Skip to content

Top 30 MCP Servers for Software Teams, Ranked (September 2026)

The 30 most useful MCP servers for software teams in September 2026 are led by GitHub, Context7, Playwright, Chrome DevTools and Figma. Twenty-three of the 30 are official vendor servers, 16 offer a hosted remote endpoint, and each read-only switch is spelled differently. Most teams need five servers or fewer, chosen by the systems they already operate.

A developer copies a GitHub MCP config from a 2025 blog post. Its package, @modelcontextprotocol/server-github, is deprecated, so they point the remote server at a full-scope personal access token instead. A week later an agent “tidying up” closes 14 issues it judged duplicates. Nothing was hacked: the server did what the token allowed, and nobody had turned on GitHub’s read-only mode.

This page is for the developer picking servers for their own agent and the tech lead who owns the team’s shared .mcp.json. New to MCP? Start with the introduction to Model Context Protocol.

  • One table of 30 verified servers: maintainer, where it runs, its read-only switch and a dated popularity signal, with an install line for each.
  • A read-only setup for GitHub, Supabase and Grafana in Claude Code, Codex and Cursor, plus a CI check that keeps it read-only.
  • A starter stack per team type, and a table of package names that look right and are wrong.

The order puts day-to-day usefulness for a software team first and popularity second. Registry presence alone does not qualify a server: the Official MCP Registry is a preview that lists 36,176 servers and checks namespaces, not quality (registry API, read 2026-09-26). Every server was checked against its own repository, package registry or plugin manifest on 2026-09-26.

Popularity as of 2026-09-26 uses three signals read directly from vendors and GitHub; download counts are not included:

MarkerWhat it means
★33.2kGitHub stars on the server’s repository (GitHub API). Stars measure attention, not use.
RegListed in the Official MCP Registry under the vendor’s own namespace.
319k inst.Installs of the vendor’s plugin on the Claude Marketplace directory (claude.com/plugins).

“Read-only switch” is the server-side setting that removes write tools. Token scope means no such switch was found on 2026-09-26, so the credential’s own permissions are the only limit.

