Best MCP Servers for Claude Code and Codex (2026)

Updated 2026-10-05 · by Murilo Prataviera, maker of Aki

Quick answer For most coding work, start with three servers: Context7 (current library docs), Playwright MCP or Chrome DevTools MCP (a real browser the agent can drive and inspect), and GitHub MCP (issues, PRs, Actions). Then add one server for each service you already use: Sentry for errors, Supabase or Postgres for data, Linear or Notion for tickets and specs, Figma for designs, Vercel for deployments. Add one with claude mcp add <name> <url-or-command> in Claude Code, or codex mcp add <name> … in Codex. Check the connection with /mcp.

Every command below was checked against the server's official README or docs page as of October 2026. Servers change their install steps often, so if a command fails, the linked source is the one to trust.

How MCP works in Claude Code (60-second version)

MCP (Model Context Protocol) lets your agent call tools that live outside it: a browser, your issue tracker, a database. A server is either remote (an HTTPS URL, usually with OAuth login) or local (a process Claude Code starts, usually through npx or Docker).

# Remote server over HTTP
claude mcp add --transport http <name> <url>

# Local server: everything after -- is the command that starts it
claude mcp add <name> --env API_KEY=... -- npx -y <package>

Scopes decide where the config lives:

Scope Where it applies Stored in
local (default) Current project, only you ~/.claude.json
project Current project, shared with your team .mcp.json in the repo root
user All your projects ~/.claude.json

Pick one with --scope project or --scope user. Claude Code asks you to approve project servers from a .mcp.json before it connects to them, and a freshly cloned repo can't approve its own servers.

Useful commands: claude mcp list, claude mcp get <name>, claude mcp remove <name>, and /mcp inside a session to see status and log in to OAuth servers.

And in Codex

Codex keeps MCP config in ~/.codex/config.toml, or in .codex/config.toml for a single project. The CLI, the IDE extension and the desktop app all read the same file.

codex mcp add context7 -- npx -y @upstash/context7-mcp   # local
codex mcp add linear --url https://mcp.linear.app/mcp    # remote
codex mcp login linear                                   # OAuth
[mcp_servers.playwright]
command = "npx"
args = ["@playwright/mcp@latest"]

[mcp_servers.github]
url = "https://api.githubcopilot.com/mcp/"
bearer_token_env_var = "GITHUB_PAT_TOKEN"

Type /mcp in the Codex TUI to see what's connected.

Comparison table

Server Category Type Auth Best for
Context7 Docs Remote or local API key Up-to-date library APIs
Playwright MCP Browser Local None Driving a browser, E2E checks
Chrome DevTools MCP Browser Local None Performance traces, console, network
GitHub MCP Code hosting Remote or Docker PAT or OAuth Issues, PRs, Actions
Figma MCP Design Remote OAuth Building UI from frames
Sentry MCP Errors Remote OAuth Debugging production errors
Supabase MCP Database Remote OAuth Schema and SQL on Supabase
DBHub (Postgres etc.) Database Local DSN Querying any SQL database
Linear MCP Tickets Remote OAuth Reading and updating issues
Notion MCP Docs/specs Remote OAuth Reading specs, writing notes
Vercel MCP Deploys Remote OAuth Deployment logs, projects
Aki (our app) Visual feedback Local Mac app None Pointing at what to fix on screen

The servers

1. Context7: current docs for any library

What it's for: Context7 pulls current, version-specific documentation and code examples into the agent's context, so it stops guessing at APIs that changed after its training cutoff. When to use it: fast-moving frameworks, new major versions, or any time the agent writes code against an API that no longer exists.

# Claude Code (remote)
claude mcp add --scope user --header "Authorization: Bearer YOUR_API_KEY" --transport http context7 https://mcp.context7.com/mcp
# Codex
[mcp_servers.context7]
url = "https://mcp.context7.com/mcp"
http_headers = { "Authorization" = "Bearer YOUR_API_KEY" }

Context7 also has a setup command, npx ctx7 setup, that logs you in and installs a CLI + skill version instead of the MCP server.

2. Playwright MCP: let the agent drive a browser

What it's for: Microsoft's server controls a real browser through Playwright. It reads the page's accessibility tree, not screenshots, so the agent can click, type and check results without a vision model. When to use it: checking a flow after a change, reproducing a bug step by step, drafting end-to-end tests.

claude mcp add playwright npx @playwright/mcp@latest
codex mcp add playwright npx "@playwright/mcp@latest"

Worth knowing: the README itself says coding agents may do better with Playwright CLI + skills, because it uses fewer tokens than loading big tool schemas and accessibility trees. It also says Playwright MCP is not a security boundary.

