state and expose a revert path), and two-phase commit (prepare-and-execute for high-stakes operations). Pick the pattern per operation based on blast radius.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How long does it take to ship at each MCP embedding level?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Level 1 (read-only), single client: one quarter ($100K–$300K partner-built). Level 2 (actions), single client: two quarters ($300K–$700K partner-built). Level 3 (agent-resident): multi-quarter, often a multi-year program ($1M+).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Should I skip read-only and go straight to actions?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Most teams should not. Read-only generates the usage data and infrastructure that informs the actions design. Skipping read-only is appropriate only for agent-first startups whose product is designed for level 2+ from inception.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What happens if I ship the wrong embedding level?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Shipping too low leaves user value on the table; shipping too high produces incidents the safety infrastructure cannot defend. The first failure mode (too low) is recoverable in a quarter. The second (too high) can produce trust damage that takes a year to recover from.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can I have different MCP embedding levels per host client?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Yes, and this is sometimes the right move. Ship level 2 actions on Claude (where per-tool consent and intent-preview UI are mature) and level 1 read-only on Cursor (where per-tool consent is weaker). Match the embedding level to what the host client's safety surface can support.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=guides" rel="noopener noreferrer"&gt;launchdayadvisors.com&lt;/a&gt;. Launch Day Advisors is a buyer-side advisory firm: we help companies select AI, software, and design partners, and we are paid only by the buyer.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>mcp</category>
      <category>ai</category>
      <category>architecture</category>
      <category>productmanagement</category>
    </item>
    <item>
      <title>MCP Build vs Buy: Should You Hire a Development Partner or Build In-House?</title>
      <dc:creator>Jonathan Blessing</dc:creator>
      <pubDate>Fri, 18 Sep 2026 12:59:13 +0000</pubDate>
      <link>https://dev.to/launchdayadvisors/mcp-build-vs-buy-should-you-hire-a-development-partner-or-build-in-house-3jo7</link>
      <guid>https://dev.to/launchdayadvisors/mcp-build-vs-buy-should-you-hire-a-development-partner-or-build-in-house-3jo7</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;In brief:&lt;/strong&gt; Build your MCP server in-house if MCP is strategically central, your roadmap coupling is tight, your team has agentic-system experience, or your product is a system of record requiring deep data-model integration. Hire a partner if time-to-ship matters more than ownership depth, your engineering capacity is fully committed, your team has not built for non-human consumers, or your first ship is a learning ship. Partner-built level-1 read-only MCP apps cost ~$100K–$300K; level-2 actions apps cost ~$300K–$700K. In-house equivalents cost 60–80% in raw spend but add headcount and calendar time. The hybrid that consistently works: partner-led first ship with structured knowledge transfer, then in-house for level-2 expansion.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Every product team that takes MCP seriously eventually arrives at the same fork: build it with internal engineering or hire a development partner. The strategic case is settled (the company is shipping an MCP app); the question is how. Build in-house if MCP is strategically central, your roadmap coupling is tight, your team has agentic-system experience, or your product is a system of record. Hire a partner if time-to-ship matters more than ownership depth, your engineering capacity is committed, your team has not built for non-human consumers, or your first ship is a learning ship. The hybrid that consistently works: partner-led first ship with structured knowledge transfer, then in-house for level-2 expansion.&lt;/p&gt;

&lt;p&gt;The shape of this decision is not new; companies have made it about mobile apps, integrations, marketing sites, and every other strategic surface where in-house and external delivery both compete. The MCP-specific texture is what changes the answer. The category is young, the work is adjacent to but not the same as previous specialties, and the failure mode of getting the build wrong is delayed by six to nine months – long enough that the team that picked the wrong path is rarely the team that pays for the choice.&lt;/p&gt;

&lt;p&gt;This guide is for the product or engineering leader who has crossed the strategic threshold (see &lt;a href="https://launchdayadvisors.com/guides/mcp-strategy-decision-framework" rel="noopener noreferrer"&gt;the MCP strategy decision framework&lt;/a&gt; if you have not) and is now making the build-vs-buy call. For broader AI implementation cost context, see our &lt;a href="https://launchdayadvisors.com/guides/ai-implementation-cost" rel="noopener noreferrer"&gt;AI implementation cost guide&lt;/a&gt;. For pricing-model selection, see &lt;a href="https://launchdayadvisors.com/guides/fixed-fee-vs-time-and-materials" rel="noopener noreferrer"&gt;fixed fee vs time and materials&lt;/a&gt;.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The Optimistic Estimate Is What Kills In-House Programs&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The build-vs-buy conversation is usually distorted by an undersized estimate of the work. A serious MCP app shipped to one client at level-2 (actions) depth is not a two-week sprint and not a single-engineer project. Teams that estimate MCP as a side project routinely discover by month three that they are short two engineers and a designer, and by month six that the first ship will not clear the safety bar that procurement is going to ask about.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  What Building an MCP App Actually Involves
&lt;/h2&gt;

&lt;p&gt;A serious MCP app – single client, level-2 (actions) depth – is one to two quarters of work for a properly staffed team. The full scope:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Server implementation&lt;/strong&gt; – process, hosting, observability, deployment pipeline, built to the MCP spec (JSON-RPC 2.0 over stdio, SSE, or streamable HTTP)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tool surface design&lt;/strong&gt; – &lt;code&gt;create_&lt;/code&gt;, &lt;code&gt;update_&lt;/code&gt;, &lt;code&gt;search_&lt;/code&gt;, &lt;code&gt;get_&lt;/code&gt; operations named with the precision of a public API&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Auth implementation&lt;/strong&gt; – OAuth 2.1 + PKCE typically, with Dynamic Client Registration (RFC 7591) and authorization server metadata (RFC 8414); plus alternate paths per target client; scope taxonomy; token lifetime and refresh; revocation flows. See &lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP auth and security&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Audit and logging surface&lt;/strong&gt; – per-invocation logs, parameter capture, session reconstruction, customer-admin-facing log views&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Safety story&lt;/strong&gt; – idempotency keys, reversibility patterns (soft delete, revision history), intent-preview-friendly parameter shapes. See &lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;MCP embedding types&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Distribution package&lt;/strong&gt; – submission to host client's marketplace, store metadata, screenshots, documentation, support workflow&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Maintenance commitment&lt;/strong&gt; – keeping up with host client's spec changes, auth changes, distribution-policy changes, your own evolving tool surface, indefinitely&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;That list is the work for one client. Each additional client adds variance – different auth, different distribution, different terminology, different review process – typically at 30–60% of the original cost of the first ship, depending on overlap.&lt;/p&gt;

&lt;h2&gt;
  
  
  When In-House Is Right
&lt;/h2&gt;

&lt;p&gt;In-house wins when one or more of the following is true:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;MCP is strategically central&lt;/strong&gt; to your product over the next three years. A category-defining product treating MCP as a major distribution surface needs the muscle in-house, eventually, regardless of how the first ship goes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Your roadmap coupling is tight.&lt;/strong&gt; The MCP app's tool surface evolves week by week with the underlying product, and the cost of cross-team coordination with an external partner exceeds the cost of having the team in your building.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Your engineering team has agentic-system experience.&lt;/strong&gt; Senior engineers who have built API products for non-human consumers – agents, integrations, automation systems – are the right people for this work. Teams without that experience can develop it, but the first MCP app is an expensive place to learn.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Your product is a system of record&lt;/strong&gt; (CRM, issue tracker, finance system) where the depth of integration into your own data model is the work, and an external partner's lack of access to that model would be the bottleneck.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The honest cost of in-house: slower in months one through six, expensive in headcount, and a first version that bears the marks of the team's first contact with the category. Real ownership in exchange for a longer, more uneven path.&lt;/p&gt;

&lt;h3&gt;
  
  
  What an in-house MCP team looks like
&lt;/h3&gt;

&lt;p&gt;A properly staffed in-house team for a level-2 single-client MCP app:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Role&lt;/th&gt;
&lt;th&gt;Allocation&lt;/th&gt;
&lt;th&gt;What they own&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Product manager&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;50–100%&lt;/td&gt;
&lt;td&gt;Posture decision, embedding-level call, tool surface scoping, marketplace submission&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Tech lead / architect&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;50–100%&lt;/td&gt;
&lt;td&gt;MCP spec implementation, auth design, audit infrastructure, hosting&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Backend engineer (senior)&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;100% × 2&lt;/td&gt;
&lt;td&gt;Tool implementation, server code, OAuth integration&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Backend engineer (mid)&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;100% × 1&lt;/td&gt;
&lt;td&gt;Audit log, supporting infrastructure&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Designer&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;25–50%&lt;/td&gt;
&lt;td&gt;Tool description quality, intent-preview UX, customer admin UI for audit logs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Security engineer&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;25–50%&lt;/td&gt;
&lt;td&gt;Threat model review, scope taxonomy review, penetration testing coordination&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;DevOps / SRE&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;25–50%&lt;/td&gt;
&lt;td&gt;Hosting, observability, deployment, on-call rotation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Technical writer&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;25–50%&lt;/td&gt;
&lt;td&gt;Tool descriptions, marketplace listing copy, customer documentation&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Roughly 4.5–6 FTE-equivalent for two quarters, plus partial allocations for security and devops. Smaller teams can ship – but most ships from sub-scale teams require rework within twelve months.&lt;/p&gt;

&lt;h3&gt;
  
  
  The in-house calendar timeline
&lt;/h3&gt;

&lt;p&gt;A representative two-quarter calendar:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Phase&lt;/th&gt;
&lt;th&gt;Calendar weeks&lt;/th&gt;
&lt;th&gt;Key deliverables&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Strategy &amp;amp; scope&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Weeks 1–3&lt;/td&gt;
&lt;td&gt;Posture documented, target client picked, embedding level set, tool surface scoped&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Auth &amp;amp; scope design&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Weeks 3–5&lt;/td&gt;
&lt;td&gt;OAuth integration designed; scope taxonomy locked; audit log spec written&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Server foundation&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Weeks 5–9&lt;/td&gt;
&lt;td&gt;MCP spec implemented; transport selected; hosting; observability live&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Tool implementation, batch 1&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Weeks 7–12&lt;/td&gt;
&lt;td&gt;First 5–10 read tools shipped to staging; agent invocation tested&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Tool implementation, batch 2&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Weeks 10–18&lt;/td&gt;
&lt;td&gt;Write tools shipped with idempotency, reversibility; intent preview tested&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Audit log + customer admin UI&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Weeks 14–20&lt;/td&gt;
&lt;td&gt;Customer-facing audit log live; tamper-evident storage configured&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Marketplace submission &amp;amp; polish&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Weeks 18–22&lt;/td&gt;
&lt;td&gt;Listing submitted; review iteration; first user installs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Beta + iteration&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Weeks 22–26&lt;/td&gt;
&lt;td&gt;Closed beta; feedback incorporated; general availability&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;This is a clean two-quarter run with no major surprises. Real-world timelines slip on auth complexity, host-client review iterations, and audit log requirements; build a 2–3 week buffer.&lt;/p&gt;

&lt;h2&gt;
  
  
  When a Partner Is Right
&lt;/h2&gt;

&lt;p&gt;A partner wins when one or more of the following is true:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Time-to-ship matters more than ownership depth&lt;/strong&gt; in the next two quarters. The MCP-app distribution surface is a window; being twelve months later costs you compounding presence in host clients.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Your engineering capacity is fully committed&lt;/strong&gt; to existing roadmap. Pulling four engineers off existing commitments is more expensive than the partner cost.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Your team has not built for non-human consumers before.&lt;/strong&gt; The patterns that produce a good MCP app – tool naming, idempotency, intent legibility, audit hygiene – are unfamiliar to teams whose API design has only ever served human-driven clients.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The category is moving fast enough that staying current is meaningful work.&lt;/strong&gt; A partner whose business is MCP absorbs auth model changes, distribution policy changes, spec additions across many clients; an internal team treats each change as an unplanned project.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Your first ship is a learning ship&lt;/strong&gt;, and you would rather rent the learning than buy it.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The honest cost of a partner: less ownership of design choices, more coordination overhead at the seams, and transition risk if you eventually want to bring it in-house. The right partner mitigates the first and second; the third is a real cost the contract structure should address up front.&lt;/p&gt;

&lt;p&gt;If you go this route, see &lt;a href="https://launchdayadvisors.com/guides/evaluate-mcp-build-partner" rel="noopener noreferrer"&gt;how to evaluate an MCP build partner&lt;/a&gt; for the buyer's checklist that separates real MCP-shipping teams from generalist agencies.&lt;/p&gt;

&lt;h2&gt;
  
  
  Cost Ranges and Line Items
&lt;/h2&gt;

&lt;p&gt;The rough cost envelopes for partner-built MCP apps in 2026:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Scope&lt;/th&gt;
&lt;th&gt;Calendar time&lt;/th&gt;
&lt;th&gt;Partner cost (USD)&lt;/th&gt;
&lt;th&gt;In-house cost (raw spend)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Level-1 read-only, single client&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;~1 quarter&lt;/td&gt;
&lt;td&gt;$100K–$300K&lt;/td&gt;
&lt;td&gt;$80K–$240K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Level-2 actions, single client&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;~2 quarters&lt;/td&gt;
&lt;td&gt;$300K–$700K&lt;/td&gt;
&lt;td&gt;$200K–$520K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Level-2 actions, two clients&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;~2.5–3 quarters&lt;/td&gt;
&lt;td&gt;$420K–$1.2M&lt;/td&gt;
&lt;td&gt;$300K–$900K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Level-3 agent-resident&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Multi-quarter program&lt;/td&gt;
&lt;td&gt;$1M+&lt;/td&gt;
&lt;td&gt;$700K+&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;In-house numbers above reflect raw spend (salaries × allocation × calendar time) and exclude opportunity cost of pulled-from-roadmap engineering. Total in-house cost including opportunity cost typically lands close to partner cost. For a dedicated cost breakdown – per-scope ranges, line items, ongoing costs, and three worked examples – see &lt;a href="https://launchdayadvisors.com/guides/mcp-server-cost" rel="noopener noreferrer"&gt;what an MCP server costs to build&lt;/a&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  Detailed line items: level-2 partner build
&lt;/h3&gt;

&lt;p&gt;A representative line-item breakdown for a level-2 single-client partner build at the middle of the range ($500K total):&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Component&lt;/th&gt;
&lt;th&gt;Typical cost (USD)&lt;/th&gt;
&lt;th&gt;What it covers&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Discovery, design, scope taxonomy&lt;/td&gt;
&lt;td&gt;$40K–$80K&lt;/td&gt;
&lt;td&gt;Posture review, embedding-level call, scope design, tool surface specification&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Server implementation, hosting, observability&lt;/td&gt;
&lt;td&gt;$50K–$100K&lt;/td&gt;
&lt;td&gt;MCP spec implementation, transport, hosting infra, monitoring&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Tool surface (10–25 tools)&lt;/td&gt;
&lt;td&gt;$80K–$180K&lt;/td&gt;
&lt;td&gt;Implementation, validation, testing, documentation per tool&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;OAuth implementation, scope design&lt;/td&gt;
&lt;td&gt;$60K–$120K&lt;/td&gt;
&lt;td&gt;OAuth 2.1 + PKCE + DCR; scope taxonomy; token lifecycle; revocation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Audit log infrastructure + customer-admin surface&lt;/td&gt;
&lt;td&gt;$40K–$80K&lt;/td&gt;
&lt;td&gt;Per-invocation logging; tamper-evident storage; admin UI&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Safety story (idempotency, reversibility, intent preview)&lt;/td&gt;
&lt;td&gt;$60K–$120K&lt;/td&gt;
&lt;td&gt;Idempotency keys; soft-delete + restore; revision history; two-phase commit&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Marketplace submission, distribution polish&lt;/td&gt;
&lt;td&gt;$20K–$50K&lt;/td&gt;
&lt;td&gt;Listing copy; screenshots; review iteration; documentation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Project management, knowledge transfer, contingency&lt;/td&gt;
&lt;td&gt;$40K–$80K&lt;/td&gt;
&lt;td&gt;PM overhead; runbooks; pairing engagements; buffer&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Total&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;$390K–$810K&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  Detailed line items: in-house equivalent
&lt;/h3&gt;

&lt;p&gt;For an in-house build at the same scope:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Component&lt;/th&gt;
&lt;th&gt;Typical cost (USD)&lt;/th&gt;
&lt;th&gt;Calendar weeks&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1 PM @ 75% × 26 weeks&lt;/td&gt;
&lt;td&gt;$50K&lt;/td&gt;
&lt;td&gt;26&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;1 Tech lead @ 75% × 26 weeks&lt;/td&gt;
&lt;td&gt;$60K&lt;/td&gt;
&lt;td&gt;26&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2 Senior backend engineers × 26 weeks&lt;/td&gt;
&lt;td&gt;$130K&lt;/td&gt;
&lt;td&gt;26&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;1 Mid backend engineer × 20 weeks&lt;/td&gt;
&lt;td&gt;$50K&lt;/td&gt;
&lt;td&gt;20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Designer @ 30% × 16 weeks&lt;/td&gt;
&lt;td&gt;$20K&lt;/td&gt;
&lt;td&gt;16&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Security engineer @ 30% × 12 weeks&lt;/td&gt;
&lt;td&gt;$15K&lt;/td&gt;
&lt;td&gt;12&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DevOps @ 25% × 16 weeks&lt;/td&gt;
&lt;td&gt;$15K&lt;/td&gt;
&lt;td&gt;16&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Technical writer @ 30% × 8 weeks&lt;/td&gt;
&lt;td&gt;$10K&lt;/td&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Hosting + tooling&lt;/td&gt;
&lt;td&gt;$20K&lt;/td&gt;
&lt;td&gt;26&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Penetration test (third party)&lt;/td&gt;
&lt;td&gt;$30K&lt;/td&gt;
&lt;td&gt;one-time&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Total&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;~$400K&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;These payroll numbers assume burdened-cost rates roughly representative of US-based product engineering. Actual numbers shift with team location, seniority mix, and accounting conventions. The point is that the gap between partner and in-house in raw dollars is real but smaller than teams typically assume – the bigger gap is calendar time and opportunity cost.&lt;/p&gt;

&lt;h2&gt;
  
  
  Hybrid Models and Contract Structure
&lt;/h2&gt;

&lt;p&gt;Three hybrid patterns are common in 2026, and one is worth avoiding.&lt;/p&gt;

&lt;h3&gt;
  
  
  Pattern 1: Partner-led first ship, in-house second ship
&lt;/h3&gt;

&lt;p&gt;The partner builds the level-1 read-only MCP app (or level-2 actions for the strategic client) and hands off to the internal team for expansion. &lt;strong&gt;Works when&lt;/strong&gt; knowledge transfer is baked into the partner contract and the internal team is shadow-staffed during the first build. &lt;strong&gt;Fails when&lt;/strong&gt; the internal team tries to take ownership of code and decisions they were not part of making.&lt;/p&gt;

&lt;p&gt;Required contract elements:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Pairing requirement.&lt;/strong&gt; Internal engineers paired with partner engineers from week 4 onwards (not just for handoff at the end).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Runbook deliverable.&lt;/strong&gt; A specific contract line item for runbooks covering deployment, on-call, common incidents, scope updates, host-client review iteration.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Architecture review milestones.&lt;/strong&gt; Internal architecture review at end of each phase (auth, server, tools, audit), with documented sign-off.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Source code ownership.&lt;/strong&gt; Code written by partner is owned by client from day one. License terms unambiguous.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Transition support.&lt;/strong&gt; 60–90 days of post-handoff support included.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Pattern 2: Partner for client breadth, in-house for client depth
&lt;/h3&gt;

&lt;p&gt;Internal team owns the deepest MCP app – usually for the client where buyer concentration is highest – and a partner ports to secondary clients. &lt;strong&gt;Right pattern for&lt;/strong&gt; products with one strategic client and three or four secondary ones; the cost is coordination of design choices across the in-house/partner boundary.&lt;/p&gt;

&lt;p&gt;Required contract elements:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Architecture-as-spec deliverable.&lt;/strong&gt; Internal team writes the architecture spec before partner engagement begins. Partner ports.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Per-client SOWs&lt;/strong&gt; with consistent scope structure.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cross-client compatibility requirement.&lt;/strong&gt; Partner-built clients must follow internal team's tool surface conventions.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Pattern 3: Partner indefinitely
&lt;/h3&gt;

&lt;p&gt;Some companies are honest with themselves that MCP, while strategic, is not the surface where they want to develop deep internal expertise. &lt;strong&gt;Defensible when&lt;/strong&gt; the partner relationship is durable; &lt;strong&gt;fragile when&lt;/strong&gt; partner staffing rotates or the partner exits the category.&lt;/p&gt;

&lt;p&gt;Required contract elements:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Long-term retainer&lt;/strong&gt; ($5K–$25K/month) covering maintenance, host-client spec changes, minor feature work&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Key-person clauses&lt;/strong&gt; – specific named engineers committed; 90+ day rotation notice&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Source code ownership&lt;/strong&gt; – same as Pattern 1&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Disengagement protocol&lt;/strong&gt; – what happens if the partner exits or is acquired; source escrow; transition assistance&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The Hybrid That Doesn't Work&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Partner for some things, in-house for others, with no documented split and no agreed-on transition trigger. That is not a hybrid; it is two half-staffed teams working around each other, and it consistently produces a first ship that is neither partner-quality nor internally-owned. By month three the team has built half an MCP app, the auth is an MVP, the audit log is a TODO, and the distribution package is a slide. The fix is to make the structure explicit before staffing, not after.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  What an MCP partner contract should include
&lt;/h3&gt;

