MCP separates the protocol from how messages are carried. Two transports are standard.
stdio
The host launches the server as a subprocess and exchanges JSON-RPC messages over its standard input and output.
- Simple and fast.
- Runs with the user's local permissions.
- Ideal for local tools: file systems, local databases, developer utilities.
Servers must write only protocol messages to stdout; logs go to stderr.
Streamable HTTP
The server runs as an independent web service. Clients send messages with HTTP requests, and servers can stream responses and notifications back.
- Suits remote and shared servers, SaaS integrations and multi-user deployments.
- Needs authentication, TLS and the usual web security measures.
Earlier versions of the protocol used a different HTTP-based transport built on server-sent events; newer implementations use Streamable HTTP. Check which versions your client and server support.
Choosing
- Local, single-user tool → stdio.
- Hosted service used by many people → HTTP with authorisation.
Security Notes
For local HTTP servers, bind to localhost and validate the origin of requests. For stdio, remember that the server runs with your privileges — install only servers you trust.