# The MCP servers connected to my editor, and the ones I actually use

> An honest inventory of the 22 MCP servers connected to my Cursor setup: the two I use every day, the ones that do one job, and the ones that just sit there.

Author: [Flavio Copes](https://flaviocopes.com/about/) | Published: 2026-09-28 | Topics: [AI](https://flaviocopes.com/tags/ai/) | Canonical: https://flaviocopes.com/mcp-servers-i-use/

My Cursor setup connects to 22 MCP servers when it starts. Ten come from entries in `~/.cursor/mcp.json`. The other twelve arrive through eight plugins I installed from the Cursor Marketplace.

I use two of them almost every day. A handful more do one specific job. The rest are connected because I tried them once, wrote about them, or taught them in a workshop, and never removed them.

This is the same kind of inventory I did for [the Cloudflare products I actually use](https://flaviocopes.com/cloudflare-products-i-use/). On September 16, 2026 I went through my config file and the plugins directory and wrote down what each server exposes, what it did for me, and whether it earns its place. If the protocol is new to you, [what is MCP](https://flaviocopes.com/what-is-mcp/) explains hosts, clients, servers and tools, and the free [MCP course](https://flaviocopes.com/courses/mcp/) goes deeper.

## Where the servers come from

Cursor reads MCP servers from two files. `~/.cursor/mcp.json` holds the ones available in every project. A `.cursor/mcp.json` inside a repository adds servers for that project only. The shape is the same in both.

A local server is a command Cursor starts for you, and the two talk over stdin and stdout. Secrets go in `env`. Cursor resolves `${env:NAME}` from your shell environment, so the token itself never has to sit in the file:

```json
{
  "mcpServers": {
    "paddle": {
      "command": "npx",
      "args": ["-y", "@paddle/paddle-mcp"],
      "env": {
        "PADDLE_API_KEY": "${env:PADDLE_API_KEY}"
      }
    }
  }
}
```

A remote server is a URL. Some need no authentication at all. Others want a header, and the same `${env:NAME}` trick works there:

```json
{
  "mcpServers": {
    "Astro docs": {
      "url": "https://mcp.docs.astro.build/mcp"
    },
    "some-service": {
      "url": "https://mcp.some-service.com/mcp",
      "headers": {
        "Authorization": "Bearer ${env:SOME_SERVICE_TOKEN}"
      }
    }
  }
}
```

Plugins are the second source. A Cursor plugin bundles skills, subagents and MCP servers, and installs from the Marketplace in one click, with an OAuth login when the service needs one. The Cloudflare plugin alone registers four servers. GitHub, X, Convex, Supabase, tldraw, Context7 and Dodo Payments register one or two each. I never wrote a line of JSON for any of them. That's part of why there are so many.

The same servers work in Codex. The desktop app lists them under Settings > Plugins > MCPs, the CLI adds one with `codex mcp add`, and the personal config lives in `~/.codex/config.toml`. I covered that side in [the complete guide to Codex](https://flaviocopes.com/codex/).

## Used all the time

Two servers get called in most sessions, and I rarely ask for them by name. Project rules do it for me.

## 1. Astro docs

This site runs on Astro 7. The upgrade in June 2026 changed a lot: a Rust compiler, Vite 8 with Rolldown, a dev server that goes to the background when a coding agent runs `npm run dev`. A model trained before that knows none of it, and an agent working from memory will write code for an older major version with full confidence.

The server has one tool, `search_astro_docs`. The agent sends a query and gets the matching pages of the official docs back. It needs no login and no token, only the `url` line you saw above.

I wrote a project rule that tells agents to use it for Astro 7 APIs and migration questions instead of guessing from training data. The repository's [`AGENTS.md`](https://flaviocopes.com/agents-md/) says the same. So the server gets called without me asking, every time an agent touches a layout, a content collection or `astro.config.mjs`.

If I could keep one server, it's this one.

## 2. Cloudflare docs

The Cloudflare plugin registers four remote servers: `cloudflare-docs`, `cloudflare-bindings`, `cloudflare-builds` and `cloudflare-observability`. It also installs nine skills, among them `wrangler`, `workers-best-practices` and `durable-objects`, that tell the agent to look things up in the docs instead of trusting what it remembers.

The docs server is the one I use. It has two tools, `search_cloudflare_documentation` and `migrate_pages_to_workers_guide`. This site deploys on Cloudflare Pages with Pages Functions, KV and R2, and I run another production app on Workers and D1. Whenever an agent needs a binding shape, a `wrangler.jsonc` field or a compatibility flag, it searches the docs and answers with a page, not a guess.

The other three need a Cloudflare login through OAuth. In my session they sit unauthenticated. I already have `wrangler` logged in on this Mac, and it does everything those servers would do, from creating a KV namespace to reading a Pages build log. I never got around to authorizing the MCP versions, and I haven't missed them.

