Context7 MCP
A focused documentation-retrieval MCP from Upstash that gives AI coding agents current, version-aware library, framework and API documentation through only two core tools. Its value is high and its schema footprint is small, but indexed documentation can still be stale, incomplete or unsafe.
Start with Decision, Freshness, Install, Client support, Token cost and Safety. The lower sections explain the reliability trade-offs, privacy boundary, self-hosting distinction and final MCPVerdict assessment.
Should you use Context7 MCP?
Current API syntax, version-specific framework questions, SDK migrations, changed configuration and debugging caused by deprecated or recently modified APIs.
You are debugging business logic, doing code review or refactoring, working offline, or already have authoritative version-specific documentation in the active context.
Two focused MCP tools provide high-value, version-aware documentation retrieval with a very small schema footprint.
“Up to date” is not the same as real-time. Less-popular libraries can lag upstream documentation, and retrieved external content must still be treated as fallible and potentially hostile.
Context7 solves a real weakness in coding agents: stale library knowledge. The counterpoint is that Context7 itself can also be stale. Its value is highest when a task genuinely depends on current or version-specific external documentation.
Why Context7 MCP scores 82/100
The score is weighted around Context7's central promise: current, accurate, version-aware documentation retrieval. Ease of installation matters, but freshness, source resolution, coverage and external-content safety matter more because they determine whether the retrieved context is actually trustworthy.
| Universal parameter | Score | Finding |
|---|---|---|
| Effectiveness | 87 | Solves a genuine coding-agent weakness: stale library and API knowledge. |
| Reliability | 77 | Mature and actively maintained, but indexing, authentication and HTTP regressions have occurred. |
| Safety | 85 | Read-only documentation retrieval keeps direct blast radius low; retrieved external content remains untrusted. |
| Efficiency | 94 | Only two core tools and focused retrieval make Context7 one of the lightest MCPs evaluated. |
| Compatibility | 91 | Broad client support and explicit MCP 2026-07-28 adoption. |
| Maintainability | 96 | Very active development with rapid fixes and releases. |
| Setup friction | 96 | Hosted remote setup is simple and anonymous access can be used initially. |
Context7-specific parameters
| Parameter | Score | Why it matters |
|---|---|---|
| Documentation freshness | 84 | Excellent for popular libraries, but refresh windows can reach 45 days and the triggering request may still receive stale content. |
| Version specificity | 91 | Version-aware library IDs and explicit version selection are central to the workflow. |
| Library resolution accuracy | 81 | Strong ranking metadata helps, but source ambiguity remains a first-stage failure point. |
| Coverage/completeness | 76 | Broad ecosystem coverage, but missing, incomplete or misindexed libraries remain possible. |
| Answer honesty | 78 | Source-grounded retrieval helps, but the agent still needs to recognize thin or missing evidence instead of filling gaps confidently. |
| Prompt-injection containment | 61 | Read-only tools limit direct damage, but a real malicious-content report exists and cross-tool escalation is possible. |
| Instruction weight vs value | 91 | Two core tools provide an unusually strong information-to-schema ratio. |
| Retrieval discipline | 82 | Specific conceptual queries work well; broad multi-concept queries dilute retrieval quality. |
The documentary evidence is strong, but no controlled coding A/B benchmark was supplied that compares a meaningful set of current-library tasks with and without Context7.
What is Context7 MCP?
Context7 MCP is a documentation-retrieval MCP server from Upstash. It gives AI coding agents access to current library, framework, SDK, API, CLI and cloud-service documentation instead of forcing the model to answer only from its training data.
Context7 solves a specific coding problem: software documentation changes faster than model training data. An AI model can remember an old Next.js API, deprecated Prisma syntax, an earlier Stripe SDK method or configuration from the wrong framework version. Context7 retrieves documentation during the current coding session and adds the relevant material to the model's working context.
It is therefore a documentation source for an AI agent, not a general autonomous coding server. The normal retrieval surface does not edit project files, execute shell commands, create GitHub commits or modify infrastructure.
Official project: github.com/upstash/context7 ↗
What does Context7 MCP do?
