[{"data":1,"prerenderedAt":725},["ShallowReactive",2],{"tool-mcp-reference-servers-en":3},{"slug":4,"published":5,"minutes":6,"category":7,"tags":8,"keywords":13,"about":20,"sources":24,"cover":61,"og":62,"expertise":63,"locales":64,"lang":65,"title":68,"description":69,"coverAlt":70,"url":27,"pricing":71,"kind":72,"metaTitle":73,"takeaways":74,"faq":80,"toc":93,"blocks":118,"others":507},"mcp-reference-servers","2026-09-25",9,"agents",[9,10,11,12],"MCP","Reference servers","Tool protocol","Server SDKs",[14,15,16,17,18,19],"mcp reference servers","modelcontextprotocol servers github","write an mcp server","mcp server examples","mcp server sdk","mcp server security",[21],{"name":22,"url":23},"Model Context Protocol","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FModel_Context_Protocol",[25,28,31,34,37,40,43,46,49,52,55,58],{"title":26,"url":27},"MCP reference servers repository","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers",{"title":29,"url":30},"Repository README and server list","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002FREADME.md",{"title":32,"url":33},"Security policy","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002FSECURITY.md",{"title":35,"url":36},"Release process and trusted publishing","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002FRELEASING.md",{"title":38,"url":39},"Filesystem server README","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002Fsrc\u002Ffilesystem\u002FREADME.md",{"title":41,"url":42},"Everything server feature list","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002Fsrc\u002Feverything\u002Fdocs\u002Ffeatures.md",{"title":44,"url":45},"MCP Registry","https:\u002F\u002Fregistry.modelcontextprotocol.io\u002F",{"title":47,"url":48},"Archived reference servers","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers-archived",{"title":50,"url":51},"Model Context Protocol documentation","https:\u002F\u002Fmodelcontextprotocol.io\u002F",{"title":53,"url":54},"TypeScript MCP SDK","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Ftypescript-sdk",{"title":56,"url":57},"Python MCP SDK","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fpython-sdk",{"title":59,"url":60},"FastMCP on PyPI","https:\u002F\u002Fpypi.org\u002Fproject\u002Ffastmcp\u002F","\u002Fimages\u002Fblog\u002Fmcp-reference-servers\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fmcp-reference-servers\u002Fog.jpg","ai-engineer",[65,66,67],"en","de","hu","MCP reference servers: what they demonstrate and what they omit","A review of modelcontextprotocol\u002Fservers: seven reference servers, what each one teaches, the SDK versions behind them and why none of them should reach production.","Seven reference servers fanning out from a single MCP client over stdio","MIT","Protocol tooling","MCP reference servers: what they demonstrate · Balázs Csorba",[75,76,77,78,79],"Seven reference servers sit in src\u002F, four in TypeScript and three in Python, and the README calls them educational examples rather than production code.","The Python servers still require mcp >=1.29.0 and \u003C2 while the Python SDK has been at 2.3.0 since 2 October 2026, so copying them teaches the 1.x API.","The repository is out of scope for vulnerability reports: SECURITY.md sends findings to the SDK repositories instead.","Packages are published from CI with OIDC trusted publishing and provenance attestations, with no registry tokens anywhere in the release path.","The filesystem server's path allowlist is the only sandbox in the collection, and the client can replace it at runtime through Roots.",[81,84,87,90],{"q":82,"a":83},"Are the MCP reference servers safe to run in production?","No, and the repository says so itself. The README calls them educational examples that are not production-ready, and SECURITY.md states that the repository is not eligible for vulnerability reporting at all. Run them locally to learn or to test a client, and put a maintained server behind any real account.",{"q":85,"a":86},"Which reference server should I read first?","Filesystem if access control is the question, because its directory allowlist and Roots handling are the most reusable design in the collection. Everything if the question is what the protocol can do: it implements sampling, elicitation, progress, structured output and tasks alongside the three core primitives.",{"q":88,"a":89},"Where did the GitHub, Slack and PostgreSQL servers go?","To modelcontextprotocol\u002Fservers-archived. Thirteen servers were retired from the reference