· Feedbot team
Best MCP Servers for Claude Code and Cursor (2026)
A practical list of Claude Code MCP servers grouped by job, with install commands, Cursor mcp.json configs, auth notes and least-privilege security tips.
TL;DR: Most teams need five to seven MCP servers, not fifty. Pick one per job: GitHub for the repo, Context7 for current library docs, Playwright for the browser, a database server that connects with a read-only role, Sentry for errors, Linear for tickets, and Feedbot for what users are actually complaining about. Add them with claude mcp add in Claude Code or .cursor/mcp.json in Cursor, keep tokens narrow, and turn on read-only modes wherever a server offers them.
Every command and config below was checked against the official docs or README of each server on the date of this post. Links are in the Sources section at the end. Servers change quickly, so if something fails, check the source first.
How MCP servers work in Claude Code
An MCP server gives your coding agent a set of tools: “list pull requests”, “run this SQL”, “open this URL in a browser”. Claude Code decides when to call them based on your prompt. There are two kinds you’ll meet:
- Remote (HTTP) servers run on the vendor’s side. You give Claude Code a URL and, usually, a token or an OAuth login.
- Local (stdio) servers run as a process on your machine, typically started with
npxordocker.
Add, list and remove servers
The core commands:
# Remote server over HTTPclaude mcp add --transport http <name> <url>
# Remote server with an auth headerclaude mcp add --transport http <name> <url> --header "Authorization: Bearer <token>"
# Local server: everything after -- is the command that starts itclaude mcp add --transport stdio <name> -- <command> [args...]
# See what's configured and whether each server connectsclaude mcp list
# Details for one serverclaude mcp get <name>
# Remove a server (also clears its stored OAuth tokens)claude mcp remove <name>Inside a session, /mcp opens a panel where you can see server status, log in to OAuth servers, and switch servers on or off without deleting them. For OAuth servers you can also run claude mcp login <name> from the terminal.
The -- matters for local servers. Flags before it belong to Claude Code (--env, --scope), and everything after it is passed to the server untouched.
Scopes: local, project, user
Each server lives in one of three scopes, set with --scope (or -s):
| Scope | Where it’s stored | Who gets it |
|---|---|---|
local (default) |
~/.claude.json, under the current project path |
Only you, only in this project |
project |
.mcp.json in the repo root |
Everyone who clones the repo |
user |
~/.claude.json, global section |
Only you, in every project |
A reasonable split: put team-wide, tokenless servers (docs, browser) in project scope so everyone gets the same setup. Keep anything with a personal token in local or user scope so it never lands in git.
If you do commit a .mcp.json that needs a secret, use environment variable expansion instead of the literal value. Claude Code expands ${VAR} and ${VAR:-default} in command, args, env, url and headers:
{ "mcpServers": { "feedbot": { "type": "http", "url": "https://mcp.feedbotai.com/mcp", "headers": { "Authorization": "Bearer ${FEEDBOT_API_KEY}" } } }}Claude Code asks for approval before using project-scoped servers in an interactive session. Note that in claude -p runs and Agent SDK sessions, they load without a prompt, which is worth knowing if you run agents in CI.
One gotcha: when you write --header "Authorization: Bearer $TOKEN" on the command line, your shell expands $TOKEN before Claude Code sees it, so the real token is saved in ~/.claude.json. That’s fine for local scope on your own laptop. It’s not fine for anything you share.
Cursor MCP servers: the config format
Cursor reads MCP servers from .cursor/mcp.json in the project, or ~/.cursor/mcp.json for all projects. The top-level key is mcpServers. A local server uses command, args and env; a remote one uses url and optional headers:
{ "mcpServers": { "local-example": { "command": "npx", "args": ["some-mcp-package"], "env": { "API_KEY": "${env:API_KEY}" } }, "remote-example": { "url": "https://example.com/mcp", "headers": { "Authorization": "Bearer ${env:API_KEY}" } } }}Cursor uses ${env:NAME} for environment variables, which is different from Claude Code’s ${NAME}. If you maintain both files, don’t copy one into the other without fixing that.
