MCP server development in 2026 means putting a small, well-guarded layer in front of your product so AI agents like Claude and ChatGPT can call it as tools. A read-only public server over data you already have is one to two engineer-weeks; an authenticated server over customer data takes three to six weeks; a server that writes data in a regulated product takes three to six months. Most of that time goes on authorization, scoping and audit, not the protocol. This guide covers the architecture, the costs and a 20-point security checklist, using the three MCP servers BeevR runs in production as the worked example. Updated October 2026.
An MCP server exposes your product's capabilities as tools that any client speaking the Model Context Protocol can discover and call. These include Claude, ChatGPT connectors, IDE agents and agent frameworks. You write the integration once and every compliant client can use it. Before MCP, each client needed its own plugin. An MCP server is not a new backend. It is a thin adapter that sits on top of your API, with its own authorization and its own audit trail.
You need one when customers or partners want to reach your product from an AI assistant. Typical requests are "summarise my account," "check whether this facility must report emissions" or "pull last quarter's numbers into my analysis." You also need one when you want AI engines to answer questions about your company from your own data instead of whatever they remember from training. You probably do not need one yet if no customer has asked, your API is unstable, or your data model is still changing every week. Fix the API first, because the MCP layer depends on it.
The current MCP revision is 2026-07-28, and it changes how servers are built. The biggest change is that MCP is now stateless. The initialize handshake and the Mcp-Session-Id header are gone. Every request carries its own protocol version and client capabilities in _meta, and servers must implement a new server/discover method that advertises their supported versions. Servers that need state across calls now mint explicit handles and receive them back as ordinary tool arguments. ping is removed, and Roots, Sampling and Logging are deprecated.
Authorization changed too. OAuth 2.0 Dynamic Client Registration (RFC 7591) is deprecated in favour of OAuth Client ID Metadata Documents, though it stays available for backwards compatibility. Clients must now validate the iss parameter in authorization responses to block mix-up attacks. The core rules did not change:
Separately, in June 2026 the MCP project declared the Enterprise-Managed Authorization extension stable. It lets a company's identity provider (Okta at launch) grant and revoke MCP access centrally, so users don't have to click through OAuth for every server. If you sell to enterprises, plan for it.
In practice, a server built in 2025 or early 2026 against the handshake-based revisions (2025-06-18, 2025-11-25) still works with clients that support those revisions. A new server should target 2026-07-28. Our own public servers still negotiate 2025-06-18 or 2025-11-25 today, so they are a good example of the migration most teams now face.

Every production MCP server has five layers, whatever the stack. Here they are from the outside in:
/.well-known/mcp/server-card.json lists the endpoint, transport, auth requirement and tools. Protected servers also publish their protected-resource metadata and authorization-server metadata.BeevR runs three MCP servers built this way, and you can connect to the two public ones right now:
| Server | Auth | What it exposes | Notes |
|---|---|---|---|
| https://beevr.ai/mcp | None (public) | 8 read-only tools: search, pricing, services, case studies, articles (EN and VI) | Stateless JSON-RPC over Streamable HTTP; GET returns 405 because there is no server-initiated stream |
| https://ecocheck.ai/mcp | None (public) | 8 read-only tools, including a greenhouse-gas inventory obligation checker and verified 2026 Vietnamese regulations | Server card published; same pattern as beevr.ai |
| https://ecocheck.ai/mcp/account | OAuth 2.1, authorization code + PKCE (S256) | The signed-in customer's own workspaces, inventories, reporting years and emissions reports, read-only | Details in the next section |
To see the protocol for yourself, list the tools on our public server:
curl -s https://beevr.ai/mcp \
-H 'content-type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
Or add https://beevr.ai/mcp as a custom connector in an MCP-capable assistant and ask it what BeevR's fixed-price packages are. The answer will come from get_pricing, not from model memory.
If you build agents yourself, the same tool boundary applies on the client side. Kite, our open-source agent framework, ships MCP integrations (Slack, Gmail, Google Drive, PostgreSQL, Stripe), and every tool call an agent proposes goes through a kernel that checks it against an allowlist, a budget and a policy before it runs.
The EcoCheck account server shows the full flow, and every step is published so you can check it:
/mcp/account returns 401 with WWW-Authenticate: Bearer resource_metadata="…/.well-known/oauth-protected-resource/mcp/account", scope="ecocheck/read". That header is how the client learns where to authorize and which scope to ask for./.well-known/oauth-authorization-server fronts AWS Cognito. It advertises the authorization code grant only, S256 as the only PKCE method, public clients (token_endpoint_auth_method: none) and a revocation endpoint./oauth/register. It accepts only an allowlist of redirect URIs (Claude, ChatGPT and the local MCP Inspector) and returns a public client ID. Agents never create customer accounts.ecocheck/read scope and allows only GET/HEAD requests on an allowlist of routes. Member lists, evidence files and exports return 403. The customer's existing workspace and organisation membership checks still apply, because the agent acts as that customer.Two design choices matter more than the rest. First, the read-only rule lives in the API that owns the data, so a bug in the MCP adapter cannot widen access. Second, the token is the customer's own, so the agent can never see more than the customer could see in the app. Our EcoCheck team explains the customer-facing side in its MCP connection guide (in Vietnamese).
There is also a 2026 update to make: this server registers clients through Dynamic Client Registration, which the 2026-07-28 spec now deprecates in favour of Client ID Metadata Documents. It is still allowed for backwards compatibility, but a new build should support Client ID Metadata Documents from the start.

