MCP Server with C#: What Is It, How It Works, Benefits & Practical Example
MCP Server with C#: What Is It, How It Works, Benefits & Practical Example
A complete, beginner-friendly guide to the Model Context Protocol (MCP) and how to build an MCP Server using C# and .NET — from zero to working code.
1. Introduction — The Problem MCP Solves
Imagine you have a smart AI assistant — one that can understand natural language and answer complex questions. Now imagine you want it to do something more useful than just answering general questions. You want it to:
- Look up a customer record from your SQL Server database.
- Fetch open orders from your existing ASP.NET Core API.
- Read a report file and summarize it.
- Execute a controlled business operation inside your C# application.
The problem is that AI models — on their own — cannot reach into your private systems. They do not know where your database is, they cannot call your API automatically, and they do not have access to your business logic. There is a gap between the AI and your real-world systems.
This is exactly the gap that MCP — the Model Context Protocol — is designed to bridge. MCP provides a standardized, secure way for AI applications to connect to external tools, data sources, and services — including those written in C# and .NET.
In this article you will learn what MCP is, how it works, and how you — as a C# developer — can build your own MCP Server to connect AI to your existing applications, databases, and APIs.
2. What Is MCP (Model Context Protocol)?
MCP stands for Model Context Protocol. It is an open, standardized protocol — originally introduced by Anthropic — that defines how an AI application can communicate with external tools, resources, and services in a consistent and structured way.
Think of MCP as a universal connector. Just as a USB-C port lets you connect many different devices (keyboard, monitor, phone) using one standard cable, MCP lets many different AI applications connect to many different tools using one standard protocol.
Why Was MCP Introduced?
Before MCP, every team that wanted to connect an AI application to an external system had to build a completely custom integration. There was no standard. Every connection was designed differently, making integrations fragile, hard to reuse, and difficult to maintain.
MCP solves this by defining a single, agreed-upon way for AI applications to discover and call external tools. If a tool is built to speak MCP, any MCP-compatible AI application can use it — without any custom glue code.
The MCP Architecture — Who Is Who?
e.g. GPT-4, Claude, Gemini
e.g. Claude Desktop, custom chatbot, IDE plugin
built into the AI application
exposes tools & resources
your real-world business data
What MCP Is — and What It Is Not
- MCP is not an AI model. It has no intelligence of its own.
- MCP is not a replacement for an LLM. You still need an LLM (like GPT-4 or Claude) to understand language.
- MCP is not a database. It is a communication protocol.
- MCP is not an AI agent. It is the communication standard the agent may use.
- MCP can work alongside REST APIs. In fact, your MCP server can call your own REST API internally.
3. What Is an MCP Server?
An MCP Server is a program — in our case, a C# application — that exposes a set of capabilities (called tools, resources, and prompts) to any MCP-compatible client.
Think of an MCP server as a knowledgeable receptionist at a large company. The receptionist knows which services are available, can route requests to the right department, and returns the result — all without the visitor (AI) needing to know how the internal systems work.
Examples of capabilities that a C# MCP server might expose:
- Get customer information by ID
- Search a product catalog
- Retrieve open orders for an account
- Query a report from SQL Server
- Read a file from a controlled folder
- Check the current weather (by calling an external API)
- Trigger a controlled business workflow
- Search internal company documents
The AI application does not need to know how these things are implemented. It just knows the tool is available and asks for it through MCP.
4. How MCP Works — Step by Step
The Communication Flow
Every step follows the MCP standard — no custom integration needed on the AI side.
Practical Step-by-Step Example
Let's trace through what happens when a user asks:
"Give me the details of customer 1001."
- User types the question in an MCP-compatible AI application (for example, Claude Desktop, a custom chatbot, or an AI-powered IDE).
- The LLM reasons about the request and determines that it needs to call a tool called
get_customerwithcustomerId = 1001. - The MCP Client (built into the AI application) sends a structured JSON-RPC request to the C# MCP Server.
- The C# MCP Server receives the request, validates the input, and calls the
GetCustomer(1001)method in your C# code. - Your C# code queries SQL Server (or calls an internal API) and retrieves the customer record.
- The MCP Server returns the result as a structured JSON response.
- The AI application receives the data and uses the LLM to compose a natural-language answer for the user.
- The user reads: "Customer 1001 is Jane Smith, based in Chicago. She has placed 7 orders and her email is jane@example.com."
