Reference architecture reviewed 7 September 2026.
MCP boundaries. One client communicates with one server; the host can manage several clients. Servers advertise supported tools, resources and prompts. This drawing follows an MCP tool call; native API adapters are another integration choice. Standard transports are stdio and Streamable HTTP. The HTTP authorization specification applies to protected HTTP servers; local stdio credentials are managed separately. MCP architecture, transports and authorization.
Runtime and context. Model inference, tool execution and stored run history are separate concerns. Checkpoints support recovery; selected context controls what enters each model call. Completion, cancellation and step or time limits bound the run. Retrieval and long-term memory are optional and do not require a vector database. Sandboxes and specialist agents depend on the task. Runtime separation, context engineering and persistence.
Action controls. Tool results do not confer authority. Input validation, least-privilege access and policy-based approval govern execution. Generated code needs a constrained execution environment. Record redacted events and evaluate model, prompt and tool changes before release. Bound retries and use idempotency or deduplication so resuming work does not duplicate a business action. Tool security, approval and resumable execution, and agent evaluations.
Optional delegation. A2A can connect independently deployed agents. It is a separate interoperability choice, not a required hop in every tool call. A2A overview.