The Reference MCP Servers and When You Don't Need Them
The MCP reference servers are seven small servers (Everything, Fetch, Filesystem, Git, Memory, Sequential Thinking and Time) that the MCP steering group maintains to demonstrate the protocol, not to run in production. Claude Code, Codex and Cursor already read and edit files and run git with their own tools, so the reference servers mostly earn their place in chat clients.
You open a repository and find an .mcp.json copied from a 2025 blog post: filesystem, git, github, puppeteer and sequential-thinking. Two of those packages are deprecated, git is launched with npx @modelcontextprotocol/server-git, a package that does not exist on npm, and the Filesystem server gives the agent a second way to write files that your Edit permission rules never see. This page is for developers who want a lean, correct setup, and for tech leads who own the shared MCP config for a team. If MCP is new to you, read the introduction to Model Context Protocol first.
What you get from auditing the reference servers
Section titled “What you get from auditing the reference servers”- A table of the seven maintained reference servers, with the verified package, run command and tool count for each
- The archived servers (GitHub, PostgreSQL, Puppeteer, Slack and nine more) mapped to what replaced them
- A “native tools first” audit of an existing
.mcp.json,.codex/config.tomlor.cursor/mcp.json, with a copy-paste prompt and a verification step - A worked example where the Filesystem server is the right answer: a notes directory for a chat client
- When Desktop Commander is worth its much wider permission surface, and how to fence it
Which MCP reference servers are still maintained?
Section titled “Which MCP reference servers are still maintained?”The modelcontextprotocol/servers README lists seven reference servers and says why they exist: they are “intended as reference implementations to demonstrate MCP features and SDK usage”, “not as production-ready solutions” (README read 2026-09-26). The same README points people who want a catalogue to the MCP Registry instead.
| Server | Package and launch command | Tools | What it does | Needed in Claude Code, Codex or Cursor? |
|---|---|---|---|---|
| Filesystem | npm @modelcontextprotocol/server-filesystem: npx -y @modelcontextprotocol/server-filesystem DIR [DIR…] | 13 | Read, write, edit, move and search files inside allowed directories | Rarely. All three have native file tools. Use it for a directory outside the project with a narrower surface than a shell |
| Git | PyPI mcp-server-git: uvx mcp-server-git --repository PATH | 12 | Status, diffs, log, show, add, commit, reset, branch, checkout | No. The agents run git through their shell. The server has no push, pull or fetch |
| Fetch | PyPI mcp-server-fetch: uvx mcp-server-fetch | 1 | Fetches a URL and converts HTML to Markdown | Rarely. Claude Code has a web fetch tool; Codex has --search. See the SSRF warning below |
| Memory | npm @modelcontextprotocol/server-memory: npx -y @modelcontextprotocol/server-memory | 9 | A knowledge graph of entities, relations and observations in a JSONL file | Rarely. Project memory belongs in CLAUDE.md or AGENTS.md, where it is reviewed in git |
| Sequential Thinking | npm @modelcontextprotocol/server-sequential-thinking: npx -y @modelcontextprotocol/server-sequential-thinking | 1 | A sequential_thinking tool that records numbered, revisable thoughts | Optional. Raising the model’s effort setting usually does the same job |
| Time | PyPI mcp-server-time: uvx mcp-server-time | 2 | Current time and conversion between IANA time zones | Rarely. The agent can run date |
| Everything | npm @modelcontextprotocol/server-everything: npx -y @modelcontextprotocol/server-everything | many | A test server that exercises every MCP feature | Never in daily use. It is for people building MCP clients |
Versions and popularity, as of 2026-09-26: the TypeScript servers are at npm 2026.8.31 and the Python servers at PyPI 2026.8.18 (checked with npm view and the PyPI JSON API). The modelcontextprotocol/servers repository has about 90.6k GitHub stars (GitHub API, read 2026-09-26, recorded in this site’s MCP research dossier). Those stars belong to the whole repository, not to any one server, so they say nothing about how many people run the Filesystem server.
Which reference servers were archived, and what replaced them?
