Best of · Developer & infrastructure
Best code, repository and documentation tools for AI agents
All 8 ranked code, repository and documentation tools on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.
- 8 ranked
- 2 agent-ready
- 5 hosted endpoints
- Updated 8 October 2026
Top three
Picks by need
Worked out from the scores, prices and facts, so they change when the research does.
Highest score overall
Context7 BB
BB, 73/100 on the benchmark.
Also GitHub MCP Server, BB, 70.3/100.
Agent ergonomics
78/100 on agent ergonomics, against 69 for the overall leader.
Transparency & trust
83/100 on transparency & trust, against 72 for the overall leader.
The shortlist
| # | Tool | Grade | Best for | Price | Where |
|---|---|---|---|---|---|
| 1 | Context7 Upstash |
BB 73 | Coding agents that need current library or framework docs and examples on demand, at little or no cost. | $5 / 1k calls | hosted and local |
| 2 | GitHub MCP Server GitHub |
BB 70.3 | Agents that read and change GitHub repositories, issues, pull requests and Actions, from triage bots to coding agents. | Free · OSS | hosted and local |
| 3 | Azure DevOps MCP Server Microsoft |
B 66.3 | Agents working in an Azure DevOps organisation on work items, pull requests, pipelines and test plans, most easily from Microsoft's own clients. | $6 / seat-mo | hosted and local |
| 4 | Salesforce DX MCP Server Salesforce |
C 59.5 | Coding agents building and deploying on the Salesforce platform (metadata, Apex tests, LWC guidance, DevOps Center). |
Free · OSS | local |
| 5 | Ref Ref Software, Inc |
C 59.4 | Coding agents that need current library documentation plus search over a team's private repositories and PDFs through two small tools. | $10 / 1k calls | hosted and local |
| 6 | Sourcegraph MCP Server Sourcegraph, Inc. |
C 57.5 | A company that already runs Sourcegraph and wants agents to search and navigate many repositories with compiler-accurate definitions and references. | Paid | local |
| 7 | Git (MCP reference server) MCP project (reference servers) |
D 51.9 | Local commit loops in a sandboxed checkout where an agent stages, commits and branches. | Free · OSS | local |
| 8 | Microsoft Learn MCP Server Microsoft |
D 47.9 | Coding and support agents working on Azure, .NET, Microsoft 365 or other Microsoft technologies, at no cost. | Free | hosted |
How to choose
- Read and write tool scopeCheck which tools can read and which can write to repositories, and whether you can filter them, since an agent needs only the calls its task requires.
- Private repository accessCheck how the server authenticates, which access controls apply and whether private sources stay private, since a broad token lets an agent read code it should not see.
- Result limits and metered creditsCheck result limits and which tools draw on metered credits, since a documentation lookup or repository search can use up a plan's allowance inside a single agent run.
- Documentation version and freshnessCheck how library documentation is versioned and how often it updates, since an agent generating code against an outdated API version may produce calls that fail.
Each one in detail
Context7
BB 73/100Serves up-to-date, version-specific library documentation and code examples into agent prompts via two tools (resolve-library-id, query-docs).
Verdict Two tools, both annotated readOnlyHint: true and idempotentHint: true. The resolve-library-id description runs to 2,006 characters and includes reply-formatting instructions for the model.
Choose it for Coding agents that need current library or framework docs and examples on demand, at little or no cost.
Strengths
- Two tools, both annotated
readOnlyHint: trueandidempotentHint: true - Anonymous calls work on https://mcp.context7.com/mcp, and the free plan allows 1,000 calls a month with no card
- 429s carry
Retry-AfterandRateLimit-*headers, documented with backoff guidance
Weaknesses
- The
resolve-library-iddescription runs to 2,006 characters and includes reply-formatting instructions for the model - No page, limit or token parameter since 2.0.0, so response size depends on how narrow the query is
- The 11 August 2026 mcp.context7.com outage (503s from a stream leak in 4.0.0) appears in the changelog but not on status.upstash.com
Price $5 / 1k callsAuth OAuth or keyx402 nohosted and local
GitHub MCP Server
BB 70.3/100GitHub's official MCP server (Go) exposing repositories, issues, pull requests, Actions, code security, discussions, gists, notifications, projects and more as toolsets.
Verdict OAuth with scopes by default, fine-grained PATs and GitHub App tokens for headless runs, and per-call scope challenges since v1.11.0. 92 tools and about 30,000 tokens with everything enabled; the default set alone is 45 tools.