collection; Brave Search was replaced by a server Brave maintains itself, and the Slack server is now maintained by Zencoder.",{"q":91,"a":92},"How is this repository different from the MCP Registry?","The registry is a catalogue of published servers that anyone can register, so it is where a reader looks for a server to run. This repository holds only the seven implementations kept by the MCP steering group, and the README points registry visitors away from it.",[94,97,100,103,106,109,112,115],{"id":95,"title":96},"what-it-is","What it is",{"id":98,"title":99},"repository-layout","The repository, server by server",{"id":101,"title":102},"how-it-works","How a server actually runs",{"id":104,"title":105},"getting-started","Getting started",{"id":107,"title":108},"security-posture","Security posture",{"id":110,"title":111},"where-it-shingles","Where it falls short",{"id":113,"title":114},"verdict","Verdict",{"id":116,"title":117},"sources","Sources",[119,123,126,129,145,163,164,170,240,243,247,250,296,299,300,303,312,315,316,319,321,336,338,357,358,361,373,395,396,399,443,446,447,450,463,467,468],{"type":120,"content":121},"paragraph",[122],"modelcontextprotocol\u002Fservers is the reference collection for the Model Context Protocol: seven small servers kept by the MCP steering group, each written to demonstrate one part of the protocol rather than to do a job well. Read as a product it is teaching material with an unusually candid README, and the position taken here is that it should be read and run locally but never deployed: the repository states outright that the servers are not production-ready, and its security policy refuses vulnerability reports against it. What it does well is show exactly what a server has to implement, in working code, from the people who wrote the specification.",{"type":120,"content":124},[125],"It sits between the specification on modelcontextprotocol.io and the ten official SDKs, and it does not compete with the MCP Registry, where published servers for actual use are listed. Nothing here replaces a search index, a browser tool or a ticketing integration. The collection replaced an earlier grab-bag of one-off examples, most of which now live in a separate archive repository and still turn up in old tutorials.",{"type":127,"level":128,"id":95,"text":96},"heading",2,{"type":120,"content":130},[131,132,136,137,140,141,144],"One npm workspace holding seven packages under ",{"tag":133,"children":134},"code",[135],"src\u002F",", published on npm as ",{"tag":133,"children":138},[139],"@modelcontextprotocol\u002Fserver-*"," and on PyPI as ",{"tag":133,"children":142},[143],"mcp-server-*",". Four servers are TypeScript and three are Python, and each isolates a different protocol feature: access control, prompts and resources, a knowledge graph, a tool that rewrites its own output, web retrieval, repository operations, time zones.",{"type":146,"ordered":147,"items":148},"list",false,[149,151,153,155,157,159,161],[150],"About 91,100 stars and 11,800 forks in early October 2026, with 4,194 commits on main.",[152],"Seven reference servers in src\u002F: everything, fetch, filesystem, git, memory, sequentialthinking and time.",[154],"Thirteen retired servers, including GitHub, Slack, PostgreSQL, SQLite, Puppeteer and Brave Search, moved to servers-archived; the Brave one was replaced by a server Brave maintains itself.",[156],"The README now sends anyone looking for a server to the MCP Registry and keeps the repository for the reference implementations only.",[158],"Licence is Apache-2.0 for new contributions with earlier code still under MIT, as the LICENSE file explains.",[160],"Server packages use calendar versions: 2026.8.31 for the TypeScript packages, 2026.8.18 for the Python ones.",[162],"Packages are published from a gated CI workflow by OIDC trusted publishing with provenance attestations, and the release path contains no registry tokens.",{"type":127,"level":128,"id":98,"text":99},{"type":120,"content":165},[166,167,169],"The layout is deliberately flat: one directory per server under ",{"tag":133,"children":168},[135],", a root package.json that wires them up as npm workspaces, and a handful of operational documents at the top level. Reading a single server directory from top to bottom is the fastest way to learn the protocol, because each one is small enough to finish in one sitting.",{"type":171,"head":172,"rows":181},"table",[173,175,177,179],[174],"Server",[176],"Language",[178],"What it demonstrates",[180],"Published