Best of · Developer & infrastructure

Best code, repository and documentation tools for AI agents

All 8 ranked code, repository and documentation tools on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.

  • 8 ranked
  • 2 agent-ready
  • 5 hosted endpoints
  • Updated 8 October 2026

Top three

Picks by need

Worked out from the scores, prices and facts, so they change when the research does.

Highest score overall

Context7 BB

BB, 73/100 on the benchmark.

Also GitHub MCP Server, BB, 70.3/100.

Reliability

Azure DevOps MCP Server B

72/100 on reliability, against 68 for the overall leader.

Agent ergonomics

GitHub MCP Server BB

78/100 on agent ergonomics, against 69 for the overall leader.

Security & auth

GitHub MCP Server BB

84/100 on security & auth, against 69 for the overall leader.

Transparency & trust

GitHub MCP Server BB

83/100 on transparency & trust, against 72 for the overall leader.

Self-hosting under an open licence

Sourcegraph MCP Server C

self-hosted, Proprietary licence.

The shortlist

#ToolGradeBest forPriceWhere
1 Context7
Upstash
BB 73 Coding agents that need current library or framework docs and examples on demand, at little or no cost. $5 / 1k calls hosted and local
2 GitHub MCP Server
GitHub
BB 70.3 Agents that read and change GitHub repositories, issues, pull requests and Actions, from triage bots to coding agents. Free · OSS hosted and local
3 Azure DevOps MCP Server
Microsoft
B 66.3 Agents working in an Azure DevOps organisation on work items, pull requests, pipelines and test plans, most easily from Microsoft's own clients. $6 / seat-mo hosted and local
4 Salesforce DX MCP Server
Salesforce
C 59.5 Coding agents building and deploying on the Salesforce platform (metadata, Apex tests, LWC guidance, DevOps Center). Free · OSS local
5 Ref
Ref Software, Inc
C 59.4 Coding agents that need current library documentation plus search over a team's private repositories and PDFs through two small tools. $10 / 1k calls hosted and local
6 Sourcegraph MCP Server
Sourcegraph, Inc.
C 57.5 A company that already runs Sourcegraph and wants agents to search and navigate many repositories with compiler-accurate definitions and references. Paid local
7 Git (MCP reference server)
MCP project (reference servers)
D 51.9 Local commit loops in a sandboxed checkout where an agent stages, commits and branches. Free · OSS local
8 Microsoft Learn MCP Server
Microsoft
D 47.9 Coding and support agents working on Azure, .NET, Microsoft 365 or other Microsoft technologies, at no cost. Free hosted

How to choose

  1. Read and write tool scopeCheck which tools can read and which can write to repositories, and whether you can filter them, since an agent needs only the calls its task requires.
  2. Private repository accessCheck how the server authenticates, which access controls apply and whether private sources stay private, since a broad token lets an agent read code it should not see.
  3. Result limits and metered creditsCheck result limits and which tools draw on metered credits, since a documentation lookup or repository search can use up a plan's allowance inside a single agent run.
  4. Documentation version and freshnessCheck how library documentation is versioned and how often it updates, since an agent generating code against an outdated API version may produce calls that fail.

Each one in detail

#1

Context7

BB 73/100

Serves up-to-date, version-specific library documentation and code examples into agent prompts via two tools (resolve-library-id, query-docs).

Verdict Two tools, both annotated readOnlyHint: true and idempotentHint: true. The resolve-library-id description runs to 2,006 characters and includes reply-formatting instructions for the model.

Choose it for Coding agents that need current library or framework docs and examples on demand, at little or no cost.

Strengths

  • Two tools, both annotated readOnlyHint: true and idempotentHint: true
  • Anonymous calls work on https://mcp.context7.com/mcp, and the free plan allows 1,000 calls a month with no card
  • 429s carry Retry-After and RateLimit-* headers, documented with backoff guidance

Weaknesses

  • The resolve-library-id description runs to 2,006 characters and includes reply-formatting instructions for the model
  • No page, limit or token parameter since 2.0.0, so response size depends on how narrow the query is
  • The 11 August 2026 mcp.context7.com outage (503s from a stream leak in 4.0.0) appears in the changelog but not on status.upstash.com

Price $5 / 1k callsAuth OAuth or keyx402 nohosted and local

Full assessment

#2

GitHub MCP Server

BB 70.3/100

GitHub's official MCP server (Go) exposing repositories, issues, pull requests, Actions, code security, discussions, gists, notifications, projects and more as toolsets.

