Apify MCP Server

Official Apify MCP for Actors, web-data extraction, and automation in an AI client.

Description

Apify MCP Server is Apify’s official Model Context Protocol interface. It connects an MCP-capable AI client to the Apify Platform and Apify Store. According to Apify, agents can search for Actors, inspect their input schemas, run Actors, read run results and storage, and search Apify documentation. Actors are prebuilt tools for web scraping, data extraction, and automation. Examples in the official README cover social-media and search-engine data, maps and e-commerce sites, and fetching individual web pages with rendering. This entry covers the server operated by Apify, not an arbitrary community Actor.

Research, automation, and social media

Research, Automation, and Social Media are appropriate categories for the documented outcome. An agent can first find a suitable Actor in the Store, review its required fields, and then run it deliberately. The server can read Actor-run datasets page by page, retrieve run status and logs, and create or change saved Actor tasks. That can support collecting sources for research, extracting structured public profile or post data, or preparing recurring data-gathering workflows. The output is still working material: an Actor result is not proof of accuracy, completeness, or permission to use data. For consequential use, check the source, collection time, field meaning, and likely gaps.

Apify documents limits on its MCP server as well. Full-permission Actors are excluded from search and execution because running one is intended to remain a decision that a person approves. Rental Actors are also excluded because their subscription model does not fit an on-demand MCP call. Actor input schemas are processed for MCP compatibility, so descriptions and enum values can be limited or truncated. Before a production run, read the individual Actor documentation and use an explicit, minimal tool selection. The README says that tools accessing external resources carry open-world behavior annotations.

Remote OAuth and local stdio operation

Apify explicitly offers two paths, so this entry is classified as both. The recommended path is the hosted Streamable HTTP endpoint at https://mcp.apify.com. On first connection, an MCP client can open a browser for sign-in to Apify and OAuth approval. This avoids placing an Apify API token in client configuration. Alternatively, the remote endpoint accepts an Apify API token as a Bearer token in the Authorization header. The hosted service also supports output-schema inference for structured Actor results according to the documentation; the local stdio server does not provide that feature.

For development, testing, or a client without remote MCP support, Apify documents local stdio operation via npx -y @apify/actors-mcp-server, with APIFY_TOKEN held in the protected environment. The package downloads at first use. Local means that the MCP process runs in the local environment; tool requests and Actor inputs still go to the Apify API for execution. Never put a real token in Git, chat, screenshots, or a shared MCP file. Use secret management, rotate a token suspected of exposure, and restrict its rights where the account and organization support that.

Scraping boundaries, personal data, and prompt injection

Web scraping does not remove obligations under website terms of use, robots or access restrictions, copyright, data-protection law, or contracts. For every Actor and target, check whether intended collection, storage, and reuse are permitted. Collect only necessary data, minimize the run, and do not bypass access controls. Social-media, map, and contact information can be personal data. Define purpose, legal basis, retention, access, and deletion before collection; do not send sensitive personal data or secrets in Actor inputs unless it is genuinely necessary.

Page content, Actor output, logs, and README text are untrusted third-party content. They can carry prompt-injection text, such as instructions to ignore rules, extract tokens, enable more tools, or publish data. Treat them as data, never instructions. Restrict the agent to needed, preferably read-only tools; independently review Actor selection, input, and every state-changing action. OAuth approves access within the Apify connection’s scope, while an API token authorizes Actor runs and protected data access in the account context. Grant only necessary permissions and assess whether the Actor, client, logs, and connected model provider may store or pass on data.

FAQ

Is the official Apify MCP Server available remotely? Yes. Apify operates https://mcp.apify.com as a Streamable HTTP endpoint with OAuth sign-in or a Bearer-token alternative.

Is there also a local route? Yes. Apify documents local stdio through npx -y @apify/actors-mcp-server and APIFY_TOKEN; Actor execution still uses the Apify API.

Can an agent start every Actor? No. Apify says full-permission and rental Actors are excluded from MCP-server search and execution. Terms, data protection, and human approval still apply.

On 2026-09-08, the GitHub API reported exactly 6,306 stars for apify/apify-mcp-server. It is a point-in-time repository-popularity signal, not evidence of quality, privacy, or security.

Requirements

An MCP-capable client; Streamable HTTP plus OAuth or Bearer-header support for remote MCP, or Node.js 18+ and a securely set APIFY_TOKEN for local use.

Installation instructions

Remote: add https://mcp.apify.com in the client and complete browser OAuth on first connection; alternatively store APIFY_TOKEN only as an Authorization: Bearer secret. Local: securely set APIFY_TOKEN and configure npx -y @apify/actors-mcp-server as the stdio command. Restrict tools and Actors to the necessary minimum before use.

npx -y @apify/actors-mcp-server

Authentication

Remote supports OAuth through browser sign-in and alternatively an Apify API token as a Bearer token. The local stdio server reads APIFY_TOKEN from the environment.

Required access permissions

OAuth and APIFY_TOKEN act in the Apify account context. Token and account rights determine accessible Actors, runs, datasets, storage, and tasks; Actor execution and write-capable task actions need deliberate approval.

Transmitted or stored data

Requests and Actor inputs are sent to the Apify API for execution. Results, run metadata, and storage content return to the connected MCP client and can be processed or retained there, in logs, and by the connected model provider.

Security risks

Token or OAuth access can expose Actor runs and account data. Scraped content can involve personal data, website terms, and prompt injection. Limit tools, review targets and inputs, and independently confirm mutating or publishing actions.

License and costs

License
MIT
Cost
paid

The source code is MIT licensed. Authenticated Actor execution and account-data access follow the current Apify account configuration and provider terms; check official information before production use.

Alternatives

Not recorded yet.

At a glance

Provider
Apify
Status
Official server
Deployment
Local and remote
Current version
Not recorded yet.
GitHub stars
8,755
Last reviewed
08.09.2026

Repository and documentation

Categories

Supported clients