Last updated: 2026: every server below was re-tested against Claude Code, Cursor, and Claude Desktop. Client setup steps re-checked on September 29, 2026 against the MCP docs, Claude Code docs, and Cursor docs; spec details checked against the 2026-07-28 MCP specification and Linux Foundation / Agentic AI Foundation (AAIF) governance.
The Model Context Protocol exploded in 2025. If you build with AI agents or ship AI apps, MCP is now table stakes.
In late 2024 Anthropic released the Model Context Protocol (MCP), a tiny open spec that lets any AI client talk to any tool. Eighteen months later, MCP has become the USB-C of the AI world. Over 300 clients — including Claude Desktop, Cursor, Windsurf, VS Code (GitHub Copilot), Zed, Replit, Continue, and Sourcegraph Cody — all speak it, and Taskade runs the server side, so any of them can connect into your workspace through the hosted Taskade MCP server. The official SDKs cross 97 million monthly downloads. The community has built more than 10,000 public servers across GitHub, npm, PyPI, and dedicated registries like Smithery, Glama, PulseMCP, and SkillsIndex. Claude alone processes over 1 billion tool calls per month via MCP.
This guide is the listicle that did not exist until now. We tested the 15 most useful MCP servers across five categories — productivity, search, dev tools, databases, and communication — installed each one against Claude Desktop, Cursor, and Windsurf, and graded them on six criteria. The result is a developer-friendly map of the MCP ecosystem in April 2026.
What Is MCP? (5-Minute Primer)
MCP stands for Model Context Protocol. It is an open spec, governed by Anthropic with community input, that defines how AI clients talk to external tools and data sources. The protocol is intentionally small. A server advertises a list of tools, the client picks one, and they exchange structured JSON-RPC messages. That is the entire idea.
The Problem MCP Solves
Before MCP, every AI client invented its own tool format. ChatGPT had plugins. Claude had tool use. Cursor had a plugin SDK. Windsurf had cascade actions. If you wanted your SaaS to be callable from all of them, you wrote four integrations and maintained four codebases. MCP collapses that to one. Write a server once, and every compliant client can use it tomorrow.
The economics are obvious. A small startup that ships a single MCP server can be reachable from Claude Desktop, Cursor, Windsurf, Zed, Continue, and any future client without writing more code. The protocol is the integration.
MCP vs OpenAPI vs Function Calling
People confuse these three constantly. They are different layers.
| Layer | What It Defines | Example |
|---|---|---|
| OpenAPI | HTTP endpoint shapes | A REST API spec |
| Function calling | Provider-specific tool format inside an LLM API | OpenAI tools array, Anthropic tool_use blocks |
| MCP | Wire protocol between any AI client and any tool server | Claude Desktop calling a Postgres MCP server |
OpenAPI describes services. Function calling is the LLM provider's runtime. MCP is the bridge that lets a client invoke tools without baking them into the model API. You can wrap an OpenAPI spec inside an MCP server in a few hundred lines of code. You can also expose function-call style tools through MCP. The protocol is the lingua franca, not the implementation.
Clients vs Servers
In MCP, a client is the AI application that wants to use tools. A server is the program that exposes them. The mental model is the reverse of HTTP. The client process spawns or connects to the server, asks "what tools do you have?", and the server replies with a JSON manifest. After that, the client calls tools by name and the server runs them.
Most servers are tiny. The reference Filesystem server is roughly 400 lines of TypeScript. The Git server is similar. The Postgres server adds query validation but is still under 800 lines. Servers are cheap to write, which is why the ecosystem grew so fast.
The 2024–2026 Explosion
Anthropic announced MCP in November 2024 with five reference servers and SDKs in TypeScript and Python. The growth since then has been exponential:
By April 2026 the picture looks like this:
- 97 million monthly SDK downloads across TypeScript, Python, Java, Kotlin, C#, and Swift — 4,750% growth in 16 months
- 10,000-12,000 public MCP servers across GitHub, npm, PyPI, and dedicated registries (up from 500 at end of 2025)
- 300+ MCP clients including Claude Desktop, Cursor, Windsurf, VS Code (GitHub Copilot), Zed, Replit, Continue, and Sourcegraph Cody — any of which can connect into a Taskade workspace
- 1 billion+ tool calls per month via MCP through Claude alone
- 67% of enterprise AI teams using or evaluating MCP, with Fortune 500 deployments at Block, Bloomberg, Amazon, and Pinterest
- Governance by the Linux Foundation — MCP was donated to the Agentic AI Foundation (AAIF) in December 2025, co-founded by Anthropic, OpenAI, Google, Microsoft, AWS, and Block
- Optional OAuth 2.1 authorization in the spec: HTTP servers that use it publish Protected Resource Metadata and bind tokens to their own URL with resource indicators (current spec: 2026-07-28). Local stdio servers read credentials from the environment instead
The protocol is small enough that an experienced developer can read the entire spec in 30 minutes, and the SDKs handle the JSON-RPC framing for you. That low barrier is the reason 10,000+ servers exist instead of 50.
MCP Transport Types (Updated April 2026)
The transport landscape has changed since MCP launched. SSE (Server-Sent Events) is now deprecated. The current standard:
| Transport | Status | Use Case |
|---|---|---|
| stdio | Active | Local development, Claude Desktop, spawned processes |
| Streamable HTTP | Active (new standard) | Remote/production, Docker, multi-client. Replaced SSE in March 2025 spec |
| HTTP+SSE | Deprecated | Backward compatibility only. Atlassian sunsetting June 2026. Many servers still ship it |
If you are building a new MCP server today, use stdio for local tools and Streamable HTTP for remote/hosted tools. Do not build on SSE — it is being phased out across the ecosystem.
MCP vs Google A2A — Complementary, Not Competing
Google announced the Agent-to-Agent (A2A) protocol in April 2025. It is not a competitor to MCP — the two protocols operate at different layers:
MCP connects agents to tools (vertical). A2A connects agents to other agents (horizontal). A server agent uses A2A to receive tasks from other agents, then uses MCP to call underlying tools and APIs. Both protocols are now co-housed under the Linux Foundation's Agentic AI Foundation (AAIF), with IBM's ACP merged into A2A in August 2025.
