Model Context Protocol

MCP server directory

86 public MCP servers, each checked by Merlonix with a real Model Context Protocol handshake — not just a ping. See the transport, protocol version, authentication posture, callable tool inventory, and an A–F security-posture grade for each.

Last checked at Aug 4, 2026, 12:45 AM UTC. These are point-in-time observations, not real-time — re-check any server live.

Independent directory maintained by Merlonix. Not affiliated with, endorsed by, or operated by the listed vendors. Each health check is Merlonix’s own point-in-time observation of a public endpoint; vendor names are used nominatively to describe what we checked. 12 of these servers expose their tools without authentication; the rest are live but gated behind a credential.

Dev & code

Buildkite

Auth required

Buildkite’s server for pipelines, builds, and test results. Requires authentication.

HTTPPosture A

Cloudflare Container Sandbox

Auth required

Cloudflare’s server for spinning up sandboxed development environments in containers. Requires authentication.

HTTPPosture A

Cloudflare Workers Bindings

Auth required

Cloudflare’s server for building Workers with storage, AI, and compute bindings. Requires authentication.

HTTPPosture A

GitHub

Auth required

GitHub’s official remote MCP server: repositories, issues, pull requests, code search, and Actions. Needs a GitHub credential.

HTTPPosture A

GitLab

Auth required

GitLab’s official server for projects, issues, merge requests, and CI on gitlab.com. Requires a GitLab credential.

HTTPPosture A

HashiCorp Terraform

Auth required

HashiCorp’s Terraform server for registry providers, modules, and infrastructure-as-code context. Requires authentication.

HTTPPosture A

Heroku

Auth required

Heroku’s server for apps, dynos, and add-ons. Requires authentication.

HTTPPosture A

Postman

Auth required

Postman’s server for collections, workspaces, and APIs. Requires authentication.

HTTPPosture A

Railway

Auth required

Railway’s server for projects, services, and deployments on its app platform. Requires authentication.

HTTPPosture A

Render

Auth required

Render’s server for services, deploys, and databases on its cloud platform. Requires authentication.

HTTPPosture A

Vercel

Auth required

Vercel’s official server for projects, deployments, and documentation. Requires authentication.

HTTPPosture A

Web & data

Alchemy

Auth required

Alchemy’s server for blockchain APIs and onchain data. Requires authentication.

HTTPPosture A

Apify

Auth required

Apify’s server exposing its marketplace of web scrapers (Actors) to agents. Requires authentication.

HTTPPosture A

Browserbase

Operational

Headless-browser automation for agents (Stagehand), by Browserbase — navigate, extract, and act on real web pages.

HTTP6 toolsPosture A

Cloudflare Browser Rendering

Auth required

Cloudflare’s server for fetching and rendering web pages, taking screenshots, and converting pages to markdown. Requires authentication.

HTTPPosture A

CoinMarketCap

Auth required

CoinMarketCap’s server for cryptocurrency market data. Requires authentication.

HTTPPosture A

Exa

Operational

Neural web search built for AI agents, by Exa. Search the web and get clean, structured results inside an agent session.

HTTP2 toolsPosture A

Firecrawl

Operational

Web scraping, crawling, search, and structured data extraction for agents, by Mendable. Turns any website into clean, LLM-ready data.

HTTP3 toolsPosture A

Kagi

Auth required

Kagi’s server for its independent search index and summarizer. Requires authentication.

HTTPPosture A

Serpstat

Auth required

Serpstat’s server for SEO data — keywords, rankings, and domain analysis. Requires authentication.

HTTPPosture A

Tavily

Auth required

Web search and extraction built for LLM agents, by Tavily. Requires an API key.

HTTPPosture A

Webflow

Auth required

Webflow’s server for sites, collections, and CMS items. Requires authentication.

HTTPPosture A

Wix

Auth required

Wix’s server for sites, stores, bookings, and data. Requires authentication.

HTTPPosture A

Check any MCP server — free, no signup.

Paste any MCP endpoint and Merlonix opens a real handshake: protocol version, tool inventory, transport, and an A–F security-posture scan. Then monitor it around the clock and catch silent tool-contract drift before it breaks your agents.