{"id":5496,"date":"2026-06-29T16:11:48","date_gmt":"2026-06-29T16:11:48","guid":{"rendered":"https:\/\/jonjones.ai\/uncategorized\/mcp-tools-solopreneur-guide-2026\/"},"modified":"2026-09-15T16:18:18","modified_gmt":"2026-09-15T16:18:18","slug":"mcp-%e5%b7%a5%e5%85%b7%e7%8d%a8%e8%b3%87%e5%89%b5%e6%a5%ad%e8%80%85%e6%8c%87%e5%8d%97-2026","status":"publish","type":"post","link":"https:\/\/jonjones.ai\/zh\/%e4%ba%ba%e5%b7%a5%e6%99%ba%e6%85%a7\/mcp-%e5%b7%a5%e5%85%b7%e7%8d%a8%e8%b3%87%e5%89%b5%e6%a5%ad%e8%80%85%e6%8c%87%e5%8d%97-2026\/","title":{"rendered":"2026 \u5e74\u7684 MCP \u5de5\u5177\uff1a\u5b83\u5011\u662f\u4ec0\u9ebc\uff0c\u5982\u4f55\u5b89\u88dd\uff0c\u4ee5\u53ca\u6211\u6bcf\u5929\u4f7f\u7528\u7684 8 \u500b\u5de5\u5177"},"content":{"rendered":"<p>Most people are still running Claude with the parking brake on. You get an AI that can think, write, and reason \u2014 but the moment it needs to touch a real system, you&#8217;re back to copy-pasting.<\/p>\n\n<p><strong>MCP tools<\/strong> remove that parking brake. They&#8217;re the callable functions an MCP server hands to your AI so it can stop describing the work and start doing it.<\/p>\n\n<p>I run 10+ autonomous brand containers inside JonOps. Every day, Claude wakes up on a cron schedule, reads the content calendar from Airtable, drafts the post, generates images, publishes to WordPress, schedules to social, and logs everything \u2014 with zero keyboard input from me. The reason that&#8217;s possible is eight MCP tools wired into my Claude Code environment.<\/p>\n\n<p>This guide is three things in one, because that&#8217;s what the question actually deserves: what MCP tools are at the protocol level, which ones are worth installing, and how to run them without shredding your context window or your security posture.<\/p>\n\n<p><strong>Updated September 2026.<\/strong> I first published this in June. Since then the spec moved to a new revision, Claude Code changed how it loads tools, and two of my original answers went from correct to flat wrong. I&#8217;ve marked both corrections in place rather than quietly deleting them \u2014 you deserve to see which claims aged badly, especially since most guides still ranking for this term were written before any of it happened.<\/p>\n\n<h2>What MCP Tools Are (And What the Spec Actually Says)<\/h2>\n<figure class=\"wp-block-image size-large\">\n  <img decoding=\"async\" src=\"https:\/\/jonjones.ai\/wp-content\/uploads\/2026\/06\/mcp-tools-what-are-they-section.jpg\" alt=\"mcp tools\" \/>\n<\/figure>\n\n<p>Let&#8217;s get the terminology right, because the framing you start with determines how useful everything after it will be.<\/p>\n\n<p><strong>MCP<\/strong> stands for Model Context Protocol \u2014 the open standard, originally from Anthropic and now maintained as a community spec, for connecting AI applications to external systems. The official docs describe it as a USB-C port for AI: one protocol, any system that ships a compatible server. It&#8217;s no longer a Claude-only story either \u2014 Claude, ChatGPT, VS Code, and Cursor all speak it.<\/p>\n\n<p>An <strong>MCP tool<\/strong> is one callable function that a server exposes. A server usually exposes several. The protocol defines three distinct things a server can offer, and conflating them is the single most common mistake I see:<\/p>\n\n<ul>\n  <li><strong>Tools<\/strong> \u2014 model-controlled callable functions with side effects. Claude decides to invoke them. Open a pull request, trigger an n8n workflow, write an Airtable record.<\/li>\n  <li><strong>Resources<\/strong> \u2014 application-controlled data the client can read. Files, records, API responses. Nobody &#8220;calls&#8221; a resource; it gets attached as context.<\/li>\n  <li><strong>Prompts<\/strong> \u2014 user-controlled templates, typically surfaced as slash commands or menu items.<\/li>\n<\/ul>\n\n<p>The distinction matters operationally: <em>tools do things, resources know things.<\/em> If you want Claude to read your database schema, that&#8217;s a resource. If you want Claude to run a migration against it, that&#8217;s a tool \u2014 and it should require confirmation.<\/p>\n\n<p>Here&#8217;s what a tool definition looks like on the wire. The server returns this from a <code>tools\/list<\/code> call:<\/p>\n\n<pre><code>{\n  \"name\": \"get_weather\",\n  \"title\": \"Weather Information Provider\",\n  \"description\": \"Get current weather information for a location\",\n  \"inputSchema\": {\n    \"type\": \"object\",\n    \"properties\": {\n      \"location\": { \"type\": \"string\", \"description\": \"City name or zip code\" }\n    },\n    \"required\": [\"location\"]\n  },\n  \"outputSchema\": {\n    \"type\": \"object\",\n    \"properties\": {\n      \"temperature\": { \"type\": \"number\" },\n      \"conditions\": { \"type\": \"string\" }\n    }\n  }\n}<\/code><\/pre>\n\n<p>That&#8217;s the whole contract: a name, a human-readable description, a JSON Schema for the input, and optionally a JSON Schema for the output. The description field is not decoration \u2014 it&#8217;s the only thing the model reads when deciding whether this tool is the right one for the job. Vague descriptions are the number one cause of &#8220;why didn&#8217;t Claude use the tool I installed.&#8221;<\/p>\n\n<p>Two details from the current spec that bite people in production:<\/p>\n\n<ul>\n  <li><strong>Tool names have rules.<\/strong> 1\u2013128 characters, case-sensitive, and only letters, digits, underscore, hyphen, and dot. No spaces, no commas. Names only need to be unique <em>within<\/em> a server.<\/li>\n  <li><strong>Collisions across servers are your problem, not the protocol&#8217;s.<\/strong> Run two servers that each expose <code>search<\/code> and you need a disambiguation strategy \u2014 the spec suggests prefixing with a server identifier. It also explicitly warns that the server&#8217;s own reported name isn&#8217;t guaranteed unique, so don&#8217;t build your prefix on that.<\/li>\n<\/ul>\n\n<p>If you&#8217;re starting from zero on the underlying concept, I wrote the foundational explainer separately: <a href=\"https:\/\/jonjones.ai\/ai\/mcp-server-meaning-solopreneur-guide-2026\/\">what an MCP server actually is<\/a>. This guide assumes you&#8217;ve got that and want to know which tools to run and how to run them safely.<\/p>\n\n<h2>How MCP Tools Work \u2014 The Wire-Level Mental Model<\/h2>\n<figure class=\"wp-block-image size-large\">\n  <img decoding=\"async\" src=\"https:\/\/jonjones.ai\/wp-content\/uploads\/2026\/06\/mcp-tools-how-they-work-section.jpg\" alt=\"mcp tools switchboard mental model for solopreneurs\" \/>\n<\/figure>\n\n<p>Picture Claude as an operator at a switchboard. Without MCP, there&#8217;s exactly one live connection: to you. You ask, it answers. You paste data, it processes. Every interaction routes through you as the relay.<\/p>\n\n<p>Install MCP tools and the board lights up. GitHub on line one. Airtable on line two. n8n on line three. A real browser on line four. When Claude needs something from one of those systems, it picks up the line itself.<\/p>\n\n<p>The actual message flow is simpler than the diagrams suggest:<\/p>\n\n<ol>\n  <li><strong>Discovery.<\/strong> The client sends <code>tools\/list<\/code>. The server returns its tool definitions.<\/li>\n  <li><strong>Selection.<\/strong> The model reads the names, descriptions, and input schemas, and picks one.<\/li>\n  <li><strong>Invocation.<\/strong> The client sends <code>tools\/call<\/code> with the tool name and arguments.<\/li>\n  <li><strong>Execution.<\/strong> The server does the real work and returns a result \u2014 text, an image, audio, a link to a resource, an embedded resource, or structured JSON validated against the tool&#8217;s <code>outputSchema<\/code>.