as",[182,191,200,208,216,224,232],[183,185,187,189],[184],"everything",[186],"TypeScript",[188],"Prompts, tools, resources, sampling, elicitation, progress, logging and tasks",[190],"@modelcontextprotocol\u002Fserver-everything",[192,194,196,198],[193],"fetch",[195],"Python",[197],"URL retrieval, readability extraction, markdown conversion, robots.txt",[199],"mcp-server-fetch",[201,203,204,206],[202],"filesystem",[186],[205],"Path allowlisting and directory control through Roots",[207],"@modelcontextprotocol\u002Fserver-filesystem",[209,211,212,214],[210],"git",[195],[213],"Twelve repository tools: status, diff, log, commit, branch, show",[215],"mcp-server-git",[217,219,220,222],[218],"memory",[186],[221],"Entities, relations and observations held as a knowledge graph",[223],"@modelcontextprotocol\u002Fserver-memory",[225,227,228,230],[226],"sequentialthinking",[186],[229],"One tool that revises earlier steps in its own reasoning",[231],"@modelcontextprotocol\u002Fserver-sequential-thinking",[233,235,236,238],[234],"time",[195],[237],"get_current_time and convert_time across IANA zones",[239],"mcp-server-time",{"type":120,"content":241},[242],"Beside src\u002F, the root holds ADDITIONAL.md for community frameworks and clients, RELEASING.md for how packages reach the registries, SECURITY.md, CLAUDE.md, a .mcp.json used by the repository's own tooling, and a scripts directory. The everything server is the exception to the flatness: it carries a docs directory with architecture, feature and extension-point notes, and it behaves more like a protocol conformance fixture than like a template.",{"type":127,"level":244,"id":245,"text":246},3,"sdks-and-languages","SDKs and language versions",{"type":120,"content":248},[249],"The README lists ten official SDKs — C#, Go, Java, Kotlin, PHP, Python, Ruby, Rust, Swift and TypeScript — and states that the reference servers are built on them. In practice the TypeScript packages are current while the Python packages sit one major version behind, and the time server's README says so in a single line.",{"type":171,"head":251,"rows":260},[252,254,256,258],[253],"Package",[255],"Version",[257],"Published",[259],"Constraint",[261,270,279,287],[262,264,266,268],[263],"@modelcontextprotocol\u002Fsdk, TypeScript",[265],"1.32.1",[267],"5 October 2026",[269],"Server packages pin it as ^1.x",[271,273,275,277],[272],"mcp, Python",[274],"2.3.0",[276],"2 October 2026",[278],"The Python servers require \u003C2",[280,281,283,285],[223],[282],"2026.8.31",[284],"31 August 2026",[286],"@modelcontextprotocol\u002Fsdk ^1.30.0",[288,290,292,294],[289],"mcp-server-git, fetch and time",[291],"2026.8.18",[293],"18 August 2026",[295],"mcp >=1.29.0 and \u003C2",{"type":120,"content":297},[298],"The time server documents the reason for the gap plainly: SDK 2.0 renamed the APIs it uses and the port is in progress. That is the honest cost of a reference collection — the examples track the specification closely, and the Python half tracks the SDK majors less closely. Anyone copying a Python server today is reading working code written against the 1.x API, which is fine for study and a trap for new work.",{"type":127,"level":128,"id":101,"text":102},{"type":120,"content":301},[302],"A client configured with a stdio server spawns it as a child process at startup and speaks newline-delimited JSON-RPC over stdin and stdout. Nothing listens on a port. During the initialize handshake both sides declare capabilities: the server announces which tools, resources and prompts it implements, the client announces whether it accepts roots, sampling and elicitation, and everything after that is a request, a response or a notification.",{"type":304,"attrs":305,"inner":309,"caption":310},"diagram",{"viewBox":306,"role":307,"aria-labelledby":308},"0 0 720 400","img","d-mrs-t d-mrs-d","\u003Ctitle id=\"d-mrs-t\">How a reference server runs\u003C\u002Ftitle>\u003Cdesc id=\"d-mrs-d\">At the top a box holds the MCP client, such as Claude Desktop, an IDE or an agent. A solid arrow labelled initialize and then JSON-RPC over stdio points down to a wide box for the reference server, a child process started from an npm or PyPI package. A dashed arrow returns from the server to the client, labelled roots and list_changed, because the client supplies the directory allowlist. Three boxes hang below the server: tools, which the model calls; resources, which the application reads at a URI; and prompts, which the user picks. A band at the bottom states that the process runs with the privileges of the user who started it and that the allowlist is a path check rather than a sandbox.