Top 30 MCP Servers for Software Teams, Ranked (September 2026)
The 30 most useful MCP servers for software teams in September 2026 are led by GitHub, Context7, Playwright, Chrome DevTools and Figma. Twenty-three of the 30 are official vendor servers, 16 offer a hosted remote endpoint, and each read-only switch is spelled differently. Most teams need five servers or fewer, chosen by the systems they already operate.
A developer copies a GitHub MCP config from a 2025 blog post. Its package, @modelcontextprotocol/server-github, is deprecated, so they point the remote server at a full-scope personal access token instead. A week later an agent “tidying up” closes 14 issues it judged duplicates. Nothing was hacked: the server did what the token allowed, and nobody had turned on GitHub’s read-only mode.
This page is for the developer picking servers for their own agent and the tech lead who owns the team’s shared .mcp.json. New to MCP? Start with the introduction to Model Context Protocol.
What this ranking gives you
Section titled “What this ranking gives you”- One table of 30 verified servers: maintainer, where it runs, its read-only switch and a dated popularity signal, with an install line for each.
- A read-only setup for GitHub, Supabase and Grafana in Claude Code, Codex and Cursor, plus a CI check that keeps it read-only.
- A starter stack per team type, and a table of package names that look right and are wrong.
How were the 30 servers ranked?
Section titled “How were the 30 servers ranked?”The order puts day-to-day usefulness for a software team first and popularity second. Registry presence alone does not qualify a server: the Official MCP Registry is a preview that lists 36,176 servers and checks namespaces, not quality (registry API, read 2026-09-26). Every server was checked against its own repository, package registry or plugin manifest on 2026-09-26.
Popularity as of 2026-09-26 uses three signals read directly from vendors and GitHub; download counts are not included:
| Marker | What it means |
|---|---|
★33.2k | GitHub stars on the server’s repository (GitHub API). Stars measure attention, not use. |
Reg | Listed in the Official MCP Registry under the vendor’s own namespace. |
319k inst. | Installs of the vendor’s plugin on the Claude Marketplace directory (claude.com/plugins). |
The top 30 MCP servers at a glance
Section titled “The top 30 MCP servers at a glance”“Read-only switch” is the server-side setting that removes write tools. Token scope means no such switch was found on 2026-09-26, so the credential’s own permissions are the only limit.
| # | Server | What the agent gets | Maintainer | Runs | Read-only switch | Popularity (2026-09-26) |
|---|---|---|---|---|---|---|
| 1 | GitHub MCP Server | PRs, issues, Actions logs, code security | Official (GitHub) | Remote + local | /readonly URL suffix, X-MCP-Readonly header, local --read-only | ★33.2k · Reg · 319k inst. |
| 2 | Context7 | Version-specific library docs | Official (Upstash) | Remote + local | Not needed: docs lookup only | ★62.4k · Reg · 418k inst. |
| 3 | Playwright MCP | Browser automation over the accessibility tree | Official (Microsoft) | Local | None; point it at local or staging URLs | ★37.6k · Reg · 320k inst. |
| 4 | Chrome DevTools MCP | Performance traces, Lighthouse, network, console | Official (Chrome DevTools team) | Local | None; --slim cuts it to basic tools | ★52.6k · Reg · 103k inst. |
| 5 | Figma MCP | Design context, code generation, Code Connect | Official (Figma) | Remote | Token scope; canvas writes are a remote beta | Reg · 168k inst. |
| 6 | Sentry MCP | Issues, events, traces, Seer | Official (Sentry) | Remote + local | Token scope | ★862 · Reg |
| 7 | Linear MCP | Work from a ticket and report back | Official (Linear) | Remote | Token scope | Reg · 48k inst. |