MCP Security: The OWASP Top 10
OWASP published an MCP-specific Top 10 vulnerability list in early 2026. If you deploy MCP servers in production, these are the risks to mitigate:
| # | Vulnerability | What Happens | Mitigation |
|---|---|---|---|
| 1 | Prompt injection | Malicious instructions in input data trick the AI into running hidden commands | Input sanitization, tool-level validation |
| 2 | Tool poisoning | Malicious servers provide poisoned tool descriptions that alter LLM behavior | Server allowlisting, description auditing |
| 3 | NeighborJack | Servers binding to 0.0.0.0 instead of localhost — found in hundreds of implementations |
Bind to 127.0.0.1 only; network segmentation |
| 4 | Shadow servers | Unapproved MCP deployments outside organizational governance | Server registry, policy enforcement |
| 5 | Cost amplification | Malicious server steers agent into prolonged tool-call chains, inflating costs up to 658x | Call depth limits, budget caps, monitoring |
The MCP authorization spec is optional, but HTTP servers that adopt it follow OAuth 2.1 and can ask for extra scopes step by step. Hosted servers like Taskade MCP run the sign-in flow for you (OAuth 2.0 with PKCE, or a Personal Access Token), and every call is limited to what your workspace role allows. Self-hosted servers require you to implement these controls yourself.
Why Developers Love MCP
Three properties drive the rapid adoption. None of them are technically novel — what is novel is the combination plus the fact that the spec is open and free.
Write Once, Use Everywhere
The single biggest reason MCP wins is that it removes the N×M integration problem. Before MCP, M tool providers had to write N client integrations for N AI clients. With MCP, M tool providers write M servers and N clients implement the protocol once. The integration matrix collapses from M×N to M+N.
For a small SaaS that wants its product to be reachable from every AI assistant, this is decisive. You ship one MCP server, list it in the public registries, and you are done. New clients pick you up automatically.
Scoped Permissions and OAuth
MCP servers can authenticate clients with OAuth, API keys, or mTLS, and they can scope tool exposure per session. A hosted MCP server can enforce that a free-tier user only sees read tools while a paid user gets writes. Taskade MCP takes a different route: no credential narrows the tool set. OAuth issues one mcp scope and a Personal Access Token carries none, so the client simply acts as you. Every tool call is checked against the permission your account holds on that specific workspace and project, so the RBAC model the rest of the product uses is what bounds the client.
This means MCP is enterprise-deployable in ways earlier protocols were not. A security team can audit a single MCP gateway, assign scopes per developer, and rotate tokens centrally.
Community Ecosystem
The combination of an open spec, official SDKs in six languages, and the network effect from Claude Desktop has created a healthy contributor base. The Anthropic GitHub org publishes reference servers under MIT license. Independent maintainers ship dozens of community servers per week. Public registries like mcp.so and pulsemcp.com index hundreds of options with stars, downloads, and last-commit timestamps so you can pick maintained servers easily.
How We Ranked These Servers
We scored each server on six criteria, each on a 1–5 scale:
- Maintenance. Is the repository active? When was the last commit? Does the maintainer respond to issues?
- Production-readiness. Does it handle errors, rate limits, and edge cases? Or is it a weekend hack?
- Documentation. Are install steps clear? Are tools documented with examples?
- Security. OAuth support, scoped tokens, input validation, audit logs.
- Community. GitHub stars, downloads, active contributors, presence in registries.
- Ease of setup. Can a new user install in under five minutes? Or does it require a 12-step guide?
We installed each server against three clients (Claude Desktop, Cursor, Windsurf) and graded the experience. The 15 below are the ones that scored at least 4/5 across the board.
How to Choose an MCP Server: Five Questions
Pick an MCP server by answering five questions in order: what data it must reach, who maintains it, where it runs, what credentials it needs, and how much damage a wrong tool call can do. A server that passes all five is safe to install. One that fails any of them needs a closer look first.
| Question | What to look for | Red flag |
|---|---|---|
| 1. What must it reach? | One clear job: repos, workspace, search, a database | A server that bundles unrelated tools |
| 2. Who maintains it? | The vendor itself, or a maintainer with recent commits | Archived repo, no release in a year |
| 3. Where does it run? | Hosted (OAuth, nothing to install) or local (you own the process) | A local server you cannot read |
| 4. What credential does it hold? | A scoped or read-only token | An admin token or a shared password |
| 5. What can a bad call do? | Read-only tools first, writes behind approval | Delete or evaluate tools with no approval step |
The official MCP reference servers repo says its own servers are "reference implementations" and "not production-ready solutions", so treat even the most famous names as starting points. Twelve former reference servers, including GitHub, PostgreSQL, Redis, Slack, and SQLite, now sit in an archived repository.
TRUST LADDER (install from the top down)
- Vendor-hosted, OAuth e.g. GitHub, Linear, Notion, Taskade
- Vendor-maintained, local e.g. Playwright, Exa
- Official reference server e.g. Filesystem, Git (read the code)
- Community server, active pin the version, read-only token
- Community server, archived avoid for anything sensitive
The 15 Best MCP Servers
We grouped the winners into five categories so you can jump straight to what you need. Productivity and workspace servers are first because they are the highest leverage for most developers — your AI assistant is only as smart as the data it can reach.
Productivity & Workspace
1. Taskade MCP Server (Featured)
Taskade ships a production-grade MCP server that exposes the entire workspace to any compliant client. It is the most complete workspace MCP available because Taskade itself is a unified platform for projects, agents, automations, and integrations. When you connect Claude Code, Claude Desktop, or Cursor to Taskade MCP, the AI can browse your projects, tasks, agents, and automations as context, and write back into the Genesis app source — all backed by a workspace that already wires up 100+ bidirectional integrations.
There are two ways to run it — a hosted endpoint for the no-code path, and an open-source npm package for the developer path. Both connect AI clients to your live Taskade workspace.
| Hosted Taskade MCP | Open-source @taskade/mcp-server |
|
|---|---|---|
| Endpoint | https://www.taskade.com/mcp (type: "url") |
Runs locally via npx -y @taskade/mcp-server |
| Auth | OAuth 2.0 — point-and-click, zero JSON secrets | Personal access token in env |
| Setup | Paste one URL, approve in browser | Edit config, supply token, restart |
| Best for | No-code operators, cross-device, teams | Developers who want local control or to extend tools |
| Plan | All paid plans | Any plan, including Free |
| Transport | Streamable HTTP (remote) | stdio (local) |
| Feature | Detail |
|---|---|
| Hosting | Hosted production endpoint (https://www.taskade.com/mcp) plus open-source self-host |
| Auth | Hosted: OAuth 2.0 with PKCE or a Personal Access Token. Either one acts as you, within your workspace roles. Self-host: personal access token |
| Tools exposed | Read + write your workspace — list spaces, inspect projects/agents/automations, edit Genesis app files |
| Project views surfaced | Every project view, including List, Board, Calendar, Table, Mind Map, Gantt, and Org Chart (Timeline is part of Gantt) |
| RBAC | Honors role model (Owner to Viewer) |
| Hosted plan gating | All paid plans — from Pro at $10/mo billed annually |
| Open-source plan | Any plan, including Free — runs locally with a personal access token |
Strengths:
- Production-grade sign-in with OAuth 2.0 (PKCE) or a Personal Access Token, and every call respects your workspace roles
- Reaches your Taskade workspace — spaces, projects, tasks, agents, media, templates, and your automations list
- Runs both roles — a hosted MCP server external clients call into, plus an MCP Client automation step that calls out to remote servers on every plan (an agent hands that call to the automation rather than making it directly)
- Hosted endpoint connects Claude Code, Claude Desktop, Cursor, Windsurf, Zed, and Continue with one OAuth handshake — no JSON to hand-edit
Weaknesses:
- The hosted, OAuth-secured endpoint requires a paid plan; the open-source package runs on any plan but requires you to manage a token
- Best value when you already use Taskade as a workspace; otherwise you are paying for the host product
Verdict: If you want one MCP server that gives your AI assistant a real workspace — projects, tasks, agents, automations, and integrations — Taskade MCP is the strongest production option in 2026. It is the only server that combines workspace memory, agent intelligence, and reliable automation workflows behind a single OAuth scope.