## Used for one job

Each of these servers covers one task for me.

## 3. Context7

Context7 is a docs server for libraries that don't have their own. Two tools: `resolve-library-id` turns a package name into an ID, and `query-docs` pulls the relevant part of that library's documentation. It came in through a Marketplace plugin, remote, no token.

The job is any library that is not Astro and not Cloudflare, when I suspect the model is remembering an older major version. The two first-party servers above are better for their own products, so when the question is about Astro or Workers I go there first.

I keep it because it's generic. For the same reason it overlaps with everything else, and it's the first server I'd drop if every framework I use shipped its own.

## 4. Playwright

`@playwright/mcp` starts a headless Chromium and exposes 24 browser tools: `browser_navigate`, `browser_snapshot`, `browser_click`, `browser_take_screenshot`, `browser_evaluate` and so on. It runs locally through `npx @playwright/mcp@latest`.

The one job is screenshots of local pages when I change a layout on this site. The agent builds the site, runs `npx astro preview`, opens the page, takes a screenshot, and I look at it in the chat.

The browser is its own profile with no cookies, so anything behind a login is out, and when I need a logged-in web app I drive my own Chrome instead. The MCP browser also ignores `browser_resize` after navigation and stays around 800px wide. For real desktop and mobile viewports I use a standalone Node script with the Playwright library rather than the server.

I keep it for quick local checks and switch to the library when I need precision.

## 5. X

When something I'm looking into was announced on X, the source is a thread there. A plain HTTP fetch of an `x.com` URL returns 403, so a coding agent can't read it on its own.

The X plugin's server talks to X's API and reads posts by ID, searches, lists quote-posts and mentions, and reports the remaining balance with `get_usage_credits`. The API is paid per call, so checking the credits before a big read is part of the routine.

I paste a link, the agent fetches the post plus its replies and quote-posts, and I read them in the chat without opening the browser. It only reads. I have never used it to post anything.

## 6. Paddle, twice

Course purchases on this site go through Paddle. The purchase webhook adds each buyer to a Sendy list, and nothing removes them when they cancel or get a refund. So every so often I pull the list of cancelled and refunded buyers and prune the list by hand. That's what the Paddle server does for me.

There are two entries. `@paddle/paddle-mcp` runs locally and mirrors most of the Paddle Billing API, about 70 tools from `list_transactions` and `list_adjustments` to `create_adjustment`, which issues a refund. The second entry, `paddle-live`, is Paddle's hosted server at `https://mcp.paddle.com/mcp` with three tools: `search`, `execute` and `report_missing_tool`. Instead of one tool per endpoint, the agent searches the API surface and runs a call.

The gotcha is the write side. The local package reads a `PADDLE_MCP_TOOLS` setting that accepts `read-only`, `non-destructive` (the default) and `all`. For a job that only lists refunds, `read-only` is enough, and I'd rather the refund tool not exist in the session at all.

## 7. Convex

I built a paid membership starter with Astro SSR on Cloudflare Workers and Convex holding users, sessions, magic links and payments. I wrote it up in [how I built a paid membership site with Astro and Convex](https://flaviocopes.com/membership-site/).

The Convex plugin from the Marketplace installs seven skills, two subagents and one local server, started with `npx convex@latest mcp start`. Its tools read a deployment (`status`, `tables`, `data`, `functionSpec`, `logs`, `insights`), run code against it (`run`, `runOneoffQuery`), and manage environment variables (`envList`, `envGet`, `envSet`, `envRemove`).

That last group is the one to watch. `run` and `envSet` write to a real deployment. Cursor asks before every MCP tool call by default, and for a server like this I'd leave that on.

It stays connected while that project is alive.

## Connected, rarely opened

Each of the servers below is configured and loads at startup, and I can't point to a recent task it did for me.

### GitHub

Forty-four tools through GitHub's hosted server. I have `gh` logged in on this Mac, and `gh` wins every time. Turning off pull requests on one of my repos is one line, `gh api -X PATCH repos/flaviocopes/things-cli -F has_pull_requests=false`, and I review pull requests on the website. I haven't found a task where the MCP version was shorter than the CLI.

### Resend

The `resend-mcp` local server, over a hundred tools covering sending, broadcasts, contacts, domains, suppressions and webhooks. Resend delivers this site's transactional email and the magic links of the membership starter. I connected the server and can't name a single task it did. A server that can `send-email` and `send-broadcast` in one call, connected and idle, is the kind of entry I should remove.

### Railway

`@railway/mcp-server`. I taught "Using the Railway MCP" in the February 2026 AI Workshop cohort. Since then Railway folded the server into its CLI as `railway mcp`, and the npm package became a shim that launches it. In my session it failed to connect, which tells you how often I open it. I deploy on Cloudflare.