| 8 | Atlassian Rovo MCP | Jira, Confluence, JSM, Bitbucket, Compass | Official (Atlassian) | Remote | Token scope | ★1.1k · Reg · 92k inst. |
| 9 | Supabase MCP | Tables, config, SQL for one project | Official (Supabase) | Remote + local | read_only=true URL parameter | ★2.9k · Reg · 119k inst. |
| 10 | Serena | Symbol-level retrieval and edits via language servers | Community (Oraios) | Local | Not applicable: edits land in your working tree | ★29.8k · Reg · 89k inst. |
| 11 | Notion MCP | Specs, runbooks, decision logs | Official (Notion) | Remote | Token scope (OAuth grant) | Reg |
| 12 | Cloudflare MCP | Whole Cloudflare API through 3 tools (Code Mode) | Official (Cloudflare) | Remote | Token scope (API token permissions) | ★883 + ★4.3k · Reg |
| 13 | Vercel MCP | Docs, projects, deployments, logs | Official (Vercel) | Remote | Read-only per Vercel’s plugin manifest (2026-09-26) | Reg · 228k inst. |
| 14 | Stripe MCP | Stripe API actions: it can move money | Official (Stripe) | Remote + local | Test mode plus a restricted API key | ★1.8k · Reg · 61k inst. |
| 15 | Browser Use | Gives an existing agent control of Chrome | Official (Browser Use) | Local | None; browser_exec runs Python, so treat it as a shell | ★116.3k · Reg |
| 16 | codebase-memory-mcp | Persistent code knowledge graph, call-path tracing | Community (DeusData) | Local | Not applicable: local index | ★44.9k · Reg |
| 17 | context-mode | Runs commands outside the context window, returns summaries | Community (mksglu) | Local | None; it executes commands | ★24.1k |
| 18 | Repomix | Packs a local or remote repo into one file | Community (yamadashy) | Local | --sandbox confines file tools to one directory | ★28.5k · Reg |
| 19 | Postgres MCP Pro | Index tuning, explain plans, health checks | Community (Crystal DBA) | Local | --access-mode=restricted | ★3.3k; releases stalled since 2025-05-16 |
| 20 | DBHub | Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite | Community (Bytebase) | Local | Built-in read-only guardrail (see its README) | ★3.6k · Reg |
| 21 | MCP Toolbox for Databases | Prebuilt or tools.yaml-defined database tools | Official (Google) | Local | Declare only read tools in tools.yaml | ★16.5k · Reg |
| 22 | AWS MCP Server + Agent Toolkit for AWS | AWS APIs and docs behind a SigV4 proxy | Official (AWS) | Remote via local proxy | IAM scope; AWS API server READ_OPERATIONS_ONLY=true | ★2.7k + ★9.7k |
| 23 | Azure MCP Server | Azure resources via your az login identity | Official (Microsoft) | Local | Token scope (Azure RBAC of that identity) | ★3.7k · Reg |
| 24 | Microsoft Learn MCP | Microsoft docs search, fetch, code samples | Official (Microsoft) | Remote, no auth | Not needed: docs only | ★1.9k · Reg |
| 25 | Docker MCP Toolkit / Gateway | Runs catalog servers in isolated containers | Official (Docker) | Local gateway | Per server behind the gateway | ★1.6k |
| 26 | Kubernetes MCP Server | Native Go access to Kubernetes and OpenShift | Community (containers org) | Local | read_only = true in its TOML config | ★2.1k · Reg |
| 27 | Terraform MCP Server | Registry lookups, HCP Terraform workspaces | Official (HashiCorp) | Local (Docker) | Operations stay off unless ENABLE_TF_OPERATIONS=true | ★1.5k · Reg |
| 28 | Grafana MCP | Dashboards, Prometheus, Loki, incidents | Official (Grafana Labs) | Local + Grafana Cloud remote | --disable-write | ★3.5k · Reg |
| 29 | PostHog MCP | Product analytics, flags, dashboards | Official (PostHog) | Remote | Scope with ?features= or ?tools= | ★39.9k (monorepo) · Reg |
| 30 | Firecrawl MCP | Scrape, search, crawl the web | Official (Firecrawl) | Remote + local | Not applicable: reads the web, spends credits | ★7.5k · Reg |
Official or community, remote or local: what changes for you?
