Of the 31,793 servers in the official MCP registry, about a dozen are built for marketing work — and the honest starting point is that 12,461 of them are packages you have to install and run on your own machine before any of it is true for you. This list is organised by the job rather than by vendor, and every entry says whether it is remote or local, official or community, and whether it can change anything.
Last updated September 14, 2026. If you are on Claude specifically, the connector shortlist is the narrower version of this page. If you are not sure what any of this is, start with what MCP is.
What the registry actually holds
Before any shortlist, the shape of the market. We paginated the official MCP registry API end to end on September 14, 2026 and deduplicated by server name.
Three things follow. Scale is not selection — a registry entry is a published manifest, not a maintained product. Remote is the usable half if you are not going to run software from a terminal. And a meaningful minority are already stale: an SSE-only server is running on a transport with a removal clock on it.
Paid media: the category with no official server
Start here because it is where the money is and where the gap is widest. Google publishes no Google Ads MCP server. Meta publishes none for Meta Ads. There is no official Search Console server either. Two real options exist.
Sprites: ad accounts, analytics and SEO behind one remote endpoint
Ours, so read it with that in mind. It covers Google Ads, Meta, LinkedIn, TikTok, Reddit, GA4, SEO and Search Console, Shopify and Google Business Profile on one URL, through official partner integrations. Doors are broad rather than granular — analyze, optimize, launch, change — which is the design decision that keeps the tool list short. Every write comes back as an approval card.
Remote · hosted · read and write, gated.
The DIY route, stated fairly
Community Google Ads and Meta Ads wrappers exist and some are good. What you take on with one: a Google Ads developer token and its approval process, OAuth credentials on your own machine, quota management, and an API that ships breaking changes on a schedule. If you have an engineer who wants that, it is a legitimate choice — the full comparison sets both out.
Research and SEO
Semrush: the one big research server
Semrush's official remote server exposes the Standard API (keywords, backlinks, organic and paid research, domain analytics), the Trends API for traffic and market estimates, and Projects as read-only. That last scope is a deliberate design choice worth copying: your tracking setup is not something a model should be able to reconfigure.
Remote · official · read. Bills against your Semrush API limits.
Google Analytics: official, and more limited than people expect
Google's own GA4 server covers account summaries, property details, custom dimensions and metrics, standard reports, funnels and realtime. Three caveats Google states plainly: it is labelled experimental, it is read-only, and it runs locally on your machine. For a marketer without a terminal that last one is decisive; GA4 through a hosted connector is the alternative.
Local · official · read only.
CMS and publishing
WordPress MCP Adapter: the Abilities API, not the old plugin
This one changed underneath everybody. The Abilities API shipped in WordPress core 6.9, and the bridge to MCP is now WordPress/mcp-adapter, a separate plugin on its own release cadence. It exposes registered Abilities as MCP tools, handles OAuth 2.1, and scopes permissions to the signed-in user's role. Automattic's earlier wordpress-mcp repository was archived on January 19, 2026 — if a guide tells you to install that, it is out of date. We wrote up the whole path on WordPress over MCP.
Self-hosted · official · read and write, role-scoped.
Webflow: sites, collections and CMS items
Webflow's server is the shortest path from noticing a bad meta description to fixing it. Writes publish, so stage them.
Remote · official · read and write.
Ecommerce and revenue
Shopify Storefront: free, open, and thinner than documented
Every eligible store answers at {shop}.myshopify.com/api/mcp with no authentication. The documentation lists six tools. On September 14, 2026 we called six live store endpoints: five answered, and every one returned exactly one tool, search_shop_policies_and_faqs. Useful for competitive checks, not for your own numbers — it is the shopper-facing surface, with no orders, sessions or conversions in it.
Remote · official · read only.
Klaviyo: campaigns, flows and the revenue behind them
Klaviyo's server reaches campaigns, flows, lists, segments and metrics — the lifecycle half of the same question your ads connector answers.
Remote · official · read and write.
Stripe: the number nobody argues with
Stripe's server turns "our ROAS" from a platform-reported figure into a comparison against money that arrived. Read-only scopes unless you have a specific reason.
Remote · official · read and write.
CRM, context and creative
HubSpot: contacts, companies, deals
HubSpot is what makes a campaign question answerable all the way through to closed-won rather than stopping at the platform's conversion count.
Remote · official · read and write.
Notion: where the brief already is
Notion is the cheapest quality upgrade on this list. Everything else produces better output when it has read the positioning doc first.