&lt;p&gt;The minimum bar:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Statement of Work&lt;/strong&gt; with embedded line items matching the cost breakdown above&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Acceptance criteria per phase&lt;/strong&gt; – what does &lt;em&gt;auth design complete&lt;/em&gt; mean? What does &lt;em&gt;tool surface implemented&lt;/em&gt; mean?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;IP ownership.&lt;/strong&gt; Code is yours. License explicit.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Source code escrow&lt;/strong&gt; for partners who hold ongoing operational responsibility.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Audit log deliverable&lt;/strong&gt; – partner is responsible for not only building the audit log but also for surfacing it to customer admins.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Penetration test deliverable&lt;/strong&gt; – third-party pentest before launch, with remediation included in scope.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Knowledge transfer deliverables&lt;/strong&gt; – documented runbooks; pairing engagement schedule; architecture review milestones with internal sign-off.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Maintenance terms&lt;/strong&gt; – what's included; what counts as scope change; rate card.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Disengagement clauses&lt;/strong&gt; – termination notice; transition assistance; source escrow.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Key-person commitments&lt;/strong&gt; – named engineers; rotation notice.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Confidentiality&lt;/strong&gt; – including AI training. Whether the partner can use any artifacts from your engagement to train models or improve their own tools.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The most common contract gaps are knowledge transfer (often soft-pedaled) and audit log surfacing (often left as engineering detail). Both deserve explicit line items.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Do You Decide Between MCP In-House and Partner?
&lt;/h2&gt;

&lt;p&gt;A short framework that captures most of the answer.&lt;/p&gt;

&lt;h3&gt;
  
  
  The decision rubric
&lt;/h3&gt;

&lt;p&gt;Score each from 1 (strongly in-house) to 5 (strongly partner):&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Roadmap pressure to ship within two quarters.&lt;/strong&gt; 1 = no pressure, can take six months. 5 = need to ship in ten weeks.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Lack of internal agentic-system experience.&lt;/strong&gt; 1 = team has shipped multiple agent or integration products. 5 = team has never built for non-human consumers.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Strategic centrality of MCP to the company in three years.&lt;/strong&gt; 1 = MCP is strategic core. 5 = MCP is a checkbox.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Available internal engineering capacity.&lt;/strong&gt; 1 = full team can be allocated. 5 = no engineers available.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Number of clients you intend to ship to in year one.&lt;/strong&gt; 1 = one client only. 5 = four or more.&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Score&lt;/th&gt;
&lt;th&gt;Recommended path&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;≤ 2.5&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;In-house – strategic centrality and team capability favor ownership&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;2.5 – 3.5&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Hybrid – partner-led first ship with structured handoff&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;≥ 3.5&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Partner – speed and capacity constraints favor external delivery&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  Break-even analysis
&lt;/h3&gt;

&lt;p&gt;A simplified break-even calculation for partner vs in-house at a level-2 single-client engagement:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Partner cost:&lt;/strong&gt; $500K, 6 months calendar → ship in 6 months&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;In-house cost:&lt;/strong&gt; $400K raw spend + opportunity cost (4 engineers × 6 months pulled from existing roadmap) → ship in 7–8 months&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If the opportunity cost of those 4 engineers (delayed feature work, missed customer commitments, slowed pipeline) exceeds $100K, partner wins on total cost. For most growth-stage SaaS companies, it does. For more mature companies with slack engineering capacity, in-house wins.&lt;/p&gt;

&lt;p&gt;The score is a starting point, not an answer. The real test: do your engineering leader and product leader read the score the same way? If they disagree, the disagreement is about an underlying assumption (how strategic this is, how fast the team can move) that needs to surface before the build starts.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Questions Before You Commit&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Have you spoken with three partners and gotten written scopes? Or only seen pitch decks? If you are leaning in-house, do you have the headcount available without pulling from existing roadmap commitments? If you are leaning partner, do you have a defensible answer for what happens at month nine when the partner's team rotates? If any of these answers is "we'll figure it out," the decision is not yet ready to be made.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Where the Wrong Call Shows Up
&lt;/h2&gt;

&lt;p&gt;The wrong move is the one we see most often: deferring the decision, staffing thinly with whoever is available, and producing a first ship that is neither a partner-quality launch nor an internally-owned program. By month three, the team has built half an MCP app. By month six, the company is hiring, or hiring a partner, or both, and the first ship has missed the window the strategy was built around.&lt;/p&gt;

&lt;p&gt;The cost of picking the wrong path is real. The cost of failing to pick is larger.&lt;/p&gt;

&lt;p&gt;If you are leaning toward in-house, staff for it like a product, not a side project. Designate a product owner. Block a dedicated team for at least two quarters. Build the auth design before the tools.&lt;/p&gt;

&lt;p&gt;If you are leaning toward a partner, the next question is &lt;em&gt;which partner&lt;/em&gt;. The criteria that separate partners who have shipped real MCP apps from generalist agencies with a fresh interest in the category are concrete. They are the subject of &lt;a href="https://launchdayadvisors.com/guides/evaluate-mcp-build-partner" rel="noopener noreferrer"&gt;How to evaluate an MCP build partner&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The work compounds either way. Half-staffed work that neither side owns does not.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Guides
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;What to Call MCP Apps: Terminology Guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-embed-app-ai-clients" rel="noopener noreferrer"&gt;How to Embed Your App in AI Clients with MCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-strategy-decision-framework" rel="noopener noreferrer"&gt;MCP Strategy Decision Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;MCP Embedding Types: Read-Only vs Actions vs Agent-Resident&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP Auth and Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/evaluate-mcp-build-partner" rel="noopener noreferrer"&gt;How to Evaluate an MCP Build Partner&lt;/a&gt; – Buyer's checklist for partner selection&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/ai-implementation-cost" rel="noopener noreferrer"&gt;AI Implementation Cost&lt;/a&gt; – Broader AI implementation budget framework&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/fixed-fee-vs-time-and-materials" rel="noopener noreferrer"&gt;Fixed Fee vs Time and Materials&lt;/a&gt; – Pricing-model risk allocation&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;How much does it cost to build an MCP server?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;In 2026, partner-built MCP apps typically cost $100K–$300K for a level-1 read-only single-client ship, $300K–$700K for a level-2 actions single-client ship, and roughly 1.4–1.7× the single-client cost for two-client expansion. In-house equivalents run 60–80% of the partner cost in raw spend, with longer calendar time and opportunity cost typically closing the gap.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How long does it take to build an MCP server in-house?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A properly staffed in-house team can ship a level-1 read-only MCP app in one quarter and a level-2 actions MCP app in two quarters (calendar weeks 1–26). Add 1–2 months for teams without prior agentic-system experience. Sub-scale staffing (one engineer, part-time) consistently produces longer timelines and worse first ships.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What roles do I need on an in-house MCP team?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A level-2 single-client MCP build typically needs ~4.5–6 FTE-equivalent: PM (50–100%), tech lead (50–100%), 2 senior backend engineers (100%), 1 mid backend engineer (100% × 5 months), designer (25–50%), security engineer (25–50%), DevOps (25–50%), technical writer (25–50%).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Should I hire an MCP agency or freelancer?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;For most product teams, an established MCP agency or development partner is the right choice over individual freelancers. The work spans server implementation, auth design, audit infrastructure, safety story, and distribution – broader than a single freelancer typically covers.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can I build an MCP server with one engineer?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;You can build a prototype, not a production MCP app. A single engineer can produce a working MCP server in a sprint, but the auth, safety, audit, and distribution work that separates a prototype from a shippable product is not single-engineer work.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What's the cheapest way to ship an MCP app?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Level-1 read-only, single client (most often Claude or ChatGPT), 5–10 carefully chosen tools, OAuth 2.1 + PKCE + DCR, basic audit logging. Partner-built, this is the bottom of the cost range ($100K–$150K). In-house with experienced staff, less still – but with longer calendar time.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Should I build for one client first or multiple at once?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;One client first. Optimize the entire first ship for that client's distribution model, auth model, and design idioms. The temptation to abstract across clients from day one produces an MCP app that is mediocre on every surface. Better to be excellent on one and port what works.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What if I start in-house and need to switch to a partner?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Workable, but expensive. The cost of mid-build vendor changes is roughly 30–50% rework on the in-progress code, plus a quarter of calendar time to onboard the partner. The fix is to make the build-vs-buy decision before staffing, not after.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What's a fair maintenance commitment for an MCP partner?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Ongoing retainer typically $5K–$25K per month, depending on app complexity and client count. The retainer should cover host-client spec changes, auth model changes, distribution-policy changes, security patches, and minor feature work. Major expansions are scoped separately. Watch for partners whose maintenance retainer covers nothing actionable – that's a red flag.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is there a break-even point where in-house becomes cheaper than a partner?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Yes, but it depends on opportunity cost. Partner $500K vs in-house $400K raw spend: partner is more expensive in dollars. But if the in-house engineers being pulled have $100K+ of opportunity cost (delayed roadmap, slowed pipeline, customer commitment risk), partner wins on total. For most growth-stage SaaS companies, partner wins on total cost.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=guides" rel="noopener noreferrer"&gt;launchdayadvisors.com&lt;/a&gt;. Launch Day Advisors is a buyer-side advisory firm: we help companies select AI, software, and design partners, and we are paid only by the buyer.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>mcp</category>
      <category>ai</category>
      <category>startup</category>
      <category>management</category>
    </item>
    <item>
      <title>How to Embed Your App in AI Clients with MCP: Complete Guide for Product Leaders</title>
      <dc:creator>Jonathan Blessing</dc:creator>
      <pubDate>Fri, 18 Sep 2026 12:13:57 +0000</pubDate>
      <link>https://dev.to/launchdayadvisors/how-to-embed-your-app-in-ai-clients-with-mcp-complete-guide-for-product-leaders-2oge</link>
      <guid>https://dev.to/launchdayadvisors/how-to-embed-your-app-in-ai-clients-with-mcp-complete-guide-for-product-leaders-2oge</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;In brief:&lt;/strong&gt; A growing share of professional software use is happening inside AI clients (Claude, ChatGPT, Cursor, Microsoft Copilot, Gemini) rather than on traditional destinations. MCP is how those clients reach external software – a JSON-RPC 2.0 protocol exposing tools, resources, and prompts. To embed your app: (1) decide which clients matter, (2) choose an embedding depth (read-only, actions, or agent-resident), (3) implement an MCP server with OAuth 2.1 + PKCE auth and audit infrastructure, (4) submit to the host marketplace, (5) optimize for agent-led discovery. Partner-built level-1 read-only MCP apps cost ~$100K–$300K; level-2 actions apps cost ~$300K–$700K.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Embedding your app in an AI client means making your software reachable through the Model Context Protocol so agents inside Claude, ChatGPT, Cursor, Microsoft Copilot, or Gemini can invoke your tools on behalf of users. This is not an integrations ticket – it is a distribution strategy. By mid-2026, a meaningful share of professional software use happens inside AI clients rather than on the destinations the AI is mediating, and the unit of competition has shifted from &lt;em&gt;will the user pick us&lt;/em&gt; to &lt;em&gt;will the agent pick us, and will the user trust the result&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;For twenty-five years, the unit of distribution for software has been a destination. You built a website, an app, a workspace – somewhere the user could go. Marketing, growth, and product roadmaps were organized around getting the user to that destination and keeping them there. That model is being challenged: a growing share of professional and consumer software use is now happening &lt;em&gt;inside an AI client&lt;/em&gt;, with the AI client mediating between the user and the destinations behind it. The user does not go to Linear; the user asks Claude to look at Linear. The user does not open Notion; the user asks ChatGPT to draft against the Notion doc.&lt;/p&gt;

&lt;p&gt;This guide is for product leaders deciding whether and how to be present inside leading AI clients via MCP. It assumes the working vocabulary in our &lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;MCP terminology guide&lt;/a&gt;: an &lt;em&gt;MCP app&lt;/em&gt; is the user-installable artifact, an &lt;em&gt;MCP server&lt;/em&gt; is the engineering artifact underneath, a &lt;em&gt;tool&lt;/em&gt; is an individual capability the server exposes.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Strategic Reframe&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Previous-generation integrations connected your software to a destination the user already chose. The user logged into Zapier, picked your app from a list, and your integration ran. MCP-mediated use is structurally different: the user is in the AI client because that is where they are working, and the agent decides mid-task whether to invoke your software. Your competition is not the integrations directory; it is whichever competing MCP app the agent chooses for a given task.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  What MCP Is and Why Distribution Is Moving
&lt;/h2&gt;

&lt;p&gt;The &lt;a href="https://modelcontextprotocol.io" rel="noopener noreferrer"&gt;Model Context Protocol&lt;/a&gt; is an open standard introduced by Anthropic in November 2024. MCP uses &lt;a href="https://www.jsonrpc.org/specification" rel="noopener noreferrer"&gt;JSON-RPC 2.0&lt;/a&gt; as its wire protocol over three transport options (stdio for local servers, SSE and streamable HTTP for remote servers). The protocol defines three primitive types an MCP server can expose: &lt;strong&gt;tools&lt;/strong&gt; (operations the agent invokes), &lt;strong&gt;resources&lt;/strong&gt; (data the agent reads), and &lt;strong&gt;prompts&lt;/strong&gt; (templated user-facing prompts).&lt;/p&gt;

&lt;p&gt;By mid-2026, every major AI client supports MCP – Claude, ChatGPT, Cursor, Microsoft Copilot, Gemini, Perplexity. Major model providers have published first-party MCP servers (Anthropic shipped reference servers for Filesystem, GitHub, Slack, Postgres, Brave Search, and Google Maps with the initial launch). Third-party MCP servers exist in production from Linear, Notion, Stripe, Sentry, Cloudflare, Block, and a long tail of B2B SaaS vendors.&lt;/p&gt;

&lt;p&gt;This is a structural shift in how software is consumed, comparable in scope to the move from desktop to web (1995–2005) or web to mobile (2008–2015). The companies that treat MCP presence as a mid-priority integrations ticket will, in eighteen months, be looking at competitors whose customers reach for them by default inside Claude or ChatGPT and wondering when that happened.&lt;/p&gt;

&lt;h3&gt;
  
  
  Three structural consequences
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;MCP presence is distribution strategy, not an integrations ticket.&lt;/strong&gt; Every percent of professional task volume that moves into AI clients is a percent of demand that bypasses your website, your funnel, and your existing growth motions. Companies that staff MCP as a side project are staffing one of their emerging distribution channels as a side project.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The design of your MCP app is the design of your product as the agent sees it.&lt;/strong&gt; The names of your tools, the shape of their parameters, the legibility of your error messages, and the latency of your endpoints all become product surface, because the agent is reading and reasoning over them in real time. Treating MCP as plumbing produces an MCP app that an agent will technically work with and routinely avoid.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The buyer-side decision compounds.&lt;/strong&gt; Which AI clients to target, in which order, with what depth – these decisions have the same weight as &lt;em&gt;which countries do we sell into&lt;/em&gt; or &lt;em&gt;which cloud platform do we deploy on&lt;/em&gt;. Pick deliberately, and your distribution compounds. Default to whichever is easiest to ship to, and you spend the next two years rebuilding.&lt;/p&gt;

&lt;h2&gt;
  
  
  How MCP Embedding Actually Works
&lt;/h2&gt;

&lt;p&gt;When a user installs an MCP app inside an AI client, four things happen technically.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Capability negotiation.&lt;/strong&gt; The AI client opens an MCP session with your server. Client and server exchange supported protocol versions and capabilities (which features each side supports – tools, resources, prompts, sampling, roots).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Primitive discovery.&lt;/strong&gt; Your server advertises its tools (with names, descriptions, and JSON Schema input definitions), resources (with URIs, names, MIME types), and prompts. The AI client caches this catalog.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Authorization.&lt;/strong&gt; The user grants OAuth scopes (or another auth credential) covering the operations the agent can perform on the user's behalf. For remote servers, the MCP spec uses &lt;a href="https://oauth.net/2.1/" rel="noopener noreferrer"&gt;OAuth 2.1&lt;/a&gt; with PKCE, Dynamic Client Registration (&lt;a href="https://datatracker.ietf.org/doc/html/rfc7591" rel="noopener noreferrer"&gt;RFC 7591&lt;/a&gt;), and authorization-server metadata discovery (&lt;a href="https://datatracker.ietf.org/doc/html/rfc8414" rel="noopener noreferrer"&gt;RFC 8414&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Runtime invocation.&lt;/strong&gt; During normal use, the client's agent decides – based on the user's request and the tool descriptions – whether and which tools to invoke. The client calls them over JSON-RPC and uses the results in its response.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  A representative tool definition
&lt;/h3&gt;

&lt;p&gt;Tools are defined as structured objects with three components: &lt;code&gt;name&lt;/code&gt;, &lt;code&gt;description&lt;/code&gt;, and &lt;code&gt;inputSchema&lt;/code&gt;. The agent reads the description at runtime to decide whether to invoke the tool.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"name"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"create_invoice"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"description"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Create a new invoice for a customer. Use this when the user wants to bill a customer for services rendered. Returns the invoice ID and a URL where the customer can view it."&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"inputSchema"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"object"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"properties"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"customer_id"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"string"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"description"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"The unique identifier of the customer to invoice"&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"amount_cents"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"integer"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"description"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"The invoice total in cents (e.g., 5000 for $50.00)"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"minimum"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"currency"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"string"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"description"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"ISO 4217 currency code"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"default"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"USD"&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"due_date"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"string"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"format"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"date"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"description"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Invoice due date in ISO 8601 format (YYYY-MM-DD)"&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"required"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"customer_id"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"amount_cents"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Tool quality compounds. The description above is what an agent reads when deciding whether &lt;code&gt;create_invoice&lt;/code&gt; is the right tool for a given user request. Description quality directly affects whether the agent picks your tool over an alternative, how often it invokes it correctly, and how often it asks for confirmation versus proceeding silently.&lt;/p&gt;

&lt;h2&gt;
  
  
  Choosing Which AI Clients to Ship To
&lt;/h2&gt;

&lt;p&gt;All major AI clients support MCP as of mid-2026, but with significant differences in distribution model, auth, audience, and discovery.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;AI client&lt;/th&gt;
&lt;th&gt;User-facing term&lt;/th&gt;
&lt;th&gt;Distribution&lt;/th&gt;
&lt;th&gt;Best for&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Claude&lt;/strong&gt; (Anthropic)&lt;/td&gt;
&lt;td&gt;Connector&lt;/td&gt;
&lt;td&gt;In-product marketplace&lt;/td&gt;
&lt;td&gt;Prosumer + enterprise; first-class buyer experience&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;ChatGPT&lt;/strong&gt; (OpenAI)&lt;/td&gt;
&lt;td&gt;App&lt;/td&gt;
&lt;td&gt;App store&lt;/td&gt;
&lt;td&gt;Largest raw audience; consumer + prosumer + Teams&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Cursor&lt;/strong&gt; + AI-first IDEs&lt;/td&gt;
&lt;td&gt;MCP server&lt;/td&gt;
&lt;td&gt;Manual install, community catalogs&lt;/td&gt;
&lt;td&gt;Developer-tools companies&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Microsoft Copilot&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Agent / Copilot extension&lt;/td&gt;
&lt;td&gt;IT-admin distribution&lt;/td&gt;
&lt;td&gt;Enterprise with Microsoft 365 footprint&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Gemini&lt;/strong&gt; (Google)&lt;/td&gt;
&lt;td&gt;Connector / extension&lt;/td&gt;
&lt;td&gt;Workspace marketplace&lt;/td&gt;
&lt;td&gt;Workspace-heavy audiences&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Perplexity&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Connector&lt;/td&gt;
&lt;td&gt;In-product, lightweight&lt;/td&gt;
&lt;td&gt;Research and retrieval-flow tools&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;For the deep comparison – including auth models, permissions granularity, and monetization paths – see our &lt;a href="https://launchdayadvisors.com/guides/mcp-client-comparison" rel="noopener noreferrer"&gt;MCP client comparison matrix&lt;/a&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  Most product teams should not ship to all of them
&lt;/h3&gt;

&lt;p&gt;The temptation is to abstract across clients from day one. The result is an MCP app that is mediocre on every surface. Better to be excellent on one client and port what works.&lt;/p&gt;

&lt;p&gt;Quick decision guide:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Prosumer or knowledge-worker buyers&lt;/strong&gt; → ship to Claude first&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Mass-market or consumer buyers&lt;/strong&gt; → ship to ChatGPT first&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Developer-tools or AI-engineering buyers&lt;/strong&gt; → ship to Cursor first&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Enterprise software buyers, especially Microsoft 365 customers&lt;/strong&gt; → ship to Copilot first&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Workspace-heavy or Google-account-centric buyers&lt;/strong&gt; → ship to Gemini first&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Research, retrieval, or vertical-data products&lt;/strong&gt; → ship to Perplexity first&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The four common postures – ship aggressively to multiple clients, ship narrowly to one, ship a defensive read-only app, or don't ship – are walked in detail in our &lt;a href="https://launchdayadvisors.com/guides/mcp-strategy-decision-framework" rel="noopener noreferrer"&gt;MCP strategy decision framework&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Building an MCP App: Steps, Timeline, Cost
&lt;/h2&gt;

&lt;p&gt;Building a production-quality MCP app for one client at level-2 (actions) depth typically takes one to two quarters with the right team.&lt;/p&gt;

&lt;h3&gt;
  