\u003C\u002Fdesc>\u003Cdefs>\u003Cmarker id=\"mrs-arrow\" viewBox=\"0 0 10 10\" refX=\"9\" refY=\"5\" markerWidth=\"7\" markerHeight=\"7\" orient=\"auto-start-reverse\">\u003Cpath d=\"M0 0L10 5L0 10z\" class=\"d-head\" \u002F>\u003C\u002Fmarker>\u003C\u002Fdefs>\u003Ctext x=\"20\" y=\"26\" class=\"d-title\">How a reference server runs\u003C\u002Ftext>\u003Ctext x=\"700\" y=\"26\" text-anchor=\"end\" class=\"d-label\">stdio subprocess, no open port\u003C\u002Ftext>\u003Crect x=\"250\" y=\"44\" width=\"220\" height=\"54\" rx=\"10\" class=\"d-accent\" \u002F>\u003Ctext x=\"360\" y=\"66\" text-anchor=\"middle\" class=\"d-text\">MCP client\u003C\u002Ftext>\u003Ctext x=\"360\" y=\"86\" text-anchor=\"middle\" class=\"d-small\">Claude Desktop, IDE, agent\u003C\u002Ftext>\u003Cpath d=\"M360 98 V136\" class=\"d-line\" marker-end=\"url(#mrs-arrow)\" \u002F>\u003Ctext x=\"374\" y=\"114\" class=\"d-label\">initialize, then\u003C\u002Ftext>\u003Ctext x=\"374\" y=\"130\" class=\"d-label\">JSON-RPC over stdio\u003C\u002Ftext>\u003Cpath d=\"M570 172 H636 V71 H474\" class=\"d-line d-dash\" marker-end=\"url(#mrs-arrow)\" \u002F>\u003Ctext x=\"644\" y=\"118\" class=\"d-label\">roots\u002Flist\u003C\u002Ftext>\u003Ctext x=\"644\" y=\"134\" class=\"d-label\">list_changed\u003C\u002Ftext>\u003Crect x=\"150\" y=\"140\" width=\"420\" height=\"64\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"360\" y=\"166\" text-anchor=\"middle\" class=\"d-text\">Reference server\u003C\u002Ftext>\u003Ctext x=\"360\" y=\"188\" text-anchor=\"middle\" class=\"d-small\">child process from an npm or PyPI package\u003C\u002Ftext>\u003Cpath d=\"M360 204 V224\" class=\"d-line\" \u002F>\u003Cpath d=\"M126 224 H594\" class=\"d-line\" \u002F>\u003Cpath d=\"M126 224 V236\" class=\"d-line\" marker-end=\"url(#mrs-arrow)\" \u002F>\u003Cpath d=\"M360 224 V236\" class=\"d-line\" marker-end=\"url(#mrs-arrow)\" \u002F>\u003Cpath d=\"M594 224 V236\" class=\"d-line\" marker-end=\"url(#mrs-arrow)\" \u002F>\u003Crect x=\"20\" y=\"240\" width=\"213\" height=\"100\" rx=\"10\" class=\"d-sky\" \u002F>\u003Ctext x=\"126\" y=\"266\" text-anchor=\"middle\" class=\"d-text\">tools\u003C\u002Ftext>\u003Ctext x=\"126\" y=\"290\" text-anchor=\"middle\" class=\"d-small\">the model calls them\u003C\u002Ftext>\u003Ctext x=\"126\" y=\"310\" text-anchor=\"middle\" class=\"d-small\">filesystem: read and write\u003C\u002Ftext>\u003Ctext x=\"126\" y=\"330\" text-anchor=\"middle\" class=\"d-small\">git: twelve operations\u003C\u002Ftext>\u003Crect x=\"253\" y=\"240\" width=\"214\" height=\"100\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"360\" y=\"266\" text-anchor=\"middle\" class=\"d-text\">resources\u003C\u002Ftext>\u003Ctext x=\"360\" y=\"290\" text-anchor=\"middle\" class=\"d-small\">the application reads them\u003C\u002Ftext>\u003Ctext x=\"360\" y=\"310\" text-anchor=\"middle\" class=\"d-small\">memory:\u002F\u002Fknowledge-graph\u003C\u002Ftext>\u003Ctext x=\"360\" y=\"330\" text-anchor=\"middle\" class=\"d-small\">addressed by URI\u003C\u002Ftext>\u003Crect x=\"486\" y=\"240\" width=\"214\" height=\"100\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"593\" y=\"266\" text-anchor=\"middle\" class=\"d-text\">prompts\u003C\u002Ftext>\u003Ctext x=\"593\" y=\"290\" text-anchor=\"middle\" class=\"d-small\">the user picks them\u003C\u002Ftext>\u003Ctext x=\"593\" y=\"310\" text-anchor=\"middle\" class=\"d-small\">templates with arguments\u003C\u002Ftext>\u003Ctext x=\"593\" y=\"330\" text-anchor=\"middle\" class=\"d-small\">everything: four prompts\u003C\u002Ftext>\u003Crect x=\"20\" y=\"356\" width=\"680\" height=\"30\" rx=\"8\" class=\"d-gold\" \u002F>\u003Ctext x=\"360\" y=\"376\" text-anchor=\"middle\" class=\"d-small\">runs with the invoking user's privileges, and the allowlist is a path check, not a sandbox\u003C\u002Ftext>",[311],"Capability negotiation at initialize decides what each side may ask for; the three primitives below are what the model and the application actually see.",{"type":120,"content":313},[314],"The three primitives are not interchangeable. A tool is something the model decides to call, a resource is something exposed at a URI for the application or the user, and a prompt is a template the user selects. The everything server implements all three plus sampling, elicitation, progress notifications, structured tool output and the newer task extension, which makes it the one directory worth reading when a protocol feature is