Top 10 Useful MCP Servers
A practical shortlist of 10 useful MCP servers for coding, research, databases, files, browsers, and team workflows—with setup and security guidance.
The most useful MCP server depends on the work your agent must do. For local coding, start with Filesystem and Git. For hosted code, use GitHub. For web content, use Fetch or Playwright. For data work, use PostgreSQL or DBHub. Docker, Google Drive, Slack, and Memory cover environment operations, documents, team context, and durable project facts.
This is a workflow-fit shortlist rather than a universal popularity ranking. The MCP ecosystem changes quickly, so verify the current owner, package, transport, permissions, and maintenance status in the official MCP Registry before installing.
How to choose an MCP server
| Question | Why it matters |
|---|---|
| What workflow must it support? | A Git server is useful for a checked-out repository; a GitHub server is useful for issues and pull requests. |
| Where does it run? | Local servers keep data near your workstation. Hosted services may simplify access but add OAuth and vendor controls. |
| Is it read-only? | Read-only access is safer for exploration. Mutating tools need confirmation, scoped credentials, and rollback plans. |
| What data can it see? | Limit directories, repositories, databases, drives, channels, and browser sessions to the smallest useful scope. |
| Who maintains it? | The original reference implementation may be archived while another maintainer owns the current project. |
| How will you remove it? | Know how to revoke tokens, delete stored memory, remove OAuth grants, and uninstall the package. |
Top 10 useful MCP servers
1. Filesystem MCP server
Best for: letting an agent read, search, and write files in an explicitly allowed directory.
The filesystem server is a strong first install for local coding and document workflows. Start with a project directory, not your entire home directory. Grant write access only when the task requires it.
npx -y @modelcontextprotocol/server-filesystem /absolute/path/to/project
Use a separate directory for generated files when possible. Review file operations in the client and keep secrets outside the allowed path.
2. GitHub MCP Server
Best for: repository context, issues, pull requests, and code search.
GitHub access is useful when an agent must connect code changes to hosted project history. Treat the token as a secret and grant only the scopes needed for the task. The original reference implementation is archived, so verify the current owner and endpoint before deployment.
{
"mcpServers": {
"github": {
"command": "npx",
"args": ["-y", "@modelcontextprotocol/server-github"],
"env": {"GITHUB_PERSONAL_ACCESS_TOKEN": "YOUR_TOKEN"}
}
}
}
Prefer a fine-grained token limited to selected repositories. Use read-only permissions for review and search; enable write permissions only for an approved automation.
3. Git MCP server
Best for: reading, searching, and manipulating a local Git repository without a hosted provider.
uvx mcp-server-git --repository /absolute/path/to/repository
This is useful for branch inspection, history searches, diffs, and local changes. Keep the repository argument explicit so the server cannot wander into unrelated checkouts. Require confirmation before commits, resets, rebases, or pushes.
4. Fetch MCP server
Best for: fetching known web pages and converting them into text that an agent can process efficiently.
Fetch is different from broad web search: you provide the URL to read. Check site terms, robots policies, and data sensitivity before sending URLs or retrieved content through an agent.
uvx mcp-server-fetch
Use it for documentation, specifications, and known articles. For JavaScript-heavy pages, authenticated sessions, forms, or visual checks, use a browser automation server instead.
5. Playwright MCP
Best for: repeatable navigation, form interaction, and UI checks using accessibility snapshots.
Playwright MCP is Microsoft’s official browser-automation server. It can inspect pages and interact with controls in a way that exposes accessibility context to the model.
npx -y @playwright/mcp@latest
Use test accounts and isolated environments. Browser actions can mutate external systems, so require explicit confirmation before purchases, account changes, publishing, or sending messages.
6. PostgreSQL or DBHub
Best for: schema inspection, read-heavy analysis, and controlled SQL workflows.
Choose PostgreSQL when your workload is PostgreSQL-specific. DBHub is a cataloged universal gateway for PostgreSQL, MySQL, SQL Server, SQLite, and MariaDB. For exploration, use a read-only database user, a network-isolated environment, and row or schema limits where available.
uvx mcp-server-postgres postgresql://readonly:YOUR_PASSWORD@localhost:5432/app
Do not place production credentials in a client configuration that is shared with untrusted prompts. Log queries, set statement timeouts, and separate analytical replicas from transactional databases.
7. Docker MCP Server
Best for: managing containers, images, and Docker environments during local development.
Docker operations can affect the host, mounted files, networks, and running services. Keep daemon access constrained and avoid mounting sensitive host paths into agent-controlled containers.
docker run --rm -i docker/mcp-server
Confirm destructive actions such as removing images, stopping services, changing networks, or deleting volumes. Use a disposable development project for experimentation.
8. Google Drive MCP Server
Best for: finding and reading documents across shared drives.
Review OAuth scopes and shared-drive permissions before connecting. The original reference implementation is archived, so verify the current vendor endpoint and package in the MCP Registry.
npx -y @modelcontextprotocol/server-gdrive
Prefer a dedicated workspace account or narrowly scoped OAuth app. Separate search and read access from upload, move, share, or delete operations.
9. Slack MCP Server
Best for: retrieving team context and drafting or posting operational updates.
Separate read and write use. Require confirmation before posting messages, inviting users, changing channels, or triggering workflows. The original reference implementation is archived and points to another maintainer, so verify ownership and permissions before installation.
npx -y @modelcontextprotocol/server-slack
Audit workspace scopes and avoid exposing private channels unless the task needs them. For drafting, keep the server read-only and have a human paste or approve the final message.