  
  The ten-step build sequence
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Define your terminology&lt;/strong&gt; using the &lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;MCP terminology guide&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Pick the strategic posture and target client&lt;/strong&gt; using the &lt;a href="https://launchdayadvisors.com/guides/mcp-strategy-decision-framework" rel="noopener noreferrer"&gt;MCP strategy decision framework&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Choose the embedding depth&lt;/strong&gt; – read-only, actions, or agent-resident. Most teams start with read-only. See &lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;MCP embedding types&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Design the auth model.&lt;/strong&gt; OAuth 2.1 with PKCE is the right default for spec-compliant clients. Build the scope taxonomy before defining tools. See &lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP auth and security&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Design the tool surface.&lt;/strong&gt; Tool names, descriptions, parameters, error responses. Treat tool definitions with the same discipline as a public API.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Implement the MCP server&lt;/strong&gt; to the spec (JSON-RPC 2.0 over your chosen transport). Deploy with proper observability and audit logging from day one.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Build the safety infrastructure.&lt;/strong&gt; For level-2: idempotency keys, reversibility, intent preview, audit trail.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Submit to the host client's marketplace.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Optimize for discovery&lt;/strong&gt; through tool naming and description quality, early reviews, verified-publisher status, featured-slot positioning.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Plan ongoing maintenance.&lt;/strong&gt; Spec changes, auth model changes, distribution-policy changes, and your evolving tool surface require continuous attention.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Where the calendar time actually goes
&lt;/h3&gt;

&lt;p&gt;A representative two-quarter calendar for a level-2 single-client MCP app:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Phase&lt;/th&gt;
&lt;th&gt;Calendar weeks&lt;/th&gt;
&lt;th&gt;Key deliverables&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Strategy &amp;amp; scope&lt;/td&gt;
&lt;td&gt;Weeks 1–3&lt;/td&gt;
&lt;td&gt;Posture documented, target client picked, embedding level set, tool surface scoped&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Auth &amp;amp; scope design&lt;/td&gt;
&lt;td&gt;Weeks 3–5&lt;/td&gt;
&lt;td&gt;OAuth integration designed; scope taxonomy locked; audit log spec written&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Server foundation&lt;/td&gt;
&lt;td&gt;Weeks 5–9&lt;/td&gt;
&lt;td&gt;MCP spec implemented; transport selected; hosting; observability live&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Tool implementation, batch 1 (read tools)&lt;/td&gt;
&lt;td&gt;Weeks 7–12&lt;/td&gt;
&lt;td&gt;First 5–10 read tools shipped to staging; agent invocation tested&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Tool implementation, batch 2 (write tools)&lt;/td&gt;
&lt;td&gt;Weeks 10–18&lt;/td&gt;
&lt;td&gt;Write tools shipped with idempotency, reversibility; intent preview tested&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Audit log + customer admin UI&lt;/td&gt;
&lt;td&gt;Weeks 14–20&lt;/td&gt;
&lt;td&gt;Customer-facing audit log live; tamper-evident storage configured&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Marketplace submission &amp;amp; polish&lt;/td&gt;
&lt;td&gt;Weeks 18–22&lt;/td&gt;
&lt;td&gt;Listing submitted; review iteration; first user installs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Beta + iteration&lt;/td&gt;
&lt;td&gt;Weeks 22–26&lt;/td&gt;
&lt;td&gt;Closed beta; feedback incorporated; general availability&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  Cost ranges in 2026
&lt;/h3&gt;

&lt;p&gt;In 2026, partner-built MCP apps typically cost as follows:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Scope&lt;/th&gt;
&lt;th&gt;Calendar time&lt;/th&gt;
&lt;th&gt;Partner cost (USD)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Level-1 read-only, single client&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;~1 quarter&lt;/td&gt;
&lt;td&gt;$100K–$300K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Level-2 actions, single client&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;~2 quarters&lt;/td&gt;
&lt;td&gt;$300K–$700K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Level-2 actions, two clients&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;~2.5–3 quarters&lt;/td&gt;
&lt;td&gt;~1.4–1.7× single-client cost&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Level-3 agent-resident&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Multi-quarter program&lt;/td&gt;
&lt;td&gt;$1M+&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;In-house equivalents are typically 60–80% of the partner cost in raw spend, but with longer calendar time and the headcount cost of pulling engineers off other work. For a dedicated cost breakdown by scope – line items, ongoing costs, and worked examples – see &lt;a href="https://launchdayadvisors.com/guides/mcp-server-cost" rel="noopener noreferrer"&gt;what it costs to build an MCP server&lt;/a&gt;. For the full build-vs-buy decision rubric, see &lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP build vs buy&lt;/a&gt;. For broader context on AI implementation budgets, see our &lt;a href="https://launchdayadvisors.com/guides/ai-implementation-cost" rel="noopener noreferrer"&gt;AI implementation cost guide&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Auth, Discovery, and the Three Risks That Ambush Teams
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Auth is product strategy
&lt;/h3&gt;

&lt;p&gt;Nothing erodes adoption of an MCP app faster than a sloppy auth story. Enterprise buyers will not install an MCP app whose permissions model they cannot explain to their security team. Each leading AI client implements auth differently: Claude leans on OAuth 2.1 + PKCE with per-tool consent, ChatGPT mixes OAuth and API key flows, Microsoft Copilot delegates to Entra ID, Gemini to Google's OAuth surface.&lt;/p&gt;

&lt;p&gt;The full breakdown is in &lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP auth and security&lt;/a&gt;. The point worth keeping here is strategic: auth and scopes are not a developer problem – they are a product problem. The scope a user grants on day one shapes what the agent will do on day thirty.&lt;/p&gt;

&lt;h3&gt;
  
  
  Discovery has four levers
&lt;/h3&gt;

&lt;p&gt;Submitting an MCP app to a marketplace is the floor; getting agents to actually pick yours when there are five competing options is the ceiling.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Marketplace search.&lt;/strong&gt; Conventional store-listing optimization applies.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Featured slots.&lt;/strong&gt; Editorial placements curated by the host client. Reserved for high-quality apps with established usage and reviews.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Agent-led routing.&lt;/strong&gt; The agent itself recommending an MCP app mid-conversation. Tool naming and description quality are the primary inputs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;External catalogs and review sites.&lt;/strong&gt; Third-party "Yelp for MCP apps" directories are emerging but too immature to recommend specific vendors as of mid-2026.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The most leveraged discovery work in 2026 is tool description quality – it directly affects agent-led routing, which is the discovery channel growing fastest.&lt;/p&gt;

&lt;h3&gt;
  
  
  The three risks that ambush teams
&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Risks That Show Up Repeatedly&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Brand-on-agent risk:&lt;/strong&gt; users experience your product through the agent's voice, pacing, and mistakes. When the agent invokes your tools incorrectly, users blame the host product. &lt;strong&gt;Support-surface risk:&lt;/strong&gt; users in an AI client experiencing problems with your MCP app rarely come to your support channel – they ask the agent. &lt;strong&gt;Versioning and breakage risk:&lt;/strong&gt; your tool definitions are now an API consumed by external agents, with the added complication that agents cannot file bug reports. Plan for all three before launch, not after the first incident.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Where to Start in 2026
&lt;/h2&gt;

&lt;p&gt;The compressed sequence for product teams new to MCP:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Define your vocabulary&lt;/strong&gt; using the &lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;MCP terminology guide&lt;/a&gt;. Pick a term – &lt;em&gt;MCP app&lt;/em&gt; is our recommendation – and use it consistently.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Decide which clients matter&lt;/strong&gt; using the &lt;a href="https://launchdayadvisors.com/guides/mcp-strategy-decision-framework" rel="noopener noreferrer"&gt;strategy decision framework&lt;/a&gt;. Resist the urge to ship to all of them.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Choose your embedding depth&lt;/strong&gt; using the &lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;embedding types breakdown&lt;/a&gt;. Read-only is the right starting point unless you have a high-confidence safety story for actions.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Get the auth story right&lt;/strong&gt; &lt;em&gt;before&lt;/em&gt; the first tool definition. See &lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP auth and security&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Decide build vs buy&lt;/strong&gt; using &lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP build vs buy&lt;/a&gt;. If with a partner, use &lt;a href="https://launchdayadvisors.com/guides/evaluate-mcp-build-partner" rel="noopener noreferrer"&gt;the partner evaluation checklist&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Ship narrowly. Instrument heavily. Expand by evidence.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Questions to Ask Yourself&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Where is your buyer doing the work today – your destination, an AI client as substitute, or an AI client as multiplexer? What is your product's role in their workflow – destination, capability, or system of record? What is the cost of being absent from AI clients – negligible, soft, compounding, or existential? Honest answers to these three diagnostics determine the right posture and the right pace.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Most product teams that get MCP wrong got it wrong by skipping the framework, picking the easiest client to ship to, and producing something that was neither the aggressive ship of a strategic commitment nor the deep ship of a focused one.&lt;/p&gt;

&lt;p&gt;Embedding via MCP is not a feature. It is a recognition that the surface where your software is consumed is moving – toward agents, toward AI clients, toward a distribution layer most product teams' growth playbooks were not built for. The companies that decide MCP is distribution, and staff it that way, will be the ones distributed through. The companies that decide it is plumbing will be the ones routed around.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Guides
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;What to Call MCP Apps: Terminology Guide&lt;/a&gt; – The working vocabulary stack for product teams&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-client-comparison" rel="noopener noreferrer"&gt;MCP Client Comparison Matrix&lt;/a&gt; – Eight dimensions of difference across Claude, ChatGPT, Cursor, Copilot, Gemini, Perplexity&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-strategy-decision-framework" rel="noopener noreferrer"&gt;MCP Strategy Decision Framework&lt;/a&gt; – Three diagnostics, four postures, and how to commit&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;MCP Embedding Types Explained&lt;/a&gt; – Read-only, actions, agent-resident&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP Auth and Security&lt;/a&gt; – OAuth 2.1, scopes, audit logs, enterprise readiness&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP Build vs Buy&lt;/a&gt; – In-house engineering or development partner&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/evaluate-mcp-build-partner" rel="noopener noreferrer"&gt;How to Evaluate an MCP Build Partner&lt;/a&gt; – Buyer's checklist for a young category&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/how-to-select-an-ai-development-partner" rel="noopener noreferrer"&gt;How to Choose an AI Development Partner&lt;/a&gt; – The broader AI partner-evaluation framework&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;What is MCP in simple terms?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;MCP (Model Context Protocol) is an open standard that lets AI clients (Claude, ChatGPT, Cursor, etc.) connect to external software and use its capabilities on behalf of users. It uses JSON-RPC 2.0 as its wire protocol, defines three primitive types (tools, resources, prompts), and was introduced by Anthropic in November 2024.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Do I need to build an MCP app to be present in AI clients?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;For most product teams whose audience uses AI clients regularly, yes. Without an MCP app, your software is invisible to agents inside those clients, and tasks that previously brought users to your product increasingly happen without it. Some destination products with low AI-client overlap among their buyers can defer this; most cannot.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can I have one MCP app that works across all AI clients?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The MCP protocol itself is standardized, so the underlying server can be largely reused across clients. But each client has its own auth model, distribution mechanism, terminology, and metadata standards. A serious cross-client MCP app implements one MCP server and ports the auth, distribution, and marketing layer per client. Expect 30–60% additional work per added client.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How is MCP different from a Zapier integration or webhook?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Zapier and webhooks are user-configured connections – the user explicitly sets up a trigger or action in advance. MCP is agent-mediated – the agent decides at runtime, based on the user's stated goal, whether and how to invoke your software's capabilities. Schema descriptions are read by the model in real time; the user is not configuring a workflow ahead of time.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What's the smallest viable MCP app I can ship?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A level-1 read-only MCP app exposing 3–5 well-named query tools to a single host client. This can be built in 6–8 weeks with the right team and is the right starting point for most product teams without prior MCP experience. Server, OAuth, basic logging, marketplace submission – that's the floor.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is it too late to ship an MCP app in 2026?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;No. The category is past the earliest-adopter phase, but the maturity of host-client distribution, agent-led routing, and buyer awareness is still developing. Shipping a quality MCP app in 2026 puts you ahead of the broad market and well-positioned for compounding distribution as agent-mediated software use grows.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What happens if I don't ship an MCP app?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Four patterns: negligible impact (your buyers do not use AI clients), soft impact (occasional missed mindshare), compounding impact (alternatives fill the gap and agents learn to route around you), or existential impact (your category gets absorbed into AI clients themselves). The right diagnosis depends on your specific buyer and category.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Which AI client should I ship to first?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Whichever client your buyer uses most. For prosumer and knowledge-worker audiences, Claude is the strongest first ship. For consumer-facing products, ChatGPT. For developer tools, Cursor and the AI-first IDEs. For enterprise software with Microsoft 365 footprint, Copilot.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What MCP servers are already in production?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;As of mid-2026, public production MCP servers include first-party offerings from Anthropic (Filesystem, GitHub, Slack, Postgres, Brave Search, Google Maps, Memory, Puppeteer) and third-party servers from Linear, Notion, Stripe, Sentry, Cloudflare, Block, Apollo, and a long tail of B2B SaaS vendors.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What transport should my MCP server use?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;For local servers (running on the user's machine alongside the AI client), use stdio. For remote/hosted servers (the typical SaaS pattern), use streamable HTTP – the consolidated remote transport that has largely replaced SSE for new builds since 2025. SSE is still supported but should not be chosen for new servers.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://launchdayadvisors.com/guides/mcp-embed-app-ai-clients?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=guides" rel="noopener noreferrer"&gt;launchdayadvisors.com&lt;/a&gt;. Launch Day Advisors is a buyer-side advisory firm: we help companies select AI, software, and design partners, and we are paid only by the buyer.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>mcp</category>
      <category>ai</category>
      <category>productmanagement</category>
      <category>architecture</category>
    </item>
    <item>
      <title>How to Evaluate an MCP Development Partner: Buyer's Checklist for 2026</title>
      <dc:creator>Jonathan Blessing</dc:creator>
      <pubDate>Fri, 18 Sep 2026 12:12:26 +0000</pubDate>
      <link>https://dev.to/launchdayadvisors/how-to-evaluate-an-mcp-development-partner-buyers-checklist-for-2026-4dba</link>
      <guid>https://dev.to/launchdayadvisors/how-to-evaluate-an-mcp-development-partner-buyers-checklist-for-2026-4dba</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;In brief:&lt;/strong&gt; The usual partner-evaluation signals (portfolio depth, named-client logos, polished case studies) are unreliable in MCP because the category is too young for any partner to have a deep portfolio. Replace them with four signal categories: production references (not case studies), specific embedding-level experience (not generic AI experience), actual artifacts from previous engagements (auth designs, tool definitions, audit logs), and a partner with a defended view rather than just execution capacity. Run a structured evaluation: written brief → screening calls → technical deep-dive → reference calls → written proposals → decision review. Disqualify any partner who cannot produce a current production reference, has no documented auth/audit artifacts, or offers execution without an opinion.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The signals product teams normally use to evaluate a build partner – portfolio depth, named-client logos, polished case studies, years of category experience – are unreliable in MCP because the category is too young for any partner to have a deep portfolio. Replace them with four signal categories: production references (not case studies), specific embedding-level experience (not generic AI experience), actual artifacts from previous engagements (auth designs, tool definitions, audit logs), and a partner with a defended view rather than just execution capacity. Run a structured evaluation: written brief, screening calls, technical deep-dive, reference calls, written proposals, decision review. Disqualify any partner who cannot produce a current production reference, has no documented auth/audit artifacts, or offers execution without an opinion.&lt;/p&gt;

&lt;p&gt;This is the structural problem of evaluating in a young category: the marketing surface and the actual capability are unusually decoupled. Two partners can have similar websites, similar logos, and similar pitch decks, and one of them has shipped three production MCP apps to enterprise customers and the other has built an internal demo. Distinguishing them takes a different kind of evaluation than the one most procurement processes are built for.&lt;/p&gt;

&lt;p&gt;This guide is for product leaders running that evaluation. It assumes you have already made the build-vs-buy decision in favor of a partner (&lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP build vs buy&lt;/a&gt;) and uses the working vocabulary in our &lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;MCP terminology guide&lt;/a&gt;. For broader context on technology partner evaluation methodology, see &lt;a href="https://launchdayadvisors.com/guides/how-to-evaluate-a-technology-partner" rel="noopener noreferrer"&gt;how to evaluate a technology partner&lt;/a&gt; and our framework for &lt;a href="https://launchdayadvisors.com/guides/reference-checks-technology-partners" rel="noopener noreferrer"&gt;reference checks for technology partners&lt;/a&gt;. The patterns for AI partner evaluation specifically are in our &lt;a href="https://launchdayadvisors.com/guides/how-to-select-an-ai-development-partner" rel="noopener noreferrer"&gt;guide to selecting an AI development partner&lt;/a&gt;.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The Cost of the Wrong Choice&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The cost of the wrong partner choice is not a contract write-off; it is a year of compounded delay during the window when MCP presence matters most. A poorly-built MCP app passes initial review and breaks in production over the following quarter – auth tokens silently expire, mutations are not idempotent, the audit story falls apart the first time a customer asks for a log. Six months in, the buyer is rebuilding while still paying for the original.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Why MCP Partner Evaluation Is Different
&lt;/h2&gt;

&lt;p&gt;Three things make MCP partner evaluation different from evaluating, say, a generalist agency for a marketing site or a typical mobile-app build:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Experience is concentrated in a small number of teams&lt;/strong&gt;, hidden by a much larger number of agencies who have updated their websites to claim MCP capability. In our assessment, fewer than fifty teams globally have shipped multiple production MCP apps to paying customers as of mid-2026 – a practitioner estimate, not a published statistic. The count of agencies whose website mentions MCP is in the thousands. The signal-to-noise ratio of the marketing surface is unusually bad.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The work is adjacent to but not the same as previous specialties.&lt;/strong&gt; Teams with strong API-design backgrounds can ship adequate MCP apps without prior MCP experience; teams with strong full-stack agency backgrounds, no API experience, and a couple of weeks of MCP demo work can produce something that looks shippable in a pitch and breaks in production.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The failure mode is delayed.&lt;/strong&gt; A poorly-built MCP app passes initial review and breaks in production over the following quarter. Six months in, the buyer is rebuilding while still paying for the original.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;A more rigorous evaluation up front pays for itself many times over. The rigor takes a different shape than mature-category evaluation. You are not looking for the partner with the most MCP-shaped marketing. You are looking for the partner with the most MCP-shaped &lt;em&gt;artifacts&lt;/em&gt; – production references, real auth designs from previous engagements, actual tool definitions, working audit-log examples – and you are looking past the partners who can talk about MCP and toward the partners who can show you what they have shipped.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Four Signals That Actually Work
&lt;/h2&gt;

&lt;p&gt;In place of the usual portfolio-and-logos checklist, four signal categories matter when the category is young.&lt;/p&gt;

&lt;h3&gt;
  
  
  Signal 1: Production references, not case studies
&lt;/h3&gt;

&lt;p&gt;A case study is a document the partner controls. A production reference is a customer the partner introduces you to, who is currently using an MCP app the partner shipped, and who will talk to you for thirty minutes about what worked and what did not.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Ask for the latter.&lt;/strong&gt; The single most valuable thirty minutes of an MCP partner evaluation is a reference call with a current customer. The single most predictive failure signal is a partner who hedges on whether such a call can happen.&lt;/p&gt;

&lt;h3&gt;
  
  
  Signal 2: Specific embedding-level experience
&lt;/h3&gt;

&lt;p&gt;A partner who has shipped three level-1 read-only MCP apps and never shipped a level-2 actions app is not the right partner for your level-2 build. The discontinuity between read-only and actions is large – idempotency, reversibility, audit, intent preview – and previous experience at the higher level matters more than total count of apps.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Ask specifically:&lt;/strong&gt; &lt;em&gt;How many MCP apps have you shipped to production, on which clients, at what embedding level?&lt;/em&gt; The honest answer for most partners in 2026 is one to three. A partner who answers &lt;em&gt;many&lt;/em&gt; without a list, or &lt;em&gt;we have AI experience&lt;/em&gt; without naming MCP-specific projects, has not shipped what they are claiming.&lt;/p&gt;

&lt;p&gt;If you are shipping at level 2, the partner should have shipped at level 2. If you are shipping to multiple clients, cross-client experience matters – Claude experience does not transfer to Microsoft Copilot's enterprise model without real cost.&lt;/p&gt;

&lt;h3&gt;
  
  
  Signal 3: Artifacts, not pitches
&lt;/h3&gt;

&lt;p&gt;The most diagnostic step in a partner evaluation is asking to see actual artifacts from a previous engagement. Three artifacts are particularly informative:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;The auth design&lt;/strong&gt; from a previous engagement. Not the marketing pitch – the actual design. Scope taxonomy, token lifetime decisions, refresh behavior, revocation flow, the SOC 2 considerations baked in. A partner who can talk fluently about why they chose per-resource per-verb scopes for a previous client has done the work. (See &lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP auth and security&lt;/a&gt; for the bar.)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The tool surface&lt;/strong&gt; from a previous build – actual tool definitions, names, descriptions, parameter shapes, error responses for a real production MCP app. Read them. Look at description quality, parameter naming, error legibility.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The audit and observability defaults.&lt;/strong&gt; What does the partner instrument out of the box? Per-invocation logs? Customer-admin-facing log surface? Session reconstruction?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These three artifacts are diagnostic because they cannot be faked in a pitch deck.&lt;/p&gt;

&lt;h3&gt;
  
  
  Signal 4: A view, not just execution capacity
&lt;/h3&gt;

&lt;p&gt;The strongest partners have an opinionated view on the work; the weakest have execution capacity but no point of view.&lt;/p&gt;

&lt;p&gt;A partner with a view will tell you which embedding level you should ship at, based on the diagnostics in our &lt;a href="https://launchdayadvisors.com/guides/mcp-strategy-decision-framework" rel="noopener noreferrer"&gt;strategy decision framework&lt;/a&gt;, and will defend the recommendation. A partner without a view will offer to build whatever you specify and will charge you to discover during the build that what you specified was not the right thing.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Ask:&lt;/strong&gt; &lt;em&gt;What would you do differently from the brief we sent?&lt;/em&gt; A partner who answers &lt;em&gt;nothing, that brief is great&lt;/em&gt; is offering execution. A partner who pushes back on something specific – embedding level, client choice, auth approach – is offering partnership. The latter is rarer and worth more.&lt;/p&gt;

&lt;h2&gt;
  
  
  Sample Brief and Screening Questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Sample MCP partner evaluation brief
&lt;/h3&gt;

&lt;p&gt;A working template for the written brief shared with three to five partners at the start of the evaluation. Keep it under 4 pages; partners who cannot scope from this should disqualify themselves.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;SUBJECT: MCP Partner Evaluation – [Your Company Name]

ABOUT US
- Company: [name, ARR, customer base, one-paragraph product description]
- Audience: [primary buyer persona; segments]
- Existing tech stack: [key infrastructure relevant to MCP work]

THE OPPORTUNITY
- Strategic posture: [Posture 1/2/3 from MCP strategy framework]
- Why we're shipping: [the specific buyer signal driving urgency]
- What success looks like: [first-year goals in measurable terms]

SCOPE
- Target client(s): [Claude / ChatGPT / Cursor / Copilot / Gemini / Perplexity, in priority order]
- Embedding level: [read-only / actions / agent-resident]
- Tool surface (rough): [estimated tool count; key resources/operations]
- Auth model: [OAuth 2.1 + PKCE expected; SSO required for enterprise]
- Audit / observability requirements: [SOC 2, HIPAA, customer-facing audit log, etc.]