Context7 MCP performs two core operations: it identifies the correct library or documentation source with resolve-library-id, then retrieves documentation and code examples for a specific question with query-docs.
| Tool | Function | Why it matters |
|---|---|---|
resolve-library-id | Maps a library name such as Next.js to a Context7-compatible library ID. | Reduces ambiguity before retrieval and can select a version-specific source. |
query-docs | Retrieves documentation and selected code examples for the resolved library and a focused technical question. | Injects current external evidence into the agent's context. |
A known Context7 library ID removes the first resolution step. Context7 recommends supplying an exact ID when available and selecting an explicit version when version-specific documentation matters.
MCP package and workflow: official repository ↗
How does Context7 MCP work?
Context7 uses a two-stage retrieval process: source resolution first, documentation retrieval second. The agent identifies the most appropriate library source, then asks a focused question against that source.
Library resolution
Context7 can rank candidates using signals such as exact name match, description relevance, snippet count, source reputation and benchmark score. When a user requests a specific version, version-specific library IDs should take priority.
Focused documentation retrieval
query-docs works best with one specific concept at a time. A query such as Next.js middleware authentication is more useful than mixing authentication, routing, caching, images and databases into one broad request.
Why resolution accuracy matters
A retrieval system can return accurate passages from the wrong project, community mirror, repository, version or documentation source. Excellent retrieval against the wrong source still produces the wrong answer. MCPVerdict therefore treats source selection and version selection as part of Context7's accuracy rather than as a trivial preprocessing step.
How fresh is Context7 documentation?
Context7 documentation is freshness-managed rather than universally real-time. Automatic refresh thresholds vary by library popularity.
| Library popularity | Automatic refresh threshold |
|---|---|
| Top 100 | 1 day |
| Top 1,000 | 15 days |
| Top 5,000 | 30 days |
| Others | 45 days |
When a stale library is requested, Context7 can trigger a background refresh. The important limitation is that the request that triggers the refresh can still receive the existing indexed documentation while the newer material is prepared for later requests.
That changes the meaning of “up to date.” Popular libraries can be refreshed on a one-day threshold, while long-tail projects may legitimately lag upstream documentation for weeks.
Version selection improves reliability when several documentation generations coexist. Asking for “Next.js 14 middleware” gives Context7 a more precise target than asking for “Next.js middleware.”
Freshness rules: Context7 library updates documentation ↗
Context7 solves stale model knowledge, but Context7 itself can also be stale. For a breaking release published today, verify the upstream source before assuming the first Context7 result already contains it.
How do you add Context7 MCP?
The simplest setup uses npx ctx7 setup. Context7 can configure supported coding agents automatically, while manual MCP clients can connect to the hosted endpoint at https://mcp.context7.com/mcp.
npx ctx7 setupThe setup flow can choose MCP mode or CLI + Skills mode. Context7 also supports local stdio execution through the @upstash/context7-mcp package.
Hosted MCP URL
https://mcp.context7.com/mcpLocal stdio package
npx -y @upstash/context7-mcpThe packaged MCP bundle currently requires Node.js 20.18.1 or later. Remote HTTP avoids the need to run the Node MCP process locally.
Verify the connection
- Confirm Context7 appears in the client's MCP/tool list.
- Ask the agent to resolve a well-known library.
- Run one specific documentation query.
- Check that the returned version/source matches the intended library.
- Only then rely on automatic retrieval for more complex work.
Setup resources: Context7 install guide ↗
Does Context7 MCP require an API key?
An API key is not required for every basic documentation lookup. Anonymous access is supported at lower limits, while authentication provides higher limits and access to account-specific features such as private repositories.
Context7 API keys use the ctx7sk-... format. Keys can be individually named and revoked from the dashboard.
Local stdio authentication
A local MCP process can receive the credential through CONTEXT7_API_KEY or an --api-key argument.
Remote authentication
Remote clients can use bearer authentication, and OAuth is increasingly supported by current client/setup flows.
The key does not control the user's GitHub account, filesystem or cloud infrastructure. Its blast radius is primarily Context7 quota and private Context7/teamspace access where enabled.
API-key documentation: Context7 API keys ↗
Which AI clients work with Context7 MCP?
