MCP Server with C#: What Is It, How It Works, Benefits & Practical Example

MCP Server with C#: What Is It, How It Works, Benefits & Practical Example
C# & .NET Developer Guide

MCP Server with C#: What Is It, How It Works, Benefits & Practical Example

A complete, beginner-friendly guide to the Model Context Protocol (MCP) and how to build an MCP Server using C# and .NET — from zero to working code.

C# / .NET AI Integration MCP Protocol Beginner-Friendly

1. Introduction — The Problem MCP Solves

Imagine you have a smart AI assistant — one that can understand natural language and answer complex questions. Now imagine you want it to do something more useful than just answering general questions. You want it to:

  • Look up a customer record from your SQL Server database.
  • Fetch open orders from your existing ASP.NET Core API.
  • Read a report file and summarize it.
  • Execute a controlled business operation inside your C# application.

The problem is that AI models — on their own — cannot reach into your private systems. They do not know where your database is, they cannot call your API automatically, and they do not have access to your business logic. There is a gap between the AI and your real-world systems.

This is exactly the gap that MCP — the Model Context Protocol — is designed to bridge. MCP provides a standardized, secure way for AI applications to connect to external tools, data sources, and services — including those written in C# and .NET.

In this article you will learn what MCP is, how it works, and how you — as a C# developer — can build your own MCP Server to connect AI to your existing applications, databases, and APIs.


2. What Is MCP (Model Context Protocol)?

MCP stands for Model Context Protocol. It is an open, standardized protocol — originally introduced by Anthropic — that defines how an AI application can communicate with external tools, resources, and services in a consistent and structured way.

💡
Simple Analogy

Think of MCP as a universal connector. Just as a USB-C port lets you connect many different devices (keyboard, monitor, phone) using one standard cable, MCP lets many different AI applications connect to many different tools using one standard protocol.

Why Was MCP Introduced?

Before MCP, every team that wanted to connect an AI application to an external system had to build a completely custom integration. There was no standard. Every connection was designed differently, making integrations fragile, hard to reuse, and difficult to maintain.

MCP solves this by defining a single, agreed-upon way for AI applications to discover and call external tools. If a tool is built to speak MCP, any MCP-compatible AI application can use it — without any custom glue code.

The MCP Architecture — Who Is Who?

AI Model (LLM)
e.g. GPT-4, Claude, Gemini
↓ understands language, reasons
AI Application
e.g. Claude Desktop, custom chatbot, IDE plugin
↓ sends requests through MCP
MCP Client
built into the AI application
↓ MCP Protocol (JSON-RPC over stdio or HTTP)
MCP Server (your C# code)
exposes tools & resources
↓ calls your actual logic
Tools / Database / API / File System
your real-world business data

What MCP Is — and What It Is Not

⚠️
Important — Clear Up Common Misconceptions
  • MCP is not an AI model. It has no intelligence of its own.
  • MCP is not a replacement for an LLM. You still need an LLM (like GPT-4 or Claude) to understand language.
  • MCP is not a database. It is a communication protocol.
  • MCP is not an AI agent. It is the communication standard the agent may use.
  • MCP can work alongside REST APIs. In fact, your MCP server can call your own REST API internally.

3. What Is an MCP Server?

An MCP Server is a program — in our case, a C# application — that exposes a set of capabilities (called tools, resources, and prompts) to any MCP-compatible client.

👥
Analogy

Think of an MCP server as a knowledgeable receptionist at a large company. The receptionist knows which services are available, can route requests to the right department, and returns the result — all without the visitor (AI) needing to know how the internal systems work.

Examples of capabilities that a C# MCP server might expose:

  • Get customer information by ID
  • Search a product catalog
  • Retrieve open orders for an account
  • Query a report from SQL Server
  • Read a file from a controlled folder
  • Check the current weather (by calling an external API)
  • Trigger a controlled business workflow
  • Search internal company documents

The AI application does not need to know how these things are implemented. It just knows the tool is available and asks for it through MCP.


