AI Coding & Agents / Practical guide

Best MCP Servers for Claude Code in 2026: Choose by Workflow

Choose an MCP server for the work you need: library docs, repository context, browser inspection, design, project knowledge, incidents or backend development. Compare access, setup and privacy before connecting.

A coding task connects through one selected local or hosted MCP server to relevant tools or context.
Start with a missing capability and one useful connection, rather than an arbitrary server count. Original AI Tech Bench illustration.
In this guide

The best MCP server for your project depends on where the information or action lives. A frontend implementation may need a Figma frame and current library documentation. A bug investigation may need a GitHub issue and an existing Sentry event. Neither task benefits automatically from installing a long list of integrations.

This guide selects eight connections by workflow, documented capabilities and access controls. Official documentation and maintaining repositories were reviewed on 9 October 2026. These are editorial choices, not a performance ranking. We did not install the servers, connect vendor accounts or execute these examples; no benchmark or hands-on result is claimed. Our evidence policy explains that distinction.

Quick comparison: choose the missing capability

Start with the row that matches your task. “Read-only” below describes a documented tool option, not a promise that retrieved information stays on your device.

MCP connections by workflow and first access checkSwipe or scroll horizontally to compare every column.
ConnectionUseful taskDocumented connectionFirst access check
Context7Retrieve library documentation and examplesHosted HTTP or local process; key or OAuth optionsVerify the library/version and what your query reveals
GitHubRead repository, issue and pull-request contextHosted HTTP or local serverUse the read-only endpoint and narrow repository access
PlaywrightInspect and interact with a browserLocal process; HTTP server mode also availableStart with an isolated profile and a disposable page
FigmaBring design structure into implementationHosted HTTP with OAuthCheck file access, supported client, seat and write tools
LinearRetrieve issue and project requirementsHosted HTTP; OAuth or documented API-key setupStart with the read-only endpoint and an appropriate grant
NotionRetrieve specifications and workspace knowledgeHosted HTTP with interactive OAuthReview accessible pages and potential update actions
SentryInvestigate existing errors and performance eventsHosted HTTP OAuth route; local options differLimit organization/project context and inspect event data
SupabaseInspect schema and backend development contextHosted HTTP with OAuthFix a development project, read-only mode and feature set

There is no score attached to these rows. The choice should change when your task, account permissions or existing tools change. The linked vendor setup pages provide each option's current requirements; do not transplant another client's configuration without checking its format.

What an MCP server adds to Claude Code

The Model Context Protocol gives AI applications a standard way to connect to external capabilities. A server can expose tools for actions, resources for context, and prompts for reusable interaction. It does not make a service trustworthy or authorize every action it offers.

In the protocol architecture, the host application contains client components that communicate with servers. For this guide, Claude Code is the host. A local server may run as a process on your machine; a hosted server is reached over a network connection. The transport specification describes stdio and Streamable HTTP. The host can use returned information while planning or answering, so retrieved data may enter the agent's configured model and service environment.

Claude Code's MCP client connects to a local stdio process or hosted HTTP service; capabilities and access vary, and returned text remains untrusted data.
A connection crosses execution, authorization and data boundaries. This original diagram describes the architecture; it is not a capture of an executed server.

An MCP connection is useful when you repeatedly copy information out of another system, or need the agent to perform a supported action there. A Claude Code skill instead provides reusable instructions for a task. A plugin packages extensions for installation; our plugin guide covers that installation and lifecycle. These can work together, but none substitutes for permission to access a private repository, workspace or database.

If an existing command-line tool already provides the required result, keep using it. A one-off schema export or public documentation page may be simpler than another authenticated connection. MCP earns its place when the ongoing context or interaction helps the actual work.

Eight useful connections, with a task for each

Context7: documentation for a specific library

Choose Context7 when an implementation depends on an API your agent may recall incorrectly. Its library lookup and documentation tools let you request relevant material for a named dependency. Supply the library and the version your project actually uses, then inspect the returned reference before accepting an implementation.

A useful first request is: “Find the documented API for this dependency version and explain which part applies to our existing code.” This can reveal a version mismatch before you change the project. It does not prove that the proposed code compiles or behaves correctly; your normal project checks still matter.

The client setup guide documents hosted HTTP, local setup and authentication choices; the hosted OAuth endpoint is https://mcp.context7.com/mcp/oauth. Pick one supported route rather than combining their instructions. Review what your query sends, and avoid including proprietary source code when a public API question is enough. Context7's documentation collection can include community contributions and gaps. Its CLI or skills may also meet the need without an MCP connection.

