On this page13 sections
  1. The short answer
  2. MCP server directories at a glance
  3. Official MCP Registry
  4. Smithery
  5. Glama
  6. Smithery vs Glama
  7. PulseMCP
  8. mcp.so
  9. Docker MCP Catalog
  10. GitHub: modelcontextprotocol/servers
  11. Where PopMCP fits
  12. How to vet an MCP server before installing
  13. FAQ

MCP server directory: the short answer

No single MCP server directory is best. Use the official MCP Registry to check who published a server, Glama for the widest search, Smithery for hosted servers with managed OAuth, and the Docker MCP Catalog for signed local containers. PulseMCP and mcp.so are free lists for browsing. A listing is not a safety check, so vet before you connect.

MCP server directories at a glance

DirectorySize on 5 October 2026What it checksHostingCostBest for
Official MCP RegistryNo total publishedWho owns the namespace, by GitHub, DNS or HTTP challenge. No code scanning.None, metadata onlyFreeConfirming a publisher
Smithery25,079+ on the homepage, 18,553 through its public API190 servers flagged verifiedHosted servers and managed OAuthFree tier, then $10 a month plus usageA hosted URL without local setup
Glama96,292Letter grades for licence, quality and maintenanceYes, with a gatewayFree to browse. Hosting rates are shown only inside a workspaceThe widest search
PulseMCPAbout 21,700Labels official providers, community builds and Anthropic referencesNoneFreeSeparating official from community
mcp.soNo total publishedCommunity submittedNoneFreeCasual browsing
Docker MCP Catalog300+Docker builds and signs local servers, with provenance and SBOM metadataLocal containers, plus some remote servicesFree to browse. Docker Desktop is paid at larger firmsTeams that run servers locally
modelcontextprotocol/servers7 reference serversKept by the MCP steering groupNoneFreeLearning how servers work

Each size comes from the directory's own page or API on that date. They change daily.

Official MCP Registry

The official MCP registry lives at registry.modelcontextprotocol.io. The MCP docs describe it as the official metadata repository for public MCP servers, backed by Anthropic, GitHub, PulseMCP and Microsoft.

It stores metadata and no code. Each entry points to a package on npm, PyPI or Docker Hub, or to a remote URL.

Its one check is on names. Server names use reverse DNS, such as io.github.username/server or com.example/server, and a publisher has to prove control of that GitHub account or domain. So a server under a company's domain was published by someone who controls that domain.

What it leaves out matters as much:

  • It does not scan code. The docs say security scanning is delegated to the package registries and to downstream directories.
  • It does not list private servers.
  • It is still in preview, and the docs warn that breaking changes or data resets may happen before general availability.
  • It is not built for end users. The docs say host apps should read a downstream marketplace, not the registry itself. Neither the site nor the API prints a total.

Use it to confirm a publisher. Browse somewhere else.

Smithery

Smithery is a registry plus hosting. Arcade.dev acquired it, announced on 5 August 2026. The site still runs and still offers a free sign-up.

The homepage says 25,079+ MCPs. Its public registry API returned 18,553 servers on 5 October 2026, and 190 of those carry the verified flag. That is roughly one in a hundred. The rest are yours to vet.

Smithery can host a server and handle OAuth for you, so you get a URL where you would otherwise install something locally. The Hobby plan is free with 50K RPCs a month. Pay as you Go is $10 a month with 100K RPCs. RPCs draw down the $10 credit, then cost $0.10 per 1,000.

One piece of history is worth knowing. In June 2025, GitGuardian researchers found a path traversal flaw in Smithery's build process that exposed credentials with access to more than 3,000 hosted apps. Smithery shipped a complete fix on 15 June 2025, two days after disclosure, and the researchers found no evidence of exploitation.

We compare the two products in PopMCP vs Smithery, and list other options in Smithery alternatives.

Glama

Glama had the largest list of the seven: 96,292 servers on 5 October 2026. It splits them into 39,817 remote, 34,584 local and 17,063 hybrid.

Each listing shows letter grades for licence, quality and maintenance, which makes a useful first filter. You can also narrow results to authors marked Official or Claimed.

Glama sells hosting with a gateway in front of each deployment, and runs an AI chat app with MCP support. Browsing is free. Hosting is billed on top of a workspace plan and metered by machine hours and egress, and the rate card is only visible inside a workspace.

Smithery vs Glama

SmitheryGlama
Listings on 5 October 202625,079+96,292
Quality signalVerified flag on 190 serversLetter grades on listings
HostingYes, with managed OAuthYes, with a gateway
Public pricingYesHosting rates only inside a workspace
Pick it ifYou want a hosted URL nowYou want the widest search

They do different jobs. Search on Glama, then run on Smithery if the server you picked is hosted there.

PulseMCP

PulseMCP listed about 21,700 servers on 5 October 2026, and its page title says the list is updated daily. It has no hosting.

Its best feature is the classification filter. You can show only Official Providers, only Community builds, or the Anthropic reference servers, and tick Remote Available on top.

Two things to know. A PulseMCP team member sits on the official registry's working group. And new submissions and listing changes were paused on 5 October 2026, while PulseMCP reworks how it ingests listings.

mcp.so

mcp.so prints no total. Its category pages carry counts, and the largest by far is "Other", with 10,559 listings on 5 October 2026. Developer Tools, the next largest, had 2,361. That tells you how much curation to expect.

Anyone can submit a server, and mcp.so hosts nothing. It is fine for browsing. Do your own vetting.

Docker MCP Catalog

Docker's catalog is small on purpose: 300+ servers, packaged as Docker images on Docker Hub.