4. How MCP Works — Step by Step

The Communication Flow

User
↓ types a question
AI Application (MCP Client)
↓ decides a tool is needed
MCP Request (JSON-RPC)
↓ sent to MCP server
C# MCP Server
↓ executes the appropriate method
Database / API / File System
↓ data returned to server
MCP Response (JSON)
↓ returned to AI application
AI Formats & Responds
↓ natural-language answer
User receives the answer

Every step follows the MCP standard — no custom integration needed on the AI side.

Practical Step-by-Step Example

Let's trace through what happens when a user asks:

User Prompt

"Give me the details of customer 1001."

  1. User types the question in an MCP-compatible AI application (for example, Claude Desktop, a custom chatbot, or an AI-powered IDE).
  2. The LLM reasons about the request and determines that it needs to call a tool called get_customer with customerId = 1001.
  3. The MCP Client (built into the AI application) sends a structured JSON-RPC request to the C# MCP Server.
  4. The C# MCP Server receives the request, validates the input, and calls the GetCustomer(1001) method in your C# code.
  5. Your C# code queries SQL Server (or calls an internal API) and retrieves the customer record.
  6. The MCP Server returns the result as a structured JSON response.
  7. The AI application receives the data and uses the LLM to compose a natural-language answer for the user.
  8. The user reads: "Customer 1001 is Jane Smith, based in Chicago. She has placed 7 orders and her email is jane@example.com."

5. Why Use MCP with C# and .NET?

If your team already works with C# and .NET, building an MCP Server is a natural extension of your existing skills — not a rewrite of everything you already have.

  • Existing .NET applications: Wrap and expose functionality from systems already built in .NET.
  • SQL Server: Query your databases safely using parameterized commands.
  • ASP.NET Core APIs: Call your existing REST endpoints from within the MCP server.
  • Enterprise C# business logic: Reuse domain services, repositories, and business rules.
  • File-processing systems: Read reports and documents from controlled locations.
  • Windows services and background jobs: Trigger controlled background operations.
  • Dependency Injection (DI): The official MCP SDK integrates directly with .NET's DI container — just like ASP.NET Core.

Most importantly: you do not have to rebuild anything. Your existing C# services, repositories, and APIs stay exactly as they are. The MCP server simply becomes a thin, structured adapter layer that bridges them to the AI world.


6. MCP vs Traditional REST API

Feature Traditional REST API MCP Server
Primary PurposeExpose data/operations to software clientsExpose tools/data to AI applications in a standard way
Typical ClientWeb apps, mobile apps, other servicesAI applications (LLM-based agents, chatbots, IDE plugins)
Tool DiscoveryManual (developer reads docs)Automatic — the AI client discovers available tools at runtime
AI IntegrationRequires custom glue code for every AI integrationBuilt-in — any MCP-compatible AI app can use it immediately
StandardizationVaries by team (REST conventions, OpenAPI, etc.)Standardized by the MCP specification
ReusabilityReusable, but AI integration requires extra workOne MCP server can serve multiple AI applications
Typical UsageApplication-to-application communicationAI-to-tool communication
AuthenticationAPI keys, OAuth, JWT, etc.MCP supports OAuth 2.0 and custom auth; stdio runs locally
TransportHTTP/HTTPSstdio (local process) or HTTP/SSE (network-accessible)
Data AccessYou define every endpoint manuallyYou define tools; the AI calls them when needed
💡
MCP Does Not Replace REST APIs

MCP and REST APIs solve related but different problems. An MCP server can call your existing REST API internally. This is a very common and recommended pattern:

AI Application
↓ MCP Protocol
C# MCP Server
↓ HTTP call
Your Existing REST API
↓ database query
Business System / Database

Your REST API stays unchanged. The MCP server is a new, thin adapter layer.


7. Real-World Scenario: Customer Lookup with C#

Let us walk through a concrete scenario before writing any code so you can see how the pieces fit together.

Scenario Setup

  • A company uses a SQL Server database with a Customers table.
  • A developer builds a C# MCP server that exposes a get_customer tool.
  • The tool accepts a customerId and returns: name, email, city, order count.
  • An AI application (e.g., Claude Desktop, or a custom chatbot) connects to this MCP server.

What Happens When the User Asks a Question

User asks

"Show me the details of customer 1001."

  1. The AI application receives this question and passes it to the LLM.
  2. The LLM — which was told about the available get_customer tool — decides to call it with customerId: 1001.
  3. The MCP Client sends: { "tool": "get_customer", "arguments": { "customerId": 1001 } }
  4. The C# MCP server's GetCustomer(1001) method runs and queries the database.
  5. The result is returned: { "name": "Jane Smith", "email": "jane@example.com", "city": "Chicago", "orderCount": 7 }
  6. The AI application formats a natural-language response for the user.
AI Response

"Customer 1001 is Jane Smith. She is based in Chicago, her email is jane@example.com, and she has placed 7 orders so far."


8. Building a Simple MCP Server in C#

Prerequisites

  • .NET SDK 8 or later installed (dotnet.microsoft.com/download)
  • Basic knowledge of C# (classes, methods, attributes)
  • A code editor (Visual Studio 2022+, VS Code, or JetBrains Rider)
  • An MCP-compatible AI client for testing (e.g., Claude Desktop, or the MCP Inspector tool)
📌
Official NuGet Package

The official C# MCP SDK is maintained jointly by Microsoft and Anthropic. The NuGet package name is ModelContextProtocol. Source code is available at github.com/modelcontextprotocol/csharp-sdk.



9. Project Setup and Structure

Step 1 — Create a New Console Project

Shell — Terminal / Command Prompt# Create a new .NET console application $ dotnet new console -n CustomerMcpServer $ cd CustomerMcpServer # Add the official MCP SDK NuGet package $ dotnet add package ModelContextProtocol # Add Microsoft.Extensions.Hosting for dependency injection support $ dotnet add package Microsoft.Extensions.Hosting

Step 2 — Project Structure

After setup, your project will look like this:

Project StructureCustomerMcpServer/ ├── Program.cs // Entry point — configure and run the MCP server ├── Tools/ │ └── CustomerTools.cs // MCP tools (methods exposed to the AI) ├── Models/ │ └── CustomerResult.cs // Data models returned by tools ├── Services/ │ └── CustomerService.cs// Business logic (kept separate from MCP adapter) └── CustomerMcpServer.csproj
💡
Best Practice: Keep Tools Thin

Your MCP tool methods should be thin adapters. Put your real business logic (database queries, API calls, validation) in separate service classes. This keeps your code clean, testable, and maintainable.


10. Creating Your First MCP Tool in C#

The Data Model

First, define the data that the tool will return:

C# — Models / CustomerResult.cs// Models/CustomerResult.cs namespace CustomerMcpServer.Models; /// <summary> /// Simple record representing the data returned by the get_customer tool. /// Each property maps to a column in the Customers table. /// </summary> public record CustomerResult( int CustomerId, string Name, string Email, string City, int OrderCount );

The Business Logic Service

Separate your business logic from the MCP adapter layer:

C# — Services / CustomerService.cs/* * Services/CustomerService.cs * * In a real application this would query SQL Server. * Here we use in-memory data to keep the example simple and runnable. */ using CustomerMcpServer.Models; namespace CustomerMcpServer.Services; public class CustomerService { // Simulated in-memory customer store — replace with a real DB in production private static readonly Dictionary<int, CustomerResult> _customers = new() { [1001] = new CustomerResult(1001, "Jane Smith", "jane@example.com", "Chicago", 7), [1002] = new CustomerResult(1002, "John Carter", "john@example.com", "New York", 3), [1003] = new CustomerResult(1003, "Aisha Patel", "aisha@example.com", "Austin", 12), }; /// <summary> /// Returns the customer matching the given ID, or null if not found. /// </summary> public CustomerResult? GetCustomer(int customerId) { _customers.TryGetValue(customerId, out var customer); return customer; } }