unclear.",{"type":127,"level":128,"id":104,"text":105},{"type":120,"content":317},[318],"Nothing needs compiling. A server is a package on npm or PyPI, and the configuration below is the whole installation: the client runs the command, the command answers over stdout, and the model is handed a tool list.",{"type":133,"code":320},"{\n  \"mcpServers\": {\n    \"filesystem\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@modelcontextprotocol\u002Fserver-filesystem\", \"\u002Fpath\u002Fto\u002Fallowed\u002Ffiles\"]\n    },\n    \"git\": {\n      \"command\": \"uvx\",\n      \"args\": [\"mcp-server-git\", \"--repository\", \"\u002Fpath\u002Fto\u002Frepo\"]\n    },\n    \"memory\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@modelcontextprotocol\u002Fserver-memory\"]\n    }\n  }\n}",{"type":120,"content":322},[323,324,327,328,331,332,335],"Writing one is not much harder. The TypeScript SDK exposes a server object with ",{"tag":133,"children":325},[326],"registerTool",", ",{"tag":133,"children":329},[330],"registerResource"," and ",{"tag":133,"children":333},[334],"registerPrompt",", plus one transport. The snippet below is a complete server with a single tool, and it is the same shape as the filesystem and memory examples.",{"type":133,"code":337},"import { readFile } from \"node:fs\u002Fpromises\";\nimport { McpServer } from \"@modelcontextprotocol\u002Fsdk\u002Fserver\u002Fmcp.js\";\nimport { StdioServerTransport } from \"@modelcontextprotocol\u002Fsdk\u002Fserver\u002Fstdio.js\";\nimport { z } from \"zod\";\n\nconst server = new McpServer({ name: \"wordcount\", version: \"0.1.0\" });\n\nserver.registerTool(\n  \"count_words\",\n  {\n    title: \"Count words\",\n    description: \"Count the words in a UTF-8 text file\",\n    inputSchema: { path: z.string() },\n  },\n  async ({ path }) => {\n    const words = (await readFile(path, \"utf8\")).split(\u002F\\s+\u002F).filter(Boolean).length;\n    return { content: [{ type: \"text\", text: String(words) }] };\n  },\n);\n\nawait server.connect(new StdioServerTransport());",{"type":339,"variant":340,"title":341,"body":342},"callout","warn","Pin the package before you trust it",[343],[344,345,348,349,352,353,356],"Every documented example uses ",{"tag":133,"children":346},[347],"npx -y"," or ",{"tag":133,"children":350},[351],"uvx",", which resolve the newest version on each start: the code that runs is whatever the registry served that morning. Pin the version, read the changelog when you bump it, and remember that a stdio server executes as your own user with access to whatever the allowlist admits. Windows needs ",{"tag":133,"children":354},[355],"cmd \u002Fc npx"," in front of the same command.",{"type":127,"level":128,"id":107,"text":108},{"type":120,"content":359},[360],"The collection is unusually explicit about what it is not. The README's warning block says the servers demonstrate features and SDK usage, that developers should evaluate their own security requirements, and that the servers are not production-ready. SECURITY.md then states that the repository is not eligible for vulnerability reporting at all, which is the clearest signal of the intended status: the SDKs are supported, the examples are not.",{"type":146,"ordered":147,"items":362},[363,365,367,369,371],[364],"Every server is a local child process holding the privileges of the user who started it, so a model's tool calls become file, network and repository operations inside that account.",[366],"The filesystem server is the only one with an access-control story: a directory allowlist set from command-line arguments or replaced at runtime by the client through Roots, and a path check is not a process sandbox.",[368],"The fetch server converts pages to markdown, respects robots.txt and exposes a configurable user-agent and proxy, which is as far as the collection goes on outbound network hygiene.",[370],"Memory persists a knowledge graph to a local JSON file with no authentication, and git writes to whichever repository path it is given; neither is meant to face a network.",[372],"Releases are manual workflow dispatch into a gated GitHub environment with a required reviewer, published to npm and PyPI with provenance attestations and without registry tokens.",{"type":339,"variant":374,"title":375,"body":376},"note","Before a server reaches a real account",[377],[378,379,384,385,389,390,394],"Read ",{"tag":380,"to":381,"children":382},"link","\u002Fblog\u002Fmcp-server-security-checklist",[383],"the MCP server security checklist"," first, then take the tool-design