PluginBench
MCP Server
Maintained
Apache-2.0

OpenResearch MCP MCP Server

io.github.olanokhin/openresearch-mcp

Zero-auth research MCP: web, academic, finance, news, weather, macro, social, SEC filings—22 tools, no API keys.

What is the OpenResearch MCP MCP server?

The OpenResearch MCP server is a zero-authentication research tool that gives AI agents like Claude and Cursor access to 22 cross-domain data sources: web search, academic papers, GitHub repos, news, financial data, SEC filings, weather, macro indicators, and social platforms. It requires no API keys and is security-hardened for local-first agents.

OpenResearch MCP bundles web search, academic literature, financial data, news, weather, macro indicators, SEC filings, and social media into a single MCP server with no authentication required. It's designed for research agents that need to chain multiple sources together—e.g., pulling a company's SEC financials, then finding recent news on its strategy—without managing API keys or quotas. All 22 tools work out of the box with optional environment variables to raise rate limits.

How to install OpenResearch MCP

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • GITHUB_TOKEN
    secret

    GitHub token — increases rate limit from 60 to 5,000 req/hr

  • OPENALEX_EMAIL

    Your email for the OpenAlex polite pool (higher rate limits)

  • STACKEXCHANGE_KEY
    secret

    Stack Exchange API key for higher daily quota on Stack Overflow searches

  • SEC_USER_AGENT

    Your contact email/string for SEC EDGAR fair-access; a default is used otherwise

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "openresearch-mcp": {
      "command": "uvx",
      "args": [
        "openresearch-mcp"
      ],
      "env": {
        "GITHUB_TOKEN": "<YOUR_GITHUB_TOKEN>",
        "OPENALEX_EMAIL": "<YOUR_OPENALEX_EMAIL>",
        "STACKEXCHANGE_KEY": "<YOUR_STACKEXCHANGE_KEY>",
        "SEC_USER_AGENT": "<YOUR_SEC_USER_AGENT>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • web_search — Search the web via DuckDuckGo with optional domain scoping
  • read_url — Fetch and clean text from any webpage
  • read_pdf — Extract text from PDFs or arXiv papers
  • read_repo — Fetch README, file tree, and key docs from public GitHub repos
  • search_hacker_news — Search Hacker News stories with points and comment counts
  • search_stackoverflow — Search Stack Overflow questions and answers
  • search_openalex — Search 250M+ academic works via OpenAlex
  • get_youtube_transcript — Retrieve captions/transcripts from YouTube videos
  • get_current_date — Get current UTC date/time to anchor relative time queries
  • get_weather_forecast — Fetch current conditions and up to 16-day forecast by place name
  • get_historical_weather — Retrieve climate data since 1940 for a location and date range
  • search_indicators — Find World Bank indicator codes by keyword
  • get_country_indicator — Fetch yearly socio-economic series (GDP, population, inflation, etc.) by country
  • get_fx_rate — Get currency exchange rates (current, historical, or time-series)
  • get_crypto_price — Fetch cryptocurrency prices via CoinGecko
  • search_news — Search fresh global news via GDELT
  • search_europepmc — Search biomedical and life-science papers with open-access flags
  • search_bluesky_users — Find Bluesky profiles by name, handle, or bio
  • get_bluesky_profile — Retrieve full bio and follower/post counts for a Bluesky handle
  • read_bluesky_feed — Fetch a user's recent original posts from Bluesky

Use cases

  • Pull a company's latest annual revenue from SEC filings and cross-reference with recent news on its strategy
  • Search academic papers on a topic, retrieve open-access PDFs, and extract key findings
  • Get macro indicators (GDP, inflation, migration) for a country and correlate with historical weather or currency rates
  • Find researcher profiles on Bluesky and read their recent posts
  • Search Stack Overflow and Hacker News for solutions to a coding problem with discussion context

OpenResearch MCP MCP server FAQ

What is OpenResearch MCP?

It's a zero-authentication MCP server that bundles 22 research tools—web search, academic papers, SEC filings, news, weather, macro data, and social media—into one install. No API keys required; all tools work out of the box.