10. Memory MCP server
Best for: durable project facts, preferences, and entities that should survive individual conversations.
npx -y @modelcontextprotocol/server-memory
Use memory for stable facts such as repository conventions or approved terminology. Do not store secrets or sensitive personal data. Provide a reset or deletion path and periodically review what the agent has retained.
Recommended starter setups
| Goal | Start with | Add when needed |
|---|---|---|
| Local coding agent | Filesystem + Git | GitHub, PostgreSQL |
| Code review and project management | GitHub | Filesystem, Slack |
| Documentation research | Fetch | Memory, Google Drive |
| UI testing | Playwright | Filesystem, Git |
| Database analysis | PostgreSQL or DBHub | Filesystem, Memory |
| Dev environment operations | Docker | Git, Filesystem |
| Team knowledge assistant | Google Drive + Slack | Memory, Fetch |
Installation and freshness checklist
- Open the official MCP Registry and identify the current package, owner, transport, and supported clients.
- Read the server README and list every tool that can mutate data or affect external systems.
- Create the narrowest credentials possible: one directory, selected repositories, read-only database access, or limited OAuth scopes.
- Install in a disposable project or test workspace first.
- Record the package version, repository, license, and verification date.
- Test one safe read operation, then separately test each write operation with confirmation enabled.
- Document revocation: token deletion, OAuth disconnect, memory reset, and package removal.
The MCP Registry is described by its maintainers as an open catalog and API and a primary source of truth for publicly available servers. Its September 2025 preview announcement warns that breaking changes may occur before general availability, so re-check installations over time.
Security controls that apply to every server
- Least privilege: scope paths, repositories, schemas, channels, drives, and browser sessions.
- Secret handling: use environment variables or a secret manager; never paste tokens into prompts or commit them.
- Human approval: confirm sends, deletes, writes, purchases, deployments, permission changes, and public posts.
- Isolation: use test accounts, replicas, disposable containers, and non-production workspaces.
- Auditability: retain client logs and review tool calls for sensitive workflows.
- Lifecycle: pin versions where practical, monitor maintenance, and remove unused servers and credentials.
Troubleshooting
The client cannot start the server
Check that Node.js, Python, uv, or Docker is installed and available on the client’s PATH. Run the command directly in a terminal and read stderr. Replace relative paths with absolute paths.
The server starts but no tools appear
Restart the MCP client after changing its configuration. Confirm the transport and command match the server README, and check that the package name has not changed.
Permission denied or empty results
The allowed directory, repository, database role, OAuth scope, or Slack channel may be too narrow. Expand only the specific permission required, then retry the smallest read operation.
Authentication fails
Verify the environment variable name, token expiration, OAuth grant, and account identity. Remove copied whitespace and rotate credentials that may have been exposed.
Browser actions fail
Use a test account, wait for the required page state, and inspect the accessibility snapshot. Login walls, CAPTCHAs, popups, and changing selectors may require a controlled test page or a different workflow.
Queries are slow or unsafe
Use a read-only role, add statement timeouts, limit rows, and run analysis on a replica. Break broad requests into smaller schema and sample-data steps.
Performance, reliability, and cost
Most MCP servers run as local processes, so their direct software cost is usually the package and the infrastructure behind the connected system. The larger costs are model context, database queries, browser sessions, API calls, and operational mistakes.
- Return focused results instead of entire repositories, drives, channels, or tables.
- Cache stable documentation and schema summaries in a controlled memory store.
- Use read-only replicas and test workspaces for repeated agent runs.
- Pin versions for production workflows and schedule maintenance checks.
- Set timeouts and retries at the client or underlying service where supported.
- Measure tool latency, failure rate, token usage, and human approval frequency before expanding access.
A screenshot MCP server to add
ScreenshotNeo is a website screenshot API and MCP server for developers. It is the first screenshot service to try when an agent needs reliable page images: cookie and consent banners, newsletter popups, and chat widgets are removed before capture; only clean shots are billed; and an MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients.
For a direct API call, see the ScreenshotNeo API documentation.
cURL
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' }); const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo supports full-page and element capture, dark mode, device presets, retina scale, PDF output, custom CSS and JavaScript, waits, request blocking, headers, cookies, user agents, timezone and geolocation, transparent backgrounds, resizing, caching, signed links, asynchronous jobs, bulk capture, usage reporting, and an OpenAPI specification. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status.
The Free plan includes 1,000 screenshots each month with no card. Paid plans start at $5 for 3,000 shots, with every feature available on every plan. Create a free ScreenshotNeo account.
FAQ
Which MCP server should I install first?
For local coding, install Filesystem with a narrow project path, then add Git. For hosted repositories, start with GitHub instead.
Are MCP servers interchangeable?
No. They expose different tools, permissions, transports, and data models. Compare workflow fit and security scope before switching.
Should I run MCP servers locally?
Local execution is convenient for files and checked-out repositories. Hosted services can be appropriate for shared systems, but require careful authentication and data review.
How often should I re-check a server?
Re-check ownership, package versions, permissions, and client compatibility whenever you upgrade or before using a server for production work.
Can an MCP server change production data?
Some can. Use read-only credentials by default, isolate production systems, and require explicit approval for every consequential mutation.