Section titled “Which reference servers were archived, and what replaced them?”Thirteen former reference servers now live in modelcontextprotocol/servers-archived, whose README states that “no security updates or bug fixes will be provided”. An archived package can keep launching for months, which is why stale configs survive audits. Replace each one with the maintained successor:
| Archived reference server | Use instead | Where this site covers it |
|---|---|---|
| GitHub | GitHub’s official MCP server (remote or Docker), or the gh CLI | GitHub MCP server |
| GitLab | GitLab’s official MCP server (beta) | GitHub MCP server (GitLab section) |
| PostgreSQL, SQLite, Redis | A maintained database server, read-only by default | Database MCP servers |
| Puppeteer | Playwright MCP or Chrome DevTools MCP | Browser automation MCP |
| Brave Search | Brave’s own @brave/brave-search-mcp-server | Web research MCP |
| Sentry | Sentry’s official MCP server | Observability MCP |
| Slack | Slack’s official remote MCP server, installed through the slack plugin (slackapi/slack-skills-plugin, formerly slack-mcp-plugin); the reference-servers README also points to a fork maintained by Zencoder | MCP setup in Claude Code (Slack plugin) |
| Google Drive, Google Maps, AWS KB Retrieval, EverArt | No successor recommended here. Check the vendor’s own server in the MCP Registry | — |
How do you run a native-tools-first audit of .mcp.json?
Section titled “How do you run a native-tools-first audit of .mcp.json?”Run the audit before the build stage starts: the MCP config decides which tools the agent can reach before it writes a line. Repeat it when you inherit a repository and whenever someone adds a server.
The principle: a native tool beats an MCP server that does the same job. Native tools sit inside each agent’s permission model. A duplicate MCP tool gets its own name and its own rules: in Claude Code, an Edit deny rule does not match mcp__filesystem__write_file.
-
List what is configured. Run the listing for each tool your team uses.
Terminal window claude mcp list # health-checks approved servers; unapproved .mcp.json entries show as pendingInside a session,
/contextshows how much of the context window MCP tools take. Note the number.Terminal window codex mcp list # name, command, args, enabled or disabledcodex mcp get git --json # full entry, including enabled_tools and disabled_toolsInside a session,
/mcplists the MCP tools Codex loaded (/mcp verbosefor details).Open
.cursor/mcp.jsonin the project and~/.cursor/mcp.jsonin your home directory. Both use the samemcpServersshape as.mcp.json. -
Classify every server. Put each entry in one of four buckets:
Bucket Test Action Duplicate A native tool does the same job (files, git,date, fetching a page)Remove Archived or deprecated The package is in the trap list above Replace with the successor, or remove Scoped gap It reaches something the agent cannot: a directory outside the project, an API, a database Keep, narrowed to the minimum directories or tools Unknown Nobody on the team can say what it is for Remove. Whoever needs it can add it back with a reason -
Hand the classification to the agent. Paste this prompt in the repository root. It proposes changes and edits nothing.
-
Apply the verdicts. Review the agent’s table, then remove or narrow entries yourself.
Terminal window claude mcp remove -s project filesystemclaude mcp remove -s project sequential-thinkingTo switch a server off without deleting its entry, run
/mcp disable SERVER_NAMEinside a session.Terminal window codex mcp remove filesystemcodex mcp removeedits~/.codex/config.toml; delete project-level entries from.codex/config.tomlby hand.To keep a server but limit it, edit
~/.codex/config.toml(or the project’s.codex/config.toml). Codex 0.157.1 acceptsenabledandenabled_toolson each server:[mcp_servers.git]command = "uvx"args = ["mcp-server-git", "--repository", "."]enabled_tools = ["git_status", "git_log", "git_diff"] # read-only subset# enabled = false # keep the entry, load nothingDelete the entries from
.cursor/mcp.json. Commit the project file, so the whole team gets the same change. -
Verify the trimmed setup. Re-run the listing from step 1 and compare
/contextwith the number you noted. In Codex, compare/mcp verbosebefore and after; in Cursor, compare the entries left in.cursor/mcp.jsonand~/.cursor/mcp.jsonwith step 1. Then run the smoke test in the next section. Open the change as a pull request that states why each server went, so the reviewer checks reasons, not JSON.
Both Claude Code and Codex now defer MCP tool definitions through tool search by default, so an idle server costs less context than it did in 2025. The audit still pays off: the risk of a duplicate tool is the permission bypass, not only the tokens.
How do you prove the trimmed setup still works?
Section titled “How do you prove the trimmed setup still works?”Do not read the new config and hope. Make the agent exercise every capability you just moved from MCP to native tools, and have it say which tool it used.
In Codex, start the session with --search or accept curl through the shell as the native route for task 4.
A pass is four completed tasks, each done with a native tool, and no call to a server you removed. For a team, the tech lead signs off on the pull request, and a CODEOWNERS entry on .mcp.json, .cursor/mcp.json and .codex/config.toml keeps later additions reviewed the same way.
Example: give a chat client your notes directory with the Filesystem server
Section titled “Example: give a chat client your notes directory with the Filesystem server”This is where the Filesystem server is the right tool. A chat client such as Claude Desktop has no file tools of its own, and you want it to read and tidy a folder of Markdown notes, and nothing else.
-
Scope the server to one absolute path. The server only touches directories passed as arguments, or directories the client sends as MCP Roots. For Claude Desktop, add this to
claude_desktop_config.json(from the server README; on Windows, launch with"command": "cmd"and put"/c", "npx"first inargs):{"mcpServers": {"notes": {"command": "npx","args": ["-y", "@modelcontextprotocol/server-filesystem", "/Users/me/notes"]}}} -
Or add it to a coding agent, when you want the notes folder available in every project without giving the agent a shell there.
Terminal window claude mcp add -s user notes -- npx -y @modelcontextprotocol/server-filesystem /Users/me/notesFor one session, the native alternative is
claude --add-dir /Users/me/notes(or/add-dirinside the session). It keeps the folder under Claude Code’s own permission rules.Terminal window codex mcp add notes -- npx -y @modelcontextprotocol/server-filesystem /Users/me/notesFor one session, the native alternative is
codex --add-dir /Users/me/notes.Add the same
notesentry as the Claude Desktop JSON above to~/.cursor/mcp.json(all projects) or.cursor/mcp.json(this project only). -
Make it read-only when you only need reads. The README’s Docker variant mounts the folder with the
roflag, so writes fail at the filesystem level rather than relying on the model:{"mcpServers": {"notes": {"command": "docker","args": ["run", "-i", "--rm","--mount", "type=bind,src=/Users/me/notes,dst=/projects/notes,ro","mcp/filesystem", "/projects"]}}} -
Run the task. Paste this prompt in the chat client or agent.
What you should see: a list_allowed_directories call that returns only /Users/me/notes (or /projects under Docker), a batch of search_files and get_file_info calls, and git-style diffs from the dry run. The server marks its tools with MCP annotations: the read tools carry readOnlyHint: true, while write_file, edit_file and move_file are marked destructive. Clients that honour the hints can auto-approve reads and still ask before a write.
When do Git, Fetch, Memory, Sequential Thinking and Time earn a place?
Section titled “When do Git, Fetch, Memory, Sequential Thinking and Time earn a place?”Each server fills a gap for a client that lacks a native tool. In a coding agent, reach for the native route first.
Git: a local repository for a client with no shell
Section titled “Git: a local repository for a client with no shell”mcp-server-git suits a chat client reviewing a local repository. Its tools read status, diffs and history, and can stage, commit, branch and check out; nothing reaches a remote. The README still calls it “in early development”.
claude mcp add git -- uvx mcp-server-git --repository /Users/me/code/apicodex mcp add git -- uvx mcp-server-git --repository /Users/me/code/apiIn Claude Code, Codex and Cursor, the agent runs git in its shell, under its own approval rules. For pull requests and issues, use gh or the GitHub MCP server.
Fetch: web pages as Markdown, with an SSRF warning
Section titled “Fetch: web pages as Markdown, with an SSRF warning”mcp-server-fetch has one tool, fetch, which returns up to 5,000 characters by default. The model reads longer pages in chunks with start_index. It obeys robots.txt for model-initiated requests; --ignore-robots-txt, --user-agent and --proxy-url change that behaviour. The README carries a caution: the server “can access local/internal IP addresses”. An agent that follows a link from a prompt-injected page can therefore reach your internal network. Run it only where that is acceptable. For search and scraping at scale, see web research MCP servers.
