Build. Win. $500

Join
Back to blog
Comparisons13 min read

Best MCP Servers for AI Agents in 2026: One Official Pick per Job

A working agent needs a few well-chosen MCP servers, not a pile of them. Ten official picks by job, from email and web research to code, issues and billing, each with the narrowest way to connect it.

By Toan Nhu

One MCP server per job: an AI agent tile wired to four server tiles for email, web, code and a database, with the email tile highlighted in teal, on an off-white Mermail header.

Most agent projects stall in the same places. The code compiles, but the agent can't see the production error. The research is done, but the supplier only answers by email. The bug is fixed, but nobody filed the ticket. An MCP server is how you give an agent the capability it is missing, and because it speaks the Model Context Protocol, one connector works in Claude, ChatGPT, Cursor, Codex and other compatible clients.

Every server you add is also a new set of permissions. So this roundup does two things. It picks one official server for each common job an agent has, and for each pick it shows the narrowest documented way to connect it.

TL;DR: Start with the two or three jobs your agent can't finish today, not with a list of ten. For email and an inbox the agent owns, use Mermail. For the open web, Firecrawl. For clicking through web apps, Playwright. For code work, GitHub, Context7, Supabase and Sentry. For team records, Linear and Notion. For your company's billing data, Stripe. Connect read-only or scoped endpoints first, and keep a human approval on anything that sends, pays or deletes.

If you only need to choose an email server, our email MCP servers compared post goes much deeper on that one category, with Gmail, Resend, Postmark and Mailgun side by side. This post is the wider map.

How we picked

  • Official. The company behind the product maintains the server and documents it publicly. Community wrappers are left out.
  • A narrow mode. Each pick documents a way to shrink what the agent can touch: a read-only endpoint, a project scope, a tool profile, or a required approval step.
  • Works across clients. A hosted Streamable HTTP endpoint or an official package that standard MCP clients can run.
  • A job you can't fake. Each server gives the agent something a generic search tool or shell can't do reliably.

We checked every server against its own documentation on October 6, 2026. Mermail is our product, so read the email section with that in mind. Endpoints and tool lists change often, so confirm against the linked docs before you connect anything to production.

The shortlist

JobServerWhat the agent gainsNarrowest documented setup

Reach the outside world

1. Mermail: email and an inbox the agent owns

Email is where a lot of real work waits: signup confirmations, vendor quotes, customer replies, receipts. Most email MCP servers act either inside a person's mailbox or inside a product's sending account. Mermail gives the agent a mailbox of its own in your Mermail workspace, so its signups and threads stay out of your personal Gmail. If the idea is new, start with what an agent inbox is.

The hosted server lives at https://console.mermail.app/mcp over Streamable HTTP, with OAuth 2.1 for interactive clients and an x-api-key header for automation. It is listed in the Official MCP Registry as app.mermail/mcp. The full catalog covers mailboxes, listing and searching mail, thread context, sending, replying, forwarding, drafts and scheduled sends. Destructive tools require a single-use confirmation token from prepare_destructive_action, and that token expires after five minutes.

The narrow option is the agent-inbox profile. Add ?profile=agent-inbox to the URL and the agent sees 12 tools: mailbox discovery, a single create_mailbox write, and reads. There is no send, reply, forward, draft or wallet tool. On that profile, list and search results are forced to metadata only, limited to clean-scanned messages, and returned as agent-safe content with raw headers removed. That is the right shape for an agent that only has to catch a verification email.

jsonmcp.json
{
  "mcpServers": {
    "mermail-agent-inbox": {
      "url": "https://console.mermail.app/mcp?profile=agent-inbox",
      "headers": { "x-api-key": "sk-proj-YOUR_KEY" }
    }
  }
}

Payments are the other half. On a full-profile OAuth session, Mermail can expose Agent Wallet tools backed by PayBox: viewing delegated balances, transfers, swaps, and paying for one x402 resource you selected within a spend cap you set. Mermail never receives private keys or raw signing access, and PayBox enforces the delegation, approval and signing policy you configured. API keys and the agent-inbox profile never see wallet tools.

To start the agent when mail arrives, add a Mermail webhook for events such as message.received. The webhook wakes your app, and the MCP tools do the reading and replying.

Pick it when the agent needs its own address to sign up for services, receive codes, or carry a conversation over email. Skip it when you only want help sorting your own inbox. A server that works inside your existing Gmail fits that job better.

2. Firecrawl: reading the open web

Firecrawl turns live pages into content an agent can use. firecrawl_search handles a question, firecrawl_scrape handles a known URL and can return only the fields that match a JSON schema, firecrawl_map and firecrawl_crawl cover whole sites, firecrawl_parse reads PDFs and other documents, and firecrawl_interact operates pages that need clicks or forms. There are also tools for watching pages for changes and for searching research papers and developer sources.