lessons from ",{"tag":380,"to":386,"children":387},"\u002Fblog\u002Fmcp-tool-design-lessons-jira-server",[388],"the Jira server write-up"," as the tools you copy start to grow. Transport is a separate question: the stateless pattern in ",{"tag":380,"to":391,"children":392},"\u002Fblog\u002Fmcp-2026-07-28-stateless-migration-guide",[393],"the stateless migration guide"," matters once a server leaves stdio.",{"type":127,"level":128,"id":110,"text":111},{"type":120,"content":397},[398],"Seven servers is a small sample and none of them is a service. There is no authentication model to copy, because stdio is local by construction and the HTTP routes in the everything server are development transports; there is no rate limiting, no support statement, no deployment story beyond a docker run in a README. The archived servers are still linked from years of tutorials, so a reader following an old guide can land in a repository that was deliberately moved. And the Python half of the collection lags the SDK it is supposed to demonstrate.",{"type":171,"head":400,"rows":408},[401,403,404,406],[402],"Option",[96],[405],"Support",[407],"Right for",[409,417,426,434],[410,411,413,415],[10],[412],"Seven steering-group examples under src\u002F",[414],"Community and the MCP steering group, with no vulnerability intake",[416],"Learning the protocol and writing your own server",[418,420,422,424],[419],"servers-archived",[421],"Thirteen retired examples, among them GitHub, Slack and PostgreSQL",[423],"Unmaintained here; Brave and Slack moved to their vendors",[425],"Reading history, not new configurations",[427,428,430,432],[44],[429],"Catalogue of published servers at registry.modelcontextprotocol.io",[431],"Per-server authors, with registration required",[433],"Finding a server to actually run",[435,437,439,441],[436],"FastMCP",[438],"Python framework for servers and clients, 4.0.11 on PyPI",[440],"The package maintainer",[442],"Shipping a server without touching protocol plumbing",{"type":120,"content":444},[445],"The honest comparison is not which of these four wins, but what each teaches. A framework gets a server running faster and hides the parts that change between specification versions. The registry gives you code somebody else wrote, with whatever review that author did. The reference servers are the only option where the source was written by the people who wrote the specification, and that is exactly why they are worth reading and not worth shipping.",{"type":127,"level":128,"id":113,"text":114},{"type":120,"content":448},[449],"Use it as documentation that executes. Recommended for anyone building an MCP server, for anyone auditing one, and for anyone who wants to see how tools, resources and sampling appear on the wire; not recommended as a base repository, as a source of production tools, or as a list of servers to add to a client.",{"type":146,"ordered":451,"items":452},true,[453,455,457,459,461],[454],"Read src\u002F before writing a server: filesystem for access control, everything for the full protocol surface, memory for a non-trivial tool design.",[456],"Run the reference servers locally to learn the protocol or to test a client, and treat their tool lists as fixtures rather than as a product.",[458],"Pin package versions in any configuration you keep, instead of the -y flag the README examples use.",[460],"Do not deploy a reference server to a shared account: no authentication, no rate limits and no vulnerability intake.",[462],"Send protocol findings to the SDK repositories, and use the registry rather than this repository when the goal is a server to run.",{"type":464,"content":465},"quote",[466],"The servers in this repository are intended as reference implementations to demonstrate MCP features and SDK usage. They are meant to serve as educational examples for developers building their own MCP servers, not as production-ready solutions.",{"type":127,"level":128,"id":116,"text":117},{"type":146,"ordered":451,"items":469},[470,474,477,480,483,486,489,492,495,498,501,504],[471],{"tag":472,"href":27,"children":473},"a",[26],[475],{"tag":472,"href":30,"children":476},[29],[478],{"tag":472,"href":33,"children":479},[32],[481],{"tag":472,"href":36,"children":482},[35],[484],{"tag":472,"href":39,"children":485},[38],[487],{"tag":472,"href":42,"children":488},[41],[490],{"tag":472,"href":45,"children":491},[44],[493],{"tag":472,"href":48,"children":494},[47],[496],{"tag":472,"href":51,"children":497},[50],[499],{"tag":472,"href":54,"children":500},[53],[502],{"tag":472,"href":57,"children":503},[56],[505],{"tag":472,"href":60,"children":506},[59],[508,558,623,677],{"slug":509,"published":510,"minutes":511,"category":7,"tags":512,"keywords":518,"about":526,"sources":533,"cover":550,"og":551,"expertise":63,"locales":552,"lang":65,"title":553,"description":554,"coverAlt":555,"url":556,"pricing":557,"kind":513},"aider","2026-09-23",10,[513,514,515,516,517],"Coding