Interactive Explainer

How AI Connects to Your Systems

Model Context Protocol (MCP) โ€” the open standard that turns AI from a chatbot into a system that can query databases, call APIs, and take actions.

๐Ÿ“– Reference โšก Interactive ๐Ÿ”Œ MCP

๐Ÿ’ก Why Does AI Need MCP?

Without MCP, AI can only work with text you paste into it. It can't look things up, check databases, or take actions in your systems. MCP changes that.

๐Ÿ“‹

Without MCP

Export CSV โ†’ paste into chat โ†’ AI analyzes what you gave it. Manual, one-at-a-time.

๐Ÿ”Œ

With MCP

AI queries your database directly, gets exactly what it needs, analyzes live data. Automatic.

๐Ÿ”Œ

USB-C for AI

Just as USB-C connects any device to any peripheral, MCP connects any AI to any data source.

๐ŸŒ

Open Standard

Works with Claude, ChatGPT, Kiro, Cursor, VS Code โ€” build once, connect everywhere.

๐Ÿฆ What MCP Means for Insurance Teams

Your team works with databases, spreadsheets, document stores, and internal APIs every day. MCP lets AI access these systems the same way you do โ€” but faster.

Today (Manual)With MCP (Automated)
Export claims data to CSV, paste into AIAI queries claims database directly
Open 50 medical reports one by oneAI scans the claims documents folder automatically
Check policy coverage across 3 different systemsAI checks all 3 systems in one request
Copy policyholder data, format it, paste itAI runs SQL query, gets exactly what it needs
Manually send alert when fraud detectedAI sends the alert automatically via MCP
๐Ÿ’ก
Key insight: MCP doesn't replace your systems โ€” it connects AI to them. Your databases, APIs, and tools stay exactly where they are. MCP just gives AI a way to talk to them.

โšก API vs MCP โ€” What's the Difference?

Both APIs and MCP let systems talk to each other. But they solve different problems and work at different levels. Here's the clearest way to think about it:

๐Ÿ”Œ

API (Application Programming Interface)

A contract between two systems. "Send me this request, I'll give you this response." Designed for programs to talk to programs.

๐Ÿง 

MCP (Model Context Protocol)

A contract between AI and systems. "Here are the tools I offer โ€” the AI decides when and how to use them." Designed for AI to discover and use capabilities.

The Key Difference: Who Decides?

AspectTraditional APIMCP
Who calls it?A developer writes code: fetch('/api/claims')The AI decides on its own: "I need claims data, let me call read_query"
DiscoveryDeveloper reads API docs, writes integration codeAI asks the server "what tools do you have?" and figures it out
FlexibilityFixed endpoints โ€” each use case needs a specific API callAI composes tools dynamically โ€” same tools, infinite use cases
Who builds it?Developers build and maintain integrationsConfigure once, AI handles the rest
Error handlingDeveloper codes retry logic, error parsingAI reads the error, adjusts its approach, tries again

๐Ÿฆ AnyCompany Example: Getting Claims Data

๐Ÿ”Œ With a Traditional API

A developer writes this code:

// Developer writes this const resp = await fetch( '/api/claims?status=pending' ); const data = await resp.json(); // Then format, display, handle errors...

Requires: developer time, API knowledge, error handling code, maintenance when API changes.

๐Ÿง  With MCP

You just ask in plain English:

// You type this in Kiro: "Show me all pending claims over $10K with their policy details" // AI automatically: โ†’ tools/call read_query SELECT * FROM claims WHERE status = 'pending' AND amount > 10000

Requires: MCP server configured (one-time JSON file). No code, no API knowledge needed.

๐Ÿ’ก
The analogy: An API is like a vending machine โ€” you press the exact button for what you want. MCP is like a personal assistant with access to the vending machine โ€” you say "I'm thirsty" and they figure out which button to press.

๐Ÿค They Work Together, Not Against Each Other

MCP doesn't replace APIs โ€” it wraps them so AI can use them. Many MCP servers are just thin wrappers around existing APIs.

