What is an MCP registry? (And what it does not check)
An MCP registry is the directory where MCP servers get listed so people and AI assistants can find them. The official one has been in preview since September 2025 and listed more than 27,000 servers on 5 September 2026. Being listed says who published a connector, not whether it is safe to run.
What is an MCP registry?
An MCP registry is a list of MCP servers: the small connectors that let an AI assistant reach a real tool like a shared inbox, a spreadsheet, or a CRM. Each listing carries the connector's name, who publishes it, a short description of what it can do, and where to install it from. Anyone who owns a domain or a GitHub account can add one.
How it works
The official registry, backed by Anthropic, GitHub, Microsoft and PulseMCP, opened in preview on 8 September 2025 and is still in preview, so listings can be reset without notice. It checks one thing: that a publisher really controls the name they are claiming. It does not read the connector's code or test what the connector does once it runs. Checking for malicious code is left to the places that host the code and to the marketplaces that copy listings out of the registry.
What a listing does and does not mean
That gap is what bites people. Installing a connector hands it real access to whatever account you point it at, and in April 2026 the security firm OX Security got a deliberately malicious test server accepted by 9 of the 11 MCP registries and marketplaces it tried.
A registry is not a gate. It tells you what exists. A gateway is the separate piece that sits between your agents and a connector and decides, at the moment of use, what that connector is allowed to touch. If your team is wiring up three or four connectors, pick them from the official registry, then check the publisher name yourself and give each connector a limited account rather than the one that owns everything.
Last updated: Sep 5, 2026