State of the MCP Registry

An independent, measured snapshot of the official Model Context Protocol registry. Data current as of 2026-07-30 to 08-02. Numbers are from live probes, not estimates.

How much of it actually works

50% of the 10,716 active remote endpoints answer an anonymous MCP handshake.

ResultEndpointsShare
Answers anonymously5,34649.9%
Auth-gated (alive, needs a key)2,64324.7%
Genuinely broken (dead host / 404 / timeout)2,03919.0%
Other (redirects, 429, odd responses)6886.4%

The widely-repeated claim that "half of MCP is dead" traces to an April 2026 study of a broader, wild-crawled population. It does not describe the curated registry today: only 19% are genuinely dead.

Failure concentrates by hosting platform

Reachability tracks whether the hostname was ever meant to be permanent, not code quality.

HostEndpointsFailing
vercel.app1988%
workers.dev32724%
fly.dev6843%
onrender.com16452%
railway.app29766%
smithery.ai21788%
trycloudflare.com84100%

Protocol adoption

86% run the current protocol. The ecosystem is newer than it is abandoned.

Protocol versionServersShare
2025-06-1841186%
2024-11-054610%
2025-03-26143%
2025-11-2551%

The tool surface

8,639 tools across a random sample of 476 live servers (≈194,480+ ecosystem-wide). Only 18% declare an output contract — the rest return whatever they return. 46% of servers expose at least one tool pair an agent could plausibly confuse.

Read this section as describing anonymously-reachable servers, not the registry. These figures come from the pre-2026-08-02 sample, which was drawn from servers that answered anonymously on 7/30. See What our own sample was getting wrong below for how large that distortion is — substantial for reachability, small for the schema-declaration rates quoted here.

Contracts drift, and it clusters

4.4% of servers changed a tool contract within 36 hours; only 3 more in the next 36. A server can be perfectly up and no longer do what your agent learned it does.

Correction, 2026-08-02. This section previously read “a small set of servers that never stop moving, plus a frozen majority.” That over-claims what two 36-hour windows can show. Quiet across our windows is quiet; frozen is a much stronger claim, and we cannot distinguish a server that never moves from one that moved before our first snapshot. If drift is bursty per server rather than steady, 21-then-3 is the shape you would see even if no server were permanently stable. The numbers are unchanged; the interpretation was wrong. Raised by @anp2network.

What our own sample was getting wrong

Until 2026-08-02 every tool-surface figure here came from a sample drawn from servers that answered an anonymous handshake on 7/30 — a survivor set, presented as a sample of the registry. A reader (@anp2network) pushed on the sampling and we went looking. We now probe two cohorts every run and never merge them.

CONTROL
7/30 responders
CURRENT
live registry draw
Answers tools/list94%54%
Current protocol85%84%
Tools declaring outputSchema17.9%16.6%
Tools carrying annotations77.5%76.6%

The reachability gap is structural rather than decay: CONTROL was defined as servers that answer anonymously, so it cannot contain the auth-gated half of the registry. What we did not expect is that the same selection barely moves schema hygiene — 17.9% against 16.6%. Selection bias is not one number you apply to a dataset. It wrecks the claims that correlate with the selection criterion and leaves the rest standing, so "most tools declare no output contract" survives intact while "this describes the registry" did not.

When a server moves, does the new address work?

The registry deletes almost nothing — of 10,716 URLs censused on 7/30, exactly one was removed within three days. The rest of the churn is supersession: the same server name publishing a newer version at a different URL. It is tempting to read that as servers moving rather than dying. So we probed both ends of every superseded pair on 2026-08-03.

56% of superseded servers’ new endpoints answer tools/list — against 54% for a fresh random draw from the registry the same day. A migrated server is not measurably more likely to work than any other entry.

448 superseded servers, by nameServersShare
Old endpoint dead, successor live — genuine migration17238.4%
Dead at both ends18641.5%
Live at both ends7817.4%
Was live, successor dead122.7%

42% are dead at both ends. The registry shows a tidy migration to a live-looking entry and nothing at either address answers. Registry freshness is not a health signal: a server that just cut a release and updated its entry is a project someone touched recently, and that does not predict a working endpoint.

Correction, 2026-08-03. We previously wrote that what a naive diff reads as dead servers is mostly servers that moved. They moved in the registry; 42% of the time the place they moved to is dead too. “Superseded” describes a database row, not a server that went on working somewhere else. The claim that the registry deletes essentially nothing stands unchanged — that was about bookkeeping, and the bookkeeping is accurate.

One caveat we cannot design away: successors are resolved through the registry’s name field, which is authored by the same operator whose endpoint broke. The stronger witness is contract continuity — does the new endpoint serve the tool set the old one did — and we hold a pre-move contract for only 4 pairs, far too few to quote as a rate. Raised by @anp2network.

The data

Every figure above comes from files you can download and re-walk. A claim about our own carefulness is worth less than an input a stranger can check.

Correction: self-hosted template URLs (2026-08-03)

Self-hosted servers publish registry URLs the deployer fills in (https://{coder_hostname}/..., myPlatform.jfrog.github.io). Those entries are correct and are supposed to fail a probe — but our census counted them as broken. Strictly matched, 97 of the 2,039 entries we classed broken are templates (0.91% of the registry), so our broken figure is overstated by that much: 19.0% becomes 18.1%, and the headline "about a quarter unusable" becomes ~24.5%.

The error is small in aggregate and concentrated exactly where it hurts: templates are how self-hosted enterprise software ships, so the false positives cluster among the best-known projects. Fixed in the probe — templates now class as self_hosted_template, and auth codes (401/403/402/429) count as alive.

Check your own server, free

Paste the URL clients connect to. We send one real anonymous initialize from outside your network and tell you what a stranger sees — the same probe used for all 10,716 entries on this page. Nothing is stored.

Get your server audited

We run this probe suite against individual servers, by request, and write up what we find: reachability from outside, registry-entry health (active / latest / URL match), anonymous auth surface, tool-contract drift, and hosting durability. Written report within 48 hours; if nothing is wrong, the report says so. $19, one-time.

Order an audit — $19