The list, grouped by job
Code and repo: GitHub
What it’s for. Reading issues and pull requests, searching code across repos, checking Actions runs, and opening PRs without leaving the agent. GitHub hosts the server, so there’s nothing to run locally.
Claude Code:
claude mcp add --transport http github https://api.githubcopilot.com/mcp/ \ --header "Authorization: Bearer $GITHUB_PAT"Cursor (.cursor/mcp.json):
{ "mcpServers": { "github": { "url": "https://api.githubcopilot.com/mcp/", "headers": { "Authorization": "Bearer ${env:GITHUB_PAT}" } } }}Auth. A GitHub personal access token. Prefer a fine-grained token limited to the repos the agent actually works on.
Caution. The server can write: comment, merge, create branches. If you only want the agent to read, use the read-only endpoint https://api.githubcopilot.com/mcp/readonly or send the header X-MCP-Readonly: true. You can also cut the tool list down with the X-MCP-Toolsets header, for example repos,issues. Fewer tools also means less noise in the agent’s context.
Docs and context: Context7
What it’s for. Pulling current, version-specific documentation for libraries into the prompt, so the agent stops writing code against an API that changed two releases ago. Add “use context7” to a prompt when you want it to look something up.
Claude Code. Context7’s docs recommend its setup command, which handles login and configuration:
npx ctx7 setup --claudeCursor. Either run npx ctx7 setup --cursor, or add the remote server by hand:
{ "mcpServers": { "context7": { "url": "https://mcp.context7.com/mcp", "headers": { "Context7-API-Key": "${env:CONTEXT7_API_KEY}" } } }}Auth. It works without a key at lower rate limits; a free API key from the Context7 dashboard raises them. Context7’s docs specifically say to use the hyphenated Context7-API-Key header name in Cursor, because header names with underscores can be dropped by Cursor’s proxy.
Caution. It’s third-party documentation fetched at runtime. Treat it like any web content the agent reads.
Browser and testing: Playwright
What it’s for. Letting the agent open your app in a real browser, click through a flow, fill forms and read the page. It’s the fastest way to have the agent confirm a UI bug before and after a fix. Microsoft maintains it.
Claude Code:
claude mcp add playwright npx @playwright/mcp@latestCursor:
{ "mcpServers": { "playwright": { "command": "npx", "args": ["@playwright/mcp@latest"] } }}Auth. None. It runs locally.
Useful flags. --headless hides the browser window, --isolated keeps the profile in memory and throws it away after the session, and --allowed-origins limits which origins the browser may request.
Caution. The Playwright MCP README states plainly that it is not a security boundary, and --allowed-origins is a convenience, not a fence. Don’t point it at a browser profile that’s logged in to your production admin panel. Use --isolated and a test account.
Databases: Postgres (DBHub) and Supabase
What it’s for. Letting the agent read your schema and run queries while it debugs. This is where least privilege matters most.
Postgres via DBHub. DBHub by Bytebase connects to Postgres, MySQL, SQL Server, MariaDB, Oracle and SQLite. The Claude Code docs use it as their database example:
claude mcp add --transport stdio db -- npx -y @bytebase/dbhub \ --dsn "postgresql://readonly:pass@localhost:5432/analytics"In Cursor, the same thing as a local server:
{ "mcpServers": { "db": { "command": "npx", "args": ["-y", "@bytebase/dbhub", "--dsn", "${env:DATABASE_URL_READONLY}"] } }}The important part is the user in the DSN. Create a database role that can only SELECT and connect as that role. DBHub has its own read-only option in its TOML config, but a published security advisory showed that older versions of that setting did not actually block writes. Enforce read-only in the database, not only in the tool.