GitHub: repository and pull-request context

Choose the official GitHub MCP server when the relevant issue, pull request or repository information is already in GitHub. For an initial review task, the remote server's read-only endpoint is a better fit than granting every available write action.

Try one bounded question: “Read this permitted issue and identify the files likely involved; do not create a branch, comment or pull request.” Inspect the issue citations and the proposed files against the repository. A summary is useful only if it reflects the actual issue rather than treating every comment as an instruction.

Hosted authentication depends on the client and supported route; local deployment has separate prerequisites. If a personal access token is needed, restrict it to the repositories and permissions required, and keep it out of shared configuration. Toolset selection narrows exposed capabilities, while repository permissions govern access. GitHub's lockdown filtering is documented as best effort, so do not treat it as a substitute for authorization or review of untrusted issue content. Skip the connection when existing git or gh commands already cover the workflow.

Playwright: a browser that the agent can inspect

Microsoft's Playwright MCP suits tasks that require interactive browser state: inspect a navigation flow, follow an accessible control, or investigate a page that only appears after a sequence of actions. Its accessibility-oriented representation gives the agent structured page information to work with.

Start on a disposable local page or another page you are authorized to test. Ask it to follow the main navigation and report which visible control failed. Record actual steps and results if you later describe the activity as a test. A browser snapshot alone is not a visual comparison, a full accessibility audit or evidence that every route works.

The documented local package needs a compatible Node runtime; its current stated minimum is Node 18. Review the current package's prerequisites before setup. Profile choices also matter: a persistent browser profile can retain authenticated sessions, while isolated mode avoids reusing that profile. Do not give an experimental workflow your everyday logged-in browser. Playwright's browser controls are not a security sandbox. The official project also recommends considering CLI plus skills for coding agents when persistent MCP interaction adds little.

Figma: design context for implementation

Choose Figma's MCP server when a task depends on a real design file: component structure, variables, layout relationships or a particular frame. Begin with a frame you can already access and ask the agent to identify the reusable components and tokens relevant to the implementation.

This gives the work a concrete reference. It does not guarantee that generated code matches the design, so compare the finished page with the actual frame at the required sizes. Avoid requests such as “rebuild the whole file” before you have established the intended screen and permitted work.

Figma's current tool inventory includes canvas and file creation capabilities, as well as design context. Describing the entire service as read-only would be inaccurate. The remote installation guide documents OAuth and Claude Code setup options. Use a client listed in Figma's MCP Catalog and check its plan and seat requirements; existing file permissions and tool-call limits still apply. If a supplied screenshot answers the task, you may not need continuing workspace access.

Linear: issues and project requirements

Linear's MCP server is useful when your team already tracks development work in Linear. It can bring issue descriptions and project context into the coding session, reducing the need to paste several records manually.

Begin by asking for a summary of a few permitted issues for one feature, with links to each record and a clear list of unresolved requirements. Keep assignments, status changes and new issue creation out of that first task. The standard endpoint includes write actions; the documented /readonly endpoint exposes read tools.

An appropriate read-scoped OAuth grant can separately restrict the credential. This is a useful distinction: selecting a read-only tool endpoint and reviewing the consent grant address different parts of the connection. Linear also documents API-key authentication, but that is not a reason to paste a real key into a prompt. Check your workspace's policy before authorizing access. If the relevant ticket is a single public paragraph, a sanitized copy may be enough.

Notion: specifications and project knowledge

Use Notion's hosted MCP when the source material lives in an existing Notion workspace: a specification, meeting decision or project reference. A practical opening task is to retrieve one permitted specification and separate explicit requirements from unanswered questions, citing the original page.

The current setup guidance uses interactive OAuth. The older local notion-mcp-server is no longer actively maintained; a recent commit in that repository does not override the vendor's maintenance statement. Choose the supported hosted route for this workflow.

The connection can read and update accessible workspace content. No official read-only endpoint was established by this review, so do not promise one. Inspect which pages your account can access and which actions you are about to allow. Notion's security guidance also discusses prompt injection and onward sharing: a legitimate document can contain content that attempts to redirect the agent. Keep workspace instructions subordinate to the task you actually authorized. A local, sanitized specification may suffice when broad workspace access is unnecessary.

