MCP Now Has an Official Certification: Inside the MCPA Exam

·10 min read·Evergreen Tools Team

On September 14, 2026, during AGNTCon + MCPCon Europe in Amsterdam, the Agentic AI Foundation (AAIF) announced the Model Context Protocol Associate, or MCPA. It is a vendor-neutral credential that validates engineering and platform builders' understanding of Model Context Protocol concepts, architecture, and implementation considerations. The Linux Foundation describes it as the first official certification validating MCP knowledge and the first certification launched by the AAIF. In other words, for the first time there is a shared benchmark an employer can point at when hiring around agent protocols.

1. Exam Structure and Weightings

Start with the structure, because the structure dictates how you prepare. The MCPA is a 120-minute, online, proctored, multiple-choice exam covering five weighted domains: MCP Fundamentals at 16 percent, Architecture and Components at 14 percent, Interactions and Execution at 26 percent, Security and Governance at 24 percent, and Use Cases and Ecosystem at 20 percent. It is aligned with the latest MCP specification release, 2026-07-28. The AAIF recommends it for candidates who understand the internals of MCP and are comfortable reasoning about how the protocol works and how its components communicate. Note that framing. It is not looking for someone who has used an MCP tool; it is looking for someone who can explain the protocol itself.

// Domain 1 study route: build the smallest MCP server you can, because
// "Architecture & Components" is a lot easier to remember once you have
// written a host, a client, and a server yourself.

import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
import { StdioServerTransport } from "@modelcontextprotocol/sdk/server/stdio.js";

const server = new McpServer({ name: "study-server", version: "1.0.0" });

server.tool(
  "add_note",
  { text: { type: "string" } },
  async ({ text }) => ({
    content: [{ type: "text", text: "stored: " + text.slice(0, 40) }],
  })
);

// Tools, resources, and prompts are three different primitives. If you
// cannot explain when to use each, that is exam Domain 1 and 2 territory.
await server.connect(new StdioServerTransport());
A team learning together

The MCPA is the first certification launched by the AAIF

2. What the Weightings Reveal: Half the Paper Is Protocol and Boundaries

The weightings say more than the domain list. Interactions and Execution plus Security and Governance is exactly 50 percent. Half the paper is about two things: how the protocol's message flow and lifecycle proceed, and how trust boundaries, permissions, and risk controls are set. Code sample 2 puts that in code shape, with per-tool permission declarations, filesystem read and write allowlists, and a deny-by-default egress policy. If your entire mental model is the one-liner that MCP lets AI connect to external systems, you will struggle on the half of the exam that carries the weight. If you have written a policy like the one above by hand, those vocabulary words suddenly have concrete referents.

// Domain 2 study route: trust boundaries. This is the heaviest single
// theme in the exam once you combine "Interactions & Execution" with
// "Security & Governance" — 26 plus 24 percent is half the paper.

const serverPolicy = {
  name: "notes",
  tools: {
    add_note: { sideEffects: "write", scope: "notes", requiresApproval: false },
    delete_all: { sideEffects: "destructive", scope: "notes", requiresApproval: true },
  },
  // Least privilege at the tool level, not the server level.
  fs: { allowRead: ["./notes/**"], allowWrite: ["./notes/**"], deny: ["**/.env*"] },
  egress: { default: "deny", allow: ["notes.internal"] },
};

export function authorise(call, policy = serverPolicy) {
  const tool = policy.tools[call.tool];
  if (!tool) return { decision: "deny", reason: "unknown tool" };
  if (tool.requiresApproval) return { decision: "ask" };
  return { decision: "allow" };
}

3. Why MCP Needs a Certification Now

Why does MCP need a certification now? The official answer is a set of numbers. Across MCP's Tier 1 SDKs, monthly downloads are approaching half a billion, with both the TypeScript and Python SDKs surpassing one billion downloads in total. Production usage is climbing just as fast: MCP tool calls from ChatGPT users reached 98 times their January level by August, and Resend passed one million MCP calls in a single month. MCP co-creator and lead maintainer David Soria Parra put it directly: they built MCP so developers could rely on one open protocol instead of writing custom integrations for every system, and since it has grown exponentially, giving developers the option to earn a certification in MCP formalises a shared understanding of how the protocol works.

# Domain 3 study route: turn the published blueprint into a checklist.
# The weights tell you where to spend your evenings.

domains:
  - name: MCP Fundamentals
    weight: 16        # hosts, clients, servers, the "why" of the protocol
  - name: Architecture & Components
    weight: 14        # primitives: tools, resources, prompts, transports
  - name: Interactions & Execution
    weight: 26        # message flow, lifecycle, error handling  <- biggest
  - name: Security & Governance
    weight: 24        # trust boundaries, permissions, risk controls <- second
  - name: Use Cases & Ecosystem
    weight: 20        # real deployments and how teams apply MCP

spec_reference: "2026-07-28"   # the exam is aligned to this release
format:
  duration_minutes: 120
  proctored: true
  question_type: multiple-choice
MCP-related code

The exam covers message flow, tools, and trust boundaries

4. The Enterprise View: A Job Description, Translated

For enterprises, the fourth domain deserves separate attention. Angie Jones, Vice President of Developer Experience at the AAIF, notes that as organisations increasingly adopt agentic AI, they need developers who understand how those connections work and how to implement them responsibly, including the permissions and trust boundaries involved. With the MCPA, developers can demonstrate that knowledge through an official certification, giving employers a shared benchmark for assessing the skills required for modern software development. Read that as a job description translation: what teams lack is not people who can call tools, but people who can explain the permission model. It also explains why the credential is positioned against emerging AI engineering, platform engineering, and AI governance roles.

