What Is the Model Context Protocol (MCP) in OpenAI Plugins: A Complete Technical Guide

The Model Context Protocol (MCP) is a lightweight, HTTP-based interface that enables language models to retrieve and invoke external resources directly from a plugin's runtime through standardized search and execute operations.

The openai/plugins repository implements MCP as a universal bridge between AI agents and external services like Cloudflare, Supabase, and Vercel. By declaring MCP servers in simple JSON configuration files, plugins expose a consistent RPC interface that eliminates the need for custom SDKs while maintaining strict authentication controls.

Core Architecture of the Model Context Protocol

The Model Context Protocol defines a minimal contract between AI agents and service APIs. Rather than implementing bespoke integration logic for each provider, MCP standardizes all interactions around two fundamental remote procedure calls.

The Search and Execute RPC Pattern

Every MCP server exposes exactly two operations:

  • search – Accepts natural-language queries or structured parameters and returns matching items from the service (such as Cloudflare zones, Supabase projects, or Granola meetings)
  • execute – Performs actions on specific objects returned by search (such as updating DNS records, creating database tables, or fetching meeting details)

This dichotomy separates data retrieval from data mutation, allowing language models to first discover available resources contextually before attempting modifications.

MCP Server Configuration via .mcp.json

In the openai/plugins repository, each plugin declares its MCP servers in a *.mcp.json file. The configuration schema requires only three fields:

{
  "mcpServers": {
    "<server-id>": {
      "type": "http",
      "url": "<base-endpoint>",
      "note": "<human-readable description>"
    }
  }
}

For example, plugins/cloudflare/.mcp.json defines the Cloudflare API integration:

{
  "mcpServers": {
    "cloudflare-api": {
      "type": "http",
      "url": "https://mcp.cloudflare.com/mcp",
      "note": "Official Cloudflare API MCP server. Uses OAuth on first connection, with optional bearer-token auth for automation. Provides token-efficient access to the Cloudflare API via search() and execute()."
    }
  }
}

The plugin manifest at plugins/cloudflare/.codex-plugin/plugin.json references this configuration via the "mcpServers": "./.mcp.json" field, linking the plugin to its runtime context providers.

How MCP Servers Work in Practice

When an AI skill requires data from a service, it constructs a JSON-RPC-style POST request to the MCP endpoint. The protocol's HTTP-native design means any language model can interact with it through standard tool interfaces without additional dependencies.

Search Operation Example

To retrieve Cloudflare zones, the agent sends:

{
  "type": "search",
  "server": "cloudflare-api",
  "query": "list zones for example.com"
}

The MCP server responds with structured data, including identifiers necessary for subsequent operations.

Execute Operation Example

After identifying a target resource, the agent invokes actions using:

{
  "type": "execute",
  "server": "cloudflare-api",
  "action": "updateZone",
  "parameters": { "zoneId": "...", "setting": "tls_1_3", "value": true }
}

This pattern appears consistently across the repository, from plugins/cloudflare/skills/building-mcp-server-on-cloudflare/SKILL.md (which documents building remote MCP servers on Cloudflare Workers) to plugins/vercel/skills/nextjs/references/debug-tricks.md (which references the built-in _next/mcp endpoint for AI-assisted debugging).

Building and Consuming MCP Endpoints

Because MCP is a pure HTTP API, client implementations require only standard networking libraries.

Python Client Implementation

The following snippet demonstrates interaction with an MCP server using the Cloudflare configuration from plugins/cloudflare/.mcp.json:

import requests

MCP_URL = "https://mcp.cloudflare.com/mcp"   # from .mcp.json

def mcp_search(query: str):
    resp = requests.post(
        MCP_URL,
        json={"type": "search", "query": query}
    )
    resp.raise_for_status()
    return resp.json()["results"]

def mcp_execute(action: str, **params):
    resp = requests.post(
        MCP_URL,
        json={"type": "execute", "action": action, "parameters": params}
    )
    resp.raise_for_status()
    return resp.json()["result"]

Skill Integration Pattern

Agents combine these primitives to perform multi-step workflows. This example from the Cloudflare skill demonstrates the canonical search-then-execute flow documented in plugins/cloudflare/skills/cloudflare/references/agents-sdk/api.md:

def list_zones(domain: str):
    # 1️⃣ Search for zones matching the domain

    zones = mcp_search(f"list zones for {domain}")
    # 2️⃣ Pick the first match (or apply additional filtering)

    zone_id = zones[0]["id"]
    # 3️⃣ Execute an action on the chosen zone

    details = mcp_execute("getZoneDetails", zoneId=zone_id)
    return details

Security and Extensibility Benefits

The Model Context Protocol provides four critical advantages for plugin development:

  • Uniformity – All plugins expose identical search and execute methods regardless of underlying service complexity, reducing the learning curve for AI agents
  • Context-awareness – Models request only necessary data, minimizing token consumption compared to broad API scraping
  • Security – MCP servers enforce authentication via OAuth or bearer tokens at the HTTP layer, with rate limiting applied at the endpoint level
  • Extensibility – Adding new services requires only a .mcp.json descriptor and thin API wrappers, as demonstrated by the minimal configuration footprint in the Cloudflare and Vercel plugins

Summary

  • The Model Context Protocol (MCP) standardizes AI-service interactions through HTTP-based search and execute RPC calls.
  • Plugins declare MCP servers in .mcp.json files (such as plugins/cloudflare/.mcp.json) and reference them in plugin.json manifests.
  • The protocol requires no custom SDKs—standard HTTP clients suffice for implementation.
  • MCP enables token-efficient, authenticated, context-aware access to external APIs across the OpenAI Plugins ecosystem.

Frequently Asked Questions

What is the difference between MCP and traditional REST API integration?

Traditional REST integrations require AI models to manage endpoint URLs, HTTP methods, and payload structures for each service individually. MCP abstracts these behind the consistent search and execute operations, allowing models to interact with Cloudflare, Supabase, or Vercel using identical calling conventions while the MCP server handles translation to service-specific REST calls.

How does authentication work in the Model Context Protocol?

MCP servers handle authentication at the HTTP layer, typically through OAuth flows on initial connection or bearer tokens for automated access. The plugins/cloudflare/.mcp.json configuration explicitly notes this dual authentication pattern, allowing both interactive user sessions and automated agent operations to operate securely without exposing raw API credentials to the language model.

Can I build my own MCP server for internal company tools?

Yes. The repository includes plugins/cloudflare/skills/building-mcp-server-on-cloudflare/SKILL.md, which provides a step-by-step guide for implementing remote MCP servers. You need only expose two HTTP endpoints handling search and execute JSON payloads, define the service in a .mcp.json file, and reference it in your plugin manifest to integrate internal APIs with OpenAI's agent framework.

Why does MCP use only two operations instead of full CRUD?

The search/execute dichotomy optimizes for language model capabilities. search accommodates natural language queries (e.g., "find the production database"), while execute handles deterministic actions on discovered resources. This two-step approach prevents hallucinated resource IDs and ensures agents operate on verified, contextually relevant objects rather than attempting direct mutations against ambiguous endpoints.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →