Go to Content
RUEN中文

Development19 min of readingAuthor: The SystemsLab command

Which web search to connect to Claude Code in Russia and how not to harm?

The final article of the series on free search for Claude Code: what works for users from Russia, what is dangerous about the MCP search server, what is known about the quality and consumption of tokens, and the final cheat sheet "what to choose".

Разработчик в российском офисе за рабочим столом, на мониторе поисковая выдача и окно терминала

Briefly

  • Russia is not included in the list of countries where Anthropic services officially operate. Through third-party gateways, the built-in WebSearch is most likely not performed, so the MCP search server for the Russian user Claude Code is a necessity.
  • Free Russian-language issuance is provided by your SearXNG and multi-engine servers without keys (agent-search-mcp includes Yandex). For a fee and with Russian payment — Yandex Search API with the official MCP server: 488 rubles per 1000 synchronous requests per day (including VAT), there is no free limit.
  • Any search server brings someone else's text into the agent context. Anthropic directly warns about the risk of prompt injection and does not check third-party MCP servers for security.
  • In the only independent benchmark of search APIs (AIMultiple, 8 services, 100 English-language queries), the first four places are statistically indistinguishable. There are no benchmarks in Russian.
  • A stable scheme for September 2026 consists of two layers: its own SearXNG as the basis and one or two cloud endpoints with a monthly free quota as a backup option.

This is the fifth and final article of five in the series "Free Internet Search for Claude Code". In the series: built—in WebSearch and WebFetch and MCP connection; services with API and free tariff; search without keys and on your server (SearXNG, DuckDuckGo, multi-slide servers); browsers, scrapers, workarounds and what stopped working; and this article - Russia, security, quality, token consumption and the final cheat sheet "what to choose". All data was verified on September 17, 2026.

First, there are two definitions on which the whole article rests. Claude Code is an Anthropic AI agent for development that works in a terminal: reads code, runs commands and can search for information on the Internet. The MCP server (Model Context Protocol) is a separate program or remote service that adds new tools to the agent, for example, searching through a specific search engine. It is connected by the claude mcp add command and works next to the built-in tools.

Does the Claude Code search from Russia work?

Officially— no: Russia is not included in the list of countries where the services of Anthropic (Anthropic supported countries; Help Center) work. Anthropic does not give an official answer as to whether the built-in WebSearch tool works in an unsupported region.

In practice, Russian users often work through third—party gateways - intermediary APIs that forward requests to the model. WebSearch in Claude Code is executed on the side of the Anthropic servers, and it most likely does not work through such a gateway (for more information about the WebSearch device, see the first article in the series). Therefore, a search MCP server for a Russian user is a necessity, not an option.

The second issue is payment. Whether Brave, Tavily and Exa accept Russian cards, primary sources could not be found. For free tariffs without linking a card (Tavily, Firecrawl and, according to the retelling, Exa), the question of payment is not worth it as long as you meet the limit.

Which search API for an agent can I pay for from Russia?

Of the paid APIs discussed in the series, only the Yandex Search API is paid for via Russian billing — via Yandex Cloud. He has an official MCP server, so connecting to Claude Code does not require a self-written code.

Yandex Search API and official MCP server

The official yandex-search-mcp-server gives the agent two tools: web_search_post returns search results with sources, and ai_search_post returns the response generated by the model. The status is paid, there is no free limit.

There are three ways to connect the server: via a remote SSE endpoint on the Yandex API Gateway (SSE is the protocol by which the server transmits data to the client via HTTP), via Docker, or locally on Python 3.10 and later. For work you need:

  • API key with scope yc.search-api.execute;
  • Yandex Cloud folder ID (folder ID);
  • the search-api.editor role for the service account.

Claude Code is not mentioned in the server README, but the connection via SSE or stdio (running the server as a local process) standard for Claude Code.

How much does the Yandex Search API cost?

A synchronous request costs 488 rubles per 1000 requests during the day and 366 rubles at night (according to Yandex AI Studio tariffs, prices with VAT, verified on 09/17/2026). In the English version of the documentation, the same tariffs are indicated in dollars without VAT. Requests that ended with a server error or authorization are not charged.

Yandex Search API modePrice per 1000 requests, including VATPrice per 1000 requests, USD without VAT
Synchronous, during the day488~$4,00
Synchronous, at night (00:00-07:59 Moscow time)366~$3,00
Postponed, during the day30,50~$0,25
Postponed, at night25,41~$0,21
With a generative response5080~$41,64
Smart Snippets (RU region)1500~$12,30

The Search API doesn't have a separate free limit. You can spend the initial Yandex Cloud grant — it is issued once to an individual or organization (Yandex Cloud documentation). The grant amount "4000 rubles" is known only from third-party sites and has not been confirmed by the original source; whether the grant applies to the Search API is also not confirmed.

Delayed mode is 16 times cheaper than synchronous, but, judging by the name, it is inconvenient for an interactive agent: the answer does not come immediately. This is our conclusion, it has not been verified in the documentation.

Are there unofficial MCP servers for Yandex?

There are, but they also work through the paid Search API. The altrr2/yandex-tools-mcp project (64 stars on GitHub) requires the YANDEX_SEARCH_API_KEY and YANDEX_FOLDER_ID variables. Another option is stufently/yandex-mcp. For work tasks, we would choose the official server: the reasons are in the security section below.

Is it possible to search inRussian from Claude Code for free?

Yes, but only through your own or scraping solutions: there was no popular free Russian search MCP without a key.