agent","Terminal","Git workflow","BYO key","Open source",[509,519,520,521,522,523,524,525],"aider vs claude code","aider polyglot benchmark","ai pair programming terminal","aider leaderboard","open source coding agent","aider architect mode","aider install",[527,530],{"name":528,"url":529},"Aider","https:\u002F\u002Faider.chat\u002F",{"name":531,"url":532},"Aider on GitHub","https:\u002F\u002Fgithub.com\u002FAider-AI\u002Faider",[534,536,539,542,545,547],{"title":535,"url":529},"Aider website",{"title":537,"url":538},"Aider LLM leaderboards","https:\u002F\u002Faider.chat\u002Fdocs\u002Fleaderboards\u002F",{"title":540,"url":541},"Aider linting and testing","https:\u002F\u002Faider.chat\u002Fdocs\u002Fusage\u002Flint-test.html",{"title":543,"url":544},"Aider token limits","https:\u002F\u002Faider.chat\u002Fdocs\u002Ftroubleshooting\u002Ftoken-limits.html",{"title":546,"url":532},"Aider repository on GitHub",{"title":548,"url":549},"aider-chat on PyPI","https:\u002F\u002Fpypi.org\u002Fproject\u002Faider-chat\u002F","\u002Fimages\u002Fblog\u002Faider\u002Fcover.webp","\u002Fimages\u002Fblog\u002Faider\u002Fog.jpg",[65,66,67],"Aider review: git-first pair programming in the terminal","A review of Aider 0.86.2, an Apache-2.0 terminal pair programmer whose benchmark ranks models honestly and whose release cadence has stopped.","Cover art for the Aider review: a terminal session turning a single request into a row of git commits","https:\u002F\u002Faider.chat","Free · BYO API key",{"slug":559,"published":560,"minutes":511,"category":7,"tags":561,"keywords":565,"about":574,"sources":584,"cover":615,"og":616,"expertise":63,"locales":617,"lang":65,"title":618,"description":619,"coverAlt":620,"url":587,"pricing":621,"kind":622},"openai-agents-sdk","2026-09-11",[562,563,564,9,195],"Agent runtime","Tracing","Guardrails",[566,567,568,569,570,571,572,573],"openai agents sdk","openai agents sdk vs langgraph","python agent framework comparison","openai agents sdk guardrails","agent run tracing tool calls","openai agents sdk human in the loop","openai-agents pypi","agents sdk vs responses api",[575,578,581],{"name":576,"url":577},"Model context protocol","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FModel_context_protocol",{"name":579,"url":580},"Software framework","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FSoftware_framework",{"name":582,"url":583},"Agentic AI","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FAgentic_AI",[585,588,591,594,597,600,603,606,609,612],{"title":586,"url":587},"OpenAI Agents SDK documentation: Intro, and Agents SDK or Responses API","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002F",{"title":589,"url":590},"OpenAI Agents SDK documentation: Running agents","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Frunning_agents\u002F",{"title":592,"url":593},"OpenAI Agents SDK documentation: Guardrails","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Fguardrails\u002F",{"title":595,"url":596},"OpenAI Agents SDK documentation: Human-in-the-loop","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Fhuman_in_the_loop\u002F",{"title":598,"url":599},"OpenAI Agents SDK documentation: Tracing","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Ftracing\u002F",{"title":601,"url":602},"OpenAI Agents SDK documentation: Configuration","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Fconfig\u002F",{"title":604,"url":605},"openai-agents 0.23.1 on PyPI, release history and licence","https:\u002F\u002Fpypi.org\u002Fproject\u002Fopenai-agents\u002F",{"title":607,"url":608},"OpenAI: The next evolution of the Agents SDK (15 April 2026)","https:\u002F\u002Fopenai.com\u002Findex\u002Fthe-next-evolution-of-the-agents-sdk\u002F",{"title":610,"url":611},"OpenAI API documentation: Agents, comparison of the three runtimes","https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents",{"title":613,"url":614},"Arize: AI agent frameworks compared (1 October 2026)","https:\u002F\u002Farize.com\u002Fai-agents\u002Fagent-frameworks\u002F","\u002Fimages\u002Fblog\u002Fopenai-agents-sdk\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fopenai-agents-sdk\u002Fog.jpg",[65,66,67],"OpenAI