Is it free?

Yes. All 22 tools are free and work without keys. Optional environment variables (GitHub token, OpenAlex email, etc.) raise rate limits but are not required.

How do I install it in Claude Desktop?

Edit ~/Library/Application Support/Claude/claude_desktop_config.json (or %APPDATA%\Claude\claude_desktop_config.json on Windows) and add the server with command 'uvx' and args ['openresearch-mcp', '--stdio']. Restart Claude Desktop.

How do I install it in Cursor?

Create or edit ~/.cursor/mcp.json (global) or .cursor/mcp.json (per-project) and add the server with command 'uvx' and args ['openresearch-mcp', '--stdio'].

Do I need authentication or API keys?

No. All tools work without keys. You can optionally set GITHUB_TOKEN, OPENALEX_EMAIL, STACKEXCHANGE_KEY, or SEC_USER_AGENT to increase rate limits, but they are not required.

What are the security considerations?

The server is SSRF-hardened, loopback-bound by default, and security-reviewed against OWASP for AI agents. When binding beyond loopback, put an auth/rate-limit gateway in front. Weather data (Open-Meteo) is CC BY 4.0 licensed for non-commercial use; commercial use requires a paid plan.

README (reference)

Source of truth, from the repository.

openresearch-mcp

PyPI version Python versions License CI MCP Registry

Zero-auth, security-hardened research MCP for cross-domain agents.

Give Claude, Cursor, OpenCode, Open WebUI, or any MCP-compatible agent a full research stack — web search, academic papers, PDFs, GitHub repos, news, macro & finance data, SEC filings, biomedical literature, Bluesky, and YouTube — with no API keys to manage. 22 tools, one install.

Why

Research agents are only as good as the sources they can reach. But every extra source usually means another API key, another signup, another quota to babysit — and more attack surface.

openresearch-mcp is built for local-first agents that need useful public data now, with safer defaults:

  • No logins, no keys — every tool works out of the box; optional env vars only raise rate limits.
  • Hardened by design — loopback-bound by default, SSRF-filtered URL fetching, prompt-injection-aware extraction, bounded downloads, graceful failures. Security-reviewed against OWASP for AI agents.
  • Cheap in context — the whole 22-tool surface is a measured ~6.2K tokens (~3% of a 200K window), and the number is generated by a script in the repo, not guessed.

What you can do

The value isn't 22 tools in isolation — it's chaining them into one cross-domain research pass:

  • Company research → search_sec_filings / get_company_financials → search_news → read_repo → read_url
  • Academic deep-dive → search_openalex → search_europepmc → read_pdf
  • Macro & country context → search_indicators → get_country_indicator → get_fx_rate → get_historical_weather

Quickstart

uvx openresearch-mcp --stdio

Point any MCP client at it (Claude Desktop, Cursor, or an HTTP agent — see Connect) and ask something cross-domain:

"Pull Apple's latest annual revenue from its SEC filings, then find recent news on its AI strategy."

The agent chains get_company_financials → search_news for you — no keys, no setup.

Install

From the MCP Registry (recommended for Claude Desktop / Cursor)

The server is listed on the official MCP Registry as io.github.olanokhin/openresearch-mcp. Registry-aware clients can discover and install it without manual config — search for openresearch-mcp in your client's MCP browser.

From PyPI

# Zero install, always isolated — recommended for manual use
uvx openresearch-mcp

# Or install globally
pip install openresearch-mcp
openresearch-mcp

By default the server starts on http://127.0.0.1:8000/mcp (Streamable HTTP, MCP 1.1+) — bound to loopback so it is not exposed to your local network. To expose it (e.g. in a container or behind a gateway), bind all interfaces explicitly:

# Custom port
uvx openresearch-mcp --port 9000

# Bind all interfaces (only behind an auth/rate-limit gateway)
uvx openresearch-mcp --host 0.0.0.0 --port 9000

Note: when binding beyond loopback, put an auth/rate-limit gateway in front. The server is zero-auth by design, and read_url/read_pdf fetch arbitrary URLs (private/link-local/loopback ranges are blocked to prevent SSRF, but rate limiting is your responsibility).

