Best MCP Tools for Building AI Agents (2026): SDKs, Servers, Clients and Gateways
The ten MCP tools worth shortlisting, sorted by which layer they occupy, and what the stateless 2026-07-28 protocol revision changed for each one.
Start here
If you are building an AI agent, you need exactly two MCP things and everything else on this page is optional. You need an agent runtime that acts as the MCP client, and you need one or more MCP servers exposing your tools. Pick the runtime by language: Mastra or the Vercel AI SDK for TypeScript, Pydantic AI or LangGraph for Python, the OpenAI Agents SDK if you are staying on OpenAI models and want the connection hosted for you. Build the servers with FastMCP in Python or the official SDK in TypeScript, Go, C# or Rust. Host them on Cloudflare Workers if they need to be remote. Put a gateway in front once you have more servers than one person can name.
That sequence is the whole answer, and it is buried in most MCP coverage because the words get used interchangeably. A server exposes tools. A client calls them, and in practice the client is your agent framework. An SDK or framework is what you write either side with. A host is the app the user touches, such as Claude, ChatGPT, VS Code or Cursor. A gateway sits in front of many servers and adds discovery, access control and auditing. A vendor describing its product as an MCP tool could mean any of those five, which is why this page sorts every entry by layer before comparing anything else.
What changed in MCP during 2026
Two things, and both matter for what you build with.
First, governance moved. MCP was contributed to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025, co-founded by Anthropic, Block and OpenAI with support from Google, Microsoft, AWS, Cloudflare and Bloomberg. MCP is no longer one company's protocol, which is the answer to the question every architecture review asks about adopting it.
Second, the protocol went stateless. The current revision is 2026-07-28, and it is the largest break MCP has had. The initialize handshake is gone. Protocol-level sessions and the Mcp-Session-Id header are gone from Streamable HTTP. SSE stream resumability is gone. Servers must now implement a server/discover RPC. Server-initiated requests such as roots/list, sampling/createMessage and elicitation/create are replaced by Multi Round-Trip Requests, where the server returns resultType: "input_required" and the client retries with the answers. ping and logging/setLevel were removed, and Roots, Sampling and Logging are formally deprecated. On the authorisation side, Dynamic Client Registration is deprecated in favour of Client ID Metadata Documents, and clients must now validate the iss parameter per RFC 9207 before redeeming an authorization code.
The reason for all of it is deployment: a stateless server sits behind an ordinary load balancer, and with method and tool names travelling in the Mcp-Method and Mcp-Name headers, a gateway can route and authorise a call without parsing the body. If your existing server assumed a session, it needs work. A new feature lifecycle policy now guarantees a minimum twelve-month deprecation window, so this should be the last upgrade that arrives without notice.
Where to read further
This page is a buying guide for the tool layer. For the deeper topics it deliberately does not repeat: MCP enterprise adoption and market trends, the hardening checklist in secure an MCP server, the authentication shift in Client ID Metadata Documents, the identity model in MCP server identity, and the current threat picture in MCP security.
Two comparisons sit next to this one and answer different questions. For orchestration frameworks judged on multi-agent patterns and RAG depth rather than MCP, see agentic AI frameworks compared. For the layer between your application and the model providers, which handles routing, caching, rate limits and observability and is routinely confused with an MCP gateway, see AI gateways compared.
