Two years of agentic editor releases have produced a lot of differentiated UI and almost no differentiated integration. Cursor, Google Antigravity, VS Code, Claude, ChatGPT, and Gemini all connect to external tools the same way: Model Context Protocol. The interesting development is not that any one of them added MCP support — it is that the protocol stopped belonging to the company that wrote it.

That changes what you are actually choosing when you pick an agentic IDE, and it makes some of the lock-in arguments from 2025 obsolete.

MCP moved out from under its author

On December 9, 2025, MCP became a founding project of the Agentic AI Foundation, a directed fund under the Linux Foundation. Anthropic, Block, and OpenAI co-founded the AAIF, with additional support from Google, Microsoft, AWS, Cloudflare, and Bloomberg. Block’s goose and OpenAI’s AGENTS.md joined as the other founding projects.

The maintainer structure did not change. What changed is who owns the trademark and the governance process — the Linux Foundation now provides neutral infrastructure while maintainers keep technical direction. This is the same pattern that made Kubernetes safe to standardize on: the protocol’s future no longer depends on one vendor’s product strategy.

Adoption at the time of the donation: over 97 million monthly SDK downloads and roughly 10,000 active servers, with first-class client support in ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot, and VS Code.

For a team deciding whether to write internal MCP servers, that governance move is the load-bearing fact. An internal server you write today targets a protocol under multi-vendor stewardship rather than one company’s roadmap.

What Antigravity actually is

Google announced Antigravity on November 20, 2025 as an agentic development platform rather than an editor with a chat panel. The structure is an IDE surface with tab completion, plus a “Manager Surface” for spawning and orchestrating multiple agents asynchronously, plus terminal and browser integration. It runs Gemini 3 Pro with generous rate limits, and also supports Anthropic’s Claude Sonnet 4.5 and OpenAI’s GPT-OSS. It launched in public preview at no cost for individuals, on macOS, Windows, and Linux.

Model optionality on a first-party Google product is the notable part. Antigravity is not a Gemini delivery vehicle in the way earlier Google developer tools were tied to Google models.

Its MCP implementation is conventional in the way that matters: the docs specify stdio, Streamable HTTP, and SSE transports, with configuration in mcp_config.json under a single mcpServers object — global at ~/.gemini/config/mcp_config.json, per-workspace at .agents/mcp_config.json. Server entries take command/args/env/cwd for stdio or serverUrl/headers for remote, with disabled and disabledTools for selective shutoff, and OAuth options via authProviderType. There is an MCP Store for browsing and installing servers, covering 40-plus platforms including GitHub, Notion, MongoDB, Firebase, Supabase, and BigQuery.

If you have written an MCP server against any other client, it runs here. That is the whole point.

Where Cursor is competing instead

Cursor’s Composer 2, released March 19, 2026, is a model, not an integration layer. Its announcement reports CursorBench 61.3 (up from 44.2 for Composer 1.5), Terminal-Bench 2.0 at 61.7 (from 47.9), and SWE-bench Multilingual at 73.7 (from 65.9), priced at $0.50/M input and $2.50/M output tokens, with a faster variant at $1.50/M and $7.50/M. Composer 2.5 followed on May 18, 2026.

Notably, the Composer 2 announcement does not mention MCP at all. It does not need to — MCP support is table stakes in the product, and the model is where Cursor is trying to win.

That division is the signal. When the integration protocol is shared, competition moves to the layers that are not: model quality and cost, agent orchestration UX, and how well parallel agents avoid stepping on each other. Cursor 2.0 addressed the last one with git worktrees and remote machines for isolating concurrent agents; Antigravity addressed it with the Manager Surface. Both are answers to the same question — how do you run several agents without them corrupting each other’s work — and neither is a protocol question.

What this means for tool selection

Your MCP servers are portable; your agent workflows are not. An internal server that exposes your deployment API, your ticket system, or your schema registry will work across clients. The prompts, rules files, and orchestration patterns built around a specific product will not. Weight your investment accordingly: put effort into servers, stay light on client-specific configuration.

Evaluate on the non-portable axes. Model cost and quality, how agents are isolated from one another, how review and diff surfaces work, and what happens when an agent fails halfway through a multi-file edit. These are where the products genuinely differ.

Config format convergence is not full portability. Antigravity’s mcpServers object is recognizable to anyone who has configured MCP elsewhere, but file locations and auth handling differ per client. Expect to maintain per-client config even when the server itself is shared. Treat server definitions as the artifact worth version-controlling, and generate client config from it if you support more than one editor across a team.

The transport choice matters more than it looks. stdio servers are simple and local, which makes them easy to trust and awkward to share. Remote HTTP/SSE servers are shareable across a team and across clients, at the cost of needing real authentication and network policy. Teams that start with stdio for everything tend to rewrite when a second person needs the same integration.

The part that is still unsettled

Protocol convergence has not produced security convergence. A shared standard for connecting agents to tools means a shared surface for everything that goes wrong when an agent connects to a tool it should not — and the ecosystem’s answer to server provenance, permission scoping, and audit is still per-client and immature.

Consolidation around MCP settled how agents talk to tools. It did not settle who is allowed to say yes on your behalf, and that is where the next round of work is.