In November 2024 Anthropic open-sourced the Model Context Protocol, a way for AI assistants to call tools and read data from other systems, with a handful of reference servers for Google Drive, Slack, GitHub and Postgres. Not quite two years later OpenAI, Google, Microsoft and AWS all ship it, the protocol belongs to a Linux Foundation fund, and in July its maintainers rewrote the core in what they call the largest revision of the protocol since launch.
Most MCP coverage is either a launch announcement or an "MCP is dead" take. We wanted the numbers in between: how big the ecosystem really is, where servers run, what they cost in context, how often they get attacked, and who is paying for all of it. So we pulled the public data ourselves (the official registry API, npm and PyPI download counts, directory snapshots), collected the security scans and vendor statements, and checked them. Vendor and security-vendor figures are their own claims and are labelled that way, and every number below links to its source.
Key findings
- 1The spec has had five revisions, and the 2026-07-28 one made MCP stateless: no handshake, no sessions, and a remote server that is "no different from any other HTTP workload". Roots, Sampling, Logging and Dynamic Client Registration were deprecated with a 12-month runway.
- 2The official MCP Registry lists about 40,000 servers (40,047 in our count of its public API on 6 Oct 2026), roughly 20 times the "close to two thousand" it had in November 2025. Quantity isn't quality: the top 10 publishers account for 18.7% of entries, and the registry is still in preview.
- 3The official Python and TypeScript SDKs are downloaded about half a billion times a month by our count (545M at the August 2026 peak, 464M in September), in line with the MCP blog's "close to half-a-billion". Both doubled in a single month, February to March 2026. Downloads are not users.
- 4Remote is now the default: 62.8% of registry entries offer a hosted endpoint, against 40.9% that ship an installable package.
- 5Context cost is the live fight. Anthropic measured 55K tokens for five servers' tool definitions, fixes like tool search and code execution cut 85% to 99.9%, and GitHub swapped its own MCP server for the
ghCLI for data fetching in its agentic workflows. - 6Exposure is growing faster than the fixes ship. Trend Micro's count of unauthenticated servers nearly tripled to 1,467 in nine months, Censys found 12,520 internet-reachable MCP services, 89.4% of them on the March 2025 protocol, and two MCP flaws reached CISA's exploited-vulnerabilities list in 2026.
- 7Money is flowing to the layer around the protocol: gateways, identity and hosting. Eight disclosed rounds add up to about $211M, Arcade bought Smithery, one of the big public registries, and Snowflake agreed to buy Natoma.
- 8Nobody publishes how many MCP tool calls actually happen. Downloads, server counts and scans are all proxies.
~40,000
Servers in the official MCP Registry, our count, 6 Oct 2026
40,047 unique names
Source: Registry API
~0.5B
Monthly downloads of the official Python + TypeScript SDKs, Jul–Sep 2026
Our computation
Source: npm and PyPI; MCP blog
The spec went stateless#
MCP has shipped five dated revisions of its specification. The first three were about filling gaps. 2025-03-26 added an OAuth 2.1 authorization framework and replaced the original HTTP+SSE transport with Streamable HTTP. 2025-06-18 made servers OAuth resource servers, required clients to bind tokens to a single server, banned servers from passing a client's token through to upstream APIs, and removed JSON-RPC batching only three months after adding it. 2025-11-25, released on the protocol's first anniversary, added experimental Tasks for long-running work and a new way for clients to register, and stayed backward compatible.
The 2026-07-28 revision is a different kind of release. In the maintainers' words, "MCP is transforming from a bidirectional stateful protocol into a request/response stateless protocol." The initialize handshake and the session header are gone. Every request carries Mcp-Method and Mcp-Name headers, so a gateway or rate limiter can route on headers instead of parsing JSON bodies. Servers that need more input from the user now answer with a "multi round-trip" result instead of holding a stream open, list results carry cache hints, and Roots, Sampling and Logging are deprecated but guaranteed to keep working for at least twelve months. Cloudflare's summary is the shortest: "MCP is now a fully stateless protocol."