The MCP Tool Class

Now create the tool class. This is what the MCP SDK will discover and expose to the AI application. The key attributes are:

  • [McpServerToolType] — marks the class as a container of MCP tools.
  • [McpServerTool] — marks individual methods as tools the AI can call.
  • [Description] — provides human-readable (and AI-readable) documentation so the LLM knows when and how to call the tool.
C# — Tools / CustomerTools.cs// Tools/CustomerTools.cs using System.ComponentModel; using ModelContextProtocol.Server; using CustomerMcpServer.Models; using CustomerMcpServer.Services; namespace CustomerMcpServer.Tools; // [McpServerToolType] tells the SDK to scan this class for MCP tool methods [McpServerToolType] public class CustomerTools { private readonly CustomerService _customerService; /// <summary> /// Constructor — the .NET DI container injects CustomerService automatically. /// </summary> public CustomerTools(CustomerService customerService) { _customerService = customerService; } // [McpServerTool] exposes this method as a callable MCP tool named "get_customer" // [Description] tells the LLM *what* this tool does and *when* to use it — this is critical! [McpServerTool("get_customer")] [Description("Retrieves customer information (name, email, city, order count) by customer ID.")] public string GetCustomer( [Description("The unique numeric ID of the customer to look up.")] int customerId) { var customer = _customerService.GetCustomer(customerId); // Return a clear, descriptive string so the LLM can build a natural-language answer if (customer is null) return $"No customer found with ID {customerId}."; return $"Customer ID: {customer.CustomerId} | Name: {customer.Name} | " + $"Email: {customer.Email} | City: {customer.City} | Orders: {customer.OrderCount}"; } }

The Program.cs Entry Point

Configure and run the MCP server:

C# — Program.csusing ModelContextProtocol.Server; using CustomerMcpServer.Services; using CustomerMcpServer.Tools; // Build the .NET generic host — this is the same pattern used in ASP.NET Core var builder = Host.CreateApplicationBuilder(args); // Register business services in the .NET DI container builder.Services.AddSingleton<CustomerService>(); /* * Configure the MCP server using a fluent builder chain: * AddMcpServer() — registers MCP services with the DI container * WithStdioServerTransport()— uses stdin/stdout as the transport (works with * Claude Desktop and the MCP Inspector tool) * WithToolsFromAssembly() — auto-discovers all classes marked [McpServerToolType] */ builder.Services .AddMcpServer() .WithStdioServerTransport() .WithToolsFromAssembly(); var host = builder.Build(); await host.RunAsync();
⚠️
Never Write to stdout in Stdio Mode

When using WithStdioServerTransport(), the MCP protocol communicates over standard output. Any accidental Console.WriteLine() in your tool code will corrupt the JSON-RPC stream. Use ILogger (which writes to stderr) for all diagnostic output.

Running the Server

Shell — Terminal / Command Prompt# Start the MCP server — it will listen for JSON-RPC messages on stdin $ dotnet run

The server is now running and listening for MCP requests. Connect to it using Claude Desktop (by adding it to your claude_desktop_config.json) or the MCP Inspector tool.


11. Extending to a Real SQL Server Database

In a production application your CustomerService would query a real database instead of using in-memory data. Here is how the service would look with a safe, parameterized SQL query using Microsoft.Data.SqlClient:

Shell — Add the SQL Client Package# Install the official Microsoft SQL Server client library $ dotnet add package Microsoft.Data.SqlClient
C# — Services / CustomerService.cs (SQL Server version)using Microsoft.Data.SqlClient; using CustomerMcpServer.Models; public class CustomerService { private readonly string _connectionString; public CustomerService(IConfiguration config) { // Read the connection string from appsettings.json — never hard-code credentials in source code _connectionString = config.GetConnectionString("DefaultConnection") ?? throw new InvalidOperationException("Connection string 'DefaultConnection' is not configured."); } /// <summary> /// Queries the Customers table for a single record by primary key. /// Returns null if the customer does not exist. /// </summary> public async Task<CustomerResult?> GetCustomerAsync(int customerId) { // Parameterized query — never concatenate user input into SQL strings const string sql = @" SELECT CustomerId, Name, Email, City, OrderCount FROM Customers WHERE CustomerId = @CustomerId"; await using var conn = new SqlConnection(_connectionString); await conn.OpenAsync(); await using var cmd = new SqlCommand(sql, conn); // @CustomerId is a named parameter — the value is bound safely, preventing SQL injection cmd.Parameters.AddWithValue("@CustomerId", customerId); await using var reader = await cmd.ExecuteReaderAsync(); // If no row was returned, the customer does not exist if (!await reader.ReadAsync()) return null; return new CustomerResult( reader.GetInt32(0), // CustomerId reader.GetString(1), // Name reader.GetString(2), // Email reader.GetString(3), // City reader.GetInt32(4) // OrderCount ); } }
🚫
Never Allow Unrestricted SQL Execution

Do not create an MCP tool that accepts raw SQL queries from the AI and executes them directly. Always implement specific, purpose-built methods with parameterized inputs. Your MCP server controls exactly what database operations are permitted.


12. MCP Tools, Resources, and Prompts

MCP defines three types of capabilities that a server can expose. Understanding the difference helps you design a well-structured MCP server.

MCP Concept What It Means C# Example
Tools Actions the AI can invoke — methods that do something and return a result. These are the most common capability type. GetCustomer(int id), SearchProducts(string query), GetOrderCount(int customerId)
Resources Data sources the AI can read — think of them as documents, files, or structured data the AI can include in its context. They are identified by a URI and are typically read-only. A markdown report file, a company policy document, a configuration JSON returned from a URI like customers://1001/profile
Prompts Pre-built prompt templates that help the AI perform consistent, repeatable tasks. The server defines the template; the AI fills it in with data and uses it in conversation. A template that generates a customer summary email draft, or a code review checklist prompt.

For most C# developers getting started with MCP, Tools will be the primary building block. Resources and Prompts can be added as your server matures.


13. Benefits of Using MCP with C#

01

Reuse Existing C# Code

Expose the C# business logic you have already built. No rewrite needed.

02

Connect AI to .NET Apps

Bridge AI applications to your ASP.NET Core systems, Windows services, and .NET libraries.

03

Controlled Business Operations

Expose only specific, safe operations. You decide exactly what the AI can and cannot do.

04

Database Integration

Let AI safely query SQL Server, PostgreSQL, or any database your .NET app supports.

05

Connect Existing APIs

Use your MCP server as a bridge — call your REST APIs internally from the tool methods.

06

Developer Productivity

Build AI-powered developer tools (IDE assistants, code reviewers) using your own .NET tooling.

07

Standardized AI-Tool Communication

Build once. Any MCP-compatible AI client can discover and use your tools — no per-client customization.

08

Separation of Concerns

Keep your AI integration logic separate from your business logic. Easier to test and maintain.

09

Support Multiple AI Clients

One MCP server can serve Claude Desktop, a custom chatbot, an IDE plugin, and more — simultaneously.

10

Enterprise-Ready Stack

The SDK uses .NET's DI, configuration, and logging systems — familiar to every .NET developer.