No-code path (hosted, recommended). Add the hosted endpoint to any MCP client and approve the OAuth login in your browser — no token to paste, no JSON secrets:
Json
{
"mcpServers": {
"taskade": {
"type": "url",
"url": "https://www.taskade.com/mcp"
}
}
}
Developer path (open-source, any plan). Run the package locally with a personal access token in env:
Bash
# Open-source Taskade MCP server — runs locally on any plan
npx -y @taskade/mcp-server
Json
{
"mcpServers": {
"taskade": {
"command": "npx",
"args": ["-y", "@taskade/mcp-server"],
"env": { "TASKADE_API_KEY": "your-personal-access-token" }
}
}
}
Full walkthrough with screenshots: Taskade MCP Server setup guide. For the deep dive on how it works, see the Taskade MCP Server deep-dive and how to connect Claude and Cursor via MCP. For everything the workspace connects to beyond MCP — apps, agents, and integrations in one view — see Taskade's ecosystem map.
From MCP Call to Running App
Most servers in this list stop at "the AI can read your data." Taskade closes a different loop. One OAuth handshake gives the client the whole workspace to read — projects, the agents configured on them, the automations wired behind them — plus a write path into the Genesis app source, so what the client produces lands in a live, cloneable app rather than a chat transcript. This is the Workspace DNA loop running over the wire: Memory (your projects the client reads) feeds Intelligence (agents wielding built-in tools, whose prompts and config the client can inspect) which triggers Execution (automations pushing and pulling across 100+ integrations inside Taskade), and the result becomes new Memory.
The unmatchable part is the last node: an MCP-connected prompt lands in a live Taskade Genesis app — custom domain, password protection, listed in the Community Gallery — not a static template. Clone a live app and point your own AI client at it.

A live community app in the Community Gallery. Connect an AI client over MCP and it can read and edit the workspace behind an app like this one. New here? Build your first app.
2. Notion MCP Server
The Notion MCP server exposes pages, databases, and blocks as tools. It is widely used because Notion is a knowledge base for many teams and the server makes that knowledge addressable from Claude Desktop and Cursor. The maintainer is responsive and the server has held up under sustained usage.
The tool surface includes search, page reads, database queries, page creation, and block updates. OAuth is supported through Notion's developer integration flow, which makes scoping straightforward. Performance is acceptable for read-heavy workflows but writes can be slow because Notion's API is rate-limited at the source.
Strengths: mature, OAuth, broad tool coverage, good docs.
Weaknesses: Notion API rate limits cap throughput; no native handling of complex page hierarchies; database writes occasionally fail on schema mismatches.
Best for: teams that already use Notion as a knowledge base and want to query it from an AI client.
Bash
# Local, with an integration token
NOTION_TOKEN=ntn_... npx -y @notionhq/notion-mcp-serverOr use the hosted server with OAuth: https://mcp.notion.com/mcp
3. Linear MCP Server
The Linear MCP server gives AI assistants access to issues, projects, and cycles in the Linear issue tracker. It is the de facto choice for engineering teams that want to triage tickets from Claude Desktop or Cursor. The server is officially endorsed by the Linear team, which means schema changes are handled upstream rather than breaking the integration.
Tool coverage includes issue search, issue creation, comment threads, status updates, and cycle queries. OAuth is supported through Linear's developer settings. Latency is excellent because Linear's API is fast and the server is thin. The main limitation is that bulk operations (creating 50 issues at once) are not optimized — you have to loop one at a time.
Strengths: official endorsement, fast, complete CRUD coverage, strong docs.
Weaknesses: bulk operations are slow; no built-in caching for project metadata.
Best for: engineering teams that want to triage and create issues from a chat interface.
Bash
# Linear runs a hosted remote MCP server with OAuth
npx -y mcp-remote https://mcp.linear.app/mcp
Data & Search
4. Exa MCP Server
Exa has emerged as the search engine of choice for AI agents because its API is designed around semantic queries and structured results, not keyword matching. The Exa MCP server wraps that API in the standard tool format and is the most-used search server in 2026 by a large margin.
The server exposes web search, similarity search, and content extraction as tools. Results come back as clean JSON with title, URL, snippet, and an optional full-text payload. That structure is friction-free for downstream LLM reasoning, which is why agent builders prefer it over scraping Google. Pricing is per-query with a generous free tier.
Strengths: built for agents, structured JSON, fast, well-documented, free tier.
Weaknesses: paid plan needed for high volume; no support for image search yet.
Best for: agent builders who need web search as a tool.
Bash
EXA_API_KEY=sk-... npx -y exa-mcp-server
5. Brave Search MCP Server
The Brave Search MCP server is the privacy-first alternative. It uses Brave's independent web index, which means no Google or Bing dependency. Results are slightly less polished than Exa for agent use cases but the privacy story is strong enough that many enterprise teams pick it for compliance reasons.
Tool surface includes web search, news search, and image search. Auth is a single API key from Brave's developer portal. The free tier is capped at 2,000 queries per month, which is enough for personal use but not for production agents.
Strengths: privacy-first, independent index, broad search types.
Weaknesses: lower-quality JSON for agent use; tight free-tier cap.
Best for: privacy-sensitive teams or open-source projects.
Bash
BRAVE_API_KEY=... npx -y @brave/brave-search-mcp-server
6. Perplexity MCP Server
Perplexity offers an AI-powered search that returns synthesized answers with citations rather than a list of links. The MCP server wraps the Perplexity API so agents can ask "what is the latest on X" and get a cited answer back. This is useful when you want the AI client to defer the synthesis step to a specialized model.
Perplexity publishes the server itself. Auth is an API key. The main caveat is cost - Perplexity charges per request and the MCP server can rack up bills quickly if you call it on every turn.
Strengths: synthesized answers, citations, easy install.