Five spec revisions and the road to a stateless protocol
Spec releases and governance milestones, Nov 2024 to Aug 2026
5 Nov 2024
5 Nov 2024
First revision, 2024-11-05
stdio and HTTP+SSE transports.25 Nov 2024
25 Nov 2024
With reference servers for Google Drive, Slack, GitHub, Git, Postgres and Puppeteer.26 Mar 2025
26 Mar 2025
Revision 2025-03-26
OAuth 2.1, Streamable HTTP replaces HTTP+SSE, tool annotations.18 Jun 2025
18 Jun 2025
Revision 2025-06-18
Servers become OAuth resource servers; token passthrough banned; batching removed.8 Sep 2025
8 Sep 2025
Official registry in preview
An open catalog and API for public MCP servers.25 Nov 2025
25 Nov 2025
Revision 2025-11-25
Experimental Tasks, client ID metadata documents, formal governance.9 Dec 2025
9 Dec 2025
MCP joins the Linux Foundation
Donated to the Agentic AI Foundation, co-founded by Anthropic, Block and OpenAI.26 Jan 2026
26 Jan 2026
MCP Apps, the first official extension
Interactive UI in ChatGPT, Claude, Goose and VS Code.28 Jul 2026
28 Jul 2026
Revision 2026-07-28: stateless
No handshake or sessions; extensions framework; DCR, Roots, Sampling and Logging deprecated.22 Aug 2026
22 Aug 2026
New roadmap
Five priority areas, including progressive tool discovery and agent identity. No date for the next revision.
Sources: MCP specification changelogs; MCP blog; Anthropic
What each spec revision changed
Headline changes per revision, from the official changelogs, 2024 to 2026
Sources: 2025-03-26 changelog; 2025-06-18 changelog; 2025-11-25 changelog; 2026-07-28 changelog
Governance grew up alongside the spec. In December 2025 Anthropic donated MCP to the Agentic AI Foundation, a directed fund under the Linux Foundation co-founded with Block and OpenAI and supported by Google, Microsoft, AWS, Cloudflare and Bloomberg. The foundation reached 247 members in August 2026, with Alibaba, Visa and Wells Fargo joining at the Gold tier. At its first anniversary the project counted 58 maintainers around a core group of nine, and 2,900+ contributors on Discord. The four Tier 1 SDKs (TypeScript, Python, Go and C#) spoke 2026-07-28 on release day; by 6 October the SDK page listed six Tier 1 SDKs, adding Rust and Ruby.
Adoption in numbers#
SDK downloads#
The cleanest public signal of developer activity is how often the official SDKs get installed. We summed daily npm counts for @modelcontextprotocol/sdk and PyPI counts for mcp (from the public ClickHouse PyPI dataset, cross-checked against pypistats) for every month since launch. In November 2024 the two together were downloaded 28,508 times. In August 2026 they were downloaded 545.5 million times, and over July to September they averaged about 509 million a month. That matches the MCP blog's statement in July of "close to half-a-billion downloads a month" across its Tier 1 SDKs, with TypeScript and Python each past a billion in total, and Anthropic's 97M+ a month in December 2025, when our count was 91.8M for November and 100.7M for December.
