Independent reporting on artificial intelligence.


The Frontier Wire

Comparisons

Top 10 MCP servers in 2026, compared on auth, tools and security

Most of the MCP servers worth connecting in 2026 are now hosted by the vendors themselves, behind OAuth. The differences that matter are how much a server lets an agent change, how finely access can be narrowed, and how each one has handled its security incidents.

TL;DR

  • Nine of the ten servers here are maintained by the company behind the product; the tenth is a reference implementation. Seven offer a vendor-hosted endpoint with OAuth sign-in, Context7 is remote with an API key, and only Playwright and Filesystem are local-only.
  • GitHub’s server ranks first because it combines OAuth, read-only mode, per-toolset endpoints and a lockdown mode for public-repository content. Atlassian and Notion follow for business data.
  • Every server that can write is a target for prompt injection through the data it reads. Documented cases include GitHub (2025), Supabase (2025), Context7 (2026, fixed server-side) and code flaws in Filesystem and Playwright, both patched.
  • The useful controls are read-only modes, project or toolset scoping, admin kill switches and human confirmation for risky writes. Coverage varies widely, so the comparison table lists them.
  • In production, teams put servers behind an MCP gateway for per-consumer tool filtering, credential custody and audit, and watch laptops for servers added outside it.

The best MCP servers in 2026 are less about raw tool count than about control: who maintains the server, how a user signs in, how much an agent can change, and what happens when the data it reads contains instructions. The Model Context Protocol (MCP) is the open standard that lets AI applications discover and call tools on other systems, and an MCP server is the program that exposes those tools. This comparison ranks ten general-purpose servers used across engineering and business work against published criteria. It reads each server’s repository, documentation and official registry entry as of 5 October 2026. None of the servers were run or load-tested for this piece.

What an MCP server does

An MCP server publishes a list of tools, each with a name, a description and a JSON Schema for its inputs. A client inside a host application (an IDE, a desktop assistant, a coding agent) fetches that list with tools/list, shows the definitions to the model, and sends tools/call when the model picks one.

The current revision of the protocol, dated 2026-07-28, defines two standard transports. stdio means the client launches the server as a local subprocess and exchanges newline-delimited JSON-RPC over standard input and output. Streamable HTTP means each message is an HTTP POST to a single endpoint, which is how vendor-hosted remote servers work. The same revision removed protocol-level sessions, so remote servers no longer need sticky connections.

Authentication depends on the transport. The authorization chapter says authorization “is OPTIONAL”, that HTTP servers that support it should act as an OAuth 2.1 resource server, and that stdio servers “SHOULD NOT follow this specification, and instead retrieve credentials from the environment.” In practice, a remote server signs the user in through a browser OAuth flow, while a local server reads an API key from an environment variable. The specification also forbids token passthrough: “MCP servers MUST NOT accept or transit any other tokens.”

The tools chapter sets the safety baseline. It says there “SHOULD always be a human in the loop with the ability to deny tool invocations,” and that clients “MUST consider tool annotations to be untrusted unless they come from trusted servers.” Annotations are hints such as readOnlyHint and destructiveHint that a server attaches to a tool. They are useful for building approval prompts, but they are claims made by the server, not guarantees.

How the servers were chosen

Candidates came from the official MCP Registry, vendor documentation and the reference repository. The registry is a useful starting point but not a filter. Its about page says it is “currently in preview,” verifies only that publishers control the GitHub account or domain in a server’s name, and delegates security scanning to package registries and aggregators. A registry search for “notion” returned more than ten entries, of which one (com.notion/mcp) is Notion’s own. Every server below was matched to its official namespace.

The criteria are published before the ranking so readers can weight them differently.

CriterionWhat was checkedWhy it matters
MaintainerVendor, community or reference implementationWho fixes it, and whether it tracks the vendor’s API
Transportstdio, Streamable HTTP, vendor-hosted remoteWhere code runs and where credentials live
Auth modelOAuth 2.1 per the MCP spec, API keys, environment tokensRevocable, scoped sign-in versus long-lived secrets
ToolsNumber and type, read versus writeWrite tools turn prompt injection into actions
Narrowing controlsRead-only mode, toolset or project scoping, admin switchesLeast privilege for each use
Security recordPublished CVEs, advisories, demonstrated attacks, fixesHow the maintainer responds
MaintenanceLatest release or commit, deprecation statusAbandoned servers do not get patched
LicenceOpen-source licence of any published codeSelf-hosting and modification rights

Ranking weights the first five criteria most heavily for a general team. A server with a strong security response ranks above one with no published history only when its other controls are also stronger. Servers built mainly for coding agents are covered separately in the companion piece on MCP servers for coding agents.