Quick Comparison
| Tool | MCP layer | Best for | 2026-07-28 readiness | Language or runtime | Price |
|---|---|---|---|---|---|
| Official MCP SDKs | Server and client SDK | Spec-exact servers and clients in any Tier 1 language | Reference implementation; TypeScript, Python, Go and C# shipped support at release, Rust in beta | TypeScript, Python, C#, Go, Rust (Tier 1) | Free, open source |
| FastMCP | Server framework | Getting a Python MCP server working in an afternoon | Tracks the official Python SDK, whose high-level API it originated | Python | Free, open source |
| Mastra | Agent runtime (client and server) | TypeScript agents where MCP is the main tool integration | MCPClient and MCPServer are first-class; supports the MCP Apps extension | TypeScript | Free, open source; Mastra Cloud priced separately |
| LangChain / LangGraph | Agent runtime (client) | Largest ecosystem, durable stateful workflows | MCP reached through langchain-mcp-adapters rather than natively | Python, TypeScript | Free, open source; LangSmith priced separately |
| OpenAI Agents SDK | Agent runtime (client) | Letting OpenAI host the MCP connection for you | Supports hosted MCP, Streamable HTTP and stdio; SSE transport now deprecated upstream | Python, TypeScript | Framework free; OpenAI API usage billed |
| Pydantic AI | Agent runtime (client) | Type-safe Python agents with a small API surface | MCP client support with validation on tool arguments and results | Python | Free, open source; Logfire priced separately |
| Vercel AI SDK | Agent runtime (client) | Chat agents wired into a Next.js or React front end | MCP via the SDK's MCP package; streaming UX is the differentiator | TypeScript | Free, open source; Vercel hosting separate |
| Cloudflare Workers and Agents | Hosting for remote servers | Standing up a remote MCP server with OAuth quickly | Streamable HTTP with OAuth authorization for remote connections | TypeScript on Workers | Cloudflare does not publish MCP-specific pricing; Workers platform rates apply |
| Prefect Horizon | Hosted gateway and registry | Governing many MCP servers across teams | Registry, tool-level RBAC and audit logging over any spec-compliant server | Any (gateway); FastMCP for deploys | Free for personal projects; enterprise pricing not published |
| Docker MCP Toolkit | Local runtime and catalog | Running third-party servers sandboxed on a laptop | Containerised servers with restricted privileges, network and resources | Any (containerised) | Included in Docker Desktop 4.62+; MCP Gateway is invite-only |
Official MCP SDKs
- MCP layer
- Server and client SDK
- Best for
- Spec-exact servers and clients in any Tier 1 language
- 2026-07-28 readiness
- Reference implementation; TypeScript, Python, Go and C# shipped support at release, Rust in beta
- Language or runtime
- TypeScript, Python, C#, Go, Rust (Tier 1)
- Price
- Free, open source
FastMCP
- MCP layer
- Server framework
- Best for
- Getting a Python MCP server working in an afternoon
- 2026-07-28 readiness
- Tracks the official Python SDK, whose high-level API it originated
- Language or runtime
- Python
- Price
- Free, open source
Mastra
- MCP layer
- Agent runtime (client and server)
- Best for
- TypeScript agents where MCP is the main tool integration
- 2026-07-28 readiness
- MCPClient and MCPServer are first-class; supports the MCP Apps extension
- Language or runtime
- TypeScript
- Price
- Free, open source; Mastra Cloud priced separately
LangChain / LangGraph
- MCP layer
- Agent runtime (client)
- Best for
- Largest ecosystem, durable stateful workflows
- 2026-07-28 readiness
- MCP reached through langchain-mcp-adapters rather than natively
- Language or runtime
- Python, TypeScript
- Price
- Free, open source; LangSmith priced separately
OpenAI Agents SDK
- MCP layer
- Agent runtime (client)
- Best for
- Letting OpenAI host the MCP connection for you
- 2026-07-28 readiness
- Supports hosted MCP, Streamable HTTP and stdio; SSE transport now deprecated upstream
- Language or runtime
- Python, TypeScript
- Price
- Framework free; OpenAI API usage billed
Pydantic AI
- MCP layer
- Agent runtime (client)
- Best for
- Type-safe Python agents with a small API surface
- 2026-07-28 readiness
- MCP client support with validation on tool arguments and results
- Language or runtime
- Python
- Price
- Free, open source; Logfire priced separately
Vercel AI SDK
- MCP layer
- Agent runtime (client)
- Best for
- Chat agents wired into a Next.js or React front end
- 2026-07-28 readiness
- MCP via the SDK's MCP package; streaming UX is the differentiator
- Language or runtime
- TypeScript
- Price
- Free, open source; Vercel hosting separate
Cloudflare Workers and Agents
- MCP layer
- Hosting for remote servers
- Best for
- Standing up a remote MCP server with OAuth quickly
- 2026-07-28 readiness
- Streamable HTTP with OAuth authorization for remote connections
- Language or runtime
- TypeScript on Workers
- Price
- Cloudflare does not publish MCP-specific pricing; Workers platform rates apply
Prefect Horizon
- MCP layer
- Hosted gateway and registry
- Best for
- Governing many MCP servers across teams
- 2026-07-28 readiness
- Registry, tool-level RBAC and audit logging over any spec-compliant server
- Language or runtime
- Any (gateway); FastMCP for deploys
- Price
- Free for personal projects; enterprise pricing not published
Docker MCP Toolkit
- MCP layer
- Local runtime and catalog
- Best for
- Running third-party servers sandboxed on a laptop
- 2026-07-28 readiness
- Containerised servers with restricted privileges, network and resources
- Language or runtime
- Any (containerised)
- Price
- Included in Docker Desktop 4.62+; MCP Gateway is invite-only
Official MCP SDKs
Best OverallBest for: Building a server or client that is exactly on spec, in the language you already use
“The official SDKs are the starting point for anything you intend to run in production, and their status changed in a way worth knowing: MCP is no longer an Anthropic project. It was contributed to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025, alongside Block's goose and OpenAI's AGENTS.md. The SDKs are now a vendor-neutral standard implementation rather than one company's reference code.”
