Brave Search MCP
an independent index, and the best security hygiene of the search servers
the proper first-party replacement for the archived reference server, and the only one thinking about dns rebinding.
brave's own server replaces the archived reference brave-search implementation. install is `npx -y @brave/brave-search-mcp-server --transport http` with `BRAVE_API_KEY` in the environment, plus a docker image and a stdio mode.
the security detail worth calling out is `BRAVE_MCP_ALLOWED_HOSTS`, an opt-in host-header allowlist providing dns-rebinding protection on the http transport. unset, the host header isn't validated; set, anything not on the list gets a 403. essentially no other mcp server does this, and it is the kind of thing that separates people who have thought about the threat model from people who haven't.
the description above is ours, condensed from the ranking. pricing moves — check it on the vendor's own page before you rely on it.
- category
- mcp servers
- pricing
- free tier; paid api for volume
- website
- github.com
the proper first-party replacement for the archived reference server, and the only one thinking about dns rebinding.
we researched this category against vendors' own pricing pages and licence files. that is where this line comes from — not from the vendor, and not from anything they paid for.