AI & Analytics Legends The knowledge platform for SAP Analytics
Concept card

MCP Server Architecture — Tools, Resources, Prompts

MCP Server Architecture — Tools, Resources, Prompts — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-10-06

What is MCP Server Architecture?

The architecture decision that defines a good MCP server is which of three surfaces — model-controlled tools, application-controlled resources, or user-controlled prompts — each capability lives on, and getting it wrong frustrates every agent that touches the server.

What it is

An MCP server exposes exactly three primary surfaces to a calling agent: tools, resources and prompts. The architecture decision that defines a good server is which surface each piece of functionality lives on — getting this wrong is the difference between a server an LLM can drive autonomously and one that frustrates every agent that touches it.

Tools are model-controlled: the LLM decides when to call them, with what arguments. They are functions with side effects or non-trivial computation — find firms, get firm profile, search news in the Analytics Legends server. Each tool declares a JSON Schema input spec (C224), a description the model reads, and returns structured content. Resources are application-controlled: the host application (Claude Desktop, Cursor) decides which to attach to context, the LLM reads but does not request them by name. They are URI-addressable read-only documents — about.json, agent.json, llms-full.txt in our server. Prompts are user-controlled: the human picks a prompt from a slash-command menu; the server returns a templated message sequence the LLM then runs as if the user typed it. analyze market position and draft outreach are our two.

Why it matters

  • Tools are model-controlled (the LLM decides when to call them); resources are application-controlled (the host decides what to attach); prompts are user-controlled (picked from a slash-command menu) — three genuinely different control loci, not interchangeable labels.
  • Logs must go to stderr, never stdout, because stdout is reserved exclusively for JSON-RPC frames — a common rookie mistake that corrupts the wire.
  • Tool handlers should never throw; returning { isError: true, content: [...] } lets the LLM react to the failure instead of the transport silently breaking.

Key points

  • Tools = model-controlled — JSON-Schema-typed functions the LLM calls (find_firms, get_firm_profile, search_news in the platform charter).
  • Resources = application-controlled — URI-addressable read-only docs the host picks (about.json, agent.json, llms-full.txt).
  • Prompts = user-controlled — slash-command templates the human triggers (analyze_market_position, draft_outreach).
  • Operational invariants — lazy JSON cache module-level, logs to stderr only on stdio, tool handlers never throw (return isError:true).
  • _attribution on every response — anti-training carve-out enforcement per agent.json.
  • SAP's own published MCP servers (BTP administration, Integration Suite Gateway) follow this same three-surface discipline; it is the right mental model for a consultant designing a custom MCP server in front of Datasphere, S/4HANA OData or a BDC data product.
  • The MCP specification moved to revision 2026-07-28, adding a client-side elicitation capability and an extensions framework (Tasks, Skills over MCP, MCP Apps) not accounted for in this architecture's original three-primitive framing — check which revision a given server targets.

Terms used on this page

Tool (MCP)
A model-controlled callable surface declared with a JSON Schema input spec and a natural-language description; the LLM decides when and with what arguments to invoke it during reasoning.
Resource (MCP)
An application-controlled URI-addressable read-only document the host attaches to the LLM's context; the LLM reads it as background knowledge but does not request specific resources by name.
Prompt (MCP)
A user-controlled named template the human triggers (usually via slash-command); the server returns a structured message sequence that the LLM then runs as if the user had typed it.
Lazy module-level cache
The MCP-server pattern where heavy JSON files are read once on the first tool call that needs them and cached for the rest of the session; keeps stdio servers under 50 ms p95 per call.
Elicitation
A client-side capability added in the MCP 2026-07-28 revision letting a tool handler ask the end user for missing or ambiguous information mid-call, through the client, instead of failing the call and asking the calling agent to re-prompt and retry.
Data Access Control-scoped tool
A tool whose input schema and server-side validation enforce the same row/column security rules (Data Access Controls in SAP Datasphere, or authorization objects in S/4HANA) that would apply to the calling user in any other SAP interface — the correct place to enforce SAP authorization for an MCP-exposed action.

Sources

  1. MCP specification — Server features (tools, resources, prompts)
  2. Anthropic MCP TypeScript SDK
  3. SAP Generative AI — official product page
  4. Model Context Protocol — Server features, specification revision 2026-07-28
  5. Model Context Protocol — Extensions overview (Tasks, Skills over MCP, MCP Apps)
  6. SAP Help Portal — Connect to MCP server for SAP BTP administration
  7. SAP Community — MCP Gateway in SAP Integration Suite: your APIs ready for the age of agents
  8. SAP Community — Principal propagation for MCP servers: SAP Integration Suite to SAP S/4HANA
  9. GitHub — modelcontextprotocol/specification (authoritative schema source)
  10. SAP Community — Public release of the MCP server for SAP BTP administration
  11. SAP Community — Build a pro-code A2A agent for SAP S/4HANA Cloud with the CAP Agent Plugin
  12. Model Context Protocol — Understanding MCP servers (tools, resources and prompts as server features)
  13. Model Context Protocol — Architecture overview (hosts, clients, servers and layers)
  14. Model Context Protocol — Client Best Practices (progressive tool discovery against loading every definition upfront)
  15. Google Cloud Blog — Empower your agents with the Google Cloud CLI remote MCP server (two-tool server, caller identity, audit logging, 1 Oct 2026)
  16. SiliconANGLE — Equals Money limits MCP server access to data, not payments (read-only MCP server design, 29 Sep 2026)
  17. SiliconANGLE — Komprise combats ‘MCP bloat’ with a universal interface for AI agents to access enterprise data (metadata-first access, 29 Sep 2026)

Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.

Open in the app →