Sentry: evidence from an existing incident

Choose Sentry's hosted MCP when Sentry already contains the error or performance evidence you need. Start with one permitted issue and ask for its relevant events, environment and timeline. Ask the agent to separate what the record shows from a proposed explanation.

This is different from asking an agent to guess why a website timed out. If the relevant deployment, request or process event was never recorded, adding a connection cannot reconstruct it. An error trace may suggest a place to investigate without proving the root cause.

The documented hosted OAuth route can use organization/project context in its URL. That context selects the working area; it is not proof that the OAuth grant is limited to that area or that all tools are read-only. Inspect the actual consent and returned event fields, including any personal or request data your project captures. The current maintained toolkit repository covers MCP and CLI work; local options have different requirements. Use the existing Sentry interface if one inspection is all you need.

Supabase: development schema and backend context

Supabase's MCP integration is useful for backend development when the agent needs actual project structure rather than an imagined schema. A restrained first task is to inspect a non-sensitive development schema and explain how an existing query relates to its tables. Do not start with production customer records or a request to “fix the database.”

The hosted setup documents project_ref, read_only=true and feature groups. Set the development project's reference, use read-only mode to run SQL as a read-only Postgres user, and select the needed feature groups. Those controls have different jobs; read-only SQL does not establish that every exposed function is harmless. The repository is maintained under Supabase's organization. Review current defaults rather than assuming an unscoped connection serves only one project.

These controls do not make every result safe to share. Rows and other database content can contain sensitive information or prompt injection, and a schema can reveal internal structure. The vendor warns against exposing this connection to your customers. Keep it within an authorized development workflow, review the OAuth grant separately from URL filters, and inspect any proposed SQL before considering a broader permission set. An exported, sanitized schema is a useful alternative for an isolated task.

Connect one server and verify what it actually does

Follow the Claude Code MCP quickstart after confirming that Claude Code works in the intended project, your organization permits the connection, and the vendor supports your client. Use a non-sensitive sample resource you are allowed to read. For a local server, also review its executable package, runtime and file access; for a remote one, review the endpoint and consent requirements.

For example, this source-checked command registers Linear's documented read-only HTTP endpoint at local configuration scope. It was not executed for this article:

Terminal — register the read-only Linear connection for this project
claude mcp add --scope local --transport http linear-readonly https://mcp.linear.app/mcp/readonly

“Local” here means the configuration is personal to the current project. The server in this example is still hosted remotely. Scope and transport answer different questions.

Claude Code configuration scopes, separate from transportSwipe or scroll horizontally to compare every column.
Configuration scopeIntended useSharing boundary
LocalYour connection for this projectPersonal project configuration
ProjectA team-agreed connectionShared .mcp.json; each person needs authorized access
UserA connection across your projectsPersonal configuration across projects

Inside an interactive Claude Code session, open the connection manager to complete the supported authentication flow and inspect status:

Inside Claude Code — inspect the connection and authentication
/mcp

Review the consent screen before completing OAuth. Confirm the account, resources and requested access; do not authorize a broader workspace simply to avoid a setup error. In your terminal, these documented commands inspect configured servers and the specific connection:

Terminal — inspect configured servers and this connection
claude mcp list
claude mcp get linear-readonly

An “added” message records configuration, not a successful task. A connected status does not prove that the right issue or page is accessible. Inspect the tools and try the bounded sample request. Compare its citations with the actual resource. Claude Code's connection reference covers these commands and scopes; vendor instructions cover service-specific authentication.

Do not translate a configuration snippet by guesswork. Claude Code HTTP JSON needs an explicit transport type; a URL alone is insufficient. Local process commands have a different shape. Keep real credentials out of shared project files, copied commands and review captures. When setup requires a secret, follow the supported credential mechanism for that service rather than adding a literal value to an article example.

Permissions and privacy: three separate checks

First, consider where code runs. A local server is a program you execute. Its process may have filesystem, environment and network access beyond the particular tool the agent calls. Inspect the publisher, command, dependencies and supported restrictions before starting it. A hosted server instead introduces a vendor service that receives the requests sent to it.

Second, consider what the credential permits. A project URL, hidden tool group and read-only endpoint are useful controls, but do not automatically narrow an underlying OAuth grant. Review that grant separately. Read-only tools reduce write capability; they can still retrieve sensitive data and return it into the agent's context.

Third, consider what the returned content says. Issue text, pages and database values are external input. A passage asking the agent to send credentials elsewhere is not a new instruction from you. Start with restricted access, inspect unexpected requests and stop a task that expands beyond its approved resource. The MCP security guidance explains why authentication alone does not solve these trust boundaries.

