200+ trusted
MCP servers,
one index.
Find trusted MCP servers for Claude, ChatGPT, Cursor, and every major AI platform. Official integrations from GitHub, Stripe, AWS, and 200+ more.
Featured Servers
The most popular and trusted MCP servers in the ecosystem
How secure are the MCP servers in this directory?
We ran every server in the catalog through the same automated framework on August 7, 2026. 113 of 199 servers exposed a source we could check. The remaining 86 (43%) publish no repository or hosted endpoint URL, so no automated check can be applied to them at all.
Full supply-chain check: releases, lockfile, SBOM, CI, contributors, license.
Hosted servers checked for TLS-only transport and OAuth metadata discovery.
86 servers publish neither a repository nor an endpoint URL.
Hosted endpoints (80 servers)
TLS-only (HTTPS) endpoint Mitigates: Plaintext credential interception | 100%80 of 80 | |
OAuth 2.1 metadata (RFC 9728) Mitigates: Token mismanagement, audience confusion | 13%10 of 80 |
Source repositories (33 servers)
SECURITY.md published Mitigates: Coordinated disclosure path | 68%21 of 31 | |
Commit in last 90 days Mitigates: Maintainer abandonment | 90%28 of 31 | |
≥2 active contributors Mitigates: Bus-factor of one | 97%30 of 31 | |
CI pipeline configured Mitigates: Code health regression | 87%27 of 31 | |
Dependency lockfile committed Mitigates: Dependency confusion | 87%27 of 31 | |
Signed releases (npm provenance) Mitigates: Supply-chain backdoor | —0 of 0 | |
Software Bill of Materials (SBOM) Mitigates: Audit trail | 0%0 of 31 | |
License declared Mitigates: Legal ambiguity | 100%31 of 31 |
Rates are calculated over checks that actually ran — a check marked not-applicable for a given server is excluded rather than counted as a failure. Deep framework checks (OAuth 2.1 / PKCE implementation, input validation, sandboxing) require human source review and are tracked separately. Read the methodology →
By integration
Browse by Category
22 categories covering every corner of the MCP ecosystem