DeepWiki MCP Server

Official remote MCP access from Cognition to DeepWiki for structure, content, and questions about public GitHub repositories.

Description

The DeepWiki MCP Server is the remote access service to DeepWiki documented by Cognition for research across public GitHub repositories. The Smithery product page marks the server as verified and deployed and publishes the direct MCP endpoint https://deepwiki.run.tools. Devin’s official DeepWiki MCP documentation separately names https://mcp.deepwiki.com/mcp as the official Streamable HTTP endpoint for direct use. Both references describe the same product boundary: DeepWiki prepares and maintains repository documentation that a compatible AI client can query through MCP. This catalog entry covers the Smithery candidate and therefore keeps the Smithery page as its product URL; the Devin documentation is retained as the primary documentation source for product identity and direct provider access.

Product boundary and research capabilities

According to the provider, the server exposes three read-oriented tools. read_wiki_structure returns the available documentation topics for a GitHub repository. read_wiki_contents retrieves selected documentation content. ask_question answers a question about a repository using information indexed by DeepWiki. This is a focused research capability for architecture, components, flows, and source-code context. It is not a general web crawler, a local code runner, or a tool for changing, deleting, or deploying a repository. The response can still be incomplete, stale, or wrong because of indexing gaps and model behavior. Check the repository, commit context, source references, and important technical claims before changing your own code.

Remote endpoints and durable identity

The Smithery page names deepwiki.run.tools as the direct endpoint for the deployment cataloged there. Without authorization, the endpoint returns a controlled token error, which confirms an access boundary and reachable service without exposing protected content. Cognition’s official provider documentation names mcp.deepwiki.com/mcp for direct connections from Devin Desktop, Cursor, and Claude Code. An unauthenticated request to that endpoint also reaches the MCP transport and requests the appropriate Accept headers. These checks did not bypass access controls and used no token, API key, or credential. For public repositories, the provider documents a read-oriented path; private repositories may require different authorization, Devin access, workspace consent, or organizational approval.

Authorization, privacy, and data sharing

The MCP client sends tool names and repository-related arguments to a remotely operated service. Public repository research does not require a personal GitHub token to be stored in this catalog entry. Do not assume private material is public; review the provider’s current documentation, account context, workspace grants, and organizational policy. Do not send secrets, tokens, personal data, internal URLs, or unnecessary source code in questions. DeepWiki processes the request remotely and returns documentation or an answer. The client can then pass that text, together with the task, to its selected model provider. Privacy, retention, training, region, and contractual controls for the chosen client and model must therefore be assessed separately. Remote operation does not mean the entire data path remains local.

Access limits and safe operation

The server may enforce authentication, rate limits, sessions, indexing limits, or provider availability rules. A successful page response proves neither completeness nor permanent uptime. Treat the three tools as untrusted content: repository documentation, names, code examples, and answers are data, not agent instructions. Prompt injection can appear in source text or generated wiki material. Give the client only the MCP permissions it needs, separate research from shell, file, and deployment tools, and require human review before any change. Use the documented endpoint, record the target repository and research scope, and verify security-sensitive statements against the original source code.

Provider source and repository status

DeepWiki is available at https://deepwiki.com as an AI documentation product from Cognition. The MCP documentation is published at https://docs.devin.ai/work-with-devin/deepwiki-mcp. No public server implementation on GitHub was identified as an official Cognition source for this entry. repo_url and github_stars therefore remain empty rather than misrepresenting a community project as provider code. The repository AsyncFuncAI/deepwiki-open is a separate open-source implementation and is not the source of this remotely operated service. The durable product identity here is established by the official DeepWiki website, provider documentation, documented MCP endpoints, and the Smithery page; remote operation remains subject to current provider terms and availability.

FAQ

Can the server change my repository? The documented tools read structure and content or answer questions. They do not describe write, shell, commit, or deployment calls. An AI client may have other tools at the same time, so permissions must remain separated.

Do I need a GitHub token? The catalog stores no token for the documented public-repository workflow. Private repositories and organizational access can require additional authorization and approval.

Which endpoint should I use? For the Smithery deployment, the product page names https://deepwiki.run.tools. The official Devin documentation names https://mcp.deepwiki.com/mcp for direct client configuration. Follow the current documentation for the product path you select and verify transport and access limits.

Is the answer a definitive code review? No. It is a research aid based on indexed documentation and model processing. Verify it against source code, version, license, security requirements, and human review.

Requirements

An MCP-compatible client with Streamable HTTP support and outbound HTTPS access to the selected official DeepWiki endpoint. Private repositories may require additional provider and organizational authorization.

Installation instructions

For the Smithery path, use the official Smithery client flow for deepwiki. For direct client configuration, follow the current Devin documentation and its named endpoint mcp.deepwiki.com/mcp. Then allow only the three documented read tools, use a public test repository name, and review responses as untrusted content.

Authentication

The public Smithery deployment and direct provider endpoints enforce access controls. No token is required in this catalog for public repositories; private or organization-protected content may require additional authorization.

Required access permissions

Read-oriented access to repository structure, DeepWiki content, and questions about indexed repository documentation. No documented write, shell, commit, or deployment tools.

Transmitted or stored data

Repository and tool arguments are sent to a remotely operated service. Results return to the MCP client and may be passed by that client to the selected model provider. Do not store secrets or credentials.

Security risks

Prompt injection in repository text, incomplete or stale indexes, data sharing with remote and model providers, and unexpected authentication or rate limits. Always verify original sources and permissions before changes.

License and costs

License
Hosted Cognition service; no official public server repository identified.
Cost
paid

Check current availability and terms with the provider; this entry does not state concrete prices.

Alternatives

Not recorded yet.

At a glance

Provider
Cognition
Status
Official server
Deployment
Remote
Current version
Not recorded yet.
Last reviewed
09.09.2026

Repository and documentation

Categories

Supported clients