Set up Exa MCP Server

Connect the official hosted Exa MCP safely, choose access deliberately, and validate web sources independently.

Published on 18.09.2026

The official Exa MCP Server connects an MCP-capable AI client to Exa’s hosted endpoint, https://mcp.exa.ai/mcp. The README documents it as a Streamable HTTP server and alternatively lists official plugin installations for supporting clients. The server provides web search and webpage fetching by default. Advanced search with subpage crawling and Exa Agent can be added optionally. Start with a small, reviewable research workflow rather than immediately allowing broad web research or automated follow-up actions.

Define purpose and data boundary before connecting

Decide which questions the agent may research, which domains it should prefer, and which claims must be checked at an original source. A sound first task is public and narrow: locate official technical documentation and then fetch that precise URL. Do not put API keys, internal customer data, unpublished agreements, or other secrets into a search request. The hosted service processes tool calls; results return to the client and can then enter the context of a connected model.

“Hosted” does not mean the entire process remains local. The path runs from the MCP client to Exa’s MCP/API service and returns to the client with a result. If the client uses a model, it may send the request and result into that model’s context. Review Exa, client, and model-provider terms separately. In a team, define which data may enter search prompts and which logs, exports, or support attachments must not be shared.

Add the remote endpoint in the client

In an MCP-capable client, add a Streamable HTTP server using https://mcp.exa.ai/mcp. The README shows the usual mcpServers shape for manual configuration with type streamable-http. If the client offers an official Exa plugin, that installation route is available instead. Save the configuration, restart the client fully if necessary, then check whether Exa tools appear in its tool list. The source explicitly notes that some clients only detect new MCP servers after a restart.

First test with a low-risk request for a public source. The default web_search_exa tool searches, while web_fetch_exa fetches full content from one or more known URLs as clean Markdown. Optional web_search_advanced_exa is enabled through the tools parameter, which replaces the default selection. Include every needed tool explicitly. Its documented functions include filters, domains, dates, highlights, summaries, and subpage crawling. Use crawling only with clear authorization and a narrow scope.

Choose anonymous access, OAuth, or an API key deliberately

According to the README, the hosted MCP can work anonymously with rate limits. For higher limits and Exa Agent, Exa names OAuth or an API key, with OAuth described there as preferred. In a supporting client, the OAuth flow signs in to Exa. Before confirming, check which account is connected and which rights or usage limits apply to the workflow.

An API key is a credential, not sample configuration. If needed, use the client’s secret store or credential facility and a Bearer or x-api-key header. The README also names URL delivery, but a real credential does not belong in a URL: browser and terminal history, reverse-proxy logs, screenshots, and support tickets can capture it. Do not put the key in a prompt or Git repository. On possible exposure, revoke or rotate it through the Exa dashboard and update only protected configuration.

Validate source rights, answers, and prompt injection

The repository’s MIT license concerns the software; it does not automatically cover material returned by a website. Observe each fetched source’s terms, copyright, privacy obligations, and access limits. Do not use Search or Fetch to circumvent protected areas or collect personal data without a basis. An answer or summary is not a substitute for the original source: for material claims, open the linked page, inspect publisher, date, and context, and use a second independent source for disputed issues.

Pages, snippets, Markdown fetches, and optionally crawled subpages are untrusted data. They can contain prompt-injection text asking an agent to ignore rules, reveal secrets, or invoke more tools. Treat them only as content. Do not grant the agent unnecessary write permissions, and require independent human confirmation for every external action. Research can prepare work; accountability and approval remain with the responsible person.

FAQ

Which endpoint belongs in the configuration? The official README names https://mcp.exa.ai/mcp for hosted MCP.

What are the default tools? web_search_exa and web_fetch_exa; an optional tool selection replaces the default tools.

Are search results trusted instructions? No. They are external data and can contain prompt injection. They must not change security rules or approvals.

Published on 18.09.2026

Categories

Frequently asked questions

Which endpoint is used for Exa MCP?

The official README names https://mcp.exa.ai/mcp as the hosted Exa MCP Server endpoint.

Do I always need OAuth or an API key?

No. The README describes anonymous access with rate limits; for higher limits and Exa Agent it names OAuth or an API key.

Can a webpage instruct the agent to take further action?

No. Pages and results are untrusted data and can contain prompt injection; they do not replace a security rule or approval.