# Domain 4 study route: read a client, do not just read about one.
# Enumerating tools from a server is the clearest way to internalise
# how discovery, capability negotiation, and execution connect.

import asyncio
from mcp import ClientSession, StdioServerParameters
from mcp.client.stdio import stdio_client

async def inspect(server_command: str, args: list[str]):
    params = StdioServerParameters(command=server_command, args=args)
    async with stdio_client(params) as (read, write):
        async with ClientSession(read, write) as session:
            await session.initialize()          # the handshake
            tools = await session.list_tools()  # capability discovery
            for tool in tools.tools:
                print(tool.name, "->", (tool.description or "")[:60])
            resources = await session.list_resources()
            print("resources:", len(resources.resources))

asyncio.run(inspect("python", ["server.py"]))

5. How to Prepare, Weighted by Domain

Prepare by weighting your evenings, not by spreading effort evenly. First, start with the lighter Fundamentals and Architecture domains, but learn them by writing code: build the smallest MCP server you can and touch all three roles, host, client, and server, as code sample 1 does, which also forces you to separate tools, resources, and prompts. Second, treat Interactions and Execution as your main line of study, focusing on message flow, lifecycle, and error handling; code sample 4 shows a client completing a handshake, discovering capabilities, and listing tools, which is the most direct way to internalise it. Third, turn Security and Governance into an audit exercise: for every server you can think of, answer who operates it, what it can read and write, and what record exists when it acts, with code sample 5 as the template. Fourth, check your understanding against specification release 2026-07-28, since the exam is aligned to it. Fifth, prepare the Use Cases and Ecosystem domain from your own integration history rather than someone else's case studies.

# Domain 5 study route: map real deployments. "Use Cases & Ecosystem" is
# a fifth of the exam and it rewards people who have shipped, not just read.
# Keep a short log of what you actually integrated.

use_cases = [
    {"id": "ide-agent",      "transport": "stdio", "trust": "workspace-write"},
    {"id": "issue-tracker",  "transport": "http",  "trust": "read-only"},
    {"id": "ci-runner",      "transport": "http",  "trust": "scoped-write"},
]

def audit_use_cases(cases):
    for case in use_cases:
        # For each case you should be able to answer three questions:
        #   who operates the server?
        #   what can it read and write?
        #   what is logged when it acts?
        print(case["id"], case["transport"], case["trust"])

audit_use_cases(use_cases)
Domains and weightings

Five domains weighted 16, 14, 26, 24, and 20 percent

6. Is It Worth Taking?

Finally, is it worth taking? The test is simple. If your work involves connecting agents to external systems, the certification provides a shared vocabulary, so you and your colleagues and vendors do not have to align on concepts from scratch when discussing permissions and trust boundaries. The official announcement also offers one practical signal: enrolling at AGNTCon + MCPCon Europe in Amsterdam carries a 20 percent discount, and the same discount applies to those registering for AGNTCon + MCPCon North America, taking place October 22 to 23, 2026 in San Jose, California. Given that the AAIF's founding projects include MCP, A2A, AGENTS.md, goose, agentgateway, and Agent Router, this credential is most likely the first of a family. If your team's agent stack keeps expanding, building that shared understanding early will pay off well past exam day.

📌 Frequently Asked Questions

What is the MCPA?

The Model Context Protocol Associate, announced by the Agentic AI Foundation on September 14, 2026. It is a vendor-neutral MCP credential and the first certification launched by the AAIF.

What is the format and length of the exam?

It is a 120-minute, online, proctored, multiple-choice exam aligned with MCP specification release 2026-07-28.

Which domains does the exam cover?

Five domains with these weightings: MCP Fundamentals 16 percent, Architecture and Components 14 percent, Interactions and Execution 26 percent, Security and Governance 24 percent, and Use Cases and Ecosystem 20 percent.

Why was the certification created?

The official rationale is MCP's scale: Tier 1 SDK monthly downloads are approaching half a billion, the TypeScript and Python SDKs each passed one billion total downloads, and MCP tool calls from ChatGPT users reached 98 times their January level by August.

Where can I get a discount on enrolment?

Enrolling on site at AGNTCon + MCPCon Europe in Amsterdam carries a 20 percent discount, and the same discount applies to those registering for AGNTCon + MCPCon North America on October 22 to 23, 2026 in San Jose, California.