#ServerWhat the agent getsMaintainerRunsRead-only switchPopularity (2026-09-26)
1GitHub MCP ServerPRs, issues, Actions logs, code securityOfficial (GitHub)Remote + local/readonly URL suffix, X-MCP-Readonly header, local --read-only★33.2k · Reg · 319k inst.
2Context7Version-specific library docsOfficial (Upstash)Remote + localNot needed: docs lookup only★62.4k · Reg · 418k inst.
3Playwright MCPBrowser automation over the accessibility treeOfficial (Microsoft)LocalNone; point it at local or staging URLs★37.6k · Reg · 320k inst.
4Chrome DevTools MCPPerformance traces, Lighthouse, network, consoleOfficial (Chrome DevTools team)LocalNone; --slim cuts it to basic tools★52.6k · Reg · 103k inst.
5Figma MCPDesign context, code generation, Code ConnectOfficial (Figma)RemoteToken scope; canvas writes are a remote betaReg · 168k inst.
6Sentry MCPIssues, events, traces, SeerOfficial (Sentry)Remote + localToken scope★862 · Reg
7Linear MCPWork from a ticket and report backOfficial (Linear)RemoteToken scopeReg · 48k inst.
8Atlassian Rovo MCPJira, Confluence, JSM, Bitbucket, CompassOfficial (Atlassian)RemoteToken scope★1.1k · Reg · 92k inst.
9Supabase MCPTables, config, SQL for one projectOfficial (Supabase)Remote + localread_only=true URL parameter★2.9k · Reg · 119k inst.
10SerenaSymbol-level retrieval and edits via language serversCommunity (Oraios)LocalNot applicable: edits land in your working tree★29.8k · Reg · 89k inst.
11Notion MCPSpecs, runbooks, decision logsOfficial (Notion)RemoteToken scope (OAuth grant)Reg
12Cloudflare MCPWhole Cloudflare API through 3 tools (Code Mode)Official (Cloudflare)RemoteToken scope (API token permissions)★883 + ★4.3k · Reg
13Vercel MCPDocs, projects, deployments, logsOfficial (Vercel)RemoteRead-only per Vercel’s plugin manifest (2026-09-26)Reg · 228k inst.
14Stripe MCPStripe API actions: it can move moneyOfficial (Stripe)Remote + localTest mode plus a restricted API key★1.8k · Reg · 61k inst.
15Browser UseGives an existing agent control of ChromeOfficial (Browser Use)LocalNone; browser_exec runs Python, so treat it as a shell★116.3k · Reg
16codebase-memory-mcpPersistent code knowledge graph, call-path tracingCommunity (DeusData)LocalNot applicable: local index★44.9k · Reg
17context-modeRuns commands outside the context window, returns summariesCommunity (mksglu)LocalNone; it executes commands★24.1k
18RepomixPacks a local or remote repo into one fileCommunity (yamadashy)Local--sandbox confines file tools to one directory★28.5k · Reg
19Postgres MCP ProIndex tuning, explain plans, health checksCommunity (Crystal DBA)Local--access-mode=restricted★3.3k; releases stalled since 2025-05-16
20DBHubPostgres, MySQL, SQL Server, Oracle, MariaDB, SQLiteCommunity (Bytebase)LocalBuilt-in read-only guardrail (see its README)★3.6k · Reg
21MCP Toolbox for DatabasesPrebuilt or tools.yaml-defined database toolsOfficial (Google)LocalDeclare only read tools in tools.yaml★16.5k · Reg
22AWS MCP Server + Agent Toolkit for AWSAWS APIs and docs behind a SigV4 proxyOfficial (AWS)Remote via local proxyIAM scope; AWS API server READ_OPERATIONS_ONLY=true★2.7k + ★9.7k
23Azure MCP ServerAzure resources via your az login identityOfficial (Microsoft)LocalToken scope (Azure RBAC of that identity)★3.7k · Reg
24Microsoft Learn MCPMicrosoft docs search, fetch, code samplesOfficial (Microsoft)Remote, no authNot needed: docs only★1.9k · Reg
25Docker MCP Toolkit / GatewayRuns catalog servers in isolated containersOfficial (Docker)Local gatewayPer server behind the gateway★1.6k
26Kubernetes MCP ServerNative Go access to Kubernetes and OpenShiftCommunity (containers org)Localread_only = true in its TOML config★2.1k · Reg
27Terraform MCP ServerRegistry lookups, HCP Terraform workspacesOfficial (HashiCorp)Local (Docker)Operations stay off unless ENABLE_TF_OPERATIONS=true★1.5k · Reg
28Grafana MCPDashboards, Prometheus, Loki, incidentsOfficial (Grafana Labs)Local + Grafana Cloud remote--disable-write★3.5k · Reg
29PostHog MCPProduct analytics, flags, dashboardsOfficial (PostHog)RemoteScope with ?features= or ?tools=★39.9k (monorepo) · Reg
30Firecrawl MCPScrape, search, crawl the webOfficial (Firecrawl)Remote + localNot applicable: reads the web, spends credits★7.5k · Reg

Official or community, remote or local: what changes for you?

Section titled “Official or community, remote or local: what changes for you?”

Official remote servers with OAuth are the SaaS default: vendor-maintained tools, no local process, and a login you can revoke centrally. You cannot pin a version, so the tool list changes when the vendor ships.

Local stdio servers run with the developer’s own credentials. Choose them when the target is local too (a browser, a dev database, your kubeconfig cluster) or data must stay on the network, and pin the version: @azure/mcp@latest resolved to 3.0.0-beta.47 on 2026-09-26, while the newest stable was 2.0.5.

Community servers fill gaps in code intelligence and databases. Check the last release date (Postgres MCP Pro: 2025-05-16 on PyPI) and what the installer writes: codebase-memory-mcp edits every agent config it detects unless you pass --skip-config.

The protocol moved to the stateless revision 2026-07-28. Claude Code negotiates it by default with direct HTTP servers (all installs by v2.1.274); Codex 0.157.1 still has mcp_2026_07_28 off. See the MCP 2026-07-28 migration guide.