Context7 works with MCP-compatible coding clients and publishes configurations for Claude Code, Cursor, Codex, OpenCode, Google Antigravity, VS Code, JetBrains-based environments and other clients.
| Client | Current Context7 path | Notes |
|---|---|---|
| Claude Code | npx ctx7 setup --claude or plugin/MCP | Strongest independent setup/search demand. |
| Cursor | npx ctx7 setup --cursor | Project/global MCP configuration supported. |
| OpenCode | npx ctx7 setup --opencode or plugin | Plugin and OAuth flow available. |
| Codex | MCP configuration or Context7 plugin | Remote or local MCP paths available. |
| Google Antigravity | Remote HTTP or local stdio | Standard Context7 MCP connection. |
| VS Code | Extension or MCP configuration | Works through supported MCP path. |
| Other MCP clients | Hosted MCP URL or local package | Requires compatible MCP transport/auth support. |
The selected LLM does not itself control the MCP connection. Claude Code, Codex, Cursor and other clients connect to Context7 as a tool source; the active model receives the retrieved documentation through that client.
Client reference: all supported client configurations ↗
How do you use Context7 MCP with Claude Code?
Claude Code can install Context7 with npx ctx7 setup --claude. The current Context7 setup supports MCP or CLI-based documentation workflows and can use OAuth during guided configuration.
npx ctx7 setup --claudeContext7 also publishes a Claude Code plugin:
claude plugin marketplace add upstash/context7
claude plugin install context7@context7-marketplaceAn API key can be supplied through CONTEXT7_API_KEY; supported anonymous access uses lower limits.
Context7 has the highest value in Claude Code when the task depends on an external library version: Next.js routing changes, current SDK methods, migrations between major package versions or configuration syntax that may have changed after model training.
Claude Code setup: Context7 for Claude Code ↗
How do you add Context7 MCP to Codex?
Codex can use Context7 through its plugin system, a local MCP process or a remote MCP server configuration. The remote option points to the hosted Context7 endpoint, while the local option starts @upstash/context7-mcp through npx.
Context7's current Codex plugin commands are:
codex plugin marketplace add upstash/context7
codex plugin add context7@context7-marketplaceLocal MCP execution can use:
npx -y @upstash/context7-mcpRemote configuration points to:
https://mcp.context7.com/mcpThe remote path removes the need to run the MCP package locally. The local path retains a local MCP process but still uses Context7's documentation service unless an Enterprise on-premise deployment is configured.
How does Context7 work with Cursor, Antigravity and OpenCode?
Cursor, Google Antigravity and OpenCode can all connect to Context7. Cursor and OpenCode have dedicated setup flows, while Antigravity supports standard remote HTTP or local stdio MCP configuration.
Context7 with Cursor
npx ctx7 setup --cursorContext7 can then retrieve documentation from Cursor when library-specific information is required. Cursor supports project-level and global MCP configurations.
Context7 with Google Antigravity
Antigravity can connect to the hosted Context7 endpoint with appropriate authentication or launch the package locally through npx.
Context7 with OpenCode
npx ctx7 setup --opencodeContext7 also provides an OpenCode plugin and OAuth authentication flow.
Cursor: setup guide ↗ · OpenCode: setup guide ↗
What is the difference between Context7 MCP and Context7 Skills?
Context7 MCP exposes native MCP tools to the coding agent, while Context7 CLI + Skills teaches the agent to retrieve documentation through ctx7 commands without requiring MCP. Both access Context7 documentation, but the integration mechanisms are different.
| Attribute | Context7 MCP | CLI + Skills |
|---|---|---|
| Agent interface | MCP tools | Skill instructions + CLI |
| Core retrieval calls | resolve-library-id, query-docs | ctx7 library, ctx7 docs |
| MCP support required | Yes | No |
| Permanent MCP schema | Yes, small | No MCP schema |
| Best fit | Native MCP workflows | Skill-first or non-MCP workflows |
| Setup utility | ctx7 setup --mcp | ctx7 setup --cli |
MCP mode is appropriate when the client already handles MCP tools well. CLI + Skills removes the MCP requirement and can reduce permanent MCP tool exposure, although the agent still performs documentation retrieval when the skill is invoked.
CLI + Skills: Context7 CLI documentation ↗
Can you self-host Context7?
Context7 now offers a full on-premise deployment for Enterprise customers. Running the public MCP package locally is not the same as self-hosting the complete Context7 documentation platform.
The open-source MCP package can run locally, but Context7's public API backend, parsing engine and crawling engine are separate from the public repository.
The Enterprise on-premise product is different. It can provide parsing and indexing, vector storage, MCP server, web interface, REST API and private GitHub/GitLab repository ingestion inside the organization's own infrastructure.
On-premise documentation: Context7 Enterprise on-premise ↗
Is Context7 MCP free?
