Pick any MCP server and the useful question is not "what can it do?" but "who controls it, and what happens when that changes?" Open-source servers let you read and pin the code you run. Hosted, closed servers trade that auditability for zero setup. Both have a place, and the right choice depends on what your agent is allowed to touch.
This ranking covers ten servers, six open source and four closed, chosen for breadth of use among people building with agents. It is an editorial ranking, not a benchmark: we did not measure latency or tool-call accuracy across them. We explain the criteria, what each is good for, and what to check before you connect it.
TL;DR: the ten at a glance
| # | Server | Type | Best for | Main trade-off |
|---|---|---|---|---|
| 1 | GitHub MCP server | Open source | Repos, issues, pull requests | Broad token scope can expose private repos |
| 2 | Playwright MCP | Open source | Browser automation and testing | Page content can carry injected text |
| 3 | Context7 | Open source | Fresh library documentation | Docs content is third-party text |
| 4 | Chrome DevTools MCP | Open source | Debugging and performance in a live browser | Powerful access to a real browser session |
| 5 | Supabase MCP | Open source | Database and project management | Write access to production data |
| 6 | Reference servers (filesystem and others) | Open source | Learning, local tools | Minimal hardening; scope paths tightly |
| 7 | Notion MCP | Closed, hosted | Workspace pages and databases | Everything the token can see is in reach |
| 8 | Vercel MCP | Closed, hosted | Deployments, logs, projects | Large tool surface including destructive actions |
| 9 | Canva MCP | Closed, hosted | Generating and editing designs | Creates and exports on your account |
| 10 | Ahrefs MCP | Closed, hosted | SEO data and research | Metered credits; data-only risk profile |
How did we rank them?
We weighted four things, in this order.
- Usefulness across many agent workflows, not just one niche.
- Maturity and maintenance, meaning an actively maintained official or well-known project.
- Trust profile, including whether the code is inspectable and how much damage a wrong action can do.
- First-hand familiarity. The four closed servers below are ones we have connected in the Claude Code environment we use to run explainx.ai, which is how we know their tool surfaces. For the open-source ones we rely on their public repositories and documentation.
Licenses and feature sets change, so verify in each repository before you depend on them. We do not quote star counts or download figures because they go stale quickly.
The open-source six
1. GitHub MCP server
github/github-mcp-server is GitHub's official server for repositories, issues, pull requests and related workflows. It is the default pick for coding agents because source control is where agent work lands. Scope the access token tightly: a token that can read every private repository is a bigger grant than most tasks need. See our walkthrough on connecting MCP servers in Claude Code.
2. Playwright MCP
microsoft/playwright-mcp lets an agent drive a browser through structured page snapshots instead of screenshots. It is the workhorse for testing flows and scraping behind logins. The risk is the web itself: any page the agent reads can contain text meant to steer it, so treat browser output as untrusted.
3. Context7
upstash/context7 fetches current documentation and code examples for libraries so the model does not rely on stale training data. It is low risk for actions because it mostly reads, but the documentation it injects is third-party text, so the same untrusted-content rule applies.
4. Chrome DevTools MCP
ChromeDevTools/chrome-devtools-mcp gives agents access to DevTools for debugging, network inspection and performance traces in a real browser. It is excellent for diagnosing front-end problems. Because it attaches to a live browser, run it against a clean profile, not the one holding your logged-in accounts.
5. Supabase MCP
supabase-community/supabase-mcp lets an agent inspect and manage database projects. It shows the central tension of agent tooling: the more useful it is, the more it can change. Use it against development projects, prefer read-only modes where available, and never point an unattended agent at production.
6. Reference servers
modelcontextprotocol/servers hosts reference implementations such as filesystem access and other building blocks. They are the best way to learn how servers work and a fine base for local tools, but they are examples, not hardened products. Restrict allowed paths and read the source before you rely on one. If you want to build your own, follow build your first MCP server.
