Blog
3 min read

The Best MCP Servers for Coding (and How to Choose Safely)

The MCP servers worth installing for everyday coding with Claude Code, Cursor or VS Code: GitHub, Playwright, your database, docs lookup, error monitoring and more. What each is for, how to add one, and the safety rules that matter more than the list.

MCP servers give AI coding tools new abilities: reading your GitHub issues, clicking through your app in a browser, querying your database. There are thousands of them. Most people need four or five.

New to the idea? Start with What is MCP? and MCP vs API.

First: fewer is better

Every connected server adds its tool descriptions to the AI's context — on every message. Ten servers with many tools each can slow the AI down, cost more and make it pick the wrong tool. Add servers for things you do often, and remove ones you don't use. (Claude Code's /doctor will point out unused servers and their context cost.)

The servers worth knowing

Lets the AI read issues, open pull requests, review PRs, check Actions runs and search code across repositories. Probably the most useful single server for day-to-day work. GitHub runs an official hosted version. (GitHub MCP server guide)

Playwright — a real browser

Lets the AI open your app in a browser, click, type, fill forms and read what's on the page. Ideal for "check the signup flow works" or reproducing a UI bug. Made by Microsoft. (Playwright MCP guide)

Your database — Supabase, Postgres and others

Lets the AI inspect tables, run queries and (if you allow it) change schema. Supabase has an official server with a read-only mode. (Supabase MCP guide) For plain Postgres, use a server that supports a read-only connection — and point it at a development database, not production.

Documentation lookup

Servers that fetch current documentation for libraries help with the classic problem of the AI using an outdated API. Useful for fast-moving frameworks.

Error monitoring — Sentry and similar

Lets the AI pull the actual stack trace and context for a production error, rather than you copying and pasting. (Error monitoring for beginners)

Project management — Linear, Jira, Notion

Read the ticket you're working on, update status, link the PR. Handy if your team lives in one of these.

Design — Figma

Lets the AI read design files so it can build UI that matches. Results vary with how tidy the design file is.

How to add one to Claude Code

Remote (hosted) servers use a URL:

claude mcp add --transport http github https://api.githubcopilot.com/mcp/

Local servers run a command on your machine:

claude mcp add playwright npx @playwright/mcp@latest

Check what's connected with /mcp inside a session, or claude mcp list in your terminal. (Connecting MCP servers to Claude Code)

Scopes decide who gets the server: local (just you, this project — the default), project (shared through a committed .mcp.json), or user (you, every project).

Safety rules that matter more than the list

  1. Install from the source. Use the vendor's official server, or one with a well-known maintainer. An MCP server runs code on your machine or holds your credentials.
  2. Least privilege. Read-only modes, narrowly scoped tokens, a single project rather than your whole account. (Principle of least privilege)
  3. Never point a write-capable server at production data. An agent that can run SQL can delete a table. (How to stop an AI agent deleting your production database)
  4. Watch for prompt injection. Content the AI reads — an issue body, a web page, a database row — can contain instructions. Don't combine "reads untrusted content" and "can take destructive actions" without approvals. (Prompt injection)
  5. Keep tokens out of committed files. Use environment variables, not a token pasted into .mcp.json. (Hide API keys)

A sensible starter set

For a typical web app: GitHub + Playwright + your database (read-only). Add others when you find yourself copying information into the chat repeatedly — that's the signal a server would help.


EasySpawn runs Claude Code on a persistent server where your MCP servers stay connected between sessions, and your development database sits safely apart from production. See how it works or join the waitlist.

Related: Connecting MCP Servers to Claude Code · Securing MCP Servers · MCP vs API · Claude Code Plugins

Keep reading