DOCUMENTATION REVIEWED, NOT TESTED
MCP Server Setup: What 12 Official Docs Actually Say
By Ethan Halfhide · Updated October 1, 2026
BestMCPTools
MCP Server Setup: What 12 Official Docs Actually Say
bestmcptools.org
Last verified 2026-10-01
We read the official setup documentation for 12 widely used MCP servers and wrote down what each one actually says: transport, authentication, permissions, and which clients have documented setup examples. The underlying dataset links 93 of 96 tracked fields to a primary source; unknowns remain explicit. This is a documentation review, not hands-on testing and not a safety certification.
TL;DR, Quick Verdict
Official docs only, checked October 1, 2026. No server was installed, run, or compatibility-tested. 93 of 96 tracked fields have a primary-source link, including fields explicitly marked unknown. Nine server rows have no stated version requirement in the reviewed docs; three version fields have no per-field source link. Unknowns are marked explicitly, in the table or under What we don't know, instead of filled in. This page is evidence, not a ranking and not a security audit.
What this page is and isn't
This page records what vendors and maintainers publish about setting up their MCP servers. It exists so you can compare setup requirements on the vendors' own words instead of marketing copy. It is not a ranking, not a benchmark, not a compatibility test, and not a security review. "Documented" always means "the official documentation says this," nothing more.
How to read the table
Operation mode: whether the vendor runs the server for you (hosted) or your client launches it on your machine (local). Some offer both. Transport: the connection protocol the documentation names. Where a doc shows an HTTP endpoint without naming the MCP transport subtype, we say so. Authentication: how the doc says you prove identity: OAuth in a browser, an API key or token, or nothing beyond local access. Permission boundary: the levers the doc gives you to limit what the server can touch: scopes, read-only flags, project or directory restrictions. Client examples: which AI clients the doc shows setup steps for. A missing client means "not in the reviewed doc," not "unsupported." Version requirements: not a table column. A version requirement is recorded only where the doc states one, and those are listed under What we don't know.
What we don't know
Version requirements: most docs show setup steps without naming a version requirement. Three version requirements were found, and they are not the same kind: GitHub's README requires VS Code 1.101+ for remote MCP with OAuth (a client requirement); Heroku's local server requires Heroku CLI v10.8.1+ (a local server CLI requirement, not an MCP client version); and Chrome DevTools MCP's auto-connect feature needs Chrome 144+ (a browser requirement for that feature). Transport labels: Brave, Webflow, and ScreenshotOne document HTTP endpoints without naming the MCP transport subtype. Filesystem and Memory (reference) show command-based local configs, which imply stdio without labeling it. We record what the doc says, not what we infer. Regional and plan gaps documented by vendors: Postman EU has no OAuth, Intercom does not support AU-hosted workspaces, and Heroku notes Claude Enterprise/Team plans may restrict adding remote servers. Safety: a documented read-only option means the vendor publishes one, not that your installation is configured read-only. Nothing here is a security audit.
How this page was put together
Each server was researched from its official documentation on October 1, 2026: vendor documentation sites, official GitHub READMEs, and official developer portals. 93 of 96 tracked fields in the underlying dataset carry a primary-source link, including fields marked unknown; three unstated version fields have no per-field link. The Sources list below gives the primary sources for each row; the table itself does not link individual cells. No server was executed, no client compatibility test was run, and no package version was pinned.
