AI agents Guide

MCP and A2A in the Enterprise: How AI Agents Reach Your Systems

MCP is how an agent reaches your systems, and A2A is how it reaches other agents. Since the July 2026 specification, MCP runs like any other API tier, so the enterprise work is governance: one gateway, a private registry, identities from your identity provider, a trace of every call, and a short list of systems opened first.

For CTOs and CISOs deciding how AI agents will connect to SAP, Salesforce and the rest of the estate, and which systems to open to them first.

Published
Reviewed
Reading time
16 min

The short answer

Enterprise MCP means connecting AI agents to company systems through the Model Context Protocol, the open standard for exposing tools and data to agents, and running it behind your own gateway, private registry, identity provider and audit trail. A2A is the companion standard for one agent delegating work to another. Since the 2026-07-28 specification, MCP is stateless and runs like any other API tier.1

Key takeaways

  • MCP connects an agent to tools and data; A2A connects an agent to other agents. Most enterprises need MCP first, and A2A only when work must pass to an agent they do not control.
  • The 2026-07-28 specification removed sessions and put the method and tool name in HTTP headers, so MCP servers scale behind ordinary load balancers and a gateway can apply policy tool by tool.2
  • Authorization is optional in the protocol, which cannot enforce its own security principles, so the controls belong in your gateway, registry and identity provider.34
  • Score every candidate system on value, read versus write, API quality and data sensitivity. Read access to knowledge, CRM and tickets goes first; payments and regulated data wait.
  • Where the vendor offers a hosted MCP server, start there: Salesforce's runs every call as the authenticated user, with the permissions your administrators already maintain.9

Every agent program reaches the point where the agent must read the account in Salesforce, check the order in SAP and open the ticket in ServiceNow, as the person who asked. The Model Context Protocol (MCP) is the open standard for those connections; the Agent2Agent protocol (A2A) is the open standard for one agent to hand work to another.

  • ~500Mmonthly downloads of MCP's main SDKs by July 20261
  • 150+organizations supporting the A2A protocol at its first anniversary in April 20268
  • 1,467MCP servers found exposed on the internet in April 2026, nearly triple the July 2025 count11

What MCP is and what an MCP server does

MCP is an open protocol that defines how an AI application discovers and calls tools and reads data held in other systems.3 It has three roles: the host is the AI application, a client inside the host holds each connection, and a server exposes capabilities. A server offers three kinds of capability: tools the model can call, resources that supply data, and prompts that package common workflows. Every message is JSON-RPC 2.0.3

An MCP server is a thin adapter in front of a system you already run. It describes each capability in a schema the model can read and translates each call into that system's own API. Build one server for your CRM and every MCP-capable agent and tool in the company can use it, so integrations stop multiplying with every new agent.

Adoption has been fast: more than 97 million monthly SDK downloads in December 2025, close to half a billion a month by July 2026.71 About a year after its release, the lab that introduced MCP donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, which does not dictate the protocol's technical direction; that stays with its maintainers.7

What A2A is and when you need it

A2A (Agent2Agent) is an open protocol that lets AI agents discover, communicate and transact with each other across frameworks, vendors and platforms.8 Where MCP connects an agent to tools, A2A connects agents to agents: the calling agent hands over a task, and the receiving agent plans the work and uses its own tools to do it.

A2A is hosted by the Linux Foundation. By its first anniversary in April 2026, its supporting organizations had grown from more than 50 to over 150, including Salesforce, SAP and ServiceNow.8 Version 1.0, its first stable specification, added multi-tenancy and modernized security flows, and the protocol supports signed Agent Cards, so an agent's published description of itself can be verified cryptographically.8

Most enterprises need MCP first. A2A earns its place when an agent must hand work to one you do not build or control: a supplier's agent, an agent inside a SaaS platform, or another business unit's agent with its own release cycle. SAP's guidance draws the same line, sending multi-agent scenarios that cross system and vendor boundaries to A2A.10 Inside one team's system, an agent calling a sub-agent is ordinary code.

MCP vs A2A vs APIs vs RAG

They work at different layers: an API is how a system exposes functions, MCP is how an agent discovers and calls those functions, A2A is how an agent delegates to another agent, and RAG is a technique for retrieving documents to ground a model's answer. A production agent often uses all four.

