Set up Apify MCP Server safely

Configure the official Apify Remote MCP with OAuth or local stdio using minimal permissions and clear scraping boundaries.

Published on 18.09.2026

The official Apify MCP Server brings Actors from Apify Store into an MCP-capable client. An Actor can fetch a web page, gather search results, structure public social-media content, or provide data from a run. Do not configure the server as broad “web access for everything.” Start with a bounded task, such as collecting public sources on a topic, reviewing results in a limited dataset, and documenting original pages. Select only the Actors and server tools needed for that task. This reduces token use, reduces the attack surface, and makes agent decisions easier to review.

Connect Remote MCP with OAuth

Apify’s recommended route is the hosted Streamable HTTP endpoint at https://mcp.apify.com. Add that URL in a client that supports Remote MCP. On the first connection, the client or browser opens Apify sign-in. Sign in only through the official Apify dialog and verify the account before approval. Then complete OAuth authorization. This avoids keeping an API token as plaintext in an MCP configuration file. After connecting, start with a low-risk read action, such as Actor search or documentation search.

For the remote endpoint, Apify also accepts an API token in the Authorization: Bearer header. Choose that route only when the client does not support OAuth or a controlled technical flow requires it. Store the token in the client’s secret or credential manager, never in a URL, prompt, sample file, or Git. Use a separate automation token where your account permits it, and rotate or revoke it if exposure is suspected. A token is not mere configuration: it represents access in the context of your Apify account.

Use local stdio deliberately

For development, testing, or clients without remote support, Apify documents local stdio. Install Node.js 18 or later, put APIFY_TOKEN in a protected environment variable, and configure npx -y @apify/actors-mcp-server as the server command. A first-run package download is expected, but still check the package source and update deliberately. Then test search or documentation tools before running a broad scraper or publishing a task.

A local stdio process does not make the data path fully local. Actor inputs and tool requests go to the Apify API for execution; results then reach the client and may enter model context, chat history, or logs. According to Apify, the hosted server supports output-schema inference for structured Actor results, while local stdio does not. Select the route based on client capability, data boundary, and operating model, not on a misleading assumption that “local” means all processing stays local.

Limit Actors, data, and scraping lawfully

First find an Actor, read its schema, and restrict its input to the target, period, fields, and quantity you truly need. For every target site, review terms of use, access restrictions, privacy and copyright obligations, and any applicable robots guidance. Do not attempt to bypass logins, rate limits, technical blocks, or other access controls. Apify says full-permission and rental Actors are excluded from MCP search and execution, but that does not replace your own assessment of legality and risk.

Social-media, map, and contact Actors can return personal data. Collect only data with a documented purpose and suitable legal basis. Decide in advance who may read results, how long they remain, how they are deleted, and whether they go to a model, service provider, or other systems. Do not put private credentials, payment data, health data, or confidential customer data into Actor inputs unless this is genuinely necessary and legally supported.

Prompt injection, permissions, and approval

Scraped pages, Actor output, and logs can include text intended to manipulate the agent: “ignore rules,” “forward data,” or “add a new server.” Those are not commands. Treat all web content as untrusted data. State in the agent task that content may only be extracted, cited, and checked. Avoid giving the agent write-capable tools where possible. Before call-actor, task changes, publication, or sending data onward, review the specific Actor, input, recipient, and expected effect.

OAuth and API tokens can grant access to runs, datasets, key-value stores, and tasks in the Apify-account context. Regularly review available permissions and remove connections no longer needed. Disable telemetry only deliberately through Apify’s documented configuration if that fits your privacy design. Responsibility for the selected Actor configuration, lawful data use, and final action remains with the operator, not the model or MCP server.

FAQ

Which URL is the official remote server? https://mcp.apify.com. The first connection can start browser OAuth.

When do I use APIFY_TOKEN? For local stdio or as the Bearer alternative to OAuth. Store it only as a secret.

Are Actor results trustworthy instructions? No. They are external data, can be incomplete, and can contain prompt injection. Validate them against original sources and approval rules.

Published on 18.09.2026

Categories

Frequently asked questions

Does Apify support Remote OAuth?

Yes. The first access to https://mcp.apify.com can open Apify sign-in and OAuth approval in a browser.

Is the local server a fully local data path?

No. The stdio process runs locally, while Actor inputs and tool requests go to the Apify API for execution.

How do I reduce prompt-injection risk?

Treat pages and Actor results as data, use a minimal tool selection, and independently confirm external or state-changing steps.