Model Context Protocol registry census: we called 1,100 listed servers | MCP Hunter

Statistics

We called 1,100 remote servers from the official Model Context Protocol registry. 13% did not answer.

Every MCP directory publishes a count. The official registry listed 23,828 servers when this edition opened, and the large catalogs list tens of thousands more. Counting a listing is not the same as reaching one. We called 1,100 of them, once each, and recorded what came back.

This is edition 2026-08, swept 20 August 2026. Each address was called exactly once. Nothing here describes what any server is doing now. This edition covered 9% of the 12,771 callable addresses in the frame. Endpoints are visited in a fixed pseudo-random order rather than alphabetically, so a partial sweep is a sample of the registry rather than a slice of one end of it.

What the Model Context Protocol registry is

The official MCP Registry lives at registry.modelcontextprotocol.io. Its own documentation calls it the official centralized metadata repository for publicly accessible MCP servers, owned by the MCP open-source community and backed by contributors including Anthropic, GitHub, PulseMCP and Microsoft. It is in preview, and its maintainers say breaking changes or data resets may occur before general availability.

It holds metadata, not code. Each entry is a server.json naming the server, its version and where to get it: a package on npm, PyPI or Docker Hub, or the address of a remote server. A maker lists one with the mcp-publisher CLI after proving they own its namespace: a name under io.github.<username>/ through a GitHub sign-in, or a reverse-DNS name such as com.example/ through a DNS or HTTP challenge.

That check establishes who published an entry. Whether the address in it answers is a separate question, and it is the one this census measured. The registry is built to be read by downstream directories that add curation on top of it, and the MCP directories comparison sets out what each of them adds.

What answered, and what did not

961 of the 1,100 addresses we called answered as an MCP server, either by listing their tools or by asking who we were. 139 did not answer as one.

What happened Endpoints Share
Connected 694 63.1%
Authorization required 263 23.9%
Protocol error 65 5.9%
Hostname did not resolve 42 3.8%
Unreachable 17 1.5%
Not an MCP endpoint 15 1.4%
Deprecated HTTP+SSE transport 4 0.4%

A refusal is not a failure. 263 endpoints (23.9%) answered by asking for credentials. That is a working server guarding itself, so it is counted as answering, not as dead. Reporting it the other way would be a claim we did not verify, and it is the largest single bucket here, so the choice moves the headline more than any other decision on this page.

Most of the registry cannot be called at all

10,630 of the 23,828 servers in the registry (44.6%) ship as an npm or PyPI package with no address. There is nothing to connect to, by design: they run on the machine of whoever installs them. We never execute one, so they are absent from every figure above and are reported here on their own denominator rather than folded into a share that would misdescribe both groups.

The servers that connected did not agree on a protocol revision

Across the 694 servers that completed a handshake, these are the revisions they negotiated with us.

Revision Servers
2025-11-25 382
2025-03-26 147
2024-11-05 82
2025-06-18 80
2026-07-28 3

The tool surfaces were small, with a long tail

The 694 servers that listed their tools exposed 10,718 in total. The median was 7, the smallest 1, and the largest 163. A tool surface sits in a client's context on every request, so the largest number here is a standing cost rather than a score.

How to read these numbers

Every figure above is one call, to one address, on one date. That supports some claims and not others, so here is the scope each number actually carries.

  • A result describes an address, not a project. A server behind geo-routing, a rate limit, or a deploy answers the same way as one that is gone, so the aggregate is worth publishing and a single endpoint is not. We name none.
  • "Asked for credentials" is a measurement, not a rating. We recorded which addresses wanted a token. Auditing an authorization implementation is a different job and a different claim.
  • The official registry is the frame. The large third-party catalogs list many times more servers, and any of them may hold entries the registry never saw.
  • Timings stay out of it. A serial sweep from one host measures our own network more than it measures anyone's server, so latency is recorded per call and aggregated nowhere.

Check your own server

The MCP connection tester runs exactly the check described above against one address and hands back a dated record you can share. The endpoints we hand-picked are a separate, smaller corpus with its own denominator, and what each directory's badge is derived from sets this measurement beside the labels other directories publish.

Built an MCP server? Launch it on the weekly board. We connect to it and publish what it answered, the same way as everything above.

Edition 2026-08: 1,100 addresses called once each, drawn from the 12,771 remote URLs the official registry listed on 20 August 2026.