What it isConnectsUse it whenWhat it leaves to you
APIThe contract a system publishes for other softwareApplication to systemCode knows in advance which call to makeNothing new: an MCP server calls it
MCPAn open protocol for agents to discover and call tools and read dataAgent to tools and dataAn agent must choose among capabilities at run timeAuthorization, tool design, gateway and audit
A2AAn open protocol for agents to delegate tasks to other agentsAgent to agentWork crosses a team, vendor or company boundaryTrust between organizations and task contracts
RAGA technique: retrieve relevant passages, then answer from themModel to documentsAnswers must come from your documents, with citationsIndex quality, document permissions and evaluation
The four are complementary. An MCP server usually calls an API, and a retrieval service is often exposed to agents as an MCP tool.

Two misreadings are common. The first treats MCP as a replacement for APIs. An MCP server calls your APIs, so every weakness in them (coarse permissions, missing validation, no rate limits) reaches the agent unchanged. The second expects MCP to make agents understand your business. SAP's reference architecture is blunt: "MCP is a connectivity protocol" that adds no business context. Wiring it straight to raw transactional APIs, SAP warns, brings poor entity discovery, heavy token use and, on writes, a significant risk of incorrect business transactions.10

RAG and MCP meet in the middle. A retrieval service over your policies and contracts can be offered to agents as an MCP tool, behind the same identity, gateway and logs as every other call. Answer quality still depends on the pipeline; see Enterprise RAG in production.

What the 2026-07-28 MCP specification changed

The revision published on July 28, 2026 made MCP stateless, made its traffic routable by standard HTTP infrastructure, hardened authorization and moved long-running work into an official Tasks extension.1 The changes that matter in production, from the release notes and changelog:12

ChangeWhat it replacedWhat it means for operations
No sessions and no initialize handshake; every request carries its own protocol version and capabilitiesSession ids, sticky sessions, a shared session storeServers scale behind a plain round-robin load balancer. State between calls travels as a server-issued handle, secured like a session token
Mcp-Method and Mcp-Name headers required on HTTP requestsGateways parsing the JSON bodyA gateway can route, rate-limit and authorize each tool by name
Multi round-trip requests: a server answers "input required" and the client retries with the answerServer-initiated requests over held-open streamsAn approval step in the middle of a call works in a stateless deployment
Tasks moved into the official io.modelcontextprotocol/tasks extension, driven by pollingAn experimental core featureLong-running jobs get a standard handle to poll, update or cancel
Issuer validation (RFC 9207), Client ID Metadata Documents preferred, credentials bound to their issuerDynamic Client Registration, now deprecatedClients reject an authorization code from an unexpected issuer; clients relying on dynamic registration need a migration plan
Roots, Sampling, Logging and the HTTP+SSE transport deprecated, with at least twelve months' noticeNo formal deprecation policyInventory servers that use them; move logging to OpenTelemetry
Our reading of the 2026-07-28 changelog for teams that run MCP in production.

Two details matter more than they look. A broken response stream now loses the in-flight request, and the client must resend it as a new request, so every tool that writes needs an idempotency key or a retried write can land twice.2 And the specification now documents how OpenTelemetry trace context travels in each request, so one trace can follow a task from the agent through the gateway into the system of record.2 The official TypeScript, Python, Go and C# SDKs support the revision, with Rust in beta.1

Enterprise MCP reference architecture: gateway, registry, identity and audit

Run MCP the way you run any API tier: agents reach tools only through a gateway, see only servers in your private registry, act with identities from your identity provider, and leave a trace of every call. The protocol will not do this for you. Authorization is optional in the specification, which says MCP cannot enforce its security principles at the protocol level.43

ComponentIts jobWhat to requireOwner
GatewayThe single path from any agent to any MCP server, in your cloud account or your data centerToken validation on every call; per-tool policy and rate limits keyed on the Mcp-Name header; unregistered servers denied; egress limited to each server's own systemPlatform or API team
Private registryThe approved servers, versions and toolsOwner, data classification and scopes per server; a pinned hash of every tool description; a review dateEnterprise architecture, with security sign-off
IdentityWho the agent acts for, with what rightsTokens from your identity provider, bound to one server; none forwarded downstream; the user's own permissions applied at the system of recordIdentity and access management
AuditEvidence of every call, replayable laterA trace id end to end; caller, tool, redacted parameters, target API, status and latency on every callSecurity operations
The four control points: the controls you already apply to APIs, pointed at a new kind of caller.