### Supabase

A remote server behind OAuth, not logged in. I compared it with the other platform plugins in [cloud platform plugins and skills for AI coding agents](https://flaviocopes.com/cloud-platform-plugins-ai-coding-agents/), and it has stayed logged out since.

### Polar Sandbox

Connected through `mcp-remote` to Polar's sandbox endpoint, with three tools: `search_tools`, `describe_tools` and `execute_tool`. StackPlan bills through Polar. This entry points at the sandbox, so it cannot touch real money, and the real billing work happens in the Polar dashboard and in code.

### Replit

A remote server that creates, updates and publishes Replit apps from a prompt. It's in the file, and I can't name a task it did for me.

### tldraw

An MCP App that returns a live canvas inside the chat instead of text. I spent time on it for [the tldraw deep dive](https://flaviocopes.com/tldraw/) and I like the idea. Outside that post it hasn't come up.

### Dodo Payments

A local plugin with two servers, `dodopayments-api` (`search_docs`, `execute`) and `dodo-knowledge` (`search_docs`). I track Dodo as a merchant of record on paymentprocessor.dev. The plugin is installed, and that's the whole story.

### Stitch

Google's UI design tool has an MCP endpoint, and the tool was part of the April 2026 AI Workshop curriculum. The entry is in my file. In my current session it doesn't even list any tools.

## What makes a server worth keeping

Docs servers for fast-moving frameworks beat training data. Astro and Cloudflare Workers change every month, and a model's training data stops months before you use it. A docs server needs no token, costs nothing, and the answer comes with a page I can open.

Anything that touches money or deletes things has to confirm. Cursor asks before each MCP tool call by default, but that's a client setting, and the server should enforce it too. The Paddle server can refund, the Resend server can broadcast to a list, the Convex server can change env vars on a deployment. When a package offers a read-only mode, use it. When it doesn't, Cursor lets you toggle the whole server off from the Customize panel until you need it.

A good CLI often beats an MCP server. An agent already has a shell. A CLI with a `--json` flag gives it structured output, works the same in a script or on a server, and adds nothing to the tool list in every conversation. `wrangler` beats three Cloudflare servers for me, `gh` beats the GitHub one, and Railway itself moved its MCP server into its CLI. [exe.dev](https://flaviocopes.com/exe-dev/) never built one: every command is `ssh exe.dev <command>` with `--json`, plus one line in `AGENTS.md`. When I built a tool for my own tasks I went the same way, so [Things CLI](https://flaviocopes.com/things-cli/) ships an agent skill and no MCP server, and [hey-cli](https://flaviocopes.com/hey-cli/) from 37signals does the same for email.

The tool list has a cost, too. The 22 servers in my setup add up to more than 300 tools, each with a description the client has to hand to the model. Half of them belong to servers I never open. Fewer servers means less noise for the agent and a shorter list of things that can go wrong. Half of this list should go.

A server is the right answer when the protocol gives you something a shell can't. A canvas drawn inside the chat, or a form the client shows before a billable call. It's also the pragmatic answer when a service has no CLI and you don't feel like writing one. I wrote about building one in [how to build an MCP server](https://flaviocopes.com/build-mcp-server/), and the free [Build with MCP](https://flaviocopes.com/courses/build-with-mcp/) course walks through a complete server from scratch.

## The one I wrote myself

The last entry in my `mcp.json` is `cloudflare-domains`, a local server I built. Cursor starts it with `node /Users/flaviocopes/dev/cloudflare-domain-mcp/dist/server.js`. It has four tools: `search_domains`, `check_domain_availability`, `quote_domain_purchase` and `purchase_domain`. Three of them only read. `purchase_domain` spends money, and the whole server exists to put a boundary around that one call.

I wrote it because I wanted an agent to help me find and buy domains without any chance of buying the wrong one. A purchase starts from a five-minute, single-use quote. The server rechecks availability and price right before asking, enforces a hard $20 cap on the full initial charge in integer cents, and then opens an MCP elicitation form where I approve one exact domain at one exact price. If the client doesn't support elicitation, the purchase is blocked, and there is no flag to skip the approval.

The Cloudflare token never enters the config file. The `env` block holds the account ID and the name of a macOS Keychain entry, and the server reads the token from the Keychain at startup.

I used it to buy `hostingpicker.dev` for $12.20, and I wrote up the boundary in [how to let an AI agent perform irreversible actions safely](https://flaviocopes.com/ai-agent-irreversible-actions-safely/). The code is MIT licensed at [github.com/flaviocopes/cloudflare-domains](https://github.com/flaviocopes/cloudflare-domains). It is the one server on this list where the protocol did something a CLI could not, which is show me a form at the exact moment a billable call was ready.