14. Real-World Use Cases

Use Case MCP Server Function C#/.NET Example
Customer Support AILook up customer accounts, orders, and ticketsC# service querying CRM SQL Server database
CRM AssistantRetrieve and update contact or opportunity recordsC# wrapper around an internal CRM REST API
E-Commerce AssistantSearch products, check stock levels, retrieve order statusC# service calling existing ASP.NET Core catalog API
Database AnalysisRun pre-approved reports and return structured dataParameterized Dapper or EF Core queries in C#
File ManagementRead reports, templates, and documents from controlled foldersSystem.IO.File.ReadAllText() with path validation
Document SearchFull-text search over indexed company documentsC# calling Azure AI Search or Elasticsearch
Developer AssistantRun tests, lint code, read error logs, query build statusC# tool that shells out to dotnet CLI or reads log files
Internal Company ToolsHR lookups, facility bookings, IT helpdesk statusC# adapters for internal intranet APIs
Business ReportingGenerate dynamic summaries from pre-approved SQL queriesC# service calling SQL Server stored procedures
Business AutomationTrigger specific, safe business workflows via AI promptsC# method that posts to an Azure Service Bus queue
AI-Powered DashboardsProvide natural language access to KPI dataC# tool that queries Azure SQL and returns JSON results

15. MCP and AI Agents — Key Differences

These terms are often mixed up. Here is a clear breakdown:

Concept What It Is Simple Analogy
LLMA large language model — understands and generates human language. The "brain" that reasons about language but has no ability to take action on its own.The brain of an expert consultant
AI AgentA system that uses an LLM to reason about a goal and takes a series of actions to achieve it. An agent may call tools, remember context, and loop until the task is done.The consultant who not only thinks but also picks up the phone and acts
Tool CallingThe mechanism by which an LLM or AI agent requests that a specific function (tool) be executed with given inputs. The LLM does not run code — it only specifies what it wants called.The consultant writing a note: "please get me the report for client 1001"
APIA defined interface that allows two software systems to communicate. APIs predate AI and are used everywhere in software.A service counter at a government office — follow a procedure to get a service
MCPA standardized protocol that defines how AI applications discover and communicate with external tools and data. MCP makes tool calling structured, discoverable, and reusable across clients.The standard telephone system — a common, agreed-upon way to make calls so any phone works anywhere
💡
How They Work Together

An AI Agent uses an LLM to reason. When it needs external data or an action, it uses Tool Calling. If that tool is exposed via MCP, the agent communicates with an MCP Server (your C# code) which may internally call a REST API or query a database. They all work together — none replaces the other.


16. Security and Privacy

🔒
Security Warning — Read This Before Deploying

Never give an AI unrestricted access to your entire database, file system, or operating system. Your MCP server is a security boundary. You control exactly what is permitted.

Security Best Practices for C# MCP Servers

  • Principle of Least Privilege: Expose only the minimum set of operations the AI needs. If the AI only needs to read customer names, do not expose a method that can update or delete records.
  • Always Validate Inputs: Treat all input arriving from the AI client as untrusted. Validate types, ranges, and formats before using them in database queries or file paths.
  • Parameterized SQL Only: Never concatenate user input into SQL strings. Always use parameterized queries to prevent SQL injection.
  • Never Hard-Code Credentials: Use appsettings.json, environment variables, or Azure Key Vault for connection strings, API keys, and secrets.
  • File Path Validation: If your tools read files, validate and restrict the paths allowed. Never let the AI specify an arbitrary file path.
  • Authentication for Network Servers: If you expose your MCP server over HTTP (using WithHttpTransport()), configure OAuth 2.0 authentication to prevent unauthorized access.
  • Logging and Auditing: Log every tool invocation — including inputs and which application triggered it — so you can audit AI actions.
  • Rate Limiting: For network-exposed servers, implement rate limiting to prevent abuse.
  • Review Tool Descriptions Carefully: The [Description] text tells the LLM when to use a tool. An ambiguous description can lead to unintended tool calls.