The public MCP Registry does not replace your own. It is in preview, holds metadata only for publicly accessible servers, does not accept private ones and leaves security scanning to others; the project recommends a private registry for internal servers, which can implement the public registry's OpenAPI interface.6 An entry needs little more than this:

# One entry in the private MCP registry. The gateway refuses any server or tool not listed.
server: crm-accounts
owner: sales-operations              # a named team, reviewed every quarter
endpoint: https://mcp.internal.example.com/crm
protocol: "2026-07-28"
data_class: confidential
auth:
  issuer: https://idp.example.com    # your identity provider
  audience: https://mcp.internal.example.com/crm
tools:
  - name: get_account                # read
    scope: crm.accounts.read
    description_sha256: 3f9a0c...    # a changed description blocks the server until reviewed
  - name: log_call_note              # reversible write
    scope: crm.activities.write
    idempotency: required
    rate_limit: 60/min
  # close_account is irreversible and deliberately absent
next_review: 2026-12-31
A sketch of a registry entry. The fields matter more than the format.

Identity is where the 2026 extensions help most. With the Enterprise-Managed Authorization extension, your identity provider checks group membership, roles and conditional access, then issues the MCP client a signed grant (an ID-JAG) that it exchanges for an access token.5 IT grants access from one console, and removing a person at the identity provider revokes their access across every MCP client. Client support varies and the extension is off by default, so confirm it for each client you allow.5

For audit, SAP's guidance makes a good minimum everywhere: log every tool invocation with the caller's identity, parameters with personal data redacted, the target API, response status and latency.10

Which systems to expose through MCP first

Expose first the systems that score high on business value and API quality and low on write risk and data sensitivity. In most estates that means read access to knowledge bases, CRM records and service tickets, well ahead of writes to ERP, payroll or payments. Score each candidate from 1 to 3 on four criteria, where 3 always favors going early, and add the scores.

Criterion3: expose early2: expose with controls1: wait
Business valueNeeded in many tasks a week; people switch screens to get it todayNeeded weekly by one teamOccasional or unproven demand
Read or writeRead onlyReversible writes: drafts, field updates, new ticketsIrreversible writes: payments, deletions, messages to customers
API qualityA vendor-hosted MCP server, or a documented, versioned API with fine-grained scopesA usable API with coarse scopesNo API: screen automation or direct database access
Data sensitivityInternal, non-personal dataConfidential business dataRegulated personal, health, card or market-sensitive data
The scoring grid. Totals of 11 or 12 go in the first wave; 8 to 10 follow once the gateway and traces are proven; 7 or below wait for approvals and a named owner.
CandidateValueRead or writeAPISensitivityTotalWave
Policy and knowledge base search333312First
CRM accounts, read, through a vendor-hosted server333211First
Service desk tickets, create and update323210Second
Curated warehouse views for finance23229Second
ERP purchase requisitions, create32229Second, with approval above a set amount
Supplier payment release21216Wait
An example scoring for a typical estate. Yours will differ; scoring every candidate the same way is what matters.

Two rules sit on top of the score. A tool that is absent from the server cannot be called, so the safest treatment for an irreversible action in the early waves is to leave it out. And count the tools: descriptions are typically loaded into the model's context, so sixty loosely named tools cost tokens and accuracy on every turn, while a handful of task-shaped ones are easier to test and review.

Exhibit 1Open systems to agents in waves
  1. Wave 1: readKnowledge, CRM and ticket lookups through the gateway, as the requesting user.Moves on when every call is traced and the gateway has blocked an out-of-policy call in testing.
  2. Wave 2: reversible writesDrafts, field updates and new tickets, each with an idempotency key and an undo.Moves on when the error rate on your graded cases stays under the owner's target.
  3. Wave 3: irreversible actionsPayments, deletions and customer messages, held for a named approver inside the call.Limits widen only on measured results.
  4. Wave 4: other agentsA2A links to agents you do not control, under a written task contract.Starts when both sides can verify identity and trace a task across the boundary.
Each wave reuses the gateway, registry, identity and audit built for the first.

Vendor-hosted MCP servers vs building your own

Use the vendor's hosted MCP server where one exists and covers the task, because it enforces the permissions you already maintain; build your own where you need task-shaped tools, logic that spans systems, or a system with no vendor offering. Most estates end up with both, behind one gateway.

Salesforce made its hosted MCP servers generally available in April 2026 for Enterprise Edition orgs and above. Access runs through OAuth with PKCE, every transaction runs as the authenticated user with no anonymous service account, and object permissions, field-level security and sharing rules still apply.9 That is the reason to prefer it: the permission model your Salesforce administrators maintain becomes the agent's, and a change there needs no change in the agent.

