Tavily MCP Server
Official Tavily MCP server for web search, extraction, website mapping, and crawling directly in a connected AI client of choice.
- Skill Road
- Tavily MCP Server
Categories
Description
Tavily MCP Server is Tavily’s official Model Context Protocol integration. It exposes the Tavily API to MCP-capable clients. According to the README, its toolset includes search, extract, map, and crawl; the official MCP documentation describes connecting AI clients to Tavily search and data extraction. Its boundary is therefore clear: an agent can find current external pages, retrieve selected content, and explore a website area instead of relying only on pre-trained knowledge.
Research: search with controllable parameters
The search tool executes a web query. The official API reference documents controls for result count, recency, language, and domains. include_domains can focus research on named domains, while exclude_domains removes them. For included domains, the source distinguishes strict filtering from boosting: filtering limits results to the named domains, whereas boosting prefers them but can still return other web sources. This is useful when a research task should start with vendor documentation or public-authority material.
The API also documents search_depth levels as a latency-versus-relevance tradeoff. That is not a guarantee of source quality. Rankings, snippets, and any optional answer are working material, not a verified factual record. For consequential decisions, a person should open the linked original page, check its author, date, and context, and preserve the evidence that supports the decision outside the chat. This source-validation work is why Research is an appropriate category.
Keep extraction, mapping, and crawling distinct
According to the README, extract performs intelligent data extraction from web pages. It is appropriate when a known URL needs to be brought into a work context. The README says that map creates a structured map of a website. That is not the same as a complete content analysis: a map helps identify relevant areas or URLs within a site. crawl systematically explores websites according to the README. Both functions can automate a research or preparation workflow, which supports the additional Automation category.
The sources describe these functions but do not guarantee completeness or the legal and professional appropriateness of a specific retrieval. Respect site terms, robots directives, content rights, and data-protection obligations. Limit the scope, domains, and fields to what is necessary. Do not use crawling or mapping to bypass access restrictions or to collect personal data without a clear basis.
Remote and local: two documented operating paths
Tavily documents a hosted Remote MCP at https://mcp.tavily.com/mcp/. Its documentation calls this the easiest route because it does not require local installation or configuration. Compatible clients can use OAuth, and API-key authentication is also documented. For clients without Remote MCP support, Tavily documents the mcp-remote bridge. The README and MCP page also document a local process through npx -y tavily-mcp@latest with Node.js. The entry is therefore classified as both: Tavily operates a remote route and publishes a local MCP-process route.
Local does not mean that the request or web data remains solely on the operator’s computer. The process uses the Tavily API and results return to the connected MCP client. In an AI application, the prompt, tool call, and result can also travel to the selected model provider and may enter client logs or that provider’s retention and policy path. Review Tavily, client, and model-provider terms separately before sensitive data enters a workflow.
Keys, attribution, and safe boundaries
For local configuration, the source requires TAVILY_API_KEY. In remote use, the key can be supplied as a Bearer header; the documentation also shows a URL variant, which is not a sensible general default because URLs can reach history, logs, and screenshots. Use the client’s secret or credential facilities instead, never a repository, prompt, or shared configuration file. OAuth is a documented alternative in supporting clients. Rotate or revoke a key if exposure is suspected.
Tavily documents session attribution through X-Session-Id. An optional human identifier can be forwarded; according to Tavily, it is hashed server-side. Still, do not use a plain email address or other unnecessary personal data as that identifier. Use an opaque internal ID if attribution is necessary. This does not automatically remove all privacy risks in the search request, returned material, or the subsequent model path.
Pages, snippets, extracted text, and map or crawl output are external, untrusted content. They can contain prompt-injection instructions, such as requests to ignore rules, disclose secrets, or invoke more tools. Treat them only as data. Limit agent permissions, avoid granting unnecessary secrets or write-capable tools, and require an independent human confirmation for external actions.
The official tavily-ai/tavily-mcp repository is MIT licensed. On 2026-09-08, the GitHub API reported exactly 2,374 stars. Stars are a point-in-time repository-popularity signal only; they do not demonstrate source quality, privacy, completeness, or security.
FAQ
Can the server only search? No. The README and MCP documentation list search, extraction, website mapping, and crawling.
Does a local launch create a fully local data path? No. The local MCP process uses the Tavily API, and responses enter the connected client and its model path.
Can web material change an agent’s instructions? No. External content is data; it must not override safety rules or trigger actions without independent review.
Requirements
An MCP-capable client; for remote use, Streamable HTTP and OAuth or a Tavily API key; locally, Node.js with npx and TAVILY_API_KEY.
Installation instructions
Remote: add https://mcp.tavily.com/mcp/ in a supported client and complete OAuth, or provide the API key only through a Bearer header or secure credential facility. Local: set TAVILY_API_KEY as a secret and register npx -y tavily-mcp@latest as a stdio server.
npx -y tavily-mcp@latest
Authentication
OAuth is documented for compatible remote clients. Alternatively, remote or local use requires a Tavily API key; locally through TAVILY_API_KEY and remotely preferably as a Bearer header.
Required access permissions
Access and available use depend on the Tavily account, API key or OAuth authorization, client support, and current provider terms.
Transmitted or stored data
Search queries and tool calls use the Tavily API; results return to the MCP client and can be processed in context, logs, and retention paths there and at the selected model provider. Tavily documents server-side hashing of optionally forwarded human IDs.
Security risks
API keys can be exposed through URLs, configuration, or logs. External web content from search, extraction, mapping, and crawling can contain prompt injection and must not change rules or trigger actions.
License and costs
- License
- MIT
- Cost
- paid
The source code is MIT licensed. API-key or OAuth use follows the account, limits, and current provider terms; check them directly with Tavily. This entry lists no specific prices.
Alternatives
Not recorded yet.
At a glance
- Provider
- Tavily
- Status
- Official server
- Deployment
- Local and remote
- Current version
- Not recorded yet.
- GitHub stars
- 2,411
- Last reviewed
- 08.09.2026
Repository and documentation
Categories
Supported clients
Related guides
Guides and background related to this entry.
Set up Mapbox MCP Server
Set up the Mapbox MCP Server: hosted endpoint or local token, a first test, and sensible limits.
30.09.2026
Set up the Asana plugin for Claude Code
Create your own Asana OAuth app, install the Claude Code plugin, and connect to Asana's V2 MCP server via /asana-setup.
30.09.2026
Setting up the Zernio MCP Server
Connect the Zernio MCP Server via OAuth or an API key, link social accounts, and deliberately safeguard write access to posts, inboxes, and ad campaigns.
28.09.2026
Setting up the Intercom MCP Server
Connect the Intercom MCP Server via OAuth or a bearer token, choose the correct regional endpoint, and deliberately safeguard write access to articles and notes.
23.09.2026