5. Why Use MCP with C# and .NET?
If your team already works with C# and .NET, building an MCP Server is a natural extension of your existing skills — not a rewrite of everything you already have.
- Existing .NET applications: Wrap and expose functionality from systems already built in .NET.
- SQL Server: Query your databases safely using parameterized commands.
- ASP.NET Core APIs: Call your existing REST endpoints from within the MCP server.
- Enterprise C# business logic: Reuse domain services, repositories, and business rules.
- File-processing systems: Read reports and documents from controlled locations.
- Windows services and background jobs: Trigger controlled background operations.
- Dependency Injection (DI): The official MCP SDK integrates directly with .NET's DI container — just like ASP.NET Core.
Most importantly: you do not have to rebuild anything. Your existing C# services, repositories, and APIs stay exactly as they are. The MCP server simply becomes a thin, structured adapter layer that bridges them to the AI world.
6. MCP vs Traditional REST API
| Feature | Traditional REST API | MCP Server |
|---|---|---|
| Primary Purpose | Expose data/operations to software clients | Expose tools/data to AI applications in a standard way |
| Typical Client | Web apps, mobile apps, other services | AI applications (LLM-based agents, chatbots, IDE plugins) |
| Tool Discovery | Manual (developer reads docs) | Automatic — the AI client discovers available tools at runtime |
| AI Integration | Requires custom glue code for every AI integration | Built-in — any MCP-compatible AI app can use it immediately |
| Standardization | Varies by team (REST conventions, OpenAPI, etc.) | Standardized by the MCP specification |
| Reusability | Reusable, but AI integration requires extra work | One MCP server can serve multiple AI applications |
| Typical Usage | Application-to-application communication | AI-to-tool communication |
| Authentication | API keys, OAuth, JWT, etc. | MCP supports OAuth 2.0 and custom auth; stdio runs locally |
| Transport | HTTP/HTTPS | stdio (local process) or HTTP/SSE (network-accessible) |
| Data Access | You define every endpoint manually | You define tools; the AI calls them when needed |
MCP and REST APIs solve related but different problems. An MCP server can call your existing REST API internally. This is a very common and recommended pattern:
Your REST API stays unchanged. The MCP server is a new, thin adapter layer.
7. Real-World Scenario: Customer Lookup with C#
Let us walk through a concrete scenario before writing any code so you can see how the pieces fit together.
Scenario Setup
- A company uses a SQL Server database with a
Customerstable. - A developer builds a C# MCP server that exposes a
get_customertool. - The tool accepts a
customerIdand returns: name, email, city, order count. - An AI application (e.g., Claude Desktop, or a custom chatbot) connects to this MCP server.
What Happens When the User Asks a Question
"Show me the details of customer 1001."
- The AI application receives this question and passes it to the LLM.
- The LLM — which was told about the available
get_customertool — decides to call it withcustomerId: 1001. - The MCP Client sends:
{ "tool": "get_customer", "arguments": { "customerId": 1001 } } - The C# MCP server's
GetCustomer(1001)method runs and queries the database. - The result is returned:
{ "name": "Jane Smith", "email": "jane@example.com", "city": "Chicago", "orderCount": 7 } - The AI application formats a natural-language response for the user.
"Customer 1001 is Jane Smith. She is based in Chicago, her email is jane@example.com, and she has placed 7 orders so far."
8. Building a Simple MCP Server in C#
Prerequisites
- .NET SDK 8 or later installed (dotnet.microsoft.com/download)
- Basic knowledge of C# (classes, methods, attributes)
- A code editor (Visual Studio 2022+, VS Code, or JetBrains Rider)
- An MCP-compatible AI client for testing (e.g., Claude Desktop, or the MCP Inspector tool)
The official C# MCP SDK is maintained jointly by Microsoft and Anthropic.
The NuGet package name is ModelContextProtocol. Source code is available at
github.com/modelcontextprotocol/csharp-sdk.
9. Project Setup and Structure
Step 1 — Create a New Console Project
Step 2 — Project Structure
After setup, your project will look like this:
Your MCP tool methods should be thin adapters. Put your real business logic (database queries, API calls, validation) in separate service classes. This keeps your code clean, testable, and maintainable.
10. Creating Your First MCP Tool in C#
The Data Model
First, define the data that the tool will return:
The Business Logic Service
Separate your business logic from the MCP adapter layer:
The MCP Tool Class
Now create the tool class. This is what the MCP SDK will discover and expose to the AI application. The key attributes are:
[McpServerToolType]— marks the class as a container of MCP tools.[McpServerTool]— marks individual methods as tools the AI can call.[Description]— provides human-readable (and AI-readable) documentation so the LLM knows when and how to call the tool.
The Program.cs Entry Point
Configure and run the MCP server:
When using WithStdioServerTransport(), the MCP protocol communicates
over standard output. Any accidental Console.WriteLine() in your tool
code will corrupt the JSON-RPC stream. Use ILogger (which writes to stderr)
for all diagnostic output.
Running the Server
The server is now running and listening for MCP requests. Connect to it using
Claude Desktop (by adding it to your claude_desktop_config.json)
or the MCP Inspector tool.
11. Extending to a Real SQL Server Database
In a production application your CustomerService would query a real
database instead of using in-memory data. Here is how the service would look with
a safe, parameterized SQL query using Microsoft.Data.SqlClient:
Do not create an MCP tool that accepts raw SQL queries from the AI and executes them directly. Always implement specific, purpose-built methods with parameterized inputs. Your MCP server controls exactly what database operations are permitted.
12. MCP Tools, Resources, and Prompts
MCP defines three types of capabilities that a server can expose. Understanding the difference helps you design a well-structured MCP server.
| MCP Concept | What It Means | C# Example |
|---|---|---|
| Tools | Actions the AI can invoke — methods that do something and return a result. These are the most common capability type. | GetCustomer(int id), SearchProducts(string query), GetOrderCount(int customerId) |
| Resources | Data sources the AI can read — think of them as documents, files, or structured data the AI can include in its context. They are identified by a URI and are typically read-only. | A markdown report file, a company policy document, a configuration JSON returned from a URI like customers://1001/profile |
| Prompts | Pre-built prompt templates that help the AI perform consistent, repeatable tasks. The server defines the template; the AI fills it in with data and uses it in conversation. | A template that generates a customer summary email draft, or a code review checklist prompt. |
For most C# developers getting started with MCP, Tools will be the primary building block. Resources and Prompts can be added as your server matures.
13. Benefits of Using MCP with C#
Reuse Existing C# Code
Expose the C# business logic you have already built. No rewrite needed.
Connect AI to .NET Apps
Bridge AI applications to your ASP.NET Core systems, Windows services, and .NET libraries.
Controlled Business Operations
Expose only specific, safe operations. You decide exactly what the AI can and cannot do.
Database Integration
Let AI safely query SQL Server, PostgreSQL, or any database your .NET app supports.
Connect Existing APIs
Use your MCP server as a bridge — call your REST APIs internally from the tool methods.
Developer Productivity
Build AI-powered developer tools (IDE assistants, code reviewers) using your own .NET tooling.
Standardized AI-Tool Communication
Build once. Any MCP-compatible AI client can discover and use your tools — no per-client customization.
Separation of Concerns
Keep your AI integration logic separate from your business logic. Easier to test and maintain.
Support Multiple AI Clients
One MCP server can serve Claude Desktop, a custom chatbot, an IDE plugin, and more — simultaneously.
Enterprise-Ready Stack
The SDK uses .NET's DI, configuration, and logging systems — familiar to every .NET developer.