Choose it for Agents that read and change GitHub repositories, issues, pull requests and Actions, from triage bots to coding agents.
Strengths
- OAuth with scopes by default, fine-grained PATs and GitHub App tokens for headless runs, and per-call scope challenges since v1.11.0
- Every remote toolset has a
/readonlyURL, and--read-onlydrops write tools even when named in--tools delete_repositoryneeds the user to type the full repository name through elicitation
Weaknesses
- 92 tools and about 30,000 tokens with everything enabled; the default set alone is 45 tools
- 27 of 35 write tools leave
destructiveHintunset, and read tools don't setidempotentHint(issue #3281 is open) - Two advisories in 2026, one of them cross-user GraphQL client confusion in HTTP mode, both fixed
Price Free · OSSAuth OAuth or keyx402 nohosted and local
Azure DevOps MCP Server
B 66.3/100Microsoft's official MCP server for Azure DevOps Services. It gives agents work items, repositories, pull requests, pipelines, wikis, test plans and Advanced Security alerts, through a hosted endpoint with Microsoft Entra sign-in or a local npm package.
Verdict The hosted endpoint takes Entra OAuth with Azure DevOps scopes, an X-MCP-Readonly header and toolset or per-tool filters, and the MIT local package annotates every tool. The remote server is still labelled public preview, and Claude Code and Cursor need a custom Entra app registration with admin consent before they can use it.
Choose it for Agents working in an Azure DevOps organisation on work items, pull requests, pipelines and test plans, most easily from Microsoft's own clients.
Strengths
X-MCP-Readonly,X-MCP-ToolsetsandX-MCP-Toolsheaders trim the remote server to read tools, eight toolsets or named tools- Remote access uses Microsoft Entra OAuth with Azure DevOps scopes, and a call needs both the app scope and the user's own permission
- All 45 tools in the local package carry read-only, destructive, idempotent and open-world hints, checked by a test
Weaknesses
- The remote server was announced as a public preview on 17 March 2026 and no general availability notice was found
- Claude Code and Cursor need a custom Entra app registration with admin consent, and Claude Desktop and Codex can't use the remote server
- Version 2.9.0 renamed the local tools in a minor release on 29 July 2026, with the README warning added two days later
Price $6 / seat-moAuth OAuth or keyx402 nohosted and local
Salesforce DX MCP Server
C 59.5/100Salesforce's official local MCP server (@salesforce/mcp) for developing on the platform.
Verdict Tools pass org usernames, never tokens, and --orgs limits which authorised orgs the server can reach. 88 tools; Salesforce's README warns that enabling all of them overwhelms the context.
Choose it for Coding agents building and deploying on the Salesforce platform (metadata, Apex tests, LWC guidance, DevOps Center).
Strengths
- Tools pass org usernames, never tokens, and
--orgslimits which authorised orgs the server can reach - Toolsets,
--toolsand NON-GA gating keep the default surface smaller than the 88-tool total - Unit tests on Linux and Windows plus end-to-end tests on every branch push
Weaknesses
- 88 tools; Salesforce's README warns that enabling all of them overwhelms the context
- Ten
DevOps Centertools anddelete_orgcarry no annotations - One release (0.30.15, 9 July 2026) in the last 90 days, and 2025 bug reports still open
Price Free · OSSAuth OAuth or keyx402 nolocal
Ref
C 59.4/100Ref Context is a hosted MCP server from Ref Software, Inc. Its two tools search public documentation and a user's private repositories and PDFs, then read a page as Markdown trimmed to the relevant sections.
Verdict Two read-only tools with short definitions, OAuth with separate scopes for public and private documentation, and an activity log of every tool call. The API key may be passed in the URL query string, no rate limit or 429 guidance is documented, and the free allowance is 200 one-time credits.
Choose it for Coding agents that need current library documentation plus search over a team's private repositories and PDFs through two small tools.
Strengths
- Two tools,
ref_search_documentationandref_read_url, each with one required string andreadOnlyHint: true - OAuth at
https://api.ref.tools/mcpadvertises two scopes,public_docs:readandprivate_docs:read - The activity log at ref.tools/activity records user identity, tool calls and arguments, per the security page
Weaknesses
- The install docs give
?apiKey=YOUR_API_KEYin the URL as a documented way to authenticate - No rate limit, 429 handling or SLA was found in the reviewed documentation
- The free plan is 200 one-time credits, and an account needs a browser sign-up
Price $10 / 1k callsAuth OAuth or keyx402 nohosted and local
Sourcegraph MCP Server
C 57.5/100Sourcegraph's official MCP server gives AI agents code search, file reading, code navigation and commit and diff search across the repositories indexed by a company's Sourcegraph instance. It is built into Enterprise instances at /.api/mcp.
