Brave Search MCP Server
1,478 starsBrave's official MCP server: exposes the full Brave Search API surface to agents — web search, local business, places, images, video, news, LLM context and AI summarization. stdio is the default transport; BRAVE_MCP_TRANSPORT=http switches to HTTP (bound to 127.0.0.1:8080 by default), with allow/deny-list env vars for individual tools.
- First published:2025-06-12
- data as of:
- 2026-09-30
- Licence:
- MIT
- Transport:
- stdio / http
- Primitives exposed:
- tools
What it can touch
Outbound to the Brave Search API (queries leave the machine), consuming your API key quota; no local file access. HTTP mode opens an unauthenticated local endpoint (officially described as unauthenticated), bound to loopback by default.
Risk
The official README warns itself: setting BRAVE_MCP_HOST to 0.0.0.0 exposes the unauthenticated HTTP endpoint on all interfaces, letting anyone on the network spend your key — trusted networks only. Search results are third-party content with injection risk; queries leak intent. It ships DNS-rebinding protection (Origin checks) but does not validate the Host header by default.
Install prompt
先到 Brave Search API 控制台取得 API key,再從官方倉庫 README 取得設定片段(以 npx 啟動 @brave/brave-search-mcp-server,用 BRAVE_API_KEY 環境變數傳入金鑰),加進客戶端設定後重啟。Paste this to your agent. It deliberately contains no tool subcommands — check the tool's official docs for commands.