Course

MCP for Engineers

Build stateless servers with typed tools, live context, and secure access

Learn the Model Context Protocol from its stateless 2026-07-28 model outward: hosts, clients, servers, and the JSON-RPC requests that connect them without an initialization handshake or connection state. You build typed tools, addressable resources, and reusable prompts, run them over STDIO and Streamable HTTP, and protect them with OAuth, per-request authorization, and deterministic abuse tests. This Deep Dive is for engineers who need servers that stay correct when connections drop and processes restart.

Latest Updates 2026

See the Invisible

Interactive simulators visualise what's hidden from view.

Hands-On Labs

Step through executions tick by tick. Manipulate state.

Why, Not Just What

Understand the reasoning behind every design decision.

Quizzes & Cheatsheets

Verify your understanding and keep a quick reference handy.

Get Certified

Earn a shareable certificate to prove your deep expertise.

What's Covered

The stateless protocol model

Every MCP request carries its own protocol version and client capabilities, so a server never depends on an initialization handshake or on which connection delivered the message. You map the host, client, and server roles, follow client-originated JSON-RPC requests to their correlated responses, and use server/discover plus UnsupportedProtocolVersion retries instead of connection state to negotiate what both sides support.

Tools, resources, and prompts as control boundaries

The three server primitives differ by who controls them: the model calls tools, the application selects resources, and the user invokes prompts. You define JSON Schema 2020-12 contracts for tools, RFC 6570 URI templates and annotations for resources, and validated arguments for prompts, then choose between them from the interaction owner and data flow rather than from habit.

Freshness and multi round-trip input

Discovery, list, and read results are cacheable with time-to-live hints, and subscriptions/listen delivers change notifications as invalidation signals rather than replayed data. When a tool needs more input, InputRequiredResult and opaque requestState let the client retry with inputResponses under a new JSON-RPC identifier, with principal binding, expiry, and replay limits protecting the state in flight.

STDIO and Streamable HTTP in production

Local servers speak newline-delimited JSON-RPC over stdin and stdout with logging kept on stderr; remote servers accept a separate POST per message and stream responses over request-scoped SSE with metadata mirrored into HTTP headers. You handle process restart, Origin validation, proxy buffering, progress tokens, and the two transport-specific forms of cancellation, including the race where a request completes while being cancelled.

Authorization and security boundaries that hold

A remote server discovers its authorization server from a 401 challenge, binds access tokens to a canonical resource URI, and validates authenticity, issuer, expiry, and audience on every protected request. Around that you threat-model confused-deputy attacks, token passthrough, SSRF through metadata and schema fetches, and prompt injection through tool results, then write deterministic abuse tests at each trust boundary.

The Curriculum

Comprehensive Lessons! Each with theory, interactive simulation, and quiz.

Hosts, Clients, Servers, and Control

Stateless Requests and Server Discovery

Designing Typed MCP Tools

Resources and Application-Controlled Context

Prompts and Primitive Selection

Caching and Change Subscriptions

Multi Round-Trip Input and Elicitation

Local Servers over STDIO

Remote Servers over Streamable HTTP

Progress, Cancellation, and Timeouts

OAuth-Protected MCP Servers

Security Boundaries That Hold

This course in one line

One stateless server instead of a custom integration per AI client

Ready to see what's really happening?

All courses included with your subscription. Cancel anytime.