Section titled “Official or community, remote or local: what changes for you?”Official remote servers with OAuth are the SaaS default: vendor-maintained tools, no local process, and a login you can revoke centrally. You cannot pin a version, so the tool list changes when the vendor ships.
Local stdio servers run with the developer’s own credentials. Choose them when the target is local too (a browser, a dev database, your kubeconfig cluster) or data must stay on the network, and pin the version: @azure/mcp@latest resolved to 3.0.0-beta.47 on 2026-09-26, while the newest stable was 2.0.5.
Community servers fill gaps in code intelligence and databases. Check the last release date (Postgres MCP Pro: 2025-05-16 on PyPI) and what the installer writes: codebase-memory-mcp edits every agent config it detects unless you pass --skip-config.
The protocol moved to the stateless revision 2026-07-28. Claude Code negotiates it by default with direct HTTP servers (all installs by v2.1.274); Codex 0.157.1 still has mcp_2026_07_28 off. See the MCP 2026-07-28 migration guide.
Install lines for all 30 servers
Section titled “Install lines for all 30 servers”These Claude Code commands were checked against Claude Code 2.1.283 --help on 2026-09-26. Credentials appear only as single-quoted ${VAR} references, which Claude Code expands from your environment when it reads .mcp.json. So every line that carries one also carries -s project, which writes it to .mcp.json; export the variable from your secret store; never paste the value itself. Replace the other UPPER_SNAKE_CASE values with your own.
# 1 GitHub (remote, read-only)claude mcp add -s project --transport http github https://api.githubcopilot.com/mcp/readonly -H 'Authorization: Bearer ${GITHUB_PAT}'# 2 Context7 (remote, keyless in .mcp.json: the key is optional, and a teammate without CONTEXT7_API_KEY# would send the literal "Bearer ${CONTEXT7_API_KEY}" and get a `claude mcp list` warning.# A developer with a key overrides it in their own local scope:# claude mcp add -s local --transport http context7 https://mcp.context7.com/mcp -H 'Authorization: Bearer ${CONTEXT7_API_KEY}'claude mcp add -s project --transport http context7 https://mcp.context7.com/mcp# 3 Playwright (--isolated so parallel agents do not share one profile)claude mcp add playwright -- npx @playwright/mcp@latest --isolated# 4 Chrome DevTools (usage statistics go to Google unless you opt out)claude mcp add chrome-devtools -- npx chrome-devtools-mcp@latest --no-usage-statistics# 5 Figma (plugin = MCP server + skills), then log in with /mcpclaude plugin install figma@claude-plugins-official# 6 Sentry (OAuth via /mcp; a token header uses "Sentry-Bearer", not "Bearer")claude mcp add --transport http sentry https://mcp.sentry.dev/mcp# 7 Linear (plugin wraps the remote server https://mcp.linear.app/mcp), then log in with /mcpclaude plugin install linear@claude-plugins-official# 8 Atlassian (v2 endpoint; /v1/sse stopped working after 2026-06-30)claude mcp add --transport http atlassian https://mcp.atlassian.com/v2/mcp# 9 Supabase (one project, read-only)claude mcp add --transport http supabase "https://mcp.supabase.com/mcp?project_ref=YOUR_PROJECT_REF&read_only=true"# 10 Serena (install the tool and create its config first; upstream warns against marketplace installs)uv tool install -p 3.13 serena-agentserena initclaude mcp add --scope user serena -- serena start-mcp-server --context claude-code --project-from-cwd# 11 Notion (plugin wraps the remote server https://mcp.notion.com/mcp; the local npm server is unmaintained)claude plugin