These Claude Code commands were checked against Claude Code 2.1.283 --help on 2026-09-26. Credentials appear only as single-quoted ${VAR} references, which Claude Code expands from your environment when it reads .mcp.json. So every line that carries one also carries -s project, which writes it to .mcp.json; export the variable from your secret store; never paste the value itself. Replace the other UPPER_SNAKE_CASE values with your own.

Terminal window
# 1 GitHub (remote, read-only)
claude mcp add -s project --transport http github https://api.githubcopilot.com/mcp/readonly -H 'Authorization: Bearer ${GITHUB_PAT}'
# 2 Context7 (remote, keyless in .mcp.json: the key is optional, and a teammate without CONTEXT7_API_KEY
# would send the literal "Bearer ${CONTEXT7_API_KEY}" and get a `claude mcp list` warning.
# A developer with a key overrides it in their own local scope:
# claude mcp add -s local --transport http context7 https://mcp.context7.com/mcp -H 'Authorization: Bearer ${CONTEXT7_API_KEY}'
claude mcp add -s project --transport http context7 https://mcp.context7.com/mcp
# 3 Playwright (--isolated so parallel agents do not share one profile)
claude mcp add playwright -- npx @playwright/mcp@latest --isolated
# 4 Chrome DevTools (usage statistics go to Google unless you opt out)
claude mcp add chrome-devtools -- npx chrome-devtools-mcp@latest --no-usage-statistics
# 5 Figma (plugin = MCP server + skills), then log in with /mcp
claude plugin install figma@claude-plugins-official
# 6 Sentry (OAuth via /mcp; a token header uses "Sentry-Bearer", not "Bearer")
claude mcp add --transport http sentry https://mcp.sentry.dev/mcp
# 7 Linear (plugin wraps the remote server https://mcp.linear.app/mcp), then log in with /mcp
claude plugin install linear@claude-plugins-official
# 8 Atlassian (v2 endpoint; /v1/sse stopped working after 2026-06-30)
claude mcp add --transport http atlassian https://mcp.atlassian.com/v2/mcp
# 9 Supabase (one project, read-only)
claude mcp add --transport http supabase "https://mcp.supabase.com/mcp?project_ref=YOUR_PROJECT_REF&read_only=true"
# 10 Serena (install the tool and create its config first; upstream warns against marketplace installs)
uv tool install -p 3.13 serena-agent
serena init
claude mcp add --scope user serena -- serena start-mcp-server --context claude-code --project-from-cwd
# 11 Notion (plugin wraps the remote server https://mcp.notion.com/mcp; the local npm server is unmaintained)
claude plugin install notion@claude-plugins-official
# 12 Cloudflare Code Mode
claude mcp add --transport http cloudflare https://mcp.cloudflare.com/mcp
# 13 Vercel (plugin installs the remote server and its skills)
claude plugin install vercel@claude-plugins-official
# 14 Stripe (use test mode)
claude plugin install stripe@claude-plugins-official
# 15 Browser Use
claude mcp add browser-use -- uvx --python 3.12 browser-use@latest --cli-mcp
# 16 codebase-memory-mcp (binary on PATH after `npm install -g codebase-memory-mcp`)
claude mcp add codebase-memory -- CODEBASE_MEMORY_BINARY_PATH
# 17 context-mode (MCP only; the plugin adds hooks)
claude mcp add context-mode -- npx -y context-mode
# 18 Repomix (confined to the current directory)
claude mcp add repomix -- npx -y repomix --mcp --sandbox
# 19 Postgres MCP Pro (PyPI, so uvx; the npm package of the same name is unrelated)
claude mcp add -s project postgres -e 'DATABASE_URI=${DATABASE_URI}' -- uvx postgres-mcp --access-mode=restricted
# 20 DBHub
claude mcp add -s project dbhub -- npx @bytebase/dbhub@latest --transport stdio --dsn '${DBHUB_DSN}'
# 21 MCP Toolbox for Databases
claude mcp add toolbox-postgres -- npx -y @toolbox-sdk/server --prebuilt=postgres --stdio
# 22 AWS (plugin), or the no-auth docs server
claude plugin install aws-core@claude-plugins-official
claude mcp add --transport http aws-knowledge https://knowledge-mcp.global.api.aws
# 23 Azure (pin the stable release)
claude mcp add azure -- npx -y @azure/mcp@2.0.5 server start
# 24 Microsoft Learn
claude mcp add --transport http microsoft-learn https://learn.microsoft.com/api/mcp
# 25 Docker MCP Gateway (create the dev-tools profile first with `docker mcp profile create ...`)
claude mcp add docker-gateway -- docker mcp gateway run --profile dev-tools
# 26 Kubernetes (put read_only = true in the TOML file)
claude mcp add kubernetes -- npx -y kubernetes-mcp-server@latest --config ~/.config/k8s-mcp.toml
# 27 Terraform
claude mcp add terraform -s user -t stdio -- docker run -i --rm hashicorp/terraform-mcp-server
# 28 Grafana (read-only)
claude mcp add -s project grafana -e 'GRAFANA_URL=${GRAFANA_URL}' -e 'GRAFANA_SERVICE_ACCOUNT_TOKEN=${GRAFANA_SERVICE_ACCOUNT_TOKEN}' -- uvx mcp-grafana --disable-write
# 29 PostHog
claude mcp add --transport http posthog https://mcp.posthog.com/mcp
# 30 Firecrawl (key in an env var, never in the URL)
claude mcp add -s project firecrawl -e 'FIRECRAWL_API_KEY=${FIRECRAWL_API_KEY}' -- npx -y firecrawl-mcp