A server listing is also a different kind of evidence. The official Registry is a preview metadata service; verified publisher identity does not certify code security or service health. Anthropic similarly distinguishes Directory listing review from auditing or managing a server. Inspect the actual maintained implementation and current vendor requirements, rather than choosing by a badge or repository star count.

An MCP selection path: use an existing CLI if sufficient, otherwise choose one task, verify the source, limit access, inspect a permitted sample and keep or remove the connection.
Use the smallest connection that answers the task. The review points are original editorial guidance, not a claim that these servers were tested.

Troubleshoot the connection before granting more access

Locate the failed layer before changing permissions. These checks are based on documented setup requirements, not errors reproduced for this guide.

Find the failed connection layer before expanding accessSwipe or scroll horizontally to compare every column.
SymptomCheck firstRestrained next step
Server was added but no tools are usableConnection/authentication status and advertised toolsComplete supported authentication; inspect the exact status
HTTP configuration is skippedExplicit transport type and the vendor's current endpointCorrect the client format; do not paste a different client's JSON unchanged
Local process cannot startRequired runtime, executable and launch argumentsFix the documented prerequisite in the launching environment
Connected server cannot read one resourceAccount, file/project permissions and selected working contextTest a resource already permitted to that account
Request is limited or refusedVendor plan/seat/rate limits and organization policyUse supported limits or ask the administrator; do not bypass controls
A previously working connection failsEndpoint changes, credential state and maintained documentationRecheck the current vendor instructions and a sanitized error

MCP standardizes the interface, while clients and servers still have particular feature and protocol support. The current protocol versioning guide identifies revision 2026-07-28; that does not establish the revision or build deployed by every hosted service. Confirm the actual pair's support when diagnosing incompatibility.

Avoid resolving a narrow read failure by granting organization-wide write access. If you need maintainer help, provide the client/server name, relevant version if known, task and sanitized error. Remove tokens, credential-bearing URLs, private record contents and account identifiers from shared evidence.

Maintain the connections you keep

Review a connection when its requested access, tool set, endpoint or implementation changes. For a local package, review and deliberately update the version you run. Hosted services may change without a local installation step. A Registry version entry describes metadata; it is not proof of the live build behind a hosted endpoint.

Remove a connection that no longer serves a task. For the example above:

Terminal — remove the personal project connection
claude mcp remove linear-readonly --scope local

Claude Code documents deletion of its stored OAuth tokens and client registration when a remote server is removed. Review unnecessary grants in the vendor's account controls as well. Removing configuration cannot recall information already sent elsewhere, and it should not be described as deletion of the vendor's retained data.

This shortlist deliberately avoids filling fifteen slots. The protocol project's reference servers include educational implementations that need a production suitability review. Platform-specific servers may be useful, but should be selected for an existing platform task rather than added as another generic recommendation. A small set you understand is easier to maintain than a collection whose access you cannot explain.

Choose the first task, then decide whether to keep the connection

Write down the missing capability and the permitted resource. For a documentation lookup, request a particular library/version and citation. For an issue tracker, use a sample issue you can already access. For a browser or backend task, start with a disposable page or a development schema.

Use a request that states the boundary explicitly. This is an original example to adapt, not an executed prompt:

Proposed first request — restrict the task to a permitted sample
Read only the sample resource I identify. Explain the information relevant to this coding task and cite its source. Do not modify records, publish content or access unrelated resources. If the resource is unavailable or more access is needed, report the limitation before expanding the task.

Instructions express your intent; they do not replace technical permission controls. Inspect the actual tool calls and result, then record what happened before describing the connection as tested. Keep the server if the information or interaction helps this workflow. Otherwise use your existing tools and remove the unnecessary access. Our AI Coding & Agents pillar groups the related implementation guides.

Sources & further reading

Product facts are checked against the sources below. Access dates describe research, not hands-on testing.

  1. IntroductionModel Context Protocol · Accessed 2026-10-09

    Standard connection of AI applications to external tools/data. Standardization does not prove a particular client/server combination works.

  2. TransportsModel Context Protocol · Accessed 2026-10-09

    Current stdio and Streamable HTTP bindings. Distinguish HTTP response/event streaming from an old SSE-only transport.

  3. Security practicesModel Context Protocol · Accessed 2026-10-09

    Local execution, authorization and untrusted-input risks; constrained scopes and token/audience boundaries matter. No candidate-specific penetration test is implied.