Context7 has a $0 Free plan with 1,000 API calls per month. Pro costs $10 per seat per month and includes 5,000 API calls per seat; additional Pro usage costs $10 per 1,000 calls. Enterprise pricing is custom.
| Plan | Price | Included API calls | Notes |
|---|---|---|---|
| Free | $0 | 1,000/month | 20 bonus calls/day after monthly allowance is exhausted until reset. |
| Pro | $10/seat/month | 5,000/seat/month | $10 per additional 1,000 calls ($0.01/call). |
| Enterprise | Custom | Custom | Enterprise/on-premise options available. |
Private repositories are a paid feature. Context7 currently lists private-repository parsing at $5 per 1 million tokens on Pro.
The Context7 service price and the AI model's token cost are separate expenses.
Current plans: Context7 pricing ↗
How much AI context does Context7 MCP use?
Context7 has low permanent MCP overhead because it exposes only two core tools. MCPVerdict estimates approximately 1,000–2,000 tokens for tool schemas and instructions, while a typical documentation result can add roughly 2,000–8,000 input tokens.
1. Tool-schema and instruction overhead
Estimated at ~1K–2K tokens, depending on client serialization and current server instructions.
2. Retrieved documentation overhead
A typical docs result may add approximately ~2K–8K input tokens. Multiple concepts should normally be separate retrievals, so broad coding sessions can accumulate considerably more context.
3. Representative combined input range
One ordinary retrieval therefore adds roughly 3K–10K tokens when the estimated MCP footprint and retrieved documentation are considered together. This is a planning range, not a universal measured token count.
| Current model | Published input price / 1M tokens | Approx. added input cost for 3K–10K |
|---|---|---|
| GPT-6 Astra OpenAI | $5.00 | $0.015–$0.050 |
| GPT-6 Sol OpenAI | $1.00 | $0.003–$0.010 |
| GPT-6 Luna OpenAI | $0.05 | $0.00015–$0.00050 |
| GPT-5.6 Sol OpenAI | $4.00 | $0.012–$0.040 |
| GPT-5.6 Terra OpenAI | $2.00 | $0.006–$0.020 |
| GPT-5.6 Luna OpenAI | $0.20 | $0.0006–$0.002 |
| Claude Opus 5.5 Anthropic | $4.00 | $0.012–$0.040 |
| Claude Opus 5 Anthropic | $5.00 | $0.015–$0.050 |
| Claude Sonnet 5 Anthropic | $2.00 | $0.006–$0.020 |
| Claude Haiku 4.5 Anthropic | $1.00 | $0.003–$0.010 |
| Gemini 3.8 Flash | $0.75 | $0.00225–$0.00750 |
| Gemini 3.7 Flash | $0.75 | $0.00225–$0.00750 |
| Gemini 3.5 Flash | $1.50 | $0.0045–$0.015 |
These figures calculate uncached input only for the estimated 3K–10K Context7-related input range. They exclude model output, repeated retrievals, long-context multipliers, caching, tool-specific charges and the Context7 API plan itself.
The dominant Context7 cost is usually the retrieved documentation rather than its tool schema. Automatic invocation is therefore not free simply because the MCP surface is small.
Illustrative evaluation workload
The MCPVerdict evaluation estimated a 10-question test at approximately 20 Context7 calls, 35K retrieved/model input tokens and 6K model output tokens. At the checked pricing snapshot, that was approximately $0.13 on Claude Sonnet 5 and $0.26 on GPT-5.6 Sol, while Context7 itself remained $0 within the included Free allowance. If all 20 calls were Pro overage, Context7 overage would be about $0.20.
Different clients serialize tool schemas differently and retrieval depth varies by question. For exact accounting, capture the current tool definitions and returned documents in the actual client/model path being evaluated.
Is Context7 MCP safe?
Context7 has a relatively limited direct-action surface because its two core tools retrieve documentation rather than modifying files or infrastructure. Its main security risks come from untrusted retrieved content, prompt injection, API credentials, private-document handling and reliance on an external retrieval service.
MCPVerdict assigns Scan Grade C. The grade reflects executable Node/TypeScript code, external network access, API authentication, a hosted backend dependency and telemetry/observability. It does not indicate destructive local tools.
Real prompt-injection evidence
A May 2026 GitHub issue reported assistant-directed prompt-injection content appended to a query-docs result for HubSpot developer documentation. The reported content attempted to influence the calling assistant.