Weaknesses: cost; no granular control over which model handles the synthesis.
Best for: research workflows where you want a cited answer rather than raw links.
Bash
PERPLEXITY_API_KEY=... npx -y @perplexity-ai/mcp-server
7. Tavily MCP Server
Tavily is another agent-focused search API that competes head-to-head with Exa. The MCP server is well-maintained and the API has a slightly different shape — Tavily emphasizes long-context retrieval and includes a "research" mode that runs a multi-step query plan before returning results. Some agent builders prefer this for deep research tasks.
Strengths: research mode, long-context optimized, agent-first design.
Weaknesses: smaller community than Exa; pricing is per-call.
Best for: deep research agents that need multi-step search planning.
Bash
TAVILY_API_KEY=... npx -y tavily-mcp
Developer Tools
8. GitHub MCP Server (Official)
The official GitHub MCP server is the gold standard for code-aware AI assistants. It exposes repository search, file reads, pull request operations, issue management, and commit history as tools. Because it is maintained by GitHub directly, schema changes are handled upstream and the server tracks new GitHub features as they ship.
Auth is GitHub's standard OAuth flow with scoped personal access tokens. The server respects token permissions, so a read-only token only exposes read tools. This is the right pattern for security and is one reason the server is widely adopted in enterprise.
Strengths: official, OAuth-scoped, broad coverage, fast updates.
Weaknesses: rate-limited by GitHub API; some advanced features (Actions, Projects v2) are partial.
Best for: any developer who wants their AI assistant to read and modify GitHub repos.
Bash
# Official server from GitHub (the old npm reference package is deprecated)
docker run -i --rm -e GITHUB_PERSONAL_ACCESS_TOKEN=ghp_... ghcr.io/github/github-mcp-serverOr the hosted remote server with OAuth: https://api.githubcopilot.com/mcp/
9. Git MCP Server
The Git MCP server is the local-first cousin of the GitHub server. It runs against a checked-out repository on your machine and exposes git operations — log, diff, blame, status, commit, branch — as tools. This is invaluable when you want the AI to understand your local working state without going through a remote API.
The server is part of the official reference servers and is dead simple to install. Performance is excellent because git is a local binary. The main caveat is that it only sees the working directory you point it at — multi-repo workflows require multiple server instances.
Strengths: zero-config, local-first, fast, official.
Weaknesses: single-repo per instance.
Best for: developers who want AI assistants to reason over local commit history.
Bash
uvx mcp-server-git --repository /path/to/repo
10. Filesystem MCP Server
The Filesystem MCP server exposes a directory tree to the AI client as read and write tools. It is the canonical example in the official MCP documentation and is often the first server new users install. Tool surface includes list, read, write, move, and delete with optional path restrictions.
Security is handled by passing an allow-list of root directories at startup. The server refuses to read or write outside those roots. This is the right design — never give an AI assistant access to your whole filesystem.
Strengths: simple, official, scoped roots.
Weaknesses: no built-in encryption; large directories slow down list calls.
Best for: giving AI clients access to a project workspace on local disk.
Bash
npx -y @modelcontextprotocol/server-filesystem /path/to/allowed/dir
11. Playwright MCP Server
Playwright is Microsoft's browser automation library. The Playwright MCP server wraps it as tools so AI clients can navigate pages, click buttons, fill forms, and screenshot results. This is the standard way to give an AI assistant a real browser, which unlocks workflows like end-to-end testing, web scraping behind logins, and visual QA.
The server runs Playwright in headless or headed mode. Tool surface includes navigate, click, type, snapshot, and a generic evaluate tool that runs arbitrary JavaScript. The evaluate tool is powerful but should be scoped carefully because it is effectively remote code execution in the browser.
Strengths: real browser, headless or headed, screenshot support, broad selector model.
Weaknesses: evaluate tool is a footgun without scoping; resource-heavy; large page snapshots can crowd the model's context after a few pages.
Best for: browser automation, E2E testing, visual QA from AI clients.
Bash
npx -y @playwright/mcp
Cloud alternative: if your AI client runs somewhere without a local browser, such as a server or a hosted agent, the Browserbase MCP server runs browser tools on cloud browsers instead, with a live view and session replay. Its tools start and end a session, navigate, and call Stagehand's act, observe, and extract. The history of Browserbase covers how that cloud-browser layer formed.
Databases
12. Postgres MCP Server
The Postgres MCP server gives AI clients read access to a PostgreSQL database. The original reference server was read-only; the maintained Postgres MCP Pro offers a restricted access mode, write operations require explicit opt-in, which is the right security posture for AI-driven analytics. Tool surface includes schema introspection, query execution, and table sampling.
The server uses standard libpq under the hood, so it works against any Postgres-compatible database including AWS RDS, Google Cloud SQL, Supabase, and Neon. Auth is a connection string, which means you should use a scoped read-only role for the AI rather than your application's full-access role.
Strengths: restricted mode, actively maintained, broad Postgres compatibility.
Weaknesses: writes are opt-in and risky; no built-in query timeout.
Best for: analytics and BI workflows where the AI needs to query a production database.
Bash
# The original reference server is archived; Postgres MCP Pro is actively maintained
DATABASE_URI=postgres://... uvx postgres-mcp --access-mode=restricted
13. SQLite MCP Server
The SQLite MCP server is the embedded-database cousin of the Postgres server. It runs against a local SQLite file and exposes the same tool surface — schema, query, sample. This is perfect for personal projects, local-first apps, and quick-and-dirty analytics where you do not want to spin up a real database.
Bash
# Archived reference server; still runs, but no longer receives updates
uvx mcp-server-sqlite --db-path /path/to/db.sqlite
Strengths: zero infrastructure, local-first, fast on small datasets.
Weaknesses: single-writer limitation of SQLite; not suitable for high-concurrency workloads.
Best for: local analytics, personal data, embedded scenarios.
Communication
14. Slack MCP Server
The Slack MCP server exposes channels, messages, users, and reactions as tools. Auth is a Slack bot token with workspace-scoped permissions. The server is widely used inside engineering teams because it lets an AI assistant read on-call channels, summarize threads, and post status updates without leaving the developer's editor.
Strengths: OAuth via Slack apps, read and write tools, broad workspace coverage.
Weaknesses: Slack rate limits are tight; some private channels require admin approval.
Best for: team workflows where the AI helps triage Slack conversations.
Bash
# The original reference server is archived; korotovsky/slack-mcp-server is an actively maintained community option
# Set SLACK_BOT_TOKEN=xoxb-... and follow that repo's install steps
15. Gmail MCP Server
The Gmail MCP server exposes inbox search, message read, draft creation, and send as tools. It uses Google OAuth with scoped permissions, so you can grant read-only access without giving the AI the ability to send mail. This is the right pattern for a personal assistant scenario.
