Exa MCP Server

Official hosted Exa MCP for web search, webpage fetching, and optional multi-step research in an AI client.

Description

Exa MCP Server is the official Model Context Protocol integration hosted by Exa. According to Exa’s product page, reference, and repository, it connects compatible AI clients to Exa web search, webpage-content fetching, and research functions. The documented MCP endpoint is https://mcp.exa.ai/mcp; the repository describes Streamable HTTP and several client integrations. This record covers the hosted server, not a locally running Exa process, so its deployment is classified as remote.

Documented tools and their precise scope

The README lists web_search_exa and web_fetch_exa as the default tools. web_search_exa searches the web for a topic and, according to the README, returns ready-to-use content. web_fetch_exa reads the full content of one or more URLs as clean Markdown. Both support research: search locates possible sources, while fetch brings a known page into MCP context. Neither is a promise that a search finds every relevant source or that fetched text is complete, current, or professionally correct.

The README says that additional tools are enabled through the tools URL parameter; selecting them replaces the defaults. web_search_advanced_exa is documented for advanced search with filters, domains, dates, highlights, summaries, and subpage crawling. Crawling is therefore described here only as part of that optional advanced-search tool, not as blanket permission to copy arbitrary websites. According to the source, agent_run runs an Exa Agent for multi-step research, list building, enrichment, and structured output. Those research and structured-result capabilities support the Research and Data Analysis categories.

Access, account, and credentials

The hosted MCP works anonymously with rate limits according to the README. For higher limits and access to Exa Agent, Exa names OAuth or an API key. OAuth is the preferred route according to the README; supporting clients lead the user through an Exa sign-in. An API key can be sent through a Bearer or x-api-key header. The source also shows a key in a URL. That is not a sound default because URLs can end up in configuration, history, proxy logs, screenshots, or support tickets. Use the client’s secret or credential management instead, and never store a key in chat, a repository, or a shared example file.

OAuth and API-key use connect activity to an Exa account and its current permissions, limits, and terms. Check them directly with Exa before enabling an automated workflow or Exa Agent. The MIT license permits use, modification, and redistribution of the software under its conditions but disclaims warranty. That source-code license does not automatically grant rights to retrieved web material. Also observe each source site’s terms, copyright, privacy obligations, and access restrictions. This record deliberately contains no specific prices.

Data path, source validation, and limits

A tool call reaches Exa’s hosted MCP/API service, and its result returns to the connected MCP client. If that client uses a model, it may place the tool result in the model context. Depending on the client and model provider, prompts, tool calls, and results can therefore enter their respective context, log, or retention paths. A remote MCP is not a promise that processing stays only in a local system. Review Exa, client, and model-provider terms separately, and do not put unnecessary secrets or personal data in a search request.

Pages, search hits, snippets, fetch output, and material from optional subpage crawling are untrusted data. They can contain prompt injection, such as instructions to ignore rules, reveal secrets, or invoke more tools. Such text must never override the task, security boundaries, or human approval. Give a research agent only the permissions it needs, avoid unnecessary write-capable tools, and confirm external actions independently of web content.

Validate consequential claims against the linked original page: inspect publisher, date, and context, and use a second independent source for disputed matters. A search response, Markdown fetch, or structured output is working material, not a reliable substitute source. On 2026-09-08, the GitHub API reported exactly 4,987 stars for exa-labs/exa-mcp-server. Stars are a point-in-time popularity signal for the whole repository, not evidence of source quality, completeness, privacy, or security.

FAQ

Which tools are available by default? The README lists web_search_exa and web_fetch_exa. Additional tools must be selected explicitly through tools.

Must I have an API key? No. The README says the hosted MCP works anonymously with rate limits. Exa names OAuth or an API key for higher limits and Exa Agent.

Can fetched web text control the agent? No. Web content is untrusted data and can contain prompt injection; it must not replace a security rule or approval.

Requirements

An MCP-capable client with Streamable HTTP support for the hosted Exa endpoint; for higher limits or Exa Agent, Exa says OAuth or an Exa API key is required.

Installation instructions

Add the server in the MCP client as Streamable HTTP using https://mcp.exa.ai/mcp, or use the official plugin where supported. Complete OAuth in the client. Store API keys only through a secret/credential facility or a header, never in a URL.

Authentication

Anonymous access is rate limited according to the README. OAuth is preferred; for higher limits and Exa Agent, Exa names OAuth or an API key. API keys can be sent through Bearer or x-api-key headers.

Required access permissions

Availability depends on client support, anonymous rate limits or OAuth/API-key authorization, and the associated Exa account and current terms.

Transmitted or stored data

Tool calls go to Exa’s hosted MCP/API service; results return to the MCP client and can be processed in model context and in client or model-provider logs or retention paths when a model is used.

Security risks

API keys can be exposed through URLs, configuration, or logs. Search, fetch, and optional crawl content is untrusted data and can contain prompt injection; it must not change rules or trigger actions.

License and costs

License
MIT
Cost
paid

The source code is MIT licensed. According to the README, the hosted MCP works anonymously with rate limits; higher limits and Exa Agent follow OAuth or API-key access and current account and provider terms. No specific prices are listed.

Alternatives

Not recorded yet.

At a glance

Provider
Exa
Status
Official server
Deployment
Remote
Current version
Not recorded yet.
GitHub stars
5,055
Last reviewed
08.09.2026

Repository and documentation

Categories

Supported clients