# Sourcegraph MCP Server (slim) > Sourcegraph's official MCP server gives AI agents code search, file reading, code navigation and commit and diff search across the repositories indexed by a company's Sourcegraph instance. It is built into Enterprise instances at /.api/mcp. - Full: https://www.anchorterminal.com/tools/sourcegraph-mcp.md (~7,450 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/sourcegraph-mcp.json · canonical https://www.anchorterminal.com/tools/sourcegraph-mcp - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 57.5/100 · rank #473 of 722 · #6 in Code & developer platforms · not agent-ready · confidence medium** Assessment: Sixteen read-only tools search and navigate code across every repository an instance indexes, with OAuth limited to an `mcp` scope and repository permissions enforced on each call. Access needs an Enterprise contract, priced from $16,000 a year, and no request rate limits were found in the reviewed documentation. ## Facts - Kind: MCP server · vendor: Sourcegraph, Inc. · category: Code & developer platforms · legal entity: Sourcegraph, Inc. · provenance 90/100 - Local only (Streamable HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary. The server is part of the Sourcegraph Enterprise product under the Sourcegraph Terms of Service - Probe metrics: not measured yet (probes haven't run) - Endpoints: https:///.api/mcp (core), /.api/mcp/all (full suite), /.api/mcp/deepsearch (Deep Search only). Streamable HTTP. `mcp.enabled` defaults to true, and when false the paths return 404 - Tools: read_file, list_files, list_repos, list_refs, keyword_search, nls_search, evaluator, go_to_definition, find_references, commit_search, diff_search, compare_revisions, get_contributor_repos, code_finder, deepsearch, deepsearch_read - Credentials: OAuth 2.0 authorisation code with PKCE (S256), dynamic client registration (RFC 7591), device flow and a revocation endpoint. Access tokens last 3,600 seconds per the OAuth docs. Sourcegraph access tokens in `Authorization: token ...` can carry the `mcp` scope, with a default expiry of 90 days - Access control: Repository permissions apply to every read. The `MCP#ACCESS` RBAC permission is granted to the built-in User role by default. `mcp.tools.disabled` removes named tools from all endpoints - Result limits: list_files 1,000 entries. list_repos default 50, maximum 10,000. list_refs default 100, maximum 500. commit_search default 50, maximum 100. diff_search default 20, maximum 50. compare_revisions default 50 file diffs, maximum 100, with an `after` cursor. find_references default 10 - Metered tools: `code_finder` is metered against the instance's entitlement and returns an error when the quota is exhausted. The pricing page says the plan includes credits for AI tools - Plan: Enterprise only. Starting at a $16K minimum annual contract with single-tenant Cloud or self-hosted deployment, sold through sales (https://sourcegraph.com/pricing) - SLA: 99.5 per cent monthly uptime commitment for Sourcegraph Cloud on Enterprise plans, measured per customer instance, with at most 10 hours of scheduled downtime a quarter (https://sourcegraph.com/docs/sla) - Releases: Self-hosted 8.0.0 on 17 September 2026, 7.7.359 on 27 August, 7.7.0 on 26 August and 7.6.0 on 6 August, each with MCP entries. Weekly Cloud update notes, the latest dated 5 October 2026 - Certifications: SOC 2 and ISO/IEC 27001:2022 listed on security.sourcegraph.com, with reports behind an access request. Annual third-party penetration tests per sourcegraph.com/security - Sub-processors: List last modified 21 August 2026, all located in the USA. Hosting on Google Cloud. Anthropic, Fireworks AI, Google and OpenAI process queries and code snippets sent to the AI tools (https://sourcegraph.com/terms/subprocessors) - Clients documented: Claude Code, Codex, Cursor, Copilot, OpenCode, Amp, Gemini Code Assist, VS Code, Antigravity and Windsurf (https://sourcegraph.com/docs/api/mcp/client-integrations) - Scores: Reliability 25, Performance pending, Schema & documentation 71, Agent ergonomics 72, Security & auth 76, Payments & pricing 15, Task success pending, Maintenance & community 83, Transparency & trust 78 · total over the 7 assessed categories - Why: Reliability, Scored with the hosted lines, because the server is an HTTP endpoint on a Sourcegraph Cloud or self-hosted instance. · Schema & documentation, The docs list each tool's parameters with required and optional marks, defaults and maximums. · Agent ergonomics, Sixteen documented tools on /.api/mcp/all, nine on the default endpoint and two on /.api/mcp/deepsearch, and admins can remove tools with… · Security & auth, OAuth 2.0 with PKCE, dynamic client registration held to the `mcp` scope, one-hour access tokens, a revocation endpoint and bearer tokens in… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The latest Cloud update notes are dated 5 October 2026, and self-hosted 8.0.0 shipped on 17 September 2026 with a new `list_refs` tool (30). · Transparency & trust, Closed source under the Sourcegraph Terms of Service, last modified 22 July 2026, with supplemental terms listed in one index (15). - Sources: 21, open questions: 7, both in the full twin - Capabilities: code.repo, code.git - JSON: https://www.anchorterminal.com/api/v1/tools/sourcegraph-mcp.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/sourcegraph-mcp.svg` or a link to https://www.anchorterminal.com/tools/sourcegraph-mcp from a page on sourcegraph.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Connect to https:///.api/mcp for the nine core tools. Use /.api/mcp/all for `go_to_definition`, `find_references`, `nls_search` and `compare_revisions` 2. Request only the `mcp` scope in OAuth. Any other scope on the MCP resource fails with `invalid_scope` 3. Without OAuth, send `Authorization: token ` and create the token with the `mcp` scope and an expiry 4. Call `list_repos` first and name the repository in every `code_finder` task. It declines broad searches across repositories 5. Read large files with `startLine` and `endLine`. Files over 128KB return only the first 200 lines ## Connect ```bash claude mcp add --transport http sourcegraph https://sourcegraph.example.com/.api/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/sourcegraph-mcp ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | GitHub MCP Server | BB | 70.3 | code.repo | https://www.anchorterminal.com/tools/github-mcp-server.min.md | | Azure DevOps MCP Server | B | 66.3 | code.repo | https://www.anchorterminal.com/tools/azure-devops-mcp.min.md | | Atlassian Rovo MCP Server | C | 57.9 | code.repo | https://www.anchorterminal.com/tools/atlassian-rovo-mcp.min.md | | Git (MCP reference server) | D | 51.9 | code.git | https://www.anchorterminal.com/tools/git-reference-server.min.md | | Context7 | BB | 73 | same category | https://www.anchorterminal.com/tools/context7.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)