AI agents Guide
MCP and A2A in the Enterprise: How AI Agents Reach Your Systems
MCP is how an agent reaches your systems, and A2A is how it reaches other agents. Since the July 2026 specification, MCP runs like any other API tier, so the enterprise work is governance: one gateway, a private registry, identities from your identity provider, a trace of every call, and a short list of systems opened first.
For CTOs and CISOs deciding how AI agents will connect to SAP, Salesforce and the rest of the estate, and which systems to open to them first.
The short answer
Enterprise MCP means connecting AI agents to company systems through the Model Context Protocol, the open standard for exposing tools and data to agents, and running it behind your own gateway, private registry, identity provider and audit trail. A2A is the companion standard for one agent delegating work to another. Since the 2026-07-28 specification, MCP is stateless and runs like any other API tier.1
Key takeaways
- MCP connects an agent to tools and data; A2A connects an agent to other agents. Most enterprises need MCP first, and A2A only when work must pass to an agent they do not control.
- The 2026-07-28 specification removed sessions and put the method and tool name in HTTP headers, so MCP servers scale behind ordinary load balancers and a gateway can apply policy tool by tool.2
- Authorization is optional in the protocol, which cannot enforce its own security principles, so the controls belong in your gateway, registry and identity provider.34
- Score every candidate system on value, read versus write, API quality and data sensitivity. Read access to knowledge, CRM and tickets goes first; payments and regulated data wait.
- Where the vendor offers a hosted MCP server, start there: Salesforce's runs every call as the authenticated user, with the permissions your administrators already maintain.9
Every agent program reaches the point where the agent must read the account in Salesforce, check the order in SAP and open the ticket in ServiceNow, as the person who asked. The Model Context Protocol (MCP) is the open standard for those connections; the Agent2Agent protocol (A2A) is the open standard for one agent to hand work to another.
- ~500Mmonthly downloads of MCP's main SDKs by July 20261
- 150+organizations supporting the A2A protocol at its first anniversary in April 20268
- 1,467MCP servers found exposed on the internet in April 2026, nearly triple the July 2025 count11
What MCP is and what an MCP server does
MCP is an open protocol that defines how an AI application discovers and calls tools and reads data held in other systems.3 It has three roles: the host is the AI application, a client inside the host holds each connection, and a server exposes capabilities. A server offers three kinds of capability: tools the model can call, resources that supply data, and prompts that package common workflows. Every message is JSON-RPC 2.0.3
An MCP server is a thin adapter in front of a system you already run. It describes each capability in a schema the model can read and translates each call into that system's own API. Build one server for your CRM and every MCP-capable agent and tool in the company can use it, so integrations stop multiplying with every new agent.
Adoption has been fast: more than 97 million monthly SDK downloads in December 2025, close to half a billion a month by July 2026.71 About a year after its release, the lab that introduced MCP donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, which does not dictate the protocol's technical direction; that stays with its maintainers.7
What A2A is and when you need it
A2A (Agent2Agent) is an open protocol that lets AI agents discover, communicate and transact with each other across frameworks, vendors and platforms.8 Where MCP connects an agent to tools, A2A connects agents to agents: the calling agent hands over a task, and the receiving agent plans the work and uses its own tools to do it.
A2A is hosted by the Linux Foundation. By its first anniversary in April 2026, its supporting organizations had grown from more than 50 to over 150, including Salesforce, SAP and ServiceNow.8 Version 1.0, its first stable specification, added multi-tenancy and modernized security flows, and the protocol supports signed Agent Cards, so an agent's published description of itself can be verified cryptographically.8
Most enterprises need MCP first. A2A earns its place when an agent must hand work to one you do not build or control: a supplier's agent, an agent inside a SaaS platform, or another business unit's agent with its own release cycle. SAP's guidance draws the same line, sending multi-agent scenarios that cross system and vendor boundaries to A2A.10 Inside one team's system, an agent calling a sub-agent is ordinary code.