install notion@claude-plugins-official# 12 Cloudflare Code Modeclaude mcp add --transport http cloudflare https://mcp.cloudflare.com/mcp# 13 Vercel (plugin installs the remote server and its skills)claude plugin install vercel@claude-plugins-official# 14 Stripe (use test mode)claude plugin install stripe@claude-plugins-official# 15 Browser Useclaude mcp add browser-use -- uvx --python 3.12 browser-use@latest --cli-mcp# 16 codebase-memory-mcp (binary on PATH after `npm install -g codebase-memory-mcp`)claude mcp add codebase-memory -- CODEBASE_MEMORY_BINARY_PATH# 17 context-mode (MCP only; the plugin adds hooks)claude mcp add context-mode -- npx -y context-mode# 18 Repomix (confined to the current directory)claude mcp add repomix -- npx -y repomix --mcp --sandbox# 19 Postgres MCP Pro (PyPI, so uvx; the npm package of the same name is unrelated)claude mcp add -s project postgres -e 'DATABASE_URI=${DATABASE_URI}' -- uvx postgres-mcp --access-mode=restricted# 20 DBHubclaude mcp add -s project dbhub -- npx @bytebase/dbhub@latest --transport stdio --dsn '${DBHUB_DSN}'# 21 MCP Toolbox for Databasesclaude mcp add toolbox-postgres -- npx -y @toolbox-sdk/server --prebuilt=postgres --stdio# 22 AWS (plugin), or the no-auth docs serverclaude plugin install aws-core@claude-plugins-officialclaude mcp add --transport http aws-knowledge https://knowledge-mcp.global.api.aws# 23 Azure (pin the stable release)claude mcp add azure -- npx -y @azure/mcp@2.0.5 server start# 24 Microsoft Learnclaude mcp add --transport http microsoft-learn https://learn.microsoft.com/api/mcp# 25 Docker MCP Gateway (create the dev-tools profile first with `docker mcp profile create ...`)claude mcp add docker-gateway -- docker mcp gateway run --profile dev-tools# 26 Kubernetes (put read_only = true in the TOML file)claude mcp add kubernetes -- npx -y kubernetes-mcp-server@latest --config ~/.config/k8s-mcp.toml# 27 Terraformclaude mcp add terraform -s user -t stdio -- docker run -i --rm hashicorp/terraform-mcp-server# 28 Grafana (read-only)claude mcp add -s project grafana -e 'GRAFANA_URL=${GRAFANA_URL}' -e 'GRAFANA_SERVICE_ACCOUNT_TOKEN=${GRAFANA_SERVICE_ACCOUNT_TOKEN}' -- uvx mcp-grafana --disable-write# 29 PostHogclaude mcp add --transport http posthog https://mcp.posthog.com/mcp# 30 Firecrawl (key in an env var, never in the URL)claude mcp add -s project firecrawl -e 'FIRECRAWL_API_KEY=${FIRECRAWL_API_KEY}' -- npx -y firecrawl-mcpCODEBASE_MEMORY_BINARY_PATH is the path to the codebase-memory-mcp binary, and YOUR_PROJECT_REF is the Supabase project reference. Each ${VAR} names an environment variable holding a credential or connection string from the vendor’s console.
The same server works in Codex and Cursor; only the wrapper changes:
| Claude Code | Codex 0.157.1 | Cursor (.cursor/mcp.json) |
|---|---|---|
claude mcp add --transport http NAME URL | codex mcp add NAME --url URL | { "url": "URL" } |
-H "Authorization: Bearer ..." | --bearer-token-env-var ENV_NAME, or http_headers in config.toml | "headers": { "Authorization": "Bearer ..." } |
claude mcp add NAME -e 'K=${K}' -- CMD ARGS | codex mcp add NAME -- CMD ARGS, then env_vars = ["K"] in config.toml (--env K=V stores the value in plain text) | { "command": "CMD", "args": [...], "env": {...} } |
OAuth: /mcp in a session, or claude mcp login NAME | codex mcp login NAME | Log in when Cursor prompts on first connect |
Project file: .mcp.json at the repo root | codex mcp add writes ~/.codex/config.toml | .cursor/mcp.json (project) or ~/.cursor/mcp.json (global) |
The Cursor column follows each vendor’s README for Cursor.
