Index live · v1.3.0 · AUG 29 2026

Ahrefs (Remote)

Official

Ahrefs' official remote MCP server delivers live SEO data — keyword research, competitor analysis, backlink profiles, top-ranking pages, AI Overview / brand sentiment, dashboards, and exports — over a Streamable HTTP endpoint at api.ahrefs.com/mcp/mcp. It requires a paid Ahrefs subscription (Lite tier or higher) and consumes API units from your monthly allowance (shared with the direct API and Ahrefs Connect). Auth is an OAuth consent flow that mints a dedicated MCP-scoped key — note that MCP keys are NOT the same as Ahrefs API v3 keys. Feature the remote endpoint only: the ahrefs/ahrefs-mcp-server GitHub repo is officially archived and Ahrefs recommends against using it.

Streamable HTTPAPI Key Required
Official remote, paid (Lite+)

Configuration

{
  "mcpServers": {
    "ahrefs": {
      "url": "https://docs.ahrefs.com/docs/mcp/reference/introduction",
      "headers": {
        "Authorization": "Bearer your-api-key-here"
      }
    }
  }
}

Add this to your claude_desktop_config.json file.

Quick Stats

Trust LevelOfficial
TransportStreamable HTTP
API KeyRequired
CategoryAnalytics & Monitoring
Visit Website

Tags

seobacklinkskeywordsrank-trackingremotepaid

AgenticSkills Audit

Automated framework checks. Deep code review tracked separately. Read the methodology →

1/2
1 of 2 automated checks passed
Audited Aug 7, 2026
Hosted endpoint
TLS-only (HTTPS) endpoint
Mitigates: Plaintext credential interceptionResponded 200 over HTTPS
Evidence
OAuth 2.1 metadata (RFC 9728)
Mitigates: Token mismanagement, audience confusionNo /.well-known/oauth-protected-resource (status 404)
Repo-level checks
SECURITY.md published
Mitigates: Coordinated disclosure pathHosted server — repo-level check not applicable
Commit in last 90 days
Mitigates: Maintainer abandonmentHosted server — no public commit log
≥2 active contributors
Mitigates: Bus-factor of oneHosted server — no public contributor list
CI pipeline configured
Mitigates: Code health regressionHosted server — no public CI
Dependency lockfile committed
Mitigates: Dependency confusionHosted server — repo-level check not applicable
Signed releases (npm provenance)
Mitigates: Supply-chain backdoorHosted server — supply chain via vendor
Software Bill of Materials (SBOM)
Mitigates: Audit trailHosted server — repo-level check not applicable
License declared
Mitigates: Legal ambiguityHosted server — vendor terms of service apply

Deep framework checks (OAuth 2.1 / PKCE implementation, input validation, sandboxing) require human source review and are tracked separately. This scorecard covers programmatically verifiable signals only.