Integrations

MCP Directory Guide: Where to Find MCP Servers and How to Pick Them

The Kopik team7 min read

To find MCP servers, start with the official MCP Registry and the reference servers repository on GitHub, then use community directories to discover more specialised tools. The real work is choosing: a server you connect to your AI assistant can read data, return content into the conversation and sometimes act on your behalf. Below you will find the main directories, a six-point due diligence checklist (authentication, data origin, maintenance, security, prompt injection, cost) and a short section on knowledge-base MCP servers.

MCP in brief: clients, servers and tools

The Model Context Protocol is an open standard for connecting AI assistants to external tools and data. The client is the assistant or editor you use (Claude, Cursor, ChatGPT and others). The server is what exposes the tools: search a wiki, read a spreadsheet, create a ticket. A server may run locally, launched by the client on your laptop, or remotely, as a hosted service you reach over HTTP. Remote servers using the current Streamable HTTP transport are becoming the norm for business tools, because they can be shared across a team and secured centrally.

Where to look: the main MCP directories

No single MCP servers list is complete, and none is a guarantee of quality. Each source has its own strengths.

  • The official MCP Registry. Run by the MCP project and referenced from the protocol site, it records server names, packages and remote endpoints submitted by publishers. It is the closest thing to a canonical index, and several other directories draw on it. Being listed is not an endorsement.
  • The reference servers repository. modelcontextprotocol/servers on GitHub contains reference implementations (filesystem, fetch, Git, memory and a few more) that show how a well-behaved server works. Its README also links to third-party servers. Use the reference servers to learn and prototype rather than as supported products.
  • Community directories. Smithery, Glama, mcp.so and PulseMCP are popular places to browse by category, read descriptions and sometimes connect to hosted versions. Submissions are largely self-service, so quality is uneven.
  • Vendor documentation and client catalogues. Many software providers now document an official MCP server, and some AI clients include a curated catalogue of connectors. When the data owner publishes the server, provenance questions largely answer themselves.

Popularity is not assurance

Download counts, stars and upvotes tell you a server is used, not that it is safe, accurate or still maintained. Treat them as a starting point for your own checks.

Due diligence: six questions before you connect

The best MCP servers are the ones you can explain to a colleague: who runs them, what they can access and what they cost. Work through these six questions for each candidate.

MCP server checklist

CriterionWhat to checkGreen flag
AuthenticationOAuth or API key, scope, revocationKey in a header, restricted to what you need
Data originOfficial API, scraping or curated datasetSources cited with each result
MaintenanceReleases, issues, named publisherRecent activity, data owner or known maintainer
SecurityTool list, write actions, hostingRead-only by default, clear privacy terms
Prompt injectionHow returned content is framedContent marked as untrusted data
CostFree, per call or subscriptionPublished limits and a spending cap

Authentication and access

For remote servers, prefer OAuth or an API key sent in the `Authorization` header, never a secret pasted into the URL. Check whether you can create a key per project and revoke it independently. For local servers, remember they run with your own permissions: a filesystem server should be limited to specific folders, and a shell server deserves real caution.

Data origin and accuracy

Find out what feeds each tool. A wrapper around an official API is very different from a scraper of public pages. If your team will rely on the answers (for HR, tax or compliance questions, say), insist on tools that return the underlying passage or document reference so that answers can be checked.

Maintenance and provenance

Look for recent releases, a changelog, issues that receive replies and a publisher you can identify. Check transport support too: older servers may only offer the earlier SSE transport, which some clients are moving away from.

Security and UK GDPR

Read the tool list before connecting. Tools that send emails, write files or delete records need tighter controls than read-only search. If personal data may pass through a remote server, that provider is likely acting as your processor under UK GDPR, so you will want a data processing agreement, clarity on where data is stored and any international transfers, and a record of the decision. The ICO publishes guidance on controllers, processors and AI that is worth a read before a wider rollout. For local servers, pin versions and review what you install, as you would any open-source dependency.

Prompt injection

Whatever a tool returns becomes part of the model's context. A malicious web page or document can hide instructions meant for your assistant. Good servers frame returned content as untrusted data, and good clients ask before sensitive actions. The riskiest pattern is one session that both reads untrusted content and can send data elsewhere, so keep those capabilities apart where you can.

Cost and limits

Agents can call tools far more often than a human would. Check whether a server is free, metered per call or part of a subscription, what its rate limits are and whether the agent can pass a maximum price per call. That last feature is a simple, effective guard against runaway spending in pounds or any other currency.

Knowledge-base MCP servers

Much of what organisations want from MCP is dependable information rather than actions: policies, product documentation, regulator guidance, specialist know-how. Knowledge-base MCP servers expose search over a curated document collection, typically using retrieval-augmented generation. If you are weighing building this yourself against using a hosted service, our guide to RAG as a service sets out the trade-offs. When comparing servers, ask whether they cite passages, whether you can retrieve raw passages, who curated the sources, and whether you can restrict a connection to one collection.

Kopik is one example of this kind of server. It is reached at `https://kopik.fr/api/mcp` over Streamable HTTP, with an API key in the `Authorization: Bearer kpk_...` header (only `list_bases` works without a key). `ask_base` returns a written answer with numbered source passages, `search_base` returns the passages alone, and `maxPriceCents` refuses a call at no charge if a base costs more than you allow. Base content is wrapped in `<kopik-untrusted>` tags, and appending `?base=<slug>` limits the connection to a single base. The catalogue of knowledge bases includes UK-focused collections such as HMRC VAT notices.

Connect your assistant to sources it can cite

Set up the Kopik MCP server in Claude, Cursor or another MCP client in a couple of minutes, with per-call price caps.

Keeping your MCP setup lean

  1. Start with official servers from tools you already pay for, using read-only keys.
  2. Add one verifiable knowledge source for questions where accuracy matters.
  3. Trial each new server in a test project before rolling it out to the team.
  4. Review quarterly: remove unused servers, rotate keys and check for updates.

Each server adds tool descriptions to the model's context. Beyond a certain point, more servers make the assistant worse at picking the right tool, so a short, well-vetted list usually beats a long one.

Frequently asked questions

Where can I find a list of MCP servers?

The official MCP Registry and the modelcontextprotocol/servers repository on GitHub are the main starting points. Community directories such as Smithery, Glama, mcp.so and PulseMCP list many more, and software vendors increasingly document their own official servers.

Is the official MCP Registry a list of approved servers?

No. It is an index of servers and their metadata as submitted by publishers. It helps you find the canonical name and endpoint of a server, but you still need to assess quality and security yourself.

Do I need a data processing agreement to use an MCP server?

If personal data will pass through a remote server operated by a third party, that provider is likely a processor under UK GDPR and you should have appropriate contract terms in place. Purely local servers or tools that never see personal data raise fewer questions. Check with your data protection lead.

How do I protect against prompt injection with MCP?

Choose servers that mark returned content as untrusted, keep write and send tools behind confirmation, avoid combining untrusted readers with powerful actions in the same session, and use restricted keys so any mistake has limited reach.

How many MCP servers should I connect?

As few as you need. Every server adds tool descriptions to the model's context, which can reduce accuracy when the assistant chooses a tool. A handful of well-chosen servers is usually more effective than dozens.

Get the Kopik newsletter

New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.

By subscribing you agree to receive our newsletter. We never share your address.