Remote · official · read and write.
Canva: the mechanical half of creative
Canva handles find, generate and resize inside your own brand account. Eleven sizes of one concept is exactly the work worth handing over.
Remote · official · read and write.
The escape hatch
Zapier: 9,000 apps, billed per call
Zapier MCP advertises 9,000+ apps and 30,000+ actions, and you choose which actions a given server exposes. The pricing is the part people miss: each tool call spends two tasks from the same quota your zaps use. An exploratory conversation is not free. The full breakdown.
Remote · official · read and write, per-action permissioned.
At a glance
| Server | Job | Remote? | Writes? |
|---|---|---|---|
| Sprites | Paid media, analytics, SEO | Remote | Yes, approval-gated |
| Semrush | Keyword, backlink, traffic research | Remote | No |
| Google Analytics | GA4 reporting | Local only | No |
| WordPress adapter | Publishing | Self-hosted | Yes, role-scoped |
| Shopify Storefront | Catalogue and policies | Remote | Cart only |
| HubSpot | CRM | Remote | Yes |
| Klaviyo | Email and SMS lifecycle | Remote | Yes |
| Stripe | Revenue | Remote | Yes |
| Notion | Briefs and context | Remote | Yes |
| Canva | Creative production | Remote | Yes |
| Webflow | CMS | Remote | Yes |
| Zapier | Everything else | Remote | Yes, per action |
Five questions before you connect one
- Remote or local? If it is local, you are installing software and storing a credential in a file. Decide that deliberately rather than discovering it at step three of a tutorial.
- Who publishes it? Vendor-official, or a wrapper by someone who may stop maintaining it. Both are fine; only one of them is somebody's job.
- Can it write, and what gates the write? The specification defines no approval step. A server that stages changes chose to.
- How many tools does it expose? Call
tools/listif you can. Forty thin endpoints is forty ways for the model to pick wrong on every turn. - What does it cost per call? Zapier's two-tasks-per-call and Semrush's API limits are both real budgets that a chatty conversation spends quickly.
What to avoid
- Anything asking you to paste a platform API key into a config file when a remote OAuth server exists for the same system. That key is long-lived, plain text, and readable by everything running as you.
- SSE-only servers. 1,076 registry entries still advertise the transport deprecated since 2025-03-26. It works today. It is not being invested in.
- Connecting ten at once. Three or four is the working number, and the symptom of too many looks like the model being careless rather than the setup being crowded.
- Servers you have not read the consent screen for. Anthropic's own guidance is to "only connect to trusted servers" because a hostile one "may include hidden instructions" the model will read as guidance (Anthropic).
If ad accounts are the reason you are reading this, the fastest test is a single URL in Claude, ChatGPT or Cursor — then ask where last month's budget went.
MCP server questions
How many MCP servers are there?
The official MCP registry listed 31,793 distinct servers when we counted it on September 14, 2026. 19,332 publish a remote endpoint you can connect to with a URL; 12,461 are packages you install and run yourself.
What is the best MCP server for marketing?
There is no single one, because no server covers both paid media and the rest of the stack. In practice a marketing setup is three: something that reaches ad accounts, something that reaches research data such as Semrush, and something that reaches where the work is written down.
Is there an official Google Ads MCP server?
No. Google publishes an official MCP server for Google Analytics — experimental, read-only and local-only — and nothing for Google Ads or Search Console. Meta publishes nothing. Everything else in paid media is a community wrapper or a hosted product.
What is the difference between a local and a remote MCP server?
A remote server runs on the vendor’s infrastructure: you paste an HTTPS URL, sign in with OAuth, and it works from any device. A local server is a package you install on your own machine, usually with an API key in a config file, and it works only there.
Do MCP servers cost money?
The server is usually free; what it reaches is not. Semrush needs a Semrush plan and bills against your API limits, Zapier spends two tasks per tool call, and a hosted marketing server is a subscription. Budget for the underlying tool, not the connector.
How many MCP servers should I connect at once?
Three or four. Every connected server adds its tool descriptions to every turn, and past a few dozen tools model accuracy falls and latency rises. The failure looks like the model being careless; it is usually the setup being crowded.
Are MCP servers safe to connect to business accounts?
It depends on the server. The protocol defines no approval step, so whether a write is staged for you to click is a product decision. Anthropic warns that "malicious MCP servers may include hidden instructions" — the model reads tool descriptions as guidance — so treat connecting one like installing an app with account access.