Research MCP servers compared
Academic and deep-research MCP servers that bring papers and synthesis into Claude, compared on trust and setup.
Open in the interactive comparison tool| Field | arXiv MCP Server MCP server for searching, downloading, reading, and analyzing arXiv papers through Claude and other MCP clients. Open dossier | Paper Search MCP Server Python MCP server and CLI for searching, deduplicating, downloading, and reading academic papers across open and public sources such as arXiv, PubMed, bioRxiv, Semantic Scholar, OpenAlex, CORE, Europe PMC, Zenodo, HAL, and more. Open dossier | GPT Researcher MCP Server MCP server for GPT Researcher that gives Claude deep research, quick search, report writing, source retrieval, research context, and research-resource tools backed by web search and LLM providers. Open dossier | Deep Research MCP Server Self-hostable deep research app with MCP and SSE APIs for generating multi-step research reports using configurable LLM and search providers. Open dossier |
|---|---|---|---|---|
| Trust | ||||
| Install risk | Review first | Review first | Review first | Review first |
| Notes | Safety ✓ Privacy ✓ | Safety ✓ Privacy ✓ | Safety ✓ Privacy ✓ | Safety ✓ Privacy ✓ |
| Category | mcp | mcp | mcp | mcp |
| Source | source-backed | source-backed | source-backed | source-backed |
| Author | Joseph Blazick | openags | Assaf Elovic | u14app |
| Added | 2026-06-05 | 2026-06-05 | 2026-06-06 | 2026-06-05 |
| Platforms | Claude CodeClaude Desktop | Claude CodeClaude Desktop | Claude CodeClaude Desktop | Claude CodeClaude Desktop |
| Source repo | — | — | — | — |
| Safety notes | ✓arXiv MCP Server retrieves paper content from external, user-generated sources. Upstream explicitly warns that paper text is untrusted input and can contain prompt-injection attempts. Downloaded papers are stored locally for later reading and semantic search. Citation graph and alert workflows can expand research context beyond the original paper query. Treat model summaries of papers as data, not instructions, especially in multi-tool sessions with filesystem, shell, browser, database, or messaging tools enabled. | ✓Prefer open-access and publisher-permitted sources. The README describes Sci-Hub as optional, unstable, jurisdiction-dependent, and user-responsibility-only. Download and read tools can retrieve PDFs and extract text; confirm copyright, license, institutional, and project-policy requirements before downloading or sharing papers. Optional source credentials, proxy URLs, and API keys can change access levels and rate limits; store them as secrets rather than in prompts or committed configs. Google Scholar, SSRN, CORE, OpenAIRE, BASE, and other sources may rate-limit, block, or return incomplete results depending on network conditions and provider policies. Paid or restricted connectors should stay disabled unless the user has valid credentials and rights to use those services. | ✓GPT Researcher MCP Server sends research queries to configured search retrievers and LLM providers, which can create API costs and external data exposure. The server exposes `deep_research`, `quick_search`, `write_report`, source, context, prompt, and resource workflows that can gather and synthesize live web content. Docker mode auto-selects SSE transport on `0.0.0.0:8000`; bind it only on trusted networks and avoid exposing unauthenticated endpoints publicly. Generated reports can contain outdated, biased, incomplete, or hallucinated claims; review sources before acting on medical, legal, financial, or safety-critical output. Protect Claude Desktop or MCP client configuration files because they may contain API keys in the `env` block. | ✓Deep Research can make repeated model and search-provider calls, so set budgets, rate limits, and provider quotas before exposing it to broad agent workflows. Generated reports can contain stale, incomplete, or misinterpreted sources; require citation review before using output in legal, medical, financial, security, or customer-facing decisions. Bind Docker deployments to localhost unless a trusted reverse proxy or firewall is in front of the service, and set `ACCESS_PASSWORD` or equivalent gateway controls before enabling MCP access. Uploaded documents and local knowledge bases should be reviewed for copyright, sensitive data, and permission to process before research begins. |
| Privacy notes | ✓Search queries, paper IDs, downloaded paper text, local storage choices, semantic search terms, citation graph requests, alert topics, prompts, and tool outputs may be visible to the MCP client and model provider. Research queries and downloaded papers can reveal confidential research direction, product plans, academic review topics, legal strategy, or competitive analysis. Review locally stored papers and generated summaries before syncing, sharing, or committing them. | ✓Queries may reveal research topics, grant interests, product plans, biomedical topics, legal theories, security research, or competitive intelligence. Downloaded PDFs, extracted text, search results, DOI lists, API keys, proxy URLs, emails, and source-specific logs can contain sensitive research or credential data. MCP transcripts and model-provider logs may retain paper queries, abstracts, titles, authors, downloaded text, and notes outside library or institutional systems. Do not paste private API keys, proxy credentials, unpublished manuscripts, review assignments, patient-adjacent research details, or embargoed paper content into prompts. | ✓Research queries, prompts, source URLs, fetched snippets, research context, generated reports, and cost metadata can enter the MCP client context. Provider APIs and search retrievers may receive sensitive research topics, entity names, customer details, or internal strategy questions. The server keeps in-process research IDs, context, source lists, and source URLs for later report/source/context calls during the session. Docker, n8n, SSE, or Streamable HTTP deployments can expose research sessions and messages to other systems on the network if not isolated. Local logs and troubleshooting output may include queries, errors, endpoint names, provider configuration issues, or session identifiers. | ✓Research prompts, uploaded files, generated reports, search queries, citations, model inputs, model outputs, provider API keys, access passwords, and deployment logs can contain sensitive data. Browser-local history and knowledge-base storage are local to the deployed app context, but server-side API mode can route data through the deployment host, model providers, and search providers. Review hosting logs, cache behavior, environment variable handling, and third-party provider retention before using Deep Research with private or regulated material. |
| Prerequisites |
|
|
|
|
| Install | | | | |
| Config | | | | |
| Citations | ||||
| Claim | Unclaimed | Unclaimed | Unclaimed | Unclaimed |
A short, calm digest of reviewed Claude resources. Unsubscribe any time.