Supabase. Supabase runs a hosted server:
claude mcp add --scope project --transport http supabase \ "https://mcp.supabase.com/mcp?project_ref=<your-project-ref>&read_only=true"{ "mcpServers": { "supabase": { "url": "https://mcp.supabase.com/mcp?project_ref=<your-project-ref>&read_only=true" } }}Auth. OAuth. Your client opens a browser window where you sign in to Supabase and grant access.
Caution. project_ref limits the server to one project and read_only=true limits it to read queries. You can also narrow the tool groups with features=, for example features=database,docs. Supabase’s own guidance is to connect to production only when the task truly needs production data, and to keep manual approval of tool calls on. The risk they call out is prompt injection: a row in your database that contains instructions the model might follow.
Errors and monitoring: Sentry
What it’s for. Searching errors, reading stack traces and event details, and triaging issues from the agent. Pair it with GitHub and the agent can go from “this exception spiked” to the commit that caused it.
Claude Code:
claude mcp add --transport http sentry \ https://mcp.sentry.dev/mcp/<organization-slug>/<project-slug>Cursor:
{ "mcpServers": { "sentry": { "url": "https://mcp.sentry.dev/mcp/<organization-slug>/<project-slug>" } }}Auth. OAuth on first connection. In Claude Code, finish it in /mcp or with claude mcp login sentry.
Caution. You can use the bare URL https://mcp.sentry.dev/mcp, but scoping it to an organization or a project keeps the agent inside the part of Sentry that’s relevant to the repo you’re in.
Project management: Linear
What it’s for. Reading and updating issues, projects and comments. Useful when the agent should pick up a ticket, or leave a note on it when the PR is ready.
Claude Code:
claude mcp add --transport http linear https://mcp.linear.app/mcpCursor:
{ "mcpServers": { "linear": { "url": "https://mcp.linear.app/mcp" } }}Auth. OAuth by default. You can skip the interactive flow by sending a Linear API key as Authorization: Bearer <key>.
Caution. If the agent only needs to read tickets, connect to https://mcp.linear.app/mcp/readonly instead. Linear also lets you request only the read OAuth scope.
Product feedback and user bugs: Feedbot
What it’s for. The other servers tell the agent about code, errors and tickets someone already wrote. None of them tell it what users are saying. Feedbot is an AI chat widget on your site that answers questions from your docs, and when a user reports a bug, complains or suggests something, it groups those reports into issues with user quotes, report counts, affected pages and suggested acceptance criteria. The MCP server lets your coding agent read those issues and mark them fixed.
Claude Code:
claude mcp add --transport http feedbot https://mcp.feedbotai.com/mcp \ --header "Authorization: Bearer $FEEDBOT_API_KEY"Cursor. Feedbot’s docs say any MCP client works the same way: HTTP transport, the URL above and the Authorization header. In Cursor’s format:
{ "mcpServers": { "feedbot": { "url": "https://mcp.feedbotai.com/mcp", "headers": { "Authorization": "Bearer ${env:FEEDBOT_API_KEY}" } } }}Tools. list_product_issues (open issues sorted by frequency), get_issue (quotes, pages and acceptance criteria), mark_issue_fixed, plus search_conversations, get_conversation, insight reports and stats.
Auth. An API key from Settings → API keys in the Feedbot dashboard. Keys start with fb_live_ and have scopes such as conversations:read, issues:read and issues:write. API and MCP access are on the Pro and Business plans.
Caution. Give the key only the scopes the agent needs. If you want the agent to read issues but have a human mark them fixed, leave out issues:write. When an issue is marked fixed, the bot stops working around the problem in its answers and, if you turned it on, tells the users who reported it. So only let the agent close issues after the fix is actually deployed.
If your agent doesn’t speak MCP, npx feedbot pull writes open issues to .feedbot/issues/<id>.md in your repo. The full walkthrough is in Send user feedback to your coding agent via MCP, and every tool and endpoint is listed in the API & MCP docs.
Security checklist for any MCP server
MCP servers act with whatever access you hand them, and the agent decides when to call them. A few habits cover most of the risk:
- Narrow tokens. Fine-grained GitHub tokens limited to specific repos, API keys with only the scopes the job needs, database roles that can’t write.
