Vendor-documented snapshot

Which AI hosts support MCP?

Claude, ChatGPT, VS Code, and Gemini CLI all document MCP host behavior, but “supports MCP” is not a binary certification. Their local connection paths, remote transports, plans, permissions, extensions, and compatibility behavior differ. First map what host, client, and server mean, then compare product behavior here.

Checked 25 August 2026First-party documentation review; not an interoperability test.

Representative—not exhaustive

Local and remote support paths

How to read this table

“Direct” means the named surface documents that connection path. “Separate product path” and “via tunnel” are materially different from a direct connection. No row proves support for every MCP revision, primitive, extension, or server.

Vendor-documented MCP connection paths and limitations for four representative host products, checked 25 August 2026.
Host and surfaceLocal pathRemote pathDocumented coverageMaterial limitsSources
ClaudeAnthropicClaude custom connectors; separate Claude Desktop local pathSeparate product path — local MCP is configured in Claude Desktop, not through the cloud custom-connector path.Direct — custom remote connectors connect from Anthropic infrastructure to a reachable endpoint.Custom remote MCP connectors across supported Claude surfaces; local extensions and configuration are documented separately.Remote endpoints must be reachable from Anthropic infrastructure; this review did not test protocol-version interoperability.Plan, surface, connector-count, organization-owner, and network allow-list requirements vary. Cowork and claude.ai do not use the local Desktop path.
ChatGPTOpenAIDeveloper mode and MCP apps on supported ChatGPT web plansVia Secure MCP Tunnel — ChatGPT does not connect directly to a local server.Direct — remote MCP apps and connectors are supported on eligible surfaces.Read/fetch behavior and, for eligible beta plans, full MCP actions through developer mode and apps.Private, on-premises, or developer-machine servers require the supported tunnel; this review did not test protocol-version interoperability.Full/write MCP is a web beta for Business, Enterprise, and Edu; Pro is documented for read/fetch. Agent mode does not use custom apps, Deep Research is read/fetch only, and MCP apps are not available on mobile.
Visual Studio CodeMicrosoftVS Code agent featuresDirect — local stdio servers are supported.Direct — remote HTTP servers are supported.Tools, resources, prompts, MCP Apps, trust controls, enterprise policy, and local sandboxing on supported systems.Remote HTTP attempts Streamable HTTP and may fall back to SSE compatibility; this review did not test protocol-version interoperability.The documented sandbox applies only to locally running stdio servers on macOS and Linux, not Windows. Sandboxed server tool calls are auto-approved; availability also varies by release and organization policy.
Gemini CLIGoogleGemini CLI MCP configurationDirect — stdio servers are supported.Direct — Streamable HTTP is supported; an SSE endpoint remains configurable for compatibility.Tools, resources, prompts, OAuth, include/exclude filtering, confirmation, and trusted-server configuration.SSE configuration is compatibility behavior, not a statement that HTTP+SSE is the current core transport; protocol-version interoperability was not tested.Trust configuration bypasses confirmations. OAuth browser and localhost-callback behavior needs special handling in headless, SSH, and container environments. Apps and Tasks support was not inferred.

Compatibility has dimensions

One “yes” hides several questions.

01

Which protocol era?

A product can speak legacy session-era MCP, modern stateless MCP, or both. Product documentation does not always state the exact wire revision.

02

Which transport?

Local stdio, current Streamable HTTP, and legacy SSE compatibility create different setup and security requirements.

03

Which capabilities?

Tools, resources, prompts, elicitation, Apps, and Tasks are not one feature. A host can support a subset.

04

Which surface and plan?

Web, desktop, CLI, mobile, agent mode, and enterprise-managed environments can expose different behavior under one product name.

05

Which trust model?

Confirmation, auto-approval, sandboxing, OAuth, tunnels, and organization policy all change the effective security boundary.

Product notes

The caveats that change setup decisions

01

Anthropic

Claude

Plan, surface, connector-count, organization-owner, and network allow-list requirements vary. Cowork and claude.ai do not use the local Desktop path.

Transport/version note: Remote endpoints must be reachable from Anthropic infrastructure; this review did not test protocol-version interoperability.

Open first-party documentation
02

OpenAI

ChatGPT

Full/write MCP is a web beta for Business, Enterprise, and Edu; Pro is documented for read/fetch. Agent mode does not use custom apps, Deep Research is read/fetch only, and MCP apps are not available on mobile.

Transport/version note: Private, on-premises, or developer-machine servers require the supported tunnel; this review did not test protocol-version interoperability.

Open first-party documentation
03

Microsoft

Visual Studio Code

The documented sandbox applies only to locally running stdio servers on macOS and Linux, not Windows. Sandboxed server tool calls are auto-approved; availability also varies by release and organization policy.

Transport/version note: Remote HTTP attempts Streamable HTTP and may fall back to SSE compatibility; this review did not test protocol-version interoperability.

Open first-party documentation
04

Google

Gemini CLI

Trust configuration bypasses confirmations. OAuth browser and localhost-callback behavior needs special handling in headless, SSH, and container environments. Apps and Tasks support was not inferred.

Transport/version note: SSE configuration is compatibility behavior, not a statement that HTTP+SSE is the current core transport; protocol-version interoperability was not tested.

Open first-party documentation

Method and limits

Documentation evidence, clearly labeled.

Each row was rechecked against first-party product documentation on 25 August 2026. We recorded what the vendor documents, including restrictions that materially change the answer. We did not independently execute a cross-version test matrix, so this page does not claim tested interoperability, performance, uptime, or complete extension coverage.

Rows are classified live-check required and scheduled for monthly review. A protocol release, plan change, staged rollout, security advisory, or product-surface change triggers an earlier review.