<\/li>\n  <li><strong>Continuation.<\/strong> The model reads the result and keeps going.<\/li>\n<\/ol>\n\n<p>Two things worth internalising because they explain most weird behaviour:<\/p>\n\n<p><strong>Tool lists are not static.<\/strong> A server that declares the <code>listChanged<\/code> capability can push a notification when its tool set changes mid-session \u2014 a server that just got authenticated can suddenly expose twenty tools it was hiding. Claude Code picks these up live.<\/p>\n\n<p><strong>There is no protocol-level session.<\/strong> This surprises people. MCP has no built-in concept of &#8220;our conversation so far&#8221; on the server side. The spec&#8217;s guidance for stateful work \u2014 a shopping cart, an open browser context, a database transaction \u2014 is to return an explicit <em>handle<\/em> from a creation tool and accept it as an argument on later calls:<\/p>\n\n<pre><code>\/\/ \u2192 tools\/call\n{ \"name\": \"create_basket\", \"arguments\": {} }\n\n\/\/ \u2190 result\n{\n  \"content\": [{ \"type\": \"text\", \"text\": \"Created basket bsk_a1b2c3\" }],\n  \"structuredContent\": { \"basket_id\": \"bsk_a1b2c3\" }\n}\n\n\/\/ \u2192 tools\/call\n{ \"name\": \"add_item\", \"arguments\": { \"basket_id\": \"bsk_a1b2c3\", \"sku\": \"...\" } }<\/code><\/pre>\n\n<p>The model is responsible for carrying that handle forward. Which means: if you&#8217;re building a server, the spec&#8217;s own advice is to make handles opaque, give them a bounded lifetime, state that lifetime in the creation tool&#8217;s description, and \u2014 critically \u2014 <strong>re-validate the caller&#8217;s authorization against the handle on every single call<\/strong>. A handle is a name, not a capability. For unauthenticated servers it&#8217;s effectively a bearer token, so generate it with real entropy.<\/p>\n\n<p>What makes this powerful for a one-person business isn&#8217;t any single tool. It&#8217;s composition. GitHub plus Airtable plus n8n plus a browser means Claude can run research \u2192 write \u2192 publish \u2192 log \u2192 trigger as one autonomous session. That&#8217;s the difference between an assistant and an operator, and it&#8217;s the same principle behind every <a href=\"https:\/\/jonjones.ai\/ai\/claude-code-agents-production\/\">Claude Code agent I run in production<\/a>.<\/p>\n<h2>What Changed for MCP Tools in the 2026-07-28 Spec<\/h2>\n<figure class=\"wp-block-image size-large\">\n  <img decoding=\"async\" src=\"https:\/\/jonjones.ai\/wp-content\/uploads\/2026\/09\/mcp-tools-spec-2026-section.jpg\" alt=\"mcp tools protocol specification updates in the 2026-07-28 revision\" \/>\n<\/figure>\n\n<p>This is the section no other guide currently ranking for &#8220;mcp tools&#8221; has, and the reason is simple: they were written before it happened. The current protocol revision is <strong>2026-07-28<\/strong>. Every listicle on page one of this SERP predates it.<\/p>\n\n<p>MCP versions are dated strings in <code>YYYY-MM-DD<\/code> form, and the date marks <em>the last time backwards-incompatible changes shipped<\/em> \u2014 not the last update. Backwards-compatible improvements land continuously without bumping the number. So a dated version is a compatibility marker, not a changelog.<\/p>\n\n<p>Here&#8217;s what actually moved, and why you&#8217;d care.<\/p>\n\n<h3>Version negotiation moved from the handshake to every request<\/h3>\n\n<p>This is the big architectural one. In the handshake-based revisions \u2014 <code>2025-11-25<\/code> and earlier \u2014 client and server agreed on a protocol version once, at initialization, and lived with it. Now every request declares its own version via the <code>io.modelcontextprotocol\/protocolVersion<\/code> key in its <code>_meta<\/code> field, and the server accepts or rejects each request independently. Over Streamable HTTP the same value rides along in an <code>MCP-Protocol-Version<\/code> header.<\/p>\n\n<p>If the server can&#8217;t handle the requested version it returns an <code>UnsupportedProtocolVersionError<\/code> that lists what it <em>can<\/em> do, and the client retries or surfaces the error. Clients and servers may support multiple versions simultaneously.<\/p>\n\n<p>There&#8217;s also a new mandatory RPC, <code>server\/discover<\/code>, which returns a server&#8217;s supported protocol versions, capabilities, and identity in a single call. Calling it is optional \u2014 you&#8217;re free to fire a request and handle the version error if one comes back \u2014 but it&#8217;s there when you want to know what you&#8217;re talking to before you talk to it.<\/p>\n\n<p><strong>Why this matters to you as an operator:<\/strong> it&#8217;s a useful staleness test. Any tutorial that describes MCP version agreement as something that happens once during <code>initialize<\/code> was written before July 2026. That includes a lot of what&#8217;s currently ranking.<\/p>\n\n<h3>Tools can now ask you for input mid-call<\/h3>\n\n<p>Previously a <code>tools\/call<\/code> either succeeded or failed. Now a server MAY respond with an <strong>input-required result<\/strong> \u2014 <code>resultType: \"input_required\"<\/code> \u2014 carrying a set of <code>inputRequests<\/code> (typically an <code>elicitation\/create<\/code> form) and an opaque <code>requestState<\/code> blob. The client collects the answers from the user and retries the call with <code>inputResponses<\/code> plus that same <code>requestState<\/code>.<\/p>\n\n<pre><code>\/\/ \u2190 server needs something from the human\n{\n  \"resultType\": \"input_required\",\n  \"inputRequests\": {\n    \"github_login\": {\n      \"method\": \"elicitation\/create\",\n      \"params\": {\n        \"mode\": \"form\",\n        \"message\": \"Please provide your GitHub username\",\n        \"requestedSchema\": { \"type\": \"object\", \"properties\": { \"name\": { \"type\": \"string\" } }, \"required\": [\"name\"] }\n      }\n    }\n  },\n  \"requestState\": \"eyJsb2NhdGlvbiI6Ik5ldyBZb3JrIn0...\"\n}<\/code><\/pre>\n\n<p>One sharp edge if you&#8217;re implementing this: the JSON-RPC <code>id<\/code> <strong>must differ<\/strong> between the original request and the retry. Reuse it and you&#8217;ll spend an afternoon debugging.<\/p>\n\n<p>Practically, this is what lets a tool ask &#8220;which account?&#8221; or &#8220;confirm the destination branch?&#8221; without the server author faking it through error strings. For anyone running unattended agents, it&#8217;s also a new failure mode to plan for: a tool that blocks on human input will stall a cron run. In JonOps I keep elicitation-capable tools out of the fully autonomous skills and reserve them for interactive sessions.<\/p>\n\n<h3>Tool parameters can be mirrored into HTTP headers<\/h3>\n\n<p>The <code>x-mcp-header<\/code> extension property lets a server designate specific tool parameters to be copied into HTTP headers on the Streamable HTTP transport, arriving as <code>Mcp-Param-{name}<\/code>. The point is infrastructure: load balancers, proxies, and WAFs can route and filter on a parameter value without parsing the JSON body.<\/p>\n\n<p>This is a &#8220;you&#8217;ll know when you need it&#8221; feature \u2014 it exists for teams putting MCP traffic behind real network infrastructure. But it&#8217;s a strong signal about where the protocol is heading: MCP is being built for production topologies, not just laptops.<\/p>\n\n<h3>Deprecation now has a published contract<\/h3>\n\n<p>Features can be marked Deprecated under a formal feature-lifecycle policy. A deprecated feature stays in the spec for <strong>at least twelve months<\/strong> \u2014 or at least ninety days under an expedited-removal exception \u2014 and has to document a migration path before it becomes eligible for removal. There&#8217;s a public registry of currently-deprecated features.<\/p>\n\n<p>For anyone building on MCP commercially, this is the most underrated change in the release. It converts &#8220;will this break?&#8221; from a vibe into a schedule.<\/p>\n\n\n<style>#kt-layout-idsignup_mid_mcp2026 > .kt-row-column-wrap{align-content:start;}:where(#kt-layout-idsignup_mid_mcp2026 > .kt-row-column-wrap) > .wp-block-kadence-column{justify-content:start;}#kt-layout-idsignup_mid_mcp2026 > .kt-row-column-wrap{column-gap:var(--global-kb-gap-md, 2rem);row-gap:var(--global-kb-gap-md, 2rem);padding-top:var( --global-kb-row-default-top, 25px );padding-bottom:var( --global-kb-row-default-bottom, 25px );padding-top:30px;padding-right:30px;padding-bottom:30px;padding-left:30px;grid-template-columns:repeat(2, minmax(0, 1fr));}#kt-layout-idsignup_mid_mcp2026{border-top-left-radius:16px;border-top-right-radius:16px;border-bottom-right-radius:16px;border-bottom-left-radius:16px;overflow:clip;isolation:isolate;}#kt-layout-idsignup_mid_mcp2026 > .kt-row-layout-overlay{border-top-left-radius:16px;border-top-right-radius:16px;border-bottom-right-radius:16px;border-bottom-left-radius:16px;}#kt-layout-idsignup_mid_mcp2026{background-color:#f0f0f0;}#kt-layout-idsignup_mid_mcp2026 > .kt-row-layout-overlay{opacity:0.30;}@media all and (max-width: 1024px){#kt-layout-idsignup_mid_mcp2026 > .kt-row-column-wrap{grid-template-columns:minmax(0, 1fr);}}@media all and (max-width: 767px){#kt-layout-idsignup_mid_mcp2026 > .kt-row-column-wrap{grid-template-columns:repeat(2, minmax(0, 1fr));}}<\/style>\n<div class=\"wp-block-kadence-rowlayout alignnone\">\n<style>.kadence-columnsignup_img_mid_mcp2026 > .kt-inside-inner-col{border-top-width:0px;border-right-width:0px;border-bottom-width:0px;border-left-width:0px;}.kadence-columnsignup_img_mid_mcp2026 > .kt-inside-inner-col,.kadence-columnsignup_img_mid_mcp2026 > .kt-inside-inner-col:before{border-top-left-radius:0px;border-top-right-radius:0px;border-bottom-right-radius:0px;border-bottom-left-radius:0px;}.kadence-columnsignup_img_mid_mcp2026 > .kt-inside-inner-col{column-gap:var(--global-kb-gap-sm, 1rem);}.kadence-columnsignup_img_mid_mcp2026 > .kt-inside-inner-col{flex-direction:column;}.kadence-columnsignup_img_mid_mcp2026 > .kt-inside-inner-col > .aligncenter{width:100%;}.kadence-columnsignup_img_mid_mcp2026 > .kt-inside-inner-col:before{opacity:0.3;}.kadence-columnsignup_img_mid_mcp2026{position:relative;}@media all and (max-width: 1024px){.kadence-columnsignup_img_mid_mcp2026 > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}@media all and (max-width: 767px){.kadence-columnsignup_img_mid_mcp2026 > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}<\/style>\n<div class=\"wp-block-kadence-column inner-column-1\"><div class=\"kt-inside-inner-col\">\n\n<figure class=\"wp-block-image size-medium\">\n  <img decoding=\"async\" src=\"https:\/\/jonjones.ai\/wp-content\/uploads\/2026\/06\/newsletter-cta-ai-playbook.jpg\" alt=\"Join the JonOps AI Playbook newsletter\" \/>\n<\/figure>\n\n<\/div><\/div>\n\n<style>.kadence-columnsignup_txt_mid_mcp2026 > .kt-inside-inner-col{border-top-width:0px;border-right-width:0px;border-bottom-width:0px;border-left-width:0px;}.kadence-columnsignup_txt_mid_mcp2026 > .kt-inside-inner-col,.kadence-columnsignup_txt_mid_mcp2026 > .kt-inside-inner-col:before{border-top-left-radius:0px;border-top-right-radius:0px;border-bottom-right-radius:0px;border-bottom-left-radius:0px;}.kadence-columnsignup_txt_mid_mcp2026 > .kt-inside-inner-col{column-gap:var(--global-kb-gap-sm, 1rem);}.kadence-columnsignup_txt_mid_mcp2026 > .kt-inside-inner-col{flex-direction:column;}.kadence-columnsignup_txt_mid_mcp2026 > .kt-inside-inner-col > .aligncenter{width:100%;}.kadence-columnsignup_txt_mid_mcp2026 > .kt-inside-inner-col:before{opacity:0.3;}.kadence-columnsignup_txt_mid_mcp2026{position:relative;}@media all and (max-width: 1024px){.kadence-columnsignup_txt_mid_mcp2026 > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}@media all and (max-width: 767px){.kadence-columnsignup_txt_mid_mcp2026 > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}<\/style>\n<div class=\"wp-block-kadence-column inner-column-2\"><div class=\"kt-inside-inner-col\">\n\n<h3 class=\"wp-block-heading has-text-color\" style=\"color:#1e1b3a\">Lead Magnet AI Playbook<\/h3>\n\n\n<p class=\"has-text-color\" style=\"color:#4a4568\">Get the AI automation playbook Jon uses to run 10+ autonomous brands \u2014 real systems, real receipts, weekly in your inbox.<\/p>\n\n<div class='fluentform ff-default fluentform_wrapper_8 ffs_default_wrap'><form data-form_id=\"8\" id=\"fluentform_8\" class=\"frm-fluent-form fluent_form_8 ff-el-form-top ff_form_instance_8_1 ff-form-loading ffs_default\" data-form_instance=\"ff_form_instance_8_1\" method=\"POST\" ><fieldset  style=\"border: none!important;margin: 0!important;padding: 0!important;background-color: transparent!important;box-shadow: none!important;outline: none!important; min-inline-size: 100%;\">\n                    <legend class=\"ff_screen_reader_title\" style=\"display: block; margin: 0!important;padding: 0!important;height: 0!important;text-indent: -999999px;width: 0!important;overflow:hidden;\">Lead Magnet - AI Playbook<\/legend><input type='hidden' name='__fluent_form_embded_post_id' value='5496' \/><input type=\"hidden\" id=\"_fluentform_8_fluentformnonce\" name=\"_fluentform_8_fluentformnonce\" value=\"887da9fad1\" \/><input type=\"hidden\" name=\"_wp_http_referer\" value=\"\/zh\/wp-json\/wp\/v2\/posts\/5496\" \/><div class='ff-el-group'><div class='ff-el-input--content'><input type=\"email\" name=\"email\" id=\"ff_8_email\" class=\"ff-el-form-control\" placeholder=\"Your email address\" data-name=\"email\"  aria-invalid=\"false\" aria-required=true><\/div><\/div><div class='ff-el-group ff-text-left ff_submit_btn_wrapper ff_submit_btn_wrapper_custom'><button class=\"ff-btn ff-btn-submit ff-btn-md ff_btn_style wpf_has_custom_css\" type=\"submit\" name=\"custom_submit_button-8_1\" data-name=\"custom_submit_button-8_1\"  aria-label=\"GET THE PLAYBOOK\">GET THE PLAYBOOK<\/button><style>form.fluent_form_8 .wpf_has_custom_css.ff-btn-submit { background-color:#00ff88;border-color:#00ff88;color:#0a0a14;min-width:100%; }form.fluent_form_8 .wpf_has_custom_css.ff-btn-submit:hover { background-color:#00cc6a;border-color:#00cc6a;color:#0a0a14;min-width:100%; } <\/style><\/div><\/fieldset><\/form><div id='fluentform_8_errors' class='ff-errors-in-stack ff_form_instance_8_1 ff-form-loading_errors ff_form_instance_8_1_errors'><\/div><\/div>            <script type=\"text\/javascript\">\n                window.fluent_form_ff_form_instance_8_1 = {\"id\":\"8\",\"settings\":{\"layout\":{\"labelPlacement\":\"top\",\"helpMessagePlacement\":\"with_label\",\"errorMessagePlacement\":\"inline\",\"asteriskPlacement\":\"asterisk-right\"},\"restrictions\":{\"denyEmptySubmission\":{\"enabled\":false}}},\"form_instance\":\"ff_form_instance_8_1\",\"form_id_selector\":\"fluentform_8\",\"rules\":{\"email\":{\"required\":{\"value\":true,\"message\":\"This field is required\"},\"email\":{\"value\":true,\"message\":\"Please enter a valid email address\"}}},\"debounce_time\":300};\n                            <\/script>\n            \n\n<\/div><\/div>\n\n<\/div>\n\n\n<h2>The 8 MCP Tools Running Inside JonOps Right Now<\/h2>\n<figure class=\"wp-block-image size-large\">\n  <img decoding=\"async\" src=\"https:\/\/jonjones.ai\/wp-content\/uploads\/2026\/06\/mcp-tools-jonops-stack-section.jpg\" alt=\"mcp tools stack showing 8 integrations running in JonOps\" \/>\n<\/figure>\n\n<p>Here&#8217;s my actual operating stack of MCP tools. Not a roundup of what&#8217;s popular \u2014 the servers that are installed and firing inside the JonOps container, today. For each one: what it does, what it unlocks in practice, and whether you should bother.