TIMELINE
- Strategy &amp;amp; scope: [target weeks]
- Build: [target weeks]
- Beta + GA: [target weeks]
- Hard constraints: [any non-negotiable dates]

ENGAGEMENT MODEL
- Build-only / build + maintenance / build + transition to in-house
- Knowledge transfer expectations: [pairing? runbooks? architecture review?]
- Maintenance retainer expected: [yes/no; range]

EVALUATION CRITERIA
- We will evaluate proposals against the criteria in the attached scorecard
- We expect a written proposal with scope, sequencing, knowledge transfer model,
  maintenance commitment, and pricing structure
- We will conduct reference calls with one production customer per finalist
- Final decision: [target date]

QUESTIONS
- Please direct questions to [contact, email]
- Proposal due: [date]
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This brief is a screening tool by itself. Partners who respond with a generic deck rather than a scoped proposal disqualify themselves. Partners who respond with thoughtful clarifying questions move forward.&lt;/p&gt;

&lt;h3&gt;
  
  
  Screening call questions
&lt;/h3&gt;

&lt;p&gt;A complete first-round screening call works through these in roughly 60 minutes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Track record (10 minutes):&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;How many MCP apps have you shipped to production, on which clients, at what embedding level? &lt;em&gt;Look for: a list with names, dates, and URLs. Vague answers disqualify.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;Of those, which is the most recent? When did it ship? When was its last meaningful update? &lt;em&gt;Look for: shipped within last 12 months; ongoing maintenance.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;Can I talk to a current customer using an MCP app you shipped, ideally at the embedding level we need? &lt;em&gt;Look for: yes, with a name and timeframe.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;What's the longest-running MCP app you've shipped, and what does maintenance look like for it? &lt;em&gt;Look for: a real story with concrete details about spec changes, auth changes, scope reviews.&lt;/em&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Technical depth (20 minutes):&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Can you walk me through the auth design from a previous engagement, in detail? &lt;em&gt;Look for: per-resource per-verb per-sensitivity scope structure; OAuth 2.1 + PKCE + DCR; thoughtful token lifetime decisions.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;Can I see actual tool definitions from a previous build? &lt;em&gt;Look for: well-named tools, clear descriptions, well-shaped parameter schemas.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;What does your audit and observability default look like? &lt;em&gt;Look for: built-in, not afterthought.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;How do you handle host-client spec changes mid-engagement? &lt;em&gt;Look for: built into retainer, not surprise scope changes.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;What's your idempotency pattern for write tools? &lt;em&gt;Look for: idempotency keys, server-side caching, Stripe-style discipline.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;What's your reversibility pattern for high-stakes operations? &lt;em&gt;Look for: soft-delete with restore tokens, two-phase commit for irreversibles, revision history.&lt;/em&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Process and engagement (15 minutes):&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;What does discovery and design look like before any code is written? &lt;em&gt;Look for: 2–3 weeks of strategy + scope work; documented deliverables before build phase.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;How do you structure knowledge transfer for in-house takeover? &lt;em&gt;Look for: pairing engagements, runbook deliverables, architecture review milestones.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;What's your maintenance commitment after launch? &lt;em&gt;Look for: written terms, clear coverage.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;What's your typical timeline for level-1 / level-2 / multi-client engagements? &lt;em&gt;Look for: realistic numbers (1 quarter / 2 quarters / 2.5–3 quarters).&lt;/em&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Commercial (10 minutes):&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;What's your pricing structure (fixed-fee, T&amp;amp;M, retainer, milestone-based)?&lt;/li&gt;
&lt;li&gt;What's typically out of scope in your fixed-fee engagements? &lt;em&gt;Look for: clear answer; "very little" is a flag.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;How do you handle scope changes? &lt;em&gt;Look for: written change-order process.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;What's your IP and source-code ownership stance? &lt;em&gt;Look for: client owns code; explicit license; source escrow if applicable.&lt;/em&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Strategic (5 minutes):&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;What would you do differently from the brief we sent? &lt;em&gt;Look for: specific pushback, not "great brief".&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;Which embedding level would you recommend for our situation, and why? &lt;em&gt;Look for: defended recommendation, not deference.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;What's the most common reason engagements like ours go wrong? &lt;em&gt;Look for: lessons from real engagements.&lt;/em&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Reference call question script
&lt;/h3&gt;

&lt;p&gt;When you reach reference calls, conduct them yourself, not via the partner. Thirty minutes per reference.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;1. How did you find [partner]?
2. What was the scope of the engagement?
3. How did the partner handle the strategy/scope phase?
   Did they push back on your initial brief? Where?
4. What changed between the proposal and the actual delivery?
5. What was the first incident in production? How did the partner handle it?
6. How was the auth design? Has it held up?
7. How was the audit story? Has it been sufficient when issues came up?
8. What's maintenance been like since launch?
9. If you were doing it again, would you hire [partner]?
   What would you do differently in the engagement?
10. What's something the partner did well that you didn't expect?
11. What's something the partner did poorly that surprised you?
12. Anything we should know that we wouldn't think to ask?
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The signals to listen for: specifics (vs generalities), proactive disclosure of issues (vs glossing), comfort answering question 11 honestly (vs deflection).&lt;/p&gt;

&lt;h2&gt;
  
  
  The 100-Point Scorecard
&lt;/h2&gt;

&lt;p&gt;A scorecard you can apply to candidate proposals. Score each finalist; the highest score is not necessarily the best partner (judgment matters), but a finalist scoring below 65 should not be selected.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Category&lt;/th&gt;
&lt;th&gt;Weight&lt;/th&gt;
&lt;th&gt;Sub-criteria&lt;/th&gt;
&lt;th&gt;Max&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Track record&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;25&lt;/td&gt;
&lt;td&gt;Production MCP apps shipped (10), specific embedding-level match (10), production reference call available (5)&lt;/td&gt;
&lt;td&gt;25&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Technical depth&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;30&lt;/td&gt;
&lt;td&gt;Auth design artifact reviewed (10), tool definition artifact reviewed (10), audit/observability default (5), idempotency/reversibility patterns demonstrated (5)&lt;/td&gt;
&lt;td&gt;30&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Process &amp;amp; engagement&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;20&lt;/td&gt;
&lt;td&gt;Discovery/design phase before build (5), knowledge transfer model (5), maintenance terms clear (5), realistic timeline (5)&lt;/td&gt;
&lt;td&gt;20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Commercial&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;td&gt;Clear pricing structure (3), explicit IP ownership (3), change-order process (2), maintenance retainer terms (2)&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Strategic view&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;15&lt;/td&gt;
&lt;td&gt;Pushed back on the brief substantively (5), defended an embedding-level recommendation (5), articulated common failure modes from experience (5)&lt;/td&gt;
&lt;td&gt;15&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Total&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;100&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Score interpretation:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;85–100:&lt;/strong&gt; strong partner; proceed with confidence&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;70–84:&lt;/strong&gt; acceptable partner; document specific concerns and address in contract&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;65–69:&lt;/strong&gt; marginal; pursue only if no stronger alternatives and you can mitigate weak areas&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&amp;lt;65:&lt;/strong&gt; do not select&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If multiple partners score 80+, the tiebreakers worth weighing are: reference customer signal (a great reference adds weight), strategic-view depth (the partner who pushed back hardest on your brief usually delivers the best engagement), and commercial alignment (the partner whose pricing structure matches your cost-management preferences).&lt;/p&gt;

&lt;h2&gt;
  
  
  Red Flags, Process, and Contract Terms
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Five disqualifiers
&lt;/h3&gt;

&lt;p&gt;Five signals strong enough to drop a partner regardless of the rest of the evaluation:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;No production reference call available.&lt;/strong&gt; If the partner cannot put you in front of a paying customer, the experience claim is unsupported.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;No documented auth or audit artifacts.&lt;/strong&gt; Partners who treat auth and audit as engineering details to be figured out during the build are starting too late.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;No view on which embedding level you should ship at.&lt;/strong&gt; A partner who says &lt;em&gt;we'll build whatever you specify&lt;/em&gt; is offering execution, not partnership.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Single-client experience masquerading as MCP expertise.&lt;/strong&gt; A team that has built three Claude connectors and never touched another client's MCP surface is a Claude partner, not an MCP partner. Fine if Claude is the only client you care about, ever. Not fine if you intend to expand.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Aggressive on timeline, vague on safety.&lt;/strong&gt; Partners who promise four-week ships at level 2 without articulating idempotency, reversibility, and audit work are either underestimating or planning to skip. Both disqualifying.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  How to run the process
&lt;/h3&gt;

&lt;p&gt;A defensible evaluation takes four to six weeks and follows six steps:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Written brief&lt;/strong&gt; (Week 1) – shared with three to five partners&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;First-round screening calls&lt;/strong&gt; (Weeks 1–2) – 60 minutes each, anchored on the question list above&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Technical deep-dive&lt;/strong&gt; (Weeks 2–3) – with the surviving two or three; review actual artifacts; engineering lead in the room&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Reference calls&lt;/strong&gt; (Weeks 3–4) – conducted directly, not via the partner; one production customer per partner; thirty minutes each&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Written proposals&lt;/strong&gt; (Weeks 4–5) – from each finalist, with scope, sequencing, knowledge transfer, maintenance, and pricing all explicit&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Decision review&lt;/strong&gt; (Weeks 5–6) – with internal stakeholders including engineering, security, and the eventual product owner&lt;/li&gt;
&lt;/ol&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Questions That Reveal True Capability&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Beyond the screening list, three questions consistently surface real capability gaps. "What's the most recent MCP-spec change you absorbed mid-engagement, and how did you handle it?" "What's a scope decision you made on a previous project that you'd reverse with hindsight?" "Walk me through how you'd handle a customer's security team asking for proof of revocation latency in production." Partners with real experience answer these with specifics. Partners with thin experience deflect or generalize.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  Required contract terms
&lt;/h3&gt;

&lt;p&gt;The minimum bar for a defensible MCP partner contract:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Statement of Work&lt;/strong&gt; with line-itemed scope matching the &lt;a href="https://launchdayadvisors.com/guides/mcp-server-cost" rel="noopener noreferrer"&gt;MCP server cost breakdown&lt;/a&gt; and the build-vs-buy framing in &lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP build vs buy&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Acceptance criteria per phase&lt;/strong&gt; – what does &lt;em&gt;auth design complete&lt;/em&gt; mean? What does &lt;em&gt;tool surface implemented&lt;/em&gt; mean?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;IP ownership&lt;/strong&gt; – code is yours, license explicit&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Source code escrow&lt;/strong&gt; for partners who hold ongoing operational responsibility&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Audit log deliverable&lt;/strong&gt; – partner builds &lt;em&gt;and&lt;/em&gt; surfaces it to customer admins&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Penetration test deliverable&lt;/strong&gt; – third-party pentest before launch, with remediation in scope&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Knowledge transfer deliverables&lt;/strong&gt; – runbooks, pairing schedule, architecture review milestones with internal sign-off&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Maintenance terms&lt;/strong&gt; – what's included; what counts as scope change; rate card&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Disengagement clauses&lt;/strong&gt; – termination notice, transition assistance, source escrow&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Key-person commitments&lt;/strong&gt; – named engineers, rotation notice&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Confidentiality&lt;/strong&gt; – including AI training. Whether the partner can use any artifacts from your engagement to train models or improve their own tools&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The most common contract gaps are knowledge transfer (often soft-pedaled) and audit log surfacing (often left as engineering detail). Both deserve explicit line items.&lt;/p&gt;

&lt;h3&gt;
  
  
  When to bring in an outside advisor
&lt;/h3&gt;

&lt;p&gt;For most product teams, this evaluation is doable internally with the framework above. Bring in an outside advisor if:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Your company has not run a build-partner evaluation in this category before&lt;/li&gt;
&lt;li&gt;The strategic stakes are high enough that an additional set of experienced eyes is worth the cost&lt;/li&gt;
&lt;li&gt;The internal team is too close to existing partner relationships to evaluate them on their merits&lt;/li&gt;
&lt;li&gt;The buyer wants the diligence documented for procurement, board, or audit purposes&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;We do this work regularly, both as the primary evaluator and as a second-opinion review on a partner the team has already chosen. Typical engagement: 4–6 weeks, $40K–$100K depending on scope and number of finalists.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why This Evaluation Matters More Now Than Later
&lt;/h2&gt;

&lt;p&gt;The MCP build-partner market will mature. In two years, evaluating partners will look more like evaluating mobile-app shops in 2014 – a settled craft, a known set of credible firms, an unambiguous portfolio standard. The asymmetry between marketing surface and actual capability will close. Production reference checks will be a formality rather than a diagnostic.&lt;/p&gt;

&lt;p&gt;We are not there yet. The next eighteen months are the period in which signal-to-noise ratio of partner marketing is at its worst, the cost of getting the choice wrong is at its highest, and the rigor of a serious evaluation has the most leverage. The teams that get this right are the ones that treat partner evaluation as a real procurement exercise rather than a vendor-shopping exercise.&lt;/p&gt;

&lt;p&gt;The MCP app you ship is the product surface your customers will see for the next five years. It is shaped, more than anyone wants to admit, by the partner you picked at the beginning. Pick deliberately. Document the reasoning. Hold the partner to the artifacts they showed you in the proposal.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Guides
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;What to Call MCP Apps: Terminology Guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-embed-app-ai-clients" rel="noopener noreferrer"&gt;How to Embed Your App in AI Clients with MCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP Build vs Buy&lt;/a&gt; – The decision before partner selection&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/how-to-select-an-ai-development-partner" rel="noopener noreferrer"&gt;How to Choose an AI Development Partner&lt;/a&gt; – The broader AI partner-evaluation framework&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/how-to-evaluate-a-technology-partner" rel="noopener noreferrer"&gt;How to Evaluate a Technology Partner&lt;/a&gt; – Cross-category partner evaluation methodology&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/reference-checks-technology-partners" rel="noopener noreferrer"&gt;Reference Checks for Technology Partners: A Structured Methodology&lt;/a&gt; – Deeper reference-check framework&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;How long does an MCP partner evaluation take?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A defensible evaluation takes four to six weeks: one week for the written brief, one to two weeks for screening calls, one to two weeks for technical deep-dive and reference calls, and one week for proposals and decision review.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How many MCP partners should I evaluate?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Three to five for the written brief; two or three through the technical deep-dive; finalists submit written proposals. Fewer than three risks no real comparison; more than five becomes process overhead without proportional decision-quality benefit.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What's the most important question to ask an MCP development partner?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Can I talk to a paying customer currently using an MCP app you shipped? The answer (and how the partner handles the answer) tells you more than any other single question. Production reference availability is the strongest single signal in the evaluation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How do I know if an MCP partner has real experience?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Three tests: production reference calls, specific embedding-level experience (not generic AI experience), and actual artifacts from previous engagements (auth designs, tool definitions, audit logs). Marketing claims, case studies, and pitch decks are unreliable in this category.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What should be in an MCP partner proposal?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Six elements: scope (specific tools, embedding level, target client), sequencing (week-by-week or sprint-by-sprint plan), knowledge transfer model (if you intend in-house takeover), maintenance commitment (post-launch), pricing structure (fixed-fee vs T&amp;amp;M vs retainer), and an articulated point of view on what you should do differently from the brief.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How much should I pay an MCP development partner?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Partner-built level-1 read-only MCP apps typically run $100K–$300K for a single client; level-2 actions apps run $300K–$700K. The cost varies with auth complexity, tool surface size, and underlying product complexity.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Should I hire an MCP agency or a freelancer?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;For most production-quality MCP apps, an established MCP agency or development partner is the right choice. Freelancers can work for narrow scopes (one tool surface, no auth complexity) but rarely have the breadth across server, auth, audit, safety, and distribution that a production MCP app requires.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What if all my partner candidates fail the disqualifiers?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Two paths: extend the search to less obvious candidates (boutique product engineering firms with strong API-design backgrounds, sometimes labeled differently than 'MCP partner'), or reconsider the build-vs-buy decision. Failing the disqualifier list across multiple candidates is a signal that the category is not yet mature enough for your specific need; in-house may be the better answer.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How do I score MCP partner proposals?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Use the 100-point scorecard: track record (25), technical depth (30), process (20), commercial (10), strategic view (15). Finalists below 65 should not be selected; above 85 is strong; 70–84 is workable with documented mitigations.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What contract terms most often cause regret post-engagement?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Two: vague knowledge-transfer deliverables (the partner did the work, your team can't take it over) and audit-log-not-surfaced (the partner built the log internally, your customers' admins can't query it). Both should be explicit, scoped, and acceptance-criteria'd in the contract.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://launchdayadvisors.com/guides/evaluate-mcp-build-partner?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=guides" rel="noopener noreferrer"&gt;launchdayadvisors.com&lt;/a&gt;. Launch Day Advisors is a buyer-side advisory firm: we help companies select AI, software, and design partners, and we are paid only by the buyer.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>mcp</category>
      <category>ai</category>
      <category>management</category>
      <category>productmanagement</category>
    </item>
    <item>
      <title>MCP Auth and Security: OAuth, Scopes, and Enterprise Permissions Guide</title>
      <dc:creator>Jonathan Blessing</dc:creator>
      <pubDate>Fri, 18 Sep 2026 12:09:09 +0000</pubDate>
      <link>https://dev.to/launchdayadvisors/mcp-auth-and-security-oauth-scopes-and-enterprise-permissions-guide-3b48</link>
      <guid>https://dev.to/launchdayadvisors/mcp-auth-and-security-oauth-scopes-and-enterprise-permissions-guide-3b48</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;In brief:&lt;/strong&gt; MCP apps use one of three auth patterns: OAuth 2.1 with PKCE (mandated by the MCP spec for remote servers, used by Claude, Gemini, modern ChatGPT), API key handoff (common in Cursor and AI-first IDEs, weak on revocation and scoping), and enterprise SSO via the host's identity provider (Microsoft Copilot delegates to Entra ID; Gemini to Google OAuth). The MCP spec mandates Dynamic Client Registration (RFC 7591) and authorization server metadata discovery (RFC 8414). For enterprise readiness: OAuth 2.1 + PKCE, scopes structured per-resource and per-verb and per-sensitivity, bounded token lifetimes (≤1 hour) with transparent refresh and immediate revocation, customer-facing audit logs, and SSO support for Entra ID, Okta, and Google Workspace.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The fastest way to lose an enterprise procurement conversation about an MCP app is to lose the auth conversation. Security teams have spent a decade getting good at evaluating OAuth implementations, scope design, and audit posture in third-party SaaS, and they apply the same lens to MCP – with the added question of how a non-human agent's behavior is bounded inside the granted permissions. A sloppy auth story is read, correctly, as a sloppy product. A clean one is the floor that lets the rest of the conversation happen.&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://modelcontextprotocol.io" rel="noopener noreferrer"&gt;MCP specification&lt;/a&gt; mandates &lt;a href="https://oauth.net/2.1/" rel="noopener noreferrer"&gt;OAuth 2.1&lt;/a&gt; with PKCE for remote servers, plus Dynamic Client Registration (&lt;a href="https://datatracker.ietf.org/doc/html/rfc7591" rel="noopener noreferrer"&gt;RFC 7591&lt;/a&gt;) and Authorization Server Metadata (&lt;a href="https://datatracker.ietf.org/doc/html/rfc8414" rel="noopener noreferrer"&gt;RFC 8414&lt;/a&gt;). The spec recommends Resource Indicators (&lt;a href="https://datatracker.ietf.org/doc/html/rfc8707" rel="noopener noreferrer"&gt;RFC 8707&lt;/a&gt;) to prevent token-confusion attacks. For enterprise readiness, scopes should be structured per-resource, per-verb, per-sensitivity, with bounded token lifetimes, immediate revocation, customer-facing audit logs, and SSO support for the major identity providers. This guide walks each piece of that bar in detail.&lt;/p&gt;

&lt;p&gt;This guide assumes the working vocabulary in our &lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;MCP terminology guide&lt;/a&gt; and the level distinctions in &lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;MCP embedding types&lt;/a&gt;.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Auth Design Is Product Strategy&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Auth design is not engineering plumbing. It determines who can install you (which clients accept your auth model), what an agent can do at runtime (coarse vs fine scopes), and how procurement reacts (whether the design maps onto reviewers' existing OAuth review checklists). Treat it as a product decision; let engineering execute the design rather than choose it.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  The Three MCP Auth Patterns
&lt;/h2&gt;

&lt;p&gt;Three auth patterns dominate in 2026:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Pattern&lt;/th&gt;
&lt;th&gt;Where it's used&lt;/th&gt;
&lt;th&gt;Strengths&lt;/th&gt;
&lt;th&gt;Weaknesses&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;OAuth 2.1 with PKCE + DCR&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Claude, Gemini, modern ChatGPT install paths&lt;/td&gt;
&lt;td&gt;Cleanest model; per-tool consent possible; bounded token lifetimes; clean revocation; spec-compliant&lt;/td&gt;
&lt;td&gt;Heavier to implement than API key&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;API key handoff&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Cursor and AI-first IDEs; lightweight integrations&lt;/td&gt;
&lt;td&gt;Cheap to implement; fast first-ship&lt;/td&gt;
&lt;td&gt;Weak revocation; weak per-tool scoping; insufficient for enterprise; not spec-compliant for remote servers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Enterprise SSO via host IdP&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Microsoft Copilot (Entra ID); Gemini (Google OAuth); Claude enterprise (SAML/SCIM)&lt;/td&gt;
&lt;td&gt;Strongest procurement story; admin-controlled distribution; existing enterprise IT mental model&lt;/td&gt;
&lt;td&gt;Heaviest implementation; per-client identity provider integration&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;A serious MCP app shipping to multiple AI clients implements at least two of these, and probably all three. There is no shortcut. The cost of pretending one auth model fits all clients is shipping to fewer of them than your strategy intended.&lt;/p&gt;

&lt;h2&gt;
  
  
  OAuth 2.1 + PKCE + DCR Flow
&lt;/h2&gt;

&lt;p&gt;OAuth 2.1 with PKCE (Proof Key for Code Exchange) is the auth pattern mandated by the MCP spec for remote servers. The user is taken through a standard OAuth flow inside the AI client, grants scopes, and the client receives an access token plus a refresh token bound to the user. PKCE protects the public-client flow against authorization code interception attacks.&lt;/p&gt;

&lt;h3&gt;
  
  
  The full flow
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Discovery.&lt;/strong&gt; AI client fetches your &lt;code&gt;/.well-known/oauth-authorization-server&lt;/code&gt; metadata document (RFC 8414) to discover the authorization endpoint, token endpoint, supported scopes, supported grant types, and registration endpoint.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Dynamic Client Registration.&lt;/strong&gt; AI client POSTs to your registration endpoint (RFC 7591) to register itself, providing redirect URIs and other metadata. Your authorization server returns a &lt;code&gt;client_id&lt;/code&gt; and (for confidential clients) a &lt;code&gt;client_secret&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Authorization request.&lt;/strong&gt; AI client generates a PKCE code verifier and challenge, then redirects the user to your authorization endpoint with &lt;code&gt;response_type=code&lt;/code&gt;, &lt;code&gt;code_challenge&lt;/code&gt;, &lt;code&gt;code_challenge_method=S256&lt;/code&gt;, and the requested scopes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;User consent.&lt;/strong&gt; User authenticates with your service and grants the requested scopes. Your service redirects back to the AI client's redirect URI with an authorization code.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Token exchange.&lt;/strong&gt; AI client POSTs the authorization code (plus the PKCE code verifier) to your token endpoint. You verify the PKCE challenge and return an access token, refresh token, and (optionally) an ID token.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Resource indicator binding.&lt;/strong&gt; The access token is bound to your MCP server's resource indicator (RFC 8707), preventing replay against other MCP servers.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tool invocation.&lt;/strong&gt; AI client uses the access token in the &lt;code&gt;Authorization: Bearer ...&lt;/code&gt; header on JSON-RPC requests to your MCP server.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Refresh.&lt;/strong&gt; When the access token expires, AI client uses the refresh token to obtain a new one.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;OAuth 2.1 + PKCE + DCR is the right default for any MCP app shipping to spec-compliant clients (Claude, Gemini, modern ChatGPT). For enterprise tier on Claude or for Microsoft Copilot, you additionally need to support SAML and SCIM.&lt;/p&gt;

&lt;h3&gt;
  
  
  Per-client variation
&lt;/h3&gt;

&lt;p&gt;Each AI client implements auth differently, with the standing caveat that any specific claim should be verified against current documentation:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Client&lt;/th&gt;
&lt;th&gt;Primary auth&lt;/th&gt;
&lt;th&gt;DCR&lt;/th&gt;
&lt;th&gt;RFC 8414&lt;/th&gt;
&lt;th&gt;Scope granularity&lt;/th&gt;
&lt;th&gt;Notable&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Claude&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;OAuth 2.1 + PKCE&lt;/td&gt;
&lt;td&gt;Yes (mandatory)&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Per-tool consent at install; per-action confirmation&lt;/td&gt;
&lt;td&gt;Strongest spec compliance; enterprise tier adds SAML/SCIM&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;ChatGPT&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;OAuth or API key&lt;/td&gt;
&lt;td&gt;Partial&lt;/td&gt;
&lt;td&gt;Partial&lt;/td&gt;
&lt;td&gt;App-level; per-tool on newer builds&lt;/td&gt;
&lt;td&gt;Verify install path before designing scopes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Cursor&lt;/strong&gt; + IDEs&lt;/td&gt;
&lt;td&gt;API key dominant; OAuth on remote&lt;/td&gt;
&lt;td&gt;Limited&lt;/td&gt;
&lt;td&gt;Limited&lt;/td&gt;
&lt;td&gt;Permissive; per-server consent&lt;/td&gt;
&lt;td&gt;Mature OAuth here is a differentiator&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Microsoft Copilot&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Entra ID&lt;/td&gt;
&lt;td&gt;N/A (Entra)&lt;/td&gt;
&lt;td&gt;N/A&lt;/td&gt;
&lt;td&gt;Admin-granted org-level&lt;/td&gt;
&lt;td&gt;Heaviest implementation; strongest procurement story&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Gemini&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Google OAuth&lt;/td&gt;
&lt;td&gt;N/A (Google)&lt;/td&gt;
&lt;td&gt;N/A&lt;/td&gt;
&lt;td&gt;Google's standard scope model&lt;/td&gt;
&lt;td&gt;Familiar to enterprise IT&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The practical implication: an MCP app shipping to Claude needs full DCR + RFC 8414 metadata support from day one. A multi-client MCP app needs all three patterns from day one. Greenfielding for a single auth model is fast and is also the most common reason teams cannot ship to client number two without a substantial rebuild six months later.&lt;/p&gt;

&lt;h2&gt;
  
  
  Scope Design: Per-Resource, Per-Verb, Per-Sensitivity
&lt;/h2&gt;

&lt;p&gt;The most common scope mistake is the binary scope: &lt;em&gt;access your data&lt;/em&gt;. This is what API-key-era integrations defaulted to, and it is what enterprise procurement now reflexively pushes back on. The fault lines that produce a defensible scope taxonomy:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Per-resource, not per-app.&lt;/strong&gt; A scope for &lt;em&gt;read tickets&lt;/em&gt; is different from a scope for &lt;em&gt;read customers&lt;/em&gt;. Granting both should be a deliberate choice, not a side effect of installing the connector.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Per-verb within resource.&lt;/strong&gt; Within a resource, separate read from write. &lt;code&gt;tickets:read&lt;/code&gt; and &lt;code&gt;tickets:write&lt;/code&gt; should be distinct scopes; the user should be able to grant one without the other.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Per-sensitivity within verb.&lt;/strong&gt; Some writes are higher-stakes than others. &lt;code&gt;tickets:write&lt;/code&gt; (create and update) should be distinct from &lt;code&gt;tickets:delete&lt;/code&gt;. &lt;code&gt;customers:write&lt;/code&gt; should be distinct from &lt;code&gt;customers:export&lt;/code&gt;. Anything that exfiltrates data or causes irreversible state change deserves its own scope.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Sample scope taxonomy: a CRM MCP app
&lt;/h3&gt;

&lt;p&gt;A representative scope structure for a mid-complexity B2B SaaS MCP app:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="c1"&gt;# Customer scopes&lt;/span&gt;
&lt;span class="s"&gt;crm:customers:read&lt;/span&gt;
&lt;span class="s"&gt;crm:customers:write&lt;/span&gt;
&lt;span class="s"&gt;crm:customers:delete&lt;/span&gt;
&lt;span class="s"&gt;crm:customers:export&lt;/span&gt;
&lt;span class="s"&gt;crm:customers:merge          // irreversible&lt;/span&gt;

&lt;span class="c1"&gt;# Deal scopes&lt;/span&gt;
&lt;span class="s"&gt;crm:deals:read&lt;/span&gt;
&lt;span class="s"&gt;crm:deals:write&lt;/span&gt;
&lt;span class="s"&gt;crm:deals:delete&lt;/span&gt;
&lt;span class="s"&gt;crm:deals:export&lt;/span&gt;
&lt;span class="s"&gt;crm:deals:close              // mark won/lost; high-stakes&lt;/span&gt;

&lt;span class="c1"&gt;# Contact scopes&lt;/span&gt;
&lt;span class="s"&gt;crm:contacts:read&lt;/span&gt;
&lt;span class="s"&gt;crm:contacts:write&lt;/span&gt;
&lt;span class="s"&gt;crm:contacts:delete&lt;/span&gt;
&lt;span class="s"&gt;crm:contacts:export&lt;/span&gt;
&lt;span class="s"&gt;crm:contacts:bulk_email      // rate-limited; high-stakes&lt;/span&gt;

&lt;span class="c1"&gt;# Note scopes (low-sensitivity attached records)&lt;/span&gt;
&lt;span class="s"&gt;crm:notes:read&lt;/span&gt;
&lt;span class="s"&gt;crm:notes:write&lt;/span&gt;

&lt;span class="c1"&gt;# Configuration scopes (admin-level)&lt;/span&gt;
&lt;span class="s"&gt;crm:settings:read&lt;/span&gt;
&lt;span class="s"&gt;crm:settings:write           // org-level; admin-only&lt;/span&gt;

&lt;span class="c1"&gt;# Billing scopes (highest sensitivity)&lt;/span&gt;
&lt;span class="s"&gt;crm:billing:read&lt;/span&gt;
&lt;span class="s"&gt;crm:billing:write&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The taxonomy reflects that &lt;em&gt;delete&lt;/em&gt;, &lt;em&gt;export&lt;/em&gt;, &lt;em&gt;merge&lt;/em&gt;, &lt;em&gt;close&lt;/em&gt;, &lt;em&gt;bulk_email&lt;/em&gt;, and &lt;em&gt;settings:write&lt;/em&gt; are higher-blast-radius than the routine read/write scopes. Procurement teams reviewing this scope list can immediately see what is at stake and which scopes need additional admin approval.&lt;/p&gt;

&lt;p&gt;The cost of fine-grained scopes is install-time UX (longer consent screens, more questions). The benefit is two-fold: enterprise procurement moves faster because the scopes map onto reviewers' existing mental models, and the blast radius of any individual mistake is smaller. Most products should err toward fine.&lt;/p&gt;

&lt;h2&gt;
  
  
  Tokens, Audit, and Revocation
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Token lifetimes
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Short-lived access tokens (1 hour or less) with refresh tokens are the right default.&lt;/strong&gt; Permanent tokens are a procurement red flag.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Token type&lt;/th&gt;
&lt;th&gt;Recommended lifetime&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Access token (routine scopes)&lt;/td&gt;
&lt;td&gt;30–60 minutes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Access token (high-sensitivity scopes)&lt;/td&gt;
&lt;td&gt;15 minutes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Refresh token&lt;/td&gt;
&lt;td&gt;30–90 days&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Re-consent prompt cadence&lt;/td&gt;
&lt;td&gt;90 days for high-stakes scopes&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Refresh should be transparent to the agent and visible to the user. Silent refresh that never surfaces to the user is acceptable for short windows; refresh that extends access indefinitely without re-prompting is not.&lt;/p&gt;

&lt;h3&gt;
  
  
  JWT vs opaque tokens
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Opaque access tokens are the safer default for most MCP apps.&lt;/strong&gt; Opaque tokens require a database lookup on every request, which gives you immediate revocation – the moment you delete the token from your store, requests using it fail. JWTs are stateless (operationally appealing) but cannot be revoked before they expire without a separate revocation list, which negates most of the JWT advantage.&lt;/p&gt;

&lt;p&gt;If you use JWTs, recommended claims include &lt;code&gt;sub&lt;/code&gt; (user ID), &lt;code&gt;aud&lt;/code&gt; (your MCP server resource indicator), &lt;code&gt;iss&lt;/code&gt; (your authorization server), &lt;code&gt;exp&lt;/code&gt; (expiration), &lt;code&gt;iat&lt;/code&gt; (issued at), &lt;code&gt;client_id&lt;/code&gt; (the AI client), &lt;code&gt;scope&lt;/code&gt; (granted scopes), and &lt;code&gt;session_id&lt;/code&gt; (for cross-call session reconstruction).&lt;/p&gt;

&lt;h3&gt;
  
  
  Revocation
&lt;/h3&gt;

&lt;p&gt;Three actors must be able to revoke MCP app access at any time:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;The user&lt;/strong&gt; can revoke through the AI client's connector or app management UI&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The admin&lt;/strong&gt; (for enterprise installs) can revoke through their identity provider or admin console&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Your service&lt;/strong&gt; can revoke through your own admin tools&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Revocation must be effective immediately, not at next token rotation.&lt;/strong&gt; Many MCP apps have a stated revocation path that, when exercised, leaves stale tokens working for hours. Test this. The gap between policy and practice is the gap that matters when an incident is live.&lt;/p&gt;

&lt;h3&gt;
  
  
  Audit log requirements
&lt;/h3&gt;

&lt;p&gt;Every action the agent takes through your MCP app should be auditable. The minimum bar:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;User identity&lt;/strong&gt; (which user the agent is acting on behalf of)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Service account / agent identity&lt;/strong&gt; (if applicable, especially at level 3)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Host AI client&lt;/strong&gt; (which client's agent invoked the tool)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Session identifier&lt;/strong&gt; (so a sequence of calls can be reconstructed)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tool invoked&lt;/strong&gt; (which capability was called)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Parameters passed&lt;/strong&gt; (with what arguments – possibly sanitized for sensitive data)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Result&lt;/strong&gt; (success, failure, error message)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Timestamp&lt;/strong&gt; (with sub-second precision)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Source IP&lt;/strong&gt; and &lt;strong&gt;user agent&lt;/strong&gt; (for forensics)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Scope used&lt;/strong&gt; (which OAuth scope authorized this call)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The reason this matters is procedural rather than technical. When something goes wrong – and at least once a year, for any MCP app touching real data, it will – the question &lt;em&gt;what did the agent do&lt;/em&gt; is a customer-facing, sometimes legally meaningful question. A team that can answer it in five minutes from a query against the audit log keeps the customer. A team that says &lt;em&gt;we'd have to reconstruct from individual logs, give us a few days&lt;/em&gt; loses them.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Common Failure Mode&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Audit logs have become the highest-leverage feature for enterprise close rates we have observed in MCP apps shipped over the past year. The most common failure pattern at level 2 is a team that built the log internally and never exposed it to customer admins – the audit exists technically and not procedurally, which is worse than not having it because it produces false confidence. Build the log on day one. Surface it to the customer's admin console, even minimally, by month three.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;For SOC 2 Type II–compliant environments, the audit log additionally needs tamper-evident storage (append-only log; cryptographic hashing or chained hashing across entries), retention aligned with customer's data retention requirements (typically 1–7 years), and access controls on the log itself.&lt;/p&gt;

&lt;h3&gt;
  
  
  SOC 2 mapping
&lt;/h3&gt;

&lt;p&gt;MCP apps shipping into enterprise commonly need SOC 2 Type II attestation. The mapping of MCP-specific security work to SOC 2 trust services criteria:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;SOC 2 Criterion&lt;/th&gt;
&lt;th&gt;What it requires&lt;/th&gt;
&lt;th&gt;MCP-specific evidence&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;CC6.1 Logical access controls&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Restrict access to information and IT systems&lt;/td&gt;
&lt;td&gt;OAuth scopes; per-tool consent; revocation procedures&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;CC6.2 New users, periodic review&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Onboard/offboard with appropriate access&lt;/td&gt;
&lt;td&gt;Token lifecycle; consent re-prompts; revocation logs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;CC6.3 Access provisioning&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Grant access based on role&lt;/td&gt;
&lt;td&gt;Scope taxonomy; admin-vs-user scope distinctions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;CC6.6 Encrypted transmission&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Encrypt data in transit&lt;/td&gt;
&lt;td&gt;TLS for all MCP transport; bearer tokens in HTTPS only&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;CC6.7 Restrict transmission of information&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Restrict data movement to authorized parties&lt;/td&gt;
&lt;td&gt;Resource indicators; scope-based data access&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;CC7.2 System monitoring&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Monitor for security events&lt;/td&gt;
&lt;td&gt;Audit log; anomaly detection on tool invocation patterns&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;CC7.3 Incident response&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Detect and respond to incidents&lt;/td&gt;
&lt;td&gt;Revocation procedures; audit forensics; communication plan&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;For most MCP apps the auth and audit work above maps cleanly onto SOC 2 controls. The work to add for SOC 2 compliance specifically is the documentation, evidence collection, and audit by a third-party assessor – typically 6–9 months and $50K–$150K for first-time SOC 2 Type II attestation. That attestation is part of the true cost of shipping to enterprise clients; auth complexity is one of the five drivers in &lt;a href="https://launchdayadvisors.com/guides/mcp-server-cost" rel="noopener noreferrer"&gt;what an MCP server costs to build&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Threat Model and Enterprise Readiness
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Threat model
&lt;/h3&gt;

&lt;p&gt;A working threat model for MCP apps shipping in 2026:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Threat&lt;/th&gt;
&lt;th&gt;Likelihood&lt;/th&gt;
&lt;th&gt;Mitigation&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Token theft via AI client compromise&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Low–medium&lt;/td&gt;
&lt;td&gt;Short-lived access tokens; immediate revocation; bind tokens to client_id and resource indicator&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Scope sprawl (user grants too much at install)&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;td&gt;Fine-grained scopes; clear consent UI; per-tool consent where supported&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Confused-deputy attack&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;td&gt;Treat agent inputs as untrusted; validate parameters server-side; never trust the agent's framing of user intent&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Prompt injection causing unintended tool invocation&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Medium–high&lt;/td&gt;
&lt;td&gt;Intent-preview UI; high-stakes scopes require user confirmation per-action; rate limits&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Replay attack (token replayed against different MCP server)&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Low–medium&lt;/td&gt;
&lt;td&gt;RFC 8707 Resource Indicators; bind tokens to specific MCP server identity&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;OAuth client impersonation&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Low&lt;/td&gt;
&lt;td&gt;Strict redirect URI validation; PKCE; verify client_id matches registered client&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Audit log gap&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;td&gt;Per-invocation logging from day one; expose to customer admins; tamper-evident storage&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Stale revocation (revoked tokens still working)&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;td&gt;Test revocation latency; use opaque tokens; if JWTs, maintain revocation list&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Privilege escalation via scope inheritance&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;td&gt;No scope inheritance; explicit grants per scope; admin scopes require step-up auth&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The two threats most often missed in initial designs are the &lt;strong&gt;confused-deputy attack&lt;/strong&gt; and &lt;strong&gt;prompt injection&lt;/strong&gt;. Both arise from the agent acting on parameters or framing it received from an untrusted source. Server-side validation of every parameter – not trusting the agent's interpretation of intent – is the primary defense.&lt;/p&gt;

&lt;h3&gt;
  
  
  Enterprise readiness checklist
&lt;/h3&gt;

&lt;p&gt;If you are selling into enterprise, the auth and security shape of your MCP app needs to clear this bar before procurement begins, not during it:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;OAuth 2.1 with PKCE as a primary auth path&lt;/li&gt;
&lt;li&gt;Dynamic Client Registration (RFC 7591) supported&lt;/li&gt;
&lt;li&gt;Authorization Server Metadata (RFC 8414) discovery document published&lt;/li&gt;
&lt;li&gt;Resource Indicators (RFC 8707) used to bind tokens to MCP server identity&lt;/li&gt;
&lt;li&gt;Scope taxonomy is per-resource, per-verb, per-sensitivity&lt;/li&gt;
&lt;li&gt;Sensitivity axis genuinely separates high-blast-radius operations from routine ones&lt;/li&gt;
&lt;li&gt;Token lifetimes are bounded (access tokens ≤1 hour)&lt;/li&gt;
&lt;li&gt;Refresh is transparent to the user; silent windows are short&lt;/li&gt;
&lt;li&gt;Re-consent prompts run on a defined cadence for high-stakes scopes&lt;/li&gt;
&lt;li&gt;Revocation is effective immediately (and tested)&lt;/li&gt;
&lt;li&gt;Audit logging captures user, client, session, tool, parameters, result, scope, IP, user-agent&lt;/li&gt;
&lt;li&gt;Customer-admin-facing audit log surface exists in your product&lt;/li&gt;
&lt;li&gt;Audit log uses tamper-evident storage (append-only, cryptographic chaining)&lt;/li&gt;
&lt;li&gt;SSO via Entra ID, Okta, and Google Workspace is supported (at minimum)&lt;/li&gt;
&lt;li&gt;SAML 2.0 supported&lt;/li&gt;
&lt;li&gt;SCIM provisioning supported&lt;/li&gt;
&lt;li&gt;SOC 2 Type II or equivalent third-party attestation is current&lt;/li&gt;
&lt;li&gt;Documented incident response process for compromise scenarios&lt;/li&gt;
&lt;li&gt;Penetration test report from the past 12 months available under NDA&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The two items teams routinely think they have and don't are the customer-facing audit log surface and the SCIM provisioning. Both are pre-procurement work, not post-. Both consistently get pushed past the first ship and consistently delay the first enterprise close by a quarter.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Pre-Procurement Diligence Questions&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If a customer's security team asks you these questions and you cannot answer with documented evidence, you have work to do before procurement. Walk through your auth design. Show the scope taxonomy. Demonstrate revocation latency end-to-end. Pull a sample audit log entry. Demonstrate the customer-admin audit surface. Walk through your SOC 2 control mapping. Each of these is a question security teams know how to ask in their sleep – and treating any of them as "we'll figure that out after we close the deal" is how the deal stops closing.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Common MCP Auth Mistakes
&lt;/h2&gt;