Strengths: Google OAuth, scoped read/write, fast.
Weaknesses: Gmail API quotas; OAuth setup is a few extra steps.
Best for: personal AI assistants that need email context.
Status note (2026): There is no official Gmail server in the reference repo, and the best-known community package (GongRzhe/Gmail-MCP-Server) was archived in August 2025. Treat any Gmail MCP as a community project, review its code, and grant read-only scopes first.
Beyond the 15: Three More Servers Worth Knowing
Three more servers show up on almost every developer shortlist. We did not rank them in the 15 because each solves a narrow job, but each is worth adding once the basics are in place.
| Server | What it gives your agent | Access | Safeguard to switch on |
|---|---|---|---|
| Context7 | Current, version-specific library docs pulled into the prompt so the agent stops guessing at APIs | Hosted at https://mcp.context7.com/mcp, MIT license |
None needed for docs lookups |
| Supabase | Schema exploration and queries against your Supabase projects | Hosted at https://mcp.supabase.com/mcp, OAuth |
Add ?read_only=true and ?project_ref=<id> to the URL |
| Sentry | Error and issue context for debugging | Hosted at https://mcp.sentry.dev/mcp, OAuth |
Approve each tool call |
Supabase's own guide names prompt injection as the main LLM-specific risk: malicious text stored in a database row can trick an agent into running unwanted queries. Its advice is to keep manual approval on for tool calls and to point the server at a development project, not production.
Mega Comparison Matrix (15 × 9)
The full comparison across all 15 servers and the criteria that matter most. Stars are GitHub counts checked on September 29, 2026. Where a server lives inside the official reference repo, the row shows that repo instead.
| Tool | Category | Hosted/Self | Language | Auth | Free | GitHub Stars | Docs Quality | Best For |
|---|---|---|---|---|---|---|---|---|
| Taskade MCP | Productivity | Hosted + Self | TypeScript | OAuth 2.0 or PAT | Self-host only | 166 (open-source repo) | Excellent | Workspace, agents, automations |
| Notion MCP | Productivity | Hosted + Self | TypeScript | OAuth or token | Yes | 4.7k | Good | Knowledge base |
| Linear MCP | Productivity | Hosted | n/a (remote) | OAuth | Yes | n/a (hosted) | Good | Issue tracker |
| Exa MCP | Search | Hosted + Self | TypeScript | API Key | Free tier | 5.1k | Excellent | Agent search |
| Brave Search MCP | Search | Self | TypeScript | API Key | Free tier | 1.5k | Good | Privacy search |
| Perplexity MCP | Search | Self | TypeScript | API Key | Limited | 2.5k | Fair | Research with citations |
| Tavily MCP | Search | Self | TypeScript | API Key | Free tier | 2.4k | Good | Deep research agents |
| GitHub MCP | Dev Tools | Hosted + Self | Go | OAuth or PAT | Yes | 33k | Excellent | Code repos |
| Git MCP | Dev Tools | Self | Python | None (local) | Yes | Reference repo (90k) | Excellent | Local git history |
| Filesystem MCP | Dev Tools | Self | TypeScript | None (local) | Yes | Reference repo (90k) | Excellent | Local files |
| Playwright MCP | Dev Tools | Self | TypeScript | None | Yes | 37.7k | Good | Browser automation |
| Postgres MCP | Databases | Self | Python | Connection string | Yes | 3.4k (Postgres MCP Pro) | Good | Read-only analytics |
| SQLite MCP | Databases | Self | Python | None (local) | Yes | Archived reference | Good | Embedded data |
| Slack MCP | Communication | Self | Go | Bot token | Yes | 1.8k (community) | Good | Team chat |
| Gmail MCP | Communication | Self | TypeScript | Google OAuth | Yes | Archived community | Fair | Personal inbox |
Where to Find MCP Servers: Registry, Directories, and Reference Repo
The official MCP Registry is the first place to look for a server, and it has a REST API at registry.modelcontextprotocol.io. Third-party directories index far more servers but apply less vetting. Use a directory to discover, then apply the five questions above before you install.
| Source | What it is | Best for |
|---|---|---|
| Official MCP Registry | Central directory of published servers, searchable in the browser or by API | Finding vendor-published servers |
| modelcontextprotocol/servers | Seven active reference servers: Everything, Fetch, Filesystem, Git, Memory, Sequential Thinking, Time | Learning the protocol, copying patterns |
| Awesome MCP Servers | Curated community list | Browsing by category |
| Glama | Large searchable registry of servers and clients | Comparing many options fast |
| Taskade Integrations | 100+ bidirectional integrations, plus the Taskade MCP server | Workflows that need triggers and actions, not only tool calls |
MCP Server Architecture
Here is the full picture of how an MCP server fits into a typical AI client setup. The client process spawns the server, talks to it over JSON-RPC (stdio for local servers, Streamable HTTP for remote), and routes tool calls through the model's tool-use API.
The key insight is that the server is a separate process. It runs in its own sandbox, has its own dependencies, and can be replaced independently of the client. That isolation is part of why the protocol scales — a buggy server cannot crash the client.
Here is the layered view in ASCII for those who prefer text:
+-----------------------------------------------------------+
| USER |
+-----------------------------------------------------------+
| AI CLIENT |
| Claude Desktop / Cursor / Windsurf / Taskade Genesis |
+-----------------------------------------------------------+
| MCP TRANSPORT (stdio local / Streamable HTTP remote) |
+-----------------------------------------------------------+
| MCP SERVER PROCESS |
| - Tool registry |
| - JSON-RPC handler |
| - Auth + rate limit |
+-----------------------------------------------------------+
| EXTERNAL RESOURCE |
| API / DB / Filesystem / SaaS |
+-----------------------------------------------------------+
How to Configure Your First MCP Server
This is the five-minute walkthrough every developer asks for. We will install the Filesystem server in Claude Desktop on macOS, but the steps are nearly identical on Windows and across Cursor and Windsurf.
Step 1: Find Your claude_desktop_config.json
The fastest route is Settings > Developer > Edit Config in Claude Desktop, which opens (or creates) the file. On macOS the config lives at:
~/Library/Application Support/Claude/claude_desktop_config.json
On Windows:
%APPDATA%\Claude\claude_desktop_config.json
If the file does not exist yet, create it. Claude Desktop reads it on startup.
Step 2: Add a Server Entry Under mcpServers
Open the file in your editor and add the following:
Json
{
"mcpServers": {
"filesystem": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-filesystem",
"/Users/you/Documents/projects"
]
}
}
}
The command is the binary that runs the server. The args array is everything you would pass on the command line. The last argument here is the allow-list root directory — the server will refuse to read or write outside it.