Agents SDK: a small agent runtime with sharp edges","A review of the OpenAI Agents SDK: the runner loop, tracing, guardrails and approvals, plus what the release churn and the Responses-only features cost.","Diagram of the Agents SDK runner loop: input, agent, model call, final output, guardrails, and tool calls feeding back into the input","MIT · API pay per token","Agent framework",{"slug":624,"published":625,"minutes":6,"category":7,"tags":626,"keywords":631,"about":638,"sources":648,"cover":669,"og":670,"expertise":63,"locales":671,"lang":65,"title":672,"description":673,"coverAlt":674,"url":675,"pricing":676,"kind":513},"openhands","2026-09-09",[513,627,628,629,630],"Sandboxed execution","Automations","Self-hosted","MIT licence",[624,632,633,634,635,636,523,637],"openhands self-host","open hands coding agent","openhands vs claude code","agent canvas","openhands docker sandbox","openhands cloud pricing",[639,642,645],{"name":640,"url":641},"OpenHands","https:\u002F\u002Fwww.openhands.dev",{"name":643,"url":644},"OpenHands on GitHub","https:\u002F\u002Fgithub.com\u002FOpenHands\u002FOpenHands",{"name":646,"url":647},"Intelligent agent","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FIntelligent_agent",[649,651,654,657,660,663,666],{"title":650,"url":644},"OpenHands README",{"title":652,"url":653},"OpenHands licence (MIT)","https:\u002F\u002Fgithub.com\u002FOpenHands\u002FOpenHands\u002Fblob\u002Fmain\u002FLICENSE",{"title":655,"url":656},"Agent Canvas 1.25.0 release notes","https:\u002F\u002Fdocs.openhands.dev\u002Fopenhands\u002Fusage\u002Fagent-canvas\u002Frelease-notes\u002Fv1.25.0.md",{"title":658,"url":659},"OpenHands sandbox overview","https:\u002F\u002Fdocs.openhands.dev\u002Fopenhands\u002Fusage\u002Fsandboxes\u002Foverview.md",{"title":661,"url":662},"OpenHands quick start","https:\u002F\u002Fdocs.openhands.dev\u002Fopenhands\u002Fusage\u002Finstallation",{"title":664,"url":665},"OpenHands pricing","https:\u002F\u002Fwww.openhands.dev\u002Fpricing",{"title":667,"url":668},"Introducing the OpenHands Index","https:\u002F\u002Fwww.openhands.dev\u002Fblog\u002Fintroducing-the-openhands-index","\u002Fimages\u002Fblog\u002Fopenhands\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fopenhands\u002Fog.jpg",[65,66,67],"OpenHands: the open-source coding agent you operate","OpenHands 1.25.0 is an MIT-licensed coding agent platform with a web canvas, a CLI, sandboxed execution and scheduled automations. A review of where it is strong and where it gets heavy.","Cover artwork for the OpenHands review showing a loop from task to agent to sandboxed run and back","https:\u002F\u002Fgithub.com\u002FAll-Hands-AI\u002FOpenHands","Free · self-host",{"slug":678,"published":679,"minutes":511,"category":7,"tags":680,"keywords":685,"about":692,"sources":696,"cover":718,"og":719,"expertise":63,"locales":720,"lang":65,"title":721,"description":722,"coverAlt":723,"url":695,"pricing":724,"kind":681},"cursor","2026-09-02",[681,682,683,684,9],"AI code editor","Coding agents","CLI","Usage-based pricing",[678,686,687,688,689,690,691],"cursor vs github copilot","cursor pricing","cursor cli","ai code editor","cursor usage limits","cursor pro plus",[693],{"name":694,"url":695},"Cursor","https:\u002F\u002Fcursor.com",[697,700,703,706,709,712,715],{"title":698,"url":699},"Cursor pricing","https:\u002F\u002Fcursor.com\u002Fpricing",{"title":701,"url":702},"Cursor models and pricing docs","https:\u002F\u002Fcursor.com\u002Fdocs\u002Fmodels-and-pricing",{"title":704,"url":705},"Cursor CLI documentation","https:\u002F\u002Fcursor.com\u002Fdocs\u002Fcli\u002Foverview",{"title":707,"url":708},"GitHub Copilot plans","https:\u002F\u002Fgithub.com\u002Ffeatures\u002Fcopilot\u002Fplans",{"title":710,"url":711},"Claude pricing","https:\u002F\u002Fclaude.com\u002Fpricing",{"title":713,"url":714},"Claude Code cost documentation","https:\u002F\u002Fdocs.claude.com\u002Fen\u002Fdocs\u002Fclaude-code\u002Fcosts",{"title":716,"url":717},"Cline pricing","https:\u002F\u002Fcline.bot\u002Fpricing","\u002Fimages\u002Fblog\u002Fcursor\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fcursor\u002Fog.jpg",[65,66,67],"Cursor reviewed: an AI code editor billed past its sticker price","Cursor bundles an editor, a terminal agent and cloud runs behind one subscription. What the two usage pools really cost, and when Copilot, Claude Code or Cline is the better buy.","Abstract pipeline artwork for the Cursor review","Free · Pro from $20 per month",1791383548687]