The short answer: add a remote server with claude mcp add --transport http <name> <url>, or a local one with claude mcp add <name> -- <command>, then check it with /mcp. Pick the scope on purpose: local is private to you and the project, project writes a shared .mcp.json, user follows you everywhere. The part that matters more than the syntax is trust. Anthropic’s docs warn that servers which fetch external content can expose you to prompt injection, so treat each server as software with access to your session, not as a plugin that is safe by default.
Commands and scopes
From Anthropic’s MCP documentation, checked 29 September 2026.
| Task | Command |
|---|---|
| Add a remote server | claude mcp add --transport http <name> <url> |
| Add a local server | claude mcp add <name> -- <command> [args] (the -- separator matters) |
| Pass an environment variable | --env API_KEY=value |
| List, inspect, remove | claude mcp list, claude mcp get <name>, claude mcp remove <name> |
| OAuth sign-in | claude mcp login <name> |
| Check inside a session | /mcp |
HTTP is the recommended transport; SSE is marked deprecated.
| Scope | Stored in | Who sees it |
|---|---|---|
| Local (default) | ~/.claude.json | You, in the current project only |
| Project | .mcp.json in the repo | Everyone on the repo, via git |
| User | ~/.claude.json | You, across all projects |
Add --scope project or --scope user to choose. A project’s .mcp.json supports environment variable expansion such as ${API_KEY}, so put secrets in the environment, not in the committed file. In interactive sessions a project-scoped server requires accepting the workspace trust dialog first.
What a server costs your context
Every connected server adds to what Claude carries. Per Anthropic’s extension docs, MCP servers load tool names at session start and defer full schemas until needed, and tool search is on by default, so idle tools cost little. Large outputs are the real hazard: Claude Code warns when one tool result exceeds 10,000 tokens and has a default cap of 25,000, adjustable with MAX_MCP_OUTPUT_TOKENS. /context all shows what each loaded tool uses. Disconnect servers you are not using.
A vetting checklist
This is our checklist, built from Anthropic’s warning, not a vendor standard.
- Who runs it? Prefer a server published by the service itself over a community wrapper you cannot audit. If it is local (stdio), it runs code on your machine with your permissions.
- What can it do? Read-only access to a database or docs is a different risk from a server that can send messages, spend money or write files.
- Does it fetch outside content? Anything that reads web pages, tickets, emails or shared documents can carry instructions written by someone else. That is the prompt-injection path Anthropic flags.
- Where does the credential live? Use scoped, revocable tokens, and keep them out of
.mcp.jsonby using variable expansion. - Is a CLI enough? Anthropic’s best practices call CLI tools such as
ghthe most context-efficient way to talk to external services. If a command-line tool exists and Claude can already use it, you may not need a server. - Try it in the narrowest scope first. Local scope, one project, then widen.
A server and a skill solve different problems: the server gives Claude the connection, the skill teaches it your conventions for using it. For a guarded setup, use permission rules so calls to a server’s tools are approved deliberately rather than by habit.
New to the tool? Start with how to use Claude Code. For the same idea in the app-builder world, where a backend connection is the main risk, see connecting Supabase to any builder and the security risks overview.
Method
Researched from Anthropic’s Claude Code documentation on 29 September 2026. We do not recommend named third-party servers on this page: we have not audited any, and a list without an audit would repeat someone else’s marketing. Re-checked every 60 days.
Common questions
How do I add an MCP server to Claude Code?
Run claude mcp add --transport http <name> <url> for a remote server, or claude mcp add <name> -- <command> for a local one, then confirm with /mcp.
Where is the server configuration stored?
Local and user scope in ~/.claude.json; project scope in .mcp.json in the repository.
Are MCP servers safe?
Not automatically. Anthropic says to verify you trust each server, and that servers fetching external content can expose you to prompt injection.