SAP's guidance, updated in June 2026, is more guarded. It permits third-party MCP servers to call SAP APIs provided its API Policy is followed in full, and offers managed alternatives: an MCP gateway in SAP Integration Suite that creates MCP servers from your existing APIs, and servers generated by its agent-building tools.10 If you run your own server against SAP, it expects authentication on every call, parameter validation, rate limits that protect API quotas from runaway agent loops, and a log of every invocation.10 That list is the scope of work for any server you build.

Exhibit 2Vendor-hosted or your own MCP server

Vendor-hosted server

Offered by the system's vendor

  • Applies each user's existing permissions in the system
  • Protocol upgrades are the vendor's job
  • Tools follow the vendor's object model, one system at a time
  • Terms, limits and roadmap are set by the vendor

Your own server

Built on the system's API

  • Tools shaped around your business tasks
  • One tool can combine several systems
  • You own authentication, validation, rate limits, logs and spec upgrades
  • Must follow each vendor's API terms
Neither column wins everywhere. The gateway, registry and identity layer are the same for both.

Is MCP secure? The risks a CISO should control

MCP is as secure as the controls around it. The failures seen so far come from five places, and each has a known control.

  • Unauthenticated servers Research published in July 2025 found 492 MCP servers with no client authentication or traffic encryption; by April 2026 exposed servers had nearly tripled to 1,467, and 70 hosts offered a tool that executes SQL.11 Control: servers are reachable only through the gateway.
  • Over-broad scopes The specification asks for least privilege: a minimal scope set up front, with more granted through step-up authorization when a privileged tool is first used.4 Control: a scope per tool, reviewed in the registry.
  • Tool poisoning Researchers showed in April 2025 that instructions hidden in a tool's description, invisible to the user but read by the model, can steer an agent into leaking data, and that a server can change a description after approval.12 The specification says tool annotations are untrusted unless they come from a trusted server.3 Control: pin description hashes in the registry and block any server whose descriptions change until reviewed.
  • Token passthrough MCP servers must accept only tokens issued for themselves and must not pass any other token on.4 SAP adds that forwarding the caller's token hands the server the user's full permissions and breaks audit attribution, and points to OAuth token exchange (RFC 8693) instead.10 Control: the gateway checks the audience on every call.
  • Shadow servers Local servers on developer laptops sit outside the OAuth flow: the specification tells STDIO servers to take credentials from the environment.4 Control: managed clients that load only registered servers, and a regular scan for the rest.

These controls cover the connection layer. Our AI agent security guide sets out the threat model for the agent itself and the controls a CISO should require.

Before any MCP server goes live

  • It is in the private registry with a named owner, a data classification and a review date.
  • It is reachable only through the gateway, which rejects tokens issued for any other audience.
  • Each tool has its own scope; irreversible actions are absent or held for approval.
  • Tool descriptions are pinned by hash, and a change blocks the server until reviewed.
  • Writes carry idempotency keys, so a retried request cannot land twice.
  • Every call carries a trace id and is logged with caller, tool, redacted parameters, status and latency.
  • Someone has tried to break it with injected content, a poisoned description and a stolen token.

Who governs MCP and A2A, and where lock-in sits

Both protocols sit under the Linux Foundation: MCP through the Agentic AI Foundation since December 2025, and A2A as a Linux Foundation project.78 MCP now has a formal feature lifecycle with a minimum twelve-month deprecation window, so a deprecated feature keeps working for at least a year after notice and upgrades can be scheduled.12

Neutral protocols move the lock-in question up a layer, to the tool designs your team writes, the gateway and registry product you choose, and the terms of any vendor-hosted server. Keep the first two as your own assets: tool schemas and descriptions in your repository, registry entries and gateway policies as exportable configuration. Test servers against both a frontier model and an open-weights model, so changing the model never forces a change to the integration.

The protocol is settled enough to build on, and the architecture around it is familiar. In our AI agent development work, the gateway, registry, identity and audit layers go in before the first server goes live, the first wave is read access as the requesting user, and agents are allowed to do more only as the traces show they can be trusted with it.

Questions leaders ask

What is an MCP server?

An MCP server is a small service that exposes one system's capabilities to AI agents through the Model Context Protocol. It describes each tool, data resource and prompt in a schema the model can read, and translates each call into that system's own API.3 One server for your CRM can serve every MCP-capable agent you run, provided it sits behind your gateway and identity controls.

