# How MCP works

> The protocol underneath all of this: tool discovery, authorization, credentials, and the parts of the specification that are still moving.

- [Enterprise MCP: a buyer's guide for IT teams](https://elaichi.ai/blog/enterprise-mcp/) — Enterprise MCP for buyers: what changes when MCP goes from one laptop to a whole company, and what to ask a vendor before you sign.
- [MCP for coding agents across an engineering org](https://elaichi.ai/blog/coding-agents-company-tools/) — MCP for coding agents needs one endpoint, a sign-in per engineer, and rules the agent cannot edit, because nobody reads each call it makes.
- [What is an MCP control plane, and who needs one?](https://elaichi.ai/blog/what-is-an-mcp-control-plane/) — An MCP control plane is one org-wide MCP endpoint that serves the tools, signs each person in and decides access on every call.
- [How MCP tool search picks one tool from hundreds](https://elaichi.ai/blog/search-tools-ranking-floor-idf/) — MCP tool search in Elaichi scores tools by matching words, then returns nothing unless a tool covers at least half the query, with rare words weighted most.
- [The MCP context window problem, and a fix](https://elaichi.ai/blog/context-window-problem-mcp-tools/) — The MCP context window problem: each listed tool sits in the model's prompt on every turn. Elaichi lists no connected tools; the model searches for them.
- [What is an MCP gateway? The four shapes](https://elaichi.ai/blog/what-is-an-mcp-gateway/) — What is an MCP gateway: one address between AI clients and their tools that signs people in, applies rules and records calls. It comes in four shapes.
- [MCP server registry vs first-party connectors](https://elaichi.ai/blog/mcp-registry-vs-first-party-connectors/) — MCP server registry vs first-party connectors comes down to who fixes a broken tool: each server's own author, or one vendor that wrote and serves them.
- [OAuth or API keys for AI agents?](https://elaichi.ai/blog/oauth-vs-api-keys-for-ai-agents/) — Choosing OAuth or API keys for AI agents comes down to revocation: a grant is checked on every call, while a key works until someone rotates it.