<\/p>\n\n<h3>1. GitHub MCP Server<\/h3>\n<p><strong>What it does:<\/strong> Direct access to your repositories \u2014 read files and directories, create branches, open pull requests, post reviews, manage issues, check history, push changes.<\/p>\n<p><strong>In JonOps:<\/strong> When I&#8217;m building or debugging a skill, Claude opens the codebase, finds the relevant files, makes the edits, opens a PR, and posts a review summary. No copy-pasting between editor and chat. Claude <em>is<\/em> the editor for autonomous tasks.<\/p>\n<p><strong>Install it if:<\/strong> You build anything with code \u2014 even if you don&#8217;t write it yourself. Full setup walkthrough: <a href=\"https:\/\/jonjones.ai\/ai\/github-mcp-server-guide-2026\/\">GitHub MCP Server guide<\/a>.<\/p>\n\n<h3>2. Playwright MCP Server<\/h3>\n<p><strong>What it does:<\/strong> Gives Claude a real browser. Navigate, click, fill forms, screenshot, extract content from JavaScript-rendered pages that plain HTTP can&#8217;t reach.<\/p>\n<p><strong>In JonOps:<\/strong> SERP research and competitor monitoring on pages that block simple scrapers \u2014 and post-publish verification. Claude opens the live URL and confirms the page rendered before marking the job done. That verification step has caught more silent failures than every log line I&#8217;ve ever written.<\/p>\n<p><strong>Install it if:<\/strong> You need Claude to touch the web beyond API calls. Details: <a href=\"https:\/\/jonjones.ai\/ai\/playwright-mcp-server-guide-2026\/\">Playwright MCP Server guide<\/a>.<\/p>\n\n<h3>3. Filesystem MCP Server<\/h3>\n<p><strong>What it does:<\/strong> Read and write files on your machine or inside a container, scoped to configured paths.<\/p>\n<p><strong>In JonOps:<\/strong> Every skill file, generated image, log, and config passes through it. When the blog-writer skill runs, Claude reads the skill markdown, executes each step, writes intermediates, and logs results \u2014 all through this server. It&#8217;s the spine of container-based autonomy.<\/p>\n<p><strong>Install it if:<\/strong> You&#8217;re running Claude Code locally or on a server. Table stakes. Install it first, and scope the path tightly.<\/p>\n\n<h3>4. Fetch MCP Server<\/h3>\n<p><strong>What it does:<\/strong> Arbitrary HTTP requests \u2014 GET, POST, PATCH, DELETE \u2014 to any API, with the response returned into context.<\/p>\n<p><strong>In JonOps:<\/strong> The catch-all for every API without a dedicated server. Metricool scheduling, Sendy sends, Telegram alerts, DataForSEO queries, WordPress REST calls. Highest raw call volume in my entire stack, by a wide margin.<\/p>\n<p><strong>Install it if:<\/strong> You use any REST API that doesn&#8217;t have its own server. Which is most of them.<\/p>\n\n<h3>5. n8n MCP<\/h3>\n<p><strong>What it does:<\/strong> Connects Claude to your n8n instance \u2014 list workflows, read definitions, trigger executions, check logs, enable and disable workflows.<\/p>\n<p><strong>In JonOps:<\/strong> n8n handles newsletter routing, lead distribution, and third-party sync. When a content pipeline finishes and should kick off a send, Claude triggers n8n directly instead of waiting on a timer. Claude becomes the trigger layer rather than a node inside it.<\/p>\n<p><strong>Install it if:<\/strong> You run n8n and want Claude deciding when things fire. Full integration guide: <a href=\"https:\/\/jonjones.ai\/automation\/n8n-mcp-claude-agents-workflow-guide-2026\/\">n8n MCP for solopreneurs<\/a>.<\/p>\n\n<h3>6. Airtable MCP<\/h3>\n<p><strong>What it does:<\/strong> Read\/write access to your bases \u2014 filter formulas, record creation, field updates, linked-table lookups.<\/p>\n<p><strong>In JonOps:<\/strong> Airtable is the source of truth for everything: content calendar, keyword queue, published posts, social queue, outreach leads, newsletter queue, image log. Every skill reads from it and writes back to it. Without this, Claude would be blind to what&#8217;s queued and unable to record what it finished. This is why JonOps has continuity across runs.<\/p>\n<p><strong>Install it if:<\/strong> Airtable is in your workflow. One caution from experience \u2014 paginated endpoints lie to agents that don&#8217;t turn the page. If a query returns exactly 100 rows, that&#8217;s a page cap, not a total.<\/p>\n\n<h3>7. Slack MCP Server<\/h3>\n<p><strong>What it does:<\/strong> Post messages, create channels, read history, mention users, react.<\/p>\n<p><strong>In JonOps:<\/strong> End-of-run notifications, error alerts, status summaries. Telegram handles my mobile push; Slack is the team-facing audit trail a VA or collaborator can scroll.<\/p>\n<p><strong>Install it if:<\/strong> You use Slack, or you want a shared channel where Claude reports outcomes and escalates the things a human has to decide.<\/p>\n\n<h3>8. Memory MCP Server<\/h3>\n<p><strong>What it does:<\/strong> Persistent storage across sessions. Store facts, decisions, project context, preferences; retrieve them next time without re-explaining.<\/p>\n<p><strong>In JonOps:<\/strong> This is what turns a stateless model into an operator. Every cron run loads brand config, recent posts, what&#8217;s published, what&#8217;s queued, what went wrong last time. Without it, every run starts cold and repeats yesterday&#8217;s mistakes. With it, the fleet compounds.<\/p>\n<p><strong>Install it if:<\/strong> You run anything recurring. If you only add one tool beyond the core three, make it this one.<\/p>\n<h2>Where to Find MCP Tools (And How to Vet One Before You Install It)<\/h2>\n<figure class=\"wp-block-image size-large\">\n  <img decoding=\"async\" src=\"https:\/\/jonjones.ai\/wp-content\/uploads\/2026\/09\/mcp-tools-registry-vetting-section.jpg\" alt=\"finding and vetting mcp tools before installing them\" \/>\n<\/figure>\n\n<p>There are three places to go looking for MCP tools, in descending order of how much I trust them.<\/p>\n\n<p><strong>1. The official MCP registry.<\/strong> There&#8217;s now a canonical registry at <code>registry.modelcontextprotocol.io<\/code> with a public API. Every entry carries official metadata \u2014 a status, a published date, a last-updated timestamp \u2014 alongside the server&#8217;s declared name, version, and remote endpoints. That provenance is the whole value. A community list tells you a server exists; the registry tells you who published it and whether the listing is still active.<\/p>\n\n<p>I paginated that API while writing this section, because I wanted a real number instead of a repeated one. <strong>I stopped counting at 40,000 entries and had still not reached the end of the cursor<\/strong> \u2014 39,377 of those 40,000 carried an <code>active<\/code> status. So treat 40,000 as a floor, not a total. The relevant point isn&#8217;t the figure anyway: it&#8217;s that &#8220;there&#8217;s an MCP server for that&#8221; is now true by default, and the scarce resource has flipped from availability to judgement.<\/p>\n\n<p><strong>2. Community directories.<\/strong> <a href=\"https:\/\/mcpservers.org\" target=\"_blank\" rel=\"noopener\">mcpservers.org<\/a> and <a href=\"https:\/\/mcp.so\" target=\"_blank\" rel=\"noopener\">mcp.so<\/a> are both large, browsable, and organised by category \u2014 development, database, search, file system, communication, memory. Better for discovery than the registry, weaker on provenance. Use them to find candidates, then verify elsewhere.<\/p>\n\n<p><strong>3. The vendor&#8217;s own docs.<\/strong> If you want the Notion server, the Notion docs are the source of truth for its URL and auth flow. First-party servers are the safest category on the board.<\/p>\n\n<h3>The five-minute vetting checklist<\/h3>\n\n<p>Installing MCP tools means handing a third party a credential and letting your AI call its code. That deserves five minutes. Mine:<\/p>\n\n<ul>\n  <li><strong>Who publishes it?