Top MCP servers at a glance

Rank and serverMaintainerTransportAuthNarrowing controlsLicence
1. GitHubGitHub (official)Remote HTTP or local stdioOAuth, PAT, GitHub AppRead-only, toolsets, lockdownMIT
2. Atlassian RovoAtlassian (official)Remote HTTPOAuth 2.1, API tokensPermission groups, admin controlsApache 2.0 (repo)
3. NotionNotion (official)Remote HTTP (SSE fallback)OAuthUser’s own page access, admin revocationHosted; old local server MIT
4. PlaywrightMicrosoft (official)Local stdio or HTTP portNone (local browser)Allowed origins, isolated profile, capabilitiesApache 2.0
5. LinearLinear (official)Remote HTTPOAuth 2.1, API keyRead-only endpointHosted
6. SentrySentry (official)Remote HTTP or local stdioOAuth, user tokenOrg and project scoping, skillsFSL-1.1-Apache-2.0
7. SupabaseSupabase (official)Remote HTTP or localOAuth, PATRead-only, project scope, feature groupsApache 2.0
8. StripeStripe (official)Remote HTTPOAuth, agent API keysPer-environment grants, human confirmationHosted; repo MIT
9. Context7UpstashRemote HTTP or local stdioAPI keyTwo tools, read-only by designMIT (server only)
10. FilesystemMCP project (reference)Local stdioNone (local directories)Allowed directories, RootsMIT and Apache 2.0

1. GitHub MCP server

GitHub’s MCP server is an MIT-licensed Go project with about 33,400 stars, and its latest release, v1.14.0, shipped on 2 October 2026. It runs locally over stdio as a binary or Docker image, or remotely at https://api.githubcopilot.com/mcp/, which the registry lists under the verified io.github.github namespace.

Authentication covers OAuth in the browser, personal access tokens and GitHub App credentials for non-interactive deployments. With classic tokens, “Tools are filtered at startup based on token scopes,” so an agent only sees what the token can do.

The tool surface is large: 21 toolsets, from issues and pull requests to Actions, code security and projects. Only five are on by default (context, repos, issues, pull requests, users). The remote server exposes per-toolset URLs such as /x/issues, and appending /readonly strips write tools. The configuration guide says read-only mode “will disable all tools that are not read-only even if they were requested.”

Its security history is the clearest case study in the category. In May 2025, Invariant Labs showed that a malicious issue in a public repository could steer an agent into reading a user’s private repositories and leaking them through a pull request. Invariant stressed that this was “not a flaw in the GitHub MCP server code itself” but an architectural problem at the agent level. The server now has a lockdown mode that, for public repositories, surfaces only content from users with push access. GitHub’s own documentation calls the header form “a best-effort content filter, not a security boundary.”

Best fit: any engineering team on GitHub. Start with the read-only URL and add write toolsets per task.

2. Atlassian Rovo MCP server

Atlassian’s Rovo MCP server is a hosted service at https://mcp.atlassian.com/v2/mcp, marked “Generally Available.” Its GitHub repository holds documentation and configuration under Apache 2.0, not the server code. It reaches Jira, Confluence, Jira Service Management, Bitbucket Cloud, Compass, Loom and several planning products. The legacy SSE endpoint was scheduled for deprecation after 30 June 2026, and older /v1/mcp URLs now expose the v2 tools.

Sign-in is OAuth 2.1 or API tokens (personal tokens over Basic auth, or service-account keys as Bearer tokens), and API-token access must be enabled by an admin. The README states that “Data access respects user permissions across every connected Atlassian product,” so the agent cannot see a project the user cannot. Admins can restrict which external AI tool domains may connect, enforce IP allowlists, review audit logs and revoke app authorizations.

The supported tools page lists more than 100 tools in permission groups (read, write, search, delete and manage). The delete_jira and manage_jira groups are “disabled by default; requires admin enablement.” Some tools draw on Rovo credits; the documentation puts Teamwork Graph and cross-product search at up to 10 credits per call.

No public advisory against the server was found. Its exposure is the same as any work-tracking server: tickets and pages written by outsiders, such as service-desk requests, are untrusted text the model will read.

Best fit: organizations on Atlassian Cloud that want one governed endpoint for tickets, documentation and code review.