CODEBASE_MEMORY_BINARY_PATH is the path to the codebase-memory-mcp binary, and YOUR_PROJECT_REF is the Supabase project reference. Each ${VAR} names an environment variable holding a credential or connection string from the vendor’s console.

The same server works in Codex and Cursor; only the wrapper changes:

Claude CodeCodex 0.157.1Cursor (.cursor/mcp.json)
claude mcp add --transport http NAME URLcodex mcp add NAME --url URL{ "url": "URL" }
-H "Authorization: Bearer ..."--bearer-token-env-var ENV_NAME, or http_headers in config.toml"headers": { "Authorization": "Bearer ..." }
claude mcp add NAME -e 'K=${K}' -- CMD ARGScodex mcp add NAME -- CMD ARGS, then env_vars = ["K"] in config.toml (--env K=V stores the value in plain text){ "command": "CMD", "args": [...], "env": {...} }
OAuth: /mcp in a session, or claude mcp login NAMEcodex mcp login NAMELog in when Cursor prompts on first connect
Project file: .mcp.json at the repo rootcodex mcp add writes ~/.codex/config.toml.cursor/mcp.json (project) or ~/.cursor/mcp.json (global)

The Cursor column follows each vendor’s README for Cursor.

Set up GitHub, Supabase and Grafana in read-only mode

Section titled “Set up GitHub, Supabase and Grafana in read-only mode”

This gives an agent code and CI history, the database, and metrics and logs to investigate a production problem, without the ability to change any of them. Use it as the default shape: read-only first, write access later and on purpose.

Run in the repository root. Project scope writes .mcp.json, which you commit; Claude Code expands ${VAR} from each developer’s environment, so no secret enters git.

Terminal window
claude mcp add -s project --transport http github \
https://api.githubcopilot.com/mcp/readonly \
-H 'Authorization: Bearer ${GITHUB_PAT}'
claude mcp add -s project --transport http supabase \
"https://mcp.supabase.com/mcp?project_ref=YOUR_PROJECT_REF&read_only=true"
claude mcp add -s project grafana \
-e 'GRAFANA_URL=${GRAFANA_URL}' \
-e 'GRAFANA_SERVICE_ACCOUNT_TOKEN=${GRAFANA_SERVICE_ACCOUNT_TOKEN}' \
-- uvx mcp-grafana --disable-write

The single quotes stop your shell from expanding ${...} before Claude Code writes the file. Start a session and run /mcp to log in to Supabase through OAuth.

YOUR_PROJECT_REF is the Supabase project reference from the dashboard URL, and YOUR_STACK is your Grafana Cloud stack name. Give the GitHub token and Grafana service account read-only permissions too, as a second line of defence if a switch is ever dropped.