Quick Comparison
| Server | Operation mode | Transport | Authentication | Permission boundary (documented) | Client setup examples |
|---|---|---|---|---|---|
| Supabase MCP | Hosted; local CLI/self-hosted subsets | Hosted Streamable HTTP | OAuth in browser; manual PAT option | project_ref scope, read_only=true, features= tool groups | Claude Code, Codex, Cursor, VS Code, Claude.ai connector |
| Brave Search MCP | Local | stdio default; HTTP option (subtype not labeled) | Brave Search API key; HTTP listener itself unauthenticated | API key scope; loopback bind by default | Claude Desktop, VS Code |
| GitHub MCP | Hosted remote or local binary/container | Remote HTTP MCP; local stdio | OAuth or PAT; host OAuth support varies | Token scopes, toolsets, org policies; --read-only overrides selected tools | VS Code 1.101+, Claude, Cursor guides |
| Filesystem (reference) | Local subprocess | Command-based local config (stdio implied, not labeled) | None beyond local process and OS access | Allowed-directory args or client Roots (Roots replace allowed dirs) | Claude Desktop, VS Code |
| Memory (reference) | Local subprocess | Command-based local config (stdio implied, not labeled) | None beyond local process access | Local memory file path (MEMORY_FILE_PATH) | Claude Desktop, VS Code |
| Postman MCP | Hosted remote or local package | Remote Streamable HTTP; local stdio | US remote OAuth or API key; EU remote/local API key only | Account/workspace permissions, region, Minimal/Code/Full tool configuration | Claude Code, Claude Desktop, Cursor, VS Code |
| Serena | Local | stdio default; Streamable HTTP option; legacy SSE discouraged | Local execution; HTTP mode binds localhost by default | Active project and context/toolset; one active project per HTTP instance | Claude Code, Claude Desktop, Codex, VS Code, others |
| Webflow MCP | Hosted remote | Remote MCP URL (subtype not labeled) | Browser OAuth; select sites and Workspaces | Authorized sites; Designer edits need MCP Bridge App open; not all API endpoints covered | Claude Desktop connector; Claude Code, Cursor named |
| Intercom MCP | Hosted remote (US/EU endpoints) | Streamable HTTP recommended; legacy SSE deprecated | OAuth recommended, or bearer API token | Required scopes; AU workspaces not supported | Guide-provided client configs |
| Heroku MCP | Hosted remote or local | Remote Streamable HTTP; local stdio | Remote OAuth 2.0; local CLI session or HEROKU_API_KEY | Account resource permissions; ops can change resources and incur cost | Cursor, VS Code remote; Claude Desktop, Cursor local |
| ScreenshotOne MCP | Hosted remote | Remote HTTP MCP (subtype not labeled) | OAuth in browser, revocable | Connected account; each tool call costs 1 credit per vendor page | Claude, Claude Code, ChatGPT, Codex, Cursor per vendor |
| Chrome DevTools MCP | Local server controlling Chrome | Local stdio; optional separate HTTP proxy | None for local server; attached Chrome session controls access | Browser data/session exposure; telemetry opt-out flags documented | Claude Code, Codex, Copilot CLI, Cursor, Gemini CLI |
Corrections
To report an error or suggest a source correction, email contact@bestmcptools.org. Include the server name, the field and a link to the official documentation.
Frequently Asked Questions
Is this a ranking of the best MCP servers?
No. These 12 are a cross-section of widely used vendor, official, and reference servers chosen for documentation coverage. The order is not a ranking and inclusion is not an endorsement.
Did you install or run any of these servers?
No. Every field comes from the server's official documentation, checked October 1, 2026. Nothing here is an executed setup or compatibility test.
Does a documented read-only option mean the server is safe?
No. It means the vendor publishes a read-only mode or flag. Whether your installation is actually read-only depends on your configuration.
What do "hosted" and "local" mean here?
"Hosted" means the vendor runs the server and you connect over HTTP. "Local" means your client launches it on your machine, usually over stdio. Several servers offer both.
Why are version requirements missing for most servers?
Because most reviewed setup docs do not state one. The three requirements we found are identified as client, CLI or browser requirements under What we don't know; other gaps stay explicit instead of being guessed.
How current is this?
Every field was checked on October 1, 2026, and the page shows that verified date. MCP docs change quickly, so treat the page as worth re-checking against the linked sources as it ages.
Sources
- 1. Supabase MCP (supabase.com docs)
- 1. Supabase MCP (GitHub: supabase/mcp)
- 2. Brave Search MCP (GitHub: brave/brave-search-mcp-server)
- 3. GitHub MCP (GitHub: github/github-mcp-server)
- 4. Filesystem, reference server (GitHub: modelcontextprotocol/servers)
- 5. Memory, reference server (GitHub README)
- 6. Postman MCP (GitHub: postmanlabs/postman-mcp-server)
- 7. Serena (GitHub: oraios/serena)
- 7. Serena (docs: running Serena)
- 8. Webflow MCP (developer docs: overview)
- 8. Webflow MCP (developer docs: FAQs)
- 9. Intercom MCP (developer docs)
- 10. Heroku MCP (Dev Center: remote MCP server)
- 10. Heroku MCP (Dev Center: MCP server)
- 11. ScreenshotOne MCP (vendor page)
- 12. Chrome DevTools MCP (GitHub: chromeDevTools/chrome-devtools-mcp)
- 12. Chrome DevTools MCP (Chrome for Developers blog)
About the author
Ethan Halfhide
Ethan Halfhide is an AI technologist who works with AI agents and Model Context Protocol integrations. He curates BestMCPTools' server directory, checking each server's documentation, supported clients and setup steps.