3. Notion MCP

Notion MCP is “a remote MCP server hosted by Notion,” at https://mcp.notion.com/mcp over Streamable HTTP, with an SSE fallback at /sse. According to its connection guide, it “currently requires you to complete the OAuth authorization flow,” so there is no static-key option for unattended jobs.

Access mirrors the user: the client “can use Notion MCP tools to read and update content that you can access.” Workspace owners manage and revoke connections in settings. The tool list has 36 tools, and 16 of them write: creating and moving pages, editing databases and views, adding comments, uploading files, and starting sessions with Notion’s Custom Agents. Search and data-source queries are rate-limited to 20 calls per 10 seconds. One search tool, notion-ai-search, also reaches connected sources such as Slack and mail, which widens what an agent can read through a single grant.

The older open-source notion-mcp-server (MIT) still exists. Its README now says it “is no longer actively maintained or supported.” Teams running it locally with an integration token should move to the hosted server.

Best fit: teams that keep specifications, meeting notes and wikis in Notion. No read-only switch is documented on the pages consulted, so approval prompts for write tools are the main control.

4. Playwright MCP

Playwright MCP, from Microsoft under Apache 2.0, lets an agent drive a real browser. It is the most-starred official server in this list after Context7, at about 37,800 stars, and ships often: v0.0.83 on 28 September 2026, v0.0.82 ten days earlier.

Its design choice is to work from the page’s accessibility tree rather than screenshots. The README calls this “fast and lightweight” because it “uses Playwright’s accessibility tree, not pixel-based input,” so no vision model is needed. Vision, PDF, network and storage tools are opt-in through --caps.

It runs locally over stdio by default, or as a standalone HTTP server on a chosen port. There is no sign-in; the controls are local flags. --allowed-origins restricts which sites the browser can request, --isolated keeps each session in a throwaway profile, and file access defaults to the workspace root. The README is direct about the limits: “Playwright MCP is not a security boundary.”

Its one public vulnerability, CVE-2025-9611, published in January 2026, affected versions before 0.0.40. The server did not validate the Origin header, so a malicious web page could use DNS rebinding to send requests to a locally running server and invoke its tools. That is exactly the “insecure local server that’s left running on localhost” scenario in the specification’s security guidance.

Best fit: testing, scraping internal tools that lack an API, and research tasks. Pin a current version and use an isolated profile with an origin allowlist, never a logged-in daily browser profile.

5. Linear MCP

Linear’s MCP server is hosted at https://mcp.linear.app/mcp over Streamable HTTP and listed in the registry as app.linear/linear. It is the cleanest example in this list of the current authorization model: “OAuth 2.1 with dynamic client registration,” with Linear API keys accepted as Bearer tokens for clients that cannot run the browser flow. Enterprise workspaces can require Okta-managed sign-in.

The tools cover finding, creating and updating issues, projects and comments. Linear does not publish a full tool list on that page. A separate endpoint at /mcp/readonly exposes read access only, which makes it easy to give a reporting agent cycle summaries without the ability to reassign work.

There is no published code, so licence and code review do not apply, and no advisories were found.

Best fit: product and engineering teams on Linear. It ranks below Notion and Atlassian mainly because it covers a narrower slice of company data, not because its controls are weaker.

6. Sentry MCP server

Sentry’s server connects agents to error, trace and log data at https://mcp.sentry.dev/mcp with OAuth, and the hosted service runs on Cloudflare. The repository also supports stdio with a user auth token. In that mode the documented scopes include project:write, team:write and event:write, so the token is broader than a read-only setup would suggest. A --host flag points it at self-hosted Sentry.

Scoping is the strong point. Adding organization and project slugs to the URL confines the server, and “skills” toggled through MCP_SKILLS or MCP_DISABLE_SKILLS switch whole groups of tools on or off. Seer, Sentry’s AI root-cause analysis, is dropped automatically for self-hosted installs. Several search tools translate natural language into Sentry queries and need a separate LLM provider key.

The code is under the Functional Source License (FSL-1.1) with an Apache 2.0 future licence: use is restricted for competing products and converts to Apache 2.0 after two years. The repository is very active, with a CLI release on the day this piece was checked.

Best fit: engineering teams that already triage in Sentry and want agents to pull stack traces into a fix. Scope to one project per agent.

7. Supabase MCP server

Supabase’s server is hosted at https://mcp.supabase.com/mcp and signs in with OAuth dynamic client registration. The Apache 2.0 package also runs against a local Supabase stack. It exposes more than 30 tools for SQL, edge functions, project management, debugging and documentation search, with storage tools off by default. Version 0.13.0 shipped on 17 September 2026.

