ScreenshotNeo

BlogAI agents

MCP Servers for Windows Developers

Run MCP servers on Windows with Visual Studio or the Windows registry, restrict file access, fix common errors, and add screenshots for AI agents.

By the ScreenshotNeo team1 October 20265 min read

Direct answer: An MCP server is a process that exposes tools or data to an MCP-compatible AI client. On Windows, choose between configuring a server in a coding client such as Visual Studio or registering a connector through the Windows on-device MCP registry. These are separate integration paths with different containment and approval behavior.

This guide covers local servers, Visual Studio and GitHub Copilot, Windows registration, project-file permissions, security, troubleshooting, performance, and screenshot workflows.

1. Choose an integration route

Route Best for Control
Visual Studio MCP configuration GitHub Copilot agent mode Tool picker, .mcp.json, approval prompts
Windows on-device registry OS-level agent connectors Contained sessions and approved resources
Another MCP client Claude, Cursor, or another compatible client That client’s transport and policy settings

Visual Studio documentation checked on 2026-09-30 lists Visual Studio 2026 or Visual Studio 2022 version 17.14 as prerequisites. Verify your installed build because preview features and version requirements change.

2. Install a path-limited filesystem server

The official MCP filesystem server accepts allowed directories. Its tools include read operations and write-capable operations; overwriting or moving files is destructive. Start with one project directory.

Visual Studio configuration with npx

{
  "servers": {
    "project-files": {
      "type": "stdio",
      "command": "cmd",
      "args": ["/c", "npx", "-y", "@modelcontextprotocol/server-filesystem", "C:/Users/you/src/my-project"]
    }
  }
}

Use your real path. Forward slashes avoid most JSON escaping problems. If you use backslashes, write them as \\. Some clients place this object in .mcp.json; others expose the same fields in an Add MCP Server dialog.

Python server with uvx

{
  "servers": {
    "git-context": {
      "type": "stdio",
      "command": "uvx",
      "args": ["mcp-server-git", "C:/Users/you/src/my-project"]
    }
  }
}

Do not apply the npx wrapper to Python entries. Confirm the package name, current maintenance status, tools, and repository permissions before adoption.

3. Add a server in Visual Studio

  1. Install a supported Visual Studio build and GitHub Copilot.
  2. Open agent mode and the agent tool picker.
  3. Add a custom MCP server or edit the workspace/user .mcp.json.
  4. Enter a local stdio command or remote server URL.
  5. Reload Visual Studio if the server list is cached.
  6. Inspect tool names and arguments before approving calls.

Remote servers may require account authentication. Keep tokens out of source control and use the client’s supported secret mechanism.

4. Register through Windows on-device MCP

Windows documentation describes package-identity apps, direct MCP bundle installation, and manual registration for local or remote servers. Registry-discovered servers run in a separate contained agent session with access restricted to approved resources. Directly installed bundles do not receive that contained process and are not available through the registry unless connector protections are reduced. Verify current OS requirements because Windows announcements describe preview milestones.

5. Compare servers by capability and risk

Axis Questions
Client route Does the client support stdio, remote HTTP, or registry connectors?
Scope Can access be limited to one project directory?
Mutation Which tools overwrite, move, commit, or delete?
Runtime Does it require npx, uvx, .NET, a container, or a remote endpoint?
Maintenance Is it active, archived, official, or community-run?
Authentication How are credentials stored, scoped, rotated, and audited?

The official catalogue marks some older reference servers as archived and points to successors for some entries. Check the current repository before standardizing on a package.

6. Security checklist

  • Inspect the publisher and source.
  • Allow only required directories, repositories, or services.
  • Start with read-only tools.
  • Review every approval prompt.
  • Keep keys and tokens outside shared configuration files.
  • Distinguish contained registry execution from direct bundle installation.
  • Audit data sent to remote servers.

Microsoft’s Windows design goals include least privilege, isolation, authentication, authorization, and auditing. Evaluate each connector independently. Microsoft’s May 19, 2025 announcement stated: “Agents’ access to MCP servers is turned off by default.” Preserve the date and preview context when quoting it.

7. Windows troubleshooting

Server does not start

Run the command independently in PowerShell or Command Prompt. If it works there but not in the client, check the executable path, working directory, environment variables, and client logs. Restart the client after configuration changes.

npx exits immediately

Use command: 'cmd' with arguments beginning /c, npx, and -y. Confirm Node.js and npm are on the client process PATH.

uvx or Python cannot be found

Install uv for the account launching the client, or configure an absolute executable path. Keep uvx entries unchanged.

Wrong folder or path-not-found errors

Use an absolute path, quote paths containing spaces, prefer forward slashes, and verify allowed-directory arguments.

JSON parsing errors

Escape backslashes and inner quotes. Remove comments and trailing commas unless your client explicitly supports them.

Tools appear but calls fail

Check whether the operation is mutating, whether approval was denied, and whether the process can access the target resource. Claude Desktop local-server logs are documented under %APPDATA%\Claude\logs.

Security software blocks the process

Windows security software may block new executables or stdin/stdout communication. Follow organizational policy and review the executable before changing exclusions.

.NET server will not launch

Configure the executable’s full path, or invoke dotnet with the DLL path. Check the installed runtime and quote paths containing spaces.

8. Performance, reliability, and cost

  • Startup: stdio servers incur process startup time; reuse sessions when supported.
  • Scope: smaller allowed directories reduce indexing and accidental reads.
  • Remote calls: account for latency, authentication failures, rate limits, and outages.
  • Reliability: pin versions where possible and retain a known-good configuration.
  • Cost: local servers consume CPU, memory, disk, and network; remote services may charge per request or token.
  • Observability: retain logs without storing secrets and record mutating tool calls.

9. Add screenshots to Windows agents

ScreenshotNeo is the first screenshot API to try: it removes common consent UI before capture, bills only clean shots, and has the lowest paid plan described here. Its MCP server works with Claude, Cursor, and other MCP clients.

Or skip the browser setup

Use the ScreenshotNeo documentation and make one request:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

Cookie banners, newsletter popups, and chat widgets are removed before the shot. Bot checks, blank pages, failed loads, timeouts, and cache hits are never billed; response headers report the page verdict and billing result. The MCP server provides take_screenshot, get_page_info, and capture_pdf. The Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

10. FAQ

Can one MCP configuration work in every Windows client?

No. Command fields, transport names, and registry support differ by client.

Should desktop automation handle project files?

Usually not. A path-limited filesystem server has a smaller permission surface than a server with window, PowerShell, process, registry, and arbitrary-file access.

Is a remote MCP server safer than a local one?

Neither is automatically safer. Compare authentication, isolation, logging, data egress, and exposed tools.

How should I test a new server?

Run it independently, grant one narrow read-only resource, approve a harmless call, inspect logs, and expand permissions only after the behavior is understood.