Set up GitHub, Supabase and Grafana in read-only mode
Section titled “Set up GitHub, Supabase and Grafana in read-only mode”This gives an agent code and CI history, the database, and metrics and logs to investigate a production problem, without the ability to change any of them. Use it as the default shape: read-only first, write access later and on purpose.
Run in the repository root. Project scope writes .mcp.json, which you commit; Claude Code expands ${VAR} from each developer’s environment, so no secret enters git.
claude mcp add -s project --transport http github \ https://api.githubcopilot.com/mcp/readonly \ -H 'Authorization: Bearer ${GITHUB_PAT}'
claude mcp add -s project --transport http supabase \ "https://mcp.supabase.com/mcp?project_ref=YOUR_PROJECT_REF&read_only=true"
claude mcp add -s project grafana \ -e 'GRAFANA_URL=${GRAFANA_URL}' \ -e 'GRAFANA_SERVICE_ACCOUNT_TOKEN=${GRAFANA_SERVICE_ACCOUNT_TOKEN}' \ -- uvx mcp-grafana --disable-writeThe single quotes stop your shell from expanding ${...} before Claude Code writes the file. Start a session and run /mcp to log in to Supabase through OAuth.
Codex writes to ~/.codex/config.toml. Tested on codex-cli 0.157.1:
codex mcp add github --url https://api.githubcopilot.com/mcp/readonly \ --bearer-token-env-var GITHUB_PAT
codex mcp add supabase \ --url "https://mcp.supabase.com/mcp?project_ref=YOUR_PROJECT_REF&read_only=true"codex mcp login supabase
codex mcp add grafana -- uvx mcp-grafana --disable-writeDo not pass the Grafana token with --env: that writes its value into config.toml in plain text. Instead, forward the variables from your shell by adding env_vars under the new entry in ~/.codex/config.toml:
[mcp_servers.grafana]command = "uvx"args = ["mcp-grafana", "--disable-write"]env_vars = ["GRAFANA_URL", "GRAFANA_SERVICE_ACCOUNT_TOKEN"]codex mcp get grafana --json on 0.157.1 lists both names under env_vars, and config.toml holds no secret.
Add to ~/.cursor/mcp.json. This file holds the GitHub token and the Grafana service account token in plain text, so keep it user-global (never .cursor/mcp.json in the repository), restrict it with chmod 600 ~/.cursor/mcp.json, and keep it out of dotfile repos:
{ "mcpServers": { "github": { "url": "https://api.githubcopilot.com/mcp/readonly", "headers": { "Authorization": "Bearer YOUR_GITHUB_PAT" } }, "supabase": { "url": "https://mcp.supabase.com/mcp?project_ref=YOUR_PROJECT_REF&read_only=true" }, "grafana": { "command": "uvx", "args": ["mcp-grafana", "--disable-write"], "env": { "GRAFANA_URL": "https://YOUR_STACK.grafana.net", "GRAFANA_SERVICE_ACCOUNT_TOKEN": "YOUR_TOKEN" } } }}Supabase’s README says the client prompts you to log in and pick an organization when the server first connects.
YOUR_PROJECT_REF is the Supabase project reference from the dashboard URL, and YOUR_STACK is your Grafana Cloud stack name. Give the GitHub token and Grafana service account read-only permissions too, as a second line of defence if a switch is ever dropped.
Pick an MCP stack by team type
Section titled “Pick an MCP stack by team type”A server earns its place when the agent would otherwise ask you to paste something from that system every week.
| Team | Core stack (read-only first) | Add when you need it | Leave out |
|---|---|---|---|
| Web product team | GitHub (/readonly), Context7, Playwright (--isolated), Sentry, Linear or Atlassian | Figma; Chrome DevTools for performance; Vercel, Supabase or Stripe (test mode) if you deploy there | A second browser server beside Playwright |
| Platform / infrastructure team | GitHub (/readonly), Terraform, Kubernetes (read_only = true), Grafana (--disable-write), your cloud: AWS, Azure or Cloudflare | Docker MCP Gateway for one shared profile; Sentry | Any database server with production write access |
| Data team | GitHub (/readonly), one database server (Postgres MCP Pro --access-mode=restricted, DBHub or MCP Toolbox), Context7 | Supabase (read_only=true); PostHog; Grafana for pipeline metrics | Firecrawl and browser servers unless you ingest web data |
-
List the systems your team touched last week. Each one the agent could not see is a candidate.