Monthly downloads of the official MCP SDKs
Python SDK (PyPI mcp) and TypeScript SDK (npm @modelcontextprotocol/sdk), downloads per month, Nov 2024 to Sep 2026
| Series | x | y |
|---|---|---|
| Python | Nov 2024 | 14.7K |
| Python | Dec 2024 | 83.4K |
| Python | Jan 2025 | 146.1K |
| Python | Feb 2025 | 317.9K |
| Python | Mar 2025 | 1.5M |
| Python | Apr 2025 | 3.5M |
| Python | May 2025 | 8M |
| Python | Jun 2025 | 10.8M |
| Python | Jul 2025 | 17.9M |
| Python | Aug 2025 | 33.3M |
| Python | Sep 2025 | 48.4M |
| Python | Oct 2025 | 49.5M |
| Python | Nov 2025 | 56.7M |
| Python | Dec 2025 | 62.2M |
| Python | Jan 2026 | 68.9M |
| Python | Feb 2026 | 85.7M |
| Python | Mar 2026 | 170.9M |
| Python | Apr 2026 | 241.9M |
| Python | May 2026 | 285.4M |
| Python | Jun 2026 | 281.3M |
| Python | Jul 2026 | 319.3M |
| Python | Aug 2026 | 328.1M (peak) |
| Python | Sep 2026 | 231.7M |
| TypeScript | Nov 2024 | 13.8K |
| TypeScript | Dec 2024 | 102.9K |
| TypeScript | Jan 2025 | 176.5K |
| TypeScript | Feb 2025 | 350.9K |
| TypeScript | Mar 2025 | 1.9M |
| TypeScript | Apr 2025 | 4.2M |
| TypeScript | May 2025 | 20.9M |
| TypeScript | Jun 2025 | 16.8M |
| TypeScript | Jul 2025 | 21.6M |
| TypeScript | Aug 2025 | 24.7M |
| TypeScript | Sep 2025 | 31.3M |
| TypeScript | Oct 2025 | 33.8M |
| TypeScript | Nov 2025 | 35M |
| TypeScript | Dec 2025 | 38.5M |
| TypeScript | Jan 2026 | 50.2M |
| TypeScript | Feb 2026 | 71.7M |
| TypeScript | Mar 2026 | 141.9M |
| TypeScript | Apr 2026 | 140.1M |
| TypeScript | May 2026 | 153.2M |
| TypeScript | Jun 2026 | 165.2M |
| TypeScript | Jul 2026 | 198.9M |
| TypeScript | Aug 2026 | 217.3M |
| TypeScript | Sep 2026 | 231.9M |
Sources: npm downloads API; pypistats; ClickHouse public PyPI dataset; host0 computation, 6 Oct 2026
Two jumps in the series need explaining, and we can only partly explain them. Between February and March 2026 both SDKs doubled in a single month: TypeScript from 71.7M to 141.9M, Python from 85.7M to 170.9M. Then on 25 August Python's daily count fell from around 13M on weekdays to 7–8M and stayed there, so September came in 29% below August. A step that sharp, on one package only, looks like one large automated consumer (a CI system, or an agent product that bundles the SDK) changing how it installs, not thousands of developers leaving. That's the general caveat for this chart: registry downloads count CI runs, transitive installs and bundled copies, not people. Over a year the growth is still large, 7.4× for TypeScript and 4.8× for Python from September 2025 to September 2026.
Surveys agree that awareness ran ahead of use. In Postman's 2025 State of the API report (over 5,700 respondents), 70% of developers were aware of MCP but only 10% used it regularly.
Servers: the registry and the directories#
There are several ways to count MCP servers, and they measure different things. The official MCP Registry, backed by Anthropic, GitHub, PulseMCP and Microsoft, is where publishers register servers under a verified namespace. We paged through its entire public API on 6 October 2026 (401 pages of version=latest, deduplicated by server name) and counted 40,047 servers: 39,565 active and 482 deprecated, from 23,818 distinct namespaces. In November 2025 the maintainers said it had "close to two thousand entries", so that's roughly twentyfold growth in ten months.
That figure needs two qualifiers. First, the registry is still in preview and verifies namespaces, not code. Second, a few publishers account for a lot of it: the 10 largest namespaces hold 18.7% of all entries, and one GitHub account alone has 2,365. The "10,000+ servers" often quoted from December 2025 is a different number again: Anthropic's estimate of active public servers across the ecosystem, made when the registry held about 2,000.