&lt;p&gt;Three patterns recur in MCP auth implementations that teams later regret:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Auth retrofit.&lt;/strong&gt; Shipping on API keys to move fast, then retrofitting OAuth when enterprise demand materializes. The retrofit is painful, breaks existing installs, and consumes a quarter of feature work. &lt;strong&gt;Fix:&lt;/strong&gt; design for OAuth from day one even if the first ship uses API keys.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Scope sprawl.&lt;/strong&gt; Shipping with one or two scopes, adding tools quickly, never re-examining the scope structure. Eighteen months in, the MCP app has fifty tools and three scopes. &lt;strong&gt;Fix:&lt;/strong&gt; scope review every quarter, with new tools mapped to the right scope deliberately.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Auth-as-blocker.&lt;/strong&gt; Treating auth as a blocker to ship, deferring to engineering, ending up with a design that constrains future choices. &lt;strong&gt;Fix:&lt;/strong&gt; treat auth as a first-class design problem owned by product.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Two additional mistakes worth naming:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Skipping Resource Indicators.&lt;/strong&gt; RFC 8707 Resource Indicators bind tokens to a specific MCP server identity, preventing replay against other servers. Many early MCP implementations skipped this. The cost is a class of token-confusion attacks that are easy to mitigate but hard to recover from after a compromise.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Audit log without admin UI.&lt;/strong&gt; Building the audit log internally but not exposing it to customer admins. The log exists technically; procedurally it is invisible to the buyer's security team.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Auth and security choices interact tightly with embedding depth (&lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;MCP embedding types&lt;/a&gt;) and the build-vs-buy decision (&lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP build vs buy&lt;/a&gt;). Get the auth right and the rest of the work has somewhere to land.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Guides
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;What to Call MCP Apps: Terminology Guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-embed-app-ai-clients" rel="noopener noreferrer"&gt;How to Embed Your App in AI Clients with MCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;MCP Embedding Types: Read-Only vs Actions vs Agent-Resident&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP Build vs Buy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://launchdayadvisors.com/guides/evaluate-mcp-build-partner" rel="noopener noreferrer"&gt;How to Evaluate an MCP Build Partner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Does MCP use OAuth?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Yes – the MCP specification mandates OAuth 2.1 with PKCE for remote MCP servers, plus Dynamic Client Registration (RFC 7591) and Authorization Server Metadata (RFC 8414). API keys are still common in local-server contexts (Cursor, AI-first IDEs) but are not spec-compliant for remote MCP servers in 2026.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What scopes should my MCP app request?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Request scopes per-resource, per-verb, per-sensitivity. A CRM MCP app should have separate scopes for customers:read, customers:write, customers:delete, customers:export, and customers:merge rather than a single crm:access scope. Fine-grained scopes are slower at install but faster through procurement.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is MCP HIPAA / SOC 2 compliant?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The MCP protocol itself is not certified for any compliance regime; certification applies to your MCP app's implementation. To meet HIPAA, SOC 2, GDPR, or other regimes, your MCP app's auth, audit, encryption, and data handling must meet the regime's requirements. Most enterprise-grade MCP apps in 2026 hold SOC 2 Type II.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can I use API keys for my MCP app?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;You can, but only for clients that support API key install (primarily Cursor and AI-first IDEs running local servers). API keys are not spec-compliant for remote MCP servers and are insufficient for enterprise procurement. For OAuth-supporting clients with remote-server requirements, OAuth 2.1 + PKCE + DCR is the right choice.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is Dynamic Client Registration in MCP?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Dynamic Client Registration (RFC 7591) is the OAuth feature that lets an AI client register itself with your authorization server programmatically, rather than requiring you to manually provision a client_id for each AI client. The MCP spec mandates DCR for spec-compliant remote servers. Without DCR, you cannot ship a generally-installable MCP app to clients like Claude that expect spec compliance.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How do I revoke access to my MCP app?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Three revocation paths must work: user-initiated (through the AI client's connector management), admin-initiated (through the customer's identity provider for enterprise installs), and service-initiated (through your own admin tools). All three should be effective immediately; verify this works in practice.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is per-tool consent in MCP?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Per-tool consent is a UX pattern where, at install, the user sees a list of the specific tools the MCP app exposes (create_ticket, delete_customer, etc.) and can grant or deny access to individual tools. Claude has the strongest per-tool consent UX in 2026; other clients are less granular.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How often should MCP tokens be refreshed?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Access tokens should expire within 30–60 minutes (15 minutes for high-sensitivity scopes); refresh tokens within 30–90 days. Re-consent prompts every 90 days are appropriate for high-stakes scopes; lower-stakes scopes can run longer between re-consents.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Does MCP work with SSO?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Yes, for clients that support enterprise SSO. Microsoft Copilot delegates to Entra ID; Gemini to Google OAuth; Claude's enterprise tier supports SAML and SCIM. Enterprise MCP app sales typically require SSO support for the major IdPs.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Should I use JWTs or opaque tokens?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Opaque tokens are the safer default for most MCP apps because they support immediate revocation. Use JWTs only when token lifetimes are very short (≤5 minutes) or when you have a specific high-throughput need and have built a JWT revocation list.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is RFC 8707 (Resource Indicators) in MCP?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Resource Indicators is an OAuth extension that binds a token to a specific resource – in MCP's case, your MCP server's identity. Without resource indicators, a token issued for one MCP server could be replayed against another, causing a token-confusion attack. The MCP spec recommends RFC 8707; spec-compliant clients enforce it.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=guides" rel="noopener noreferrer"&gt;launchdayadvisors.com&lt;/a&gt;. Launch Day Advisors is a buyer-side advisory firm: we help companies select AI, software, and design partners, and we are paid only by the buyer.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>mcp</category>
      <category>security</category>
      <category>oauth</category>
      <category>ai</category>
    </item>
    <item>
      <title>MCP Client Comparison: Claude vs ChatGPT vs Cursor vs Copilot vs Gemini</title>
      <dc:creator>Jonathan Blessing</dc:creator>
      <pubDate>Fri, 18 Sep 2026 12:07:29 +0000</pubDate>
      <link>https://dev.to/launchdayadvisors/mcp-client-comparison-claude-vs-chatgpt-vs-cursor-vs-copilot-vs-gemini-4dme</link>
      <guid>https://dev.to/launchdayadvisors/mcp-client-comparison-claude-vs-chatgpt-vs-cursor-vs-copilot-vs-gemini-4dme</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;In brief:&lt;/strong&gt; All major AI clients support MCP as of mid-2026, but they differ sharply in distribution model, auth, audience, and discovery. Claude is the strongest first ship for prosumer and knowledge-worker audiences. ChatGPT has the largest raw audience and the most mature app store. Cursor is the right surface for developer-tools companies. Microsoft Copilot wins for enterprise software with a Microsoft 365 footprint. Gemini matters for Workspace-heavy audiences. Perplexity is narrow and research-focused. The full matrix below covers eight dimensions per client and includes per-client gotchas, transport support, and realistic time-to-first-install.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;All major AI clients support MCP as of mid-2026 – Claude, ChatGPT, Cursor, Microsoft Copilot, Gemini, Perplexity – but they differ sharply in distribution model, auth pattern, audience, and discovery. The protocol itself is standardized (&lt;a href="https://www.jsonrpc.org/specification" rel="noopener noreferrer"&gt;JSON-RPC 2.0&lt;/a&gt;, three primitives, three transports), but two clients that both &lt;em&gt;support MCP&lt;/em&gt; can still be radically different distribution channels. Choosing where to ship first is one of the highest-leverage product decisions in an MCP roadmap, and the matrices most product teams build for themselves stop at "which clients support MCP." That is not the question that moves the decision.&lt;/p&gt;

&lt;p&gt;This guide compares the six clients that account for the bulk of professional MCP-mediated use across the eight dimensions that consistently matter. It uses the working vocabulary in our &lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;MCP terminology guide&lt;/a&gt;: an &lt;em&gt;MCP app&lt;/em&gt; is the user-installable artifact, an &lt;em&gt;MCP server&lt;/em&gt; is the engineering artifact underneath, a &lt;em&gt;tool&lt;/em&gt; is a single capability the server exposes.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Snapshot, Not Forecast&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Last verified: May 2026.&lt;/em&gt; The MCP client landscape moves faster than this page can be updated; we re-verify quarterly. If you are about to make a meaningful product investment based on what is below, confirm specifics with each vendor. The dimensions most likely to shift between updates are monetization (no client has a mature paid-app pathway yet) and agent-led routing (the discovery channel growing fastest).&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Which AI Clients Support MCP in 2026
&lt;/h2&gt;

&lt;p&gt;All major AI clients support MCP as of mid-2026. Long-tail vertical AI clients (legal, medical, sales-specific) are adopting at varying rates. The protocol itself is standardized; the differences across clients are in distribution, auth, audience, and discovery, not in whether the protocol works.&lt;/p&gt;

&lt;p&gt;The clients in scope for this comparison:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Claude&lt;/strong&gt; (Anthropic) – first-class MCP support since 2024 launch&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;ChatGPT&lt;/strong&gt; (OpenAI) – first-class as of 2025, consolidated from earlier Plugin/GPT framework&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cursor&lt;/strong&gt; + AI-first IDEs (Windsurf, Cline, Continue) – first-class, treats MCP as primary extension model&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Microsoft Copilot&lt;/strong&gt; – supported via Copilot agent framework&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Gemini&lt;/strong&gt; (Google) – first-party servers from late 2025; third-party support firming through 2026&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Perplexity&lt;/strong&gt; – supported, retrieval-focused&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  The Eight Dimensions That Matter
&lt;/h2&gt;

&lt;p&gt;If you are deciding which AI clients to ship to and in what order, the questions that actually move the decision are: how does each client distribute MCP apps, what is its auth model, who is its audience, and how does discovery work inside it.&lt;/p&gt;

&lt;p&gt;The eight dimensions:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;MCP support.&lt;/strong&gt; Whether the client supports MCP, what version of the spec it implements, whether support is first-class or retrofitted.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;User-facing term.&lt;/strong&gt; What the client calls an installable MCP app inside its own product. Determines marketing language.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Distribution mechanism.&lt;/strong&gt; How a user gets your MCP app installed: curated marketplace, manual install via configuration, or admin-controlled enterprise distribution.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Discovery.&lt;/strong&gt; How a user finds your MCP app among alternatives: marketplace search, featured slots, agent-led routing, external catalogs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Auth model.&lt;/strong&gt; OAuth 2.1 with PKCE, API-key handoff, or enterprise SSO via the host's identity provider.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Permissions granularity.&lt;/strong&gt; Whether access is granted at the MCP app level, the tool level, or per-action at runtime.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Audience.&lt;/strong&gt; Who actually uses this client – consumer, prosumer, developer, enterprise knowledge worker, vertical specialist.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Monetization pathway.&lt;/strong&gt; Whether and how an MCP app developer can charge for use.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  The matrix
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Client&lt;/th&gt;
&lt;th&gt;MCP support&lt;/th&gt;
&lt;th&gt;User-facing term&lt;/th&gt;
&lt;th&gt;Distribution&lt;/th&gt;
&lt;th&gt;Discovery&lt;/th&gt;
&lt;th&gt;Auth model&lt;/th&gt;
&lt;th&gt;Permissions&lt;/th&gt;
&lt;th&gt;Audience&lt;/th&gt;
&lt;th&gt;Monetization&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Claude&lt;/strong&gt; (Anthropic)&lt;/td&gt;
&lt;td&gt;First-class, since 2024 launch; tracks current spec&lt;/td&gt;
&lt;td&gt;Connector&lt;/td&gt;
&lt;td&gt;In-product connector marketplace + manual config (claude.json)&lt;/td&gt;
&lt;td&gt;Marketplace search, editorial featured, agent-led suggestion&lt;/td&gt;
&lt;td&gt;OAuth 2.1 + PKCE; Dynamic Client Registration; SAML/SCIM on enterprise tier&lt;/td&gt;
&lt;td&gt;Per-tool consent at install; per-action confirmation for mutations&lt;/td&gt;
&lt;td&gt;Prosumer + enterprise; strong dev adoption&lt;/td&gt;
&lt;td&gt;No first-class paid-app billing yet; vendor-side billing common&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;ChatGPT&lt;/strong&gt; (OpenAI)&lt;/td&gt;
&lt;td&gt;First-class as of 2025; consolidated from Plugin/GPT framework&lt;/td&gt;
&lt;td&gt;App&lt;/td&gt;
&lt;td&gt;Consolidated GPT/MCP app store + manual install paths&lt;/td&gt;
&lt;td&gt;Store search, featured slots, prompt-led routing&lt;/td&gt;
&lt;td&gt;OAuth or API key depending on install path&lt;/td&gt;
&lt;td&gt;App-level scopes; per-tool consent on newer builds&lt;/td&gt;
&lt;td&gt;Broad consumer + prosumer; growing enterprise via Teams/Enterprise&lt;/td&gt;
&lt;td&gt;App store with revenue share emerging; details still firming&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Cursor&lt;/strong&gt; + AI-first IDEs&lt;/td&gt;
&lt;td&gt;First-class; treats MCP as primary extension model&lt;/td&gt;
&lt;td&gt;MCP server&lt;/td&gt;
&lt;td&gt;Manual install via config file (&lt;code&gt;mcp.json&lt;/code&gt;); community catalogs; one-click install URLs&lt;/td&gt;
&lt;td&gt;Community catalogs, GitHub, word-of-mouth, Cursor's directory&lt;/td&gt;
&lt;td&gt;API key dominant; OAuth supported on remote servers&lt;/td&gt;
&lt;td&gt;Largely permissive; per-server install consent&lt;/td&gt;
&lt;td&gt;Developers, AI-first engineering teams&lt;/td&gt;
&lt;td&gt;No first-party billing; open-source norms dominate&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Microsoft Copilot&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Supported via Copilot agent framework&lt;/td&gt;
&lt;td&gt;Agent / Copilot extension&lt;/td&gt;
&lt;td&gt;IT admin-controlled deployment via Microsoft 365 admin center&lt;/td&gt;
&lt;td&gt;Internal corporate catalogs; Microsoft AppSource&lt;/td&gt;
&lt;td&gt;Entra ID; SAML; SCIM&lt;/td&gt;
&lt;td&gt;Admin-granted org-level scopes; per-user consent for sensitive scopes&lt;/td&gt;
&lt;td&gt;Enterprise knowledge workers, Microsoft 365 customers&lt;/td&gt;
&lt;td&gt;AppSource billing; co-sell programs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Gemini&lt;/strong&gt; (Google)&lt;/td&gt;
&lt;td&gt;First-party servers from late 2025; third-party support expanding through 2026&lt;/td&gt;
&lt;td&gt;Connector / extension (terminology in flux)&lt;/td&gt;
&lt;td&gt;Workspace admin distribution; account-level installs for individuals&lt;/td&gt;
&lt;td&gt;Workspace marketplace; Google search-led discovery&lt;/td&gt;
&lt;td&gt;Google OAuth&lt;/td&gt;
&lt;td&gt;Scope-based (Google's standard model)&lt;/td&gt;
&lt;td&gt;Workspace customers, Google account holders&lt;/td&gt;
&lt;td&gt;Workspace marketplace billing pathways&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Perplexity&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Supported, focused on retrieval and research-flow tools&lt;/td&gt;
&lt;td&gt;Connector&lt;/td&gt;
&lt;td&gt;In-product, lightweight install&lt;/td&gt;
&lt;td&gt;Curated; small surface&lt;/td&gt;
&lt;td&gt;OAuth&lt;/td&gt;
&lt;td&gt;App-level&lt;/td&gt;
&lt;td&gt;Research-heavy professionals, prosumer&lt;/td&gt;
&lt;td&gt;Limited; product-led growth focus&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Transport and Auth Support Per Client
&lt;/h2&gt;

&lt;p&gt;The MCP spec defines three transports (stdio for local servers, SSE for early remote servers, streamable HTTP for current remote servers). Client support varies, and this affects which hosting model you can use.&lt;/p&gt;

&lt;h3&gt;
  
  
  Transports
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Client&lt;/th&gt;
&lt;th&gt;stdio (local)&lt;/th&gt;
&lt;th&gt;SSE (legacy remote)&lt;/th&gt;
&lt;th&gt;Streamable HTTP (current remote)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Claude desktop&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Claude.ai (web)&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;ChatGPT&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Limited (developer mode)&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Cursor&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Microsoft Copilot&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Gemini&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Limited&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Perplexity&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;For a remote MCP server in 2026, &lt;strong&gt;streamable HTTP is the right default&lt;/strong&gt;. SSE is supported across all clients but is the older transport and is slowly being deprecated. Stdio matters only for desktop clients and developer-mode integrations.&lt;/p&gt;

&lt;h3&gt;
  
  
  Auth and security capabilities
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Client&lt;/th&gt;
&lt;th&gt;OAuth 2.1&lt;/th&gt;
&lt;th&gt;PKCE&lt;/th&gt;
&lt;th&gt;Dynamic Client Registration&lt;/th&gt;
&lt;th&gt;Authorization server metadata&lt;/th&gt;
&lt;th&gt;Enterprise SSO&lt;/th&gt;
&lt;th&gt;Per-tool consent&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Claude&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Required&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Yes (RFC 8414)&lt;/td&gt;
&lt;td&gt;SAML, SCIM (enterprise tier)&lt;/td&gt;
&lt;td&gt;Yes, at install&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;ChatGPT&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Yes (modern install paths)&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Partial&lt;/td&gt;
&lt;td&gt;Partial&lt;/td&gt;
&lt;td&gt;OIDC&lt;/td&gt;
&lt;td&gt;App-level + emerging per-tool&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Cursor&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Yes (remote servers)&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Limited&lt;/td&gt;
&lt;td&gt;Limited&lt;/td&gt;
&lt;td&gt;Limited&lt;/td&gt;
&lt;td&gt;No native UI&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Microsoft Copilot&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Via Entra ID&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;N/A (Entra-managed)&lt;/td&gt;
&lt;td&gt;N/A (Entra-managed)&lt;/td&gt;
&lt;td&gt;Native (Entra)&lt;/td&gt;
&lt;td&gt;Admin-granted org-level&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Gemini&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Via Google OAuth&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;N/A (Google-managed)&lt;/td&gt;
&lt;td&gt;N/A&lt;/td&gt;
&lt;td&gt;Native (Google Workspace)&lt;/td&gt;
&lt;td&gt;Scope-level&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Perplexity&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Limited&lt;/td&gt;
&lt;td&gt;Limited&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;td&gt;App-level&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The practical implication: an MCP app shipping to Claude needs full DCR + RFC 8414 metadata support from day one. A multi-client MCP app needs all three auth patterns. For deep auth design guidance, see &lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP auth and security&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Per-Client Decisions and Gotchas
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Should I ship my MCP app to Claude?
&lt;/h3&gt;

&lt;p&gt;Ship to Claude first if your buyer is prosumer or knowledge-worker. Claude has the most coherent buyer experience for connectors, the strongest baseline for &lt;em&gt;if you ship to one client, ship here&lt;/em&gt;, and editorial featured slots that meaningfully drive distribution.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Distinguishing characteristics:&lt;/strong&gt; in-product connector marketplace, OAuth 2.1 + PKCE with mandatory Dynamic Client Registration (the spec compliance bar is the highest in the table), per-tool consent at install, agent-led suggestion (Claude itself surfacing your connector mid-conversation when relevant), strong adoption among developers and knowledge workers.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Claude Gotchas&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Connector marketplace review takes 2–3 weeks for new submissions; rejections most often cite scope-design issues or unclear tool descriptions. Per-tool consent screens get long with many tools – connectors with 30+ tools have noticeably higher abandonment at install. Group tools by capability or split into multiple connectors. Enterprise tier has additional review requirements (SAML SSO support, admin install support, audit log surface).&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  Should I ship my MCP app to ChatGPT?
&lt;/h3&gt;

&lt;p&gt;Ship to ChatGPT first if your audience is broadly consumer or prosumer and raw audience size matters more than depth of feature support. ChatGPT has the largest user base in the table by a wide margin, and the consolidated GPT/MCP app store is the most mature MCP marketplace as of 2026.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Distinguishing characteristics:&lt;/strong&gt; consolidated app store, OAuth or API key depending on install path, store search + featured slots + prompt-led routing, broadest audience.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Gotchas:&lt;/strong&gt; legacy Custom GPT documentation still leaks into developer docs (verify which install path your app actually uses); revenue share program details for the app store have been firming through 2026; featured-slot positioning is the dominant distribution lever and the long tail is hard.&lt;/p&gt;

&lt;h3&gt;
  
  
  Should I ship my MCP app to Cursor and the AI-first IDEs?
&lt;/h3&gt;

&lt;p&gt;Ship to Cursor (and Windsurf, Cline, Continue) first only if your product is a developer tool. The AI-first IDEs are the right surface for developer-tooling companies and almost no one else; the audience does not match most B2B SaaS buyer profiles.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Distinguishing characteristics:&lt;/strong&gt; manual install via &lt;code&gt;mcp.json&lt;/code&gt; config file, community catalogs, no marketplace gatekeeper, API-key-dominant auth.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Gotchas:&lt;/strong&gt; the configuration file is the install vector – users manually edit &lt;code&gt;mcp.json&lt;/code&gt; (error-prone, higher install-fail rate than marketplace clients); one-click install URLs (&lt;code&gt;cursor://...&lt;/code&gt;) reduce this and should be provided where possible; Cline, Continue, and Windsurf have similar install patterns but slightly different config schemas; DevRel matters here more than in any other client.&lt;/p&gt;