Memory: a knowledge graph in one JSONL file
Section titled “Memory: a knowledge graph in one JSONL file”The Memory server stores entities, relations and observations in a JSONL file. The file path comes from MEMORY_FILE_PATH, and by default the file sits in the server’s own directory, which under npx is a package cache. Set the variable to a path you back up:
claude mcp add memory -e MEMORY_FILE_PATH=/Users/me/.agent-memory/memory.jsonl -- npx -y @modelcontextprotocol/server-memoryFor a coding team, project knowledge in CLAUDE.md or AGENTS.md wins, because it changes through reviewed commits. For session-to-session memory tools, see persistent memory plugins.
Sequential Thinking: optional since reasoning models
Section titled “Sequential Thinking: optional since reasoning models”The server gives the model a scratchpad tool for numbered, revisable thoughts. It helped models without built-in reasoning. With current models, raising the effort setting usually does the same job without an extra tool; this is an editorial judgement, not a measured result. If you keep it, set DISABLE_THOUGHT_LOGGING=true to stop it logging every thought.
Time and Everything: niche and testing
Section titled “Time and Everything: niche and testing”Time answers “what time is it in Asia/Tokyo” with two tools; an agent with a shell can run date instead. Everything is a test server for people building MCP clients. Pair it with the MCP Inspector (npx @modelcontextprotocol/inspector, npm 2.8.0) when you build your own MCP server.
When is Desktop Commander worth it?
Section titled “When is Desktop Commander worth it?”Desktop Commander (wonderwhy-er/DesktopCommanderMCP, about 9.8k GitHub stars and npm 0.2.51 as of 2026-09-26) is a community server that gives a chat client a terminal. It starts and talks to long-running processes (start_process, interact_with_process, read_process_output), searches with ripgrep, edits files in blocks, and reads Excel and PDF files. Its README lists about 25 tools.
It targets Claude Desktop. In Claude Code, Codex and Cursor it duplicates the built-in shell and file tools, and it widens the permission surface, so add it there only for a specific gap. The README’s install lines:
# Claude Desktop (writes claude_desktop_config.json; auto-updates on restart)npx @wonderwhy-er/desktop-commander@latest setup
# Claude Code and Codex, per the READMEclaude mcp add --scope user desktop-commander -- npx -y @wonderwhy-er/desktop-commander@latestcodex mcp add desktop-commander -- npx -y @wonderwhy-er/desktop-commander@latestWhere it does earn its keep is a chat client watching a running process:
When reference MCP servers break
Section titled “When reference MCP servers break”npxfails with a 404 for@modelcontextprotocol/server-git. Git, Fetch and Time are PyPI packages. Installuvand launch them withuvx mcp-server-git,uvx mcp-server-fetchoruvx mcp-server-time.- The Filesystem server exits at startup. It needs at least one allowed directory. It throws an error when started with no directory arguments and the client sends no Roots. Add an absolute path to
args. - “Access denied” on a path you allowed. A relative path in
args, or Roots that replaced your arguments. Use absolute paths and ask the agent to calllist_allowed_directories. - “Permission denied” from the operating system. The server runs as your user, so it cannot read files owned by root or another account. Fix the file permissions, or run the Docker variant with a bind mount.
- Large files flood the context.
read_text_filereturns the whole file unless you passheadortail. Tell the agent to search first withsearch_files, then read withhead, and passexcludePatternssuch asnode_modulestodirectory_tree. - Fetch returns a cut-off page. That is the 5,000-character default. Ask the agent to continue with
start_index, or raisemax_lengthin the call. - The Memory graph is empty after a cache cleanup.
MEMORY_FILE_PATHwas not set, so the file lived in thenpxcache. Set it to a stable path and restore the JSONL from backup. mcp-server-gitormcp-server-fetchcrashes after apip install. Both READMEs require MCP Python SDK 1.x (mcp>=1.29.0,<2). An environment with SDK 2.0 breaks them.uvxresolves the right version in an isolated environment.- An archived server still “works”. A deprecated package can keep launching until an API behind it changes. Do not wait for the failure: replace it with the successor from the archived table.
- The agent writes a file your permission rules should have blocked. It used an MCP write tool, not the native one. Remove the duplicate server, or add a deny rule for the MCP tool name, for example
mcp__filesystem__write_filein Claude Code.
Where to go next with MCP servers
Section titled “Where to go next with MCP servers”New to MCP? Start with the introduction to Model Context Protocol.