← Back to Insights
ORIGINAL

ACP vs MCP — The Editor Layer Is Not the Tool Layer

Agent Client Protocol is how Zed and JetBrains host a coding agent. MCP is how that agent reaches tools. They share JSON-RPC. They do not share an allowlist. Spell the words before you pick a winner.

Two-layer operator desk: a code editor reviewing agent diffs on top, tool sockets to git, database, and CI below, with the agent connecting both

The slide this month is “ACP vs MCP.” It sounds like a bake-off. It is not.

Agent Client Protocol is how an editor hosts a coding agent — sessions, prompts, diffs, permission prompts. Model Context Protocol is how that agent reaches GitHub, CI, a warehouse, a browser. They share JSON-RPC. They do not share a job, a trust boundary, or an allowlist row.

If you treat ACP as the new MCP, you will install Claude Code in Zed and think the org is done. If you treat MCP as the new ACP, you will paste a remote URL into .cursor/mcp.json and wonder why JetBrains still has no agent. The operator mistake is collapsing two sockets.

Say which ACP you mean

Three products share the letters. Boards will mix them. Do not.

LettersFull nameConnectsStatus in 2026
ACPAgent Client Protocol (Zed + JetBrains)Editor ↔ coding agentActive. This article.
ACPAgent Communication Protocol (BeeAI / IBM)Agent ↔ agent over RESTFolded into Linux Foundation A2A. Archived as a separate spec.
ACPAgentic Commerce Protocol (OpenAI / Stripe)Checkout ↔ merchantUnrelated. Do not put it in the engineering allowlist.

A2A (Google, now Linux Foundation) is the surviving agent-to-agent layer. WebMCP is still the page. MCP Apps are still widgets inside a host — see MCP Apps are not WebMCP. None of those replace Agent Client Protocol, and none of them replace MCP.

What ACP actually standardizes

Without ACP, every editor ships a custom plug for every agent, and every agent ships a custom plug for every editor. That is the LSP problem with a chat window. Zed published Agent Client Protocol so one agent implementation can sit in Zed, JetBrains IDEs, Neovim, Emacs, and anything else that speaks the spec. JetBrains co-leads the protocol and the ACP Registry — browse, install, run. Gemini CLI, Claude Agent / Claude Code, Codex CLI, Copilot CLI, OpenCode, Goose, and others already show up there.

The shape:

That is why the LSP analogy sticks. LSP gave every editor language intelligence. ACP gives every editor a coding agent without forking the IDE. Official overview: agentclientprotocol.com.

ACP does not tell the agent how to talk to Postgres. That is MCP’s job — and ACP is explicit about it. On session/new / session/resume, the editor MAY pass mcpServers: stdio and HTTP connection blocks the agent should attach. Agents advertise session.mcp.stdio and session.mcp.http at initialize. The ACP v2 migration note goes further: if the editor wants the agent to see files and terminals, it should hand those over as an MCP server on the session, not a second private API. The editor socket and the tool socket are designed to meet in the middle.

What MCP still is (and is not)

MCP is the client-to-server protocol for tools, resources, and prompts. Hosts like Cursor, Claude, ChatGPT, VS Code, and Claude Code open one MCP client per server. Servers expose tools/list / tools/call. Transport is stdio locally or Streamable HTTP remotely. Spec revision 2026-07-28 made the protocol stateless. Governance is the Agentic AI Foundation under the Linux Foundation. Primer: what MCP is.

Influzer’s job is that catalog. Snapshot this week: about 12,850 MCP servers, about 383 with indexed tools. Search is abundant. Governed surfaces are not. ACP’s registry is a directory of agents. Ours is a directory of tool servers. Mixing them is how a “we installed MCP” slide gets written after someone clicked Install on Claude Code in IntelliJ.

The agent sits in both conversations

Direction is the whole difference.

Same process, two hats. To the editor it is an ACP server. To GitHub MCP it is an MCP client. That is why “ACP vs MCP” is a bad title for a strategy offsite and a good title for a wiring diagram.

ACPMCP
QuestionWhich agent, in which editor?What may that agent touch?
LSP cousinLanguage servers for agentsUSB-C for tools
Typical transportstdio (editor ↔ subprocess)stdio or HTTPS
Core objectsSessions, turns, diffs, permissionsTools, resources, prompts
Who starts itThe editor launches the agentThe agent (or host) attaches a server
GovernanceZed + JetBrains (Apache 2.0 spec)AAIF / Linux Foundation
Influzer surfaceNot our catalogMCP directory + Discovery

Where this shows up in a real stack

Terminal-only (Claude Code, Codex, Gemini CLI in a shell)

ACP is idle. The human is the client. MCP still matters: claude mcp add, Codex MCP config, whatever the harness uses. See CLI vs Desktop connectors.

Zed or JetBrains with an ACP agent

Both protocols are live. The editor hosts the agent over ACP. That agent still needs MCP for CI logs, Linear, Discovery, Postgres. MCP servers already configured inside the agent usually travel with it into the IDE. MCP servers configured in the editor get forwarded on session/new as mcpServers — if the agent advertised the transport.

Cursor and VS Code

First-class MCP. Not native ACP hosts (community extensions exist for VS Code). Cursor’s own CLI can appear as an ACP agent in other editors. So “we standardized on Cursor MCP” does not answer “what runs in IntelliJ.” And “we installed from the ACP Registry” does not answer “which remotes can write.”

Claude Desktop / ChatGPT

These are MCP hosts (and ChatGPT has site tools / MCP Apps). They are not ACP clients. Different humans, different attach path — one connector, three surfaces.

Why it matters (this is the operating issue)

1. You now have two install buttons

ACP Registry Install puts an agent binary in the IDE. MCP Connect puts a tool server on that agent (or on Cursor). Security questionnaires that only list MCP URLs miss the agent that will call them. Questionnaires that only list “we use Claude Code” miss the 12,000-server long tail someone pasted into the agent’s config.

2. There are two allowlists, and they leak into each other

Allowlist A: which agents may run in which editors (ACP). Allowlist B: which MCP URLs those agents may call. Editor-forwarded mcpServers is how B gets injected at session start. Agent-local MCP config is how B bypasses the editor. If you only govern .cursor/mcp.json, JetBrains users are a shadow inventory. If you only govern the ACP Registry, a stdio MCP with a PAT in env is still live. Same discipline as policy before plugins — now applied twice.

3. Auth splits three ways

The agent has its own login (Claude Code /login, Gemini Google login, Codex ChatGPT). The editor may have its own AI subscription — JetBrains is explicit that ACP agents bill the agent vendor, not JetBrains AI. MCP servers have a third gate: OAuth, PAT, or open. “The IDE is signed in” is not “GitHub MCP is scoped.” Paste-a-key in an ACP-launched stdio server is still paste-a-key.

4. Permissions are not the same control

ACP permission prompts are about edits and terminals in this repo. MCP permissions are about tools on that host. Approving a diff does not approve repos_delete. Approving an MCP tool does not mean the editor showed you the patch. Keep eyes before hands on the MCP side even when ACP makes the diff feel safe.

5. Abandoned domains and demoware did not move

OX’s $4 MCP hostnames, thin listings, sessionful leftovers — those are MCP supply-chain issues. ACP does not inventory them. Putting Claude Code in IntelliJ does not handshake tools/list. You still need owner, DNS, auth gate, keep/quarantine/kill. See abandoned domains and honest labels.

6. MCP Apps and WebMCP are yet more surfaces

An ACP session can still call a server that ships SEP-1865 UI into Claude, or a human can still open a site with WebMCP. The editor protocol does not collapse those. Do not file “ACP support” as the WebMCP roadmap.