It also has the most instructive security history in the list. In July 2025, General Analysis showed a support ticket carrying hidden instructions. A developer’s assistant, connected with the service_role key that bypasses row-level security, read the ticket, queried an integration_tokens table and posted the secrets back into the ticket. As the researchers put it, “the IDE assistant ingests untrusted customer text and holds service_role privileges.”

Supabase’s response added layers: read_only=true runs queries as a read-only Postgres user, project_ref confines the server to one project, features limits tool groups, and SQL results are wrapped with warnings not to follow embedded commands. It also stated plainly that “Guardrails alone aren’t enough,” and advises never connecting agents to production data.

Best fit: development and staging databases, with read-only and project scoping on by default.

8. Stripe MCP server

Stripe’s server is hosted at https://mcp.stripe.com. Its tool design is unusual. Instead of one tool per endpoint, it exposes stripe_api_search, stripe_api_details, stripe_api_read and stripe_api_write, which reach more than 100 listed API methods, plus documentation search and a preview analytics tool. That keeps the tool list short, but it means a single write tool spans refunds, subscriptions, coupons and invoices.

Stripe compensates with the strongest write controls in this comparison. OAuth consent lets a user grant access per live or sandbox account “and set different permissions for each environment.” Administrators can switch MCP access on or off for the whole team and revoke any member’s sessions. Certain stripe_api_write actions, “such as refunds and outbound payments,” require a human to approve through a link before the agent can retry. For unattended use, Stripe requires dedicated agent API keys. From 31 October 2026 it “no longer accepts full-access secret keys or restricted API keys without the Agent tag.” Tool calls can be reviewed in Workbench logs.

The hosted server is not open source; the related stripe/ai repository is MIT-licensed. Stripe’s own page warns users to “exercise caution when using the Stripe MCP with other servers to avoid prompt injection attacks.”

Best fit: finance operations and support teams that need billing lookups. Start in a sandbox, and grant live-mode write access only with confirmation flows on.

9. Context7

Context7, from Upstash, feeds coding agents current, version-specific library documentation. Its repository, at about 62,700 stars, is the most-starred single-server repository in this list. It has two tools, resolve-library-id and query-docs, and runs remotely at https://mcp.context7.com/mcp with an API key, or locally over stdio. The MCP server is MIT-licensed, but the API backend, parsing engine and crawling engine behind it are private.

It is read-only by design, which makes its security incident more instructive, not less. In February 2026, Noma Labs reported that library owners’ “Custom Rules” were “served verbatim through Context7’s MCP server to every user who queried that library, with no sanitization.” A poisoned rule could tell an agent to read environment files and delete data. According to Noma’s timeline, Upstash deployed a server-side fix on 23 February 2026, before public disclosure in March. The CVE record, CVE-2026-75130, followed in August. The project’s own disclaimer still applies: documentation is community-contributed and its “accuracy, completeness, or security” is not guaranteed.

Best fit: developers whose agents keep calling outdated APIs. Treat the returned text as untrusted input, like any web content.

10. Filesystem reference server

The Filesystem server is one of seven reference servers still maintained by the MCP project, alongside Fetch, Git, Memory and others. The servers repository warns that these are “reference implementations” meant as “educational examples,” “not as production-ready solutions.” Postgres, Slack, GitHub, Google Drive and Sentry have all been archived from that repository in favour of vendor or community servers.

It is still widely used because it does one thing simply. It runs locally over stdio, reads and writes only inside allowed directories, and accepts MCP Roots from the client, which “completely replace any server-side Allowed directories when provided.” Nine tools read; four write, and write_file, edit_file and move_file carry destructiveHint. The npm package was last published as version 2026.8.31.

It also illustrates why path checks are hard. In July 2025, Cymulate disclosed two flaws. CVE-2025-53110 allowed access “in cases where the prefix matches an allowed directory.” CVE-2025-53109 allowed a symlink bypass that Cymulate rated 8.4 and linked to possible code execution. Both were fixed in 0.6.3 and 2025.7.01.

Best fit: local document and code work on a single machine, with narrow directories. For shared or remote use, a vendor server or a container is the better choice.

Security record across MCP servers

The incidents above fall into two groups, and they call for different responses.

ServerEventTypeStatus
GitHubMalicious public issue steers agent to leak private repos (May 2025)Prompt injection through dataArchitectural; lockdown and read-only modes available
SupabaseSupport ticket injects SQL exfiltration (July 2025)Prompt injection with over-privileged keyRead-only, scoping and result wrapping added
FilesystemCVE-2025-53110 and CVE-2025-53109 (July 2025)Path validation bugsFixed in 0.6.3 and 2025.7.01
PlaywrightCVE-2025-9611 (published January 2026)Missing Origin check, DNS rebindingFixed in 0.0.40
Context7Custom Rules served unsanitized (February 2026)Prompt injection through served contentFixed server-side; CVE-2026-75130

Code flaws get patched; staying on current versions closes them. Prompt injection through data does not have a patch. Any server that reads text written by outsiders (issues, tickets, pages, documentation) and can also write gives an attacker a path. The risk is highest when one agent combines access to private data, exposure to untrusted content and a way to send data out. The defences are the ones the vendors now ship: read-only modes, narrow scopes, human confirmation for writes and separation between servers that read untrusted text and servers that hold secrets. The review of MCP security tools covers scanners and runtime guards built for this problem.

Governing MCP servers in production

Connecting one server to one laptop is simple. Connecting ten servers to hundreds of users raises four problems that individual servers do not solve: who may use which tools, where credentials live, what gets logged, and which servers are running at all.

An MCP gateway handles the first three by sitting between clients and servers. The comparison of MCP gateways ranks the options. Bifrost, an open-source (Apache 2.0) gateway written in Go by Maxim AI, illustrates the pattern; its MCP gateway overview summarizes the features:

  • Aggregation. Bifrost connects to upstream servers over stdio, HTTP or SSE and exposes their tools at one /mcp endpoint. By default, model-proposed tool calls “are suggestions only,” and execution requires a separate call.
  • Per-consumer tool filtering. Tool access is attached to virtual keys and is deny-by-default: “If a Virtual Key has no specific MCP configurations, no MCP tools are available.” A request header can narrow the allowed tools but never widen them, and the list is checked again at execution time. A support team’s key could see Linear read tools and Stripe lookups, while a platform key sees GitHub writes.
  • Credentials. Upstream OAuth tokens and API keys stay in the gateway rather than in each user’s configuration file. That matters for servers like Sentry’s stdio mode, whose token carries write scopes.
  • Audit. Every tool call passes one point where it can be logged with the calling key. Maxim describes a timestamped trail recording each call’s tool name, server, virtual key and latency. Audit logs, SSO and guardrails are in Bifrost’s enterprise tier.

Content checks add a fifth layer. Gateway-level guardrails for PII, secrets and prompt injection, an enterprise feature in Bifrost, can inspect the text flowing to and from models, which is where injected instructions from a ticket or README end up.

The fourth problem, servers nobody approved, sits on laptops. Developers add MCP servers directly to Claude Desktop, Cursor or a coding agent, and those connections never touch a central gateway. Bifrost Edge, currently in alpha, is an endpoint agent for that case. According to its MCP governance documentation, it reads the MCP configuration of supported apps (Claude Code, Claude Desktop, Gemini CLI, OpenCode, Codex and Cursor) and builds a fleet inventory. New servers go to an approval queue, and a denied server cannot be used “even by an app that had it configured before.” As an alpha it suits a pilot, not yet a compliance control. The broader case for routing agent traffic through one control point is made in the explainer on running an AI gateway in front of every model call.

Choosing MCP servers by use case

NeedFirst server to evaluateControl to switch on first
Code review, issues and pull requestsGitHubRead-only URL; lockdown for public repos
Tickets and documentation across teamsAtlassian RovoLeave delete and manage groups disabled
Wikis, specs and meeting notesNotionApproval prompts for write tools
Browser automation and UI testingPlaywright--isolated and --allowed-origins
Product planning and cycle reportsLinear/mcp/readonly endpoint
Debugging production errorsSentryOrg and project slugs in the URL
Database schema and queriesSupabaseread_only=true and project_ref
Billing and payment lookupsStripeSandbox first; human confirmation
Current library documentationContext7Treat output as untrusted
Local files on one machineFilesystemNarrow allowed directories

Most teams need three to five of these, not ten. Every connected server adds tool definitions to each model call, and the input-token cost of large tool lists is the same dynamic described in the piece on reasoning-model inference costs.

Limits of this ranking

This comparison rests on documentation, repositories, registry entries and published advisories read on 5 October 2026. No server was installed, run, load-tested or penetration-tested, and no vendor claim was reproduced. Tool counts and features change between releases, sometimes weekly.

