Docs · Updated 2026-10-03
How to choose an MCP server for your task
Choose an MCP server by the operation you need, the publisher you can identify, the client and permissions it requires, and a small test you can verify. Keep unresolved questions visible before connecting sensitive accounts or relying on its results.
Start with a specific outcome: “inspect this public page’s canonical tag” is easier to evaluate than “give my assistant more tools.” A directory listing supplies candidates. The publisher’s documentation and an observed tool result supply different kinds of evidence.
MCP server evaluation checklist
| Check | Evidence to collect | Decision it supports |
|---|---|---|
| Task fit | Exact operations, input fields, output fields and documented limits. | Can it complete your actual request? |
| Publisher | Publisher documentation, repository or package ownership, and the expected service domain. | Who operates or maintains the implementation? |
| Client support | Your client/version, transport and authentication method; recorded setup evidence where available. | Can your application connect to this server? |
| Permissions | Requested scopes, readable resources, available write operations and client approval controls. | Does the access match your task? |
| Data handling | Where arguments go, downstream services, storage and retention described by the operator. | Can you use the intended inputs with this deployment? |
| Operation and cost | Version/update information, service limits, provider credentials, fees and support route. | Can you operate it with your budget and requirements? |
| Acceptance test | A bounded task, expected result, observed response and independent comparison. | What has worked in your own environment? |
A missing field means “not confirmed.” Popularity, a recent release or a listing in a registry does not answer all these questions. ToolCargo’s MCP server directory contains a dated, partial registry snapshot; its third-party listings are publisher-provided and are not verified by ToolCargo.
Check the actual client and deployment
Inspect the exact remote URL or local package and version in the publisher’s instructions. Confirm that your client supports the stated transport and authentication method. Use local vs remote MCP servers to compare process location and reach; use client setup guides for ToolCargo’s documented and recorded client support.
Local execution can still contact external services. A remote connection can have a different operator or data path from the package you inspected. Review the specific deployment you plan to use.
Inspect tools and permissions separately
After you trust the intended connection enough to establish it, inspect the tool list in your client. Compare names, descriptions and input schemas with the operation you need. The official MCP tools specification defines tool discovery and calls; a successful connection does not prove that every operation will succeed.
Tool annotations such as read-only hints describe declared behavior. The specification says clients must treat annotations as untrusted unless they come from trusted servers. Check actual granted permissions and your client’s control over consequential tool calls; an annotation is not a permission boundary.
For authenticated deployments, review the intended service and scopes before approving access. The MCP security best practices discusses authorization risks including token passthrough. Keep service credentials in the appropriate provider/client configuration. Record permission names in your comparison, without copying credentials into the record.
Run a small acceptance test
- Pick an operation and input that you intend to share with this operator. Start with a public or disposable test resource.
- Write the expected behavior and the source you will compare with. Include units, dates or identifiers when they affect the answer.
- Make one bounded call and inspect the tool result, including errors and missing values. Connection success and an error-free tool result are separate checks.
- Compare the result with the original source. Record your client/version, server/package version where available, test date and remaining limitations.
This establishes what happened for that task and environment. It does not certify every tool, input, client, future release or security property.
Example: choosing a server for a page audit
Suppose the task is to inspect a public page’s canonical tag. ToolCargo’s Site Audit connector offers audit_page, which reads served HTML and reports technical findings. Its tool reference describes arguments and limits. It does not run page JavaScript, so choose a different verification method when the required evidence appears only after browser rendering.
A proposed first test is the reserved public demonstration page https://example.com/. Compare the tool’s reported canonical information with that page’s served HTML. Record the actual response; this guide does not present a new test result or score.
Public discovery at /mcp helps find candidates without an account. Executing this hosted audit requires ToolCargo authentication and the shared hosted-tool allowance. Review authentication and scopes and current plan limits before connecting. Finding a server’s connection metadata is a separate step from executing its tools.
Copy a candidate comparison record
Task and expected result:
Candidate server and publisher:
Exact URL, or package and version:
Client/version, transport and authentication:
Required tool and input fields:
Granted permission names:
Operator and downstream data handling:
Provider requirements, fees and limits:
Documentation links and dates:
Small test input and expected behavior:
Observed result and original-source comparison:
Decision and unresolved questions:Common questions
How do I know whether an MCP server is safe?
Assess the implementation, operator, deployment, granted access and your client’s controls for your task. Registry metadata and successful tests contribute evidence, but neither is a complete security review. Resolve important unknowns before expanding access or using sensitive inputs.
Should I choose the server with the most tools?
Compare the operations you need and the access they require. Additional tools can be useful, but their count does not prove fit, accuracy, compatibility or appropriate permissions.
Continue with public MCP discovery and search, getting started or connection diagnostics once you have a candidate and an acceptance task.