Pros
- Five Tier 1 SDKs cover TypeScript, Python, C#, Go and Rust, with Java and Ruby at Tier 2 and Swift, PHP and Kotlin at Tier 3
- New protocol features land here first, so building against the SDK insulates you from framework-specific abstractions going stale
- Governance now sits with the Agentic AI Foundation under the Linux Foundation, which removes single-vendor risk from the dependency
Cons
- Lower level than an agent runtime; you assemble the agent loop yourself or put a framework on top within the first sprint
- Documentation is written as a protocol specification, so application patterns have to be inferred rather than copied
What the 2026-07-28 revision changed
This is the largest revision MCP has had. The protocol is now stateless: the initialize and notifications/initialized handshake is removed, and every request carries its own protocol version and client capabilities in _meta. Servers must implement a new server/discover RPC that returns supported versions, capabilities and identity in one call. Streamable HTTP lost protocol-level sessions and the Mcp-Session-Id header, and lost SSE stream resumability, so a broken stream means re-issuing the request. Server-initiated requests such as roots/list, sampling/createMessage and elicitation/create are replaced by Multi Round-Trip Requests, where a server returns a result with resultType input_required and the client retries with the answers. Tasks moved out of the core protocol into an official extension.
Why it went stateless
The stated reason is deployment reality. Without sessions and handshakes, an MCP server sits behind an ordinary load balancer and scales horizontally like any HTTP service. Method and tool names now travel in the Mcp-Method and Mcp-Name headers, so a gateway can route and authorise without parsing the JSON body. List results carry ttlMs and cacheScope hints so clients and shared intermediaries can cache them. Read together, those three changes are the protocol conceding that most real MCP traffic goes through infrastructure that was never going to hold a stateful socket open.
Authorisation, which is where most teams get hurt
The authorisation section hardened in the same revision. Authorization servers should include the iss parameter per RFC 9207 and clients must validate it before redeeming an authorization code. Client credentials are now explicitly bound to the issuer that minted them, so they must be keyed by issuer and must not be reused against a different authorization server. Most significantly, OAuth 2.0 Dynamic Client Registration is deprecated in favour of Client ID Metadata Documents, remaining available only for backwards compatibility. If you are building an MCP server behind a login, read that section before writing any code.
Free, open source
FastMCP
Best Open SourceBest for: Writing a Python MCP server quickly without hand-rolling protocol plumbing
“FastMCP is the most-used way to build an MCP server in Python, and its high-level API is the one that was folded into the official Python SDK in 2024. It remains maintained as a standalone framework with a wider feature surface than the SDK alone, covering servers, clients and interactive applications through one Python API with validated schemas.”
Pros
- Decorator-style API turns ordinary Python functions into MCP tools with schemas derived from type hints, which is the fastest credible path to a working server
- Covers client construction and interactive applications too, so a single dependency handles both ends during development
- Prefect, which maintains it, states FastMCP powers around 70% of MCP servers worldwide at roughly 49 million downloads a month, so examples and answers are easy to find
Cons
- Python only, so a polyglot organisation still needs the official SDKs for its other languages
- The adoption and market-share figures quoted for it come from the vendor that maintains it, not from an independent count
Why it beats the raw SDK for a first server
Most internal MCP servers are a thin wrapper over an existing API or database. FastMCP reduces that to declaring functions and letting the framework derive the tool schema, handle the transport and manage the protocol layer. The difference is measured in hours for a first server, and the output is still a spec-compliant server any client can call. That is the whole reason it dominates the Python side of this ecosystem.