17. MCP Limitations — A Balanced View

MCP is powerful, but it is not a magic solution. Be aware of these limitations:

  • Setup Complexity: Configuring an MCP server, connecting it to an AI client, and testing the full flow requires some initial learning and setup effort.
  • Security Responsibility Falls on You: MCP is a protocol, not a security framework. You are responsible for authentication, authorization, input validation, and data access control in your C# server.
  • Client Compatibility: Not all AI applications support MCP yet. Check whether your target AI client is MCP-compatible before building a server for it.
  • Evolving Specification: MCP is a relatively new protocol. APIs, SDK versions, and best practices continue to evolve. Track the official GitHub repository for updates.
  • Server Maintenance: An MCP server is a real application — it needs deployment, monitoring, error handling, and maintenance like any other service.
  • External Service Failures: If your MCP server depends on a database or external API, failures in those systems will affect the AI's ability to respond. Implement proper error handling and fallbacks.
  • Not Every Application Needs MCP: If you just need a simple chatbot that answers general questions, MCP may be unnecessary overhead. MCP adds value when you need the AI to access your specific, private, or dynamic data.

18. Final Comparison: MCP vs API vs AI Agent vs LLM

Aspect LLM AI Agent MCP REST API
What is it?Language model — reasons & generates textSystem that uses LLM to plan & actStandard protocol for AI-to-tool communicationInterface for software-to-software communication
Has intelligence?Yes (language understanding)Yes (goal-directed reasoning)NoNo
Can take actions?No (text only)Yes (via tools)No (provides the channel)Yes (when called)
Written in C#?No (trained model)Partially (orchestration)Yes (MCP server)Yes (API server)
Discoverable by AI?N/AN/AYes — automaticallyNo — requires manual integration
AnalogyThe brainThe worker with a brainStandard phone systemA specific service counter

19. Complete Practical Scenario — Enterprise Order Query

The Company Setup

  • A Customer table and an Orders table in SQL Server.
  • An existing ASP.NET Core REST API that manages orders.
  • A new requirement: their AI assistant should answer business questions in natural language.
User Asks

"How many orders did customer 1001 place this year?"

The Full Flow

User types the question in AI chatbot
↓
LLM reasons: "I need to call get_order_count(customerId: 1001, year: 2026)"
↓ MCP tool call request
C# MCP Server receives the request
↓ validates customerId and year
OrderService.GetOrderCountAsync(1001, 2026)
↓ parameterized SQL query
SQL Server returns: 7
↓ MCP response: "Customer 1001 placed 7 orders in 2026."
AI formats the natural-language answer
↓
User reads: "Customer Jane Smith placed 7 orders in 2026."

The C# Tool Method for This Scenario

C# — Tools / OrderTools.cs// Tools/OrderTools.cs using System.ComponentModel; using ModelContextProtocol.Server; using CustomerMcpServer.Services; [McpServerToolType] public class OrderTools { private readonly OrderService _orderService; public OrderTools(OrderService orderService) => _orderService = orderService; [McpServerTool("get_order_count")] [Description("Returns the number of orders placed by a customer in a given year.")] public async Task<string> GetOrderCountAsync( [Description("The unique numeric ID of the customer.")] int customerId, [Description("The four-digit year to query orders for (e.g. 2026).")] int year) { // Validate inputs before touching the database if (customerId <= 0) return "Invalid customer ID. Please provide a positive integer."; if (year < 2000 || year > DateTime.UtcNow.Year) return $"Invalid year. Please provide a year between 2000 and {DateTime.UtcNow.Year}."; var count = await _orderService.GetOrderCountAsync(customerId, year); // Return a plain string — the LLM will turn this into a natural-language answer return $"Customer {customerId} placed {count} order(s) in {year}."; } }

20. Frequently Asked Questions

1. What is MCP?

MCP stands for Model Context Protocol. It is an open standard that defines how AI applications communicate with external tools, data sources, and services in a structured and consistent way. It was originally created by Anthropic and is now supported by Microsoft and the broader AI ecosystem.

2. What is an MCP Server?

An MCP Server is a program that exposes a set of tools, resources, or prompts to MCP-compatible AI clients. When an AI application needs external data or wants to trigger an action, it sends a request to an MCP server, which executes the appropriate code and returns the result.