3. Chrome DevTools MCP: debugging and performance

What it's for: Google's server gives the agent DevTools: performance traces with insights, network requests, console messages with source-mapped stack traces, screenshots, and browser automation. When to use it: "why is this page slow?", a failing fetch call, a console error you can't reproduce. Pick it over Playwright when you need to diagnose, not just click through.

claude mcp add chrome-devtools --scope user npx chrome-devtools-mcp@latest
codex mcp add chrome-devtools -- npx chrome-devtools-mcp@latest

There's also a Claude Code plugin that bundles the server with skills: /plugin marketplace add ChromeDevTools/chrome-devtools-mcp, then /plugin install chrome-devtools-mcp@chrome-devtools-plugins. The README warns that the agent can see and change anything in that browser instance, so keep personal accounts out of it.

4. GitHub MCP: issues, pull requests, Actions

What it's for: GitHub's official server reaches past what git can do: reading and filing issues, reviewing PRs, checking workflow runs, searching code across repos. When to use it: "pick up issue #142", "why did CI fail on this PR?" If you only need commits and branches, the gh CLI may be enough.

# Claude Code 2.1.1+ (remote, personal access token)
claude mcp add-json github '{"type":"http","url":"https://api.githubcopilot.com/mcp","headers":{"Authorization":"Bearer YOUR_GITHUB_PAT"}}'

# Codex
codex mcp add github --url https://api.githubcopilot.com/mcp/ --bearer-token-env-var GITHUB_PAT_TOKEN

Use a fine-grained token with only the scopes you need. A local Docker version with OAuth login is also available (ghcr.io/github/github-mcp-server).

5. Figma MCP: from design to code

What it's for: Figma's server gives the agent the structure of a frame (layout, components, variables), so the code it writes matches the design instead of a guess from a screenshot. When to use it: building or updating UI from Figma files.

claude plugin install figma@claude-plugins-official          # preferred
claude mcp add --scope user --transport http figma https://mcp.figma.com/mcp
codex mcp add figma --url https://mcp.figma.com/mcp

Figma only lets clients in its MCP catalog connect; Claude Code is on that list.

6. Sentry MCP: real errors, real stack traces

What it's for: search errors, look at issues and traces, triage, and read Sentry docs, all from the agent. When to use it: "fix the top unresolved error in checkout" works much better when the agent can read the actual event.

claude mcp add --transport http sentry https://mcp.sentry.dev/mcp

Run /mcp to log in. You can scope it to one org and project by adding /{organizationSlug}/{projectSlug} to the URL. Sentry also ships a Claude Code plugin (claude plugin marketplace add getsentry/sentry-mcp). For Codex, Sentry doesn't publish its own snippet, but the generic form works: codex mcp add sentry --url https://mcp.sentry.dev/mcp.

7. Supabase MCP: your database and backend

What it's for: let the agent work with a Supabase project: inspect the schema and run SQL queries.

claude mcp add --scope project --transport http supabase "https://mcp.supabase.com/mcp"
codex mcp add supabase --url "https://mcp.supabase.com/mcp"

Do this: add ?project_ref=<id>&read_only=true to the URL to limit it to one project and read-only queries. Supabase's own guidance is to connect to production only when the task needs production data, and to treat prompt injection from stored user content as the main risk.

8. DBHub: any Postgres (or other SQL) database

What it's for: Bytebase's DBHub connects the agent to a database through a connection string. Anthropic's MCP docs use it as their Postgres example.

claude mcp add --transport stdio db -- npx -y @bytebase/dbhub \
  --dsn "postgresql://readonly:pass@localhost:5432/analytics"

Connect as a read-only database user. That stops a wrong guess from becoming a DROP TABLE.

9. Linear MCP: tickets in the loop

What it's for: find, create and update Linear issues, projects and comments.

claude mcp add --transport http linear-server https://mcp.linear.app/mcp
codex mcp add linear --url https://mcp.linear.app/mcp

Log in with /mcp in Claude Code or codex mcp login linear in Codex.