Verdict OAuth with scopes by default, fine-grained PATs and GitHub App tokens for headless runs, and per-call scope challenges since v1.11.0. 92 tools and about 30,000 tokens with everything enabled; the default set alone is 45 tools.

Choose it for Agents that read and change GitHub repositories, issues, pull requests and Actions, from triage bots to coding agents.

Strengths

  • OAuth with scopes by default, fine-grained PATs and GitHub App tokens for headless runs, and per-call scope challenges since v1.11.0
  • Every remote toolset has a /readonly URL, and --read-only drops write tools even when named in --tools
  • delete_repository needs the user to type the full repository name through elicitation

Weaknesses

  • 92 tools and about 30,000 tokens with everything enabled; the default set alone is 45 tools
  • 27 of 35 write tools leave destructiveHint unset, and read tools don't set idempotentHint (issue #3281 is open)
  • Two advisories in 2026, one of them cross-user GraphQL client confusion in HTTP mode, both fixed

Price Free · OSSAuth OAuth or keyx402 nohosted and local

Full assessment

#3

Azure DevOps MCP Server

B 66.3/100

Microsoft's official MCP server for Azure DevOps Services. It gives agents work items, repositories, pull requests, pipelines, wikis, test plans and Advanced Security alerts, through a hosted endpoint with Microsoft Entra sign-in or a local npm package.

Verdict The hosted endpoint takes Entra OAuth with Azure DevOps scopes, an X-MCP-Readonly header and toolset or per-tool filters, and the MIT local package annotates every tool. The remote server is still labelled public preview, and Claude Code and Cursor need a custom Entra app registration with admin consent before they can use it.

Choose it for Agents working in an Azure DevOps organisation on work items, pull requests, pipelines and test plans, most easily from Microsoft's own clients.

Strengths

  • X-MCP-Readonly, X-MCP-Toolsets and X-MCP-Tools headers trim the remote server to read tools, eight toolsets or named tools
  • Remote access uses Microsoft Entra OAuth with Azure DevOps scopes, and a call needs both the app scope and the user's own permission
  • All 45 tools in the local package carry read-only, destructive, idempotent and open-world hints, checked by a test

Weaknesses

  • The remote server was announced as a public preview on 17 March 2026 and no general availability notice was found
  • Claude Code and Cursor need a custom Entra app registration with admin consent, and Claude Desktop and Codex can't use the remote server
  • Version 2.9.0 renamed the local tools in a minor release on 29 July 2026, with the README warning added two days later

Price $6 / seat-moAuth OAuth or keyx402 nohosted and local

Full assessment

#4

Salesforce DX MCP Server

C 59.5/100

Salesforce's official local MCP server (@salesforce/mcp) for developing on the platform.

Verdict Tools pass org usernames, never tokens, and --orgs limits which authorised orgs the server can reach. 88 tools; Salesforce's README warns that enabling all of them overwhelms the context.

Choose it for Coding agents building and deploying on the Salesforce platform (metadata, Apex tests, LWC guidance, DevOps Center).

Strengths

  • Tools pass org usernames, never tokens, and --orgs limits which authorised orgs the server can reach
  • Toolsets, --tools and NON-GA gating keep the default surface smaller than the 88-tool total
  • Unit tests on Linux and Windows plus end-to-end tests on every branch push

Weaknesses

  • 88 tools; Salesforce's README warns that enabling all of them overwhelms the context
  • Ten DevOps Center tools and delete_org carry no annotations
  • One release (0.30.15, 9 July 2026) in the last 90 days, and 2025 bug reports still open

Price Free · OSSAuth OAuth or keyx402 nolocal

Full assessment

#5

Ref

C 59.4/100

Ref Context is a hosted MCP server from Ref Software, Inc. Its two tools search public documentation and a user's private repositories and PDFs, then read a page as Markdown trimmed to the relevant sections.

Verdict Two read-only tools with short definitions, OAuth with separate scopes for public and private documentation, and an activity log of every tool call. The API key may be passed in the URL query string, no rate limit or 429 guidance is documented, and the free allowance is 200 one-time credits.

Choose it for Coding agents that need current library documentation plus search over a team's private repositories and PDFs through two small tools.