Several strong candidates were considered and not ranked: Slack, Figma, Cloudflare and Google Workspace servers among them. Each is relevant for teams on those platforms. The ten here were chosen for breadth across engineering, product, data, finance and documentation work, and for the depth of public material on their auth and controls. Absence of a published advisory is not evidence of security. Hosted servers such as Linear’s and Notion’s publish no code to audit. Pricing, including Rovo credits and Context7 plans, was not compared. Finally, no server’s controls address prompt injection by themselves. The ranking measures how much each server helps a team limit damage, not whether it prevents the attack.

Sources

  1. MCP specification: Transports (2026-07-28)
  2. MCP specification: Authorization (2026-07-28)
  3. MCP specification: Tools (2026-07-28)
  4. MCP specification: Security Best Practices (2026-07-28)
  5. The MCP Registry: about (preview)
  6. Official MCP Registry
  7. GitHub MCP server repository (MIT)
  8. GitHub MCP server: remote server documentation
  9. GitHub MCP server: server configuration, lockdown and read-only modes
  10. Invariant Labs: GitHub MCP exploited, accessing private repositories via MCP (May 2025)
  11. Atlassian Rovo MCP server repository (Apache 2.0)
  12. Atlassian: Rovo MCP server supported tools
  13. Atlassian: Get started with the Rovo MCP server
  14. Notion: Notion MCP overview
  15. Notion: Connecting to Notion MCP
  16. Notion: Notion MCP supported tools
  17. Notion open-source MCP server repository (MIT, no longer maintained)
  18. Playwright MCP repository (Apache 2.0)
  19. Playwright MCP releases
  20. CVE-2025-9611: Playwright MCP DNS rebinding via missing Origin validation
  21. Linear: MCP server documentation
  22. Sentry MCP server: setup
  23. Sentry MCP repository (FSL-1.1-Apache-2.0)
  24. Supabase: Model Context Protocol guide
  25. Supabase MCP repository (Apache 2.0)
  26. Supabase: Defense in depth for MCP servers (September 2025)
  27. General Analysis: Supabase MCP can leak your entire SQL database (July 2025)
  28. Stripe: Model Context Protocol documentation
  29. Stripe AI repository (MIT)
  30. Context7 repository (MIT)
  31. CVE-2026-75130: Context7 prompt injection via Custom AI Instructions
  32. Noma Security: ContextCrush, the Context7 MCP server vulnerability
  33. MCP reference servers repository
  34. MCP reference servers: Filesystem server
  35. GHSA-hc55-p739-j48w: Filesystem server path validation bypass (CVE-2025-53110)
  36. Cymulate: EscapeRoute, CVE-2025-53109 and CVE-2025-53110
  37. Bifrost docs: MCP overview
  38. Bifrost docs: MCP tool filtering per virtual key
  39. Bifrost docs: Bifrost Edge MCP governance
  40. Maxim AI: Bifrost MCP gateway

Questions readers ask

What is an MCP server?

An MCP server is a program that exposes tools, resources and prompts to AI applications over the Model Context Protocol. A client inside an application such as Claude Code, Cursor or VS Code connects to it, lists its tools and calls them on the model's behalf. A server can run locally as a subprocess over stdio or remotely over Streamable HTTP.

What are the best MCP servers in 2026?

For general business and engineering use, the strongest options in this comparison are the official servers from GitHub, Atlassian, Notion, Playwright (Microsoft), Linear, Sentry, Supabase and Stripe, plus Context7 for library documentation and the reference Filesystem server for local files. The right set depends on which systems a team already uses and how much write access it is willing to give an agent.

Are remote MCP servers safer than local ones?

They remove some risks and add others. A vendor-hosted server with OAuth avoids long-lived API keys in configuration files and does not run code on the laptop, which the MCP specification flags as a local-compromise risk. But a remote server still acts with the permissions the user grants, and prompt injection through data it returns works the same way. Read-only modes and narrow scopes matter in both cases.

Is the official MCP Registry a list of vetted servers?

No. The registry, still in preview, verifies that a publisher controls the GitHub account or domain in a server's name, and hosts metadata. It delegates security scanning to package registries and downstream aggregators. Searching it for a popular product returns many unofficial servers alongside the vendor's own, so checking the namespace matters.

How do companies control which MCP servers employees use?

Usually with two layers. An MCP gateway aggregates approved servers behind one endpoint and decides which tools each user or team can call, holds upstream credentials and logs every call. An endpoint agent on company laptops finds MCP servers configured directly in desktop apps and coding agents, so unapproved ones can be blocked.

More comparisons