The closed-source four
"Closed" here means hosted by the vendor, with the server implementation not published as far as we can tell. You connect to a URL and authenticate. You get convenience and vendor support; you give up the ability to read or pin the code.
7. Notion MCP
Notion's hosted server exposes search, page and database reads and writes, comments and related actions inside a workspace. It is a strong example of knowledge-work MCP: the agent works where your team's docs and tasks already live. The catch is breadth. Whatever the connected account can see, the agent can reach. Create a limited integration or a dedicated test workspace first.
8. Vercel MCP
Vercel's hosted server covers projects, deployments, logs, domains and configuration, with a very large tool surface. That is useful for debugging a failed deploy or reading runtime logs, and it is also the clearest example here of why tool count matters. Some tools are read-only; others change or delete resources, and a few involve purchases. Review the tool list and keep approval prompts on for anything that mutates state.
9. Canva MCP
Canva's hosted server lets agents search, create, edit and export designs. It is a good illustration of non-developer MCP: marketing and content workflows driven from a chat. Risk is moderate, since actions are mostly creation inside your account, but exports and shared links can publish content, so check what gets shared.
10. Ahrefs MCP
Ahrefs exposes SEO data, keyword research, site audits and rank tracking through MCP. It is read-heavy, so the direct risk is low, but queries consume metered credits, and results can influence decisions, so verify before acting on them. It also shows a pattern worth copying: tool outputs that tell the client how to render data. That is useful, and it is another reason to treat server responses as inputs to be checked, not commands.
Open source versus closed source: which should you pick?
| Factor | Open source (local) | Closed (hosted) |
|---|---|---|
| Audit the code | Yes | No |
| Pin a version | Yes, via package or commit | Not directly; snapshot definitions instead |
| Setup effort | Install, configure | Add a URL, authenticate |
| Where it runs | Your machine or infra | Vendor infrastructure |
| Rug pull exposure | Package or repository compromise | Vendor-side definition changes |
| Maintenance | You update it | Vendor handles it |
| Best for | Code, local data, sensitive work | Business apps, quick wins |
Neither wins outright. A sensible stack uses open-source servers for anything touching your code and local files, and hosted servers for business tools where the vendor is already trusted with the data.
What people are asking
Which MCP server should I install first? For developers, GitHub plus either Playwright or Context7. For non-developers, the hosted server for the app you already live in, such as your notes or design tool.
Can I browse and compare servers in one place? Yes, the explainx.ai MCP registry lists servers with descriptions, and our directory comparison shows where else to look.
How do I use these inside ChatGPT or Claude? See how to use Claude connectors and MCP servers and how to host an MCP server on ChatGPT Sites.
Can servers wake my agent up? With MCP Events, a server can push signed webhooks to ChatGPT; see MCP Events in ChatGPT.
A pre-connect checklist for any server
- Confirm the publisher and the official repository or documentation link.
- Read every tool description for instructions that mention secrets, files or other tools.
- Grant the narrowest scope and use a test account or workspace first.
- Pin the version, or snapshot the hosted tool definitions you approved.
- Scan the configuration and re-scan after updates; explainx.ai plans to offer scanning with AgentBeam, as described in what is an MCP rug pull.
- Keep approval prompts on for writes, deletes, purchases and outbound messages.
- Connect only what the task needs and remove servers you stop using.
Read the full threat model in the MCP security guide and the background in what is MCP.
Honest limitations
This is an editorial list, not a measured benchmark, and the tool surfaces of hosted servers change without notice. We describe the closed servers from our own use and the open-source ones from public documentation; we did not run a fresh security audit of any of them for this post. Check licenses, maintainers and scopes yourself before connecting anything to sensitive systems.
Related reading
- MCP rug pull, tool poisoning and scanners
- MCP security guide 2026
- Top 10 MCP server directories
- Claude Code MCP servers: connect your tools
- Build your first MCP server
- MCP Events in ChatGPT
- Top 10 open and closed source agent harnesses
- What is MCP? The complete guide
Accurate as of October 4, 2026. Servers, licenses and tool lists change often; verify before use.
