Model Context Protocol

MCP server directory

86 public MCP servers, each checked by Merlonix with a real Model Context Protocol handshake — not just a ping. See the transport, protocol version, authentication posture, callable tool inventory, and an A–F security-posture grade for each.

Last checked at Sep 11, 2026, 08:30 AM UTC. These are point-in-time observations, not real-time — re-check any server live.

Independent directory maintained by Merlonix. Not affiliated with, endorsed by, or operated by the listed vendors. Each health check is Merlonix’s own point-in-time observation of a public endpoint; vendor names are used nominatively to describe what we checked. 11 of these servers expose their tools without authentication; the rest are live but gated behind a credential.

Dev & code

Buildkite

Auth required

Buildkite’s server for pipelines, builds, and test results. Requires authentication.

HTTPPosture A

Cloudflare Container Sandbox

Auth required

Cloudflare’s server for spinning up sandboxed development environments in containers. Requires authentication.

HTTPPosture A

Cloudflare Workers Bindings

Auth required

Cloudflare’s server for building Workers with storage, AI, and compute bindings. Requires authentication.

HTTPPosture A

GitHub

Auth required

GitHub’s official remote MCP server: repositories, issues, pull requests, code search, and Actions. Needs a GitHub credential.

HTTPPosture A

GitLab

Auth required

GitLab’s official server for projects, issues, merge requests, and CI on gitlab.com. Requires a GitLab credential.

HTTPPosture A

HashiCorp Terraform

Auth required

HashiCorp’s Terraform server for registry providers, modules, and infrastructure-as-code context. Requires authentication.

HTTPPosture A

Heroku

Auth required

Heroku’s server for apps, dynos, and add-ons. Requires authentication.

HTTPPosture A

Postman

Auth required

Postman’s server for collections, workspaces, and APIs. Requires authentication.

HTTPPosture A

Railway

Auth required

Railway’s server for projects, services, and deployments on its app platform. Requires authentication.

HTTPPosture A

Render

Auth required

Render’s server for services, deploys, and databases on its cloud platform. Requires authentication.

HTTPPosture A

Vercel

Auth required

Vercel’s official server for projects, deployments, and documentation. Requires authentication.

HTTPPosture A

Web & data

Alchemy

Auth required

Alchemy’s server for blockchain APIs and onchain data. Requires authentication.

HTTPPosture A

Apify

Auth required

Apify’s server exposing its marketplace of web scrapers (Actors) to agents. Requires authentication.

HTTPPosture A

Browserbase

Operational

Headless-browser automation for agents (Stagehand), by Browserbase — navigate, extract, and act on real web pages.

HTTP6 toolsPosture A

Cloudflare Browser Rendering

Auth required

Cloudflare’s server for fetching and rendering web pages, taking screenshots, and converting pages to markdown. Requires authentication.

HTTPPosture A

CoinMarketCap

Auth required

CoinMarketCap’s server for cryptocurrency market data. Requires authentication.

HTTP14 toolsPosture A

Exa

Auth required

Neural web search built for AI agents, by Exa. Search the web and get clean, structured results inside an agent session.

HTTPPosture A

Firecrawl

Operational

Web scraping, crawling, search, and structured data extraction for agents, by Mendable. Turns any website into clean, LLM-ready data.

HTTP3 toolsPosture A

Kagi

Auth required

Kagi’s server for its independent search index and summarizer. Requires authentication.

HTTPPosture A

Serpstat

Auth required

Serpstat’s server for SEO data — keywords, rankings, and domain analysis. Requires authentication.

HTTPPosture A

Tavily

Auth required

Web search and extraction built for LLM agents, by Tavily. Requires an API key.

HTTPPosture A

Webflow

Auth required

Webflow’s server for sites, collections, and CMS items. Requires authentication.

HTTPPosture A

Wix

Auth required

Wix’s server for sites, stores, bookings, and data. Requires authentication.

HTTPPosture A

Common questions

How many public MCP servers are live right now?

As of the last sweep (Sep 11, 2026, 08:30 AM UTC), Merlonix reached 86 public Model Context Protocol servers with a real JSON-RPC handshake. 11 of them expose their full tool inventory with no authentication; the rest answered but require a credential for a complete check. These are point-in-time observations — re-verify any server live with the free MCP health checker.

Which public MCP servers work without authentication?

11 servers in this directory answered a full tools/list handshake with no credential at the last sweep. Each server's detail page lists the transport, protocol version, and observed tool inventory; the auth-gated servers are reachable and healthy but need a token before their tools can be listed.

How is this different from other MCP directory sites?

Most MCP directories list a server from a submitted description. Every entry here was reached by an actual Model Context Protocol handshake from Merlonix — transport, protocol version, authentication posture, callable tool inventory, and an A–F security-posture grade are observed, not self-reported. A server that stops answering is marked down rather than left listed as live.

How often is the directory re-checked?

The current sweep is stamped Sep 11, 2026, 08:30 AM UTC, and each entry carries its own last-checked timestamp. The checks are point-in-time snapshots rather than real-time; the live MCP health checker re-runs the same handshake on demand for any single server.

Check any MCP server — free, no signup.

Paste any MCP endpoint and Merlonix opens a real handshake: protocol version, tool inventory, transport, and an A–F security-posture scan. Then monitor it around the clock and catch silent tool-contract drift before it breaks your agents.