ScenarioUse API directlyUse MCP
Building a web app that shows claims dashboardโœ… Yes โ€” your app code calls the APIโŒ No โ€” apps don't need AI reasoning
AI agent that investigates claims fraud patternsโŒ No โ€” AI can't call APIs on its ownโœ… Yes โ€” AI discovers and calls tools
Automated report that pulls from policy, claims, and underwriting databasesโš ๏ธ Possible but needs custom codeโœ… Yes โ€” AI queries all 3 via MCP
Slack bot that responds to commandsโœ… Yes โ€” fixed command โ†’ fixed responseโœ… Also works โ€” AI reasons about the request
Dashboard with real-time chartsโœ… Yes โ€” direct data pipelineโŒ No โ€” MCP is for AI, not dashboards
๐Ÿ”‘
Rule of thumb: If a human or program knows exactly what data it needs โ†’ use an API. If an AI needs to figure out what data it needs based on a question โ†’ use MCP. In practice, MCP servers often call APIs under the hood โ€” you just don't have to write the integration code.

๐Ÿ”ง MCP Architecture

MCP follows a simple client-server pattern. The AI application (Kiro) is the host. It creates clients that connect to servers. Each server provides access to a specific data source or tool.

๐Ÿค– MCP Host Kiro / Claude / Cursor
โ†’
๐Ÿ”— MCP Client One per server
โ†’
๐Ÿ—„๏ธ MCP Server Database / API / Files

Three Core Primitives

Every MCP server can expose three types of capabilities:

๐Ÿ”จ

Tools

Actions the AI can perform: run a SQL query, call an API, send a message. The AI decides when to use them.

๐Ÿ“ฆ

Resources

Data the AI can read: file contents, database schemas, API responses. Like giving the AI access to a document.

๐Ÿ’ฌ

Prompts

Reusable templates that structure how the AI interacts with the server. Like pre-built query patterns.

โš™๏ธ How Connection Works

When you configure an MCP server in Kiro, here's what happens under the hood:

StepWhat happensYou see
1. ConfigureYou add the server to .kiro/settings/mcp.jsonEdit a JSON file
2. ConnectKiro launches the MCP server process and negotiates capabilitiesGreen checkmark โœ… in MCP panel
3. DiscoverKiro asks the server "what tools do you have?" via tools/listTool names appear in the panel
4. UseWhen you ask a question, Kiro decides which tool to call and sends a tools/call requestAI response includes data from the server
๐Ÿ”
Two transport modes: MCP servers can run locally (on your machine, using stdio โ€” like the Fetch server) or remotely (on a server, using HTTP โ€” like a cloud API). The protocol is the same either way.

๐Ÿ”ฌ Under the Hood: What Actually Happens

When you type a question in plain English, here's the exact transformation that occurs โ€” from your words to a structured tool call and back to a human-readable answer.

The Full Transformation Chain

1 You type (natural language)
"What are the pending claims over $50K that were submitted this month?"
2 LLM decides which tool to call

The LLM sees the list of tools the MCP server advertised during connection. Based on your question, it decides which tool to call and constructs the arguments:

// LLM's output (structured tool call โ€” NOT raw JSON-RPC): Tool: read_query Arguments: { "query": "SELECT claim_id, policyholder, amount, status, submitted_date FROM claims WHERE status = 'pending' AND amount > 50000 AND submitted_date >= '2026-05-01'" }

๐Ÿ’ก The AI decides what to call and what arguments to pass. It does NOT write the JSON-RPC envelope โ€” that's the next layer's job.

3 MCP Client wraps it in JSON-RPC and sends to server Protocol layer

Kiro's MCP Client takes the LLM's tool call decision and packages it into the standard JSON-RPC 2.0 format. The AI never writes this โ€” the infrastructure handles it automatically:

{ "jsonrpc": "2.0", "method": "tools/call", "params": { "name": "read_query", "arguments": { "query": "SELECT claim_id, policyholder, amount, status, submitted_date FROM claims WHERE status = 'pending' AND amount > 50000 AND submitted_date >= '2026-05-01'" } }, "id": 1 }

๐Ÿ’ก The MCP protocol is the transport standard โ€” it ensures any AI host (Kiro, Claude, Cursor) can talk to any MCP server using the same format. The LLM provides the intent; the protocol provides the envelope.

