About MCP Store

MCP Store is the independent MCP guide for business. The international MCP ecosystem is growing fast — directories such as mcp.so list more than 23,000 servers and Glama over 51,000 — but those lists are developer-first and say nothing about what an organisation is actually allowed, or required, to do with them. We fill that gap with three things: curation (a small, vetted selection instead of the longest list), sector context (what an MCP server concretely means for banks, insurers or accountants) and compliance guidance (GDPR, DORA, NIS2 and the AI Act — see MCP and EU regulation).

Why does this site exist?

Because a listing in a directory is a place to find something, not a seal of approval. Even the official MCP Registry — backed by Anthropic, GitHub, Microsoft and PulseMCP — states in its own moderation policy that users should expect "minimal-to-no moderation": servers with security vulnerabilities are not removed. Business decision-makers therefore need a layer on top of those international sources: someone who checks, per server, who the publisher really is, what access the server requests and which risks you need to weigh before connecting it to your company data. That layer is MCP Store.

How do we review MCP servers?

Every server in our directory goes through the same checks:

  1. Verification against the primary source. We verify each server at the source itself — the official documentation, the vendor's GitHub organisation or the official MCP Registry — never solely on the basis of another directory.
  2. Official or community label. We explicitly distinguish between servers published by the vendor itself and servers built by the community. That difference is the strongest trust signal in the ecosystem.
  3. Authentication check. We describe how the server authenticates (OAuth, API key, tokens) and whether the permissions it requests match its function. A server that asks for broad account access to perform a read-only task is a red flag.
  4. Naming the watchouts. Known limitations, risks and points of attention go straight into the entry — even when that makes a server less attractive. See also our page on security.
  5. 'Last verified' date. Every entry gets a date showing when we last checked it. The ecosystem changes fast; a review without a date is worthless.

Who is behind MCP Store?

MCP Store is an initiative of Ivo Thijssen, CEO of a Dutch insurance group. He uses MCP daily in real business practice: for energy management, financial administration and email automation. That first-hand experience sets the tone of this site — no theoretical musings, but the questions you actually run into: which server do I choose, what should it be allowed to see, and what does the regulator expect? As an executive in a regulated sector, he also knows the compliance side from the inside — the Dutch financial regulators DNB and AFM, and the Dutch DPA (Autoriteit Persoonsgegevens) — exactly the perspective that is missing from the international, developer-oriented ecosystem.

How independent is MCP Store?

At launch, MCP Store contains no paid listings: not a single server is in the directory because a vendor paid for it, and no review has been influenced by a commercial relationship. Should sponsorship be introduced in the future, it will always be explicitly labelled — sponsored content here is recognisable as sponsored content, kept separate from editorial reviews. Spot something that is incorrect or outdated anyway? Let us know; we process corrections with a fresh verification date.

Last updated: