How to make an MCP server
Last reviewed 7 October 2026
Decide what the server exposes and where it runs
The official build guide names three kinds of capability a server can offer. Resources are file-like data that clients can read, such as API responses or file contents. Tools are functions the model can call, with the user’s approval. Prompts are pre-written templates that help users with specific tasks. Most first servers expose tools, and the guide does the same.
Then choose the transport. The architecture page says local servers using stdio usually serve a single client, while remote servers using Streamable HTTP usually serve many. Over HTTP a server can accept bearer tokens, API keys or custom headers, and MCP recommends OAuth to obtain tokens. Start local unless other people need to reach the server.
| SDK | Repository | Tier on the SDK page |
|---|---|---|
| TypeScript | modelcontextprotocol/typescript-sdk | Tier 1 |
| Python | modelcontextprotocol/python-sdk | Tier 1 |
| C# | modelcontextprotocol/csharp-sdk | Tier 1 |
| Go | modelcontextprotocol/go-sdk | Tier 1 |
| Rust | modelcontextprotocol/rust-sdk | Tier 1 |
| Ruby | modelcontextprotocol/ruby-sdk | Tier 1 |
| Java | modelcontextprotocol/java-sdk | Tier 2 |
| Swift, PHP and Kotlin | modelcontextprotocol/swift-sdk, php-sdk and kotlin-sdk | Tier 3 |
The steps from the official quickstart
The MCP documentation’s build guide makes a weather server with two tools, get_alerts and get_forecast, which call the US National Weather Service API, and connects it to Claude for Desktop. The Python track, as read on 7 October 2026, runs as follows.
The TypeScript track installs the @modelcontextprotocol/server package and zod and needs Node.js 20 or higher. The same guide has tabs for Java, Kotlin, C#, Ruby, Rust and Go, and the SDK page lists the official SDKs in the table on this page.
- Check the requirements: Python 3.10 or higher and the Python MCP SDK 2.0.0 or higher.
- Install the uv tool, create a project with uv init, create and activate a virtual environment, add the mcp package with its command-line extras, and create the server file.
- Create a server instance with the MCPServer class and give it a name. The guide says the class uses Python type hints and docstrings to generate the tool definitions.
- Write helper functions that call the upstream API with error handling, so a failed request returns a clear message instead of crashing the server.
- Mark each tool function with the tool decorator. The docstring becomes the description the model reads, and the typed arguments become the input schema.
- Run the server with the stdio transport, then start it with uv run to check that it launches.
- Add the server to claude_desktop_config.json under the mcpServers key, with the command and the absolute path to the project. You may need the full path to uv.
- Quit Claude for Desktop completely and start it again, because closing the window does not reload the configuration.
The logging rule that breaks many first servers
For servers on the stdio transport, the guide is blunt: never write to standard output, because doing so corrupts the JSON-RPC messages and breaks the server. In Python, keep print out of the server and use the standard logging module, which writes to standard error. In TypeScript, use console.error instead of console.log. Servers on HTTP can log to standard output safely.
Claude for Desktop writes its MCP logs to ~/Library/Logs/Claude on macOS and ~/.config/Claude/logs on Linux. The file mcp.log covers connections and connection failures, and a file named after each server holds that server’s standard error output.
How to test it
In Claude for Desktop, open the add files and connectors menu and look for your server under Connectors. Then ask a question that should need a tool; the guide uses the weather in Sacramento and the active alerts in Texas. Claude reads the available tools, picks one, the client runs it through your server, and the result returns to Claude for the answer.
If the server does not appear, the guide says to check the configuration file syntax, make sure the project path is absolute, and fully restart the host. For deeper checks, the MCP project lists the MCP Inspector among its tools for developing servers and clients.
Security rules from the MCP documentation
The MCP security best practices page lists attacks and the rules that prevent them. These apply to the server you write.
- Accept only tokens issued for your server. The guidance says MCP servers MUST NOT accept tokens that were not explicitly issued for them, and forbids passing a client’s token through to a downstream API.
- If your server proxies a third-party API with one static OAuth client ID, implement consent for each client before forwarding, to prevent confused deputy attacks.
- For a local server, prefer stdio so that only the MCP client can reach it. If you use HTTP locally, require an authorisation token or use a restricted IPC channel such as a unix domain socket.
- If a tool returns a handle to saved state, such as a cart or workflow ID, generate it randomly, bind it to the authenticated user, and never treat possession of the handle as authentication.
- Ask for the narrowest scopes that do the job and request more only when a privileged tool is first used. Avoid wildcard or catch-all scopes.
- For tools that change data, rely on the host’s approval dialog and keep the tool narrow, so that each approval means one clear action.
Using your MCP server with Swfte
Built in the product
Agents built in Studio can act as MCP clients and call tools on external MCP servers, so a server you build and host can serve a Studio agent as well as a desktop host. Studio can also deploy MCP servers from templates into a workspace, and each deployment answers tools/list.
Calls through Swfte’s MCP gateway need an API key scoped to that server, and the gateway logs the workspace, server, method, status and latency. Per-tool allow and deny rules, call-level rate limits and recording of tool arguments are not built, so keep the security rules above inside your own server.
Common questions
- Which language should I write an MCP server in?
- Use the language your team already maintains. The SDK page lists TypeScript, Python, C#, Go, Rust and Ruby as Tier 1, Java as Tier 2, and Swift, PHP and Kotlin as Tier 3. The page says each SDK provides the same functionality while following the idioms of its language.
- Do I need Claude Desktop to build an MCP server?
- No. The official guide uses Claude for Desktop for simplicity and says servers can connect to any client. Any MCP host that supports your transport can load the server. For testing without a chat client, the MCP project lists the MCP Inspector among its development tools.
- Should my MCP server be local or remote?
- Local over stdio suits a server that reads files or tools on one person’s machine, and the security guidance prefers stdio for local servers because only the client can reach it. Remote over Streamable HTTP suits shared systems that many users reach, and then you need proper authorisation, ideally OAuth.
- Why does my server not show up in Claude for Desktop?
- The guide lists three usual causes: invalid syntax in claude_desktop_config.json, a relative path where an absolute one is needed, and a host that was closed rather than fully quit. Check mcp.log and the log file named after your server for the actual error before changing code.
- Can an MCP server call other APIs?
- Yes, and most do. The official weather example calls the US National Weather Service API inside its tools. Wrap each upstream call with error handling, keep the API key on the server side, and expose narrow tools rather than one tool that forwards any request to the upstream API.
Sources
Facts about other vendors and about the terms on this page were read on the pages below on 7 October 2026. Vendor plans, names and menus change, so check the vendor’s page before you rely on a detail.
- MCP documentation, build an MCP server (read 2026-10-07)
- MCP documentation, official SDKs and tiers (read 2026-10-07)
- MCP documentation, security best practices (read 2026-10-07)
- MCP documentation, architecture overview (read 2026-10-07)
Related reading
More plain answers are on the learn page, and definitions are in the glossary.