Skip to content

The Reference MCP Servers and When You Don't Need Them

The MCP reference servers are seven small servers (Everything, Fetch, Filesystem, Git, Memory, Sequential Thinking and Time) that the MCP steering group maintains to demonstrate the protocol, not to run in production. Claude Code, Codex and Cursor already read and edit files and run git with their own tools, so the reference servers mostly earn their place in chat clients.

You open a repository and find an .mcp.json copied from a 2025 blog post: filesystem, git, github, puppeteer and sequential-thinking. Two of those packages are deprecated, git is launched with npx @modelcontextprotocol/server-git, a package that does not exist on npm, and the Filesystem server gives the agent a second way to write files that your Edit permission rules never see. This page is for developers who want a lean, correct setup, and for tech leads who own the shared MCP config for a team. If MCP is new to you, read the introduction to Model Context Protocol first.

What you get from auditing the reference servers

Section titled “What you get from auditing the reference servers”
  • A table of the seven maintained reference servers, with the verified package, run command and tool count for each
  • The archived servers (GitHub, PostgreSQL, Puppeteer, Slack and nine more) mapped to what replaced them
  • A “native tools first” audit of an existing .mcp.json, .codex/config.toml or .cursor/mcp.json, with a copy-paste prompt and a verification step
  • A worked example where the Filesystem server is the right answer: a notes directory for a chat client
  • When Desktop Commander is worth its much wider permission surface, and how to fence it

Which MCP reference servers are still maintained?

Section titled “Which MCP reference servers are still maintained?”

The modelcontextprotocol/servers README lists seven reference servers and says why they exist: they are “intended as reference implementations to demonstrate MCP features and SDK usage”, “not as production-ready solutions” (README read 2026-09-26). The same README points people who want a catalogue to the MCP Registry instead.

ServerPackage and launch commandToolsWhat it doesNeeded in Claude Code, Codex or Cursor?
Filesystemnpm @modelcontextprotocol/server-filesystem: npx -y @modelcontextprotocol/server-filesystem DIR [DIR…]13Read, write, edit, move and search files inside allowed directoriesRarely. All three have native file tools. Use it for a directory outside the project with a narrower surface than a shell
GitPyPI mcp-server-git: uvx mcp-server-git --repository PATH12Status, diffs, log, show, add, commit, reset, branch, checkoutNo. The agents run git through their shell. The server has no push, pull or fetch
FetchPyPI mcp-server-fetch: uvx mcp-server-fetch1Fetches a URL and converts HTML to MarkdownRarely. Claude Code has a web fetch tool; Codex has --search. See the SSRF warning below
Memorynpm @modelcontextprotocol/server-memory: npx -y @modelcontextprotocol/server-memory9A knowledge graph of entities, relations and observations in a JSONL fileRarely. Project memory belongs in CLAUDE.md or AGENTS.md, where it is reviewed in git
Sequential Thinkingnpm @modelcontextprotocol/server-sequential-thinking: npx -y @modelcontextprotocol/server-sequential-thinking1A sequential_thinking tool that records numbered, revisable thoughtsOptional. Raising the model’s effort setting usually does the same job
TimePyPI mcp-server-time: uvx mcp-server-time2Current time and conversion between IANA time zonesRarely. The agent can run date
Everythingnpm @modelcontextprotocol/server-everything: npx -y @modelcontextprotocol/server-everythingmanyA test server that exercises every MCP featureNever in daily use. It is for people building MCP clients

Versions and popularity, as of 2026-09-26: the TypeScript servers are at npm 2026.8.31 and the Python servers at PyPI 2026.8.18 (checked with npm view and the PyPI JSON API). The modelcontextprotocol/servers repository has about 90.6k GitHub stars (GitHub API, read 2026-09-26, recorded in this site’s MCP research dossier). Those stars belong to the whole repository, not to any one server, so they say nothing about how many people run the Filesystem server.

