# What Is the Model Context Protocol (MCP) in OpenAI Plugins: A Complete Technical Guide

> Discover the Model Context Protocol (MCP) in OpenAI plugins. Learn how this HTTP interface lets language models access external resources via search and execute operations. A complete technical guide.

- Repository: [OpenAI/plugins](https://github.com/openai/plugins)
- Tags: deep-dive
- Published: 2026-09-13

---

**The Model Context Protocol (MCP) is a lightweight, HTTP-based interface that enables language models to retrieve and invoke external resources directly from a plugin's runtime through standardized `search` and `execute` operations.**

The `openai/plugins` repository implements MCP as a universal bridge between AI agents and external services like Cloudflare, Supabase, and Vercel. By declaring MCP servers in simple JSON configuration files, plugins expose a consistent RPC interface that eliminates the need for custom SDKs while maintaining strict authentication controls.

## Core Architecture of the Model Context Protocol

The Model Context Protocol defines a minimal contract between AI agents and service APIs. Rather than implementing bespoke integration logic for each provider, MCP standardizes all interactions around two fundamental remote procedure calls.

### The Search and Execute RPC Pattern

Every MCP server exposes exactly two operations:

- **`search`** – Accepts natural-language queries or structured parameters and returns matching items from the service (such as Cloudflare zones, Supabase projects, or Granola meetings)
- **`execute`** – Performs actions on specific objects returned by `search` (such as updating DNS records, creating database tables, or fetching meeting details)

This dichotomy separates data retrieval from data mutation, allowing language models to first discover available resources contextually before attempting modifications.

### MCP Server Configuration via .mcp.json

In the `openai/plugins` repository, each plugin declares its MCP servers in a `*.mcp.json` file. The configuration schema requires only three fields:

```json
{
  "mcpServers": {
    "<server-id>": {
      "type": "http",
      "url": "<base-endpoint>",
      "note": "<human-readable description>"
    }
  }
}

```

For example, [`plugins/cloudflare/.mcp.json`](https://github.com/openai/plugins/blob/main/plugins/cloudflare/.mcp.json) defines the Cloudflare API integration:

```json
{
  "mcpServers": {
    "cloudflare-api": {
      "type": "http",
      "url": "https://mcp.cloudflare.com/mcp",
      "note": "Official Cloudflare API MCP server. Uses OAuth on first connection, with optional bearer-token auth for automation. Provides token-efficient access to the Cloudflare API via search() and execute()."
    }
  }
}

```

The plugin manifest at [`plugins/cloudflare/.codex-plugin/plugin.json`](https://github.com/openai/plugins/blob/main/plugins/cloudflare/.codex-plugin/plugin.json) references this configuration via the `"mcpServers": "./.mcp.json"` field, linking the plugin to its runtime context providers.

## How MCP Servers Work in Practice

When an AI skill requires data from a service, it constructs a JSON-RPC-style POST request to the MCP endpoint. The protocol's HTTP-native design means any language model can interact with it through standard tool interfaces without additional dependencies.

### Search Operation Example

To retrieve Cloudflare zones, the agent sends:

```json
{
  "type": "search",
  "server": "cloudflare-api",
  "query": "list zones for example.com"
}

```

The MCP server responds with structured data, including identifiers necessary for subsequent operations.

### Execute Operation Example

After identifying a target resource, the agent invokes actions using:

```json
{
  "type": "execute",
  "server": "cloudflare-api",
  "action": "updateZone",
  "parameters": { "zoneId": "...", "setting": "tls_1_3", "value": true }
}

```

This pattern appears consistently across the repository, from [`plugins/cloudflare/skills/building-mcp-server-on-cloudflare/SKILL.md`](https://github.com/openai/plugins/blob/main/plugins/cloudflare/skills/building-mcp-server-on-cloudflare/SKILL.md) (which documents building remote MCP servers on Cloudflare Workers) to [`plugins/vercel/skills/nextjs/references/debug-tricks.md`](https://github.com/openai/plugins/blob/main/plugins/vercel/skills/nextjs/references/debug-tricks.md) (which references the built-in `_next/mcp` endpoint for AI-assisted debugging).

## Building and Consuming MCP Endpoints

Because MCP is a pure HTTP API, client implementations require only standard networking libraries.

