MCPNews

The Model Context Protocol ecosystem, verified

Current spec 2026-07-28

Context7

Current Spec Verified First-party Confidence: High (0.95)

Context7 is an MCP server published by Upstash with verified support for the current MCP specification revision (2026-07-28). It is the first-party server from Upstash. Last verified 2026-08-25.

Does Context7 support the current MCP specification (2026-07-28)?

Yes. Context7 has verified support for MCP revision 2026-07-28, the current stable specification (last verified 2026-08-25).

Is Context7 a first-party (official) MCP server?

Yes. Context7 is the first-party MCP server published by Upstash (last verified 2026-08-25).

How do I connect to Context7?

Context7 is available via a hosted remote endpoint at https://mcp.context7.com/mcp, the package npm:@upstash/context7-mcp, the official MCP Registry under io.github.upstash/context7, the source repository at https://github.com/upstash/context7. Authentication: api_key. Transports: streamable-http, stdio.

What tools does Context7 expose?

Context7 exposes 2 tools, including resolve-library-id, query-docs (last verified 2026-08-25).

Does Context7 support MCP revision 2026-07-28?

Yes. Context7 supports MCP revision 2026-07-28 (checked 2026-08-25).

When were Context7's facts last verified?

2026-08-25. Each fact on this page links to the sources used to verify it.

Which tools does Context7 expose?

2 tools verified.

  • resolve-library-id
  • query-docs

Which MCP concepts apply to Context7?

  • Stateless core - The 2026-07-28 revision's redesign of MCP from a bidirectional stateful protocol into a request/response stateless one: the initialize handshake and protocol-level session are removed, every request carries its protocol version, client identity, and capabilities in _meta, and any request can land on any server instance behind a plain load balancer.
  • Streamable HTTP - MCP's HTTP transport, introduced in the 2025-03-26 revision as the replacement for the original HTTP+SSE transport. A single endpoint accepts JSON-RPC POST requests; since 2026-07-28, requests must carry the Mcp-Method and Mcp-Name headers for header-based routing, and the legacy HTTP+SSE transport is formally deprecated.

Context7 is Upstash's documentation server for coding agents. It pulls current, version-specific library documentation and code examples into a prompt, addressing stale training data; the README's framing is that it places docs "straight from the source" into context. The open-source repository contains the MCP server only. Upstash discloses that the supporting API backend, parsing engine, and crawling engine are private.

The primary deployment is Upstash's hosted endpoint at https://mcp.context7.com/mcp, authorized with a bearer API key (free keys issue from context7.com/dashboard; anonymous use works at lower rate limits) with an OAuth variant at /mcp/oauth. A local stdio install via npm remains available, and the docs describe enterprise SSO paths alongside the API-key model.

Spec support is current, confirmed two ways on the same day. The @upstash/context7-mcp@4.0.0 release of 2026-08-07 states it migrated the server to the v2 SDK packages and "the 2026-07-28 protocol revision", with stateless HTTP for modern and legacy clients and Redis-backed sessions removed. A probe of the hosted endpoint that afternoon answered server/discover unauthenticated, reporting supportedVersions ["2026-07-28"] and serverInfo Context7 4.0.0.

One catalog caveat: the official MCP Registry record for io.github.upstash/context7 still describes version 1.0.31, published 2025-11-28, with no remote endpoint listed. The npm package and the hosted service are three major versions ahead of the registry record.

Which MCP spec revisions does Context7 support?

Context7 has 1 verified spec-support record. Each row lists the revision, the verified status, the evidence URL, and the date that fact was last checked.

Spec revision Status Last checked Evidence
MCP 2026-07-28 Supported Source

How widely adopted is Context7?

Ranked #3 in The MCP 500 with Adoption Index 81.78 (snapshot , methodology v1).

Measurement Value Source
Official MCP Registry yes API ·
Docker MCP Catalog no API ·
npm downloads (weekly) 1,132,952 API ·
GitHub stars 62,051 API ·
GitHub forks 2,996 API ·
Last push 2026-09-15T13:11:04Z API ·
Repository archived no API ·

Repository and package signals for Context7

Measured directly from the source registries, not asserted from a document. Each figure carries the date it was read; none of it affects the verified spec status above.

Repository as of

Created
Open issues
53
Primary language
TypeScript
License (repository)
MIT
Continuous integration
Present
Tests
None detected
Security policy
Present

Declared topics: llm, mcp, mcp-server, vibe-coding — author-declared on the repository, not our taxonomy.

Package (npm) as of

Latest version
4.0.3
Last published
First published
Releases
80
License (package)
MIT
Maintainers
8
Direct dependencies
8
Unpacked size
94 KB
Registry signature
Signed
Build provenance
No attestation

How was this verified, and what are the sources?

Verified · method: endpoint-probe · confidence 0.95 (High).

  1. Official MCP Registry record io.github.upstash/context7 version 1.0.31 (published 2025-11-28) - npm package @upstash/context7-mcp, stdio transport, no remote endpoint listed; the record is three major versions behind the current npm release - accessed
  2. @upstash/context7-mcp@4.0.0 release notes (published 2026-08-07) - "Migrate the MCP server to the v2 SDK (@modelcontextprotocol/{node, server,client} 2.0.0) and the 2026-07-28 protocol revision. HTTP serving is now stateless for both modern and legacy clients, and Redis-backed sessions are removed." - accessed
  3. Endpoint probe of https://mcp.context7.com/mcp - answered server/discover unauthenticated with supportedVersions ["2026-07-28"] and serverInfo Context7 4.0.0, over a streamable-http POST with an SSE-framed response; response headers advertise a Bearer WWW-Authenticate challenge with an RFC 9728 resource_metadata URL - accessed
  4. upstash/context7 README - "Context7 pulls up-to-date, version-specific documentation and code examples straight from the source"; documents the hosted server URL https://mcp.context7.com/mcp with an Authorization Bearer API key, a free key at context7.com/dashboard for higher rate limits, and discloses that the API backend, parsing engine, and crawling engine are private and not part of the repository - accessed
  5. Context7 client setup docs - document the remote endpoint https://mcp.context7.com/mcp with bearer-token auth and an OAuth 2.0 variant at https://mcp.context7.com/mcp/oauth; context7.com's footer states "Context7 is an Upstash project" - accessed
  6. Re-verification 2026-08-18 - npm @upstash/context7-mcp latest is 4.0.2 (published 2026-08-11), while the official registry record io.github.upstash/context7 still reads v1.0.31 (published 2025-11-28), so the registry entry lags the distributed package. CVE-2026-75130, published 2026-08-18, covers the custom-rules prompt injection in versions through 2.1.2, which Upstash fixed server-side on 2026-02-23 with 2.1.3 following on 2026-03-04 - accessed
  7. Endpoint probe of https://mcp.context7.com/mcp - answered server/discover at 2026-07-28; tools/list returned 2 tools - accessed