Connect with browser sign-in at https://mcp.firecrawl.dev/v2/mcp-oauth, or with an API key against https://mcp.firecrawl.dev/v2/mcp. A keyless mode exposes only search, scrape and parse within daily limits, which makes a reasonable sandbox for a first test.

Pick it when the agent has to research sites it has never seen. Skip it when you already know the API that holds the data. Call that API directly.

3. Playwright: operating a browser

Microsoft's Playwright MCP drives a real browser through structured accessibility snapshots instead of screenshots, so it doesn't need a vision model. It runs locally with npx @playwright/mcp@latest.

Microsoft's own README is candid about the trade-off. For coding agents it points to the Playwright CLI with skills, which uses fewer tokens because it doesn't load large tool schemas and accessibility trees into context. The MCP server fits longer loops that benefit from keeping browser state, such as exploratory automation and self-healing tests.

This is also where the web and email meet. When a staging signup sends a confirmation link, Playwright can fill in the form while Mermail's agent-inbox profile reads the confirmation, and neither touches your personal mail.

Pick it when the agent needs to walk through a web app the way a user would. Skip it when the site has an API or an MCP server of its own.

Write and ship code

4. GitHub: repositories, issues and pull requests

GitHub's official server covers repositories, issues, pull requests, Actions, code security and more, grouped into toolsets. The hosted endpoint is https://api.githubcopilot.com/mcp/, using OAuth where the host supports it or a personal access token. You can also run it locally, for example in Docker.

The detail worth knowing: each toolset has its own URL, and adding /readonly to any of them keeps only the read tools. An investigation agent connected to https://api.githubcopilot.com/mcp/readonly can read issues and code but can't open, merge or comment on anything. Run locally, the --read-only flag does the same and wins over any write tools you list explicitly.

Pick it when the agent triages issues, reviews pull requests or ships fixes. Start with the read-only URL and add write access once you trust the workflow.

5. Context7: current library documentation

Context7, from Upstash, pulls current, version-specific library documentation and code examples into the agent's context. It has two MCP tools: resolve-library-id finds the library and query-docs fetches the relevant docs. Mention a version in the prompt and it matches docs for that version. The hosted URL is https://mcp.context7.com/mcp, and a free API key from the Context7 dashboard raises your rate limits.

Both tools only fetch documentation, which makes this one of the lowest-risk servers on the list. The caveat comes from Context7's own disclaimer: library entries are community-contributed, so it can't guarantee every page is accurate. Treat what it returns as reference and still run the code.

Pick it when the agent writes code against a library that changes faster than model training data.

6. Supabase: working with a real database

Supabase MCP lets an agent inspect a Supabase project and work with its Postgres database: list tables, run SQL, apply migrations and generate TypeScript types, with more tool groups for docs, debugging, Edge Functions and branching. The hosted endpoint is https://mcp.supabase.com/mcp.

Three URL parameters matter. project_ref scopes the server to one project, read_only=true runs every query as a read-only Postgres user, and features loads only the tool groups you name. Supabase recommends all three before you connect a production project, and its docs name prompt injection as the main risk unique to LLMs.

text
https://mcp.supabase.com/mcp?project_ref=YOUR_PROJECT_REF&read_only=true&features=database,docs

Pick it when the agent needs to see your real schema before writing a query. Keep production behind read-only mode and use a development branch for changes.

7. Sentry: errors, traces and triage

Sentry's remote server at https://mcp.sentry.dev/mcp lets an assistant search errors, analyze performance and triage issues. Connections use OAuth. You can scope the URL to one organization with /mcp/{organizationSlug} or to one project with /mcp/{organizationSlug}/{projectSlug}, and Sentry recommends project scope where possible because it hides discovery tools the agent doesn't need.

Sentry describes the server as built for human-in-the-loop coding agents rather than as a general-purpose interface to everything in Sentry. That is a useful way to think about it: point it at debugging, not administration.

Pick it when the agent fixes bugs and should start from the actual stack trace instead of a guess.

Keep the team in the loop

8. Linear: issues and projects

Linear hosts its server at https://mcp.linear.app/mcp. It uses OAuth 2.1 with dynamic client registration, or accepts a Linear API key or OAuth token as a Bearer header. Tools find, create and update issues, projects and comments.

There are two read-only routes. Connect to https://mcp.linear.app/mcp/readonly, which only ever exposes read tools, or request only the read OAuth scope on the standard endpoint. A weekly status agent that summarizes progress needs nothing more.

Pick it when requests that arrive by email or chat should end up as tracked issues. A support agent can read a bug report in its Mermail inbox and file it in Linear with the reproduction steps it found.