Strengths

  • Two tools, ref_search_documentation and ref_read_url, each with one required string and readOnlyHint: true
  • OAuth at https://api.ref.tools/mcp advertises two scopes, public_docs:read and private_docs:read
  • The activity log at ref.tools/activity records user identity, tool calls and arguments, per the security page

Weaknesses

  • The install docs give ?apiKey=YOUR_API_KEY in the URL as a documented way to authenticate
  • No rate limit, 429 handling or SLA was found in the reviewed documentation
  • The free plan is 200 one-time credits, and an account needs a browser sign-up

Price $10 / 1k callsAuth OAuth or keyx402 nohosted and local

Full assessment · Against #1, Context7

#6

Sourcegraph MCP Server

C 57.5/100

Sourcegraph's official MCP server gives AI agents code search, file reading, code navigation and commit and diff search across the repositories indexed by a company's Sourcegraph instance. It is built into Enterprise instances at /.api/mcp.

Verdict Sixteen read-only tools search and navigate code across every repository an instance indexes, with OAuth limited to an mcp scope and repository permissions enforced on each call. Access needs an Enterprise contract, priced from $16,000 a year, and no request rate limits were found in the reviewed documentation.

Choose it for A company that already runs Sourcegraph and wants agents to search and navigate many repositories with compiler-accurate definitions and references.

Strengths

  • All 16 documented tools read and none writes to a repository, with three endpoints so a client can load 9, 16 or 2 tools
  • OAuth 2.0 with PKCE and dynamic client registration, registered clients held to the mcp scope, and access tokens that can carry the same scope
  • Repository permissions apply to every call, and admins can gate MCP by role (MCP#ACCESS) or switch off single tools with mcp.tools.disabled

Weaknesses

  • Enterprise plans only, from a $16,000 minimum annual contract through sales. A Cloud trial is by request and subject to eligibility
  • No request rate limits, 429 behaviour or tool error catalogue found in the reviewed documentation
  • code_finder and Deep Search draw on the instance's credit entitlement and return an error once the quota is used up

Price PaidAuth OAuth or keyx402 nolocal

Full assessment

#7

Git (MCP reference server)

D 51.9/100

Python reference server for reading and changing local Git repositories through twelve tools (status, staged and unstaged diffs, diff against a ref, add, commit, reset, log, create branch, checkout, show, branch list). git_init was removed in September 2025.

Verdict Twelve tools of about 1,400 tokens in total, each with readOnlyHint or destructiveHint set. Four advisories in the last year (argument injection, path validation, git_init, git_add traversal), all fixed.

Choose it for Local commit loops in a sandboxed checkout where an agent stages, commits and branches.

Strengths

  • Twelve tools of about 1,400 tokens in total, each with readOnlyHint or destructiveHint set
  • --repository and MCP roots confine every call to allowed paths, with checks hardened after the December 2025 advisories
  • Refs and paths starting with - are rejected, closing the argument-injection class

Weaknesses

  • Four advisories in the last year (argument injection, path validation, git_init, git_add traversal), all fixed
  • SECURITY.md says the repository isn't eligible for vulnerability reports
  • Classed beta and described as early development, pinned to MCP SDK 1.x

Price Free · OSSAuth Nonex402 nolocal

Full assessment

Disclosure MCP started at Anthropic, which makes the Claude models our research agents and review panel run on (Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025), and this server is graded by the same checklist as every other listing.

#8

Microsoft Learn MCP Server

D 47.9/100

Microsoft's hosted documentation server at learn.microsoft.com/api/mcp.

Verdict Access requires no account, key or card. No status page was found, and the FAQ does not specify numeric rate limits.

Choose it for Coding and support agents working on Azure, .NET, Microsoft 365 or other Microsoft technologies, at no cost.

Strengths

  • No account, key or card, so an agent connects in one step
  • Three tools, each a read with one required parameter
  • maxTokenBudget on the URL caps search-result size

Weaknesses

  • No status page, and the FAQ admits rate limits without giving numbers
  • Microsoft says tools can change at any time and doesn't version them
  • No statement of what the endpoint logs or keeps

Price FreeAuth Nonex402 nohosted

Full assessment · Against #1, Context7

Head to head

All 8 comparisons in this category

Questions

What are the highest-rated code, repository and documentation tools for AI agents?

Context7 has the highest benchmark score of the 8 ranked code, repository and documentation tools, 73 (BB). GitHub MCP Server is second with 70.3 (BB).

How many code, repository and documentation tools are agent-ready?

2 of the 8 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.

Which code, repository and documentation tools accept x402 payments?

None of the ranked listings here accepts x402 for its main call yet.

How is this list ranked?

By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 8 October 2026.

How this list is made

The order is the Anchor benchmark score, the same number as on each listing and in the top list. Each listing is graded from public evidence against the benchmark checklist, and the picks above are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.

Full ranked table · 8 head-to-head comparisons · Best tools in every category

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.