Overview
The Model Context Protocol, built rather than described. Eleven modules take one running project, a research-notes assistant, from a single search tool to a secured multi-server host: real JSON-RPC on the wire, tools whose descriptions the model can actually use, resources and prompts, OAuth-style authorization, the attacks a tool-calling host is open to and the defences that hold, then stateless replicas, tracing and a registry. Every example is runnable Python against protocol revision 2026-07-28, and every module ends with a lab, a project milestone and interview questions.
What you will learn
- Write an MCP server whose tools a model picks correctly without being told twice
- Read and debug JSON-RPC 2.0 on the wire, over stdio and over Streamable HTTP
- Build a host that connects several servers, resolves name collisions and asks before acting
- Verify tokens, scope a server's authority, and refuse a confused-deputy request
- Name the tool-poisoning, shadowing and injection attacks, and test your own server for them
- Run a server as stateless replicas with tracing, rate limits and a versioned registry entry
Included with the course
- 83 written parts, yours for good
- 14h 44m of reading, measured not estimated
- Written for the intermediate level
- Every future revision included
- UPI, cards and netbanking
Prerequisites
- Comfortable reading and writing Python, including async and await
- HTTP and JSON; having called an LLM API at least once
- No prior MCP knowledge needed
Curriculum
11 sections · 83 parts · 14h 44m1h 5m free to read · 13h 39m with the course
01Module 1: Foundations8 parts · 65 min
- Topic 1: Module 1 at a glance, and the setupPreview3 min
- Topic 2: Why MCP existsPreview7 min
- Topic 3: The running projectPreview13 min
- Topic 4: One capability, two waysPreview11 min
- Topic 5: Core conceptsPreview12 min
- Topic 6: How the protocol has evolvedPreview7 min
- Topic 7: Module 1 labPreview6 min
- Topic 8: Module 1 milestone and interview questionsPreview6 min
02Module 2: The Protocol and Its Transports6 parts · 82 min
- Topic 1: Module 2 at a glance, and the setup11 min
- Topic 2: Messages and lifecycle24 min
- Topic 3: Protocol utilities10 min
- Topic 4: Transports23 min
- Topic 5: Module 2 lab5 min
- Topic 6: Module 2 milestone and interview questions9 min
03Module 3: Tools7 parts · 78 min
- Topic 1: Module 3 at a glance, and the setup3 min
- Topic 2: Defining tools17 min
- Topic 3: Descriptions as prompts17 min
- Topic 4: Results and errors13 min
- Topic 5: Tool design16 min
- Topic 6: Module 3 lab4 min
- Topic 7: Module 3 milestone and interview questions8 min
04Module 4: Resources, Prompts and Interaction6 parts · 82 min
- Topic 1: Module 4 at a glance, and the setup3 min
- Topic 2: Resources20 min
- Topic 3: Prompts8 min
- Topic 4: User interaction39 min
- Topic 5: Module 4 lab4 min
- Topic 6: Module 4 milestone and interview questions8 min
05Module 5: Building Servers6 parts · 73 min
- Topic 1: Module 5 at a glance2 min
- Topic 2: The Python SDK v217 min
- Topic 3: Server structure22 min
- Topic 4: Testing19 min
- Topic 5: Module 5 lab5 min
- Topic 6: Module 5 milestone and interview questions8 min
06Module 6: Clients and Hosts6 parts · 86 min
- Topic 1: Module 6 at a glance, and the setup7 min
- Topic 2: Client integration30 min
- Topic 3: Multi-server hosts20 min
- Topic 4: Host responsibilities16 min
- Topic 5: Module 6 lab5 min
- Topic 6: Module 6 milestone and interview questions8 min
07Module 7: Authorization6 parts · 77 min
- Topic 1: Module 7 at a glance3 min
- Topic 2: The model18 min
- Topic 3: The flow21 min
- Topic 4: Scopes and rules21 min
- Topic 5: Module 7 lab5 min
- Topic 6: Module 7 milestone and interview questions9 min
08Module 8: Security12 parts · 69 min
- Topic 1: Module 8 at a glance3 min
- Topic 2: The threat model7 min
- Topic 3: Tool poisoning4 min
- Topic 4: Pinning and diffing tool definitions11 min
- Topic 5: Tool shadowing across servers4 min
- Topic 6: Indirect prompt injection through a note5 min
- Topic 7: Exfiltration and the confused deputy6 min
- Topic 8: Supply chain risk4 min
- Topic 9: Defences that work, and one that does not8 min
- Topic 10: Measure it5 min
- Topic 11: Module 8 lab4 min
- Topic 12: Module 8 milestone and interview questions8 min
09Module 9: Production and Ecosystem10 parts · 92 min
- Topic 1: Module 9 at a glance3 min
- Topic 2: The production app12 min
- Topic 3: Stateless replicas behind a load balancer11 min
- Topic 4: Protecting the service16 min
- Topic 5: Observability12 min
- Topic 6: Long-running work9 min
- Topic 7: Registry and versioning13 min
- Topic 8: Measure4 min
- Topic 9: Module 9 lab4 min
- Topic 10: Module 9 milestone and interview questions8 min
10Module 10: Design Patterns and Agents6 parts · 93 min
- Topic 1: Module 10 at a glance, and the setup12 min
- Topic 2: Server patterns26 min
- Topic 3: Agentic patterns16 min
- Topic 4: Context efficiency and evaluation27 min
- Topic 5: Module 10 lab4 min
- Topic 6: Module 10 milestone and interview questions8 min
11Module 11: Capstone10 parts · 87 min
- Topic 1: Module 11 at a glance3 min
- Topic 2: The assembled repository5 min
- Topic 3: The server, requirement by requirement9 min
- Topic 4: The host and its CLI14 min
- Topic 5: Securing it8 min
- Topic 6: Testing it20 min
- Topic 7: Measuring it4 min
- Topic 8: Deliverables10 min
- Topic 9: Module 11 lab4 min
- Topic 10: Module 11 milestone and interview questions10 min
By the end of this module, you'll have:
- A clear, numbers-backed answer to "why does MCP exist?", including the N applications times M tools arithmetic and a decision table for when MCP is the wrong tool.
- The running project's two foundation files,
notes_assistant/store.pyandnotes_assistant/llm.py, read line by line and exercised against Nare's eight sample notes. - The same "search my notes" capability built two ways: once with native function calling and once as a real MCP server with one
search_notestool, reached by a client in memory and over stdio.
Reviews
to review this course once you have finished it.