A server earns its place when the agent would otherwise ask you to paste something from that system every week.

TeamCore stack (read-only first)Add when you need itLeave out
Web product teamGitHub (/readonly), Context7, Playwright (--isolated), Sentry, Linear or AtlassianFigma; Chrome DevTools for performance; Vercel, Supabase or Stripe (test mode) if you deploy thereA second browser server beside Playwright
Platform / infrastructure teamGitHub (/readonly), Terraform, Kubernetes (read_only = true), Grafana (--disable-write), your cloud: AWS, Azure or CloudflareDocker MCP Gateway for one shared profile; SentryAny database server with production write access
Data teamGitHub (/readonly), one database server (Postgres MCP Pro --access-mode=restricted, DBHub or MCP Toolbox), Context7Supabase (read_only=true); PostHog; Grafana for pipeline metricsFirecrawl and browser servers unless you ingest web data
  1. List the systems your team touched last week. Each one the agent could not see is a candidate.

  2. Cap the core stack at five servers. Tool search in Claude Code and Codex defers most schemas, but results still cost tokens, and every server widens what a prompt injection can reach.

  3. Configure every server in its read-only form using the switch column above. Where the answer is “token scope”, create a credential with read permissions only.

  4. Commit the shared servers at project scope. Claude Code reads .mcp.json and Cursor .cursor/mcp.json. Codex writes each developer’s ~/.codex/config.toml, so publish the codex mcp add lines in AGENTS.md.

  5. Measure the context cost. Run /context in a fresh Claude Code session before and after; claude plugin details PLUGIN_NAME prints a plugin’s component inventory and projected token cost.

  6. Grant write access per task, not per team. Add the write-capable server at local scope for that task, then remove it with claude mcp remove NAME (or codex mcp remove NAME).

How do you prove the servers are really read-only?

Section titled “How do you prove the servers are really read-only?”

A config that says read-only is a claim. Three checks turn it into evidence without reading the server’s source.

Check the tool list. Ask the agent which tools each server exposes and look for write verbs. The GitHub /readonly endpoint should show nothing that creates, updates, merges or closes; Grafana with --disable-write should lack update_dashboard and create_incident.

Check the written config. claude mcp get NAME and codex mcp get NAME --json print what the agent will load, which catches a URL stored as a stdio command and a dropped Codex header (see below).

Gate the shared file in CI. This script fails the build when .mcp.json names a server outside the allowlist or loses a read-only switch. Against the .mcp.json from the Claude Code tab it passes; with /readonly removed it fails.

#!/usr/bin/env bash
# scripts/check-mcp-policy.sh: run in CI on every change to .mcp.json
set -euo pipefail
jq -e '
.mcpServers as $s
| ($s | keys - ["github", "supabase", "grafana"] | length == 0)
and (($s.github.url // "") | test("/readonly$"))
and (($s.supabase.url // "") | test("read_only=true"))
and ((($s.grafana.args // []) | index("--disable-write")) != null)
' .mcp.json > /dev/null || { echo "MCP policy check failed: see .mcp.json"; exit 1; }
echo "MCP policy check passed"

Who signs off. The tech lead owns .mcp.json through CODEOWNERS; adding a write-capable server or removing a switch needs a second approver. For organization-wide allowlists, see MCP registries and gateways.

Which MCP package names are fake or wrong?

Section titled “Which MCP package names are fake or wrong?”

Agents and old blog posts both produce plausible names. Every row was checked against npm or PyPI on 2026-09-26.

