Oct 08, 2026
11 min read

How PayPal turned MCP from a common protocol into a governed platform for identity, discovery, certification, and scale.
Historical point-in-time figures as of May 2026, not public service-level commitments.
An AI assistant can draft an incident update, retrieve a metric, or assemble project context. Inside a large company, every useful answer crosses live systems. The hard part is carrying identity, policy, and auditability with the request.
MCP speaks the language. Enterprises still need the operating model.
Anthropic introduced the Model Context Protocol in November 2024 as an open standard for connecting AI applications to tools and data. MCP later moved under the Linux Foundation's Agentic AI Foundation, giving the protocol a vendor-neutral home.
The standard solves a vital interoperability problem. Current MCP specifications also include authorization and security building blocks. A large enterprise still has to make its own policy, identity, certification, discovery, and operating choices.
| MCP provides | The platform adds |
|---|---|
| A common way for AI applications and servers to communicate | Certification, registry ownership, and a production operating model |
| Standard primitives for tools, resources, and prompts | Enterprise identity, policy, and authorization-scoped discovery |
| Authorization and security building blocks | Downstream credential mediation, observability, and audit evidence |
These platform responsibilities are PayPal's implementation choices, not requirements imposed by the protocol.
The first few integrations can answer those questions locally. The next hundred expose the weakness of that model. Local choices become fragmented policy, duplicated credentials, uneven telemetry, and a user experience built from setup instructions.
At this point, connecting more tools was no longer the challenge. Designing a platform to manage them was.
The Cosmos.AI MCP platform places the PayPal MCP Hub between supported AI clients and certified internal MCP servers. By May 2026, supported clients included Claude, ChatGPT, Perplexity, and VS Code.
They connected to one stable MCP surface, while retaining client-specific capabilities and action-approval experiences. Users reached the certified catalog subject to their own authorization, not a universal list of every server.
The Hub exposes two operations:
Conceptual architecture: four supported AI clients connect to a central Hub, which routes authorized calls to certified servers across two trust zones while emitting operations and audit events.
The client sees a small, stable surface. Behind it, the platform coordinates registration, certification state, identity, policy, routing, downstream credentials, and telemetry.
Discovery and execution are separate policy events. A plain-language request becomes a tool call in three distinct phases. The Hub limits what can be discovered, the client decides how the action should be presented or approved, and the Hub checks authorization again before execution.
One connection does not mean one universal permission. The Hub uses a separately selected, audience-bound credential downstream instead of passing its inbound credential through. Consequential actions can still require client approval, and authorization is evaluated again at invocation time.
A large catalog can make the model less useful. Two thousand tools sound useful until every schema competes for space in the model's working context. In PayPal's 2025 client tests, naively exposing the full discovered catalog to the model produced about 140,000 tokens of tool definitions in the measured 200K-context setup.
That was 70 percent of the available context before the user had asked a question.
| Approach (internal 2025 study setup) | Tool-schema context |
|---|---|
| Full catalog test | ~140K tokens |
| On-demand retrieval | ~1.6K tokens |
That is an estimated 98.9% reduction in this catalog and client setup, returning about 138,400 tokens to the user's work.
The Hub inverted the pattern. Instead of placing the full catalog in model context, it retrieved a small set of relevant schemas on demand. Authorization was applied before retrieval, so the search corpus was already limited to tools the user could invoke.
The finding is historical and environment specific. Current MCP specifications support cacheable list results, and schemas, clients, tokenizers, and cache behavior vary. The durable lesson is not the exact count. It is that a large enterprise catalog needs a deliberate context strategy.
Make the safe path feel like the easy path. The team organized the platform around six gaps that appeared as MCP moved from pilot to production.
Catalog growth also depended on a predictable producer journey. Shared tooling moved common engineering and governance work into a repeatable path:
Scaffold, Implement, Build and scan, Register, Test, Certify, Deploy and observe.
A single review path would either slow low-risk integrations or weaken scrutiny for sensitive systems. The platform used two trust zones.
Both paths fed the same certified registry and monitoring model. The rigor changed with the risk. The existence of a gate did not.
Growth without a new destination. The Hub launched deliberately with roughly 100 active users in September 2025. A smaller launch protected trust while the team exercised certification, authentication, and scale under realistic use.
Eight months later, in May 2026, the platform served 6,000 active users, including 3,500 monthly active users, across functions that included engineering, product, marketing, support, finance, and legal.
The platform did not ask people to move into another interface. It made their supported AI clients more useful for PayPal-specific tasks. The supply side mattered too: shared builder infrastructure and risk-calibrated certification helped the catalog grow to 175 certified servers in the same period.
The source paper reports an operational case study, not a controlled causal analysis. The figures are historical internal metrics and should be published with PayPal's definitions of active user and monthly active user.
Every company's identity, network, and risk model will differ. These five principles travel well.
A protocol became enterprise infrastructure.
MCP gave PayPal a common language. The platform around it made that language operable across identity, policy, discovery, credentials, certification, and telemetry.
Service teams could focus on the systems they own. Users could focus on the task in front of them. One connection, governed end to end, with the complexity carried by the platform instead of the person.
Unless otherwise noted, adoption, catalog, architecture, process, and benchmark figures are based on aggregated PayPal internal telemetry, registry snapshots, and the externally approved case-study paper through May 2026. They are historical point-in-time figures, not public service-level commitments.
The token comparison is an internal estimate from the study's catalog and client setup. Results vary with schema content, client behavior, caching, model, and tokenizer. This article describes Hub-mediated access to certified MCP systems. It does not claim that architecture alone establishes legal or regulatory compliance.

4 min read

4 min read

10 min read