Verdict Sixteen read-only tools search and navigate code across every repository an instance indexes, with OAuth limited to an mcp scope and repository permissions enforced on each call. Access needs an Enterprise contract, priced from $16,000 a year, and no request rate limits were found in the reviewed documentation.
Choose it for A company that already runs Sourcegraph and wants agents to search and navigate many repositories with compiler-accurate definitions and references.
Strengths
- All 16 documented tools read and none writes to a repository, with three endpoints so a client can load 9, 16 or 2 tools
- OAuth 2.0 with PKCE and dynamic client registration, registered clients held to the
mcpscope, and access tokens that can carry the same scope - Repository permissions apply to every call, and admins can gate MCP by role (
MCP#ACCESS) or switch off single tools withmcp.tools.disabled
Weaknesses
- Enterprise plans only, from a $16,000 minimum annual contract through sales. A Cloud trial is by request and subject to eligibility
- No request rate limits, 429 behaviour or tool error catalogue found in the reviewed documentation
code_finderand Deep Search draw on the instance's credit entitlement and return an error once the quota is used up
Price PaidAuth OAuth or keyx402 nolocal
Git (MCP reference server)
D 51.9/100Python reference server for reading and changing local Git repositories through twelve tools (status, staged and unstaged diffs, diff against a ref, add, commit, reset, log, create branch, checkout, show, branch list). git_init was removed in September 2025.
Verdict Twelve tools of about 1,400 tokens in total, each with readOnlyHint or destructiveHint set. Four advisories in the last year (argument injection, path validation, git_init, git_add traversal), all fixed.
Choose it for Local commit loops in a sandboxed checkout where an agent stages, commits and branches.
Strengths
- Twelve tools of about 1,400 tokens in total, each with
readOnlyHintordestructiveHintset --repositoryand MCP roots confine every call to allowed paths, with checks hardened after the December 2025 advisories- Refs and paths starting with
-are rejected, closing the argument-injection class
Weaknesses
- Four advisories in the last year (argument injection, path validation,
git_init,git_addtraversal), all fixed - SECURITY.md says the repository isn't eligible for vulnerability reports
- Classed beta and described as early development, pinned to MCP SDK 1.x
Price Free · OSSAuth Nonex402 nolocal
Disclosure MCP started at Anthropic, which makes the Claude models our research agents and review panel run on (Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025), and this server is graded by the same checklist as every other listing.
Microsoft Learn MCP Server
D 47.9/100Microsoft's hosted documentation server at learn.microsoft.com/api/mcp.
Verdict Access requires no account, key or card. No status page was found, and the FAQ does not specify numeric rate limits.
Choose it for Coding and support agents working on Azure, .NET, Microsoft 365 or other Microsoft technologies, at no cost.
Strengths
- No account, key or card, so an agent connects in one step
- Three tools, each a read with one required parameter
maxTokenBudgeton the URL caps search-result size
Weaknesses
- No status page, and the FAQ admits rate limits without giving numbers
- Microsoft says tools can change at any time and doesn't version them
- No statement of what the endpoint logs or keeps
Price FreeAuth Nonex402 nohosted
Head to head
- Context7 vs Ref BB 73 vs C 59.4
- Azure DevOps MCP Server vs GitHub MCP Server B 66.3 vs BB 70.3
- Azure DevOps MCP Server vs Salesforce DX MCP Server B 66.3 vs C 59.5
Questions
What are the highest-rated code, repository and documentation tools for AI agents?
Context7 has the highest benchmark score of the 8 ranked code, repository and documentation tools, 73 (BB). GitHub MCP Server is second with 70.3 (BB).
How many code, repository and documentation tools are agent-ready?
2 of the 8 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.
Which code, repository and documentation tools accept x402 payments?
None of the ranked listings here accepts x402 for its main call yet.
How is this list ranked?
By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 8 October 2026.
How this list is made
The order is the Anchor benchmark score, the same number as on each listing and in the top list. Each listing is graded from public evidence against the benchmark checklist, and the picks above are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.
Full ranked table · 8 head-to-head comparisons · Best tools in every category