Which reference servers were archived, and what replaced them?

Section titled “Which reference servers were archived, and what replaced them?”

Thirteen former reference servers now live in modelcontextprotocol/servers-archived, whose README states that “no security updates or bug fixes will be provided”. An archived package can keep launching for months, which is why stale configs survive audits. Replace each one with the maintained successor:

Archived reference serverUse insteadWhere this site covers it
GitHubGitHub’s official MCP server (remote or Docker), or the gh CLIGitHub MCP server
GitLabGitLab’s official MCP server (beta)GitHub MCP server (GitLab section)
PostgreSQL, SQLite, RedisA maintained database server, read-only by defaultDatabase MCP servers
PuppeteerPlaywright MCP or Chrome DevTools MCPBrowser automation MCP
Brave SearchBrave’s own @brave/brave-search-mcp-serverWeb research MCP
SentrySentry’s official MCP serverObservability MCP
SlackSlack’s official remote MCP server, installed through the slack plugin (slackapi/slack-skills-plugin, formerly slack-mcp-plugin); the reference-servers README also points to a fork maintained by ZencoderMCP setup in Claude Code (Slack plugin)
Google Drive, Google Maps, AWS KB Retrieval, EverArtNo successor recommended here. Check the vendor’s own server in the MCP Registry—

How do you run a native-tools-first audit of .mcp.json?

Section titled “How do you run a native-tools-first audit of .mcp.json?”

Run the audit before the build stage starts: the MCP config decides which tools the agent can reach before it writes a line. Repeat it when you inherit a repository and whenever someone adds a server.

The principle: a native tool beats an MCP server that does the same job. Native tools sit inside each agent’s permission model. A duplicate MCP tool gets its own name and its own rules: in Claude Code, an Edit deny rule does not match mcp__filesystem__write_file.

  1. List what is configured. Run the listing for each tool your team uses.

    Terminal window
    claude mcp list # health-checks approved servers; unapproved .mcp.json entries show as pending

    Inside a session, /context shows how much of the context window MCP tools take. Note the number.

  2. Classify every server. Put each entry in one of four buckets:

    BucketTestAction
    DuplicateA native tool does the same job (files, git, date, fetching a page)Remove
    Archived or deprecatedThe package is in the trap list aboveReplace with the successor, or remove
    Scoped gapIt reaches something the agent cannot: a directory outside the project, an API, a databaseKeep, narrowed to the minimum directories or tools
    UnknownNobody on the team can say what it is forRemove. Whoever needs it can add it back with a reason
  3. Hand the classification to the agent. Paste this prompt in the repository root. It proposes changes and edits nothing.

  4. Apply the verdicts. Review the agent’s table, then remove or narrow entries yourself.

    Terminal window
    claude mcp remove -s project filesystem
    claude mcp remove -s project sequential-thinking

    To switch a server off without deleting its entry, run /mcp disable SERVER_NAME inside a session.

  5. Verify the trimmed setup. Re-run the listing from step 1 and compare /context with the number you noted. In Codex, compare /mcp verbose before and after; in Cursor, compare the entries left in .cursor/mcp.json and ~/.cursor/mcp.json with step 1. Then run the smoke test in the next section. Open the change as a pull request that states why each server went, so the reviewer checks reasons, not JSON.

Both Claude Code and Codex now defer MCP tool definitions through tool search by default, so an idle server costs less context than it did in 2025. The audit still pays off: the risk of a duplicate tool is the permission bypass, not only the tokens.

How do you prove the trimmed setup still works?

Section titled “How do you prove the trimmed setup still works?”

Do not read the new config and hope. Make the agent exercise every capability you just moved from MCP to native tools, and have it say which tool it used.

In Codex, start the session with --search or accept curl through the shell as the native route for task 4.

A pass is four completed tasks, each done with a native tool, and no call to a server you removed. For a team, the tech lead signs off on the pull request, and a CODEOWNERS entry on .mcp.json, .cursor/mcp.json and .codex/config.toml keeps later additions reviewed the same way.

Example: give a chat client your notes directory with the Filesystem server

Section titled “Example: give a chat client your notes directory with the Filesystem server”

This is where the Filesystem server is the right tool. A chat client such as Claude Desktop has no file tools of its own, and you want it to read and tidy a folder of Markdown notes, and nothing else.

  1. Scope the server to one absolute path. The server only touches directories passed as arguments, or directories the client sends as MCP Roots. For Claude Desktop, add this to claude_desktop_config.json (from the server README; on Windows, launch with "command": "cmd" and put "/c", "npx" first in args):

    {
    "mcpServers": {
    "notes": {
    "command": "npx",
    "args": ["-y", "@modelcontextprotocol/server-filesystem", "/Users/me/notes"]
    }
    }
    }
  2. Or add it to a coding agent, when you want the notes folder available in every project without giving the agent a shell there.

    Terminal window
    claude mcp add -s user notes -- npx -y @modelcontextprotocol/server-filesystem /Users/me/notes

    For one session, the native alternative is claude --add-dir /Users/me/notes (or /add-dir inside the session). It keeps the folder under Claude Code’s own permission rules.

  3. Make it read-only when you only need reads. The README’s Docker variant mounts the folder with the ro flag, so writes fail at the filesystem level rather than relying on the model:

    {
    "mcpServers": {
    "notes": {
    "command": "docker",
    "args": ["run", "-i", "--rm",
    "--mount", "type=bind,src=/Users/me/notes,dst=/projects/notes,ro",
    "mcp/filesystem", "/projects"]
    }
    }
    }
  4. Run the task. Paste this prompt in the chat client or agent.

What you should see: a list_allowed_directories call that returns only /Users/me/notes (or /projects under Docker), a batch of search_files and get_file_info calls, and git-style diffs from the dry run. The server marks its tools with MCP annotations: the read tools carry readOnlyHint: true, while write_file, edit_file and move_file are marked destructive. Clients that honour the hints can auto-approve reads and still ask before a write.

When do Git, Fetch, Memory, Sequential Thinking and Time earn a place?

Section titled “When do Git, Fetch, Memory, Sequential Thinking and Time earn a place?”

Each server fills a gap for a client that lacks a native tool. In a coding agent, reach for the native route first.

Git: a local repository for a client with no shell

Section titled “Git: a local repository for a client with no shell”

mcp-server-git suits a chat client reviewing a local repository. Its tools read status, diffs and history, and can stage, commit, branch and check out; nothing reaches a remote. The README still calls it “in early development”.

Terminal window
claude mcp add git -- uvx mcp-server-git --repository /Users/me/code/api
codex mcp add git -- uvx mcp-server-git --repository /Users/me/code/api

In Claude Code, Codex and Cursor, the agent runs git in its shell, under its own approval rules. For pull requests and issues, use gh or the GitHub MCP server.

Fetch: web pages as Markdown, with an SSRF warning

Section titled “Fetch: web pages as Markdown, with an SSRF warning”

mcp-server-fetch has one tool, fetch, which returns up to 5,000 characters by default. The model reads longer pages in chunks with start_index. It obeys robots.txt for model-initiated requests; --ignore-robots-txt, --user-agent and --proxy-url change that behaviour. The README carries a caution: the server “can access local/internal IP addresses”. An agent that follows a link from a prompt-injected page can therefore reach your internal network. Run it only where that is acceptable. For search and scraping at scale, see web research MCP servers.

Memory: a knowledge graph in one JSONL file

Section titled “Memory: a knowledge graph in one JSONL file”

The Memory server stores entities, relations and observations in a JSONL file. The file path comes from MEMORY_FILE_PATH, and by default the file sits in the server’s own directory, which under npx is a package cache. Set the variable to a path you back up:

Terminal window
claude mcp add memory -e MEMORY_FILE_PATH=/Users/me/.agent-memory/memory.jsonl -- npx -y @modelcontextprotocol/server-memory

For a coding team, project knowledge in CLAUDE.md or AGENTS.md wins, because it changes through reviewed commits. For session-to-session memory tools, see persistent memory plugins.

Sequential Thinking: optional since reasoning models

Section titled “Sequential Thinking: optional since reasoning models”

The server gives the model a scratchpad tool for numbered, revisable thoughts. It helped models without built-in reasoning. With current models, raising the effort setting usually does the same job without an extra tool; this is an editorial judgement, not a measured result. If you keep it, set DISABLE_THOUGHT_LOGGING=true to stop it logging every thought.

Time answers “what time is it in Asia/Tokyo” with two tools; an agent with a shell can run date instead. Everything is a test server for people building MCP clients. Pair it with the MCP Inspector (npx @modelcontextprotocol/inspector, npm 2.8.0) when you build your own MCP server.

Desktop Commander (wonderwhy-er/DesktopCommanderMCP, about 9.8k GitHub stars and npm 0.2.51 as of 2026-09-26) is a community server that gives a chat client a terminal. It starts and talks to long-running processes (start_process, interact_with_process, read_process_output), searches with ripgrep, edits files in blocks, and reads Excel and PDF files. Its README lists about 25 tools.

It targets Claude Desktop. In Claude Code, Codex and Cursor it duplicates the built-in shell and file tools, and it widens the permission surface, so add it there only for a specific gap. The README’s install lines:

Terminal window
# Claude Desktop (writes claude_desktop_config.json; auto-updates on restart)
npx @wonderwhy-er/desktop-commander@latest setup
# Claude Code and Codex, per the README
claude mcp add --scope user desktop-commander -- npx -y @wonderwhy-er/desktop-commander@latest
codex mcp add desktop-commander -- npx -y @wonderwhy-er/desktop-commander@latest

Where it does earn its keep is a chat client watching a running process:

  • npx fails with a 404 for @modelcontextprotocol/server-git. Git, Fetch and Time are PyPI packages. Install uv and launch them with uvx mcp-server-git, uvx mcp-server-fetch or uvx mcp-server-time.
  • The Filesystem server exits at startup. It needs at least one allowed directory. It throws an error when started with no directory arguments and the client sends no Roots. Add an absolute path to args.
  • “Access denied” on a path you allowed. A relative path in args, or Roots that replaced your arguments. Use absolute paths and ask the agent to call list_allowed_directories.
  • “Permission denied” from the operating system. The server runs as your user, so it cannot read files owned by root or another account. Fix the file permissions, or run the Docker variant with a bind mount.
  • Large files flood the context. read_text_file returns the whole file unless you pass head or tail. Tell the agent to search first with search_files, then read with head, and pass excludePatterns such as node_modules to directory_tree.
  • Fetch returns a cut-off page. That is the 5,000-character default. Ask the agent to continue with start_index, or raise max_length in the call.
  • The Memory graph is empty after a cache cleanup. MEMORY_FILE_PATH was not set, so the file lived in the npx cache. Set it to a stable path and restore the JSONL from backup.
  • mcp-server-git or mcp-server-fetch crashes after a pip install. Both READMEs require MCP Python SDK 1.x (mcp>=1.29.0,<2). An environment with SDK 2.0 breaks them. uvx resolves the right version in an isolated environment.
  • An archived server still “works”. A deprecated package can keep launching until an API behind it changes. Do not wait for the failure: replace it with the successor from the archived table.
  • The agent writes a file your permission rules should have blocked. It used an MCP write tool, not the native one. Remove the duplicate server, or add a deny rule for the MCP tool name, for example mcp__filesystem__write_file in Claude Code.

New to MCP? Start with the introduction to Model Context Protocol.