Everyone says there are "thousands of MCP servers". We wanted the actual number, and to know what is behind it, so we read the whole official registry through its public API and counted. The result is also the data behind our new MCP server directory.
What the registry is
The MCP Registry is, in its maintainers' words, "the official centralized metadata repository for publicly accessible MCP servers". It launched in preview on 8 September 2025. It stores metadata, not code: a name, a description, and where to find the server, which is either a package on npm, PyPI or a container registry, or the URL of a server somebody hosts.
Two sentences from that page explain most of what follows. First: "The metadata hosted by the MCP Registry is deliberately unopinionated." Second, the registry "is intended to be consumed primarily by downstream aggregators", which are expected to add the curation. It checks who owns a namespace. It does not check whether a server is any good.
The headline numbers
| Measure | Count | Share |
|---|---|---|
| Servers (latest version of each) | 38,212 | 100% |
| Active | 37,744 | 98.8% |
| Marked deprecated | 454 | 1.2% |
| With a repository link | 28,771 | 75.3% |
| With a title | 24,173 | 63.3% |
| With a website | 19,657 | 51.4% |
| Version still 0.x | 15,425 | 40.4% |
| Version exactly 1.0.0 | 11,199 | 29.3% |
Remote beats local
| How you run it | Servers | Share |
|---|---|---|
| Remote: connect to a URL | 23,687 | 62.0% |
| Local: install a package | 15,944 | 41.7% |
| Both offered | 1,881 | 4.9% |
| Neither listed | 462 | 1.2% |
Of the remote servers, 22,947 use streamable HTTP and 1,077 still list the older SSE transport. Among the packages, npm dominates:
| Package registry | Servers |
|---|---|
| npm | 10,300 |
| PyPI | 4,108 |
| Docker and other OCI images | 1,012 |
| MCPB bundles | 963 |
| NuGet | 133 |
| Cargo | 65 |
For a small team this matters in a practical way. A remote server is one line of configuration and somebody else's uptime, but your prompts and data pass through their infrastructure. A local package runs on your own machine with your own credentials, and you own the updates.
The growth is recent, and lopsided
The registry gives each entry the date its current version was published. Grouped by month:
| Month | Current versions published | Running total |
|---|---|---|
| Sep to Dec 2025 | 927 | 927 |
| Jan 2026 | 293 | 1,220 |
| Feb 2026 | 909 | 2,129 |
| Mar 2026 | 1,541 | 3,670 |
| Apr 2026 | 1,687 | 5,357 |
| May 2026 | 2,147 | 7,504 |
| Jun 2026 | 2,680 | 10,184 |
| Jul 2026 | 4,176 | 14,360 |
| Aug 2026 | 6,858 | 21,218 |
| Sep 2026 | 16,110 | 37,328 |
| 1 Oct 2026 | 884 | 38,212 |
September 2026 alone accounts for 42% of the registry, and 73% of entries have a current version from July or later. These are version dates, not first-registration dates, so an old server that shipped an update in September counts there. Even so, the curve is steep: 884 entries carry the date of the single day we crawled.
Who publishes all of this
There are 22,420 publisher namespaces. Nine in ten of them (20,173) have published exactly one server. The volume comes from the other end:
| Publishers | Entries | Share of registry |
|---|---|---|
| Largest single namespace | 2,365 | 6.2% |
| Top 3 namespaces | 5,192 | 13.6% |
| Top 10 namespaces | 7,482 | 19.6% |
| The 17 namespaces with more than 100 entries each | 8,324 | 21.8% |
The largest namespace publishes entries such as "ISO 639 language tag fr." Another 158 entries share the description "Small public utility for autonomous clients." and 22 still say "Description of my MCP server", the template default. None of that breaks a rule: the registry verifies the namespace, and the namespace is real.
Two thirds of all entries (25,123, or 65.7%) sit under io.github.*, which means the publisher proved control of a GitHub account. The remaining 13,089 use a domain namespace such as com.stripe, which requires proving control of the domain. That second group is where the vendors are: we found 68 servers published by well-known companies under their own namespace, including Stripe, GitHub, Notion, Cloudflare, Supabase, Atlassian, Microsoft and Google. They are collected on the vendor servers page.
What is left after a quality bar
For the directory we score each entry on how complete it is (repository, package, title, website, a real description) and subtract points for placeholder text, copy-pasted descriptions and namespaces with hundreds of near-identical entries. That score is about completeness, not quality of the code. 29,663 of the 37,744 active servers pass, which is 78.6%.
Sorted by keyword rules on the name and description, the listed servers fall into these groups:
| Category | Listed servers |
|---|---|
| Finance, payments and crypto | 3,197 |
| AI, memory and agents | 2,803 |
| Developer tools | 2,793 |
| Browser, search and web data | 1,833 |
| Data, analytics and research | 1,504 |
| Security and compliance | 1,315 |
| E-commerce and business data | 1,233 |
| Productivity and project tools | 1,229 |
| Cloud and DevOps | 1,140 |
| Communication and email | 934 |
| Media and design | 932 |
| Marketing, sales and CRM | 928 |
| Databases | 735 |
| Monitoring and observability | 672 |
| Location, government and law | 636 |
| Health, education and lifestyle | 576 |
| Files and storage | 322 |
| No category matched | 6,881 |
The keyword rules are blunt. A server that mentions "token" lands in finance even when it means an API token, and almost a quarter match nothing. We will tighten the rules as we go; the counts above are what the rules produced on the day.
How to pick a server from 38,000
- Start with the vendor's own server. If you want Stripe, GitHub or Notion in your agent, the server published under that company's namespace is the first one to try.
- Check that there is a repository. A quarter of entries have none. No source means nothing to read before you hand over credentials.
- Look at what it asks for. The registry does not scan code. Its documentation says security scanning is delegated to the package registries and to downstream aggregators.
- Prefer a package or a remote URL you can identify. 462 entries list neither, so there is nothing to install or connect to.
- Treat version 0.x as what it says. Four in ten entries are still there.
What we will do with it
The crawl now runs every day and takes seconds, because the API can return only what changed since the last run. The directory updates with it. The part a list cannot give you is whether a server works, so that is what our MCP articles will be: one server at a time, installed and run, with the tools it exposes, the setup that worked and what broke.
FAQ
How many MCP servers are there?
The official MCP Registry listed 38,212 servers on 1 Oct 2026, of which 37,744 were active. That counts only servers whose publishers registered them; servers that were never registered are not included, and the total includes many near-identical entries from a few publishers.
What is the official MCP Registry?
It is the metadata repository for publicly accessible MCP servers run by the Model Context Protocol project, in preview since 8 September 2025. It stores each server's name, description and install or connection details, and points to packages on npm, PyPI and container registries or to remote server URLs.
Are MCP servers in the registry verified or safe?
The registry verifies namespace ownership: only the owner of a GitHub account or a domain can publish under it. It does not review or scan the server's code. Its documentation says security scanning is left to package registries and downstream aggregators.
Are most MCP servers remote or local?
Remote. 62% of registry entries give a URL to connect to, and 42% give a package to install; 5% offer both. Among packages, npm is the most common with 10,300 servers, followed by PyPI with 4,108.
How often does the registry change?
Quickly. 884 entries carried a current-version date of the day we crawled, and 16,110 were dated September 2026. Our directory re-reads the registry once a day.

