MCP 有了官方认证:MCPA 考试到底考什么

·阅读约10分钟·Evergreen Tools Team

2026 年 9 月 14 日,Linux Foundation 旗下的 Agentic AI Foundation(AAIF)在阿姆斯特丹举办 AGNTCon + MCPCon Europe 期间,发布了 Model Context Protocol Associate(MCPA)。这是一项厂商中立的认证,用来验证工程与平台构建者对 Model Context Protocol 概念、架构与实现要点的理解。官方称它是首个官方 MCP 认证,也是 AAIF 推出的第一个认证——换句话说,围绕 Agent 协议这条赛道,第一次出现了可被雇主当作共同基准的东西。

一、考试结构与权重

先把考试结构说清楚,因为它决定了你怎么准备。MCPA 是一场 120 分钟、在线、有监考、全部为选择题的考试,覆盖五个领域,并按权重分配:MCP 基础占 16%,架构与组件占 14%,交互与执行占 26%,安全与治理占 24%,用例与生态占 20%。考试与最新版 MCP 规范 release 2026-07-28 对齐。官方推荐的报考人群是那些理解 MCP 内部机制、并且能从容推理协议如何工作、各组件如何通信的候选人。注意这个措辞——它不是在招「用过某个 MCP 工具的人」,而是在招「能解释协议本身的人」。

// Domain 1 study route: build the smallest MCP server you can, because
// "Architecture & Components" is a lot easier to remember once you have
// written a host, a client, and a server yourself.

import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
import { StdioServerTransport } from "@modelcontextprotocol/sdk/server/stdio.js";

const server = new McpServer({ name: "study-server", version: "1.0.0" });

server.tool(
  "add_note",
  { text: { type: "string" } },
  async ({ text }) => ({
    content: [{ type: "text", text: "stored: " + text.slice(0, 40) }],
  })
);

// Tools, resources, and prompts are three different primitives. If you
// cannot explain when to use each, that is exam Domain 1 and 2 territory.
await server.connect(new StdioServerTransport());
团队学习与培训

MCPA 是 AAIF 推出的首个认证

二、权重透露了什么:一半分值在协议与边界

权重分布透露的信息比考纲本身更多。交互与执行加上安全与治理,正好是 50%。也就是说,这张卷子有整整一半在考两件事:协议的消息流与生命周期是怎么走的,以及信任边界、权限与风险控制是怎么设的。示例 2 把这件事写成了代码形状——工具级别的权限声明、文件系统的读写白名单、默认拒绝的出口策略。如果你只能背出「MCP 让 AI 连接外部系统」这种一句话定义,那么在占一半分值的两个领域上会很难看。反过来,如果你亲手写过一份上面这样的策略,考纲里那些词汇会立刻有具体的对应物。

// Domain 2 study route: trust boundaries. This is the heaviest single
// theme in the exam once you combine "Interactions & Execution" with
// "Security & Governance" — 26 plus 24 percent is half the paper.

const serverPolicy = {
  name: "notes",
  tools: {
    add_note: { sideEffects: "write", scope: "notes", requiresApproval: false },
    delete_all: { sideEffects: "destructive", scope: "notes", requiresApproval: true },
  },
  // Least privilege at the tool level, not the server level.
  fs: { allowRead: ["./notes/**"], allowWrite: ["./notes/**"], deny: ["**/.env*"] },
  egress: { default: "deny", allow: ["notes.internal"] },
};

export function authorise(call, policy = serverPolicy) {
  const tool = policy.tools[call.tool];
  if (!tool) return { decision: "deny", reason: "unknown tool" };
  if (tool.requiresApproval) return { decision: "ask" };
  return { decision: "allow" };
}

三、为什么现在需要一项 MCP 认证

为什么现在需要一项 MCP 认证?官方给出的答案是一串规模数字。在 MCP 的一级 SDK 中,月下载量正逼近 5 亿次,其中 TypeScript 与 Python SDK 的累计下载量均已突破 10 亿次。生产环境的使用增长同样快:来自 ChatGPT 用户的 MCP 工具调用量到 8 月已经达到 1 月的 98 倍,而 Resend 在一个月内就突破了 100 万次 MCP 调用。MCP 的共同创造者与首席维护者 David Soria Parra 说得很直接:他们构建 MCP 是为了让开发者依赖一个开放协议,而不是为每个系统写定制集成;既然它已经指数级增长,让开发者能考取一项 MCP 认证,可以把「协议如何工作」这件事变成一种共享理解。

# Domain 3 study route: turn the published blueprint into a checklist.
# The weights tell you where to spend your evenings.

domains:
  - name: MCP Fundamentals
    weight: 16        # hosts, clients, servers, the "why" of the protocol
  - name: Architecture & Components
    weight: 14        # primitives: tools, resources, prompts, transports
  - name: Interactions & Execution
    weight: 26        # message flow, lifecycle, error handling  <- biggest
  - name: Security & Governance
    weight: 24        # trust boundaries, permissions, risk controls <- second
  - name: Use Cases & Ecosystem
    weight: 20        # real deployments and how teams apply MCP

spec_reference: "2026-07-28"   # the exam is aligned to this release
format:
  duration_minutes: 120
  proctored: true
  question_type: multiple-choice
MCP 相关代码