Servers listed by MCP directories
Listed servers by directory and date, Dec 2024 to Oct 2026
| Series | x | y |
|---|---|---|
| Glama | 9 Mar 2025 | 1.4K |
| Glama | 3 Jun 2025 | 5.4K |
| Glama | 10 Sep 2025 | 9.1K |
| Glama | 2 Nov 2025 | 10.8K |
| Glama | 28 Jan 2026 | 17.3K |
| Glama | 4 Apr 2026 | 20.9K |
| Glama | 1 Jun 2026 | 29.9K |
| Glama | 8 Jul 2026 | 52.5K |
| Glama | 6 Oct 2026 | 97K |
| Official registry | 25 Nov 2025 | 2K |
| Official registry | 6 Oct 2026 | 40K |
| PulseMCP | 19 Dec 2024 | 270 |
| PulseMCP | 19 Feb 2025 | 1.1K |
| PulseMCP | 4 May 2025 | 4.1K |
| PulseMCP | 11 Aug 2025 | 5.4K |
| PulseMCP | 4 Dec 2025 | 6.9K |
| PulseMCP | 7 Mar 2026 | 8.6K |
| PulseMCP | 25 Apr 2026 | 13.4K |
| PulseMCP | 28 Jun 2026 | 20.1K |
| PulseMCP | 6 Oct 2026 | 21.7K |
Sources: MCP Registry API; MCP blog (Nov 2025); Glama; PulseMCP; Wayback Machine snapshots
The registry's own timestamps show how recent most of this activity is. For each server we took the month its latest version was published. More than a third of all entries, 14,456, were last published in September 2026 alone.
When registry servers were last published
Official MCP Registry entries by month of their latest version, Sep 2025 to 6 Oct 2026
| Label | Value |
|---|---|
| Sep 2025 | 347 |
| Oct 2025 | 227 |
| Nov 2025 | 142 |
| Dec 2025 | 208 |
| Jan 2026 | 293 |
| Feb 2026 | 903 |
| Mar 2026 | 1,535 |
| Apr 2026 | 1,672 |
| May 2026 | 2,125 |
| Jun 2026 | 2,649 |
| Jul 2026 | 4,121 |
| Aug 2026 | 6,665 |
| Sep 2026 | 14,456 |
| Oct 2026 | 4,704 (1–6 Oct) |
Sources: MCP Registry API; host0 count, 6 Oct 2026
Clients#
On the client side, adoption was close to complete within a year. Cursor added MCP in January 2025. OpenAI adopted it in March, Google in April, and Microsoft and GitHub joined the steering committee in May. By the time the stateless spec shipped, AWS, Cloudflare, Google Cloud and Microsoft Foundry supported it on day one. A few vendors have shared usage: Honeycomb says nearly 20% of its monthly interactive queries are now made by agents, and Cloudflare says its MCP hosting has served billions of tool calls.
Who shipped MCP, and when
Client and platform adoption milestones, Nov 2024 to Jul 2026
25 Nov 2024
25 Nov 2024
Claude Desktop
Launch partners include Block, Apollo, Zed, Replit, Codeium and Sourcegraph.30 Jan 2025
30 Jan 2025
Cursor
MCP support in version 0.45.26 Mar 2025
26 Mar 2025
OpenAI Agents SDK
Sam Altman: “people love MCP”.9 Apr 2025
9 Apr 2025
Google Gemini
Models and SDK to support MCP.1 May 2025
1 May 2025
Claude.ai remote servers
Integrations with 10 launch partners.19 May 2025
19 May 2025
Windows 11, GitHub, Microsoft
Windows embraces MCP; GitHub and Microsoft join the steering committee.21 May 2025
21 May 2025
OpenAI Responses API
Any remote MCP server; OpenAI joins the steering committee.Jul 2025
Jul 2025
VS Code
MCP generally available in v1.102.9 Sep 2025
9 Sep 2025
ChatGPT developer mode
A full MCP client, read and write.6 Oct 2025
6 Oct 2025
ChatGPT Apps SDK
Built on MCP, pitched at 800M+ ChatGPT users.10 Dec 2025
10 Dec 2025
Google managed servers
Fully managed remote MCP servers for Google services; 50+ by April 2026.28 Jul 2026
28 Jul 2026
Stateless spec, day one
AWS, Cloudflare, Google Cloud and Microsoft Foundry support 2026-07-28 at release.
Sources: Anthropic; TechCrunch; OpenAI; VS Code; Google Cloud; MCP blog
Remote is now the majority#
MCP started as a local protocol: a client launched a server as a subprocess and talked to it over stdio. That's no longer where most servers live. In our registry pull, 57.9% of entries list only a remote endpoint, 36.0% list only an installable package, and 4.9% offer both, so 62.8% can be used without installing anything. Excluding the 10 biggest bulk publishers only lowers that to 58.4%. Among packages, npm leads with 10,826, then PyPI with 4,245.
