---
title: "MCP vs CLI: Which One Should Your Agent Use?"
author: "Ecem Karaman"
source: "https://aiwithecem.com/guides/mcp-vs-cli"
published: 2026-09-16
tools: ["Claude","Codex","Multi-Tool"]
topics: ["AI Agents","Workflows","Security"]
---

# MCP vs CLI

Your agent can reach GitHub, a database or Sentry in two ways: through an MCP server or through the tool's command-line interface. The right choice depends on where the agent runs, what each option costs in context, and how tightly you need to control what it can do.

**Last checked against [Claude Code's docs](https://code.claude.com/docs/en/mcp), [Anthropic's API docs](https://platform.claude.com/docs/en/agents-and-tools/tool-use/tool-search-tool) and each server's repository on September 16, 2026.**

> **In this guide**
>
> 1. [The short answer](#the-short-answer)
> 2. [What each one is](#what-each-one-is)
> 3. [The case for the CLI](#the-case-for-the-cli)
> 4. [What changed for MCP](#what-changed-for-mcp)
> 5. [When MCP is the right tool](#when-mcp-is-the-right-tool)
> 6. [Decide in five questions](#decide-in-five-questions)
> 7. [Lock down and audit](#lock-down-and-audit)

## The short answer

> #### Use the CLI
>
> Your agent works in your terminal and the service has a mature command-line tool, like `gh`, `aws` or `gcloud`.
>
> #### Use an MCP server
>
> The agent can't run your CLIs, there's no good CLI, you need a logged-in browser, or you must enforce narrow permissions.
>
> #### Add a skill
>
> On top of either one, to teach the agent when and how to use the tool well.

## What each one is

| Option | What it is | Where it works | Context cost |
| ------ | ---------- | -------------- | ------------ |
| **CLI** | A program the agent runs in a terminal, like `gh pr list` | Agents that run commands in your environment: Claude Code, Codex, Cursor | Nothing until it runs, then its output |
| **MCP server** | A server that exposes typed tools, handles sign-in and returns structured results | Local on your computer or remote, in most AI apps | Tool names or definitions, plus every result |
| **Skill** | Instructions and optional scripts the agent loads when a task matches | Claude, ChatGPT, Codex and other tools that support skills | A short description until used |

## The case for the CLI

- **No tool menu.** An MCP server describes its tools to the model. A CLI adds nothing until the agent runs it. Claude Code's docs recommend preferring CLIs like `gh`, `aws`, `gcloud` and `sentry-cli` when available, since they are "still more context-efficient than MCP servers."
- **Composable output.** A CLI's output can be piped through `grep`, `jq` or into a file, so the agent reads only the part it needs.
- **Fewer tools, better choices.** Anthropic's API docs say Claude's accuracy at picking the right tool degrades past 30 to 50 available tools.
- **Definitions add up.** The same docs put a typical five-server setup (GitHub, Slack, Sentry, Grafana, Splunk) at about 55,000 tokens of tool definitions.

## What changed for MCP

**Definitions now load on demand.** In Claude Code, tool search is on by default. Only tool names and server instructions load at the start of a session, and a tool's full definition loads when Claude needs it. Anthropic reports this typically cuts definition overhead by more than 85%. It needs Claude Sonnet 4.5, Haiku 4.5, Opus 4.5 or a later model.

**Apps offer the same control.** In claude.ai, set **Tool access** to **On demand** once you have 10 or more connectors. OpenAI's Codex docs recommend disabling MCP servers you aren't using, since each one adds context.

**Output is often the bigger cost.** A tool that returns a whole web page or log fills context fast, whether it's an MCP server or a CLI. Claude Code warns when a single MCP result passes 10,000 tokens and caps it at 25,000 by default. Ask for filtered, paginated or summarized output either way.

**Code can replace definitions.** Anthropic describes agents calling MCP tools through code instead of loading every definition. One example dropped from 150,000 tokens to 2,000.

## When MCP is the right tool

| Situation | Why MCP wins | Example |
| --------- | ------------ | ------- |
| The agent can't run your CLIs | Claude on the web and ChatGPT run code in a sandbox, not with your signed-in tools | Connectors for Gmail, Drive or Slack |
| You need a logged-in browser | The agent works in your own session on sites that block automated access | [chrome-devtools-mcp](https://github.com/ChromeDevTools/chrome-devtools-mcp) with `--autoConnect` |
| The CLI is missing or limited | The server handles sign-in and gives the agent clean, structured tools | Check the service's CLI first |
| You need narrow, enforced permissions | The server only exposes the actions you allow | A read-only database server |
| It's an internal tool | You decide exactly what the agent can see and do | Your company's admin API |
| The server does real work | It searches or combines across systems instead of wrapping one API | Error triage with code context |

**Why permissions matter here:** Claude Code's command rules match text patterns. Its docs show that a rule blocking `git push` doesn't match the same push written as `git -C . push`. A server that has no write tool can't be talked into writing.

## Decide in five questions

1. **Can the agent run your signed-in CLIs?** No: use a connector or MCP server.
2. **Is there a mature CLI for this service?** Yes: use it, and add a skill if you repeat the task.
3. **Does the task need your logged-in browser?** Yes: use a browser MCP server.
4. **Do you need to limit it to specific actions?** Yes: use an MCP server with read-only mode or tool filters.
5. **Will the agent use it on most turns?** If not, keep it deferred or turned off until you need it.

## Lock down and audit

**Lock down what you keep:**

- **Databases:** give the agent its own read-only database user, even if the server has safeguards.
- **GitHub MCP:** start it with `--read-only`, and expose only what you need with `--toolsets` or `--tools`.
- **Supabase MCP:** scope it to one project with `project_ref` and add `read_only=true`.
- **Claude connectors:** set each tool to **Always allow**, **Needs approval** or **Blocked** in Customize > Connectors.
- **Browser servers:** a logged-in browser exposes everything in it. chrome-devtools-mcp also collects usage statistics unless you pass `--no-usage-statistics`.
- **Local servers** run with your computer's permissions. Install only ones you trust.

**Audit your setup in 10 minutes:**

1. In Claude Code, run `/context` to see what uses space.
2. Run `/mcp` and list servers you haven't used recently.
3. Disable any server a mature CLI already covers.
4. Turn repeated CLI tasks into a skill.
5. Restrict what's left, then run `/context` again.

A skill that replaces a GitHub MCP server with `gh` can be this short:

```markdown
---
name: github-triage
description: Review open issues and pull requests in this repository with the gh CLI. Use when asked what needs attention.
---

Use the `gh` CLI for GitHub work in this repository.

- List open issues: `gh issue list --state open --limit 20 --json number,title,labels`
- Check pull requests: `gh pr status`
- Ask me before commenting, labeling, closing or merging anything.

Reply with a table: number, title, status, suggested next step.
```

**Go deeper:** [Claude Code MCP docs](https://code.claude.com/docs/en/mcp) · [Code execution with MCP](https://www.anthropic.com/engineering/code-execution-with-mcp) · [The AI Tool Map](/guides/ai-tool-map) · [Claude, End to End](/guides/claude-end-to-end)