-
Cap the core stack at five servers. Tool search in Claude Code and Codex defers most schemas, but results still cost tokens, and every server widens what a prompt injection can reach.
-
Configure every server in its read-only form using the switch column above. Where the answer is “token scope”, create a credential with read permissions only.
-
Commit the shared servers at project scope. Claude Code reads
.mcp.jsonand Cursor.cursor/mcp.json. Codex writes each developer’s~/.codex/config.toml, so publish thecodex mcp addlines inAGENTS.md. -
Measure the context cost. Run
/contextin a fresh Claude Code session before and after;claude plugin details PLUGIN_NAMEprints a plugin’s component inventory and projected token cost. -
Grant write access per task, not per team. Add the write-capable server at local scope for that task, then remove it with
claude mcp remove NAME(orcodex mcp remove NAME).
How do you prove the servers are really read-only?
Section titled “How do you prove the servers are really read-only?”A config that says read-only is a claim. Three checks turn it into evidence without reading the server’s source.
Check the tool list. Ask the agent which tools each server exposes and look for write verbs. The GitHub /readonly endpoint should show nothing that creates, updates, merges or closes; Grafana with --disable-write should lack update_dashboard and create_incident.
Check the written config. claude mcp get NAME and codex mcp get NAME --json print what the agent will load, which catches a URL stored as a stdio command and a dropped Codex header (see below).
Gate the shared file in CI. This script fails the build when .mcp.json names a server outside the allowlist or loses a read-only switch. Against the .mcp.json from the Claude Code tab it passes; with /readonly removed it fails.
#!/usr/bin/env bash# scripts/check-mcp-policy.sh: run in CI on every change to .mcp.jsonset -euo pipefailjq -e ' .mcpServers as $s | ($s | keys - ["github", "supabase", "grafana"] | length == 0) and (($s.github.url // "") | test("/readonly$")) and (($s.supabase.url // "") | test("read_only=true")) and ((($s.grafana.args // []) | index("--disable-write")) != null)' .mcp.json > /dev/null || { echo "MCP policy check failed: see .mcp.json"; exit 1; }echo "MCP policy check passed"Who signs off. The tech lead owns .mcp.json through CODEOWNERS; adding a write-capable server or removing a switch needs a second approver. For organization-wide allowlists, see MCP registries and gateways.
Which MCP package names are fake or wrong?
Section titled “Which MCP package names are fake or wrong?”Agents and old blog posts both produce plausible names. Every row was checked against npm or PyPI on 2026-09-26.
