Give Claude Code access to explicitly allowed local folders.
mcp serversCommunity project91,000 repo starsRepo updated Oct 4, 2026
Connect Claude Code to files, browser automation, and current documentation.
3 selected entries
Showing 3 entries
Give Claude Code access to explicitly allowed local folders.
mcp serversCommunity project91,000 repo starsRepo updated Oct 4, 2026
Search current library documentation through the Context7 MCP service.
mcp serversCommunity project62,668 repo starsRepo updated Oct 3, 2026
Let Claude Code navigate and inspect real browser pages through Playwright.
mcp serversCommunity project37,807 repo starsRepo updated Sep 28, 2026
The Model Context Protocol lets Claude Code use tools supplied by an external server. A filesystem server can expose selected folders; a browser server can inspect pages; a documentation service can fetch current reference material. The protocol describes the connection, not the trustworthiness of a server. Read the maintainer’s capabilities and permissions before you add one.
Start from the capability your task lacks. Reading a documentation page, controlling a browser, and accessing a private database call for different servers and credentials. Compare the exposed tools with the actual task before enabling a large integration that gives access to unrelated systems.
The directory links to the maintainer so you can check supported transports and runtime requirements. A source repository is not itself an MCP endpoint. Use the documented package command or server URL, and distinguish a local process from a remote service that receives your requests.
For a local stdio server, `claude mcp add` registers the name and command that Claude Code will launch. Replace placeholder paths before running it. Remote servers may require a URL, login, or API key, so follow the source’s current setup steps. After installation, use Claude Code’s MCP manager to confirm the server connects and exposes only the tools you expect.
After registration, use /mcp to check connection status and complete any authentication the server requires. Try a small read operation first, then confirm the result came from the intended account or folder. Registration can succeed even when a missing runtime, expired credential, or unreachable endpoint prevents tools from working.
Document the setup scope when sharing instructions with teammates. A project configuration should describe what to install without embedding personal credentials. Keep credential values in the supported secret or environment mechanism, and let each person authorize access to their own account where the service requires it.
The JSON example below shows how a project can declare the reference filesystem server in `.mcp.json`. Restrict the allowed directory to a folder that you intend to share. For teams, project configuration can be reviewed in version control before others approve it. The example path is deliberately a placeholder and should never be copied unchanged.
Replace /path/to/allowed-folder with an absolute path to a small test directory. Create a harmless text fixture there and ask the server to list or read it. Do not broaden the allowed root to your whole home directory merely to resolve a path error; first compare the configuration with the folder you intended to expose.
The example uses npx to start the package and therefore needs Node.js and package access at startup. For a reproducible team setup, review the package version policy in the maintainer’s documentation. Merge the named server into an existing mcpServers object rather than deleting other working server entries.
.mcp.json · filesystem
{
"mcpServers": {
"filesystem": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-filesystem",
"/path/to/allowed-folder"
]
}
}
}MCP tools may read files, modify data, access authenticated services, or fetch untrusted content. Use least-privilege credentials and dedicated test accounts where possible. For filesystem access, limit roots; for browser access, consider the profile and logged-in pages; for hosted services, check what queries leave your machine. Remove servers you no longer need.
Separate read access from actions that create, update, or publish data. Try the integration with the least access that meets the task, and inspect tool requests before approving remote changes. A trusted server can still return untrusted web content, so retrieved text should not become an instruction to disclose credentials.
When removing an integration, consider both its Claude Code configuration and any credentials granted at the provider. Deleting a local entry prevents normal use from that configuration but does not necessarily revoke a remote token. Follow the provider’s account settings if the access is no longer needed.
Claude Code documentationA mod is a plugin with JavaScript or TypeScript function hooks running inside Claude Code. It can change the interface or how session events are handled. Skills and MCP servers are separate extension types.
This is an independent directory. Some entries link to Anthropic repositories; others come from community maintainers. Check the source of each entry before installing.
Extensions can read files, run commands, or connect to external services. Review the source and permissions, especially for hooks and MCP servers. A listing here is not a security guarantee.
They describe the linked GitHub repository. A plugin inside a repository does not have its own separate star count or update date.