Remote or local: how registry servers are offered
Share of official MCP Registry entries, 40,047 servers, 6 Oct 2026
| Label | Value |
|---|---|
| Remote endpoint only | 57.9% |
| Installable package only | 36.0% |
| Both | 4.9% |
| Neither listed | 1.2% |
Sources: MCP Registry API; host0 count, 6 Oct 2026
The long tail on GitHub looks different. Glama, which indexes open-source repositories broadly, tags 41% of its 96,973 servers as remote, about the same share as in June 2025 (42%). The likely reading: individual developers still write local servers, while companies publishing to the official registry ship hosted endpoints. The stateless spec pushes further in that direction. The maintainers' August roadmap says a remote MCP server is now "no different from any other HTTP workload", which means it can run on ordinary serverless hosting behind ordinary load balancers.
The context-cost fight#
Every MCP tool a client loads comes with a name, a description and a JSON schema, and all of it goes into the model's context before the user has typed anything. With one or two servers that's fine. With a realistic set it isn't. Anthropic measured a five-server setup (GitHub, Slack, Sentry, Grafana and Splunk) at 58 tools and about 55K tokens, and says it has seen tool definitions reach 134K tokens internally. The GitHub MCP server on its own used 64.6K tokens for its 101 default tools, before its maintainers cut the default set to 52 tools and 30.3K.
What MCP tool definitions cost in context
Tokens used by a server's tool definitions, as measured by each source, Oct to Nov 2025
| Label | Value |
|---|---|
| GitHub MCP, old default (101 tools) | 64.6K (GitHub) |
| GitHub MCP, default toolsets (52 tools) | 30.3K (GitHub) |
| GitHub MCP (35 tools) | ~26K (Anthropic) |
| Slack MCP (11 tools) | ~21K (Anthropic) |
| Chrome DevTools MCP (26 tools) | 18K (Mario Zechner) |
| Playwright MCP (21 tools) | 13.7K (Mario Zechner) |
| Sentry MCP (5 tools) | ~3K (Anthropic) |
| Grafana MCP (5 tools) | ~3K (Anthropic) |
| Splunk MCP (2 tools) | ~2K (Anthropic) |
Sources: Anthropic; github-mcp-server #1182; Mario Zechner
The fixes come in two families. One loads tools lazily: Anthropic's Tool Search Tool cut token use by 85% and raised accuracy on MCP evaluations (Opus 4 from 49% to 74%), and Claude Code now switches it on automatically when tool descriptions would take more than 10% of the context. The other lets the model write code against tools instead of calling them one at a time. Anthropic's code-execution example went from 150,000 tokens to 2,000, and Cloudflare put its entire API behind two tools in about 1,000 tokens, where one tool per endpoint would have taken 1.17 million.
How much the context fixes save
Reduction in tokens, before vs after, as reported by each vendor, Oct 2025 to Feb 2026
| Label | Value |
|---|---|
| Code Mode, whole Cloudflare API | 99.9% (1.17M → ~1,000 tokens) |
| Code execution with MCP (Anthropic example) | 98.7% (150,000 → 2,000 tokens) |
| Tool Search Tool (Anthropic) | 85% |
| GitHub MCP default toolsets | 53% (64.6K → 30.3K tokens) |
Sources: Cloudflare; Anthropic (code execution); Anthropic (tool search); GitHub
The cost also fed a wider argument about whether agents need MCP at all. When Anthropic launched Agent Skills, folders of instructions and scripts loaded only when needed, Simon Willison called them "maybe a bigger deal than MCP", noting that GitHub's MCP server alone "famously consumes tens of thousands of tokens of context". Mario Zechner's essay "What if you don't need MCP at all?" argued that an agent with bash and a code interpreter can skip it. GitHub itself made the practical version of that call: in its own agentic workflows it replaced GitHub MCP calls for data fetching, such as pull-request diffs and file contents, with the gh CLI, because a CLI call is a plain HTTP request while every MCP tool call is also a round trip through the model.
The argument hasn't ended in either direction. In late September 2026 Pi, Zechner's own coding agent, added MCP support in its 1.0 release, with its new owner Earendil writing that "the MCP of today is not the MCP of yesteryear". One reading of these moves is a division of labour: skills and CLIs for an agent working on its own machine, MCP for authenticated access to someone else's service.