| Looks right | What is true | Use instead |
|---|---|---|
@modelcontextprotocol/server-github | Deprecated; GitHub says it is no longer functional | https://api.githubcopilot.com/mcp/ or ghcr.io/github/github-mcp-server |
@modelcontextprotocol/server-postgres, -puppeteer, -slack, -gitlab, -brave-search | Deprecated and archived | Postgres MCP Pro or DBHub; Playwright MCP; the vendor servers |
@modelcontextprotocol/server-git, -fetch, -time | Not on npm (404); these are Python | uvx mcp-server-git, uvx mcp-server-fetch |
@anthropic-ai/mcp, @anthropic/mcp-server-github | 404 on npm (checked 2026-09-26) | The vendor’s own server |
@context7/mcp, @upstash/context7, context7-mcp | 404 | @upstash/context7-mcp |
@figma/mcp, @linear/mcp, @vercel/mcp, @supabase/mcp | 404 | Remote URLs; for Supabase local, @supabase/mcp-server-supabase |
@microsoft/playwright-mcp, unscoped playwright-mcp | 404, and an unrelated community package | @playwright/mcp |
@chrome-devtools/mcp, @google/chrome-devtools-mcp | 404 | chrome-devtools-mcp (unscoped) |
npx postgres-mcp | The npm package is unrelated | uvx postgres-mcp (PyPI) |
@leval/mcp-grafana | A community port, not Grafana’s | uvx mcp-grafana or Docker grafana/mcp-grafana |
serena on npm or PyPI | Both unrelated | PyPI serena-agent |
docker-mcp on npm | A community package, not Docker’s | The docker mcp CLI plugin |
npm browser-use | An unrelated TypeScript library | PyPI browser-use via uvx |
@neondatabase/mcp-server-neon | Deprecated | https://mcp.neon.tech/mcp |
@azure/mcp@latest | Resolves to a beta (3.0.0-beta.47) | @azure/mcp@2.0.5 |
Which other MCP servers were verified?
Section titled “Which other MCP servers were verified?”These passed the same checks but serve a narrower job than the top 30.
| Servers | Covered in |
|---|---|
Slack MCP (via the slack plugin), GitLab MCP (beta) | tickets and docs over MCP, GitHub MCP guide |
| Datadog MCP | Observability MCP servers |
| Exa, Tavily, Brave Search, MarkItDown MCP (alpha) | Web research MCP servers |
Neon (readonly=true), MongoDB (--readOnly) | Database MCP servers |
| Google Cloud managed servers, gcloud MCP | Cloud platform MCP servers |
Stagehand with Browserbase, dev-browser (next pre-release) | Browser MCP servers |
| Claude Context (Zilliz) | Code intelligence MCP servers |
| n8n-mcp, Composio Connect | Integration hub MCP servers |
| Next.js DevTools MCP, MobileBuildMCP, Hugging Face MCP; shadcn MCP | Framework DevTools MCP, shadcn/ui MCP |
| Filesystem, Git, Fetch, Memory, Sequential Thinking, Desktop Commander | MCP reference servers |
What breaks when a team adopts these MCP servers?
Section titled “What breaks when a team adopts these MCP servers?”claude mcp add NAME URL connects to nothing. Without --transport http, Claude Code 2.1.283 writes a stdio server whose command is the URL, and fails only at connect time. Remove it, add it again with --transport http, and confirm with claude mcp get NAME. --url is a Codex flag; Claude Code rejects it.
Codex drops your auth header without an error. A headers = { ... } table in config.toml parses and is ignored (codex-cli 0.157.1). Use --bearer-token-env-var or the http_headers / env_http_headers keys, and check codex mcp get NAME --json.
A vendor plugin quietly restores write access. github@claude-plugins-official points at the full https://api.githubcopilot.com/mcp/ URL, not /readonly, so installing it next to your read-only entry gives the agent both. Run the audit prompt after any plugin install.
Parallel agents fight over one browser. Only one client at a time can open a persistent Playwright profile. Start Playwright with --isolated or a distinct --user-data-dir per worktree.
A copied endpoint is dead. Atlassian’s /v1/sse stopped working after 2026-06-30; use /v2/mcp. Firecrawl says never to put an API key in the server URL. Sentry token auth needs Sentry-Bearer, not Bearer.
Lockdown mode is mistaken for a permission. GitHub’s --lockdown-mode filters public-repository content from authors without push access, to reduce prompt injection, but GitHub states it “is not an authorization boundary”. Pair it with /readonly and a narrow token.
The context window fills before the task starts. If /context shows MCP tools taking a large share of a fresh session, remove servers the task does not need and prefer compact designs: Cloudflare quotes about 1k tokens for its 3-tool Code Mode server against about 244k for native API schemas (Cloudflare, read 2026-09-26). Playwright itself says coding agents “might benefit from using the CLI+SKILLS instead”. See the MCP token cost guide.