<\/strong> First-party vendor server, official registry entry, or a random GitHub account with eleven stars? These are not the same risk.<\/li>\n  <li><strong>Remote or local?<\/strong> A remote HTTP server means your arguments travel to someone else&#8217;s infrastructure. A local stdio server runs on your machine and can only leak what you give it. For anything touching sensitive data, prefer local.<\/li>\n  <li><strong>What&#8217;s the narrowest credential that works?<\/strong> Not &#8220;does it need write access&#8221; \u2014 &#8220;can I give it a token scoped to one repo, one base, one channel.&#8221; Almost always yes, and almost nobody does it.<\/li>\n  <li><strong>Read the tool descriptions before you trust them.<\/strong> The spec is blunt on this point: clients <strong>MUST<\/strong> treat tool annotations as untrusted unless they come from a trusted server. A tool&#8217;s own description of itself is a claim, not a guarantee.<\/li>\n  <li><strong>Does it need to be on all the time?<\/strong> Most don&#8217;t. Scope it to the one project that needs it.<\/li>\n<\/ul>\n\n<p>The failure mode nobody warns you about isn&#8217;t a malicious server \u2014 it&#8217;s an over-permissioned honest one. A read-write token handed to a tool that only ever reads is a bad trade you make once and forget about for a year.<\/p>\n\n<h2>How to Install MCP Tools in Claude Code (2026 Commands)<\/h2>\n<figure class=\"wp-block-image size-large\">\n  <img decoding=\"async\" src=\"https:\/\/jonjones.ai\/wp-content\/uploads\/2026\/06\/mcp-tools-installation-section.jpg\" alt=\"installing mcp tools in Claude Code terminal configuration\" \/>\n<\/figure>\n\n<p><strong>Correction from the June version of this guide:<\/strong> I originally walked you through hand-editing <code>claude_desktop_config.json<\/code>. That still works, but it&#8217;s no longer the path I&#8217;d point anyone at. Claude Code has a proper CLI for this, and it handles the JSON, the scope, and the auth flow for you.<\/p>\n\n<p><strong>Remote HTTP server<\/strong> \u2014 the recommended option for cloud services:<\/p>\n\n<pre><code># Basic syntax\nclaude mcp add --transport http &lt;name&gt; &lt;url&gt;\n\n# Real example\nclaude mcp add --transport http notion https:\/\/mcp.notion.com\/mcp\n\n# With a bearer token\nclaude mcp add --transport http secure-api https:\/\/api.example.com\/mcp \\\n  --header \"Authorization: Bearer your-token\"<\/code><\/pre>\n\n<p><strong>Local stdio server<\/strong> \u2014 for anything that needs direct system access:<\/p>\n\n<pre><code>claude mcp add --transport stdio &lt;name&gt; -- &lt;command&gt; [args...]<\/code><\/pre>\n\n<p>A note on SSE: that transport is deprecated. Some services still only expose an SSE endpoint, but on current Claude Code you add them with the same <code>--transport http<\/code> command \u2014 it tries HTTP first and falls back to SSE automatically. Only reach for <code>--transport sse<\/code> explicitly on older versions.<\/p>\n\n<h3>Pick the right scope \u2014 this is the part people get wrong<\/h3>\n\n<p>MCP tools install at one of three scopes, and the choice controls both which projects see the tool and whether your credentials end up in version control:<\/p>\n\n<table>\n<thead><tr><th>Scope<\/th><th>Loads in<\/th><th>Shared with team<\/th><th>Stored in<\/th><\/tr><\/thead>\n<tbody>\n<tr><td><strong>Local<\/strong> (default)<\/td><td>Current project only<\/td><td>No<\/td><td><code>~\/.claude.json<\/code><\/td><\/tr>\n<tr><td><strong>Project<\/strong><\/td><td>Current project only<\/td><td>Yes, via version control<\/td><td><code>.mcp.json<\/code> in project root<\/td><\/tr>\n<tr><td><strong>User<\/strong><\/td><td>All your projects<\/td><td>No<\/td><td><code>~\/.claude.json<\/code><\/td><\/tr>\n<\/tbody>\n<\/table>\n\n<p>Rule of thumb: <strong>project scope for the server, never for the secret.<\/strong> Commit the <code>.mcp.json<\/code> that tells your team which servers the project uses; keep the credentials in environment variables that <code>.mcp.json<\/code> expands at runtime. Local scope is the default and the right home for anything experimental or personal.<\/p>\n\n<h3>Two gotchas worth knowing before they cost you an hour<\/h3>\n\n<ul>\n  <li><strong>A JSON entry with a <code>url<\/code> but no <code>type<\/code> is a configuration error.<\/strong> Claude Code reads a typeless entry as a stdio server, skips it, and tells you to add <code>\"type\": \"http\"<\/code>. If you&#8217;re pasting config from someone&#8217;s README, check for that field first. (The spec calls this transport <code>streamable-http<\/code>; Claude Code accepts that as an alias for <code>http<\/code>, so copied config works unmodified.)<\/li>\n  <li><strong><code>npx<\/code>-based servers need Node.js in the environment.<\/strong> Desktop usually finds it. Containers often don&#8217;t. In JonOps I pre-install server packages globally at image build time rather than letting <code>npx<\/code> cold-start on every cron run \u2014 that alone cut tens of seconds off each execution.<\/li>\n<\/ul>\n\n<p>Verify any install by running <code>\/mcp<\/code> in a Claude Code session. You&#8217;ll get every registered server, its connection state, and its tools.<\/p>\n\n<p><strong>Second correction, and this one&#8217;s a bigger deal.<\/strong> In June I wrote that you couldn&#8217;t use custom MCP servers with Claude on the web. That&#8217;s no longer true. Servers you add as <strong>connectors<\/strong> at <code>claude.ai\/customize\/connectors<\/code> now flow automatically into Claude Code when you&#8217;re signed in with a claude.ai account \u2014 they show up in <code>\/mcp<\/code> marked as coming from claude.ai. One caveat that matters for headless setups like mine: connectors are only fetched when a claude.ai subscription login is your active auth method. If <code>ANTHROPIC_API_KEY<\/code> is set, or you&#8217;re routed through Bedrock or Google Cloud, they won&#8217;t load at all.<\/p>\n\n<p>For the full walkthrough including environment-variable management and container-specific traps: <a href=\"https:\/\/jonjones.ai\/ai\/claude-code-mcp-guide-2026\/\">the Claude Code MCP setup guide<\/a>.<\/p>\n\n<h2>How Many MCP Tools Can You Run? (I Got This Wrong in June)<\/h2>\n<figure class=\"wp-block-image size-large\">\n  <img decoding=\"async\" src=\"https:\/\/jonjones.ai\/wp-content\/uploads\/2026\/09\/mcp-tools-tool-search-section.jpg\" alt=\"how many mcp tools you can run with tool search enabled\" \/>\n<\/figure>\n\n<p>Here&#8217;s the claim I need to retract.<\/p>\n\n<p>In June I wrote that every registered server adds its tool descriptions to Claude&#8217;s context window, so the practical ceiling was somewhere around 8\u201312 servers before you started eating the space your actual work needs. That was accurate when I wrote it. It isn&#8217;t anymore.<\/p>\n\n<p>Claude Code now ships <strong>tool search<\/strong>, and it&#8217;s on by default. Instead of loading every tool definition at session start, it loads only tool <em>names<\/em> plus each server&#8217;s instructions, and pulls the full definitions on demand when Claude actually needs them. Anthropic&#8217;s own documentation puts it plainly: adding more MCP servers has minimal impact on your context window, and there&#8217;s no fixed per-server tool cap \u2014 the practical limit is your context budget.<\/p>\n\n<p>So the honest 2026 answer to &#8220;how many MCP tools can I run&#8221; is: <strong>more than you think, and the number is no longer the interesting question.