Context7 itself could not execute a shell command through its two documentation tools. Risk increases when the same agent also has access to GitHub, filesystem, shell, browser-control or other write-capable tools because malicious documentation can become a cross-tool prompt-injection pathway.
Context7 also warns that community-contributed projects are not guaranteed to be accurate, complete or secure. Retrieved documentation should therefore be treated as external evidence, not as trusted instructions.
Prompt-injection report: GitHub issue #2673 ↗
What data does Context7 send?
Context7 states that the MCP client sends a generated documentation query and library information rather than the user's complete original prompt, full conversation history or source code. Its tool descriptions also instruct clients to remove secrets and proprietary information from retrieval queries.
The privacy boundary changes for private repositories. Public-library retrieval mainly sends documentation lookup information; private-library use adds trust in Context7's repository ingestion, indexing and hosted infrastructure unless the organization uses Enterprise on-premise deployment.
API keys also carry a narrower blast radius than credentials such as a GitHub personal access token or a cloud-administrator secret. A Context7 key primarily controls Context7 access, quota and associated private Context7 resources.
Privacy documentation: Context7 data privacy ↗
Does Context7 collect telemetry?
Yes. Context7 MCP 4.1.0 added bounded OpenTelemetry metrics for MCP requests, tool calls, authentication and upstream API operations. The separate ctx7 CLI also collects anonymous usage telemetry and supports CTX7_TELEMETRY_DISABLED=1 as an opt-out.
These are separate systems:
- MCP server observability: operational metrics for requests, tools, authentication and upstream API activity.
- CLI telemetry: anonymous product usage telemetry with an opt-out.
Integration tests indicate that metric labels are bounded and avoid exporting values such as API keys, client IPs, library IDs, queries and session IDs as metric labels.
Any older Context7 review saying the current MCP has no telemetry is outdated.
MCP changelog: Context7 MCP changelog ↗
What are Context7 MCP's main limitations?
The main limitations are freshness lag, wrong library resolution, incomplete coverage, community-source quality, prompt-injection exposure, external-service dependency, retrieval token cost and unnecessary calls when equivalent authoritative documentation is already available.
| Limitation | Practical effect |
|---|---|
| Freshness thresholds | Long-tail libraries can remain unchanged for up to 45 days before automatic refresh. |
| Background refresh | The first stale request can receive the older indexed version. |
| Wrong source resolution | Accurate retrieval from the wrong source still gives the wrong context. |
| Incomplete indexing | Some projects or documentation pages can be missing or only partially crawled. |
| Community sources | Retrieved content is not automatically authoritative. |
| Prompt injection | External documentation can contain assistant-directed instructions. |
| Network dependency | Cloud use depends on Context7's hosted service. |
| Retrieval overhead | Documentation adds context tokens on every call. |
| Aggressive auto-use | Unnecessary lookups add latency, quota usage and another possible source of disagreement. |
| Private repositories | Using Context7 for proprietary docs materially changes the trust/privacy model. |
Context7's own rules also set useful scope boundaries. It is intended for library APIs, configuration, migration, library-specific debugging and setup. It is not intended for general refactoring, business-logic debugging, code review or generic programming concepts.
The “use Context7 for everything” problem
Current default guidance encourages Context7 retrieval for library, framework, SDK, API, CLI and cloud-service questions even when the model believes it knows the answer. That protects against stale training knowledge, but it can become redundant when authoritative version-specific documentation is already in context.
A more efficient operating rule is: Use Context7 when current or version-specific external documentation is required and equivalent authoritative documentation is not already available in the active context.
Who is Context7 MCP best for?
Context7 fits coding workflows where correctness depends on current external documentation. Its strongest cases are version-specific framework work, changed SDK methods, migrations, current configuration, deprecated APIs and code generation that depends on a library's present interface.
| Workflow | MCPVerdict fit | Reason |
|---|---|---|
| Current API syntax | Strong | Direct match for Context7's documentation retrieval role. |
| Version-specific implementation | Strong | Version-aware IDs reduce mixed-version answers. |
| Framework migration | Strong | Changed and deprecated APIs are a primary value case. |
| Deprecated API replacement | Strong | Current docs can expose the replacement path. |
| Current SDK configuration | Strong | Configuration often changes faster than model memory. |
| Recently changed libraries | Strong, verify freshness | Useful, but same-day upstream changes may not be indexed yet. |
| Obscure library with weak indexing | Conditional | Coverage, source choice and refresh lag become more important. |
| Generic programming concept | Poor | No external-library freshness need. |
| Business-logic debugging | Poor | Depends on project behavior rather than library docs. |
| Code review | Poor | Not Context7's designed scope. |
Context7 becomes most valuable when the answer changes with the library version. Its value falls when the task depends on the application's own business logic or when authoritative documentation is already present.
