"Free" and "no API key" are not the same thing in the MCP world. A server can have a free tier that still makes you create an account, mint a token and paste it into a config file before an agent can make its first call. For an autonomous agent, or a developer who wants to try a tool before adopting it, that provisioning step is the whole cost.
So instead of repeating what vendor pages say, we tested it. On 5 September 2026 we pointed a plain HTTP client, with no cookies, no token and no key, at 24 public remote MCP endpoints and ran the same three-step probe against each one: an MCP initialize handshake, a tools/list, and then one real tools/call with sensible arguments. An endpoint only counts as keyless below if all three succeeded anonymously.
The ten that answered with no account and no key
Server | Endpoint (Streamable HTTP) | Tools without a key | What it is for |
|---|---|---|---|
Moltline Studio |
| 110 of 160 | Deterministic work tools: code review, date maths, CSV analytics, pricing arithmetic, shipping economics, research formatting, a SKILL.md linter, and a catalogue of 138 agent skills |
DeepWiki |
| 3 | Ask questions about any public GitHub repository and read its generated wiki |
Context7 |
| 2 | Resolve a library name and query its current documentation |
Cloudflare Docs |
| 2 | Search Cloudflare's developer documentation |
Microsoft Learn |
| 3 | Search and fetch Microsoft Learn docs and code samples |
Hugging Face |
| 4 | Search the Hub, read repository details and files |
Firecrawl |
| 3 | Scrape a URL to markdown, web search, parse |
Astro Docs |
| 1 | Search the Astro documentation |
GitMCP |
| 4 per repo | Fetch and search a repository's documentation and code |
Exa |
| 2 | Web search and page fetch |
A few notes from the probe, because the table hides them.
Moltline Studio is ours, so apply the same test to it rather than taking our word: every one of the servers at mcp.moltlinestudio.com accepted the anonymous handshake (19 on the day of the probe; the three added on 6 September 2026, regclock, taxlots and optimize, passed the same three-step probe the day they went live), and an automated check on our side re-measures that every day. Of the 160 tools, 110 run with nothing more than the URL; the other 50 answer an unlicensed call with a machine-readable refusal (HTTP 200, a JSON body naming the price) rather than a login wall.
DeepWiki, Context7, Cloudflare Docs, Microsoft Learn and Astro Docs are documentation servers. They exist so an agent can read the current docs instead of the training-data version, and all of them answered a real search or structure query anonymously. Context7 also accepts a key; the anonymous path worked in our test and we did not measure where its limits sit.
Hugging Face exposed four tools with no token: hf_whoami, hub_repo_search, hub_repo_details and hf_fs. Signing in adds more, which we did not test.
Firecrawl exposed a keyless trio: firecrawl_scrape, firecrawl_search and firecrawl_parse. Our anonymous scrape of example.com came back as markdown. Crawl, map and agent tools are behind a key.
GitMCP turns any public repository into an MCP server by URL. The handshake and the search call worked anonymously; the search itself returned nothing for our query, which says more about the index than about access.
Exa answered an anonymous web_search_exa with real results. We are reporting what we observed on the day; read Exa's own terms before building on it.
The eleven that require a login
Server | Endpoint | What the challenge said |
|---|---|---|
GitHub |
| 401, "No access token was provided" |
Stripe |
| 401, OAuth protected resource |
Notion |
| 401, OAuth realm |
Linear |
| 401, OAuth realm |
Supabase |
| 401, "No access token was provided" |
Vercel |
| 401, "No authorization provided" |
Sentry |
| 401, OAuth realm |
Semgrep |
| 401, "Authentication required" |
Tavily |
| 401, OAuth protected resource |
Zapier |
| 401, invalid token |
Apify |
| 401, OAuth realm |
None of these is doing anything wrong. They front account-scoped products: your repositories, your customers, your workspace. A server that reads your Stripe balance had better ask who you are. The point of listing them is only that "has an MCP server" does not mean "an agent can use it without a human first completing a login flow", and for unattended pipelines that distinction decides whether the tool exists at all.
What keyless actually means
Three caveats before you wire any of the ten into a production agent.
Keyless does not mean unlimited. Every anonymous tier we tested is rate-limited in some way, and the limits are the vendor's to change. We deliberately did not publish numbers we could not measure.
Keyless tiers grow with a key. Hugging Face, Firecrawl and Context7 all expose more once you identify yourself. The anonymous surface is an on-ramp, and a good one, because you can see real output before you create anything.
Keyless today is not keyless forever. The probe above is a snapshot from 5 September 2026. Endpoints move, tiers close, and the two "remote reference server" URLs we expected to include no longer resolved at all. Re-run the test before you rely on a result; the method is at the end of this post and takes a minute.
Adding one to Claude Code or Cursor
Every server in the first table speaks Streamable HTTP, so the configuration is a URL and nothing else. In Cursor (~/.cursor/mcp.json):
{
"mcpServers": {
"moltline-catalog": { "url": "https://mcp.moltlinestudio.com/catalog" },
"deepwiki": { "url": "https://mcp.deepwiki.com/mcp" },
"context7": { "url": "https://mcp.context7.com/mcp" }
}
}
In Claude Code, the equivalent is one command per server:
claude mcp add --transport http moltline-catalog https://mcp.moltlinestudio.com/catalog
claude mcp add --transport http deepwiki https://mcp.deepwiki.com/mcp
In Claude Desktop, add the same URL as a custom connector. Restart the client, list the tools, then actually call one. A tool list that loads is a necessary signal, not a sufficient one; the call is the test.
Where Moltline's paid tier fits
Since our own servers are in the list, the terms in one paragraph. The 110 free tools are the permanent baseline, not a trial. The remaining 50 unlock with one All-Access licence at $19 a month, billed monthly through NOWPayments, settled in cryptocurrency and cancellable at any time; the key covers every server. An agent can buy the same month without a human present: https://moltlinestudio.com/api answers with an HTTP 402 carrying an x402 payment demand in USDC on Base, and a retry with the transaction hash returns the licence key. Nothing is metered per call on either route.
The method, so you can repeat it
Each endpoint received three JSON-RPC 2.0 requests over HTTPS with Content-Type: application/json and Accept: application/json, text/event-stream, no Authorization header, no cookies, and an identifying User-Agent:
initializewithprotocolVersion2025-06-18and an empty capabilities object, followed by anotifications/initializednotification (re-sending theMcp-Session-Idheader if the server returned one).tools/list.One
tools/callwith plausible arguments, for exampleread_wiki_structureon a public repository,resolve-library-idfor a well-known library, or a documentation search for a common term.
An endpoint was scored keyless only if all three returned a result; a 401 or 403 at any step, or a WWW-Authenticate challenge, scored it as requiring a login. The probe ran from a single IP on 5 September 2026 between 08:55 and 08:57 UTC. Twenty-four endpoints were tried: the ten and eleven above, two remote reference-server URLs that no longer resolved, and a second Moltline server to confirm the first result was not a fluke.
If you run the same probe and get a different answer, the endpoint changed, not the method. That is the reason to keep the method rather than the list.