MCP Server Install Commands: What a Directory Audit Reveals About stdio and HTTP

A missing install command on an MCP directory page can mean two very different things. A hosted server may not need a local package at all. But if the server runs on your machine, that missing command might be the one thing you needed to get started. The blank field tells you very little on its own.

We counted install_cmd, transport, and endpoint fields in the AgentNDX src/data/servers.ts snapshot on October 2, 2026. This is an audit of directory records, not a test of whether the commands run, the URLs respond, or an agent can connect.

The split in the directory

The snapshot contains 1,496 server records. Of those, 824 have a nonempty install_cmd field and 672 do not. The transport split explains much of the gap:

Recorded transportRecordsWith install commandWithout install command
stdio872687185
HTTP619135484
SSE523
Total1,496824672

Roughly four in five stdio listings have an install command. For HTTP, it is closer to one in five. HTTP servers aren’t necessarily harder to use; a remote server may have nothing to install locally. The directory’s fields also leave some setup details out.

A stdio server generally runs as a local process launched by the MCP client. The client needs an executable command, any required arguments, and a way to pass credentials. Playwright MCP records npx @playwright/mcp as both its endpoint string and install command. GitHub MCP also records a launch command, but its API-key auth adds a separate setup step. A one-line command is not the whole connection recipe.

An HTTP server can instead be hosted elsewhere. AgentNDX records https://agentndx.ai/mcp as its endpoint and has no install command. In that case, asking for a package installer misses the point; the developer needs a client configuration and any auth or payment setup. But the HTTP label alone does not prove that a record contains a usable remote URL. Only 304 of the 619 HTTP records have an endpoint string beginning with http:// or https:// in this snapshot. That is a string-shape check, not an endpoint health check.

Where the missing command actually hurts

The 185 stdio records without an install command deserve a closer look. A local client cannot launch a server from a name alone unless that executable is already available in the user’s environment. Some records do provide a command-like endpoint. For example, the OpenAPI MCP record has uvx awslabs.openapi-mcp-server in endpoint while install_cmd is empty. Others, such as the Weaviate MCP record, have a bare weaviate-mcp-server endpoint string with no separate install command. Neither pattern tells you whether the package is available on your machine or what credentials it requires.

The same endpoint field is doing three jobs here: remote URL, local launch command, and sometimes just a name. Paste the wrong kind of value into your client’s URL field or a shell and it will fail. Read the upstream instructions before running a command or granting an agent access to an account.

HTTP listings have their own ambiguity. A missing install command is expected for a hosted service, but a hosted URL may still need OAuth, a scoped API key, workspace approval, or a paid account. Conversely, an HTTP transport can be served locally after installation. A transport label tells you how client and server communicate, not who hosts the server or whether setup is complete. For the connection-model basics, see our stdio transport guide and the Streamable HTTP explainer.

A better way to evaluate a listing

Start with the transport, then inspect the endpoint value. If it is stdio, look for the actual executable, package source, runtime prerequisites, arguments, and environment variables. If it is HTTP, determine whether the URL is a real MCP endpoint, whether it is remote or localhost, and how the client authenticates. Do not mistake a product homepage for the MCP endpoint.

Then open the project’s own documentation. Confirm the command or URL against the upstream source and connect in a limited-permission environment first. An install field records an instruction, not a successful install. An endpoint field records a string, not a successful handshake. Our local testing guide covers the checks to run after configuration; the server evaluation guide covers the trust decision before it.

For directory maintainers, the fix is in the schema. Give package source, launch command, remote MCP URL, client-config example, auth requirements, and last-tested date their own fields. Then a missing install command on a hosted listing is simply expected, while a missing launch command on a local listing is something to investigate. You still have to test the connection.

FAQ

Does a missing install command mean an MCP server is unusable? No. A hosted HTTP server may need only a URL and authorization in your client. A local stdio server with no command is a different case: check the upstream documentation for a launch procedure.

Do the 824 recorded install commands work? This audit did not run them. The count is of nonempty directory fields, not successful installations. Package names, versions, prerequisites, and auth can change after a listing is added.

Is every HTTP endpoint in the directory a hosted MCP URL? No. The transport field describes communication, not hosting. In this snapshot, fewer than half of HTTP records have an endpoint string beginning with an HTTP URL, and even a URL-shaped value still needs verification against the project’s documentation and a real client connection.