MCP vs A2A vs APIs vs RAG
They work at different layers: an API is how a system exposes functions, MCP is how an agent discovers and calls those functions, A2A is how an agent delegates to another agent, and RAG is a technique for retrieving documents to ground a model's answer. A production agent often uses all four.
| What it is | Connects | Use it when | What it leaves to you | |
|---|---|---|---|---|
| API | The contract a system publishes for other software | Application to system | Code knows in advance which call to make | Nothing new: an MCP server calls it |
| MCP | An open protocol for agents to discover and call tools and read data | Agent to tools and data | An agent must choose among capabilities at run time | Authorization, tool design, gateway and audit |
| A2A | An open protocol for agents to delegate tasks to other agents | Agent to agent | Work crosses a team, vendor or company boundary | Trust between organizations and task contracts |
| RAG | A technique: retrieve relevant passages, then answer from them | Model to documents | Answers must come from your documents, with citations | Index quality, document permissions and evaluation |
Two misreadings are common. The first treats MCP as a replacement for APIs. An MCP server calls your APIs, so every weakness in them (coarse permissions, missing validation, no rate limits) reaches the agent unchanged. The second expects MCP to make agents understand your business. SAP's reference architecture is blunt: "MCP is a connectivity protocol" that adds no business context. Wiring it straight to raw transactional APIs, SAP warns, brings poor entity discovery, heavy token use and, on writes, a significant risk of incorrect business transactions.10
RAG and MCP meet in the middle. A retrieval service over your policies and contracts can be offered to agents as an MCP tool, behind the same identity, gateway and logs as every other call. Answer quality still depends on the pipeline; see Enterprise RAG in production.
What the 2026-07-28 MCP specification changed
The revision published on July 28, 2026 made MCP stateless, made its traffic routable by standard HTTP infrastructure, hardened authorization and moved long-running work into an official Tasks extension.1 The changes that matter in production, from the release notes and changelog:12
| Change | What it replaced | What it means for operations |
|---|---|---|
| No sessions and no initialize handshake; every request carries its own protocol version and capabilities | Session ids, sticky sessions, a shared session store | Servers scale behind a plain round-robin load balancer. State between calls travels as a server-issued handle, secured like a session token |
| Mcp-Method and Mcp-Name headers required on HTTP requests | Gateways parsing the JSON body | A gateway can route, rate-limit and authorize each tool by name |
| Multi round-trip requests: a server answers "input required" and the client retries with the answer | Server-initiated requests over held-open streams | An approval step in the middle of a call works in a stateless deployment |
| Tasks moved into the official io.modelcontextprotocol/tasks extension, driven by polling | An experimental core feature | Long-running jobs get a standard handle to poll, update or cancel |
| Issuer validation (RFC 9207), Client ID Metadata Documents preferred, credentials bound to their issuer | Dynamic Client Registration, now deprecated | Clients reject an authorization code from an unexpected issuer; clients relying on dynamic registration need a migration plan |
| Roots, Sampling, Logging and the HTTP+SSE transport deprecated, with at least twelve months' notice | No formal deprecation policy | Inventory servers that use them; move logging to OpenTelemetry |
Two details matter more than they look. A broken response stream now loses the in-flight request, and the client must resend it as a new request, so every tool that writes needs an idempotency key or a retried write can land twice.2 And the specification now documents how OpenTelemetry trace context travels in each request, so one trace can follow a task from the agent through the gateway into the system of record.2 The official TypeScript, Python, Go and C# SDKs support the revision, with Rust in beta.1
Enterprise MCP reference architecture: gateway, registry, identity and audit
Run MCP the way you run any API tier: agents reach tools only through a gateway, see only servers in your private registry, act with identities from your identity provider, and leave a trace of every call. The protocol will not do this for you. Authorization is optional in the specification, which says MCP cannot enforce its security principles at the protocol level.43
| Component | Its job | What to require | Owner |
|---|---|---|---|
| Gateway | The single path from any agent to any MCP server, in your cloud account or your data center | Token validation on every call; per-tool policy and rate limits keyed on the Mcp-Name header; unregistered servers denied; egress limited to each server's own system | Platform or API team |
| Private registry | The approved servers, versions and tools | Owner, data classification and scopes per server; a pinned hash of every tool description; a review date | Enterprise architecture, with security sign-off |
| Identity | Who the agent acts for, with what rights | Tokens from your identity provider, bound to one server; none forwarded downstream; the user's own permissions applied at the system of record | Identity and access management |
| Audit | Evidence of every call, replayable later | A trace id end to end; caller, tool, redacted parameters, target API, status and latency on every call | Security operations |
The public MCP Registry does not replace your own. It is in preview, holds metadata only for publicly accessible servers, does not accept private ones and leaves security scanning to others; the project recommends a private registry for internal servers, which can implement the public registry's OpenAPI interface.6 An entry needs little more than this:
# One entry in the private MCP registry. The gateway refuses any server or tool not listed.
server: crm-accounts
owner: sales-operations # a named team, reviewed every quarter
endpoint: https://mcp.internal.example.com/crm
protocol: "2026-07-28"
data_class: confidential
auth:
issuer: https://idp.example.com # your identity provider
audience: https://mcp.internal.example.com/crm
tools:
- name: get_account # read
scope: crm.accounts.read
description_sha256: 3f9a0c... # a changed description blocks the server until reviewed
- name: log_call_note # reversible write
scope: crm.activities.write
idempotency: required
rate_limit: 60/min
# close_account is irreversible and deliberately absent
next_review: 2026-12-31Identity is where the 2026 extensions help most. With the Enterprise-Managed Authorization extension, your identity provider checks group membership, roles and conditional access, then issues the MCP client a signed grant (an ID-JAG) that it exchanges for an access token.5 IT grants access from one console, and removing a person at the identity provider revokes their access across every MCP client. Client support varies and the extension is off by default, so confirm it for each client you allow.5
For audit, SAP's guidance makes a good minimum everywhere: log every tool invocation with the caller's identity, parameters with personal data redacted, the target API, response status and latency.10
Which systems to expose through MCP first
Expose first the systems that score high on business value and API quality and low on write risk and data sensitivity. In most estates that means read access to knowledge bases, CRM records and service tickets, well ahead of writes to ERP, payroll or payments. Score each candidate from 1 to 3 on four criteria, where 3 always favors going early, and add the scores.
| Criterion | 3: expose early | 2: expose with controls | 1: wait |
|---|---|---|---|
| Business value | Needed in many tasks a week; people switch screens to get it today | Needed weekly by one team | Occasional or unproven demand |
| Read or write | Read only | Reversible writes: drafts, field updates, new tickets | Irreversible writes: payments, deletions, messages to customers |
| API quality | A vendor-hosted MCP server, or a documented, versioned API with fine-grained scopes | A usable API with coarse scopes | No API: screen automation or direct database access |
| Data sensitivity | Internal, non-personal data | Confidential business data | Regulated personal, health, card or market-sensitive data |
| Candidate | Value | Read or write | API | Sensitivity | Total | Wave |
|---|---|---|---|---|---|---|
| Policy and knowledge base search | 3 | 3 | 3 | 3 | 12 | First |
| CRM accounts, read, through a vendor-hosted server | 3 | 3 | 3 | 2 | 11 | First |
| Service desk tickets, create and update | 3 | 2 | 3 | 2 | 10 | Second |
| Curated warehouse views for finance | 2 | 3 | 2 | 2 | 9 | Second |
| ERP purchase requisitions, create | 3 | 2 | 2 | 2 | 9 | Second, with approval above a set amount |
| Supplier payment release | 2 | 1 | 2 | 1 | 6 | Wait |
Two rules sit on top of the score. A tool that is absent from the server cannot be called, so the safest treatment for an irreversible action in the early waves is to leave it out. And count the tools: descriptions are typically loaded into the model's context, so sixty loosely named tools cost tokens and accuracy on every turn, while a handful of task-shaped ones are easier to test and review.
- Wave 1: readKnowledge, CRM and ticket lookups through the gateway, as the requesting user.Moves on when every call is traced and the gateway has blocked an out-of-policy call in testing.