&lt;h3&gt;
  
  
  Should I ship my MCP app to Microsoft Copilot?
&lt;/h3&gt;

&lt;p&gt;Ship to Copilot first if your product sells into enterprise and your buyers already have a Microsoft 365 footprint. Copilot is the strongest enterprise distribution surface in the table, with the heaviest implementation requirements and the most mature procurement story.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Distinguishing characteristics:&lt;/strong&gt; IT admin-controlled deployment via Microsoft 365 admin center, Entra ID identity, AppSource marketplace, enterprise knowledge worker audience, AppSource billing + co-sell programs.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Copilot Gotchas&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Entra ID setup is the longest pole – plan for 2–4 weeks of identity-integration work even with experienced engineering. AppSource review can take 6–12 weeks for new MCP-app submissions; the review is more rigorous than other clients (security, accessibility, compliance). Copilot's MCP support sits inside the larger Copilot Studio + agents framework, which has its own concepts (knowledge sources, topics, actions) that overlap MCP terminology – expect a translation layer in conversations with Microsoft.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  Should I ship my MCP app to Gemini?
&lt;/h3&gt;

&lt;p&gt;Ship to Gemini first if your audience is Workspace-heavy. Gemini supports MCP across Google Workspace properties, with first-party MCP servers shipped by Google for Drive, Gmail, Calendar, Chat, and Chrome DevTools through late 2025 and 2026.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Distinguishing characteristics:&lt;/strong&gt; Workspace admin distribution, Google OAuth, Workspace marketplace + Google search-led discovery, Workspace customer audience.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Gotchas:&lt;/strong&gt; third-party MCP support is real but firming through 2026 (Google's first-party servers shipped first, third-party path lags – verify current state before committing roadmap); Workspace admin distribution requires a Workspace customer account on the buyer side; feature parity with Anthropic is uneven.&lt;/p&gt;

&lt;h3&gt;
  
  
  Should I ship my MCP app to Perplexity?
&lt;/h3&gt;

&lt;p&gt;Ship to Perplexity first only if your product augments research, retrieval, or a vertical-data workflow. Narrower surface than the other clients, focused on research-heavy professional use.&lt;/p&gt;

&lt;h2&gt;
  
  
  Time to First Install and What Will Change First
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Realistic deployment timelines
&lt;/h3&gt;

&lt;p&gt;Time from a working MCP server to first user install per client, assuming an experienced team with the server already built:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Client&lt;/th&gt;
&lt;th&gt;Time to first install&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Cursor&lt;/strong&gt; + AI-first IDEs&lt;/td&gt;
&lt;td&gt;1–2 days (no marketplace review; just publish install URL or community catalog entry)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Claude&lt;/strong&gt; (consumer connectors)&lt;/td&gt;
&lt;td&gt;2–4 weeks (marketplace review, scope review)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Claude&lt;/strong&gt; (enterprise tier)&lt;/td&gt;
&lt;td&gt;4–8 weeks (additional review for SAML/SCIM, admin distribution)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;ChatGPT&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;3–6 weeks (app store review; revenue share enrollment if applicable)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Gemini&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;2–6 weeks (Workspace marketplace review)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Perplexity&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;1–3 weeks (lightweight curation)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Microsoft Copilot&lt;/strong&gt; + AppSource&lt;/td&gt;
&lt;td&gt;6–12 weeks (rigorous AppSource review)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;These ranges assume the server is built and OAuth is working. Full timeline from project kickoff to first user install runs 8–24 weeks depending on the client and build complexity. Each additional client also adds 30–60% to the build, which is why client count is one of the larger line items in &lt;a href="https://launchdayadvisors.com/guides/mcp-server-cost" rel="noopener noreferrer"&gt;what an MCP server costs to build&lt;/a&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  Monetization landscape
&lt;/h3&gt;

&lt;p&gt;Monetization is currently weak across all clients in 2026:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Microsoft AppSource&lt;/strong&gt; and &lt;strong&gt;Workspace marketplace (Gemini)&lt;/strong&gt;: mature billing infrastructure inherited from existing Microsoft / Google channels&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;ChatGPT app store&lt;/strong&gt;: revenue share programs emerging, details still firming&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Claude&lt;/strong&gt;, &lt;strong&gt;Cursor&lt;/strong&gt;, &lt;strong&gt;Perplexity&lt;/strong&gt;: no first-class paid-app billing&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For most B2B products in 2026, the right monetization path is your existing subscription. The MCP app is a distribution surface, not a billing channel. Revisit in twelve to eighteen months.&lt;/p&gt;

&lt;h3&gt;
  
  
  What will change first
&lt;/h3&gt;

&lt;p&gt;Two dimensions are most likely to shift between quarterly updates of this matrix:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Monetization.&lt;/strong&gt; Every client knows it needs a story; none has fully shipped one. Expect meaningful changes in 2026 and 2027. The first client to ship a credible developer-revenue model will reshape distribution math.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Agent-led routing.&lt;/strong&gt; The degree to which the AI client itself recommends MCP apps to users mid-conversation. Tool description quality compounds disproportionately on agent-led routing in ways it does not yet on marketplace search.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Reading the matrix when you choose where to ship
&lt;/h2&gt;

&lt;p&gt;A few patterns recur across the engagements we work on, and they are the patterns most absent from the matrices product teams build for themselves.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Audience first, mechanics second.&lt;/strong&gt; The single most common mistake is choosing a client because the developer experience is good rather than because the buyer is there. Cursor has the most permissive distribution model in the table, and for most B2B SaaS products it is the wrong place to start, because the buyer of a CRM or a contracts platform is not an AI-first engineer using Cursor.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Distribution model determines distribution work.&lt;/strong&gt; A marketplace-distributed client (Claude, ChatGPT, AppSource) means submitting, getting reviewed, optimizing for store search, and competing for featured slots – work that looks more like App Store optimization than like API integration. A manual-install client means a different motion entirely.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Auth model is a procurement signal.&lt;/strong&gt; Enterprise buyers have radically different reactions to "OAuth with per-tool consent" versus "API key in a config file" versus "Entra-ID-mediated admin install." If you intend to sell into enterprise, the clients with mature auth and admin-controlled distribution are higher-leverage even when the developer experience is heavier.&lt;/p&gt;

&lt;p&gt;For the strategic question of &lt;em&gt;which clients to ship to&lt;/em&gt;, this matrix is most useful read alongside &lt;a href="https://launchdayadvisors.com/guides/mcp-strategy-decision-framework" rel="noopener noreferrer"&gt;the MCP strategy decision framework&lt;/a&gt;. For the technical question of &lt;em&gt;what auth model to design for&lt;/em&gt;, see &lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP auth and security&lt;/a&gt;. For build-vs-buy, see &lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP build vs buy&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;A matrix is a snapshot. The strategy is the read.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Guides
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;What to Call MCP Apps: Terminology Guide&lt;/a&gt; – Working vocabulary for product teams shipping in 2026&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-embed-app-ai-clients" rel="noopener noreferrer"&gt;How to Embed Your App in AI Clients with MCP&lt;/a&gt; – The full strategic framework&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-strategy-decision-framework" rel="noopener noreferrer"&gt;MCP Strategy Decision Framework&lt;/a&gt; – Should your app be in AI clients in 2026?&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;MCP Embedding Types Explained&lt;/a&gt; – Read-only, actions, agent-resident&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP Auth and Security&lt;/a&gt; – OAuth 2.1, scopes, audit logs, enterprise readiness&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Which AI clients support MCP?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;All major AI clients support MCP as of mid-2026: Claude, ChatGPT, Cursor (and other AI-first IDEs like Windsurf, Cline, Continue), Microsoft Copilot, Gemini, and Perplexity. The protocol itself is standardized across these clients; differences are in distribution, auth, audience, and discovery.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is Claude or ChatGPT better for MCP apps?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Claude has the more coherent connector experience, stronger agent-led discovery, and the most spec-compliant OAuth implementation. ChatGPT has the larger raw audience and the more mature app store. For prosumer and knowledge-worker audiences, Claude is typically the stronger first ship. For consumer-facing products, ChatGPT typically wins on reach.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Does Microsoft Copilot support MCP?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Yes, through the Copilot agent framework (Copilot Studio + agents). Distribution is admin-controlled via the Microsoft 365 admin center, auth uses Entra ID, and AppSource provides the marketplace. Implementation overhead is higher than other clients; procurement story is stronger.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Does Cursor support MCP?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Yes, as a first-class extension model. Cursor and other AI-first IDEs (Windsurf, Cline, Continue) treat MCP as the primary extension surface. Auth is predominantly API-key based for local servers; OAuth is supported for remote servers. Distribution is via manual install (mcp.json config) and community catalogs.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can one MCP app work in all AI clients?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The MCP protocol is standardized, so the underlying server can be reused. But each client has its own auth model, distribution mechanism, terminology, and metadata standards. Expect 30–60% additional work per added client even with full server reuse.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Which MCP client has the largest user base?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;ChatGPT has the largest raw audience among the major AI clients in 2026, by a meaningful margin. Claude has the most engaged prosumer audience. Cursor leads in AI-first developer audience. Microsoft Copilot has the largest enterprise footprint via Microsoft 365 distribution.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What MCP transport should I use?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;For local servers, stdio. For remote/hosted servers (the typical SaaS pattern), streamable HTTP is the right default in 2026. SSE is supported but is the older transport and is slowly being deprecated for new builds.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Does MCP support Dynamic Client Registration?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Yes – the MCP spec specifies OAuth 2.1 with Dynamic Client Registration (RFC 7591) and authorization server metadata discovery (RFC 8414) for remote servers. Claude has the strongest DCR support in 2026; other clients have partial implementations.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://launchdayadvisors.com/guides/mcp-client-comparison?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=guides" rel="noopener noreferrer"&gt;launchdayadvisors.com&lt;/a&gt;. Launch Day Advisors is a buyer-side advisory firm: we help companies select AI, software, and design partners, and we are paid only by the buyer.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>mcp</category>
      <category>ai</category>
      <category>tooling</category>
      <category>productivity</category>
    </item>
    <item>
      <title>What It Costs to Build an MCP Server in 2026</title>
      <dc:creator>Jonathan Blessing</dc:creator>
      <pubDate>Fri, 18 Sep 2026 12:06:08 +0000</pubDate>
      <link>https://dev.to/launchdayadvisors/what-it-costs-to-build-an-mcp-server-in-2026-2obh</link>
      <guid>https://dev.to/launchdayadvisors/what-it-costs-to-build-an-mcp-server-in-2026-2obh</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;In brief:&lt;/strong&gt; A partner-built MCP server costs ~$100K–$300K for a level-1 read-only single-client app and ~$300K–$700K for a level-2 actions app; a second client adds 1.4–1.7×, and a level-3 agent-resident build starts at $1M+. In-house equivalents run 60–80% of partner cost in raw spend before opportunity cost. The number is driven by auth complexity, tool-surface size, your own product's complexity, multi-client overhead, and embedding depth – not by the server code itself. Budget $5K–$25K/month for ongoing maintenance on top of the build.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Building an MCP server costs between $100K and $1M+ in 2026, and the single biggest factor is how much the server is allowed to do. A read-only connector to one AI client runs $100K–$300K. A server that takes actions on a user's behalf runs $300K–$700K. An agent-resident rebuild starts at $1M. The server code itself is the cheap part – auth, audit, the safety story, and distribution are where the budget actually goes.&lt;/p&gt;

&lt;p&gt;MCP servers are almost never priced as a license – the protocol is open and no major AI client has first-class paid-app billing yet – so "MCP server pricing" means the build ($100K–$1M+ by scope), the retainer that follows it ($5K–$25K/month), and the underlying API and token costs that land on whoever uses it.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;What you are pricing&lt;/th&gt;
&lt;th&gt;2026 figure&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Level-1 read-only server, one client, partner-built&lt;/td&gt;
&lt;td&gt;$100K–$300K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Level-2 actions server, one client, partner-built&lt;/td&gt;
&lt;td&gt;$300K–$700K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Second client&lt;/td&gt;
&lt;td&gt;1.4–1.7× the single-client total ($420K–$1.2M at level 2)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Security and auth line items in a level-2 build&lt;/td&gt;
&lt;td&gt;OAuth $60K–$120K · audit log $40K–$80K · third-party pen test $30K · first-time SOC 2 Type II $50K–$150K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Ongoing maintenance&lt;/td&gt;
&lt;td&gt;$5K–$25K/month retainer, plus ~$20K/year hosting&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Fee to install or use the server&lt;/td&gt;
&lt;td&gt;None – the cost is the underlying service's API plan, the AI client's token bill, and hosting; see MCP server pricing below&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Those ranges come from the same place every figure in this guide does: real 2026 partner engagements and in-house builds, cross-checked against our &lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP build vs buy analysis&lt;/a&gt;. This guide breaks the number down – what you are paying for, how scope moves it, what it looks like in-house versus with a partner, and three worked examples at different sizes. If you are still deciding whether to ship to AI clients at all, start with the &lt;a href="https://launchdayadvisors.com/guides/mcp-strategy-decision-framework" rel="noopener noreferrer"&gt;MCP strategy decision framework&lt;/a&gt;; if you have decided and are choosing who builds it, see &lt;a href="https://launchdayadvisors.com/guides/evaluate-mcp-build-partner" rel="noopener noreferrer"&gt;how to evaluate an MCP build partner&lt;/a&gt;.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The Estimate That Wrecks the Budget&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Almost every blown MCP budget starts with an undersized estimate. A serious MCP server shipped to one client at actions depth is not a two-week sprint and not a single-engineer project. Teams that scope it that way routinely discover by month three that they are short two engineers and a designer, and by month six that the first ship will not clear the safety bar enterprise procurement asks about. The number below is what it costs to do it once, correctly, instead of twice.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  What Goes Into an MCP Server Build
&lt;/h2&gt;

&lt;p&gt;When you budget for an MCP server, you are budgeting for seven things, and only one of them is the server. A complete level-2 (actions) build for a single client is one to two quarters of work for a properly staffed team. The scope:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Server implementation&lt;/strong&gt; – the process, hosting, observability, and deployment pipeline, built to the &lt;a href="https://modelcontextprotocol.io" rel="noopener noreferrer"&gt;MCP spec&lt;/a&gt; (&lt;a href="https://www.jsonrpc.org/specification" rel="noopener noreferrer"&gt;JSON-RPC 2.0&lt;/a&gt; over stdio, SSE, or streamable HTTP).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tool surface design&lt;/strong&gt; – the &lt;code&gt;create_&lt;/code&gt;, &lt;code&gt;update_&lt;/code&gt;, &lt;code&gt;search_&lt;/code&gt;, and &lt;code&gt;get_&lt;/code&gt; operations, each named and documented with the precision of a public API, because an agent reads the names to decide what to call.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Auth implementation&lt;/strong&gt; – OAuth 2.1 + PKCE, typically with Dynamic Client Registration and authorization-server metadata, plus a scope taxonomy, token lifetimes, refresh, and revocation. This is one of the largest line items, and it is covered in depth in &lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP auth and security&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Audit and logging surface&lt;/strong&gt; – per-invocation logs, parameter capture, session reconstruction, and a customer-admin-facing view of what the agent did.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Safety story&lt;/strong&gt; – idempotency keys, reversibility patterns (soft delete, revision history), and intent-preview-friendly parameter shapes. The depth required here scales with &lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;embedding level&lt;/a&gt;: read-only barely needs it, actions cannot ship without it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Distribution package&lt;/strong&gt; – submission to the host client's marketplace, store metadata, screenshots, documentation, and a support workflow.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Maintenance commitment&lt;/strong&gt; – keeping up with the host client's spec, auth, and distribution-policy changes, plus your own evolving tool surface, indefinitely.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;That list is the work for one client. The server code – item one – is genuinely the cheap part. Auth, audit, and the safety story are where a six-figure budget is spent, because they are the difference between a prototype that demos well and a product that survives a security review.&lt;/p&gt;

&lt;h2&gt;
  
  
  Cost Ranges by Scope
&lt;/h2&gt;

&lt;p&gt;Scope is the master lever. "Scope" here means two things: how much the server is allowed to do (its &lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;embedding level&lt;/a&gt;) and how many AI clients you ship to. The rough envelopes for partner-built MCP servers in 2026:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Scope&lt;/th&gt;
&lt;th&gt;Calendar time&lt;/th&gt;
&lt;th&gt;Partner cost (USD)&lt;/th&gt;
&lt;th&gt;In-house (raw spend)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Level-1 read-only, single client&lt;/td&gt;
&lt;td&gt;~1 quarter&lt;/td&gt;
&lt;td&gt;$100K–$300K&lt;/td&gt;
&lt;td&gt;$80K–$240K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Level-2 actions, single client&lt;/td&gt;
&lt;td&gt;~2 quarters&lt;/td&gt;
&lt;td&gt;$300K–$700K&lt;/td&gt;
&lt;td&gt;$200K–$520K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Level-2 actions, two clients&lt;/td&gt;
&lt;td&gt;~2.5–3 quarters&lt;/td&gt;
&lt;td&gt;$420K–$1.2M&lt;/td&gt;
&lt;td&gt;$300K–$900K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Level-3 agent-resident&lt;/td&gt;
&lt;td&gt;Multi-quarter program&lt;/td&gt;
&lt;td&gt;$1M+&lt;/td&gt;
&lt;td&gt;$700K+&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;Level-1 read-only&lt;/strong&gt; lets an agent search and retrieve from your product but never change anything. The safety surface is small, so this is the cheapest serious ship. The bottom of the range – roughly $100K–$150K – buys a single client, 5–10 carefully chosen tools, OAuth 2.1 + PKCE + DCR, and basic audit logging.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Level-2 actions&lt;/strong&gt; lets the agent create, update, and delete on the user's behalf. That single capability change roughly doubles the cost, because every write operation needs idempotency, reversibility, and an intent-preview-friendly shape, and the audit log moves from nice-to-have to mandatory.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Two clients&lt;/strong&gt; is not double the work, but it is not free either. A second client adds 1.4–1.7× the single-client cost – different auth, different distribution, different terminology, different review process. You are porting a working design, not rebuilding it, but each surface wants to be excellent on its own terms.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Level-3 agent-resident&lt;/strong&gt; is a different category: rebuilding the product so an agent can operate it end to end. It is a multi-quarter program starting at $1M, and most teams should not start here. The &lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;embedding types guide&lt;/a&gt; covers when level-3 is justified – almost always only when the company is rebuilding around an agent-first thesis.&lt;/p&gt;

&lt;h2&gt;
  
  
  Line-Item Cost Breakdown
&lt;/h2&gt;

&lt;p&gt;Ranges are useful for a board slide; line items are what you negotiate against. Here is a representative breakdown for a level-2 single-client partner build at the middle of its range (about $500K total):&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Component&lt;/th&gt;
&lt;th&gt;Typical cost (USD)&lt;/th&gt;
&lt;th&gt;What it covers&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Discovery, design, scope taxonomy&lt;/td&gt;
&lt;td&gt;$40K–$80K&lt;/td&gt;
&lt;td&gt;Posture review, embedding-level decision, scope design, tool-surface specification&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Server implementation, hosting, observability&lt;/td&gt;
&lt;td&gt;$50K–$100K&lt;/td&gt;
&lt;td&gt;MCP spec implementation, transport, hosting infra, monitoring&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Tool surface (10–25 tools)&lt;/td&gt;
&lt;td&gt;$80K–$180K&lt;/td&gt;
&lt;td&gt;Implementation, validation, testing, and documentation per tool&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;OAuth implementation, scope design&lt;/td&gt;
&lt;td&gt;$60K–$120K&lt;/td&gt;
&lt;td&gt;OAuth 2.1 + PKCE + DCR, scope taxonomy, token lifecycle, revocation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Audit log + customer-admin surface&lt;/td&gt;
&lt;td&gt;$40K–$80K&lt;/td&gt;
&lt;td&gt;Per-invocation logging, tamper-evident storage, admin UI&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Safety story&lt;/td&gt;
&lt;td&gt;$60K–$120K&lt;/td&gt;
&lt;td&gt;Idempotency keys, soft-delete and restore, revision history, intent preview&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Marketplace submission, distribution polish&lt;/td&gt;
&lt;td&gt;$20K–$50K&lt;/td&gt;
&lt;td&gt;Listing copy, screenshots, review iteration, documentation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Project management, knowledge transfer, contingency&lt;/td&gt;
&lt;td&gt;$40K–$80K&lt;/td&gt;
&lt;td&gt;PM overhead, runbooks, pairing engagements, buffer&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The two line items that dominate are the &lt;strong&gt;tool surface&lt;/strong&gt; and the &lt;strong&gt;safety story&lt;/strong&gt;. The tool surface is expensive because each tool is a small public API – it gets implemented, validated, tested, and documented, and an agent's willingness to call it depends on how well the last two are done. The safety story is expensive for the same reason auth is: it is invisible when it works and catastrophic when it does not. A proposal that lists these two as small numbers is a proposal that has not thought about write operations.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Questions to Ask a Proposal&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Ask any partner to break the build into line items matching the table above. What does "auth design complete" mean as an acceptance criterion? Is the third-party penetration test in scope or extra? Who owns the code, and from what date? Does the safety story include reversibility for every write tool, or only some? A transparent, line-itemed proposal is a real estimate. A vague lump sum is padding or guessing – and you cannot tell which until it is too late.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  In-House vs Partner and Break-Even
&lt;/h2&gt;

