Skip to content
anavem.com

MCP server

Exa MCP Server

MCP server published by Exa Labs. It connects an MCP client to Exa for web search, fetching clean content from known URLs, and multi-step research, through a hosted remote endpoint; Exa docs also describe a local npm package.

Maintainer
Exa Labs (exa-labs organization on GitHub; documented on exa.ai)
Licence
MIT (LICENSE file, copyright 2025 Exa Labs). The package.json shown has no license field.
Last release
No tagged release shown (the repository package.json shows version 3.4.1)
Last verified Jump to what it can access ↓

What it can access

An MCP server gives an AI application a set of capabilities, and it can do only what its code and the credentials you give it allow. This is what the listing states, based on the sources below. Anavem does not rate it safe or unsafe: check it against what you plan to use it for.

Permissions it asks for

  • Default tools (per README): web_search_exa, web_fetch_exa
  • Other tools: web_search_advanced_exa (opt-in via the tools URL parameter) and agent_run (multi-step research, list-building, enrichment, structured output). The README lists both as optional; the Exa docs say agent_run is enabled by default once you connect with OAuth or an API key
  • Three access modes per Exa docs: keyless (free, rate-limited, no sign-in or API key), OAuth sign-in, or an API key sent in the x-api-key header
  • README: "Exa Agent requires authentication (OAuth or an API key)". The README also says an API key can be passed on the URL as ?exaApiKey=, as an Authorization: Bearer header or as an x-api-key header

Data it can reach

The hosted endpoint is https://mcp.exa.ai/mcp, a remote server run by Exa and reached over Streamable HTTP (per the MCP architecture page, 2026-10-03, remote servers run on the provider's platform). Search queries and URLs your AI application sends go to Exa. Exa docs say unauthenticated use is on free rate limits and authenticated requests use your team's plan and limits. The Exa docs also describe running the local npm package (npx -y exa-mcp-server with an EXA_API_KEY environment variable), which is a local process. The README and the docs page read do not include a privacy or data-retention statement; check Exa's terms and privacy policy.

How it is installed or connected

Steps from the official docs (https://exa.ai/docs/reference/exa-mcp) and README (https://github.com/exa-labs/exa-mcp-server), read 2026-10-03:

  1. Generic client configuration shown in the Exa docs:
{
  "mcpServers": {
    "exa": {
      "url": "https://mcp.exa.ai/mcp"
    }
  }
}
  1. The README and docs list, for Claude Code: claude plugin install exa@claude-plugins-official; the README lists, for Codex: codex mcp add exa --url https://mcp.exa.ai/mcp.
  2. OAuth sign-in for interactive clients: https://mcp.exa.ai/mcp?login (per Exa docs). API key option: send the key from https://dashboard.exa.ai/api-keys in the x-api-key header.
  3. Local npm package option, as shown in the Exa docs: command npx, args ["-y", "exa-mcp-server"], env EXA_API_KEY.

Limitations

  • The hosted endpoint is run by Exa; its tool definitions and behavior can change on Exa's side without a change in this repository.
  • Keyless use is rate limited, per Exa docs.
  • The repository shows no tags or releases and its package.json shows no license field (the LICENSE file is MIT).
  • Anavem has not audited this software.

Not sure what to look for? Read what to check before installing.

Quick answers

Who maintains this MCP server?
Exa Labs (exa-labs organization on GitHub; documented on exa.ai).
What can it access?
It asks for: Default tools (per README): web_search_exa, web_fetch_exa, Other tools: web_search_advanced_exa (opt-in via the tools URL parameter) and agent_run (multi-step research, list-building, enrichment, structured output). The README lists both as optional; the Exa docs say agent_run is enabled by default once you connect with OAuth or an API key, Three access modes per Exa docs: keyless (free, rate-limited, no sign-in or API key), OAuth sign-in, or an API key sent in the x-api-key header, README: "Exa Agent requires authentication (OAuth or an API key)". The README also says an API key can be passed on the URL as ?exaApiKey=, as an Authorization: Bearer header or as an x-api-key header. The hosted endpoint is https://mcp.exa.ai/mcp, a remote server run by Exa and reached over Streamable HTTP (per the MCP architecture page, 2026-10-03, remote servers run on the provider's platform). Search queries and URLs your AI application sends go to Exa. Exa docs say unauthenticated use is on free rate limits and authenticated requests use your team's plan and limits. The Exa docs also describe running the local npm package (npx -y exa-mcp-server with an EXA_API_KEY environment variable), which is a local process. The README and the docs page read do not include a privacy or data-retention statement; check Exa's terms and privacy policy. We do not label anything safe or unsafe; read the official sources before you install.
What licence does it use?
MIT (LICENSE file, copyright 2025 Exa Labs). The package.json shown has no license field. Check the terms if you plan to use it commercially.
What are its limitations?
The hosted endpoint is run by Exa; its tool definitions and behavior can change on Exa's side without a change in this repository. Keyless use is rate limited, per Exa docs. The repository shows no tags or releases and its package.json shows no license field (the LICENSE file is MIT). Anavem has not audited this software.
When was it last released?
No tagged release shown (the repository package.json shows version 3.4.1). Verified Oct 3, 2026.

Sources

Other listings in the same category.

All MCP servers →