For troubleshooting that benefits from developer experience alongside current documentation, compare Stack Overflow MCP.
Who should not use Context7 for every coding question?
Developers gain less from Context7 when authoritative documentation already exists in the active context, when the task is independent of an external library, or when retrieval adds more latency and tokens than new information.
Context7 should be a targeted current-documentation layer rather than an automatic tax on every coding prompt. The most sensible policy is to call it when current or version-specific external evidence is required and not already available.
What are the alternatives to Context7?
Context7 alternatives include direct official documentation, AI-agent web search, Context7 CLI + Skills and repository-oriented documentation systems. The better choice depends on whether the task requires library API documentation, broader web information or deeper understanding of a specific repository.
| Alternative approach | Where it is stronger | Where Context7 is stronger |
|---|---|---|
| Direct official docs | Highest source authority when the exact documentation location is known. | Agent-native retrieval and lower manual lookup friction. |
| Web search | Broader information and very recent material outside Context7's index. | Library/version-oriented source resolution and focused docs retrieval. |
| Context7 CLI + Skills | No MCP requirement and no permanent MCP schema exposure. | Native MCP workflow in clients that already handle tools well. |
| Repository-oriented systems such as DeepWiki | Deeper repository/project explanation and generated codebase knowledge. | Narrow current library/API documentation retrieval. |
These options can be complementary rather than mutually exclusive. Context7 is best understood as a current documentation layer, not a replacement for every research or code-understanding tool.
Recent reliability and maintenance evidence
Context7 is actively maintained, but the recent evidence also shows why its reliability score is below its efficiency and maintainability scores.
| Finding | Practical effect | Interpretation |
|---|---|---|
| Private repository refresh failures | Private libraries could exist in the UI while refresh API returned library-not-found. | Negative; private-content workflow reliability concern. |
Prompt-injection content in query-docs | Retrieved docs can contain assistant-directed instructions. | Negative; real external-content risk. |
| Incorrect/misindexed library documentation reports | Agent can receive grounded but wrong or incomplete context. | Negative; coverage/source-quality concern. |
| Partial crawling of documentation sites | Index can contain only a fraction of available upstream pages. | Negative; completeness concern. |
| Manual refresh requests | Some libraries require explicit refresh attention. | Maintenance signal and freshness caveat. |
| MCP 2026-07-28 migration | Modern SDK v2 and stateless HTTP support. | Positive compatibility signal. |
| 4.0.0 SSE connection leak | Concurrent upstream streams reportedly grew dramatically and produced 503 overflow failures. | Serious negative regression. |
| 4.0.1 transport fix | Returned normal JSON unless streaming was required. | Positive rapid-maintenance signal. |
| 4.1.0 OpenTelemetry metrics | Improved server observability. | Neutral/positive operational change. |
| 4.1.1 notification cleanup | Reduced unnecessary notification subscription behavior. | Positive incremental maintenance. |
| OAuth/HTTP hardening | Origin/Host validation and JWT/auth improvements. | Positive active-hardening signal. |
| Public-doc validation failures | Some valid documentation sources can still fail ingestion checks. | Negative coverage/ingestion edge case. |
MCPVerdict assessment
Context7 is one of the strongest examples of an MCP doing one narrow job instead of becoming a large agent control plane. Two tools are enough to resolve a library and retrieve relevant documentation, which keeps schema overhead unusually low.
Its strongest value appears when libraries move faster than model training: current framework configuration, changed SDK methods, migrations, version-specific syntax and deprecated APIs.
The qualification is that retrieval does not automatically equal truth. Context7 libraries can lag upstream sources, obscure libraries may refresh only every several weeks, first requests can receive stale content while a background refresh runs, and community-contributed documentation may be inaccurate or unsafe. A real prompt-injection report also shows that documentation retrieval must be treated as untrusted external context.