Step 3: Handle OAuth Tokens (For Hosted Servers)
For servers that need API keys or OAuth tokens, use the env field rather than embedding secrets in args:
Json
{
"mcpServers": {
"github": {
"command": "npx",
"args": ["-y", "@modelcontextprotocol/server-github"],
"env": {
"GITHUB_TOKEN": "ghp_xxxxxxxxxxxxxxxxxxxx"
}
}
}
}
This keeps tokens out of process-list output and makes rotation easier. For Taskade MCP, you can also use a hosted endpoint with OAuth — the server handles the OAuth dance and stores refresh tokens for you.
Step 4: Restart Claude Desktop
Quit and relaunch the app. MCP server config is read at startup, not hot-reloaded. After relaunch, click the "Add files, connectors, and more" control at the bottom-left of the message box, hover Connectors, and click Manage connectors. Your server appears in that list.
Step 5: Verify the Tool Shows Up
Select your server in the connector list. You should see its available tools. For the Filesystem server you should see read_file, write_file, list_directory, move_file, and so on. If the list is empty, the server failed to start.
Step 6: Troubleshoot Common Issues
If tools are not appearing, the most common causes are:
- JSON syntax error in config. Validate the file with
cat claude_desktop_config.json | jqfirst. - Wrong path to npx. On some systems npx is not in Claude Desktop's PATH. Use the absolute path from
which npx. - Server crashed on startup. Run the same command in a terminal to see the error.
- Permission denied. The Filesystem server's allow-list path must be readable by the user that launched Claude Desktop.
Connect MCP Servers to Claude Desktop, Claude Code, and Cursor
Each client connects to MCP servers in a different place: Claude Desktop uses a JSON file or Settings > Connectors, Claude Code uses the claude mcp add command, and Cursor reads mcp.json. The server stays the same, so one hosted URL such as https://www.taskade.com/mcp works in all three.
| Client | Where you add a server | Remote (hosted) server | Local (stdio) server |
|---|---|---|---|
| Claude Desktop | Settings > Developer > Edit Config, or Settings > Connectors | Add > Add custom connector, paste the URL | mcpServers entry with command and args |
| Claude Code | Terminal: claude mcp add |
claude mcp add --transport http <name> <url> |
claude mcp add --transport stdio <name> -- <command> |
| Cursor | ~/.cursor/mcp.json (global) or .cursor/mcp.json (project) |
url field, optional headers |
command, args, optional env |
Claude Code
Add a hosted server, then sign in from inside Claude Code. The -- separator marks where the server command begins for local servers.
Bash
# Hosted server with OAuth (Taskade example)
claude mcp add --transport http taskade https://www.taskade.com/mcp
# Then run /mcp inside Claude Code and follow the browser sign-inLocal server with an environment variable
claude mcp add --env EXA_API_KEY=your-key --transport stdio exa -- npx -y exa-mcp-server
claude mcp list # show servers and health
claude mcp remove exa # remove one
Scopes control who sees a server. The default local scope loads it only in the current project for you. --scope project writes a shared .mcp.json you can commit for your team, and --scope user loads the server in all your projects. Per the Claude Code MCP docs, claude mcp add-from-claude-desktop imports servers you already configured in Claude Desktop.
Cursor
Cursor takes the same mcpServers shape as Claude Desktop, and a hosted server needs only a url:
Json
{
"mcpServers": {
"taskade": { "url": "https://www.taskade.com/mcp" }
}
}
The Cursor MCP docs advise keeping secrets in environment variables, limiting API key permissions, and reading a server's source before you rely on it.
Claude Desktop (hosted servers)
Open Settings > Connectors, click Add, choose Add custom connector, paste the server URL, and complete the sign-in. Afterward you can turn individual tools on or off in the connector settings, per the MCP remote-server guide. Local servers still use the JSON file shown earlier.
What Happens During a Hosted Sign-In
When a client meets a protected remote server, the server answers with a 401 that points to its metadata. The client then finds the authorization server and opens your browser. You approve once, and the client attaches the token to every later request.
This flow follows the MCP authorization spec: clients use PKCE and send a resource parameter naming the server, and the server accepts only tokens issued for itself. You never paste a secret into a file.

For the Taskade-specific walkthrough with screenshots, follow the MCP server setup guide. To call other servers from inside Taskade, the MCP client guide covers the automation step, and MCP connectors explains how they attach to apps.
Building Your Own MCP Server
If none of the existing servers fit, build one. The official SDKs make this trivial — most internal MCP servers ship in a single file under 200 lines. The mental model is simple: define a list of tools with JSON schemas, write a handler function for each, and export the server with a transport.
Here is the request lifecycle of a tool call from the client perspective:
The cycle is symmetric. Each tool call is a single JSON-RPC round trip. Errors flow back as JSON-RPC error objects with structured codes, which lets the client surface them gracefully or retry.
A minimal TypeScript server looks like this:
Typescript
import { Server } from '@modelcontextprotocol/sdk/server/index.js';
import { StdioServerTransport } from '@modelcontextprotocol/sdk/server/stdio.js';const server = new Server({ name: 'hello', version: '1.0.0' }, {
capabilities: { tools: {} },
});
server.setRequestHandler('tools/list', async () => ({
tools: [{
name: 'greet',
description: 'Return a friendly greeting',
inputSchema: {
type: 'object',
properties: { name: { type: 'string' } },
required: ['name'],
},
}],
}));
server.setRequestHandler('tools/call', async (req) => ({
content: [{ type: 'text', text: Hello, ${req.params.arguments.name}! }],
}));
await server.connect(new StdioServerTransport());
That is a fully functional MCP server. Add it to your claude_desktop_config.json, restart, and Claude can call it.
Security Best Practices
MCP gives an AI assistant the ability to take actions in the real world. Treat it accordingly. The security model is your responsibility, not the protocol's.
Scoped OAuth and Least Privilege
Always issue tokens with the narrowest scopes that work. A read-only token for analytics, a write-scoped token for triage, a separate admin token kept out of AI clients entirely. Taskade MCP works the other way around: no credential narrows it, so the narrowing has to happen on the account. Check the effective permission everywhere that account can reach, not just its nominal workspace role, because a project can grant a higher role than the workspace does and a Personal Access Token reaches the whole account. An account that is Viewer across every workspace and project it can see is the read-only equivalent here.
