AI Tools

Arcade.dev Acquires Smithery, Merging MCP Registry with Execution Layer

Arcade.dev has acquired Smithery, a public registry for MCP servers, merging discovery with Arcade's execution and authorization layer. The deal, announced August 5, combines Smithery's catalog of tens of thousands of entries with Arcade's secure action layer, which handles delegated authorization and audit logging. Financial terms were undisclosed, and Smithery co-founder Anirudh Kamath joins Arcade. The acquisition raises questions about registry neutrality and grading independence, as Arcade also runs ToolBench, its own benchmark for MCP server quality.

Neura News

Neura News

Neura Market Editorial

August 11, 20266 min read
Arcade.dev Acquires Smithery, Merging MCP Registry with Execution Layer

Arcade.dev, a vendor of a secure action layer for AI agents, has acquired Smithery, a public registry and hosting platform for Model Context Protocol (MCP) servers. The acquisition, announced August 5, combines Smithery's discovery platform with Arcade's execution and authorization layer. Financial terms were not disclosed.

The deal marks the first time an MCP registry with developer mindshare has been bought by an execution layer vendor. Smithery's index grew to tens of thousands of entries covering MCP servers and Anthropic's Agent Skills format. Anirudh Kamath, co-founder of Smithery, joins the Arcade team as part of the acquisition.

One Vendor for Finding, Running, and Auditing Agent Tools

Arcade's pitch to enterprise buyers is now simpler. The company provides a secure action layer that handles delegated authorization, so an agent acts as a specific authenticated user with only that user's permissions. Every action taken by an agent through Arcade leaves an audit record.

The combination of registry and runtime makes the pitch to a CIO simple: one vendor finds the tool, runs it, and proves afterward which user it acted for. Arcade wants the request path at execution time to answer which agent did what, against which system, on whose behalf.

Arcade claims it authored the MCP authorization specification referenced by major clients and servers. The company's call volume grew 25 times in six months, according to Arcade.

The acquisition gives Arcade control over both the catalog and the runtime. That combination is what makes the pitch to a CIO simple. It also raises questions about how independent the catalog can remain.

The Quality Problem and Three Approaches to MCP Tooling

The underlying observation about poor quality of community MCP servers is easier to confirm. Common problems include malformed schemas, missing tool descriptions, and overlapping tool names. The rate of publishing MCP servers has outrun the rate of engineering.

Arcade's ToolBench benchmark indexed more than 43,400 MCP servers and analyzed 219,069 tools. Arcade reports that 0.5% of MCP servers earned an A grade on a scale from A+ to F. Read the 0.5% figure with caution since Arcade writes the rubric and sells the remedy.

The quality gap is a real problem. Publishing rate has outrun engineering rate. A grade assigned before the MCP breaking change may not describe how a server behaves after it.

The three approaches to MCP tooling differ in where trust is enforced. The official MCP Registry, launched in preview in September 2025, is described as a community-owned source of truth, built to be thin for downstream catalogs to mirror. It verifies namespaces and publishes metadata, stopping there by design.

Docker's MCP Catalog and Toolkit takes a different route. It containerizes servers with secret management, policy enforcement, and audit logging. Docker isolates the process and constrains what it can reach on the host.

Arcade's approach puts trust at the execution path. The company's position at the request path at execution time is the only position from which a security team can answer which agent did what, against which system, on whose behalf.

The Protocol Is Moving Under Everyone

Anthropic donated the MCP protocol to the Agentic AI Foundation under the Linux Foundation. Block, OpenAI, Google, Microsoft, and AWS supported the protocol donation. The MCP protocol is moving under everyone due to the breaking change in the 2026-07-28 release.

MCP maintainers used that release to remove the initialize handshake and session identifiers for remote servers. That is a breaking change. A grade assigned before that change may not describe how a server behaves after it.

The #1 Newsletter in AI

Stay ahead of the AI curve

The most important updates, news, and content — delivered weekly.

No spam. Unsubscribe anytime.

The official MCP Registry maintainers launched the registry in preview in September 2025. It is meant for downstream catalogs to mirror rather than serve as anyone's front end.

Funding and the Conflict of Interest Question

Arcade announced a $60 million Series A in June, led by SYN Ventures with strategic investment from Morgan Stanley and Wipro. Total funding for Arcade is $72 million.

Neutrality is a sharper problem. Developers adopted Smithery partly because it was not owned by a vendor selling the layer underneath. Arcade has not yet addressed the conflict of interest regarding controlling both registry and runtime.

How ranking, verification, and grading stay insulated from Arcade's own runtime business is an open question. The deal is small enough that terms would not move anyone's model of the market, but the direction matters. A registry with heavy traffic and thin revenue can be worth a great deal strategically and very little financially. Nothing in the announcement distinguishes a talent acquisition from a substantial purchase.

Arcade has not publicly addressed the conflict of interest. The company's ToolBench grading rubric is written by Arcade, which also sells the remedy. The rate of publishing MCP servers has outrun the rate of engineering, and that gap is what makes the registry valuable in the first place.

What Enterprise Buyers Should Ask

MCP tooling is no longer something a platform team assembles from free parts. It is becoming a procured layer with vendors, benchmarks, and contracts. Enterprises are pushing agents out of pilots and into production, and they need a catalog of tools and a runtime that can authorize and audit what those tools do.

Enterprise buyers should ask about portability of tool definitions, authorization policies, and audit records. They should ask whether ToolBench grading stays independent and reproducible. They should ask about pricing under load, especially when tool call volume spikes.

The scenario of one workflow tripling its tool calls after a model upgrade could turn a modest platform fee into a line item the CFO wants explained. Security teams who have been blocking agents from production now have a shorter list of vendors to evaluate.

Developers who valued Smithery for its speed should keep getting that speed. The acquisition signals a broader industry shift towards vendor-backed, procured MCP tooling solutions. The underlying observation about poor quality of community MCP servers is easier to confirm than any single benchmark grade.

The MCP protocol is now under the Agentic AI Foundation, with support from Block, OpenAI, Google, Microsoft, and AWS. The official MCP Registry remains thin by design. Docker continues to offer containerized servers with its own trust model.

Arcade's call volume grew 25 times in six months. The company's ToolBench benchmark analyzed 219,069 tools across more than 43,400 MCP servers. Only 0.5% earned an A grade.

The $60 million Series A in June brought Arcade's total funding to $72 million. The acquisition of Smithery adds a registry with tens of thousands of entries to that foundation.

The direction matters more than the deal size. MCP tooling is becoming a procured layer. The question of who controls the registry, the runtime, and the grading is now central to that market.

Related on Neura Market

More from Neura News

Product Launch

Microsoft Delays Teams Facilitator Question-Answering Feature to November, December

Microsoft has delayed the general availability of its Teams Facilitator question detection and answering feature to November, with worldwide availability in mid-December. The AI assistant, part of Microsoft 365 Copilot, will detect knowledge gaps in meetings and offer answers. The delay extends the timeline by about two months from the September estimate, with no official reason provided.

Aug 28·3 min read
Developer

Meta's MTIA 300 Puts Networking Inside the Chip to Speed Up Recommendation Training

Meta unveiled MTIA 300, its first in-house accelerator for training recommendation models, integrating networking and collective communication directly into the silicon. The chip delivers 1.2 TB/s of I/O bandwidth and reduces communication time by 3.9x on a 150-billion-parameter model, addressing the bottleneck where embedding tables dominate. This marks a strategic push in Meta's custom silicon portfolio, with four more generations planned.

Aug 28·5 min read