Context7 MCP: Current Library Docs for Your Coding Agent
Context7 feeds a coding agent up-to-date, version-specific documentation for the libraries it is using, so it stops writing code against APIs that have changed. Who runs it, how to add it to each client, what the API key changes, how it picks a library, what it costs in context, and how far to trust what it returns.
6 min read
Context7 is a documentation service run by Upstash that gives a coding agent current, version-specific docs and code examples for the libraries it is working with. You add it to Claude Code, Cursor, VS Code or another client as an MCP server, or install it as a skill that calls a small CLI, and the agent looks up the library before it writes code against it. An API key is optional: without one you use an anonymous tier with lower rate limits. The docs it returns come from a community-contributed index, so treat them as helpful input, not as instructions.
What Context7 is, and who runs it
Models learn libraries from their training data, which is months old by the time you use them. The result is code that calls a function that was renamed, or a config option that no longer exists. Context7 answers that by indexing library documentation and serving the relevant part on request, matched to the version you name.
It is an Upstash project. The Context7 repository (opens in a new tab) holds the MCP server’s source; the README says the API backend, the parsing engine and the crawling engine are private. It also says Context7 projects are community-contributed, and that Upstash cannot guarantee the accuracy, completeness or security of every library’s documentation. Both facts shape how you should use it.
How to add Context7 MCP
The quickest route is one command, npx ctx7 setup, which needs Node.js 18 or newer. It signs you in with OAuth, generates an API key, and lets you choose between two modes: CLI plus skills, or an MCP server. Add --claude, --cursor or --opencode to target one agent. npx ctx7 remove undoes it.
To configure it by hand, point your client at the hosted server, https://mcp.context7.com/mcp, and pass your key as a bearer token. Context7’s page of installation examples for MCP clients (opens in a new tab) gives the entry for each client; these are the common ones.
# Remote server claude mcp add --scope user --header "Authorization: Bearer YOUR_API_KEY" --transport http context7 https://mcp.context7.com/mcp # Local server claude mcp add --scope user context7 -- npx -y @upstash/context7-mcp --api-key YOUR_API_KEY
{
"mcpServers": {
"context7": {
"url": "https://mcp.context7.com/mcp",
"headers": { "Authorization": "Bearer YOUR_API_KEY" }
}
}
}VS Code takes the same server under a servers key with "type": "http", or you can use Context7’s VS Code extension. Do not paste a real key into a file you commit: VS Code’s input variables, covered in VS Code MCP security, keep it out of the repository. For Claude Code, --scope user stores the entry in your own ~/.claude.json rather than in a shared .mcp.json.
Do you need a Context7 API key?
No, but it changes two things. Context7’s Claude Code setup page (opens in a new tab) says that without a key, requests go through the anonymous tier, which has lower rate limits.
The Context7 overview (opens in a new tab) adds that a key gives you higher rate limits and lets you use your private repositories. Keys come from the Context7 dashboard. Some clients can sign in with OAuth instead, through a separate endpoint ending in /mcp/oauth.
In practice: try it without a key. If you hit rate limits in a long session, or you want your own private code indexed, create one. Treat it like any other credential, and revoke it from the dashboard if it leaks.
How it resolves a library
The MCP server offers two tools. resolve-library-id takes the library name and what you are trying to do, and returns candidate libraries, each with a Context7 ID in the form /org/project, a description, a count of code snippets, a source reputation of High, Medium, Low or Unknown, a benchmark score out of 100, and the versions available. The agent picks one. query-docs then takes that ID and a question and returns the matching documentation and examples.
- Skip the guess. If you know the library, name its ID in your prompt, for example “use library /supabase/supabase”, and the resolve step is skipped.
- Name the version. Mention it in the prompt, or use an ID of the form
/org/project/version, and Context7 matches it. - Watch the pick. Two packages with similar names can both appear. If the answer looks wrong, check which ID it chose before you blame the model.
- Nudge it once. A line in
CLAUDE.mdor your Cursor rules, such as “use Context7 whenever I need library or API documentation”, saves typing “use context7” in every prompt.
What it costs in context
Two small tool definitions cost little. The real cost is what comes back: each query-docs call adds a block of documentation and code to the conversation, and it stays there. The server’s own tool descriptions, in its source (opens in a new tab), tell the model not to call either tool more than three times per question and to keep each query to one concept.
Claude Code helps at both ends. Its MCP documentation (opens in a new tab) says tool search, on by default, defers tool definitions until they are needed, and that it warns when a single tool result passes 10,000 tokens, with a default ceiling of 25,000 you can change with MAX_MCP_OUTPUT_TOKENS. Specific questions keep results small: “how to set up JWT authentication in Express” fetches less than “auth”. For the wider habit, see reducing Claude Code token usage.
Context7 as an MCP server or as a skill
Context7 documents both, and ctx7 setup asks you to choose. In MCP mode the agent calls resolve-library-id and query-docs as native tools. In CLI plus skills mode, nothing is registered as a server: a skill tells the agent to run ctx7 library and ctx7 docs commands, and it triggers on its own when you ask about a library. Claude Code users can also install the Context7 plugin, which adds a /context7:docs command for a manual lookup.
- Choose MCP if your client has no skills, or you want the same server in several clients, including ones that cannot run a local command.
- Choose the skill if your agent supports skills and you want nothing loaded until a library question comes up.
The general trade-off between the two is in MCP vs Claude skills.
Trusting third-party docs
Everything query-docs returns is text written by someone else, collected from a public index, and placed straight into your agent’s context. Most of it is ordinary documentation. But text that reaches a model can carry instructions, and a poisoned README is a known route for indirect prompt injection. Context7 itself asks users to report suspicious, inappropriate or potentially harmful content through a Report button.
- Keep your client’s approval prompt on for anything that writes files or runs commands, so a line in the docs cannot quietly become an action.
- Prefer libraries with a High or Medium source reputation, and read the code the agent writes as you would code copied from a web page.
- Keep secrets out of queries. The tool descriptions say queries are sent to the Context7 API, and ask the model not to include keys, passwords, personal data or proprietary code.
- Check the server list you rely on, as you would any third-party server; MCP security risks covers the rest.
Library docs are half the context
Context7 knows how a library works. It does not know how your project uses it: the version you are pinned to on purpose, the wrapper everyone is meant to go through, the migration that is half done. That lives with the work. On a fenbs board it is the AI context, notes any assistant reads with fenbs_get_context before it starts, next to the tasks themselves. The library docs answer “how do I call this”, and the board answers “what are we doing and why”.
Related
What AI context holds: AI context. Connect a board next to Context7: Claude Code integration and Cursor integration. How an agent’s context fills up: the AI context window.