- Read-only first. GitHub, Linear and Supabase all have read-only modes. Start there and add write access only when you have a workflow that needs it.
- Scope to one project. Sentry’s project URL, Supabase’s
project_ref, Feedbot’s per-key scopes. Less reach means less damage if something goes wrong. - Keep secrets out of git. Personal tokens go in
localoruserscope. Shared.mcp.jsonfiles reference environment variables, never literal keys. - Assume prompt injection is possible. Any server that returns content written by others (web pages, docs, database rows, issue comments, user messages) can carry instructions the model might follow. Keep tool-call approval on for servers that can write.
- Only install servers you trust. Stick to servers published by the vendor or a maintainer you can identify. Both Anthropic’s and Cursor’s docs say the same.
- Prune. Run
claude mcp listonce in a while and remove what you don’t use. Every connected server adds tool definitions to the agent’s context.
A starter setup
If you’re starting from zero, this order works for most web products:
- Playwright first. No auth, no risk to production data, and it lets the agent check its own UI work.
- GitHub in read-only mode.
- Sentry scoped to your main project.
- A database server connected with a read-only role to a staging or local database.
- Feedbot, so the agent’s to-do list includes the bugs users reported in chat, not only the ones that threw an exception.
- Linear or Context7 as needed.
A prompt that uses several of them at once:
Take the top open Feedbot issue, find matching errors in Sentry, reproduce it in Playwright, fix it and open a PR.
FAQ
What’s the difference between Claude Code MCP servers and Cursor MCP servers?
None on the server side. The same servers work in both. Only the setup differs: Claude Code uses claude mcp add (or a .mcp.json file) and Cursor uses .cursor/mcp.json. Watch the environment variable syntax: ${VAR} in Claude Code, ${env:VAR} in Cursor.
Where does Claude Code store MCP server settings?
Local and user scopes are stored in ~/.claude.json. Project scope is stored in .mcp.json at the root of the repo, which you can commit so the whole team gets the same servers.
How many MCP servers should I install?
As few as cover your daily work. Each server adds tool descriptions to the agent’s context, and a long tool list makes it more likely the agent picks the wrong one. Five to seven focused servers is plenty for most teams.
Are MCP servers safe to use with production data?
They’re as safe as the credentials you give them. Use read-only modes, read-only database roles and project-scoped URLs, keep approval prompts on for tools that write, and prefer staging data where you can.
How do I remove an MCP server from Claude Code?
Run claude mcp remove <name>. It deletes the configuration and any stored OAuth tokens. To turn a server off temporarily without removing it, use the /mcp panel inside a session.
Sources
- Claude Code docs, Connect Claude Code to tools via MCP: https://code.claude.com/docs/en/mcp
- Cursor docs, Model Context Protocol: https://cursor.com/docs/context/mcp
- GitHub MCP Server: https://github.com/github/github-mcp-server
- GitHub MCP Server, Cursor install guide: https://github.com/github/github-mcp-server/blob/main/docs/installation-guides/install-cursor.md
- GitHub MCP Server, remote server options (read-only, toolsets): https://github.com/github/github-mcp-server/blob/main/docs/remote-server.md
- Context7, Claude Code setup: https://context7.com/docs/clients/claude-code
- Context7, Cursor setup: https://context7.com/docs/clients/cursor
- Playwright MCP: https://github.com/microsoft/playwright-mcp
- DBHub: https://github.com/bytebase/dbhub
- DBHub TOML configuration: https://dbhub.ai/config/toml
- DBHub security advisory on read-only mode: https://github.com/bytebase/dbhub/security/advisories/GHSA-mwwr-p57h-56pf
- Supabase MCP server: https://supabase.com/docs/guides/getting-started/mcp
- Sentry MCP server: https://mcp.sentry.dev/
- Linear MCP server: https://linear.app/docs/mcp
- Feedbot API & MCP docs: https://feedbotai.com/docs/api-mcp/