<\/strong><\/p>\n\n<p>What replaces it is selection quality \u2014 which MCP tools you run, not how many. A few things that actually still matter:<\/p>\n\n<ul>\n  <li><strong>Tool search needs a model that supports <code>tool_reference<\/code> blocks<\/strong> \u2014 Sonnet 4.5, Haiku 4.5, Opus 4.5, and later. On older models you&#8217;re back to upfront loading and the old ceiling applies.<\/li>\n  <li><strong>It gets disabled in some environments.<\/strong> Point <code>ANTHROPIC_BASE_URL<\/code> at a non-first-party host and Claude Code turns tool search off, because most proxies don&#8217;t forward <code>tool_reference<\/code> blocks. If you run through a gateway, check this before assuming you have headroom.<\/li>\n  <li><strong>Server instructions became load-bearing.<\/strong> With definitions deferred, the server&#8217;s instruction text is how Claude decides whether to go looking for your tools at all. If you&#8217;re publishing a server, say what category of work your tools handle and when Claude should search for them. Descriptions and instructions truncate at 2KB each, so front-load the important part.<\/li>\n  <li><strong>More tools still means more ways to pick the wrong one.<\/strong> Context pressure was never the only cost. Twenty overlapping tools with vague descriptions produce a model that hesitates, and hesitation in an unattended cron run looks like a hang.<\/li>\n<\/ul>\n\n<p>My stack sat at eight for months because eight was what the work needed \u2014 not because I was rationing context. That reasoning happened to survive the change. The number I published did not, and I&#8217;d rather show you the correction than let a stale ceiling talk you out of a tool you need.<\/p>\n<h2>Which MCP Tools Do You Actually Need? (Matched to Your Business Type)<\/h2>\n<figure class=\"wp-block-image size-large\">\n  <img decoding=\"async\" src=\"https:\/\/jonjones.ai\/wp-content\/uploads\/2026\/06\/mcp-tools-use-cases-section.jpg\" alt=\"mcp tools use cases for different solopreneur business types\" \/>\n<\/figure>\n\n<p>Now that context pressure isn&#8217;t the constraint, the temptation is to install every MCP tool on the board. Don&#8217;t. Every tool you add is a credential you&#8217;re responsible for and a decision surface the model has to navigate. Here&#8217;s how I&#8217;d sequence it by business type.<\/p>\n\n<p><strong>Content creators (bloggers, newsletter writers, course builders):<\/strong><br>\nStart with <strong>Filesystem + Airtable + Fetch<\/strong>. Filesystem is where your drafts live. Airtable is your editorial queue. Fetch covers every API without a dedicated server. Add Playwright when you want real-browser competitive research.<\/p>\n\n<p><strong>Software builders and developers:<\/strong><br>\nStart with <strong>GitHub + Filesystem + Fetch<\/strong>. GitHub MCP is the one that turns Claude Code from a coding assistant into something that opens PRs and manages issues. Add Playwright for automated testing.<\/p>\n\n<p><strong>Service businesses and consultants:<\/strong><br>\nStart with <strong>Airtable + Slack + Fetch + Memory<\/strong>. Airtable holds the client pipeline, Slack handles comms, Fetch reaches your CRM and billing. Memory is the one people skip and shouldn&#8217;t \u2014 you want Claude holding each client&#8217;s context between sessions instead of relearning it every time.<\/p>\n\n<p><strong>Automation operators (the JonOps model):<\/strong><br>\nYou&#8217;ll end up with all eight. Add them in this order: Filesystem \u2192 Fetch \u2192 Airtable \u2192 GitHub \u2192 n8n \u2192 Memory \u2192 Playwright \u2192 Slack. Data layer, then action layer, then orchestration, then monitoring. Each addition should retire a specific place where you&#8217;re still the one clicking.<\/p>\n\n<blockquote>\n  <p><strong>The honest 80\/20:<\/strong> Filesystem + Airtable + Fetch covers most solopreneur use cases. Those three alone let Claude manage your content, your data, and your API calls. Everything after that is deliberate leverage, not completeness.<\/p>\n<\/blockquote>\n\n<p>The selection rule hasn&#8217;t changed and I don&#8217;t expect it to: <strong>follow the friction.<\/strong> Don&#8217;t install speculatively. Install when you catch yourself thinking &#8220;I wish Claude could just push this&#8221; \u2014 then install the server that removes exactly that step. If you want to see where this ends up, I documented the full picture in <a href=\"https:\/\/jonjones.ai\/business\/fully-autonomous-ai-agent\/\">what it actually takes to run a fully autonomous AI agent<\/a>.<\/p>\n\n<h2>MCP Tools Security: What the Listicles Leave Out<\/h2>\n<figure class=\"wp-block-image size-large\">\n  <img decoding=\"async\" src=\"https:\/\/jonjones.ai\/wp-content\/uploads\/2026\/09\/mcp-tools-security-section.jpg\" alt=\"mcp tools security considerations for autonomous agents\" \/>\n<\/figure>\n\n<p>Every roundup tells you which MCP tools to install. Almost none tell you what you&#8217;re accepting when you do. The spec itself is explicit, so let&#8217;s just read it.<\/p>\n\n<p><strong>What a server is required to do:<\/strong> validate all tool inputs, implement proper access controls, rate limit invocations, and sanitize outputs. Those are MUSTs. If you&#8217;re building a server, that&#8217;s your floor, not your aspiration.<\/p>\n\n<p><strong>What a client should do<\/strong> \u2014 and this is the list to hold your setup against:<\/p>\n\n<ul>\n  <li>Prompt for user confirmation on sensitive operations<\/li>\n  <li><strong>Show tool inputs to the user before calling the server<\/strong>, specifically to prevent malicious or accidental data exfiltration<\/li>\n  <li>Validate tool results before passing them to the model<\/li>\n  <li>Implement timeouts on tool calls<\/li>\n  <li>Log tool usage for audit purposes<\/li>\n<\/ul>\n\n<p>Read the second one again, because it&#8217;s the one that should change your behaviour. The risk isn&#8217;t only that a tool does something bad \u2014 it&#8217;s that a tool <em>receives<\/em> something it shouldn&#8217;t. Arguments get composed by a model that has your whole session in context. A remote server sees whatever ends up in those arguments. That&#8217;s an exfiltration path, and it&#8217;s silent.<\/p>\n\n<p>Three operator habits that fall out of this:<\/p>\n\n<ul>\n  <li><strong>Scope every credential to the narrowest thing that works.<\/strong> GitHub MCP can be limited to specific repositories. Airtable can be limited to one base. Start read-only, confirm the behaviour you expected, then widen. The default is almost always broader than the job.<\/li>\n  <li><strong>Treat tool metadata as untrusted input.<\/strong> The spec says clients MUST consider tool annotations untrusted unless the server is trusted. A tool that describes itself as read-only is making a claim about itself. Verify with a scoped credential rather than a hopeful one.<\/li>\n  <li><strong>Log everything, and check the log.<\/strong> Unattended agents fail quietly. Audit logging is in the spec&#8217;s client guidance for a reason \u2014 it&#8217;s the only way you find out that a tool has been failing for six days. My own rule after a few painful lessons: <a href=\"https:\/\/jonjones.ai\/ai\/claude-code-subagents\/\">every autonomous run writes a structured result line<\/a>, success or failure, no exceptions.<\/li>\n<\/ul>\n\n<p>None of this makes MCP tools dangerous to use. It makes them infrastructure, which is exactly how you should treat anything holding a credential to your business.<\/p>\n\n<h2>Frequently Asked Questions About MCP Tools<\/h2>\n<figure class=\"wp-block-image size-large\">\n  <img decoding=\"async\" src=\"https:\/\/jonjones.ai\/wp-content\/uploads\/2026\/06\/mcp-tools-faq-section.jpg\" alt=\"mcp tools frequently asked questions answered for solopreneurs\" \/>\n<\/figure>\n\n<p><strong>What&#8217;s the difference between MCP tools, resources, and prompts?