Using AI · 03 / How AI connects
A brain in a jar, until you give it hands
On its own, a language model can only read what you send it and write a reply. It can’t check the weather, open your files or post to a website. APIs, command lines, tools, MCP and connectors are how AI reaches the rest of the digital world. Here’s how each one works, one hop at a time.
The layers
Interactive · follow one question
“Will it rain at recess?”
Step through what happens behind the scenes when an AI assistant with a weather connector answers a simple question. Watch for the key moment: the model never fetches anything itself. It asks, and the app does the fetching.
Forecast numbers in this demo are made up.
Step 1 of 8
01 · API
The order window between programs
An API (application programming interface) is a set of rules one program uses to ask another program for something. Think of a restaurant: you don’t walk into the kitchen. You order at the window in a set format, and food comes back.
Most AI apps, from a homework helper to a car’s voice assistant, send requests like the one here to a model’s API. The answer comes back with a count of tokens used, which is how AI companies charge.
Access is controlled with an API key, a long secret code. Treat it like a password: never paste it into a chat or post it online.
A real request, simplified
// what the app sends
POST /v1/messages
{
"model": "a-model-name",
"max_tokens": 300,
"messages": [
{ "role": "user",
"content": "Explain photosynthesis in 2 sentences." }
]
}
// what comes back
{
"content": "Plants capture sunlight and use its energy…",
"usage": { "input_tokens": 14, "output_tokens": 41 }
}
$ ai-agent "the science fair site's sign-up form is broken. fix it." ● Reading signup.html, form.js ● Thinking The email check rejects addresses with a “+” in them. ● Running the tests … 2 failed ● Proposing an edit to form.js (line 42) Allow this change? (y/n) y ● Running the tests … all 14 passed ✓ ● Done. Here’s what I changed and why…
02 · CLI
AI in the command line
A CLI (command-line interface) is the text-only way to control a computer: you type commands into a terminal instead of clicking. Programmers have used it for decades.
In 2025, AI companies put agents there: Anthropic’s Claude Code (February), OpenAI’s Codex CLI (April) and Google’s Gemini CLI (June). In a terminal, an AI can read files, run programs and edit code directly, so the human’s job shifts to setting goals and approving actions.
That loop, think → act → observe → repeat, is what makes something an agent rather than a chatbot.
03 · MCP
One plug that fits everything
The Model Context Protocol (MCP) is an open standard for connecting AI applications to outside tools and data. Its official site compares it to a USB-C port for AI: build a connection once, and any AI app that speaks MCP can use it.
12
custom connections to build and maintain: every AI app needs its own adapter for every service.
The AI app you use, like a chat app, a code editor or a terminal agent.
The part of the host that holds one connection to one server.
A small program that offers a service’s abilities: tools (actions), resources (data) and prompts (templates).
Anthropic releases MCP as an open standard.
OpenAI adopts it.
Google says Gemini will support it.
Microsoft announces MCP support for Windows 11.
MCP is donated to the Agentic AI Foundation at the Linux Foundation, so no single company owns it.
04 · Connectors
“Connect your Drive?” What you’re really agreeing to
In chat apps, connectors are the buttons that link an assistant to your email, calendar, documents or a website. Many are built on MCP. When you click “Allow,” you’re giving the AI a key to that account, often through a sign-in screen (OAuth) that lists exactly what it may do.
Ask 1
What can it read?
All your files, or one folder? Every email, or only some?
Ask 2
Can it act?
Reading is different from sending, posting, buying or deleting. Prefer tools that ask you first.
Ask 3
Who built it?
Connectors run code. Use ones from the service itself or from developers you trust.
Ask 4
Can I unplug it?
Know where to remove access in your account settings, and do it when you’re finished.
Least privilege: give an AI only the access it needs for the job. And remember prompt injection: anything a connector reads, like an email or a web page, could contain hidden instructions. See how that works →
A real example · this website
How ARQIV updates itself
The AI race tracker on You are here refreshes every day. A small program on our server calls Artificial Analysis’s API and records each lab’s top benchmark score.
Every week, a scheduled AI agent searches for new studies from trusted sources, writes plain-language summaries, and publishes them to our research feed through a WordPress connector built on MCP. Each story is labeled as AI-generated and links to its original source.
API, agent, connector: the same building blocks on this page, working together.
Our weekly pipeline
Glossary
The words, decoded
Bookmark this for the next time someone says “just hook it up to the API.”
A set of rules for one program to request something from another. AI apps use APIs to talk to models.
A secret code that proves a program is allowed to use an API. Keep it private.
A chunk of text (a word or part of one). Models read and write tokens, and APIs charge by them.
Command-line interface: controlling a computer by typing text commands in a terminal.
An AI that loops through think → act → observe to complete a multi-step goal, using tools.
A structured request from the model (“get_forecast for Elkhart”) that the app carries out.
Model Context Protocol: an open standard that lets any AI app plug into tools and data the same way.
A ready-made link between an AI app and a service like Drive, Slack or a website.
The “Sign in with… / Allow access?” screen that grants an app limited access without sharing your password.
In the classroom · unplugged
Play “Human API”
Students act out a request. It’s the fastest way to understand why the model never fetches anything itself.
Roles
Five students
User, App, Model, Tool server and Website (sits at a desk with a printed forecast and copies the line asked for onto a card). Everyone else watches and tracks the messages on the board.
Rule 1
Notes only
Players pass only written index cards, never talk. Each card is a message with a fixed format, listed below.
Rule 2
The Model can’t look
The Model can only write text, either an answer or a tool request card. Only the Tool server may walk to the Website’s desk.
Debrief
Where could it fail?
What if the Website card had a hidden instruction? What if the Tool server could also delete things? Who should approve that?
Card formats. One message per card, passed in this order:
- User → App:
QUESTION: Will it rain in Elkhart at recess today (11:30)? - App → Model: the question, plus
TOOLS YOU MAY ASK FOR: get_forecast(city, time) - Model → App:
TOOL REQUEST: get_forecast(Elkhart, 11:30), orANSWER: …if it needs no data - App → Tool server: the same tool request (a careful App asks the User “Allow?” first)
- Tool server → Website → Tool server: the Website copies the 11:30 line of its forecast onto a card
- Tool server → App:
TOOL RESULT:that forecast line - App → Model: the question plus the tool result
- Model → App → User:
ANSWER: …
Sources: Model Context Protocol docs (modelcontextprotocol.io); Anthropic, “Introducing the Model Context Protocol” (Nov 25, 2024) and “Donating the Model Context Protocol and establishing the Agentic AI Foundation” (Dec 9, 2025); TechCrunch on OpenAI (Mar 26, 2025) and Google (Apr 9, 2025) adopting MCP; Windows Central on MCP in Windows 11 (May 19, 2025); Anthropic Messages API docs; Anthropic, Claude 3.7 Sonnet and Claude Code (Feb 24, 2025); OpenAI, o3 and o4-mini with Codex CLI (Apr 16, 2025); Google, Gemini CLI (Jun 25, 2025); IBM, “What is an API (application programming interface)?”
Put curiosity to work
Read it. Try it. Question it.
Explore new AI research, or take a paper-first investigation into your classroom.