Connect to an MCP client

Claude Desktop

Edit ~/Library/Application Support/Claude/claude_desktop_config.json
(Windows: %APPDATA%\Claude\claude_desktop_config.json)

{
  "mcpServers": {
    "openresearch": {
      "command": "uvx",
      "args": ["openresearch-mcp", "--stdio"]
    }
  }
}

Restart Claude Desktop after saving. The server runs in stdio mode — no port needed.

Cursor

Create or edit ~/.cursor/mcp.json (global) or .cursor/mcp.json (per-project):

{
  "mcpServers": {
    "openresearch": {
      "command": "uvx",
      "args": ["openresearch-mcp", "--stdio"]
    }
  }
}

HTTP agents (OpenCode, Open WebUI, custom)

Start the server:

uvx openresearch-mcp
# or: openresearch-mcp

Point your agent at:

http://localhost:8000/mcp

Tools

<!-- context-cost:start -->

The ~Tok column is each tool's full definition (name + description + JSON input schema, as sent in tools/list) — injected into the agent context on every request.

ToolSourceNotes~Tok
web_searchDuckDuckGoOptional site= param to scope to a domain (e.g. arxiv.org)251
read_urlAny webpageStrips nav/scripts, returns clean text164
read_pdfAny PDF or arXivAccepts /abs/, /pdf/, /html/ arXiv URLs interchangeably181
read_repoGitHub public reposREADME + file tree + key docs; set GITHUB_TOKEN for 5k req/hr211
search_hacker_newsHN via AlgoliaStory search with points + comment counts206
search_stackoverflowStack Overflow APISet STACKEXCHANGE_KEY for higher quota212
search_openalexOpenAlex250M+ works, zero rate limiting; set OPENALEX_EMAIL for polite pool231
get_youtube_transcriptYouTube captionsAccepts full URLs, youtu.be/ links, shorts, or bare video IDs194
get_current_dateServer clockCurrent UTC date/time — anchors relative requests ("last 30 days") instead of guessing240
get_weather_forecastOpen-MeteoCurrent conditions + up to 16-day forecast by place name; no key. See licensing note below229
get_historical_weatherOpen-MeteoClimate series since 1940 for a place + date range, aggregated monthly/yearly; no key. See licensing note below328
search_indicatorsWorld BankFind an indicator code by keyword ("GDP", "migration"); feed into get_country_indicator240
get_country_indicatorWorld BankYearly socio-economic series (GDP, population, inflation, migration, life expectancy…) by country + code; no key338
get_fx_rateFrankfurter (ECB)Currency rates: latest, a historical date, or a date-range series (downsample week/month); no key367
get_crypto_priceCoinGeckoCrypto price (current or daily history) by coin id/symbol vs a quote currency; no key284
search_newsGDELTFresh global news on a topic (multilingual); returns articles to feed into read_url; no key (rate-limited ~1/5s)481
search_europepmcEurope PMCBiomedical/life-science papers; flags open-access and gives a PDF URL to feed into read_pdf; no key264
search_bluesky_usersBlueskyFind researcher/dev profiles by name, handle, or bio; no key227
get_bluesky_profileBlueskyFull bio + follower/post counts for a handle; no key200
read_bluesky_feedBlueskyA user's recent original posts (reposts/replies filtered); no key228
get_company_financialsSEC EDGARAnnual revenue, earnings, assets for a US-listed company by ticker (10-K filings); no key (set SEC_USER_AGENT for heavy use)233
search_sec_filingsSEC EDGARFull-text search of filings (10-K/10-Q/8-K) by keyword/company; returns a document URL to feed into read_url/read_pdf; no key300
All 22 tool definitions5,609
Server instructionsselection guide + chaining recipes815
Total per request≈ 3% of a 200K context window6,424

Tokens measured with tiktoken o200k_base (GPT-4o / o-series encoding), offline; Claude's tokenizer differs by ~±10-15%. This table is generated — run uv run python scripts/context_cost.py --write; CI fails if it drifts.