<\/strong><br>\nTools are model-controlled functions with side effects \u2014 Claude decides to call them. Resources are application-controlled data the client reads and attaches as context. Prompts are user-controlled templates, usually surfaced as slash commands. Shortest version: tools do things, resources know things, prompts start things.<\/p>\n\n<p><strong>Do I need to be a developer to use MCP tools?<\/strong><br>\nNo. Installing one is a single <code>claude mcp add<\/code> command, or a few clicks if you&#8217;re adding a connector in claude.ai. Getting the API credential for the underlying service is usually the longest step, and it&#8217;s a five-minute job for most services.<\/p>\n\n<p><strong>Are MCP tools safe? Can they delete my data?<\/strong><br>\nThey operate with exactly the permissions you grant. A read-write Airtable key means Claude can write to Airtable. A read-only key means it can&#8217;t. Start narrow, verify, then expand \u2014 and keep in mind the spec&#8217;s own advice that clients should show you tool inputs before a call and confirm sensitive operations.<\/p>\n\n<p><strong>Can I use MCP tools with Claude on the web?<\/strong><br>\nYes \u2014 this changed since the first version of this guide. Servers added as connectors at <code>claude.ai\/customize\/connectors<\/code> work in claude.ai and sync into Claude Code when you&#8217;re signed in with that account. On Team and Enterprise plans only admins can add them. The one gap: connectors don&#8217;t load in Claude Code if your active auth is an API key or a third-party provider like Bedrock.<\/p>\n\n<p><strong>How many MCP servers can Claude handle at once?<\/strong><br>\nMore than the old advice suggested. Tool search defers tool definitions until they&#8217;re needed, so extra servers cost very little context and there&#8217;s no fixed per-server cap. The real limit is your context budget and your own ability to keep the tools distinguishable from each other.<\/p>\n\n<p><strong>How do I know if a guide I&#8217;m reading is out of date?<\/strong><br>\nTwo quick tests. If it describes protocol version agreement as a one-time <code>initialize<\/code> handshake, it predates the 2026-07-28 revision. If it tells you to hand-edit <code>claude_desktop_config.json<\/code> as the primary install path, it predates the CLI. Neither makes the advice wrong, but both tell you how much has happened since.<\/p>\n\n<p><strong>What if there&#8217;s no MCP server for a tool I use?<\/strong><br>\nUse Fetch to hit the REST API directly \u2014 that covers most cases \u2014 or build your own server. Building one is a matter of hours with the <a href=\"https:\/\/jonjones.ai\/ai\/claude-agent-sdk-guide-2026\/\">Claude Agent SDK<\/a>, not weeks. Reach for Fetch first; build custom only when Fetch&#8217;s flexibility genuinely isn&#8217;t enough.<\/p>\n\n<p><strong>Do MCP tools work with anything other than Claude?<\/strong><br>\nYes. MCP is an open protocol with broad client support \u2014 ChatGPT, VS Code, and Cursor all speak it alongside Claude. That&#8217;s the actual argument for building on it: the server you write today isn&#8217;t locked to one vendor&#8217;s roadmap.<\/p>\n\n<h2>The Bottom Line: Start With Three, Stack From There<\/h2>\n\n<p>MCP tools aren&#8217;t magic. They&#8217;re infrastructure. And like all infrastructure, the payoff compounds in proportion to how deliberately you build it.<\/p>\n\n<p>The honest JonOps take after months in production: the single biggest jump in leverage came from three tools \u2014 Filesystem, Airtable, and Fetch. Those three turned Claude from a conversational assistant into something that could complete multi-step work without me in the loop. Everything after was additive and intentional.<\/p>\n\n<p>What changed since June is worth naming plainly. The protocol got a new revision with real production features. The context ceiling I warned you about got engineered away. Claude on the web went from &#8220;can&#8217;t&#8221; to &#8220;can.&#8221; Two of my own answers went stale inside three months, and I&#8217;d rather correct them in public than leave you optimising for a constraint that no longer exists.<\/p>\n\n<p>That&#8217;s the actual lesson, and it outlasts any tool list: <strong>this stack moves faster than the guides written about it.<\/strong> Check the spec date. Check the CLI. Check whether the ceiling you&#8217;re designing around is still there.<\/p>\n\n<p>Then start small. Install Filesystem, Airtable, and Fetch. Run one workflow end to end without touching it. Add the next tool when you hit the next bottleneck \u2014 not before.<\/p>\n\n<p>The autonomous business doesn&#8217;t arrive overnight. But with the right MCP tools in place, every week it needs a little less of you. That&#8217;s the whole point.<\/p>\n\n<style>#kt-layout-idsignup_end_mcp2026 > .kt-row-column-wrap{align-content:start;}:where(#kt-layout-idsignup_end_mcp2026 > .kt-row-column-wrap) > .wp-block-kadence-column{justify-content:start;}#kt-layout-idsignup_end_mcp2026 > .kt-row-column-wrap{column-gap:var(--global-kb-gap-md, 2rem);row-gap:var(--global-kb-gap-md, 2rem);padding-top:var( --global-kb-row-default-top, 25px );padding-bottom:var( --global-kb-row-default-bottom, 25px );padding-top:30px;padding-right:30px;padding-bottom:30px;padding-left:30px;grid-template-columns:repeat(2, minmax(0, 1fr));}#kt-layout-idsignup_end_mcp2026{border-top-left-radius:16px;border-top-right-radius:16px;border-bottom-right-radius:16px;border-bottom-left-radius:16px;overflow:clip;isolation:isolate;}#kt-layout-idsignup_end_mcp2026 > .kt-row-layout-overlay{border-top-left-radius:16px;border-top-right-radius:16px;border-bottom-right-radius:16px;border-bottom-left-radius:16px;}#kt-layout-idsignup_end_mcp2026{background-color:#f0f0f0;}#kt-layout-idsignup_end_mcp2026 > .kt-row-layout-overlay{opacity:0.30;}@media all and (max-width: 1024px){#kt-layout-idsignup_end_mcp2026 > .kt-row-column-wrap{grid-template-columns:minmax(0, 1fr);}}@media all and (max-width: 767px){#kt-layout-idsignup_end_mcp2026 > .kt-row-column-wrap{grid-template-columns:repeat(2, minmax(0, 1fr));}}<\/style>\n<div class=\"wp-block-kadence-rowlayout alignnone\">\n<style>.kadence-columnsignup_img_end_mcp2026 > .kt-inside-inner-col{border-top-width:0px;border-right-width:0px;border-bottom-width:0px;border-left-width:0px;}.kadence-columnsignup_img_end_mcp2026 > .kt-inside-inner-col,.kadence-columnsignup_img_end_mcp2026 > .kt-inside-inner-col:before{border-top-left-radius:0px;border-top-right-radius:0px;border-bottom-right-radius:0px;border-bottom-left-radius:0px;}.kadence-columnsignup_img_end_mcp2026 > .kt-inside-inner-col{column-gap:var(--global-kb-gap-sm, 1rem);}.kadence-columnsignup_img_end_mcp2026 > .kt-inside-inner-col{flex-direction:column;}.kadence-columnsignup_img_end_mcp2026 > .kt-inside-inner-col > .aligncenter{width:100%;}.kadence-columnsignup_img_end_mcp2026 > .kt-inside-inner-col:before{opacity:0.3;}.kadence-columnsignup_img_end_mcp2026{position:relative;}@media all and (max-width: 1024px){.kadence-columnsignup_img_end_mcp2026 > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}@media all and (max-width: 767px){.kadence-columnsignup_img_end_mcp2026 > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}<\/style>\n<div class=\"wp-block-kadence-column inner-column-1\"><div class=\"kt-inside-inner-col\">\n\n<figure class=\"wp-block-image size-medium\">\n  <img decoding=\"async\" src=\"https:\/\/jonjones.ai\/wp-content\/uploads\/2026\/06\/newsletter-cta-ai-playbook.jpg\" alt=\"Join the JonOps AI Playbook newsletter\" \/>\n<\/figure>\n\n<\/div><\/div>\n\n<style>.kadence-columnsignup_txt_end_mcp2026 > .kt-inside-inner-col{border-top-width:0px;border-right-width:0px;border-bottom-width:0px;border-left-width:0px;}.kadence-columnsignup_txt_end_mcp2026 > .kt-inside-inner-col,.kadence-columnsignup_txt_end_mcp2026 > .kt-inside-inner-col:before{border-top-left-radius:0px;border-top-right-radius:0px;border-bottom-right-radius:0px;border-bottom-left-radius:0px;}.kadence-columnsignup_txt_end_mcp2026 > .kt-inside-inner-col{column-gap:var(--global-kb-gap-sm, 1rem);}.kadence-columnsignup_txt_end_mcp2026 > .kt-inside-inner-col{flex-direction:column;}.kadence-columnsignup_txt_end_mcp2026 > .kt-inside-inner-col > .aligncenter{width:100%;}.kadence-columnsignup_txt_end_mcp2026 > .kt-inside-inner-col:before{opacity:0.3;}.kadence-columnsignup_txt_end_mcp2026{position:relative;}@media all and (max-width: 1024px){.kadence-columnsignup_txt_end_mcp2026 > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}@media all and (max-width: 767px){.kadence-columnsignup_txt_end_mcp2026 > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}<\/style>\n<div class=\"wp-block-kadence-column inner-column-2\"><div class=\"kt-inside-inner-col\">\n\n<h3 class=\"wp-block-heading has-text-color\" style=\"color:#1e1b3a\">Lead Magnet AI Playbook<\/h3>\n\n\n<p class=\"has-text-color\" style=\"color:#4a4568\">Get the AI automation playbook Jon uses to run 10+ autonomous brands \u2014 real systems, real receipts, weekly in your inbox.<\/p>\n\n<div class='fluentform ff-default fluentform_wrapper_8 ffs_default_wrap'><form data-form_id=\"8\" id=\"fluentform_8\" class=\"frm-fluent-form fluent_form_8 ff-el-form-top ff_form_instance_8_2 ff-form-loading ffs_default\" data-form_instance=\"ff_form_instance_8_2\" method=\"POST\" ><fieldset  style=\"border: none!important;margin: 0!important;padding: 0!important;background-color: transparent!important;box-shadow: none!important;outline: none!important; min-inline-size: 100%;\">\n                    <legend class=\"ff_screen_reader_title\" style=\"display: block; margin: 0!important;padding: 0!important;height: 0!important;text-indent: -999999px;width: 0!important;overflow:hidden;\">Lead Magnet - AI Playbook<\/legend><input type='hidden' name='__fluent_form_embded_post_id' value='5496' \/><input type=\"hidden\" id=\"_fluentform_8_fluentformnonce\" name=\"_fluentform_8_fluentformnonce\" value=\"887da9fad1\" \/><input type=\"hidden\" name=\"_wp_http_referer\" value=\"\/zh\/wp-json\/wp\/v2\/posts\/5496\" \/><div class='ff-el-group'><div class='ff-el-input--content'><input type=\"email\" name=\"email\" id=\"ff_8_2_email\" class=\"ff-el-form-control\" placeholder=\"Your email address\" data-name=\"email\"  aria-invalid=\"false\" aria-required=true><\/div><\/div><div class='ff-el-group ff-text-left ff_submit_btn_wrapper ff_submit_btn_wrapper_custom'><button class=\"ff-btn ff-btn-submit ff-btn-md ff_btn_style wpf_has_custom_css\" type=\"submit\" name=\"custom_submit_button-8_1\" data-name=\"custom_submit_button-8_1\"  aria-label=\"GET THE PLAYBOOK\">GET THE PLAYBOOK<\/button><style>form.fluent_form_8 .wpf_has_custom_css.ff-btn-submit { background-color:#00ff88;border-color:#00ff88;color:#0a0a14;min-width:100%; }form.fluent_form_8 .wpf_has_custom_css.ff-btn-submit:hover { background-color:#00cc6a;border-color:#00cc6a;color:#0a0a14;min-width:100%; } <\/style><\/div><\/fieldset><\/form><div id='fluentform_8_errors' class='ff-errors-in-stack ff_form_instance_8_2 ff-form-loading_errors ff_form_instance_8_2_errors'><\/div><\/div>            <script type=\"text\/javascript\">\n                window.fluent_form_ff_form_instance_8_2 = {\"id\":\"8\",\"settings\":{\"layout\":{\"labelPlacement\":\"top\",\"helpMessagePlacement\":\"with_label\",\"errorMessagePlacement\":\"inline\",\"asteriskPlacement\":\"asterisk-right\"},\"restrictions\":{\"denyEmptySubmission\":{\"enabled\":false}}},\"form_instance\":\"ff_form_instance_8_2\",\"form_id_selector\":\"fluentform_8\",\"rules\":{\"email\":{\"required\":{\"value\":true,\"message\":\"This field is required\"},\"email\":{\"value\":true,\"message\":\"Please enter a valid email address\"}}},\"debounce_time\":300};\n                            <\/script>\n            \n\n<\/div><\/div>\n\n<\/div>\n\n\n","protected":false},"excerpt":{"rendered":"<p>\u5927\u591a\u6578\u4eba\u4ecd\u7136\u50cf\u62c9\u8457\u624b\u715e\u8eca\u4e00\u6a23\u64cd\u63a7\u8457 Claude\u3002\u4f60\u5f97\u5230\u4e86\u4e00\u500b\u80fd\u5920\u601d\u8003\u3001\u5beb\u4f5c\u548c\u63a8\u7406\u7684\u4eba\u5de5\u667a\u6167\u2014\u2014\u4f46\u4e00\u65e6\u5b83\u9700\u8981\u63a5\u89f8\u771f\u5be6\u7684\u7cfb\u7d71\uff0c\u4e00\u5207\u53c8\u56de\u5230\u4e86\u539f\u9ede\u2026<\/p>","protected":false},"author":2,"featured_media":5489,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_kad_blocks_custom_css":"","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","_kadence_starter_templates_imported_post":false,"_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","footnotes":""},"categories":[28],"tags":[66,53,237,236,96],"class_list":["post-5496","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai","tag-ai-automation","tag-claude-code-2","tag-mcp-servers","tag-mcp-tools","tag-model-context-protocol"],"taxonomy_info":{"category":[{"value":28,"label":"AI"}],"post_tag":[{"value":66,"label":"ai automation"},{"value":53,"label":"claude code"},{"value":237,"label":"mcp servers"},{"value":236,"label":"mcp tools"},{"value":96,"label":"model context protocol"}]},"featured_image_src_large":["https:\/\/jonjones.ai\/wp-content\/uploads\/2026\/06\/mcp-tools-solopreneur-guide-featured.jpg",1344,752,false],"author_info":{"display_name":"Jon Jones","author_link":"https:\/\/jonjones.ai\/zh\/author\/jonjonjones-ai\/"},"comment_info":0,"category_info":[{"term_id":28,"name":"AI","slug":"ai","term_group":0,"term_taxonomy_id":28,"taxonomy":"category","description":"","parent":0,"count":89,"filter":"raw","cat_ID":28,"category_count":89,"category_description":"","cat_name":"AI","category_nicename":"ai","category_parent":0}],"tag_info":[{"term_id":66,"name":"ai automation","slug":"ai-automation","term_group":0,"term_taxonomy_id":66,"taxonomy":"post_tag","description":"","parent":0,"count":33,"filter":"raw"},{"term_id":53,"name":"claude code","slug":"claude-code-2","term_group":0,"term_taxonomy_id":53,"taxonomy":"post_tag","description":"","parent":0,"count":39,"filter":"raw"},{"term_id":237,"name":"mcp servers","slug":"mcp-servers","term_group":0,"term_taxonomy_id":237,"taxonomy":"post_tag","description":"","parent":0,"count":1,"filter":"raw"},{"term_id":236,"name":"mcp tools","slug":"mcp-tools","term_group":0,"term_taxonomy_id":236,"taxonomy":"post_tag","description":"","parent":0,"count":1,"filter":"raw"},{"term_id":96,"name":"model context protocol","slug":"model-context-protocol","term_group":0,"term_taxonomy_id":96,"taxonomy":"post_tag","description":"","parent":0,"count":3,"filter":"raw"}],"_links":{"self":[{"href":"https:\/\/jonjones.ai\/zh\/wp-json\/wp\/v2\/posts\/5496","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jonjones.ai\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jonjones.ai\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jonjones.ai\/zh\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/jonjones.ai\/zh\/wp-json\/wp\/v2\/comments?post=5496"}],"version-history":[{"count":1,"href":"https:\/\/jonjones.ai\/zh\/wp-json\/wp\/v2\/posts\/5496\/revisions"}],"predecessor-version":[{"id":6897,"href":"https:\/\/jonjones.ai\/zh\/wp-json\/wp\/v2\/posts\/5496\/revisions\/6897"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jonjones.ai\/zh\/wp-json\/wp\/v2\/media\/5489"}],"wp:attachment":[{"href":"https:\/\/jonjones.ai\/zh\/wp-json\/wp\/v2\/media?parent=5496"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jonjones.ai\/zh\/wp-json\/wp\/v2\/categories?post=5496"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jonjones.ai\/zh\/wp-json\/wp\/v2\/tags?post=5496"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}