exa-mcp-serverSAFE
Exa MCP for web search and web crawling!
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Exa MCP Server
Connect AI agents to Exa for web search, content fetching, and multi-step research.
f614aae2c956OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add exa-mcp-server --env EXA_API_KEY=${EXA_API_KEY} --env EXA_API_KEY_BYPASS=${EXA_API_KEY_BYPASS} --env KV_REST_API_TOKEN=${KV_REST_API_TOKEN} --env OAUTH_AUDIENCE=${OAUTH_AUDIENCE} -- npx -y [email protected]{
"mcpServers": {
"exa-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"EXA_API_KEY": "${EXA_API_KEY}",
"EXA_API_KEY_BYPASS": "${EXA_API_KEY_BYPASS}",
"KV_REST_API_TOKEN": "${KV_REST_API_TOKEN}",
"OAUTH_AUDIENCE": "${OAUTH_AUDIENCE}"
}
}
}
}Exposed tools (9)
7 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
agent_run | write | Start or resume an Exa Agent run; runs may take several minutes. Retain the returned run ID and resume with runId when the tool reports the run is still running. An interrupted tool call is not an explicit cancellation request. |
company_research_exa | read | [Deprecated: Use web_search_advanced_exa instead] Research any company to get business information, news, and insights. Best for: Learning about a company |
deep_researcher_check | read | [Deprecated] Check status and get results from a deep research task. Best for: Getting the research report after calling deep_researcher_start. Returns: Research report when complete, or status update if still running. Important: Keep calling with the same research ID until status is |
deep_researcher_start | write | |
deep_search_exa | read | |
get_code_context_exa | read | Find code examples, documentation, and programming solutions. Best for: Any programming question - API usage, library examples, code snippets, debugging help. Returns: Relevant code and documentation. Query tips: describe what you |
linkedin_search_exa | read | ⚠️ DEPRECATED: This tool is deprecated. Please use |
people_search_exa | read | [Deprecated: Use web_search_advanced_exa instead] Find people and their professional profiles. Best for: Finding professionals, executives, or anyone with a public profile. Returns: Profile information and links. |
web_search_advanced_exa | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (13)
.prettierignore
.prettierrc.json
.vercelignore
import type { ExaContentsResponse, ExaSearchResponse } from "../../src/types.js";vi.mock("../../../src/mcp-handler.js", () => ({vi.mock("../../../src/utils/auth.js", () => ({const { handleRequest } = await import("../../../api/mcp.js");const { handleOptions } = await import("../../../api/mcp.js");<a href="https://chatgpt.com/plugins/exa?open_in_app"><img src="https://img.shields.io/badge/Codex%2FChatGPT_Plugin-4A5BFE?style=for-the-badge&logo=data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3
sudo mv mcp-publisher /usr/local/bin/
@modelcontextprotocol/sdk, agnost, exa-js, jose, mcp-handler, zod, @types/node, @upstash/ratelimit
If you prefer, you can get an API key from the [dashboard](https://dashboard.exa.ai/api-keys) and pass it on the URL as `?exaApiKey=...`. You can also send it as a `Authorization: Bearer ...` header o
The hosted MCP server works anonymously with rate limits. For higher limits and access to Exa Agent, use either OAuth or an API key.
Gates applied: no_behavioural_pass.
f614aae2c956full audit observations/trust-audit/mcp-server/exa-labs__exa-mcp-server.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | f614aae2c956 | SAFE | B | 89 | first audit |
Questions
What is the exa-mcp-server MCP server?
Exa MCP for web search and web crawling!
What tools does exa-mcp-server expose?
9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is exa-mcp-server safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does exa-mcp-server need?
It reads EXA_API_KEY, EXA_API_KEY_BYPASS, KV_REST_API_TOKEN, OAUTH_AUDIENCE, OAUTH_ISSUER, OAUTH_USER_AGENTS, OPENAI_APPS_CHALLENGE_TOKEN, RATE_LIMIT_BYPASS and UPSTASH_REDIS_REST_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does exa-mcp-server run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as exa-mcp-server at 3.4.2.
How current is this page?
The grade is for one exact copy of the source (f614aae2c956), read on 2026-10-07. The repository is watched and re-audited when it changes.