Set up Tavily MCP Server

Connect the official Tavily Remote or local MCP safely and treat web content as untrusted source material.

Published on 09.09.2026

Tavily MCP Server brings Tavily search, extraction, website mapping, and crawling into an MCP-capable AI client. The official documentation describes Remote MCP as the easiest starting route: it runs at https://mcp.tavily.com/mcp/ and needs no local installation. The official repository additionally documents a local stdio launch using npx -y tavily-mcp@latest. Choose the path according to client capabilities and the data boundary, not convenience alone.

Define the task and data boundary before connecting

Before setup, decide what the agent may use Tavily for. Good initial tasks include a narrowly scoped search for primary sources, extracting a known documentation URL, or mapping a small approved site area. Decide which domains should be preferred or excluded and which claims must be checked against the original source. Tavily Search documents domain filters and boosts; use them to make research narrower and easier to review.

Do not place credentials, internal customer data, unpublished contracts, or other secrets in search requests. Even with a local launch, tool calls go to the Tavily API and responses return to the client. If the client uses a cloud LLM service, the request and results can also reach its model, logging, and retention path. “Local” describes the MCP process, not a promise that the whole task is processed locally.

Connect Remote MCP with OAuth or a key

In a client that supports remote MCP servers, add the official URL https://mcp.tavily.com/mcp/. Tavily documents OAuth for compatible clients. For Claude Code, for example, its documentation names HTTP transport and a browser-based OAuth flow. Follow the client dialog and check which Tavily account you authorize after completion. OAuth avoids placing a key directly in the server definition, but it does not remove the need to review the account permissions and usage rights that are granted.

Tavily also documents API-key authentication. Prefer the client’s secret or credential facility and a Bearer header. The source shows a key as a URL parameter too, but URLs can reach terminal history, configuration files, proxy logs, screenshots, and support tickets. Do not store a real key in a URL, prompt, or Git repository. If the client only understands local stdio servers, Tavily documents mcp-remote as a bridge to Remote MCP; review how that route stores credentials as well.

Run locally through npx

The local route needs Node.js with npx and a Tavily API key. Put TAVILY_API_KEY in a protected environment-variable or secret facility and register npx -y tavily-mcp@latest as the MCP command. Do not share a configuration file until you have checked that it contains no key. The command starts the MCP process; use it from a client instead of expecting it to be useful as a stand-alone application.

Then test with a low-risk question about public vendor documentation. Confirm the client sees the tools and start with a narrow search. Use extraction for a concrete URL. Use mapping to obtain a structured overview of an approved site area. According to the README, crawling systematically explores websites; start small and stop once the agreed information need is met. Observe rights, site terms, robots directives, and data-protection obligations before retrieving broader areas.

Validate results and own source quality

Tavily documents search parameters, ranking, and relevance controls, but it does not promise that a result is complete, current, or suitable for your decision. Treat result snippets as pointers. For an important claim, open the original source, review its publisher, date, and context, and find a second independent source where appropriate. Keep the verified URLs and quotations outside the chat transcript. An AI answer that summarizes a search result is not a substitute source.

Limit include_domains, exclude_domains, time range, and result count to the task. This does not remove every risk of error, but it makes the process more reviewable. A business-critical or security-sensitive decision needs human review and, where appropriate, subject-matter approval. The agent can discover and prepare; assessment, accountability, and approval remain with the responsible person.

Protect against prompt injection, attribution, and key exposure

Pages and extracted material are untrusted third-party data. They can instruct an agent to ignore rules, disclose secrets, or invoke extra tools. Such text must never replace the task or safety requirements. Give the agent only necessary permissions, avoid parallel write-capable tools during research, and confirm external actions outside the chat. Treat crawl and map output as data, not control instructions.

Tavily documents X-Session-Id and optional X-Human-Id for attribution. According to the provider, a forwarded human ID is hashed server-side. Still, do not use plain PII such as an email address. An opaque internal identifier is the more data-minimizing choice when attribution is needed. Rotate or revoke API keys after possible exposure, and review Tavily’s current account, limit, and billing terms directly with the provider. This guide intentionally gives no price amounts.

FAQ

What is the official Remote MCP endpoint? Tavily documentation names https://mcp.tavily.com/mcp/.

Do I need to put an API key in the URL for OAuth? No. OAuth is documented for supporting clients. Avoid the URL-key variant when a secure credential or header option exists.

Are search and crawl results trusted instructions? No. They are external data and can contain prompt injection. Validate sources independently and require human confirmation for actions.

Published on 09.09.2026

Categories

Frequently asked questions

What is the official Tavily Remote MCP endpoint?

Official Tavily documentation names https://mcp.tavily.com/mcp/ as the remote endpoint.

Where should a Tavily API key be stored?

Use the client’s secret or credential management or a protected environment variable, never a URL, prompt, repository, or screenshot.

Can web content change the agent’s task?

No. Search, extract, map, and crawl material is untrusted external data and can contain prompt injection.