14. Real-World Use Cases
| Use Case | MCP Server Function | C#/.NET Example |
|---|---|---|
| Customer Support AI | Look up customer accounts, orders, and tickets | C# service querying CRM SQL Server database |
| CRM Assistant | Retrieve and update contact or opportunity records | C# wrapper around an internal CRM REST API |
| E-Commerce Assistant | Search products, check stock levels, retrieve order status | C# service calling existing ASP.NET Core catalog API |
| Database Analysis | Run pre-approved reports and return structured data | Parameterized Dapper or EF Core queries in C# |
| File Management | Read reports, templates, and documents from controlled folders | System.IO.File.ReadAllText() with path validation |
| Document Search | Full-text search over indexed company documents | C# calling Azure AI Search or Elasticsearch |
| Developer Assistant | Run tests, lint code, read error logs, query build status | C# tool that shells out to dotnet CLI or reads log files |
| Internal Company Tools | HR lookups, facility bookings, IT helpdesk status | C# adapters for internal intranet APIs |
| Business Reporting | Generate dynamic summaries from pre-approved SQL queries | C# service calling SQL Server stored procedures |
| Business Automation | Trigger specific, safe business workflows via AI prompts | C# method that posts to an Azure Service Bus queue |
| AI-Powered Dashboards | Provide natural language access to KPI data | C# tool that queries Azure SQL and returns JSON results |
15. MCP and AI Agents — Key Differences
These terms are often mixed up. Here is a clear breakdown:
| Concept | What It Is | Simple Analogy |
|---|---|---|
| LLM | A large language model — understands and generates human language. The "brain" that reasons about language but has no ability to take action on its own. | The brain of an expert consultant |
| AI Agent | A system that uses an LLM to reason about a goal and takes a series of actions to achieve it. An agent may call tools, remember context, and loop until the task is done. | The consultant who not only thinks but also picks up the phone and acts |
| Tool Calling | The mechanism by which an LLM or AI agent requests that a specific function (tool) be executed with given inputs. The LLM does not run code — it only specifies what it wants called. | The consultant writing a note: "please get me the report for client 1001" |
| API | A defined interface that allows two software systems to communicate. APIs predate AI and are used everywhere in software. | A service counter at a government office — follow a procedure to get a service |
| MCP | A standardized protocol that defines how AI applications discover and communicate with external tools and data. MCP makes tool calling structured, discoverable, and reusable across clients. | The standard telephone system — a common, agreed-upon way to make calls so any phone works anywhere |
An AI Agent uses an LLM to reason. When it needs external data or an action, it uses Tool Calling. If that tool is exposed via MCP, the agent communicates with an MCP Server (your C# code) which may internally call a REST API or query a database. They all work together — none replaces the other.
16. Security and Privacy
Never give an AI unrestricted access to your entire database, file system, or operating system. Your MCP server is a security boundary. You control exactly what is permitted.
Security Best Practices for C# MCP Servers
- Principle of Least Privilege: Expose only the minimum set of operations the AI needs. If the AI only needs to read customer names, do not expose a method that can update or delete records.
- Always Validate Inputs: Treat all input arriving from the AI client as untrusted. Validate types, ranges, and formats before using them in database queries or file paths.
- Parameterized SQL Only: Never concatenate user input into SQL strings. Always use parameterized queries to prevent SQL injection.
- Never Hard-Code Credentials: Use
appsettings.json, environment variables, or Azure Key Vault for connection strings, API keys, and secrets. - File Path Validation: If your tools read files, validate and restrict the paths allowed. Never let the AI specify an arbitrary file path.
- Authentication for Network Servers: If you expose your MCP server over HTTP (using
WithHttpTransport()), configure OAuth 2.0 authentication to prevent unauthorized access. - Logging and Auditing: Log every tool invocation — including inputs and which application triggered it — so you can audit AI actions.
- Rate Limiting: For network-exposed servers, implement rate limiting to prevent abuse.
- Review Tool Descriptions Carefully: The
[Description]text tells the LLM when to use a tool. An ambiguous description can lead to unintended tool calls.
17. MCP Limitations — A Balanced View
MCP is powerful, but it is not a magic solution. Be aware of these limitations:
- Setup Complexity: Configuring an MCP server, connecting it to an AI client, and testing the full flow requires some initial learning and setup effort.
- Security Responsibility Falls on You: MCP is a protocol, not a security framework. You are responsible for authentication, authorization, input validation, and data access control in your C# server.
- Client Compatibility: Not all AI applications support MCP yet. Check whether your target AI client is MCP-compatible before building a server for it.
- Evolving Specification: MCP is a relatively new protocol. APIs, SDK versions, and best practices continue to evolve. Track the official GitHub repository for updates.
- Server Maintenance: An MCP server is a real application — it needs deployment, monitoring, error handling, and maintenance like any other service.
- External Service Failures: If your MCP server depends on a database or external API, failures in those systems will affect the AI's ability to respond. Implement proper error handling and fallbacks.
- Not Every Application Needs MCP: If you just need a simple chatbot that answers general questions, MCP may be unnecessary overhead. MCP adds value when you need the AI to access your specific, private, or dynamic data.
18. Final Comparison: MCP vs API vs AI Agent vs LLM
| Aspect | LLM | AI Agent | MCP | REST API |
|---|---|---|---|---|
| What is it? | Language model — reasons & generates text | System that uses LLM to plan & act | Standard protocol for AI-to-tool communication | Interface for software-to-software communication |
| Has intelligence? | Yes (language understanding) | Yes (goal-directed reasoning) | No | No |
| Can take actions? | No (text only) | Yes (via tools) | No (provides the channel) | Yes (when called) |
| Written in C#? | No (trained model) | Partially (orchestration) | Yes (MCP server) | Yes (API server) |
| Discoverable by AI? | N/A | N/A | Yes — automatically | No — requires manual integration |
| Analogy | The brain | The worker with a brain | Standard phone system | A specific service counter |
19. Complete Practical Scenario — Enterprise Order Query
The Company Setup
- A Customer table and an Orders table in SQL Server.
- An existing ASP.NET Core REST API that manages orders.
- A new requirement: their AI assistant should answer business questions in natural language.
"How many orders did customer 1001 place this year?"
The Full Flow
The C# Tool Method for This Scenario
20. Frequently Asked Questions
1. What is MCP?
MCP stands for Model Context Protocol. It is an open standard that defines how AI applications communicate with external tools, data sources, and services in a structured and consistent way. It was originally created by Anthropic and is now supported by Microsoft and the broader AI ecosystem.
2. What is an MCP Server?
An MCP Server is a program that exposes a set of tools, resources, or prompts to MCP-compatible AI clients. When an AI application needs external data or wants to trigger an action, it sends a request to an MCP server, which executes the appropriate code and returns the result.
3. Can I create an MCP Server using C#?
Yes, absolutely. The official MCP C# SDK (the ModelContextProtocol NuGet package) is maintained jointly by Microsoft and Anthropic. It integrates with .NET's standard hosting and dependency injection systems, making it very familiar to C# developers.
4. What .NET version should I use?
The official SDK targets netstandard2.0, so it is compatible with .NET 8, .NET 9, and .NET 10. For new projects, .NET 8 LTS or later is recommended, as it is the current long-term support release.
5. Is MCP an API?
No. MCP is a protocol — a set of rules and message formats for how AI applications and tools communicate. An API is an interface that a system exposes. Your MCP server can call REST APIs internally, but MCP itself is not an API.
6. Does MCP replace REST APIs?
No. MCP does not replace REST APIs. They solve different problems. REST APIs allow software systems to communicate with each other. MCP defines how AI applications discover and interact with tools. A very common pattern is for an MCP server to call existing REST APIs internally.
7. Can an MCP Server connect to SQL Server?
Yes. Your MCP server is a standard C# application, so it can use Microsoft.Data.SqlClient, Entity Framework Core, Dapper, or any other .NET data access library to connect to SQL Server. Always use parameterized queries to prevent SQL injection.
8. Can MCP access files?
Yes. You can write MCP tool methods that read files using standard System.IO APIs. However, always validate and restrict the file paths your tools accept. Never let the AI specify an arbitrary path on your file system.
9. Is MCP secure?
MCP provides mechanisms for authentication (OAuth 2.0 for HTTP-based servers) and the stdio transport runs locally, limiting network exposure. However, security is your responsibility as the server developer. You must implement input validation, least privilege, parameterized queries, and proper credential management in your C# code.
10. What is an MCP Tool?
An MCP Tool is a specific function exposed by an MCP server that an AI application can discover and invoke. In C#, you create a tool by marking a method with the [McpServerTool] attribute and providing a [Description] that helps the LLM understand when and how to use it.
11. What is the difference between MCP and an AI agent?
An AI agent is a system that uses an LLM to reason about goals and take actions. MCP is the standardized communication protocol that the agent may use to call external tools. Think of MCP as the telephone system and the AI agent as the person making the calls.
12. Can one MCP Server be used by multiple AI applications?
Yes. Any MCP-compatible AI client can connect to your MCP server. If you use the HTTP transport (WithHttpTransport()) and proper authentication, multiple AI applications can share a single MCP server simultaneously.
13. Is MCP only useful for large companies?
Not at all. MCP is useful for any developer who wants to connect an AI application to their own data or tools — from individual developers building personal productivity tools to large enterprises building AI assistants for their employees.
14. Can beginners learn MCP with C#?
Yes. If you know basic C# (classes, methods, and attributes) and have used .NET's dependency injection before (as in ASP.NET Core), you have everything you need to get started. The official SDK is designed to feel natural for .NET developers.
Comments
Post a Comment