  • Docker builds and signs every local server in the catalog. Servers are versioned with provenance and SBOM metadata.
  • Local servers run as isolated containers on your machine. The catalog also lists remote services such as GitHub, Notion and Linear.
  • Organizations can build a custom catalog to limit which servers staff can use.
  • Docker's docs mark the catalog as Beta.

Browsing is free. The MCP Toolkit that runs the servers is part of Docker Desktop, which is free for personal use, education, non-commercial open source and small businesses. A business with 250 or more employees, or $10 million or more in annual revenue, needs a paid subscription.

It is the pick for security-minded teams who are happy to run servers themselves.

GitHub: modelcontextprotocol/servers

This repo has about 91,000 stars, so people still land on it looking for a list. It has not been one for a while.

It now holds seven reference servers: Everything, Fetch, Filesystem, Git, Memory, Sequential Thinking and Time. Older ones, including GitHub, Slack and PostgreSQL, are archived. The README sends you to the official registry for a server list, and says the reference servers are teaching examples, not production software.

Read it to learn how servers are built. For vendor-run servers worth using, see the best MCP servers.

Where PopMCP fits

PopMCP is not a directory. You cannot browse community servers there or publish your own. It builds and hosts its own servers for 100+ business tools, such as Shopify, Klaviyo, GA4, Meta Ads, HubSpot and Xero.

The difference shows in a search. On 5 October 2026, Smithery's API returned 127 servers for "shopify". PopMCP has one Shopify server, built and maintained by PopMCP, and every connection is served from one URL, https://app.popmcp.com/mcp.

That narrows the vetting to one publisher. It does not remove it. How to choose an MCP provider has nine questions to ask, with our own answers, including the fact that PopMCP has no SOC 2 report.

How to vet an MCP server before installing

Run through this for any server you find in any directory.

  1. Check the publisher. Prefer the vendor itself. In the official registry, the namespace should match the vendor's domain or GitHub organization.
  2. Check it is maintained. Look for recent releases and for issues that get answers.
  3. Know where it runs. A local server runs with the same privileges as your AI client. A remote server means trusting a third party with access. Remote vs local MCP servers covers both.
  4. Look at what it asks for. Prefer OAuth over a pasted API key, and grant the smallest scopes that work.
  5. Read the tool list. Look for tools that delete, send or pay. Use a read-only mode if the server has one. In Claude, review each tool approval request and keep "Allow always" for tools you trust.
  6. Pin the version of a local server. With @latest in a config file, an update can change behaviour without you noticing.
  7. Watch for prompt injection. A web page or an email can carry hidden instructions. Be careful when one server reads untrusted content and another can write. See MCP security best practices.
  8. Plan the exit. Know where to remove the connector or end the OAuth session before you need to.

Frequently asked questions

What is the best MCP server directory?

It depends on the job. The official MCP Registry confirms who published a server. Glama has the most listings. Smithery hosts servers for you. The Docker MCP Catalog gives you signed images to run locally.

What is the official MCP registry?

It is the metadata registry run under the Model Context Protocol project at registry.modelcontextprotocol.io. It verifies that a publisher controls the GitHub account or domain in a server's name. It does not host servers or scan their code, and it is still in preview.

Is there a complete MCP server list?

No. Glama is the largest of the seven here, with 96,292 servers on 5 October 2026. Smithery's homepage says 25,079+ and PulseMCP lists about 21,700. The same server often appears in several directories, so the figures overlap.

Smithery vs Glama: which is better?

Glama has more listings and grades each one. Smithery has managed hosting, managed OAuth and public pricing. If you only need to find a server, start with Glama. If you want one running without a local install, check Smithery.

Are servers in MCP directories safe?

Not by default. Most listings come from third parties, and the official registry does not scan code. On Smithery, 190 of the 18,553 servers in its API carried the verified flag on 5 October 2026. Vet the publisher, the tools and the permissions before you connect a real account.

Can I publish my own MCP server?

Yes. Publish its metadata to the official registry under a namespace you can prove you own. The registry is designed for downstream directories to pull from. Docker accepts pull requests to its docker/mcp-registry repo. PulseMCP had paused new submissions as of 5 October 2026.

Who owns Smithery?

Arcade.dev. It announced the acquisition on 5 August 2026, and smithery.ai continues to run.

Sources

17 references, checked 5 October 2026
  1. Official MCP Registryregistry.modelcontextprotocol.io
  2. MCP Registry docs (preview status, namespace verification, security scanning, aggregators)modelcontextprotocol.io
  3. MCP Registry repo (working group members)github.com
  4. Smithery homepage (25,079+ MCPs, Arcade.dev notice)smithery.ai
  5. Smithery registry API (18,553 servers, 190 verified, 127 for "shopify", 5 October 2026)api.smithery.ai
  6. Smithery pricingsmithery.ai
  7. Arcade.dev, Smithery Is Now Part of Arcade.dev (5 August 2026)arcade.dev
  8. GitGuardian, Breaking MCP Server Hostingblog.gitguardian.com
  9. Glama MCP servers (96,292 servers, hosting split, grades)glama.ai
  10. Glama MCP hosting (gateway, billing)glama.ai
  11. PulseMCP server directorypulsemcp.com
  12. mcp.so servers (category counts)mcp.so
  13. Docker MCP Catalog docsdocs.docker.com
  14. Docker Desktop license termsdocs.docker.com
  15. modelcontextprotocol/serversgithub.com
  16. MCP security best practices (local server privileges)modelcontextprotocol.io
  17. Claude custom connectors (tool approval requests, prompt injection warning)support.claude.com