Local vs Hosted: Where the Risk Sits
A local stdio server runs on your machine with your user permissions, so its risk is the code you run. A hosted server runs elsewhere, so its risk is the token you hand over and the data it can reach. The MCP security guide warns that a local server can run any command the client can, and that clients must show the exact startup command before they run it.
| Local (stdio) | Hosted (Streamable HTTP) | |
|---|---|---|
| Runs as | Your user account | The vendor's service |
| Main risk | Malicious or buggy code on your machine | Over-broad token, vendor-side breach |
| Credentials | Environment variables you supply | OAuth token the client stores |
| Your best control | Read the code, restrict directories, pin versions | Narrow the account's permissions, revoke the token |
| Spec guidance | Read credentials from the environment | Follow the OAuth-based authorization spec |
Prompt Injection Through Tool Output
Prompt injection is the risk that text a tool returns, such as a web page, ticket, or database row, contains instructions the model then follows. Claude Code's docs say to verify you trust each server before connecting it, because servers that fetch external content can expose you to prompt injection. Least privilege limits the damage: a read-only token cannot delete anything, whatever the text says.
Vetting Flow Before You Install
Scope minimization is the other half of the spec's advice: request only the scopes an operation needs, and avoid wildcard or all-access scopes so a leaked token cannot reach unrelated tools. If you keep API keys in a config file, follow the same rule as in Taskade's app secrets: never commit them.
Rate Limiting
Hosted servers should enforce per-token rate limits. Self-hosted servers should add a token bucket in front of expensive tools. Without this, a runaway AI loop can exhaust your API quota or your database connection pool in seconds.
Input Validation
Every tool argument must be validated against the JSON schema before execution. The official SDKs do this automatically when you declare schemas, but custom servers often skip the step. Do not skip the step. AI clients sometimes pass malformed arguments and you do not want a SQL injection from a hallucinated query.
Audit Logs
Log every tool call with timestamp, tool name, arguments (redacting secrets), and result code. This is essential for debugging and for security review. Hosted servers like Taskade MCP do this automatically; self-hosted servers should add it from day one.
Dependency Updates
MCP servers depend on official SDKs and third-party libraries. Both ship security fixes regularly. Enable Dependabot or Renovate on every server repo and apply patches promptly. The cost of a known CVE in a server that has filesystem write access is enormous.
MCP Servers by Use Case
A decision tree for picking the right server based on what you need.
Popularity by Client
A rough sense of how MCP server adoption breaks down across the major clients. These bar values are estimated from public registry downloads and self-reported install counts as of April 2026.
Claude Desktop leads because it shipped MCP support first and is still the canonical reference client. Cursor and Windsurf are close behind because their developer audience overlaps heavily with the early MCP adopter base. VS Code arrived later through the GitHub Copilot extension but carries the largest installed base of any editor. Taskade does not appear on this chart because it sits on the other side of the protocol: it ships a server these clients connect into, not a client of its own.
Per-Client Compatibility Matrix
Not every server works equally well in every client. Here is a quick compatibility map.
| Server | Claude Desktop | Cursor | Windsurf | VS Code (Copilot) |
|---|---|---|---|---|
| Taskade MCP | Full | Full | Full | Full |
| GitHub MCP | Full | Full | Full | Full |
| Filesystem MCP | Full | Full | Full | Sandboxed |
| Postgres MCP | Full | Full | Full | Full |
| Exa MCP | Full | Full | Full | Full |
| Notion MCP | Full | Full | Full | Full |
| Playwright MCP | Full | Full | Partial | Full |
| Slack MCP | Full | Full | Full | Full |
Common MCP Gotchas
Five patterns we see trip up every new MCP user. Knowing them in advance saves an hour of head-scratching.
Config Path Bugs
Claude Desktop's config path is non-obvious on every OS. macOS users often miss the space in Application Support. Windows users miss the %APPDATA% expansion. The fix is to copy-paste the path from the official docs and never type it by hand.
Environment Variable Leakage
If you put a secret in the env field of claude_desktop_config.json and commit that file to git, the secret leaks. Add the config to .gitignore immediately or use a secrets manager wrapper that injects env vars at startup.
Tool Naming Collisions
If two MCP servers expose a tool with the same name, the client picks one and ignores the other. This is silent. The fix is to namespace tool names by server (e.g., github.search vs linear.search) or to disable conflicting servers per session.
Transport Timeouts
Default JSON-RPC timeouts are short. If a tool takes more than 30 seconds the client may give up and report an error. The fix is to either bump the client timeout or to make long tools async — return a job ID immediately and let the client poll.
Client Version Drift
The MCP spec is stable but adds capabilities periodically. If your server uses a feature from spec version 1.3 and the client only supports 1.2, you get a confusing error. Pin both ends to compatible versions or test against the lowest version you need to support.
Related Reading
If you build with MCP, you are probably also evaluating agent frameworks, AI app builders, and the broader vibe-coding ecosystem. Here are the deepest internal guides we publish on adjacent topics.
- AI agent builders — full landscape map
- AI agents taxonomy — how agent types break down
- AI prompt generators — the 12 best in 2026
- The living app movement — software that runs itself
- Nemoclaw review — the new entrant in AI agents
- Best Claude Code alternatives for AI coding
- What are AI agents? The full guide
- Claude models explained
- Model Context Protocol in the Taskade wiki
- MCP vs API: what is the difference
- Tool use explained
- Agent tools in Taskade
- Automations that call external MCP servers
- Best Cursor alternatives in 2026
- Best vibe coding tools and AI app builders compared
- Free AI app builders — ship a working app at zero cost
- Community Gallery SEO — programmatic app pages
- Best AI dashboard builders in 2026
- Explore the live AI apps gallery
- Taskade AI Agents — see them in action
- Build with Taskade Genesis (free)
- Browse the Community Gallery
- Integrations directory — 100+ apps
Verdict
The MCP ecosystem in 2026 is the healthiest open protocol the AI tooling world has ever seen. 10,000+ servers, 97 million monthly SDK downloads, official client support across every major editor, and an enterprise security story that holds up under audit. If you build with AI agents and you have not tried MCP yet, you are leaving capability on the table.
Pick the servers from this list that match your stack. Start with one — Filesystem or GitHub if you build software, Taskade if you live in a workspace, Exa if you build search agents — and add more as your needs grow. The protocol rewards composition. Three small servers that each do one thing well beat one giant server that tries to do everything.
For workspace and team data, Taskade MCP is the strongest production option because it combines the full Workspace DNA loop — Memory feeds Intelligence, Intelligence triggers Execution, Execution creates Memory — behind a single OAuth scope. That is the same loop that powers Taskade Genesis, and bringing it into your favorite AI client unlocks the same compounding flywheel. ▲ ■ ● Connect once, and your AI client browses a real workspace instead of a static config file.
FAQ
What is an MCP server?
An MCP server is a small program that exposes tools, data, or APIs to AI clients like Claude Desktop, Cursor, or Windsurf using the Model Context Protocol. It speaks JSON-RPC over stdio (local) or Streamable HTTP (remote), advertises a list of callable tools, and lets the AI invoke them with structured arguments. Think of it as a USB-C port for AI assistants.
What is the best MCP server in 2026?