<!-- context-cost:end -->

Optional env vars

All tools work without any keys. Set these to increase rate limits:

VariableEffect
GITHUB_TOKENGitHub: 60 → 5,000 req/hr
OPENALEX_EMAILOpenAlex polite pool (higher limits)
STACKEXCHANGE_KEYStack Overflow: higher daily quota
SEC_USER_AGENTYour contact (e.g. email) for SEC EDGAR fair-access; a default is used otherwise

Example with keys:

GITHUB_TOKEN=ghp_... OPENALEX_EMAIL=you@example.com uvx openresearch-mcp

Or in Claude Desktop config:

{
  "mcpServers": {
    "openresearch": {
      "command": "uvx",
      "args": ["openresearch-mcp", "--stdio"],
      "env": {
        "GITHUB_TOKEN": "ghp_...",
        "OPENALEX_EMAIL": "you@example.com"
      }
    }
  }
}

Security

openresearch-mcp was reviewed and hardened using agent-security-skill, an OWASP-aligned AI agent security review skill developed by the maintainer.

That review directly led to concrete hardening in this server: SSRF-resistant URL fetching, untrusted-content framing for tool outputs, bounded downloads, pinned GitHub Actions, dependency major-version caps, and regression tests for security-sensitive behavior.

See the hardening notes and current security posture in SECURITY.md.

Health check

When running in HTTP mode, check which sources are reachable:

curl http://localhost:8000/health
{
  "status": "ok",
  "sources": {
    "duckduckgo":    { "status": "ok", "latency_ms": 173 },
    "github":        { "status": "ok", "latency_ms": 101 },
    "hacker_news":   { "status": "ok", "latency_ms": 308 },
    "stackoverflow": { "status": "ok", "latency_ms": 247 },
    "openalex":      { "status": "ok", "latency_ms": 412 },
    "worldbank":     { "status": "ok", "latency_ms": 296 },
    "frankfurter":   { "status": "ok", "latency_ms": 184 },
    "europepmc":     { "status": "ok", "latency_ms": 356 },
    "bluesky":       { "status": "ok", "latency_ms": 152 },
    "youtube":       { "status": "ok", "latency_ms": 320 }
  }
}

status is "ok", "degraded" (some sources down), or "down" (all unreachable). HTTP 200 / 503. /health is a lightweight upstream reachability sample, not a per-tool status matrix. Rate-limited or policy-sensitive sources (GDELT, SEC, CoinGecko, etc.) are checked when their tools are called.

Known limitations

  • Reddit / Zenodo: block unauthenticated scraping — not included
  • YouTube: rate-limited at scale; works well for personal/low-volume use
  • Weather (Open-Meteo): data is licensed CC BY 4.0 and free for non-commercial use up to ~10,000 requests/day. Commercial use requires Open-Meteo's paid plan or self-hosting — embedding get_weather_forecast in a commercial product without one inherits a license obligation. Attribution to Open-Meteo is required.
  • PDF parsing: read_pdf parses untrusted PDFs in-process (with download-size and page caps). Fine for personal/low-volume use; a public high-volume deployment should isolate parsing in a subprocess with CPU/memory limits.

Roadmap

  • Reddit OAuth (browser-based, no user key management)
  • GitHub Device Flow login
  • PubMed / NCBI (optional key)
  • NewsAPI support (optional key)

License

Apache 2.0

<!-- mcp-name: io.github.olanokhin/openresearch-mcp -->

Related MCP servers

CACamptocamp logo

Camptocamp

Maintained

API Camptocamp.org : itinéraires alpins, sommets et points de passage.

1
TypeScript
MIT
View repository →

Passport, mandate, fail-closed action gate and tamper-evident journal for AI agents.

4
Python
AGPL-3.0
View repository →

A Test MCP server that provides tools, promts and resources

0
Python
View repository →

A Test MCP server that provides tools, promts and resources

PMPMB AI logo

PMB AI

Active

Local-first persistent memory for AI coding agents—SQLite-backed, no cloud, no API keys.

290
Python
Apache-2.0
View repository →

Access the GLEIF LEI database for company verification, KYC, and ownership research.

6
Go
MIT
View repository →