A map you can print

Human
  → Editor (Zed / JetBrains / …)     [ACP: sessions, diffs, yes/no]
      → Coding agent (Claude Code, Gemini CLI, Codex, …)
          → MCP servers (GitHub, CI, Discovery, filesystem)
              tools/list  ·  tools/call  ·  maybe MCP App HTML

Human (no editor)
  → Same agent in a terminal          [no ACP]
      → Same MCP servers

Human in a browser
  → Website                           [WebMCP / site tools]
  → ChatGPT / Claude chat             [MCP connectors, not ACP]

If a vendor cannot point at one of those arrows, they are selling a slogan.

Operator checklist (90 minutes)

  1. Inventory ACP agents. Zed ACP Registry, JetBrains Settings → AI Assistant → Agents, any acp.json. Name, vendor, who pays, who is allowed.
  2. Inventory MCP on each agent. Agent-local config and editor-forwarded mcpServers. Same URL on both is one row, not two servers.
  3. Mark transport. Stdio vs HTTP on MCP. If the agent never advertised session.mcp.http, your remote connector will not magically appear in that IDE session.
  4. Split writes. Repo edits via ACP prompts. Tool writes via MCP allowlist. Read-only Discovery can stay search-open: https://www.influzer.ai/mcp/discovery.
  5. Do not confuse registries. ACP Registry = agents. Influzer / official MCP registries = servers. Install from the wrong list and you will either get a model with no tools or tools with no review UI.
  6. Test one loop. ACP agent in the IDE, one MCP server you already trust, one question that requires a tool. Confirm the permission prompt and the tool call. If you only see a diff, you never left ACP.

What Influzer will not pretend

We will not index ACP agents as MCP servers. Claude Code in the ACP Registry is not a listing in the Top 100. Discovery will not “search ACP.” If you need a tool surface, you still search MCP by capability and allowlist the URL.

We will keep saying the complementary sentences: a website is not an MCP server; an MCP App is not a website; ACP is not MCP. The stack that ships is allowed to use all of them. The slide that ships should not pretend they are one protocol with three logos.

Quick answers

Is ACP a replacement for MCP?

No. ACP replaces per-editor agent plugins. MCP replaces per-agent tool glue. You often run both.

Do we need ACP if everyone uses Cursor?

Not for Cursor itself today. You need it the moment someone lives in IntelliJ or Zed and still wants Claude Code or Gemini CLI with native diffs. You needed MCP yesterday either way.

If the editor forwards MCP servers, can we ignore agent-local config?

No. Agents bring their own MCP. Forwarding is additive. Inventory both.

Is BeeAI ACP the same thing?

No. That Agent Communication Protocol merged into A2A. If a procurement doc says “ACP” in 2026, make them spell the words.

Where should we start on Influzer?

Directory for servers. Discovery from inside the agent. This Insight for the editor socket. Do not submit an ACP agent to /mcp/submit.

Final thought

LSP unbundled languages from editors. MCP unbundled tools from models. ACP unbundles coding agents from IDEs. They stack. They do not compete.

ACP picks the agent. MCP picks what it can touch. Policy has to name both.

Start with the MCP directory. Search from the agent with Discovery. If your next architecture slide has a single box labeled “ACP/MCP,” split it before Toronto’s hallway does it for you.

GET PRACTICAL AI PLAYBOOKS WEEKLY

One clear email each Thursday

Actionable frameworks on AI execution, agents, and MCP. Join 4,200+ builders.

✓ You're in — first briefing Thursday.

Leave a comment

Be the first to share your thoughts.

Related insights

2026-10-02
MCP Apps Are Not WebMCP
SEP-1865 puts a sandboxed widget inside Claude and ChatGPT. WebMCP puts tools on the live page. Classic MCP is still just JSON. Pick the surface before Toronto sells you all three as one demo.
2026-10-01
Pack an Allowlist for MCP Dev Summit
MCP Dev Summit opens in Toronto on 5–6 October. The hallway will sell you plugins. Bring a map of the remotes you already run — and a one-page allowlist — or you will come home with stickers.
2026-09-28
Your Website Is Not an MCP Server
ChatGPT site tools are WebMCP on a live page — not another remote connector. If you wrap your storefront as an MCP server, you built the wrong trust boundary.