Looks rightWhat is trueUse instead
@modelcontextprotocol/server-githubDeprecated; GitHub says it is no longer functionalhttps://api.githubcopilot.com/mcp/ or ghcr.io/github/github-mcp-server
@modelcontextprotocol/server-postgres, -puppeteer, -slack, -gitlab, -brave-searchDeprecated and archivedPostgres MCP Pro or DBHub; Playwright MCP; the vendor servers
@modelcontextprotocol/server-git, -fetch, -timeNot on npm (404); these are Pythonuvx mcp-server-git, uvx mcp-server-fetch
@anthropic-ai/mcp, @anthropic/mcp-server-github404 on npm (checked 2026-09-26)The vendor’s own server
@context7/mcp, @upstash/context7, context7-mcp404@upstash/context7-mcp
@figma/mcp, @linear/mcp, @vercel/mcp, @supabase/mcp404Remote URLs; for Supabase local, @supabase/mcp-server-supabase
@microsoft/playwright-mcp, unscoped playwright-mcp404, and an unrelated community package@playwright/mcp
@chrome-devtools/mcp, @google/chrome-devtools-mcp404chrome-devtools-mcp (unscoped)
npx postgres-mcpThe npm package is unrelateduvx postgres-mcp (PyPI)
@leval/mcp-grafanaA community port, not Grafana’suvx mcp-grafana or Docker grafana/mcp-grafana
serena on npm or PyPIBoth unrelatedPyPI serena-agent
docker-mcp on npmA community package, not Docker’sThe docker mcp CLI plugin
npm browser-useAn unrelated TypeScript libraryPyPI browser-use via uvx
@neondatabase/mcp-server-neonDeprecatedhttps://mcp.neon.tech/mcp
@azure/mcp@latestResolves to a beta (3.0.0-beta.47)@azure/mcp@2.0.5

These passed the same checks but serve a narrower job than the top 30.

ServersCovered in
Slack MCP (via the slack plugin), GitLab MCP (beta)tickets and docs over MCP, GitHub MCP guide
Datadog MCPObservability MCP servers
Exa, Tavily, Brave Search, MarkItDown MCP (alpha)Web research MCP servers
Neon (readonly=true), MongoDB (--readOnly)Database MCP servers
Google Cloud managed servers, gcloud MCPCloud platform MCP servers
Stagehand with Browserbase, dev-browser (next pre-release)Browser MCP servers
Claude Context (Zilliz)Code intelligence MCP servers
n8n-mcp, Composio ConnectIntegration hub MCP servers
Next.js DevTools MCP, MobileBuildMCP, Hugging Face MCP; shadcn MCPFramework DevTools MCP, shadcn/ui MCP
Filesystem, Git, Fetch, Memory, Sequential Thinking, Desktop CommanderMCP reference servers

What breaks when a team adopts these MCP servers?

Section titled “What breaks when a team adopts these MCP servers?”

claude mcp add NAME URL connects to nothing. Without --transport http, Claude Code 2.1.283 writes a stdio server whose command is the URL, and fails only at connect time. Remove it, add it again with --transport http, and confirm with claude mcp get NAME. --url is a Codex flag; Claude Code rejects it.

Codex drops your auth header without an error. A headers = { ... } table in config.toml parses and is ignored (codex-cli 0.157.1). Use --bearer-token-env-var or the http_headers / env_http_headers keys, and check codex mcp get NAME --json.

A vendor plugin quietly restores write access. github@claude-plugins-official points at the full https://api.githubcopilot.com/mcp/ URL, not /readonly, so installing it next to your read-only entry gives the agent both. Run the audit prompt after any plugin install.

Parallel agents fight over one browser. Only one client at a time can open a persistent Playwright profile. Start Playwright with --isolated or a distinct --user-data-dir per worktree.

A copied endpoint is dead. Atlassian’s /v1/sse stopped working after 2026-06-30; use /v2/mcp. Firecrawl says never to put an API key in the server URL. Sentry token auth needs Sentry-Bearer, not Bearer.

Lockdown mode is mistaken for a permission. GitHub’s --lockdown-mode filters public-repository content from authors without push access, to reduce prompt injection, but GitHub states it “is not an authorization boundary”. Pair it with /readonly and a narrow token.

The context window fills before the task starts. If /context shows MCP tools taking a large share of a fresh session, remove servers the task does not need and prefer compact designs: Cloudflare quotes about 1k tokens for its 3-tool Code Mode server against about 244k for native API schemas (Cloudflare, read 2026-09-26). Playwright itself says coding agents “might benefit from using the CLI+SKILLS instead”. See the MCP token cost guide.