Zoteus logo

Zoteus

Verified

by oscardvs

⚡ The everything Zotero MCP server: complete Zotero Web API v3 + desktop local API for Claude & any MCP client. Search, safe writes, add-by-DOI, CSL citations, hybrid semantic search, and a scholarly-context graph. TypeScript, local-first.

Set up this server

01 / Choose your client

02 / Before you connect

Authentication is not specified. Check the project instructions before connecting.

Install the runtime required by the project and make it available to your client.

Project instructions

Use names from the project instructions, separated by commas. Enter names only, never secret values.

03 / Add the configuration

Source: generated from public install instructions

claude mcp add --transport stdio 'zoteus' -- 'npx' '-y' '@oscardvs/zoteus'

Run in your terminal after replacing any placeholders.

04 / Check it in your client

Open your client’s MCP settings and confirm the server connects and lists its tools. A copied configuration does not confirm a working connection.

academicanthropicbibliographycitationcitationsclaudecslmcpmcp-servermodel-context-protocolreference-managerresearchsemantic-searchtypescriptzoterozotero-api

More in Search & Web

Browse the full directory

Badge

Show this listing on your README and website

You are one of MCPVault's first 100 verified servers: verified for good, badge or no badge. Put it on your README or site if you want a live Verified proof link for visitors.

Security profile

Exposure: Broad

Reaches into the environment, credential files or other agents' configuration.

What this server can reach, from a static read of the shipped code. Nothing was executed and nothing here is a verdict: a browser tool has to run commands and an API wrapper has to call its API. Decide what fits your setup.

NVIDIA SkillSpector v2.11.0, MCPVault MCP-server policy. Scanned 4 days ago @ 941dc5e.

Detected

  • Talks to external services8 places

    Makes outbound requests. The hosts are listed so you can see where data goes.

    api.github.com, api.openai.com, api.openalex.org, api.zotero.org

  • Loads code at runtime1 places

    Uses eval, dynamic imports or encoded payloads, which static review cannot fully follow.

  • Accesses credential files2 places

    References SSH keys, cloud credential files or token stores.

  • Reads local configuration files1 places

    Loads a .env, .npmrc or config file. Normal for a server that needs an API key.

  • Contains instructions aimed at AI agents4 places

    Text in code or agent-facing files that steers a model. Worth reading before you trust it.

  • Passes model output on without checks1 places

    Model output reaches HTML, SQL or a shell without validation.

  • Runs unpinned packages at runtime10 places

    Executes npx or uvx without a version, so a compromised upstream release would run.

Not detected: reads environment variables in bulk, sends conversation content outward, runs shell commands, reads or writes other agents' configuration, uses elevated privileges, installs itself to run later, matches a known malicious pattern.

Dependencies with known advisories

None found in the lockfiles and manifests checked against OSV.dev.

Left out of the profile

23 pattern matches in documentation, configuration or CI files were recorded but are not part of the profile, because they do not run when the server does. The owner dashboard lists them.

How the profile works Maintainers see file, line and a fix for each item in their dashboard.
34Tools reported by the last successful handshake

0 of 0 tools · Observed tool names: 34/34

Observed tool names (34)

Reported by a complete handshake for the current saved configuration. Tools were listed, not invoked.

· 1.3.0

search_toolszotero_annotatezotero_attach_filezotero_attachmentzotero_bibliographyzotero_create_itemszotero_delete_itemszotero_evidence_tablezotero_exportzotero_format_bibliographyzotero_fulltextzotero_get_fulltextzotero_get_itemzotero_groupszotero_importzotero_indexzotero_list_collectionszotero_list_tagszotero_manage_collectionszotero_manage_tagszotero_merge_itemszotero_pdf_imageszotero_saved_searcheszotero_schemazotero_scholarzotero_search_itemszotero_semantic_searchzotero_styleszotero_synczotero_tag_auditzotero_trash_itemszotero_update_itemzotero_whoamizotero_word_document

Documented tools (0)

From project documentation. A server handshake does not verify each tool’s description or behavior.

Tool descriptions have not been documented here yet.

Tool change history

Compared across complete checks of the same configuration. Tools were listed, not invoked. Input-schema changes are not measured here.

  1. Oct 1, 2026, 02:22 AM UTC

    Compared with Sep 23, 2026, 02:23 AM UTC

    No tool-name changes

  2. Sep 23, 2026, 02:23 AM UTC

    Compared with Sep 15, 2026, 02:22 AM UTC

    + 3 Added

    • zotero_evidence_table
    • zotero_merge_items
    • zotero_word_document

    − 0 Removed

    FAQ

    Questions about Zoteus MCP Server

    How do I connect Zoteus MCP Server to Claude?
    Run `claude mcp add zoteus -- npx -y @oscardvs/zoteus` in Claude Code, or add the same command and arguments under mcpServers in Cursor's mcp.json or Claude Desktop's claude_desktop_config.json, then restart the client. The blocks above are ready to paste.
    Is Zoteus MCP Server free?
    The listed licence is MIT. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
    What can Zoteus MCP Server do?
    MCPVault has not yet recorded the tool list for Zoteus MCP Server; it is captured when the server passes a live MCP handshake. The description above is what the project publishes.