Security: exposure grows faster than fixes#
MCP's security problems fall into two groups. Some are ordinary bugs in servers and tools: missing authentication, command injection, path traversal. Others come from the model itself. Invariant Labs described tool poisoning in April 2025, hidden instructions in a tool's description that the model reads and the user never sees. Simon Willison's "lethal trifecta" names the dangerous combination: an agent with access to private data, exposure to untrusted content and a way to send data out. In an academic benchmark, MCPTox, the best tool-poisoning attack succeeded 72.8% of the time across 20 agents, and no model refused more than 3% of attacks.
Exposed servers#
Several security vendors have scanned the internet for MCP servers. Their methods differ, so the counts aren't a trend line. The one like-for-like pair is Trend Micro's: 492 servers with no client authentication and no encryption in July 2025, and 1,467 in April 2026 using the same method. The largest scan is Censys's. As of 28 April 2026 it found 12,520 internet-accessible MCP services on 8,758 IP addresses in 56 countries; 11,379 listed at least one tool to its probe, and 687 fell into its "system control" category, which covers command execution and remote system interaction.
Internet-exposed MCP servers, by scan
Servers or services each vendor reported, by method and date, Jul 2025 to Apr 2026
| Label | Value |
|---|---|
| Trend Micro, Jul 2025 | 492 (no auth, no encryption) |
| Knostic, Jul 2025 | 1,862 (all 119 sampled lacked auth) |
| Bitsight, Dec 2025 | ~1,000 (no authorization) |
| Trend Micro, Apr 2026 | 1,467 (same method as 2025) |
| Censys, Apr 2026 | 12,520 (internet-accessible services) |
Sources: Trend Micro 2025; Knostic; Bitsight; Trend Micro 2026; Censys
The Censys data also shows how slowly the spec's security work reaches deployed servers. 89.4% of the services it saw spoke protocol version 2025-03-26. Only 1.0% were on 2025-06-18, the revision that made servers OAuth resource servers and banned token passthrough, and 0.7% on 2025-11-25. The scan predates 2026-07-28, so the newest hardening (issuer validation, client registration bound to its issuer) has no deployment data yet.
Protocol versions spoken by internet-facing MCP services
Share of 12,520 services Censys observed, as of 28 Apr 2026
| Label | Value |
|---|---|
| 2025-03-26 | 89.4% |
| 2024-11-05 | 8.3% |
| 2025-06-18 | 1.0% |
| 2025-11-25 | 0.7% |
| Empty | 0.5% |
| Other | 0.1% |
Incidents and exploitation#
The incident record runs from research demos in 2025 to criminal exploitation in 2026. In 2025 the notable cases were proofs of concept and bugs found by researchers: a GitHub MCP prompt injection that leaked private repositories, a cross-tenant leak in Asana's MCP server that a spokesperson said affected about 1,000 customers, remote code execution in mcp-remote (CVSS 9.6) and the MCP Inspector (CVSS 9.4), and postmark-mcp, the first malicious MCP server found in the wild, which published 15 clean versions before quietly BCC'ing every email.
In 2026 attackers caught up. A missing-authentication bug on nginx-ui's MCP endpoint (CVSS 9.8) was exploited in the wild within two weeks of its advisory, according to Recorded Future as cited by Rapid7. Pluto Security says a flaw in mcp-atlassian went from patch to a criminal proof of concept in 20 days. And two MCP-related bugs, both in the LiteLLM gateway, were added to CISA's Known Exploited Vulnerabilities catalog: CVE-2026-42271, where MCP "test connection" endpoints ran a command supplied in the request, on 8 June, and CVE-2026-59822, an authentication bypass to MCP tools, on 2 September. Even the official Python SDK had a high-severity advisory in September that let a malicious server choose where a client's OAuth credentials went, the kind of gap the July spec's issuer validation is meant to close.