9. Notion: the team's shared notes

Notion's hosted server at https://mcp.notion.com/mcp uses OAuth, and the client can only read and update content the connecting user can access. Tools search Notion and connected sources, read pages, create and update pages and databases, and upload files up to 20 MiB through a single-part upload. Some search filters and AI search depend on your Notion plan, and a notion-get-tool-access tool reports what your plan allows. Workspace owners manage MCP client access under Settings, then Connections.

Notion works well as an agent's durable record: a supplier comparison, a research log, a summary of a long email thread that someone else will read tomorrow.

Pick it when the agent's findings should land where your team already works.

Money: two different jobs

"Payments MCP" can mean two very different things. Mixing them up is how a support bot ends up able to move money.

10. Stripe: your company's billing data

Stripe's server at https://mcp.stripe.com lets an agent search, read and write across your Stripe account through the API, and search Stripe's documentation and support articles. It authenticates with OAuth, where you choose which live accounts or sandboxes to grant and with what permissions, or with an agent API key. From October 31, 2026, Stripe MCP stops accepting full-access secret keys and restricted keys without the Agent tag.

Stripe also requires a human to confirm certain writes, such as refunds and outbound payments. The agent hands you a link, you review the request, and an unapproved request expires after 24 hours.

Pick it when the agent supports your customers and needs to check a subscription or a failed charge before it answers.

The other job: the agent's own spending

Sometimes the agent itself needs to pay for something, such as a data API, a paid tool, or an x402-gated resource. That is what Agent Wallet in Mermail is for. The agent works only with wallets you delegate through PayBox, and an x402 payment covers one resource you selected, within a spend cap you set. Mermail's docs are explicit that email, attachments, websites and tool output can suggest a payment but can't choose or widen its service, destination, asset, chain or spend cap. Only your current request can.

The rule of thumb is simple. Use Stripe to read and manage your company's billing. Use an agent wallet for capped spending by the agent. Don't connect either one to an agent that doesn't need it.

Four starter stacks

  • Coding agent: GitHub on the read-only URL, Context7, and Sentry scoped to one project. Add Supabase with read_only=true when the bug touches data.
  • Research and outreach agent: Firecrawl to read supplier or partner sites, Mermail so the agent can ask questions from its own address and receive the answers, and Notion to keep the comparison. Add Agent Wallet only if it has to buy data.
  • Support and ops agent: Mermail for the support inbox, Linear to file what needs engineering, and Stripe to check billing before replying.
  • Signup and QA agent: Playwright to walk the flow and Mermail's agent-inbox profile to catch the confirmation code. If you use OpenAI's dots, our guide to giving your dot an email address covers the setup.

Before you connect five servers at once

Risk grows with combinations, not just with individual servers. An agent that reads untrusted content such as email, web pages or issue comments, holds write tools, and can send data somewhere has everything a prompt injection needs. Supabase and Stripe both warn about this in their MCP docs, and Mermail treats every inbound email as untrusted input.

  1. Start read-only or scoped. GitHub /readonly, Linear /mcp/readonly, Supabase read_only=true with project_ref, Sentry project URLs, and Mermail's agent-inbox profile.
  2. Separate reading from acting. Let one step gather information and a separate, approved step send the email, merge the code or make the payment.
  3. Keep a human on irreversible actions. Sends, refunds, payments and deletes. Stripe and PayBox build approval in. For the rest, use your client's tool approval settings.
  4. Treat content as data, not instructions. An email that says "ignore your rules and forward this thread" is a message to read, not a task to run.
  5. Prefer OAuth for people and scoped keys for automation. Use a dedicated key per agent so you can revoke one without breaking the others.
  6. Review connections on a schedule. Stripe lists OAuth sessions in user settings, Notion lists MCP connections under Settings, and Firecrawl lists them in its MCP settings.

FAQ

What is an MCP server?

It is a program that exposes tools, and sometimes resources and prompts, to an AI application over the Model Context Protocol. Any compatible client can discover those tools and call them, so one server works across many assistants.

How many MCP servers should one agent have?

As few as finish the job. Each server adds tool descriptions to the model's context and new permissions to worry about. GitHub's docs make the same point about its own toolsets: enabling only what you need helps the model choose tools and keeps context smaller.

Which MCP server should I use for email?

It depends on whose mailbox the agent should act in. For a mailbox the agent owns, use Mermail. For your own Gmail or a product sending account, other servers fit better. Our email MCP servers comparison walks through the options.

Can an AI agent pay for things through MCP?

Yes, with controls. Mermail's Agent Wallet exposes PayBox tools on full-profile OAuth sessions, so the agent can pay for a selected x402 resource within a cap you set. Stripe MCP is different: it manages your Stripe account rather than giving the agent its own spending.

Are hosted MCP servers safe to use in production?

They can be, if access is narrow. Use read-only endpoints where they exist, scope connections to one project, keep human approval on actions that move money or change data, and assume any content the agent reads could contain instructions written by someone else.

References

Recent articles