The commercial path
FastMCP is maintained by Prefect, which also sells Horizon, an enterprise MCP platform that deploys FastMCP projects from GitHub to a production URL. That relationship is worth knowing when reading FastMCP's own adoption claims, and it is also genuinely useful. The open framework and the managed deployment target are built by the same people, so the path from prototype to governed deployment is short.
Free, open source; Prefect Horizon is the commercial gateway built by the same team
Mastra
Runner UpBest for: TypeScript agents where MCP servers are the primary tool integration
“Mastra is the agent runtime that treats MCP as a native concept rather than an adapter. MCPClient connects agents to external servers over HTTP or local commands, including OAuth-protected ones through browser-based authorisation, and MCPServer exposes Mastra agents, tools, workflows, prompts and resources back out to any MCP-compatible system. Being bidirectional in one framework is unusual and it is the reason Mastra sits this high.”
Pros
- MCPClient and MCPServer are first-class primitives, so connecting to a server and publishing one are both idiomatic rather than integration work
- Supports tool approval workflows for sensitive operations and OAuth-protected servers, which is the pair of features enterprise reviews always ask about
- MCPServer supports the MCP Apps extension, so a server can ship an interactive HTML interface that runs inside the AI client
Cons
- TypeScript only, so Python teams need a different runtime
- Mastra does not state in its MCP documentation which protocol revision it implements, so confirm against your target clients before committing
Client and server in one framework
MCPClient handles multiple servers with different authentication methods, loads tools either as static configuration or as runtime toolsets, and supports approval gates before sensitive tool calls run. MCPServer goes the other direction, exposing Mastra agents, tools, workflows, prompts and resources over stdio for local packages run through npx, or over HTTP with optional OAuth middleware. Very few frameworks do both well, and the ones that do not force you to run two stacks.
MCP Apps, and why it matters
MCP Apps became an official extension in the 2026 revision, alongside Tasks and Enterprise Managed Authorization. It lets a server ship an interactive interface that renders inside the AI client rather than returning text for the model to describe. Mastra's MCPServer supports it. For anything where the right answer is a form, a chart or a confirmation dialog rather than a paragraph, that is a materially better interaction than tool output the model has to narrate.
Free, open source; Mastra Cloud for managed deployment at separately published rates
LangChain / LangGraph
Best ValueBest for: The widest ecosystem, and durable long-running agent workflows
“LangChain is still the most-adopted agent stack, and LangGraph is the part you should actually deploy. The graph model gives durable execution with checkpointing, human-in-the-loop pause and resume, and clean multi-agent state. MCP arrives through langchain-mcp-adapters rather than as a native primitive, which is fine in practice and one more moving part to keep current across a protocol revision.”
Pros
- Largest integration surface of any agent framework, which is the deciding factor when you need a specific connector today rather than next sprint
- LangGraph gives durable stateful workflows with checkpointing, so an agent survives a process restart and can pause for a human for hours
- LangSmith tracing is the most complete observability story available to a LangChain deployment
Cons
- MCP support is an adapter package, so protocol changes reach you on the adapter maintainers' schedule rather than the SDK's
- API churn across major versions has repeatedly cost production teams upgrade work, which is the well-known price of the ecosystem breadth
LangGraph is the production target
The original AgentExecutor is not what you should ship. LangGraph's graph model supports durable execution with checkpointing so a run resumes after a crash, human-in-the-loop interruption, structured multi-agent orchestration and explicit state. For any agent that might pause and continue later, that durability is a selection criterion rather than a nicety, and it is the thing LangChain has that most of the newer frameworks do not.
Where the MCP adapter fits
langchain-mcp-adapters bridges LangChain tools to any MCP server, so a tool published once is reachable from a LangChain agent without per-tool integration code. That is exactly the problem MCP exists to solve. The caveat is layering: your agent depends on LangChain, which depends on the adapter, which depends on the SDK, which implements the protocol. Every one of those has its own release cadence.
Free, open source; LangSmith observability priced separately by trace volume
OpenAI Agents SDK
Honorable MentionBest for: Teams on OpenAI models that want the MCP connection hosted for them
“The OpenAI Agents SDK has the broadest set of MCP connection options of any runtime here, and one of them is genuinely distinctive. HostedMCPTool pushes tool listing and invocation into OpenAI's infrastructure through the Responses API, so your process never opens a connection to the MCP server at all. That removes a whole class of networking and deployment work, in exchange for the obvious dependency.”
Pros
- Five connection modes cover hosted MCP, Streamable HTTP, SSE, stdio, and a MCPServerManager that connects several servers and tracks failures
- Hosted MCP means no inbound connection management, no transport tuning and no local process supervision for the server side
- Tool filtering and approval policies are built in, which is the control enterprises ask for before letting an agent call anything sensitive
Cons
- Hosted MCP tools only work with OpenAI models that support the Responses API's hosted MCP integration, so the convenience is provider-specific
- The SDK adapts across a wide range of MCP Python SDK versions, which is helpful for compatibility and makes it harder to know exactly which protocol behaviour you are getting
Five ways to connect, and when to use each
HostedMCPTool hands the whole connection to OpenAI. MCPServerStreamableHttp is the right default when you control the network and want low latency. MCPServerSse exists for older servers and should not be chosen for new work. MCPServerStdio spawns a local subprocess and closes the pipes when the context manager exits, which is ideal for prototypes and command-line servers. MCPServerManager connects several servers up front, exposes the ones that connected and records the ones that failed, which is the behaviour you want in production.
Caching and approval
The SDK supports caching list_tools results, which matters more now that the protocol added ttlMs and cacheScope hints to list responses for exactly this purpose. It also supports tool filtering and approval policies so a sensitive tool requires an explicit decision before it runs. Turn both on: caching for cost and latency, approval for the tools whose blast radius you would have to explain afterwards.
Framework free; OpenAI API usage billed at model rates
Pydantic AI
Honorable MentionBest for: Python teams that want type safety and a small, stable API
“Pydantic AI applies the Pydantic team's design discipline to agent code. Tool definitions are Pydantic models, tool arguments and results are validated, and structured model output is checked against the expected schema. For a Python team that would rather have a small stable surface than the largest ecosystem, it is the most appealing alternative to LangChain.”
Pros
- Validation on tool arguments and tool results catches integration bugs at development time instead of in production traces
- Small focused API that has stayed stable across versions, which is the specific thing LangChain users complain about not having
- Provider-neutral across OpenAI, Anthropic, Google and others, so model choice stays a configuration decision
Cons
- Ecosystem of prebuilt tools and community examples is materially smaller than LangChain's
- Python only, and lighter than LangGraph or Mastra for complex multi-agent orchestration
Type safety as an MCP strategy
MCP tools are remote functions defined by someone else, often another team. Validating their arguments and their responses at the boundary is exactly the right instinct, because the failure mode of an agent calling a changed tool is a plausible wrong answer rather than an exception. Pydantic AI makes that validation the default rather than something you remember to add.
Multi-provider without lock-in
Support spans OpenAI, Anthropic, Google, Groq, Mistral and local models through one interface, so switching providers is configuration rather than a rewrite. Combined with MCP handling the tool layer, that leaves very little of an agent tied to any single vendor, which is the strongest architectural argument for this combination.
Free, open source; Logfire observability priced separately
Vercel AI SDK
Honorable MentionBest for: Chat agents that live inside a Next.js or React front end
“The Vercel AI SDK is the cleanest path from an MCP server to a streaming chat interface a user can actually use. Its React hooks and streaming primitives produce token-by-token rendering with very little application code, and its provider-neutral packages keep the model choice open. It is a front-end framework with agent capability, not an agent runtime with a UI.”
Pros
- Streaming UX primitives and chat hooks are the best developer experience available for a user-facing agent interface
- Provider-neutral across OpenAI, Anthropic, Google and others through the same streaming interface
- MCP tool integration slots into the same tool-calling model as any other tool, so there is no separate mental model to learn
Cons
- Complex multi-agent orchestration and long-running workflows are awkward fits for a front-end-shaped SDK
- Workflow durability and checkpointing are not first-class, so stateful agents need a second tool behind it
Streaming chat, done properly
The SDK's hooks and streaming primitives handle partial responses, tool call rendering, and error states that are tedious to build by hand. For a consumer-facing or internal chat product on Next.js, that is most of the interface work. Pair it with a proper agent runtime as soon as the logic behind the chat stops being a single turn with tools.