MCP security incidents, research to exploitation
Selected disclosures, incidents and responses, Apr 2025 to Sep 2026
1 Apr 2025
1 Apr 2025
Tool poisoning named
Invariant Labs describes hidden instructions in tool descriptions, rug pulls and shadowing.26 May 2025
26 May 2025
GitHub MCP prompt injection
A malicious public issue makes an agent leak private repository data.18 Jun 2025
18 Jun 2025
Asana cross-tenant leak
About 1,000 customers affected, per a spokesperson; the server was offline for 12 days.9 Jul 2025
9 Jul 2025
mcp-remote RCE
CVE-2025-6514, CVSS 9.6: a malicious server could run commands on the client.25 Sep 2025
25 Sep 2025
First malicious MCP server
postmark-mcp adds a hidden BCC after 15 clean versions.30 Mar 2026
30 Mar 2026
nginx-ui “MCPwn”
Missing auth on the MCP endpoint, CVSS 9.8; exploited in the wild by mid-April.15 Apr 2026
15 Apr 2026
OX Security on stdio
OX says the stdio transport runs any command it's given and counts 10 CVEs; per OX, Anthropic called it by design.20 May 2026
20 May 2026
NSA guidance on MCP
Tool and model output should never be implicitly trusted.8 Jun 2026
8 Jun 2026
First MCP bug on CISA's KEV list
LiteLLM CVE-2026-42271: a command from the request body, run via stdio.28 Jul 2026
28 Jul 2026
Spec hardens authorization
Issuer validation required; Dynamic Client Registration deprecated.2 Sep 2026
2 Sep 2026
Second KEV entry
LiteLLM CVE-2026-59822: unauthenticated access to MCP tools.16 Sep 2026
16 Sep 2026
Patch to criminal exploit in 20 days
Pluto Security's account of mcp-atlassian “MCPwnfluence”.
Sources: Invariant Labs; BleepingComputer; JFrog; Postmark; Rapid7; OX Security; NSA; NVD; Pluto Security
The response has come from every direction at once: the spec (token binding in 2025, issuer validation in 2026), platforms (Windows runs MCP servers under a separate agent account behind an OS proxy), and governments, with joint Five Eyes guidance on agentic AI in May 2026 and an NSA information sheet specific to MCP. The registry itself verifies who published a server and can denylist entries, but it doesn't scan code.
Distribution and money#
MCP became a distribution channel when the chat apps opened up to it. Claude added remote servers in May 2025; OpenAI built its Apps SDK on MCP in October 2025, pitching it as a way to reach over 800 million ChatGPT users, and opened app submissions in December. In January 2026 the two efforts met in MCP Apps, the first official extension, which lets a tool return interactive UI that ChatGPT, Claude, Goose and VS Code render in the conversation. Google now offers more than 50 managed MCP servers for its own services.
The money has gone to the infrastructure around the protocol, not the protocol itself. Gateways, which sit between agents and servers to enforce auth and policy, are the most common type of MCP security product, according to TechCrunch. The eight rounds below add up to about $211M, by our arithmetic over the announced amounts. In 2026 the first acquisitions followed: Snowflake agreed to buy Natoma for its MCP governance platform, and Arcade, seven weeks after raising a $60M Series A, bought Smithery, one of the largest public MCP registries, on 5 August.
Funding and acquisitions in MCP infrastructure
Disclosed rounds and deals, amounts as announced, Jul 2025 to Aug 2026
Sources: SiliconANGLE (Composio); Alpic; Obot; GlobeNewswire (Keycard); TechCrunch (Runlayer); SiliconANGLE (Manufact); CIO (Natoma); BusinessWire (Arcade); Runlayer; Arcade (Smithery)
MCP also isn't the only agent protocol under the Linux Foundation. Google's Agent2Agent protocol moved there in June 2025, absorbed IBM's ACP, and had 150+ supporting organizations by April 2026. The foundation frames the two as complementary: A2A for agents talking to each other, MCP for agents reaching tools and data.
What this means if you build with AI#
MCP is now infrastructure: nearly every assistant speaks it, and anything you expose through it can be reached by an agent you didn't write. The data points to a short list of habits.
- Build new servers on 2026-07-28, and keep older clients working. The stateless core means any HTTP host works, with no sticky sessions. But 89.4% of the servers Censys saw were still on the March 2025 version, so expect clients that lag too.