- Wave 2: reversible writesDrafts, field updates and new tickets, each with an idempotency key and an undo.Moves on when the error rate on your graded cases stays under the owner's target.
- Wave 3: irreversible actionsPayments, deletions and customer messages, held for a named approver inside the call.Limits widen only on measured results.
- Wave 4: other agentsA2A links to agents you do not control, under a written task contract.Starts when both sides can verify identity and trace a task across the boundary.
Vendor-hosted MCP servers vs building your own
Use the vendor's hosted MCP server where one exists and covers the task, because it enforces the permissions you already maintain; build your own where you need task-shaped tools, logic that spans systems, or a system with no vendor offering. Most estates end up with both, behind one gateway.
Salesforce made its hosted MCP servers generally available in April 2026 for Enterprise Edition orgs and above. Access runs through OAuth with PKCE, every transaction runs as the authenticated user with no anonymous service account, and object permissions, field-level security and sharing rules still apply.9 That is the reason to prefer it: the permission model your Salesforce administrators maintain becomes the agent's, and a change there needs no change in the agent.
SAP's guidance, updated in June 2026, is more guarded. It permits third-party MCP servers to call SAP APIs provided its API Policy is followed in full, and offers managed alternatives: an MCP gateway in SAP Integration Suite that creates MCP servers from your existing APIs, and servers generated by its agent-building tools.10 If you run your own server against SAP, it expects authentication on every call, parameter validation, rate limits that protect API quotas from runaway agent loops, and a log of every invocation.10 That list is the scope of work for any server you build.
Vendor-hosted server
Offered by the system's vendor
- Applies each user's existing permissions in the system
- Protocol upgrades are the vendor's job
- Tools follow the vendor's object model, one system at a time
- Terms, limits and roadmap are set by the vendor
Your own server
Built on the system's API
- Tools shaped around your business tasks
- One tool can combine several systems
- You own authentication, validation, rate limits, logs and spec upgrades
- Must follow each vendor's API terms
Is MCP secure? The risks a CISO should control
MCP is as secure as the controls around it. The failures seen so far come from five places, and each has a known control.
- Unauthenticated servers Research published in July 2025 found 492 MCP servers with no client authentication or traffic encryption; by April 2026 exposed servers had nearly tripled to 1,467, and 70 hosts offered a tool that executes SQL.11 Control: servers are reachable only through the gateway.
- Over-broad scopes The specification asks for least privilege: a minimal scope set up front, with more granted through step-up authorization when a privileged tool is first used.4 Control: a scope per tool, reviewed in the registry.
- Tool poisoning Researchers showed in April 2025 that instructions hidden in a tool's description, invisible to the user but read by the model, can steer an agent into leaking data, and that a server can change a description after approval.12 The specification says tool annotations are untrusted unless they come from a trusted server.3 Control: pin description hashes in the registry and block any server whose descriptions change until reviewed.
- Token passthrough MCP servers must accept only tokens issued for themselves and must not pass any other token on.4 SAP adds that forwarding the caller's token hands the server the user's full permissions and breaks audit attribution, and points to OAuth token exchange (RFC 8693) instead.10 Control: the gateway checks the audience on every call.
- Shadow servers Local servers on developer laptops sit outside the OAuth flow: the specification tells STDIO servers to take credentials from the environment.4 Control: managed clients that load only registered servers, and a regular scan for the rest.
These controls cover the connection layer. Our AI agent security guide sets out the threat model for the agent itself and the controls a CISO should require.
Before any MCP server goes live
- It is in the private registry with a named owner, a data classification and a review date.
- It is reachable only through the gateway, which rejects tokens issued for any other audience.
- Each tool has its own scope; irreversible actions are absent or held for approval.
- Tool descriptions are pinned by hash, and a change blocks the server until reviewed.
- Writes carry idempotency keys, so a retried request cannot land twice.
- Every call carries a trace id and is logged with caller, tool, redacted parameters, status and latency.
- Someone has tried to break it with injected content, a poisoned description and a stolen token.