Free, open source; Vercel hosting billed separately
Cloudflare Workers and Agents
FastestBest for: Standing up a remote MCP server with OAuth without running infrastructure
“Cloudflare is the fastest route from a local stdio server to a remote one that other people can actually connect to. Its agents documentation covers building and deploying remote MCP servers on Workers over Streamable HTTP, with OAuth for authorising client access to resources on a user's account. That combination, remote transport plus an authorisation story, is the step most internal MCP projects stall on.”
Pros
- Deploys a remote MCP server on Workers without provisioning or operating any servers of your own
- Documents OAuth authorisation for remote connections, which is the part teams most often postpone and then regret
- Edge deployment suits the newly stateless protocol well, since there is no session affinity left to preserve
Cons
- Cloudflare does not publish MCP-specific pricing, so cost has to be modelled from the underlying Workers platform rates
- TypeScript on Workers, with the runtime constraints that implies, so heavy native dependencies do not travel
Local to remote is the real migration
Almost every MCP project starts with a stdio server on a developer laptop, and almost every one of them eventually has to become a remote server other people and other clients can reach. That transition brings transport, authentication, authorisation, deployment and scaling all at once. Hosting on Workers collapses most of it, which is why this belongs on a list of MCP tools even though it is not an MCP framework.
Why statelessness makes this easier
The 2026-07-28 revision removed protocol-level sessions and the Mcp-Session-Id header specifically so servers could sit behind ordinary load balancers and scale horizontally. An edge platform that spreads requests across many isolates is exactly the deployment shape that used to fight the protocol and now matches it.
Cloudflare does not publish MCP-specific pricing; the underlying Workers platform rates apply
Prefect Horizon
Best for EnterpriseBest for: Governing many MCP servers across many teams
“Horizon is the enterprise answer to the problem that shows up around the tenth MCP server: nobody knows which servers exist, who owns them, or which tools an agent is allowed to call. It combines deployment from GitHub, a registry of internal and third-party servers with ownership tracking, tool-level role-based access control with audit logging, and remix servers that assemble tools from several sources into one endpoint per team.”
Pros
- Tool-level RBAC and audit logging are the controls a security review actually asks for, and they apply to any spec-compliant server, not only FastMCP ones
- Integrates with identity providers including Okta, Microsoft Entra ID and Google Workspace, so access is anchored in existing corporate identity
- Remix servers let each team get one endpoint composed from several upstream servers, which avoids the client-side config sprawl that kills adoption
Cons
- Enterprise pricing is not published, so the cost of the governance layer cannot be compared against alternatives without a sales conversation
- It is a platform commitment, and the registry and access model become load-bearing once teams depend on them
The problem it exists to solve
MCP made it cheap to expose tools, which means organisations end up with many servers faster than they expect. The questions that follow are governance questions: which servers exist, who owns each one, which tools can which agent call, and where is the record of what was called. A registry plus tool-level RBAC plus audit logging answers all four in one place, and doing it per-client does not scale past a handful of teams.
Gateway as a protocol beneficiary
The 2026 revision was partly designed for this layer. Requiring Mcp-Method and Mcp-Name headers on Streamable HTTP POSTs lets a gateway route and authorise a call without parsing the JSON body. cacheScope on list results tells a shared intermediary whether it may cache a response at all. Gateways were previously working against the protocol; they are now working with it.
Free for personal projects; enterprise pricing not published
Docker MCP Toolkit
Best Free OptionBest for: Running third-party MCP servers on a developer machine without trusting them
“The Docker MCP Toolkit is the sanest default for the thing most developers actually do first, which is running someone else's MCP server locally. It is a management interface in Docker Desktop 4.62 and later that sets up, manages and runs containerised MCP servers and connects them to clients including Claude, Cursor and VS Code. The value is isolation, not features.”