  4. Registry aboutModel Context Protocol · Accessed 2026-10-09

    Preview metadata, ownership verification and separate package-hosting/security roles. A listing is not an audit or performance score.

  5. Reference serversModel Context Protocol · Accessed 2026-10-09

    Educational reference examples, not declared production-ready solutions.

  6. Claude Code MCPAnthropic · Accessed 2026-10-09

    Current transport/configuration/authentication and scope guidance. Registration does not prove successful authentication or execution.

  7. Managed MCPAnthropic · Accessed 2026-10-09

    Directory review differs from a security audit; server endpoint/command policy matters beyond its assigned local name.

  8. Server READMEGitHub · Accessed 2026-10-09

    Official hosted/local choices, read/write tooling, filtering and local requirements. Lockdown is best effort.

  9. Remote configurationGitHub · Accessed 2026-10-09

    Remote read-only paths, toolsets and host-dependent authentication. Do not combine multiple toolsets into an invented endpoint path.

  10. Context7 READMEUpstash · Accessed 2026-10-09

    Library lookup/documentation tools and CLI/skills alternative; community documentation can have gaps.

  11. Context7 client setupUpstash · Accessed 2026-10-09

    Separate remote key/OAuth and local options. No account plan, real key or rate limit was tested.

  12. Playwright MCP READMEMicrosoft · Accessed 2026-10-09

    Accessibility-driven browser tools, process/profile choices and the CLI/skills tradeoff. Controls are not a sandbox.

  13. IntroductionFigma · Accessed 2026-10-09

    Design context and broader current capabilities; supported-client requirements.

  14. Remote installationFigma · Accessed 2026-10-09

    Hosted OAuth and Claude Code plugin/standalone options; remote workflow can use frame links without the desktop application.

  15. Tools and promptsFigma · Accessed 2026-10-09

    Design-context tools and native canvas/file writes. Do not reduce the service to a read-only design export.

  16. Rate limits and accessFigma · Accessed 2026-10-09

    Plan/seat, Catalog and existing file permissions matter; limits may change. Exact quota figures are intentionally not transcribed from the partially collapsed table.

  17. MCP guideSupabase · Accessed 2026-10-09

    OAuth, project/read-only/feature limits, backend tools and data-injection risk. Account-wide default access is broader than a single development schema.

  18. Current repositorySupabase · Accessed 2026-10-09

    Current package/configuration and maintained vendor organization. Old community repository URLs redirect here.

  19. OverviewNotion · Accessed 2026-10-09

    Hosted connection for project knowledge and read/write workspace workflows.

  20. Connect to Notion MCPNotion · Accessed 2026-10-09

    Interactive hosted OAuth; current local package is no longer actively maintained. Generic client snippets require adaptation.

  21. Security practicesNotion · Accessed 2026-10-09

    Accessible workspace data, prompt injection, onward sharing and connection/revocation controls.

  22. MCP guideLinear · Accessed 2026-10-09

    Hosted issue/project tools, OAuth/API-key options and explicit read-only endpoint/scopes. No local benchmark or service availability promise.

  23. Hosted MCP serviceSentry · Accessed 2026-10-09

    Documented hosted OAuth setup and organization/project working-context URLs; project URLs default tool context and hide discovery tools, without establishing a smaller credential grant. The maintained repository also documents explicit upstream-token authentication, so this landing page does not establish OAuth-only support.

  24. Current toolkit repositorySentry · Accessed 2026-10-09

    Current Sentry toolkit repository, hosted/local differences and explicit upstream Sentry-Bearer authentication. A maintained source repository does not establish an installed or hosted build version.

  25. VersioningModel Context Protocol · Accessed 2026-10-09

    Current revision `2026-07-28`; per-request version declaration and interoperability distinction for older handshake-based revisions.

  26. Architecture overviewModel Context Protocol · Accessed 2026-10-09

    Host applications coordinate MCP client components and server connections; tools, resources and prompts are distinct capabilities, not capabilities every server necessarily implements. Local and hosted server programs follow different process/data boundaries.

  27. Connect to MCP serversAnthropic · Accessed 2026-10-09

    Registering a server is distinct from connection, authentication, available tools and execution. Credential-free add/list/get/remove examples, local/project/user scope storage, local stdio prerequisites, and connection-status troubleshooting.

Continue with context

Understand the method behind the advice.