Who governs MCP and A2A, and where lock-in sits
Both protocols sit under the Linux Foundation: MCP through the Agentic AI Foundation since December 2025, and A2A as a Linux Foundation project.78 MCP now has a formal feature lifecycle with a minimum twelve-month deprecation window, so a deprecated feature keeps working for at least a year after notice and upgrades can be scheduled.12
Neutral protocols move the lock-in question up a layer, to the tool designs your team writes, the gateway and registry product you choose, and the terms of any vendor-hosted server. Keep the first two as your own assets: tool schemas and descriptions in your repository, registry entries and gateway policies as exportable configuration. Test servers against both a frontier model and an open-weights model, so changing the model never forces a change to the integration.
The protocol is settled enough to build on, and the architecture around it is familiar. In our AI agent development work, the gateway, registry, identity and audit layers go in before the first server goes live, the first wave is read access as the requesting user, and agents are allowed to do more only as the traces show they can be trusted with it.
Questions leaders ask
What is an MCP server?
An MCP server is a small service that exposes one system's capabilities to AI agents through the Model Context Protocol. It describes each tool, data resource and prompt in a schema the model can read, and translates each call into that system's own API.3 One server for your CRM can serve every MCP-capable agent you run, provided it sits behind your gateway and identity controls.
What is the difference between MCP and A2A?
MCP connects an agent to tools and data; A2A connects an agent to other agents. Use MCP when an agent needs to read or act on a system, such as looking up an account or opening a ticket. Use A2A when an agent hands a whole task to another agent that plans its own steps, typically one owned by another team or company.8
Is MCP secure?
Yes, when it runs behind the right controls. Authorization is optional in the specification, and the specification states that MCP cannot enforce its security principles at the protocol level.43 Security comes from the layers around it: a gateway every call must pass, a private registry of approved servers, audience-bound tokens from your identity provider, least-privilege scopes, pinned tool descriptions and a trace of every call.
What is the difference between MCP and an API?
An API is how a system exposes functions to software; MCP is how an AI agent discovers and calls functions at run time. An MCP server usually sits in front of an existing API and adds what a model needs: descriptions it can read, typed inputs and a standard way to find tools. The API's permissions, validation and limits still decide what is safe.10
Does MCP replace RAG?
No. RAG is a technique for retrieving passages from your documents so a model can ground its answer in them; MCP is a protocol for connecting agents to tools and data. They work together: a retrieval service can be exposed as an MCP tool, so retrieval runs under the same identity, gateway and audit trail as every other call. Answer quality still depends on the retrieval pipeline.
Does Salesforce have an MCP server?
Yes. Salesforce made hosted MCP servers generally available in April 2026 for Enterprise Edition orgs and above. Every transaction runs as the authenticated user, so object permissions, field-level security and sharing rules apply to the agent exactly as they apply to that person.9 Register it in your private registry and route it through your gateway like any other server.
Sources
- The 2026-07-28 SpecificationModel Context Protocol Blog, July 28, 2026
- Key Changes (specification version 2026-07-28)Model Context Protocol
- Specification (version 2026-07-28)Model Context Protocol
- Authorization (version 2026-07-28)Model Context Protocol
- Enterprise-Managed AuthorizationModel Context Protocol, official extension
- The MCP RegistryModel Context Protocol
- MCP joins the Agentic AI FoundationModel Context Protocol Blog, December 9, 2025
- A2A Protocol Surpasses 150 Organizations, Lands in Major Cloud Platforms, and Sees Enterprise Production Use in First YearLinux Foundation, April 9, 2026
- Salesforce Hosted MCP Servers Are Now Generally AvailableSalesforce Developers Blog, April 2026
- Third-Party MCP Access to SAP SolutionsSAP Architecture Center, updated June 8, 2026
- Update on Exposed MCP Servers: The Threat Widens to the CloudTrendAI, April 28, 2026
- MCP Security Notification: Tool Poisoning AttacksInvariant Labs, April 1, 2025
Written by DigyAi Engineering from the systems we build and run. Every figure links to its public source, and every link and figure was checked on September 26, 2026. No client data appears in our insights.