Why it scores well
- solves a genuine stale-documentation problem;
- only two core MCP tools;
- strong version-specific retrieval design;
- broad coding-client support;
- simple hosted setup;
- anonymous/basic access available before creating another credential;
- active maintenance and quick regression fixes;
- modern MCP 2026-07-28 adoption.
Why it does not score higher
- freshness is not real-time for every library;
- wrong library/source resolution can ground an answer in the wrong evidence;
- coverage can be incomplete;
- community-contributed documentation is not guaranteed safe or correct;
- a real prompt-injection incident has been reported;
- automatic retrieval can consume quota, latency and context unnecessarily;
- private repositories materially increase the trust boundary.
Bottom line
Context7 works best as a current documentation layer, not an unquestionable source of truth.
Its efficiency is exceptional: only two MCP tools. The larger question is whether the source selected for a particular library/version is actually current, correct and complete.
Context7 MCP technical details
Show the full technical profile
| Attribute | Evaluated value |
|---|---|
| Publisher | Upstash |
| Type | Documentation-retrieval MCP |
| Canonical repository | https://github.com/upstash/context7 |
| Package | @upstash/context7-mcp |
| Hosted endpoint | https://mcp.context7.com/mcp |
| Current package checked | 4.1.1 |
| Evaluation date | September 2026 |
| Transports | Remote Streamable HTTP + local stdio |
| Authentication | Anonymous/basic access, API key, OAuth depending on setup |
| Node requirement | Node.js 20.18.1+ for packaged MCP bundle |
| Open-source MCP implementation | Yes |
| Hosted crawler/parser/search infrastructure open source | No |
| Core tools | 2 |
| Filesystem access | No for normal retrieval |
| Project/code writes | No |
| Shell execution | No |
| Scan grade | C |
| Overall score | 82/100 |
| Confidence | Moderate |
| MCP 2026-07-28 | Adopted |
| Telemetry | OpenTelemetry metrics present; CLI usage telemetry separately opt-out |
Frequently asked questions
What is Context7 MCP for?
Context7 MCP retrieves current, version-aware library and API documentation for AI coding agents. Its primary purpose is reducing errors caused by obsolete model knowledge about frameworks, SDKs, APIs, configuration and package versions.
Is Context7 MCP free?
Yes. The Free plan costs $0 and currently includes 1,000 API calls per month. Pro costs $10 per seat per month with 5,000 included calls per seat and $10 per additional 1,000 calls.
What is the Context7 MCP URL?
The hosted endpoint is https://mcp.context7.com/mcp.
Does Context7 work with Claude Code?
Yes. Context7 has a dedicated Claude Code setup flow, plugin, skills, commands and MCP integration. The guided setup command is npx ctx7 setup --claude.
Does Context7 work with Codex?
Yes. Context7 documents local and remote MCP configurations for Codex and also provides a Context7 Codex plugin.
Does Context7 work with Google Antigravity?
Yes. Context7 publishes remote HTTP and local stdio MCP configurations for Google Antigravity.
Does Context7 work with Cursor?
Yes. Context7 provides a dedicated Cursor setup command, MCP configuration and rules integration.
Does Context7 work with OpenCode?
Yes. OpenCode can install Context7 through npx ctx7 setup --opencode or the official Context7 OpenCode plugin.
Can Context7 be self-hosted?
Yes, full on-premise deployment is available as an Enterprise capability. Running the public MCP package locally does not by itself self-host Context7's complete crawling, parsing and retrieval backend.
Is Context7 MCP the same as Context7 Skills?
No. MCP mode exposes native MCP tools. CLI + Skills mode teaches the agent to retrieve documentation through ctx7 commands without requiring MCP.
Is MCP obsolete for Context7?
No current Context7 implementation indicates that MCP has been abandoned. Context7 migrated to MCP SDK v2 and protocol revision 2026-07-28, continues releasing MCP updates, and also offers CLI + Skills as a separate integration path.
Where is the official Context7 MCP source code?
The official project is maintained by Upstash at github.com/upstash/context7. The MCP server is open source under MIT; the supporting hosted API, parser and crawler are separate from the public repository.
Primary sources
- Upstash Context7 repository
- Context7 MCP changelog
- Context7 install guide
- Context7 client configurations
- Claude Code setup
- Cursor setup
- OpenCode setup
- Context7 CLI + Skills
- Library update/freshness policy
- Context7 data privacy
- API key documentation
- Context7 plans and pricing
- Prompt-injection issue report
- Enterprise on-premise documentation