考试覆盖协议消息流、工具与信任边界

四、企业视角:这是一份招聘需求的翻译

对企业而言,第四领域值得单独关注。AAIF 负责开发者体验的副总裁 Angie Jones 指出,随着组织越来越多地采用 Agentic AI,他们需要真正理解这些连接如何工作、如何负责任地实现(包括其中涉及的权限与信任边界)的开发者;有了 MCPA,开发者可以用官方认证证明这些知识,而雇主也获得了一个共享基准来评估现代软件开发所需的技能。这段官方表述其实是一份招聘需求的翻译:团队缺的不是会调工具的人,而是能解释权限模型的人。这也解释了为什么官方把认证定位成与 AI 工程、平台工程和 AI 治理这些新兴角色对齐。

# Domain 4 study route: read a client, do not just read about one.
# Enumerating tools from a server is the clearest way to internalise
# how discovery, capability negotiation, and execution connect.

import asyncio
from mcp import ClientSession, StdioServerParameters
from mcp.client.stdio import stdio_client

async def inspect(server_command: str, args: list[str]):
    params = StdioServerParameters(command=server_command, args=args)
    async with stdio_client(params) as (read, write):
        async with ClientSession(read, write) as session:
            await session.initialize()          # the handshake
            tools = await session.list_tools()  # capability discovery
            for tool in tools.tools:
                print(tool.name, "->", (tool.description or "")[:60])
            resources = await session.list_resources()
            print("resources:", len(resources.resources))

asyncio.run(inspect("python", ["server.py"]))

五、按权重备考的具体路线

备考建议按领域轻重来分配时间,而不是平均用力。第一,从最轻的基础与架构入手,但用写代码的方式学:亲手搭一个最小 MCP 服务器,把 host、client、server 三个角色都摸一遍,示例 1 就是这份起点,顺带理解 tools、resources、prompts 三个原语的差别。第二,把「交互与执行」当作主线来啃,重点放在消息流、生命周期与错误处理上,示例 4 展示了一个客户端如何完成握手、发现能力、列出工具——这是理解这条主线最直接的方式。第三,把「安全与治理」当成一次审计练习来做,针对每一个你能想到的服务器回答三个问题:谁在运营它、它能读写什么、它行动时留下什么记录,示例 5 是这份练习的模板。第四,对照 2026-07-28 版规范逐条核对,考试与它对齐。第五,准备「用例与生态」这一领域时用你自己的集成记录,而不是别人的案例。

# Domain 5 study route: map real deployments. "Use Cases & Ecosystem" is
# a fifth of the exam and it rewards people who have shipped, not just read.
# Keep a short log of what you actually integrated.

use_cases = [
    {"id": "ide-agent",      "transport": "stdio", "trust": "workspace-write"},
    {"id": "issue-tracker",  "transport": "http",  "trust": "read-only"},
    {"id": "ci-runner",      "transport": "http",  "trust": "scoped-write"},
]

def audit_use_cases(cases):
    for case in use_cases:
        # For each case you should be able to answer three questions:
        #   who operates the server?
        #   what can it read and write?
        #   what is logged when it acts?
        print(case["id"], case["transport"], case["trust"])

audit_use_cases(use_cases)
技能与权重分布

五个领域按 16/14/26/24/20 的权重分配

六、值不值得考

最后说值不值得考。判断标准很简单:如果你的工作涉及把 Agent 接到外部系统,那么这个认证提供的是一份共享词汇表——它能让你和同事、供应商在讨论权限与信任边界时不用从零对齐概念。官方也给了时间与价格之外的一个信号:在阿姆斯特丹的 AGNTCon + MCPCon Europe 现场报名可享受 20% 折扣,同样的折扣也适用于报名 10 月 22 至 23 日在加州圣何塞举行的 AGNTCon + MCPCon North America 的参会者。考虑到 AAIF 的创始项目包括 MCP、A2A、AGENTS.md、goose、agentgateway 与 Agent Router,这项认证大概率只是这套协议家族认证体系的第一块。如果你所在团队的 Agent 技术栈会持续扩张,早点建立这份共同理解,回报不会只在考试当天。

📌 常见问题 FAQ

MCPA 是什么?

Model Context Protocol Associate,由 Agentic AI Foundation 于 2026 年 9 月 14 日发布,是厂商中立的 MCP 认证,也是 AAIF 推出的首个认证。

MCPA 考试的形式与时长是什么?

120 分钟、在线、有监考的多选题考试,与 MCP 规范 release 2026-07-28 对齐。

考试覆盖哪些领域?

五个领域及其权重为:MCP 基础 16%、架构与组件 14%、交互与执行 26%、安全与治理 24%、用例与生态 20%。

为什么要设立这项认证?

官方给出的理由是 MCP 规模增长迅速:一级 SDK 月下载量逼近 5 亿次,TypeScript 与 Python SDK 累计下载均超 10 亿次,ChatGPT 用户的 MCP 工具调用到 8 月已达 1 月的 98 倍。

在哪里报名有优惠?

在阿姆斯特丹举行的 AGNTCon + MCPCon Europe 现场报名可享 20% 折扣,报名 2026 年 10 月 22 至 23 日在加州圣何塞举行的 AGNTCon + MCPCon North America 也可享同样折扣。