What is the difference between MCP and A2A?

MCP connects an agent to tools and data; A2A connects an agent to other agents. Use MCP when an agent needs to read or act on a system, such as looking up an account or opening a ticket. Use A2A when an agent hands a whole task to another agent that plans its own steps, typically one owned by another team or company.8

Is MCP secure?

Yes, when it runs behind the right controls. Authorization is optional in the specification, and the specification states that MCP cannot enforce its security principles at the protocol level.43 Security comes from the layers around it: a gateway every call must pass, a private registry of approved servers, audience-bound tokens from your identity provider, least-privilege scopes, pinned tool descriptions and a trace of every call.

What is the difference between MCP and an API?

An API is how a system exposes functions to software; MCP is how an AI agent discovers and calls functions at run time. An MCP server usually sits in front of an existing API and adds what a model needs: descriptions it can read, typed inputs and a standard way to find tools. The API's permissions, validation and limits still decide what is safe.10

Does MCP replace RAG?

No. RAG is a technique for retrieving passages from your documents so a model can ground its answer in them; MCP is a protocol for connecting agents to tools and data. They work together: a retrieval service can be exposed as an MCP tool, so retrieval runs under the same identity, gateway and audit trail as every other call. Answer quality still depends on the retrieval pipeline.

Does Salesforce have an MCP server?

Yes. Salesforce made hosted MCP servers generally available in April 2026 for Enterprise Edition orgs and above. Every transaction runs as the authenticated user, so object permissions, field-level security and sharing rules apply to the agent exactly as they apply to that person.9 Register it in your private registry and route it through your gateway like any other server.

Sources

  1. The 2026-07-28 SpecificationModel Context Protocol Blog, July 28, 2026
  2. Key Changes (specification version 2026-07-28)Model Context Protocol
  3. Specification (version 2026-07-28)Model Context Protocol
  4. Authorization (version 2026-07-28)Model Context Protocol
  5. Enterprise-Managed AuthorizationModel Context Protocol, official extension
  6. The MCP RegistryModel Context Protocol
  7. MCP joins the Agentic AI FoundationModel Context Protocol Blog, December 9, 2025
  8. A2A Protocol Surpasses 150 Organizations, Lands in Major Cloud Platforms, and Sees Enterprise Production Use in First YearLinux Foundation, April 9, 2026
  9. Salesforce Hosted MCP Servers Are Now Generally AvailableSalesforce Developers Blog, April 2026
  10. Third-Party MCP Access to SAP SolutionsSAP Architecture Center, updated June 8, 2026
  11. Update on Exposed MCP Servers: The Threat Widens to the CloudTrendAI, April 28, 2026
  12. MCP Security Notification: Tool Poisoning AttacksInvariant Labs, April 1, 2025

Written by DigyAi Engineering from the systems we build and run. Every figure links to its public source, and every link and figure was checked on September 26, 2026. No client data appears in our insights.

Read next

All insights
  • An AI agent on its own tower reads web pages, email and tool text from an island outside; every action it plans passes through a lit policy engine, which lets calls to the company's systems through and stops a call to send data out at a lowered barrier. A kill switch is wired to the agent at the front.

    Security, risk and compliance Guide

    AI Agent Security: The Threat Model and Controls a CISO Should Require

    For CISOs and security architects deciding whether an AI agent is safe to connect to production systems, company data and customers.

    16 min read

  • A chatbot on its own small island answers on a screen, and its only lane ends at a red stop at the island's edge; on the main plinth an AI agent tower cancels the order, queues the refund, notifies the customer and logs each step, every system ticked.

    AI agents Explainer

    AI Agents vs Chatbots vs Agentic AI: What Actually Differs

    For CTOs and business owners deciding whether a workflow needs an AI agent, a chatbot or plain automation before they fund the build.

    16 min read

  • A person's question enters a lit retrieval hall at the centre of a plinth, which searches the company's document sources as that person, while one walled-off source has its lane barred in red. Only a few passages travel on to a small model, and every line of the answer carries a citation back to its source.

    LLM and RAG engineering Playbook

    Enterprise RAG in Production: Why Pilots Stall and What Fixes Them

    For CTOs deciding whether a RAG pilot that impressed in the demo can be trusted with real users, real permissions and real data.

    16 min read

Get in touch

Tell us what you are building.

Write it as big as you imagine it.