Skip to content
ToolCargo

The MCP directory / Open to explore

MCP server directory.
Find your next tool.

Search 3,974 indexed servers from the official MCP Registry and selected vendor documentation. Find remote endpoints and local packages, inspect the publisher’s setup details, then connect in your AI client.

Where will your next task take you?

Free discovery · no account · no API key

Let your agent do the finding.

Paste into your AI agent
Read https://toolcargo.com/agents.txt, then find the MCP servers I need and help me connect them. Ask me what I want to do first.

Or add https://toolcargo.com/mcp as a Streamable HTTP MCP server. Discovery is free and needs no account.

Compare task fit, publisher, permissions and a small acceptance test with the MCP server selection guide.

Connect directly to official MCP servers

Vendor setup guides for your existing accounts. These connections run with the vendor; ToolCargo does not host them or supply their credentials.

Browse the remote MCP server directory →

Not sure which connection to choose? Read local vs remote MCP servers. Building a discovery workflow? See the MCP server search API reference.

PostgreSQL (hardened, read-only)

Close details

Read-only PostgreSQL over MCP. Writes refused at the parsed SQL, plus a READ ONLY transaction.

Directory identity: io.github.Eszetael/postgres-mcp-hardened · Version: 0.1.10

Publisher connection metadata
{
  "remotes": [],
  "packages": [
    {
      "registryType": "npm",
      "identifier": "postgres-mcp-hardened",
      "version": "0.1.10",
      "runtimeHint": "npx",
      "transport": {
        "type": "stdio"
      },
      "runtimeArguments": [
        {
          "isRequired": true,
          "value": "--stdio",
          "type": "positional"
        }
      ],
      "environmentVariables": [
        {
          "description": "Connection string for the role the server connects as. Use a role that cannot write — the server refuses writes twice, but a read-only role is the layer that does not depend on us being correct. `--print-setup-sql` prints the SQL that creates one.",
          "isRequired": true,
          "isSecret": true,
          "name": "DATABASE_URL"
        },
        {
          "description": "Server-side statement timeout, e.g. `5s`. A question that would pin the database is cancelled by PostgreSQL, not by hope.",
          "name": "MCP_STATEMENT_TIMEOUT"
        },
        {
          "description": "Comma-separated allowlist. A table off the list is refused by name, and hiding it inside a CTE, a view or a join does not help.",
          "name": "MCP_ALLOW_TABLES"
        },
        {
          "description": "Path to the tamper-evident audit log. Entries are chained by hash and survive a restart; `--verify-audit` checks the chain against an off-host anchor.",
          "name": "MCP_AUDIT_LOG"
        }
      ]
    },
    {
      "registryType": "oci",
      "identifier": "ghcr.io/eszetael/postgres-mcp-hardened:0.1.10",
      "transport": {
        "type": "streamable-http",
        "url": "http://localhost:8080/mcp"
      },
      "environmentVariables": [
        {
          "description": "Connection string for a role that cannot write.",
          "isRequired": true,
          "isSecret": true,
          "name": "DATABASE_URL"
        },
        {
          "description": "Address to bind, default 127.0.0.1:8080.",
          "name": "MCP_ADDR"
        }
      ]
    }
  ]
}

Remote URLs go into your client's MCP settings. Local packages need a compatible runtime. Check required headers, environment variables, permissions and provider costs before setup.

Publisher repository ↗

3,974 results

Index updated 2026-10-02

This directory combines dated registry listings and selected vendor-documentation entries. Documentation checks are not live account or client verification. Third-party servers run with their own providers, credentials and pricing. ToolCargo discovery supplies setup metadata; it does not run their tools. Explore ToolCargo's hosted connectors.