10. Notion MCP: specs and docs

What it's for: read product specs and team docs, and write back notes or changelogs.

claude mcp add --transport http notion https://mcp.notion.com/mcp
# Codex, then run: codex mcp login notion
[mcp_servers.notion]
url = "https://mcp.notion.com/mcp"

11. Vercel MCP: deployments and logs

What it's for: search Vercel docs, manage projects and deployments, read deployment logs, and query Web Analytics.

claude mcp add --transport http vercel https://mcp.vercel.com
codex mcp add vercel --url https://mcp.vercel.com

Vercel only accepts clients it has reviewed (Claude Code and Codex CLI both are). The agent gets the same access as your Vercel account, so keep human confirmation on.

12. Aki: show the agent what to fix on your screen (our app, so take this with a grain of salt)

Disclosure: we make Aki. It's here because "visual feedback" is a real gap in the list above, not because the rest of the list is about it.

What it's for: Playwright and DevTools let the agent look at a page. Aki goes the other direction: you point at things. Press ⇧⌘A, click an element, drag an area or hold ⌥ to select lines of text, and type what should change. Queue several marks, then send them with ⌘⏎. In Chromium browsers (Chrome, Brave, Edge, Arc, Vivaldi) each mark carries the element's CSS selector, text, HTML and, in React dev builds, the component's source file. In other apps it uses macOS Accessibility, and areas work anywhere. Marks are text first; a small image crop goes along only when what you marked is visual, which uses fewer tokens than pasting whole screenshots.

How the agent gets it: a page on localhost:PORT goes to the session running that port; anything else goes to the session you pick in Aki's sidebar. The agent reads the marks through Aki's local MCP server (on 127.0.0.1 only) or the aki CLI, and marks each one resolved when it's done. Marks stay on your Mac; there's no account and no telemetry.

Real limits: Mac only (Apple Silicon, macOS 14+). Element picking needs a Chromium browser with "Allow JavaScript from Apple Events" turned on. Aki types into the terminal on its own only with the Orca terminal; with other terminals the agent has to read the marks through MCP or the CLI. It's version 0.2.0, so expect rough edges. Free to use and source-available (FSL license). Install from useaki.vercel.app.

Tips: get the benefit without the mess

Don't install everything. Each server adds tools and instructions the agent has to consider. Claude Code's tool search (on by default) loads only tool names at startup and fetches full definitions when needed, which helps a lot. Still, fewer servers means fewer wrong tool picks. Install per project (local or project scope) and keep user scope for the two or three you use everywhere.

Watch output size. Claude Code warns when one MCP result goes over 10,000 tokens and caps it at 25,000 by default (MAX_MCP_OUTPUT_TOKENS changes the cap). Accessibility trees and big SQL results reach that fast.

Consider CLI + skills. Playwright and Context7 now offer CLI + skill versions because they use less context. If a server mostly wraps a CLI you already have (like gh), the CLI may be enough.

Security basics: - Install only servers from the vendor itself or a source you trust. Anthropic's docs warn that servers which fetch outside content expose you to prompt injection. - Prefer OAuth over pasted tokens. When you need a token, give it the fewest scopes possible and keep it in an environment variable, not in a committed .mcp.json. Claude Code supports ${VAR} expansion in .mcp.json. - Point database servers at dev data, read-only, scoped to one project. - Use a separate browser profile for browser servers.

FAQ

What are the best MCP servers for Claude Code?

For general coding: Context7 for docs, Playwright MCP or Chrome DevTools MCP for the browser, and GitHub MCP for repo work. After that, add the server that matches each tool your team already uses (Sentry, Supabase, Linear, Notion, Figma, Vercel).

How do I add an MCP server to Claude Code?

Run claude mcp add --transport http <name> <url> for a remote server, or claude mcp add <name> -- <command> for a local one. Add --scope project to share it through .mcp.json, or --scope user to use it in every project. Then run /mcp in a session to check status and log in.

Where does Codex store MCP servers?

In ~/.codex/config.toml under [mcp_servers.<name>], or in a project's .codex/config.toml. You can edit the file directly or use codex mcp add. The CLI, IDE extension and app share the same config.

Playwright MCP or Chrome DevTools MCP?

Playwright MCP is built for driving pages through the accessibility tree: clicking through flows and writing tests. Chrome DevTools MCP is built for diagnosis: performance traces, network, console with source maps. Many people keep one and add the other only when they need it.

Do too many MCP servers slow Claude Code down?

Less than they used to, because tool search defers full tool definitions until they're needed. But every server is still something the model can pick wrongly, and big tool results eat context. Keep the list short and scoped to the project.

Are MCP servers safe?

A server can do whatever its credentials allow, and content it fetches can carry prompt injection. Use official servers, least-privilege tokens or OAuth, read-only database users, and keep confirmations on for anything that writes.

Sources