# What is an MCP server? A plain-language guide

> An MCP server lets an AI assistant use one outside tool, such as your Gmail. How remote MCP and OAuth sign-in work, local versus remote, and real examples.

Updated: 2026-10-03 · Canonical: https://staging.nickbox.io/en/resources/what-is-an-mcp-server

An MCP server is a small service that gives an AI assistant one extra ability, such as searching your Gmail. MCP stands for Model Context Protocol, an [open standard created by Anthropic](https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp) that lets assistants connect to tools and data. You grant it a permission once, then ask in plain words. A Gmail MCP server, or MCP for Gmail, is one that reads your mail this way. Assistants such as Claude call the same thing a "connector"; the [connector comparison](/en/resources/gmail-connector-vs-gmail-mcp-server) sorts out the two names.

## What does an MCP server actually do?

It sits between your assistant and another service and translates. The assistant asks a question in everyday language, the server turns it into a request the service understands, and the answer comes back for the assistant to read to you. Each server offers a fixed list of actions, called tools.

Think of a plug adapter. Your assistant has one kind of socket, every service has a different one, and MCP is the shared shape that fits them all. Without it, each assistant would need custom work for each service.

## What are some examples?

Examples are easiest to see by the tool list. A Gmail server might offer "search mail" and "read a message". A calendar server might offer "list events". A notes server might offer "find a page".

Nickbox, our hosted server for Gmail, exposes five tools: `list_accounts`, `search_emails`, `search_all_accounts`, `read_email` and `list_labels`. When you ask "find the invoice from Dana across my work and billing inboxes", the assistant picks the tools and runs them for you. For ideas on what to ask, see [prompts to search all your inboxes](/en/resources/prompts-to-search-all-your-inboxes).

## What is the difference between a local and a remote MCP server?

A local server runs as a program on your own computer, started by the assistant app. A remote server runs on the internet and the assistant connects to it through a URL. Remote servers also work in web and mobile apps, where there is no local program to start.

| | Local | Remote |
|---|---|---|
| Where it runs | Your computer | A hosting provider |
| How you add it | Install software, edit a config file | Paste a URL |
| Works in web and mobile apps | Usually not | Yes |
| Who maintains it | You | The provider |

Local setups were the first to appear. As [Claude's help center explains](https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp), servers used to work only on your own machine, and remote servers hosted on the internet are the newer option. If you do not want to run anything yourself, choose remote. The usual technical split is that local servers talk to the app through the computer's standard input, while remote ones use [HTTP](https://developers.cloudflare.com/agents/model-context-protocol/transport).

## How does remote MCP sign-in work with OAuth?

OAuth is the "Sign in with Google" style of permission. You approve access on Google's own page, and the service receives a token instead of your password. The token carries only the permission you approved, and you can cancel it later.

For a hosted Gmail server the flow has five steps:

1. You paste the server's URL into your assistant as a custom connector.
2. The assistant sends you to a sign-in page to approve the connection.
3. The server sends you to Google, which asks whether to allow read-only access to your mail.
4. You approve. Google gives the server a token for that one permission.
5. Back in the assistant, you ask questions and the server uses the token to read your mail.

Claude's documentation states that with this kind of sign-in [Claude never sees your actual password](https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp). Some connectors use an API key instead, stored encrypted.

## How do I set one up without coding?

Setup for a hosted server takes about two minutes. You need an assistant that accepts custom connectors and a URL from the provider.

1. Sign in to the provider and connect your account. Nickbox asks Google for the read-only Gmail permission (`gmail.readonly`).
2. Copy the MCP URL from the dashboard.
3. In your assistant, add a custom connector and paste the URL.
4. Approve the sign-in when the assistant opens it.
5. Ask a first question, such as "Which accounts do you see?"

Step-by-step guides exist for [Claude](/en/docs/claude), [ChatGPT](/en/docs/chatgpt), [Gemini](/en/docs/gemini), [Cursor](/en/docs/cursor) and [VS Code](/en/docs/vscode). Menu names change often, so follow the guide for your client. Nickbox is in a limited beta: Google lets an unverified app connect only 100 Gmail accounts, so places are few. You start by signing in with Google.

## Is an MCP server safe to connect?

It depends on the permission and on who runs the server. The risk grows with what the permission allows: a server that can only read is less risky than one that can send and delete. Email is also untrusted input, so a malicious message can try to steer an assistant. Read-only access reduces that risk without removing it.

Nickbox holds a read-only Gmail permission, so it cannot send, draft or delete. It does not store message content. The [security page](/en/security) lists what is stored. The [safety guide](/en/resources/is-it-safe-to-give-an-ai-assistant-access-to-gmail) covers prompt injection in more detail. Price is on the [pricing page](/en/pricing): US$5 a month or US$48 a year, with a 7-day trial that needs a card.

## How do I remove an MCP server later?

Remove the connector in your assistant, then remove the permission in your Google Account. Removing only the connector stops the assistant from calling the server. Removing the permission in Google ends the server's own access. The [revoke guide](/en/resources/how-to-revoke-gmail-access-from-an-ai-app) has the steps.

## FAQ

**Do I need to be a developer to use an MCP server?**

No. With a hosted server you paste one URL into your assistant and sign in with your Google account. You do not install code or edit files.

**Does the assistant see my Google password?**

No. You sign in on Google's own page and approve a permission. The assistant and the server receive a token for that permission, never the password.

**What is the difference between a local and a remote MCP server?**

A local server runs as a program on your own computer. A remote server runs on the internet and your assistant reaches it through a URL, so it also works in web and mobile apps.

**Can an MCP server do things I did not approve?**

It can only do what the permission you granted allows. A read-only Gmail permission lets it read and search mail and never send or delete.

## Sources

- [Get started with custom connectors using remote MCP (Claude Help Center)](https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp)
- [Remote vs local MCP servers (Clipspeed)](https://www.clipspeed.ai/mcp/remote-vs-local-mcp.html)
- [MCP transports on Cloudflare Agents docs](https://developers.cloudflare.com/agents/model-context-protocol/transport)