Pros
- Runs each server in an isolated container with restricted privileges, network access and resource usage, instead of as a trusted process on your machine
- Included in Docker Desktop rather than sold separately, so the security improvement costs nothing to adopt
- Connects to Claude Desktop, VS Code, Cursor and other MCP clients from one place, which removes hand-edited config files per client
Cons
- Docker does not publish a catalog size, so breadth of available servers has to be checked against your own needs
- The separately branded MCP Gateway, with centralised credentials and call tracing, is invite-only under Docker AI Governance and requires contacting sales
Why sandboxing third-party servers is not paranoid
An MCP server is arbitrary code that an AI client will call with arguments a model chose. Running an unfamiliar one directly on a development machine gives it your filesystem, your network and your credentials. Containerising it with restricted privileges, network access and resource limits turns a broad trust decision into a bounded one, and costs a few seconds of setup. This is the lowest-effort security improvement available anywhere on this page.
Included in Docker Desktop 4.62 and later; the MCP Gateway is invite-only under Docker AI Governance
Which One Should You Pick?
| Use Case | Our Recommendation |
|---|---|
| I want to build an AI agent and I do not know which of these I need | You need two things, not one: an agent runtime that acts as the MCP client, and one or more MCP servers that expose your tools. Pick the runtime by language, Mastra or the Vercel AI SDK for TypeScript, Pydantic AI or LangGraph for Python. Build the servers with FastMCP in Python or the official TypeScript SDK. Everything else on this page is hosting, governance or isolation for those two pieces. |
| Expose an internal API or database to AI agents | FastMCP if the team writes Python, the official SDK for the language otherwise. Build it as a server, not as a plugin for one framework, because that is the entire point of the protocol: publish once and any compliant client can call it. Target the 2026-07-28 revision, and read the authorisation section before wiring up any login-protected resource. |
| Take a working local MCP server and make it reachable by other people | Cloudflare Workers with the Agents documentation is the shortest route, since Streamable HTTP and OAuth authorisation for remote connections are both covered. Do not carry stdio assumptions across. Model the cost from Workers platform rates, because Cloudflare does not publish MCP-specific pricing. |
| Production TypeScript agent where MCP servers are the main tool source | Mastra. MCPClient and MCPServer are first-class, tool approval gates and OAuth-protected servers are supported, and MCPServer can ship an MCP Apps interface that renders inside the client. Confirm which protocol revision your build targets against your intended clients, because Mastra does not state it in its MCP documentation. |
| Type-safe Python agent that must not silently accept malformed tool output | Pydantic AI. Tool arguments and results are validated against Pydantic models, which is the correct posture when the tools are remote functions maintained by other teams. Watch for friction with servers that exploit the loosened schema rules in the current revision, which permits any JSON Schema 2020-12 keywords and any JSON value in structuredContent. |
| Agent that pauses for hours waiting on a human and must resume | LangGraph. Durable execution with checkpointing and human-in-the-loop interruption are its distinguishing features and most alternatives here do not match them. Note that the protocol's own answer to mid-call human input changed: server-initiated requests are replaced by Multi Round-Trip Requests, where the server returns resultType input_required and the client retries with the answers. |
| We are on OpenAI models and want the least infrastructure possible | OpenAI Agents SDK with HostedMCPTool, which pushes tool listing and invocation into OpenAI's infrastructure so your process never connects to the server. Accept that this path is specific to OpenAI models supporting the Responses API's hosted MCP integration, and keep a Streamable HTTP fallback in mind if provider optionality ever matters. |
| Twenty MCP servers across five teams and nobody knows who owns what | Prefect Horizon. A registry with ownership tracking, tool-level RBAC, audit logging and remix servers that compose one endpoint per team is the shape of the answer. Get the pricing in writing early, since enterprise rates are not published, and note that Horizon works with any spec-compliant server rather than only FastMCP ones. |
| A developer wants to try an MCP server they found online | Docker MCP Toolkit, included in Docker Desktop 4.62 and later. It runs the server in a container with restricted privileges, network access and resource usage, and connects it to Claude, Cursor or VS Code from one interface. An MCP server is arbitrary code invoked with model-chosen arguments, so the isolation is proportionate rather than paranoid. |
| Choosing between MCP servers and a hosted AI gateway for tool access | They solve different problems and are frequently confused. An MCP server exposes tools to an agent. An AI gateway sits between your application and model providers, handling routing, caching, rate limits and observability for model calls. Most production stacks end up with both. For the gateway decision specifically, see the dedicated AI gateways comparison on this site. |
How we evaluated
The buyer problem in MCP tooling is not ranking ten similar products. It is working out which layer you are shopping in, because an SDK, a server framework, an agent runtime, a hosting platform and a gateway all describe themselves as MCP tools and none of them substitute for the others. So every entry here is labelled by layer first, and only compared with its neighbours after that.
Each tool was assessed on the dimensions in the comparison table above:
- MCP layer: server SDK, server framework, agent runtime acting as client, hosting, gateway, or local runtime. This decides whether the tool is even a candidate.
- Best fit: the specific job it does better than the alternatives in its own layer, stated narrowly enough to be falsifiable.
- Protocol readiness: how the tool stands relative to the current 2026-07-28 revision, including whether the vendor states a protocol version at all. With a breaking revision in circulation, silence on that point is a finding.
- Language or runtime: the hard constraint that eliminates most options before any feature comparison starts.
- Price: published rates only. Where a vendor does not publish, this page says so rather than estimating.
An entry earned a place by being the thing a team would actually reach for at one of those layers, not by supporting MCP. Orchestration frameworks whose MCP support is one checkbox among many were moved out of scope and are covered in the agentic AI frameworks comparison instead, because ranking them here by MCP support alone produced a list that answered neither question well.
What we reviewed
Protocol claims came from the specification and the project's own blog. Tool claims came from each vendor's own documentation:
- The MCP versioning page and the 2026-07-28 key changes, read in full for the statelessness, transport, authorisation and deprecation changes
- The 2026-07-28 release announcement for the rationale, SDK readiness and migration position
- The Agentic AI Foundation announcement for the governance change
- The official SDK tiering table for language support and tier
- FastMCP documentation, Mastra's MCP overview, the OpenAI Agents SDK MCP guide, Cloudflare's MCP documentation, Prefect Horizon and the Docker MCP Toolkit documentation
- The official MCP Registry and its preview status, which is stated by the project rather than inferred
Gaps are reported rather than filled. Mastra does not state which protocol revision it implements. Cloudflare does not publish MCP-specific pricing. Prefect does not publish enterprise pricing for Horizon. Docker does not publish a catalog size and its MCP Gateway is invite-only. FastMCP's adoption figures are published by the company that maintains it. Each of those is noted at the entry it belongs to, because an unpublished number is part of what you are buying.
This is a research comparison, not a hands-on benchmark. Nothing here rests on private testing; every protocol and product claim traces to a document you can open from the links above.
Last verified: 18 September 2026. This pass re-angled the page from ranking agent frameworks by MCP support to covering the MCP tool layer itself, added the current protocol state including the stateless 2026-07-28 revision and the Linux Foundation governance move, removed AutoGen, CrewAI, LlamaIndex and Haystack as better served by the agentic frameworks comparison, and added the official SDKs, FastMCP, Cloudflare Workers and Agents, Prefect Horizon and the Docker MCP Toolkit.
Editorial independence: this is a vendor-neutral comparison with no paid placements, sponsorships, or affiliate links. Rankings reflect fit for the stated use cases, not commercial relationships.
Frequently Asked Questions
What is the difference between an MCP framework, an MCP server, an MCP client and an MCP gateway?
What changed in MCP in 2026, and does it break my existing server?
Who owns MCP now that it is not just an Anthropic project?
Which MCP SDK should I build against?
Do I need an MCP registry, and is the official one ready?
Is MCP secure enough to expose internal systems to an agent?
Why are LangChain, CrewAI, AutoGen and LlamaIndex not ranked higher here?
What are MCP Apps, Tasks and Enterprise Managed Authorization?
Related Comparisons
GPU Cloud and AI Compute
Top 7 GPU Cloud and AI Compute Providers 2026: Price Per GPU-Hour by Chip Class, Verified From Each Provider's Own Pricing Page
7 tools compared
LLM Evaluation and Prompt Management
Top 7 LLM Evaluation and Prompt Management Platforms 2026: How to Stop Shipping Prompt Changes Blind
7 tools compared
Fine-Tuning and Model Customization
Top 8 Fine-Tuning and Model Customization Platforms 2026: What It Costs, When It Wins, and Why OpenAI Is Shutting Its Own Down
8 tools compared
AI Legal / Contract
Top 5 AI Legal and Contract Tools 2026: Harvey vs Spellbook vs Ironclad vs LegalOn vs Luminance
5 tools compared