&lt;p&gt;The instinct is that in-house must be cheaper, and in raw dollars it is – about 60–80% of partner cost. (If the partner route wins for you, &lt;a href="https://launchdayadvisors.com/guides/how-to-select-an-ai-development-partner" rel="noopener noreferrer"&gt;how to choose an AI development partner&lt;/a&gt; covers the selection side.) Here is the same level-2 scope, staffed internally:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Component&lt;/th&gt;
&lt;th&gt;Typical cost (USD)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1 PM @ 75% × 26 weeks&lt;/td&gt;
&lt;td&gt;$50K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;1 tech lead @ 75% × 26 weeks&lt;/td&gt;
&lt;td&gt;$60K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2 senior backend engineers × 26 weeks&lt;/td&gt;
&lt;td&gt;$130K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;1 mid backend engineer × 20 weeks&lt;/td&gt;
&lt;td&gt;$50K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Designer @ 30% × 16 weeks&lt;/td&gt;
&lt;td&gt;$20K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Security engineer @ 30% × 12 weeks&lt;/td&gt;
&lt;td&gt;$15K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DevOps @ 25% × 16 weeks&lt;/td&gt;
&lt;td&gt;$15K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Technical writer @ 30% × 8 weeks&lt;/td&gt;
&lt;td&gt;$10K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Hosting + tooling&lt;/td&gt;
&lt;td&gt;$20K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Penetration test (third party)&lt;/td&gt;
&lt;td&gt;$30K&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Total&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;~$400K&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;So in-house lands near $400K against a $500K partner mid-point – a real gap of $100K in raw spend. The catch is that the gap closes, and often reverses, once opportunity cost is counted. Those four-plus engineers are not idle; they are pulled off the roadmap. If the delayed features, missed customer commitments, and slowed pipeline add up to more than ~$100K in value, the partner wins on total cost. For most growth-stage SaaS companies, they do. For more mature companies with genuine slack capacity, in-house wins.&lt;/p&gt;

&lt;p&gt;There is also a calendar-time gap the dollars hide: a partner ships in roughly six months, an in-house team running its first MCP build in seven to eight. The full build-versus-buy decision – including the hybrid models that consistently work – is the subject of &lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP build vs buy&lt;/a&gt;. The cost framing here is the input to that decision, not a substitute for it.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The False Economy&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The most expensive MCP build is the one staffed thinly to "save money." One engineer, part-time, no security review, audit log as a TODO. By month three the team has half a server. By month six the company is hiring or hiring a partner anyway, and the rework – roughly 30–50% of the in-progress code – is on top of the original spend. Picking the right path before staffing is the cheapest decision in the whole project. Picking it after is the most expensive.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Three Worked Examples
&lt;/h2&gt;

&lt;p&gt;Ranges land better against concrete shapes. Three teams, three budgets.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Small SaaS shipping a read-only Claude connector.&lt;/strong&gt; A 30-person SaaS wants its data searchable inside Claude – no writes, one client, a focused tool surface of 6–8 read tools. This is the cheapest serious ship: level-1, single client, OAuth 2.1 + PKCE + DCR, basic audit logging. Budget &lt;strong&gt;$100K–$150K&lt;/strong&gt; partner-built, one quarter of calendar time. The temptation is to add write tools "while we're in there." Resist it – that decision moves the project into the next tier.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Mid-market SaaS shipping level-2 actions to Claude and ChatGPT.&lt;/strong&gt; A 200-person SaaS wants agents to create and update records, and it wants to be in both Claude and ChatGPT at launch. That is level-2 actions across two clients. Build the first client fully ($300K–$700K), then add the second at 1.4–1.7× the single-client cost. Plan for &lt;strong&gt;$420K–$1.2M&lt;/strong&gt; and 2.5–3 quarters. Ship the strategic client first and port what works rather than abstracting across both from day one – the cross-client abstraction is what produces a server that is mediocre on every surface.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Enterprise SaaS shipping level-2 to Microsoft Copilot via AppSource.&lt;/strong&gt; A large SaaS wants actions inside Microsoft Copilot, distributed through AppSource. The build itself is level-2 single-client: &lt;strong&gt;$300K–$700K&lt;/strong&gt;. Two enterprise-specific costs sit on top. First, the AppSource review and listing process adds calendar time – plan for a 6–12 week review window, per the &lt;a href="https://launchdayadvisors.com/guides/mcp-client-comparison" rel="noopener noreferrer"&gt;MCP client comparison&lt;/a&gt;, and budget the iteration. Second, enterprise procurement will ask for &lt;a href="https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services" rel="noopener noreferrer"&gt;SOC 2&lt;/a&gt;; first-time SOC 2 Type II attestation typically runs $50K–$150K over 6–9 months, per &lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP auth and security&lt;/a&gt;. If you are not already attested, that is part of the true cost of shipping to an enterprise client.&lt;/p&gt;

&lt;h2&gt;
  
  
  Ongoing Operational Costs
&lt;/h2&gt;

&lt;p&gt;The build is a one-time number. The MCP server is not. Three recurring costs outlive the launch:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Hosting and tooling&lt;/strong&gt; – roughly $20K/year for a single-client production server, scaling with traffic and client count.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Maintenance retainer&lt;/strong&gt; – $5K–$25K/month, depending on complexity and number of clients. A good retainer covers host-client spec changes, auth-model changes, distribution-policy changes, security patches, and minor feature work. Watch for a retainer that covers nothing actionable – maintenance that is real work, not a line item.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Spec-change upkeep&lt;/strong&gt; – the host clients you ship to keep changing. New spec versions, new auth requirements, new marketplace policies. A partner whose business is MCP absorbs these across many clients; an internal team treats each as an unplanned project. This is a cost either way; the only question is whether it is amortized or absorbed.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The honest framing: an MCP server is a product with an indefinite maintenance commitment, not a project that ends at launch. Budget for the retainer from day one, because the alternative – letting the server drift out of spec until it breaks – is more expensive and worse for the buyers who came to depend on it.&lt;/p&gt;

&lt;h3&gt;
  
  
  MCP Server Pricing: Do MCP Servers Cost Money to Use?
&lt;/h3&gt;

&lt;p&gt;Most MCP servers are free to install and the protocol itself costs nothing – Anthropic open-sourced it in November 2024, and as of 2026 no major AI client has shipped a first-class paid-app billing pathway (see the &lt;a href="https://launchdayadvisors.com/guides/mcp-client-comparison" rel="noopener noreferrer"&gt;MCP client comparison&lt;/a&gt;). So "MCP server pricing" is almost never a license fee. The money lands in three other places. First, the &lt;strong&gt;underlying service&lt;/strong&gt;: the server is a thin door into a product, and that product's API is often gated to a paid plan or metered per call, so the API keys behind the server carry the real price. Second, &lt;strong&gt;tokens in the AI client&lt;/strong&gt;: every tool definition and every tool result is fed to the model as input, billed at the model provider's per-token rate on each turn – roughly $3 per million input tokens for a frontier model, per the &lt;a href="https://launchdayadvisors.com/guides/ai-implementation-cost#run-cost-token-economics-at-scale" rel="noopener noreferrer"&gt;run-cost math in the AI implementation cost guide&lt;/a&gt;. A server with thirty verbose tools taxes every conversation it is installed in, whether or not a tool is called. Third, &lt;strong&gt;hosting&lt;/strong&gt;, if the server is remote – small for a local stdio server, ~$20K/year for a production single-client server as above. If you are the vendor, the fourth cost is this guide: the build and the retainer.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Where the money goes&lt;/th&gt;
&lt;th&gt;Who pays&lt;/th&gt;
&lt;th&gt;Typical shape&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Protocol and server software&lt;/td&gt;
&lt;td&gt;Nobody&lt;/td&gt;
&lt;td&gt;Open spec; most servers open-source or bundled free&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Underlying service API&lt;/td&gt;
&lt;td&gt;The user's company&lt;/td&gt;
&lt;td&gt;Paid plan tier or per-call API metering&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Tokens in the AI client&lt;/td&gt;
&lt;td&gt;The user's model bill&lt;/td&gt;
&lt;td&gt;Per-token; tool definitions + results count as input on every turn&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Hosting (remote servers)&lt;/td&gt;
&lt;td&gt;The vendor&lt;/td&gt;
&lt;td&gt;~$20K/year for a production single-client server&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Build and maintenance&lt;/td&gt;
&lt;td&gt;The vendor&lt;/td&gt;
&lt;td&gt;$100K–$1M+ build, $5K–$25K/month retainer&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  What Drives MCP Server Cost Up or Down
&lt;/h2&gt;

&lt;p&gt;Five levers move the number more than any others. Knowing them lets you keep a build at the bottom of its range instead of the top:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Auth complexity.&lt;/strong&gt; Basic OAuth with a handful of scopes is cheap. Fine-grained scopes, enterprise SSO, and per-client auth paths are not. Fine-grained scopes cost more up front but move enterprise procurement faster – a trade-off, not waste.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tool-surface size.&lt;/strong&gt; Each tool is implemented, validated, tested, and documented. Ten well-chosen tools cost far less than thirty mediocre ones, and agents call a tight surface more reliably.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Underlying product complexity.&lt;/strong&gt; A clean, well-modeled product is cheap to expose. A tangled data model or brittle internal API means the MCP build pays to work around it – sometimes more than the server itself costs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Multi-client overhead.&lt;/strong&gt; Every additional client is a partial rebuild at 30–60% of the first ship. Shipping to one client excellently is cheaper and better than shipping to three clients adequately.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Embedding depth.&lt;/strong&gt; Read-only is cheap; actions roughly double it; agent-resident is a different category entirely. The single largest decision you make about cost is how much the server is allowed to do.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The teams that come in at the bottom of the range are not cutting corners – they are scoping deliberately: one client, a tight tool surface, the embedding level the use case actually needs, and a clean product underneath. The teams that come in at the top usually got there by abstracting across clients too early or shipping write tools without a safety story, then paying to fix both.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related Guides
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;MCP Build vs Buy: Should You Hire a Partner or Build In-House?&lt;/a&gt; – The decision this cost model feeds into&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-embed-app-ai-clients" rel="noopener noreferrer"&gt;How to Embed Your App in AI Clients with MCP&lt;/a&gt; – The complete build playbook for product leaders&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;MCP Embedding Types: Read-Only vs Actions vs Agent-Resident&lt;/a&gt; – The embedding-level decision that drives most of the cost&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;MCP Auth and Security&lt;/a&gt; – Why auth is one of the largest line items&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/mcp-client-comparison" rel="noopener noreferrer"&gt;MCP Client Comparison&lt;/a&gt; – Per-client distribution, review timelines, and monetization&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/evaluate-mcp-build-partner" rel="noopener noreferrer"&gt;How to Evaluate an MCP Build Partner&lt;/a&gt; – Pressure-testing a quote against defensible ranges&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://launchdayadvisors.com/guides/ai-implementation-cost" rel="noopener noreferrer"&gt;AI Implementation Cost: A Buyer's Cost Model&lt;/a&gt; – The broader AI budget this sits inside&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;How much does it cost to build an MCP server?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;In 2026, a partner-built MCP server costs $100K–$300K for a level-1 read-only single-client app and $300K–$700K for a level-2 actions app. A second client adds 1.4–1.7×, and a level-3 agent-resident build starts at $1M+. In-house equivalents run 60–80% of partner cost in raw spend.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How much does an MCP server cost?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The build ranges from $100K to $1M+ depending on scope. Read-only single-client sits at the bottom ($100K–$300K), actions in the middle ($300K–$700K), and agent-resident at the top ($1M+). On top of the build, plan $5K–$25K per month for ongoing maintenance.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What's the cheapest way to build an MCP server?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Level-1 read-only, a single client (usually Claude or ChatGPT), 5–10 carefully chosen tools, OAuth 2.1 + PKCE + DCR, and basic audit logging. Partner-built, that is the bottom of the range at roughly $100K–$150K. In-house with experienced staff, less in raw spend but with longer calendar time.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How much does a level-2 (actions) MCP server cost?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A level-2 actions MCP server for a single client costs $300K–$700K partner-built, with a representative mid-point around $500K. The two largest line items are the tool surface ($80K–$180K) and the safety story ($60K–$120K) – idempotency, reversibility, and intent preview for write operations.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is it cheaper to build an MCP server in-house or hire a partner?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;In-house is cheaper in raw spend – about 60–80% of partner cost – but the gap narrows once you count the opportunity cost of pulling engineers off the roadmap. If that opportunity cost exceeds ~$100K, the partner usually wins on total cost. For most growth-stage SaaS teams, it does.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How much does MCP development cost per client?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The first client carries the full build cost. Each additional client adds roughly 30–60% of the first ship – different auth, distribution, terminology, and review process per client. Two clients at level-2 typically land at 1.4–1.7× the single-client cost, or about $420K–$1.2M.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What are the ongoing costs of running an MCP server?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Hosting and tooling (roughly $20K/year), plus a maintenance retainer of $5K–$25K/month covering host-client spec changes, auth changes, distribution-policy changes, security patches, and minor feature work. The maintenance is indefinite – the clients you ship to keep changing their specs.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Do MCP servers cost money to use?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Usually not as a license fee – the protocol is open and no major AI client has first-class paid-app billing yet. The real costs are the underlying service's API plan, the tokens the AI client spends on tool definitions and results every turn, and hosting for remote servers. Vendors additionally pay to build and maintain the server.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What drives MCP server cost up?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Five things: auth complexity (fine-grained scopes, enterprise SSO), tool-surface size (more tools, more testing), the complexity of your own product, multi-client overhead (each client is a partial rebuild), and embedding depth (read-only is cheap, actions and agent-resident are not).&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://launchdayadvisors.com/guides/mcp-server-cost?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=guides" rel="noopener noreferrer"&gt;launchdayadvisors.com&lt;/a&gt;. Launch Day Advisors is a buyer-side advisory firm: we help companies select AI, software, and design partners, and we are paid only by the buyer.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>mcp</category>
      <category>ai</category>
      <category>architecture</category>
      <category>productmanagement</category>
    </item>
    <item>
      <title>AI-Native Apps Will Swallow the Web</title>
      <dc:creator>Jonathan Blessing</dc:creator>
      <pubDate>Thu, 21 May 2026 19:20:05 +0000</pubDate>
      <link>https://dev.to/launchdayadvisors/ai-native-apps-will-swallow-the-web-33p4</link>
      <guid>https://dev.to/launchdayadvisors/ai-native-apps-will-swallow-the-web-33p4</guid>
      <description>&lt;p&gt;Here is my prediction: AI-native apps will swallow the web. Not in ten years, but before 2026 is over – and the transition is already underway.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;MCP&lt;/a&gt; – the Model Context Protocol Anthropic introduced in November 2024 – has already been adopted by Google, Microsoft, and the W3C. Every major LLM speaks it. The browser vendors are integrating it directly: WebMCP is a draft at the W3C with an early implementation already shipped in Chrome. The naming is still loose – agentic apps, agent-native apps, in-chat applications – but the category is real.&lt;/p&gt;

&lt;p&gt;MCP is going to swallow the web just as the web did the desktop. AI-native apps (or whatever they come to be called) are the next web.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;MCP is going to swallow the web just as the web did the desktop.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The web we have will not vanish. It will be subsumed. Before 2026 is over, AI-native-only will be a viable path: a product that exists as MCP-callable tools and machine-readable state, with no browser, no mobile app, no human-facing surface – and a real customer base. The agents are &lt;a href="https://launchdayadvisors.com/blog/the-future-is-agents" rel="noopener noreferrer"&gt;already there&lt;/a&gt;. The protocol is in place.&lt;/p&gt;

&lt;p&gt;Users will pull this forward because the AI becomes both the access point and the source of enrichment. One conversation instead of a dozen tabs. The AI knows the sneakers, knows the cars, knows how you like to travel. Like the whole of the web, the merchant's site becomes raw material.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Like the whole of the web, the merchant's site becomes raw material.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This sounds extreme, but it is also already underway. Shopify has built a Storefront MCP for AI-mediated commerce. AI-native apps are bringing back the constraints that shaped the early web – stateless protocols, server-side logic, forms for input – for a new class of consumer.&lt;/p&gt;

&lt;p&gt;It is because of this seismic shift that &lt;a href="https://launchdayadvisors.com/services" rel="noopener noreferrer"&gt;our client work has reorganized around it&lt;/a&gt;, and it is why we just published a new cluster of MCP guides – eight pieces written for product leaders deciding whether and how to be present inside leading AI clients. We start with the &lt;a href="https://launchdayadvisors.com/guides/mcp-terminology" rel="noopener noreferrer"&gt;working vocabulary&lt;/a&gt; the category has not yet settled, lay out a &lt;a href="https://launchdayadvisors.com/guides/mcp-strategy-decision-framework" rel="noopener noreferrer"&gt;strategic decision framework&lt;/a&gt; that determines posture, set the &lt;a href="https://launchdayadvisors.com/guides/mcp-client-comparison" rel="noopener noreferrer"&gt;client comparison matrix&lt;/a&gt; for choosing where to ship first, walk through the &lt;a href="https://launchdayadvisors.com/guides/mcp-embedding-types" rel="noopener noreferrer"&gt;embedding-types breakdown&lt;/a&gt; that distinguishes read-only from actions from agent-resident, frame the &lt;a href="https://launchdayadvisors.com/guides/mcp-auth-and-security" rel="noopener noreferrer"&gt;auth and security expectations&lt;/a&gt; enterprise procurement actually wants, work the &lt;a href="https://launchdayadvisors.com/guides/mcp-build-vs-buy" rel="noopener noreferrer"&gt;build-vs-buy economics&lt;/a&gt; of in-house engineering versus a development partner, give you a &lt;a href="https://launchdayadvisors.com/guides/evaluate-mcp-build-partner" rel="noopener noreferrer"&gt;partner evaluation checklist&lt;/a&gt; for a category too young for the usual portfolio signals, and tie it together in a &lt;a href="https://launchdayadvisors.com/guides/mcp-embed-app-ai-clients" rel="noopener noreferrer"&gt;hub guide&lt;/a&gt;. The category is moving fast enough that vague advice ages quickly. These guides are specific, current, and built to be useful for the decisions our clients are making right now.&lt;/p&gt;

&lt;p&gt;AI-native apps will swallow the web.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://launchdayadvisors.com/blog/ai-native-apps-will-swallow-the-web?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog" rel="noopener noreferrer"&gt;launchdayadvisors.com&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>agents</category>
      <category>ai</category>
      <category>mcp</category>
      <category>web</category>
    </item>
    <item>
      <title>Every Day is Y2K</title>
      <dc:creator>Jonathan Blessing</dc:creator>
      <pubDate>Wed, 08 Apr 2026 16:22:27 +0000</pubDate>
      <link>https://dev.to/launchdayadvisors/every-day-is-y2k-53d2</link>
      <guid>https://dev.to/launchdayadvisors/every-day-is-y2k-53d2</guid>
      <description>&lt;p&gt;Twenty-six years later, I think we should remember Y2K —a crisis named after its deadline.&lt;/p&gt;

&lt;p&gt;My first job in New York was as the BBC's Y2K coordinator for the Americas. I spent months preparing systems for a single night. Fix the code, test and re-test the systems, and hold my breath at midnight. The sun rose the next morning and Y2K was happily forgotten.&lt;/p&gt;

&lt;p&gt;Mythos-class AI does not offer a date. It offers a condition. Thousands of zero-day vulnerabilities surfaced in weeks, with no reason to believe the rate slows. The next model will find more. The one after that, more still. There will be no midnight.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Mythos-class AI does not offer a date. It offers a condition.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Consider: Mythos found a 27-year-old zero-day in OpenBSD —the operating system built, from the ground up, by people whose entire reputation rests on not having exploitable code. It is like discovering that if you hold water just so, it explodes. If that system had a door no one found for 27 years, what is hiding in the systems that were not built with security as a founding obsession?&lt;/p&gt;

&lt;p&gt;This week, tech companies &lt;a href="https://www.nytimes.com/2026/04/07/opinion/anthropic-ai-claude-mythos.html" rel="noopener noreferrer"&gt;privately briefed the White House&lt;/a&gt; on what Mythos means for national security. The conversation is no longer theoretical.&lt;/p&gt;

&lt;p&gt;Imagine a Y2K-level event every day. We are moving into a permanent state of crisis.&lt;/p&gt;

&lt;p&gt;Most people have not yet absorbed this because they are still thinking in terms of events —a breach here, a hack there, each one reported, investigated, and forgotten. That is the old model. The new model is not a series of events. It is a climate.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The new model is not a series of events. It is a climate.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This is the new operating environment. Not a crisis to be resolved, but a tempo to be endured. We survived Y2K by treating it as an engineering problem with a deadline. The institutions that survive this will be the ones that recognize there is no deadline. The present does not end. It only compounds.&lt;/p&gt;

&lt;p&gt;The question is no longer whether the vulnerabilities exist. Mythos answered that. The question is whether the rate of discovery will outpace the rate of repair. For any system where theft is irreversible —&lt;a href="https://launchdayadvisors.com/blog/mythos-is-where-crypto-ends" rel="noopener noreferrer"&gt;crypto being the most obvious&lt;/a&gt;, but not the only one— the math is not encouraging.&lt;/p&gt;

&lt;p&gt;So much for the forecasted employment crisis. What comes instead is a permanent mobilization. The work of hardening systems, triaging vulnerabilities, and patching what each successive model discovers does not end. AI will not replace the workforce. It will redirect it —into an unending cycle of repair. The machines will not take your job. They will make sure you never finish it.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://launchdayadvisors.com/blog/every-day-is-y2k?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog" rel="noopener noreferrer"&gt;launchdayadvisors.com&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>cybersecurity</category>
      <category>discuss</category>
      <category>security</category>
    </item>
  </channel>
</rss>