For workspace and team data, Taskade MCP is the strongest production-grade option, exposing your workspace — projects, tasks, agents, and your automations list — over OAuth 2.0 or a Personal Access Token. For code repositories, GitHub MCP (official) leads. For web search, Exa MCP is the most agent-friendly. The right answer depends on whether you need workspace context, code, search, files, or databases.
How do I install an MCP server?
Open your Claude Desktop config file at ~/Library/Application Support/Claude/claude_desktop_config.json on macOS or %APPDATA%/Claude/claude_desktop_config.json on Windows. Add an entry under mcpServers with a command and args. Restart Claude Desktop. The new tools appear under Connectors in the message box menu. Claude Code uses the claude mcp add command instead, and Cursor uses ~/.cursor/mcp.json.
Is MCP secure?
MCP itself is a transport protocol, so security depends on the server. Best practice is to use OAuth-scoped tokens, restrict tool permissions to least privilege, validate every tool argument, run audit logs, and keep dependencies patched. Hosted servers like Taskade MCP handle sign-in for you. Taskade MCP issues one mcp scope, so the client acts as you, and every call is limited to what your workspace role allows. Self-hosted servers require you to harden them.
MCP vs function calling — what is the difference?
Function calling is a model-specific feature where the AI provider exposes a tool-call format inside its API. MCP is an open protocol that standardizes tool use across providers and clients. Write a tool once as an MCP server and any compliant client (Claude Desktop, Cursor, Windsurf, VS Code) can use it without re-implementation.
Can I build my own MCP server?
Yes. Anthropic publishes official SDKs in TypeScript, Python, Java, Kotlin, C#, and Swift. The minimum server needs a tool list, a tool handler, and a JSON-RPC transport (stdio for local, Streamable HTTP for remote). Most simple servers ship in under 200 lines of code. Start from the official quickstart and add tools incrementally.
What MCP servers work with Cursor and Windsurf?
Almost all of them. Cursor and Windsurf both implement the standard MCP client spec, so any server that runs in Claude Desktop also runs in those editors. Cursor reads MCP servers from ~/.cursor/mcp.json (global) or .cursor/mcp.json (per project) with the same command and args fields, and Windsurf has its own MCP settings. Hosted servers using the Streamable HTTP transport are fully cross-compatible.
Are MCP servers free?
Most open-source MCP servers are free, including the maintained reference servers (Filesystem, Git, Fetch, Memory, Time, Sequential Thinking, Everything). Hosted MCP servers tied to SaaS products often inherit the host product pricing. Taskade ships both: the open-source @taskade/mcp-server runs locally on any plan including Free, while the hosted OAuth endpoint (https://www.taskade.com/mcp) is available on all paid plans.
How many MCP servers exist in 2026?
The community has built more than 10,000 public MCP servers since Anthropic released the protocol in late 2024, with independent registry censuses indexing as many as 17,000 across all sources. The official Anthropic SDKs have crossed 97 million monthly downloads as of early 2026, signaling that MCP has become the de facto standard for AI tool integration across Claude, Cursor, Windsurf, and a growing list of independent clients.
How do I use MCP without writing code?
You do not have to edit JSON config to use MCP. Hosted MCP servers like the Taskade MCP server use OAuth: you paste one URL (https://www.taskade.com/mcp), approve the login in your browser, and your AI client can read your workspace and write into your Genesis app source right away. No tokens to manage, no secrets in files. Ask Claude or Cursor to read a project, review how an agent is configured, or check the automation behind it. The hosted Taskade MCP server is available on all paid plans; the open-source @taskade/mcp-server runs locally on any plan.
Who governs MCP now?
MCP is no longer a single-vendor protocol. Anthropic introduced it in November 2024, then donated it to the Linux Foundation's Agentic AI Foundation (AAIF) in December 2025. The AAIF is co-founded by Anthropic, OpenAI, and Block, with support from Google, Microsoft, AWS, Cloudflare, and Bloomberg. MCP is now vendor-neutral industry infrastructure, governed in the open alongside the complementary Agent-to-Agent (A2A) protocol.
Which plan includes the Taskade MCP server?
The hosted Taskade MCP server (OAuth 2.0, https://www.taskade.com/mcp) is included on all paid plans, starting with Pro at $10/mo billed annually. The open-source @taskade/mcp-server npm package runs locally with a personal access token on any plan, including Free. Both let connected AI clients work across your whole workspace — read projects, inspect the agents and automations on them, and write into your live app's source.
How does Taskade work with MCP?
Taskade runs both sides. It ships a production MCP server that exposes your projects, agents, automations, and integrations to other clients, so you can connect Claude Desktop, Cursor, or VS Code straight to your workspace. In the other direction, the MCP Client step in a Taskade automation points at an external MCP server, lists what it publishes, and calls a tool — on every plan, including Free, with your automation run allowance as the only ceiling. The boundary worth knowing: an agent cannot reach a remote server by itself. Let it make the judgment call and hand the outbound step to the automation. To reach GitHub, Postgres, or anything that does not publish an MCP server, the 100+ integrations and the built-in agent tools still apply.
How do I choose the best MCP server for my project?
Answer five questions in order: what data the server must reach, who maintains it, whether it runs hosted or local, what credential it holds, and what a wrong tool call can do. Prefer vendor-hosted servers with OAuth, start with read-only tokens, and add write tools behind approval. Start with one server that matches your stack, such as GitHub for code, Exa for search, or Taskade for workspace data.
How do I add an MCP server to Claude Code?
Run claude mcp add --transport http NAME URL for a hosted server, then run /mcp inside Claude Code to sign in. For a local server, run claude mcp add --transport stdio NAME -- COMMAND, using the double dash before the command. Use --scope project to write a shared .mcp.json for your team, and claude mcp list to check that each server connects.
Is a local or a hosted MCP server safer?
Neither is safe by default. A local stdio server runs with your user permissions, so the risk is the code you run: read it, restrict directories, and pin versions. A hosted server shifts the risk to the token you grant, so use OAuth, keep scopes narrow, and revoke access you no longer need. Vendor-maintained hosted servers with read-only access are the lowest-risk starting point.
What is prompt injection in MCP?
Prompt injection happens when text returned by a tool, such as a web page, ticket, or database row, contains instructions that the model follows. MCP servers that fetch external content are the main exposure. Limit the damage with read-only tokens, approval prompts for write and delete tools, and trust only servers you have vetted.
Where can I find a list of MCP servers?
Start with the official MCP Registry at registry.modelcontextprotocol.io, which you can search in the browser or through its REST API. The modelcontextprotocol/servers repository holds seven active reference servers, and directories such as Awesome MCP Servers and Glama index many more. Treat every list as discovery only and vet each server before installing.