### Python Client Implementation

The following snippet demonstrates interaction with an MCP server using the Cloudflare configuration from [`plugins/cloudflare/.mcp.json`](https://github.com/openai/plugins/blob/main/plugins/cloudflare/.mcp.json):

```python
import requests

MCP_URL = "https://mcp.cloudflare.com/mcp"   # from .mcp.json

def mcp_search(query: str):
    resp = requests.post(
        MCP_URL,
        json={"type": "search", "query": query}
    )
    resp.raise_for_status()
    return resp.json()["results"]

def mcp_execute(action: str, **params):
    resp = requests.post(
        MCP_URL,
        json={"type": "execute", "action": action, "parameters": params}
    )
    resp.raise_for_status()
    return resp.json()["result"]

```

### Skill Integration Pattern

Agents combine these primitives to perform multi-step workflows. This example from the Cloudflare skill demonstrates the canonical search-then-execute flow documented in [`plugins/cloudflare/skills/cloudflare/references/agents-sdk/api.md`](https://github.com/openai/plugins/blob/main/plugins/cloudflare/skills/cloudflare/references/agents-sdk/api.md):

```python
def list_zones(domain: str):
    # 1️⃣ Search for zones matching the domain

    zones = mcp_search(f"list zones for {domain}")
    # 2️⃣ Pick the first match (or apply additional filtering)

    zone_id = zones[0]["id"]
    # 3️⃣ Execute an action on the chosen zone

    details = mcp_execute("getZoneDetails", zoneId=zone_id)
    return details

```

## Security and Extensibility Benefits

The Model Context Protocol provides four critical advantages for plugin development:

- **Uniformity** – All plugins expose identical `search` and `execute` methods regardless of underlying service complexity, reducing the learning curve for AI agents
- **Context-awareness** – Models request only necessary data, minimizing token consumption compared to broad API scraping
- **Security** – MCP servers enforce authentication via OAuth or bearer tokens at the HTTP layer, with rate limiting applied at the endpoint level
- **Extensibility** – Adding new services requires only a [`.mcp.json`](https://github.com/openai/plugins/blob/main/.mcp.json) descriptor and thin API wrappers, as demonstrated by the minimal configuration footprint in the Cloudflare and Vercel plugins

## Summary

- The **Model Context Protocol (MCP)** standardizes AI-service interactions through HTTP-based `search` and `execute` RPC calls.
- Plugins declare MCP servers in [`.mcp.json`](https://github.com/openai/plugins/blob/main/.mcp.json) files (such as [`plugins/cloudflare/.mcp.json`](https://github.com/openai/plugins/blob/main/plugins/cloudflare/.mcp.json)) and reference them in [`plugin.json`](https://github.com/openai/plugins/blob/main/plugin.json) manifests.
- The protocol requires no custom SDKs—standard HTTP clients suffice for implementation.
- MCP enables token-efficient, authenticated, context-aware access to external APIs across the OpenAI Plugins ecosystem.

## Frequently Asked Questions

### What is the difference between MCP and traditional REST API integration?

Traditional REST integrations require AI models to manage endpoint URLs, HTTP methods, and payload structures for each service individually. MCP abstracts these behind the consistent `search` and `execute` operations, allowing models to interact with Cloudflare, Supabase, or Vercel using identical calling conventions while the MCP server handles translation to service-specific REST calls.

### How does authentication work in the Model Context Protocol?

MCP servers handle authentication at the HTTP layer, typically through OAuth flows on initial connection or bearer tokens for automated access. The [`plugins/cloudflare/.mcp.json`](https://github.com/openai/plugins/blob/main/plugins/cloudflare/.mcp.json) configuration explicitly notes this dual authentication pattern, allowing both interactive user sessions and automated agent operations to operate securely without exposing raw API credentials to the language model.

### Can I build my own MCP server for internal company tools?

Yes. The repository includes [`plugins/cloudflare/skills/building-mcp-server-on-cloudflare/SKILL.md`](https://github.com/openai/plugins/blob/main/plugins/cloudflare/skills/building-mcp-server-on-cloudflare/SKILL.md), which provides a step-by-step guide for implementing remote MCP servers. You need only expose two HTTP endpoints handling `search` and `execute` JSON payloads, define the service in a [`.mcp.json`](https://github.com/openai/plugins/blob/main/.mcp.json) file, and reference it in your plugin manifest to integrate internal APIs with OpenAI's agent framework.

### Why does MCP use only two operations instead of full CRUD?

The `search`/`execute` dichotomy optimizes for language model capabilities. `search` accommodates natural language queries (e.g., "find the production database"), while `execute` handles deterministic actions on discovered resources. This two-step approach prevents hallucinated resource IDs and ensures agents operate on verified, contextually relevant objects rather than attempting direct mutations against ambiguous endpoints.