14 - MCP & A2A
The two open protocols that connect agents to the world. The Model Context Protocol (MCP) standardises how AI applications discover and use tools, data and prompts from any provider; Agent2Agent (A2A) standardises how one agent delegates tasks to another. This module teaches both at their current versions - MCP 2026-07-28 (the stateless revision) and A2A v1.0 - from the wire format to authorization, security and working code.
Learning objectives 8-10 hours (notes + lab)
By the end of this module you will be able to:- Explain what MCP and A2A standardise, how they differ from function calling and from each other, and when each is the right tool
- Read and write MCP messages under the stateless 2026-07-28 protocol, including multi round-trip requests and elicitation
- Build, test and deploy an MCP server and connect its tools to an agent loop
- Secure MCP deployments - OAuth 2.1 resource servers, audience-bound tokens, least-privilege scopes - and defend against tool poisoning, rug pulls and prompt injection
- Publish an agent over A2A and follow its tasks from a client agent
Prerequisites
- Agent Foundations - the agent loop and tool use
- Basic HTTP, JSON and OAuth concepts
Where This Module Fits
flowchart LR
W["01 Why MCP"] --> A["02 Architecture<br/>& protocol"]
A --> F["03 Server<br/>features"]
A --> AU["04 Authorization"]
F --> B["05 Building servers<br/>& clients"]
AU --> S["06 Security"]
B --> S
W --> A2A["07 A2A"]
B -.-> LAB["🧪 Lab: MCP server,<br/>agent, poisoning, A2A"]
S -.-> LAB
A2A -.-> LAB
style W fill:#e8e2d9,stroke:#ccc4b8
style A fill:#d8dfe8,stroke:#b0bac8
style S fill:#e8e0d4,stroke:#c8b89a
style A2A fill:#ddd8e4,stroke:#b8b0c8
style LAB fill:#dde4dc,stroke:#b0c4b0
Chapter Map
| # | Chapter | You will learn | Time |
|---|---|---|---|
| 1 | Why MCP | The M×N problem, hosts/clients/servers, tools/resources/prompts, MCP vs function calling vs A2A, governance and versions | 35 min |
| 2 | Architecture & Protocol | JSON-RPC, the stateless 2026-07-28 core, stdio and Streamable HTTP, multi round-trip requests, caching, extensions, compatibility | 60 min |
| 3 | Server Features | Tools, annotations, structured output, handles, resources, prompts, elicitation; deprecated roots/sampling/logging | 55 min |
| 4 | Authorization | OAuth 2.1 flow, RFC 9728/8707/9207, Client ID Metadata Documents, scopes and step-up, no token passthrough | 50 min |
| 5 | Building Servers & Clients | Python SDK v2, FastMCP, Inspector, connecting tools to agents, hosted connectors, deployment | 55 min |
| 6 | MCP Security | Tool poisoning, rug pulls, shadowing, prompt injection, the lethal trifecta, supply chain, defences | 50 min |
| 7 | The A2A Protocol | Agent Cards, tasks and states, update delivery, bindings, security, A2A in code | 45 min |
| 8 | Q&A Review Bank | 41 questions across the module | 50 min |
Code Lab
| Lab | What you build | Runs on |
|---|---|---|
| MCP Server & Agent | The Lab 13 shop as an MCP server (stdio and HTTP); a client tour of every feature; an agent using its tools; a measured tool-poisoning attack and a harness guard; the agent published over A2A | Laptop; a local OpenAI-compatible model (or any hosted API) for the agent parts |
Mini-Project
Expose a real system you use (a ticket tracker, a wiki, a database) as an MCP server and put an agent on it:
- 4-8 task-shaped tools with strict schemas, honest annotations and structured output; one resource and one prompt.
- Elicitation (form mode) before every destructive action; URL mode if a secret or third-party authorization is needed.
- Streamable HTTP deployment with OAuth as a resource server (a local Keycloak or your identity provider), least-privilege scopes and a scope-filtered tool list.
- An evaluation of an agent using the server (20+ tasks, state-based checks) and a security test: a poisoned description and an injected instruction inside data the tools return - with your defence and before/after attack success rates.
- A short threat model covering the lethal trifecta for your server.
Review
- Q&A Review Bank - consolidated questions for this module
- Module quiz - every Check Yourself question in this module, in course order
Previous: 13 - Agent Foundations · Next: 15 - Agent Patterns & Multi-Agent
Section Appendix
Summary & Key Terms - a quick recap of this section and its essential vocabulary.