4 MCP Server executes and returns result
{ "jsonrpc": "2.0", "result": { "content": [{ "type": "text", "text": "[{\"claim_id\":\"CLM-2026-0847\",\"policyholder\":\"Tan Wei Ming\",\"amount\":78500,\"status\":\"pending\",\"submitted_date\":\"2026-05-03\"}, ...]" }] }, "id": 1 }
5 AI formats the answer for you
Found 3 pending claims over $50K submitted this month: | Claim ID | Policyholder | Amount | Date | |----------------|----------------|-----------|------------| | CLM-2026-0847 | Tan Wei Ming | $78,500 | 3 May 2026 | | CLM-2026-0891 | Sarah Lim | $125,000 | 7 May 2026 | | CLM-2026-0903 | Ahmad bin Ismail| $62,300 | 5 May 2026 | Total pending: $265,800 across 3 claims.

๐Ÿง  Why This Helps AI Agents

Without MCP, an AI agent is limited to what's in its training data and what you paste into the chat. With MCP, the agent gains real capabilities:

๐Ÿ”

Tool Discovery

At connection time, the server tells the AI: "Here are my tools, here's what each one does, here are the parameters." The AI doesn't need to be pre-programmed โ€” it learns what's available.

๐Ÿงฉ

Dynamic Composition

The AI can chain multiple tools together. "Get claims data" โ†’ "Cross-reference with policy limits" โ†’ "Flag the ones that exceed coverage." One question, multiple tool calls.

๐Ÿ”„

Error Recovery

If a tool call fails, the AI reads the error message and adjusts. Wrong table name? It asks the server for the schema and tries again. No human intervention needed.

๐Ÿ“

Structured I/O

MCP uses JSON-RPC 2.0 โ€” a standard wire format. This means any AI that speaks MCP can use any MCP server. Build once, connect to Claude, Kiro, Cursor, or any future AI.

๐Ÿ“‹ What the AI Sees: Tool Advertisement

When an MCP server connects, it advertises its tools with a schema. This is what the AI "reads" to understand what it can do:

// Response to "tools/list" โ€” the AI sees this at connection time { "tools": [ { "name": "read_query", "description": "Execute a SELECT query on the claims database", "inputSchema": { "type": "object", "properties": { "query": { "type": "string", "description": "SQL SELECT query" } }, "required": ["query"] } }, { "name": "list_tables", "description": "List all tables in the database", "inputSchema": { "type": "object", "properties": {} } } ] }
๐Ÿ”‘
This is the magic: The AI reads the tool name, description, and parameter schema โ€” then decides on its own when and how to use it. You never write integration code. The AI figures out that "pending claims over $50K" means calling read_query with a SQL WHERE clause. The description field is what teaches the AI what each tool does.

๐Ÿ” Security: Who Controls What the AI Can Do?

MCP gives AI capabilities โ€” but with clear boundaries:

Control LayerWho sets itWhat it controls
MCP Server designServer developerWhich tools exist, what they can do (e.g., read-only vs. read-write)
IAM / PermissionsCloud adminWhat the server's credentials can access (e.g., only the claims table, not the HR table)
MCP configYou (the user)Which servers are enabled, which tools are auto-approved vs. require confirmation
Human-in-the-loopKiro UIYou see each tool call and can Allow or Reject before it executes
๐Ÿ’ก
For AnyCompany: You'd build an MCP server for claims that only exposes read_query (no writes). The IAM role would only have SELECT access to the claims table. Even if the AI "wanted" to delete data, it physically can't โ€” the permissions don't allow it. Defense in depth.

๐ŸŽฎ MCP Message Flow โ€” Interactive Demo

Watch messages flow through the full MCP architecture as you ask a question. Each step shows exactly what's happening between components.

Message Flow

Step 0 / 0
๐Ÿ‘ค
You
Plain English
๐Ÿค–
Kiro (Host)
AI reasoning
๐Ÿ”—
MCP Client
JSON-RPC 2.0
โš™๏ธ
MCP Server
varies per scenario
๐ŸŒ
Data Source
Web / DB / AWS
Press Play or Step Forward to watch the message flow.

๐Ÿฆ MCP Servers for Insurance Teams

These are the most common MCP servers your team would use. You specify what connections are needed in the Agent Design Canvas โ€” your tech team configures the actual servers.

MCP ServerConnects toInsurance use caseSetup
AWS APIAWS servicesQuery S3, Bedrock models, check infrastructure statusConfig + credentials
AWS DocumentationAWS docsSearch service documentation, architecture guidanceConfig only
FetchWeb pagesRead product guides, competitor pages, regulatory noticesConfig only
Database (PostgreSQL)DatabasesQuery policy data, claims history, underwriting recordsConfig + credentials
FilesystemFile directoriesProcess folders of medical reports, scan claim documentsConfig only
Slack / TeamsTeam messagingSend alerts when fraud pattern detectedAPI key
Google Drive / S3Document storageRead policy wordings and product specs for RAG groundingOAuth / IAM
Email (SMTP)Email systemsSend claims decisions, escalation alertsSMTP config
Custom REST APIInternal servicesCall underwriting rules engine, claims adjudication APICustom build
๐Ÿ’ก
You design the recipe, your tech team sets up the kitchen. In the Agent Design Canvas, you specify "MCP connections needed: claims database, policy admin system, Slack for alerts." Your engineering team then configures the actual MCP servers. The open-source community has pre-built servers for most common systems.

โš™๏ธ Configuration Example

This is what an MCP configuration looks like in Kiro. It's a simple JSON file โ€” no code required:

// .kiro/settings/mcp.json { "mcpServers": { "fetch": { "command": "uvx", "args": ["mcp-server-fetch"], "disabled": false }, "aws-docs": { "command": "uvx", "args": ["awslabs.aws-documentation-mcp-server@latest"], "env": { "FASTMCP_LOG_LEVEL": "ERROR" } }, "aws-api": { "command": "uvx", "args": ["awslabs.aws-api-mcp-server@latest"], "env": { "AWS_REGION": "us-east-1" } } } }

Three MCP servers, each a few lines of JSON. Kiro launches them, connects, and you can fetch web pages, search documentation, and query AWS โ€” all in plain English.

๐Ÿ”— The Complete Kiro Stack

MCP is the fourth and final layer of the Kiro automation stack. Here's how all 4 layers work together:

๐Ÿ“‹ Steering
Global rules
โ†’
๐Ÿ› ๏ธ Skills
On-demand expertise
โ†’
โšก Hooks
Auto-triggers
โ†’
๐Ÿ”Œ MCP
Data connections

How They Work Together โ€” Claims Fraud Detection Example

LayerWhat it doesIn the fraud detection workflow
SteeringSets global rulesSGD currency, no PII (NRIC/policy numbers), APPROVE/FLAG/REJECT ratings
SkillDefines the investigation processClaims Fraud Investigator persona, investigation report format, guardrails
HookTriggers automaticallyNew claim flagged โ†’ run fraud investigation skill
MCPConnects to dataFetch MCP โ†’ read policy documents; AWS API โ†’ query claims database, check provider records
๐Ÿ”
The full automation loop: Flagged claim arrives โ†’ Hook detects it โ†’ Skill activates โ†’ MCP queries claims database โ†’ Investigation report generated โ†’ Claims adjuster reviews the recommendation. The AI handles the investigation; you make the decision.

๐Ÿ—บ๏ธ Your Workshop Journey

ModuleWhat you learnWhat you build
M1-M2What agents are, how they workUnderstanding of agent architecture
M3Workflow patterns (chain, parallel, route, orchestrate)Pattern selection for insurance workflows
M4-M5AWS tools, frameworks (Kiro, Strands, AgentCore)Hands-on with Kiro skills, hooks, MCP
M6Custom solutions, guardrails, evaluationWorking agent with database connection

The thread: Module 1's agent concepts โ†’ applied in Module 3's workflow patterns. Module 3's patterns โ†’ implemented in Module 5's hands-on labs. Module 4's tools โ†’ connected via Module 5's MCP. Everything builds on what came before.