3. Can I create an MCP Server using C#?

Yes, absolutely. The official MCP C# SDK (the ModelContextProtocol NuGet package) is maintained jointly by Microsoft and Anthropic. It integrates with .NET's standard hosting and dependency injection systems, making it very familiar to C# developers.

4. What .NET version should I use?

The official SDK targets netstandard2.0, so it is compatible with .NET 8, .NET 9, and .NET 10. For new projects, .NET 8 LTS or later is recommended, as it is the current long-term support release.

5. Is MCP an API?

No. MCP is a protocol — a set of rules and message formats for how AI applications and tools communicate. An API is an interface that a system exposes. Your MCP server can call REST APIs internally, but MCP itself is not an API.

6. Does MCP replace REST APIs?

No. MCP does not replace REST APIs. They solve different problems. REST APIs allow software systems to communicate with each other. MCP defines how AI applications discover and interact with tools. A very common pattern is for an MCP server to call existing REST APIs internally.

7. Can an MCP Server connect to SQL Server?

Yes. Your MCP server is a standard C# application, so it can use Microsoft.Data.SqlClient, Entity Framework Core, Dapper, or any other .NET data access library to connect to SQL Server. Always use parameterized queries to prevent SQL injection.

8. Can MCP access files?

Yes. You can write MCP tool methods that read files using standard System.IO APIs. However, always validate and restrict the file paths your tools accept. Never let the AI specify an arbitrary path on your file system.

9. Is MCP secure?

MCP provides mechanisms for authentication (OAuth 2.0 for HTTP-based servers) and the stdio transport runs locally, limiting network exposure. However, security is your responsibility as the server developer. You must implement input validation, least privilege, parameterized queries, and proper credential management in your C# code.

10. What is an MCP Tool?

An MCP Tool is a specific function exposed by an MCP server that an AI application can discover and invoke. In C#, you create a tool by marking a method with the [McpServerTool] attribute and providing a [Description] that helps the LLM understand when and how to use it.

11. What is the difference between MCP and an AI agent?

An AI agent is a system that uses an LLM to reason about goals and take actions. MCP is the standardized communication protocol that the agent may use to call external tools. Think of MCP as the telephone system and the AI agent as the person making the calls.

12. Can one MCP Server be used by multiple AI applications?

Yes. Any MCP-compatible AI client can connect to your MCP server. If you use the HTTP transport (WithHttpTransport()) and proper authentication, multiple AI applications can share a single MCP server simultaneously.

13. Is MCP only useful for large companies?

Not at all. MCP is useful for any developer who wants to connect an AI application to their own data or tools — from individual developers building personal productivity tools to large enterprises building AI assistants for their employees.

14. Can beginners learn MCP with C#?

Yes. If you know basic C# (classes, methods, and attributes) and have used .NET's dependency injection before (as in ASP.NET Core), you have everything you need to get started. The official SDK is designed to feel natural for .NET developers.


Conclusion

MCP — the Model Context Protocol — is the standardized bridge that connects AI applications to the real-world tools, data, and services they need to be truly useful.

In this article you learned what MCP is, how it differs from REST APIs, AI agents, and LLMs, and how to build a working MCP server using C# and .NET with the official ModelContextProtocol SDK.

As a C# or .NET developer, you are in an excellent position to build MCP servers. Your existing business logic, database access layers, ASP.NET Core APIs, and .NET services can all be exposed to AI applications — without rebuilding a single thing from scratch.

Remember: security and controlled access are not optional. Your MCP server is a security boundary. Always apply least privilege, validate all inputs, use parameterized queries, and protect your credentials.

Start building your first MCP Server today

Official SDK: github.com/modelcontextprotocol/csharp-sdk  |  NuGet: ModelContextProtocol

Comments

Popular posts from this blog

Filter DataGrid and ListView in wpf using ICollectionView

Pagination of DataGrid in WPF using MVVM

How to Create TabControl using Prism Region