- Put authentication in front of every remote server. Trend Micro's count of servers with no client auth nearly tripled in nine months. Never bind a local server to every network interface, and treat a test or "preview" endpoint like a production one: that's how LiteLLM ended up on CISA's list.
- Measure what your tools cost in context. A single server can take 30K–65K tokens. Ship a small default toolset, and prefer clients with tool search or code execution.
- Treat tool output as untrusted input. Don't give one agent private data, untrusted content and a way to send data out at the same time, which is the lethal trifecta. In one demo, a support ticket was enough to make an agent with service-role access leak a Supabase secrets table.
- Pin the servers you install, and patch fast. postmark-mcp turned malicious on its sixteenth version, and one MCP flaw went from patch to criminal exploit in 20 days. If you use mcp-remote or the Python SDK, check you're past the fixed versions (0.1.16 and 1.30.0).
- Pick MCP or a CLI by the job. For data fetching inside your own pipelines, a CLI call skips a model round trip, which is why GitHub switched. For letting other people's agents reach your service with their own sign-in, MCP is the standard every client speaks.
- Don't read a registry listing as a quality signal. The official registry verifies namespaces, not code, and 18.7% of its entries come from ten publishers. Check who publishes a server before you connect it.
host0 is a cloud for small software: agents deploy apps through a skill and a REST API, and host0's own MCP server is deliberately control-only (list, rename, share and delete apps, no deploy). The context-cost and security data above is a large part of why we split it that way.
Methodology#
This post draws on four research passes we ran on 6 October 2026, one per angle: the spec and its governance, adoption, security, and the market and its debates. Each was limited to primary sources: the specification and its changelogs, the official MCP blog, company announcements, security-vendor reports, NVD entries and academic papers. We used aggregator and "statistics" sites only as leads. Before publishing, we re-opened every single-source page the post leans on for a headline number and confirmed the quoted sentence was still there.
Several numbers are our own computations from public data:
- Registry size and shape: we paged through the official registry's public API (
/v0/servers?limit=100&version=latest, 401 pages) on 6 October 2026 and deduplicated by server name. Two pulls a few hours apart gave 40,041 and 40,047; we use the later one. Remote and local shares come from each entry'sremotesandpackagesfields. - SDK downloads: monthly sums of daily npm counts for
@modelcontextprotocol/sdkand PyPI counts formcpfrom the public ClickHouse PyPI dataset, cross-checked against pypistats. - Directory growth: Wayback Machine snapshots of PulseMCP and Glama, read from the counts in their page titles.
We dropped claims that didn't hold up: a widely repeated "78% of enterprise AI teams use MCP in production" (no traceable source), several aggregator totals for servers and downloads, a "first MCP flaw on CISA's list" headline that named the wrong CVE, and paraphrases of Censys's data as "unauthenticated" servers. We also left out a third-party registry pull from May 2026 in favour of our own.
Limitations:
- Downloads are not users. They include CI runs, transitive installs and bundled copies, and one large consumer can move the total by tens of millions a month.
- Server counts are listings. Neither the registry nor any directory measures whether a server is used, maintained or safe.
- Security scans use different methods. Only Trend Micro's two scans are directly comparable. Vendor counts are the vendor's claim.
- Vendor figures are self-reported. Funding amounts are as announced; the $211M total is our sum, not a market size.
- Everything has a date. The registry is in preview and may reset, and the Censys scan predates the July spec.
Open questions#
The public data has clear holes:
- How many tool calls happen. No client vendor publishes MCP call volumes; the only figure we found is Cloudflare's "billions of tool calls" for its own hosting.
- How much of the registry is real. What share of the 40,047 entries are maintained, distinct servers rather than bulk or automated listings?
- What moved the download curves. Why did both SDKs double in March 2026, and what dropped Python by about 40% overnight on 25 August?
- Whether the 2026 hardening has shipped. How many clients and internet-facing servers have adopted 2026-07-28's authorization changes?
- How many MCP vulnerabilities there are. No maintained, current count of MCP CVEs exists.
- How big the app directories are. Neither ChatGPT's app directory nor Claude's connector directory has published a count since Anthropic's "over 75" in December 2025.