Cost is driven by three questions: whose data the server exposes, whether agents can change anything, and which compliance regime applies. The protocol layer itself is a few hundred lines. The table converts effort into money at two published rate bands: the senior Asia rate of $31–$41 an hour from our 2026 Vietnam rates guide, and the $100–$300 an hour typical of US mid-market firms.
| Server type | What's in scope | Typical effort (senior engineer-weeks) | At $31–$41/h | At $100–$300/h |
|---|---|---|---|---|
| Public, read-only (like beevr.ai/mcp) | 5–10 tools over existing content or a public API, server card, rate limit, tests | 1–2 | $1.2K–$3.3K | $4K–$24K |
| Authenticated, read-only (like ecocheck.ai/mcp/account) | OAuth 2.1 + PKCE against your identity provider, RFC 9728/8414 metadata, client registration, route allowlist in the API, per-user limits, audit log | 3–6 | $3.7K–$9.8K | $12K–$72K |
| Read-write | Per-tool scopes and step-up authorization, confirmation for consequential actions, idempotency, rollback, tool-description review, abuse testing | 6–12 | $7.4K–$19.7K | $24K–$144K |
| Regulated or multi-tenant enterprise | All of the above, plus tenant isolation tests, HIPAA/PCI data-flow scoping, log retention, enterprise SSO/managed authorization, external penetration test | 12–24+ | $15K–$39K+ | $48K–$288K+ |
The effort ranges are our planning estimates, not quotes. They assume a team that already knows OAuth and the API behind the server, and they exclude external audit or pen-test fees. Running costs are usually small, because a stateless MCP server is a light HTTP function. The real cost sits in the API calls and model usage the agent triggers on your side. For context on the agent side of the bill, see what an AI agent costs to build and run.

The risks fall into three groups: what the model reads, who the server trusts, and what you can prove after the fact. The OWASP MCP Top 10, currently in beta, is the most useful map of them. It lists, in order:
Three findings show why these are not theoretical:
For the wider governance picture (who may connect which agent to what, and how spend is capped), see our guide to AI agent governance.
This is the 20-point list we hold our own servers to. Items marked with an asterisk are what the 2026-07-28 spec requires or strongly recommends.
Authorization
S256 only, for any non-public data.*401 with WWW-Authenticate that carries resource_metadata and the required scope.*Least privilege
insufficient_scope challenge.*Tools
Operations
Before launch, run the server against the MCP Inspector and at least two real clients. Then repeat the denied-path tests from the checklist: wrong scope, expired token, another tenant's ID, write method, oversized input.
Build it yourself when the data is yours, sensitive or regulated, because the authorization logic has to live next to the data. Hosted MCP gateways are a good fit for exposing third-party SaaS tools inside your company, or for prototypes. For a customer-facing server over your own product, the gateway still needs your API to enforce scope, tenancy and audit, and that is most of the work anyway. Whichever you choose, the agent around the server needs the same production discipline as any agent: see taking AI agents from pilot to production.
A public, read-only MCP server over data you already serve takes one to two senior engineer-weeks, including tests and a server card. An OAuth-protected, read-only server over customer data takes three to six weeks. Read-write or regulated servers take longer because of scoping, confirmations and security testing.
Not for public data. Our beevr.ai and ecocheck.ai public servers need no credentials. For anything user-specific, yes: the MCP spec defines OAuth 2.1 with PKCE, with the server acting as a resource server that publishes RFC 9728 metadata. Never put API keys or passwords into an agent conversation.
Yes, but it is deprecated as of the 2026-07-28 revision. Client ID Metadata Documents are now the recommended way for clients to identify themselves. DCR remains for authorization servers that don't support them yet. If you keep DCR, restrict redirect URIs to an exact-match allowlist.
Tool poisoning is when malicious instructions are hidden in a tool's description or output, and the model follows them, for example by sending data to an attacker. In the MCPTox benchmark it succeeded 36.5% of the time on average. Defences are reviewed and versioned descriptions, strict outputs, least-privilege scopes and user confirmation for consequential actions.
The server can be designed to fit inside a compliant system, but compliance belongs to the whole system, not the protocol. Keep PHI or card data out of tool outputs unless the model endpoint is covered by the right agreements, log every access, and scope the server into your risk analysis. Our HIPAA-compliant AI agents guide covers the healthcare side.
BeevR builds production MCP servers and the agents that call them for regulated products, with a fixed price per phase and full code ownership from day one. You can connect to our public server at https://beevr.ai/mcp right now. To make your own product agent-ready, see our AI agent development work or tell us what you want agents to do with your product.