Russian-language issuance is provided free of charge by two types of solutions:

  • Your own SearXNG. SearXNG is an open meta search engine: you deploy it on your server in Docker, it polls the search engines itself and gives a summary output. It is connected to the Claude Code by the mcp-searxng server. No keys, no quotas, no third party between you and the search engines. Detailed settings are in the third article of the series.
  • Multi-slide servers without keys. These are MCP servers that themselves access several search engines through scraping — parsing of regular search results pages. lennney/agent-search-mcp explicitly includes Yandex in its eight engines (according to the awesome-mcp-servers catalog).

Sources do not say how stable the Yandex engine works inside SearXNG and how often Google shows captcha to Russian IP addresses. If the server for the agent is located in your office or in the Russian cloud, it is worth checking on your requests before the team starts relying on it. The server for SearXNG does not require powerful hardware, but it needs to be kept and maintained somewhere - this is a common task for your own server or rented virtual machine.

Щит с замком на фоне сетевой схемы — защита ИИ-агента от вредных инструкций
The MCP search server brings someone else's text into the agent context. Anthropic warns about the risk of prompt injection and does not check third-party servers for security.

What is the danger of a search MCP server for an agent?

The main risk is prompt injection: the search brings someone else's text into the agent context, and instructions for the model may be hidden in it. Prompt injection is an attack in which an attacker embeds commands into data (page, snippet, tool description), and the model executes them as user instructions.

Anthropic warns about this directly: "Servers that fetch external content can expose you to prompt injection risk" — servers that load external content put you at risk of prompt injection (Claude Code documentation on MCP). It also says that Anthropic "does not security-audit or manage any MCP server", that is, it does not check the security of third-party servers and does not manage them (Security section).

How does the search MCP differ from the built-in WebFetch?

The built-in tool is better isolated. WebFetch processes the page in a separate context window, and the raw results of the search MCP fall directly into the main context of the agent — especially when the server retrieves the full text of the pages. The context is all that the model "sees" in the current session: your instructions, code, tool results.

Anthropic recommends:

  • check commands before approval;
  • start working with external web services in a VM or dev container;
  • do not automatically approve curl and wget;
  • periodically review the permissions granted by the /permissions command.

What kind of attacks are aimed at the MCP servers themselves?

In addition to the harmful text in the output, the server itself is dangerous. Invariant Labs described three types of attacks (Invariant Labs):

  • Tool poisoning — instructions are hidden in the description of the tool: the model sees them, the user does not.
  • Shadowing — a malicious server overrides the behavior of another, trusted server.
  • Rug pull ("pulled carpet") — the description of the tool changes after you have approved it.

The first public PoC (proof of concept, demonstration of the attack) in April 2025 pumped out the contents of a private repository without user participation (Cloud Security Alliance). OWASP maintains the MCP Top 10 risk catalog, as of September 2026 it is in beta status (OWASP).

Reviews often cite the figures "30+ CVE for January–February 2026" and "78.3% of successful attacks with five connected servers." They are found only in secondary retellings (Practical DevSecOps) and are not confirmed by the original source — we do not recommend relying on them.

A separate security audit of specific search MCP servers (Brave, Tavily, Exa, SearXNG, Yandex) could not be found.

How to protect an agent: practical rules

  1. Take the official vendor servers or the code that you have read.
  2. Instead of npx -y ...@latest, fix the version of the package — this is protection from rug pull: the update will not arrive without your decision.
  3. Keep the keys in the environment variables and in the configuration with the scope user (user's personal settings), and not in the .mcp.json file of the repository, which is visible to all project participants.
  4. Do not combine the search MCP with wide automatic permissions for Bash and file writing: it is this pair that turns a harmful instruction from the page into a executed command.
  5. Do not give fetch servers access to the internal network. The README of the fetch reference server itself warns about calls to local IP addresses.
  6. Be especially careful with anonymous proxies (ContextX), services that register a user on behalf of an agent (anysearch), and projects without a license.

For the company, these rules are part of the general threat model: an agent with access to the code, secrets and internal network must undergo the same risk assessment as any other system. This is done by the information security department: we analyze what data is available to the agent, and restrict the rights to the necessary ones.

Which search API for agents is better in terms of quality?

There is no clear winner: in the only independent benchmark, the first four APIs are statistically indistinguishable. This is a comparison of the AIMultiple "Agentic Search: Benchmark 8 Search APIs for Agents" (published 05/25/2026, updated 09/16/2026).

Methodology: 100 real queries, 5 results for each, the GPT-5 model puts an estimate.2 at temperature 0 (without randomness in the answers), about 10% of the ratings are double-checked by people (AIMultiple). Agent Score is a consolidated benchmark score that takes into account the relevance and quality of the results.

PlaceAPIAgent ScoreRelevant out of 5Quality out of 5Delay
1Brave Search14,894,283,48669 ms
2Firecrawl14,584,303,391335 ms
3Exa14,394,323,33~1.2 s
4Parallel Search Pro14,214,323,2913.6 s
5Tavily13,674,183,27998 ms
6Parallel Base13,504,183,23~2.9 s
7Perplexity12,964,003,2411+ s
8SerpAPI12,283,583,432.4 s

The first four participants are statistically indistinguishable: their confidence intervals overlap. But the delay varies twenty times — from 669 ms for Brave to 13.6 s for Parallel Search Pro, and for interactive work this is more noticeable than the difference in points.

What are the limitations of this benchmark?

  • Requests are taken from the traffic of AIMultiple itself, so they are shifted to the topic of AI and LLM.
  • All requests are in English.
  • AIMultiple has a commercial line of paid benchmarks.
  • SearXNG, DuckDuckGo scrapers and Yandex were not tested in it.

There were no benchmarks in Russian at all.

Comparisons from Exa ("27% faster Tavily on p90", that is, in response time for 90% of requests), Parallel, Firecrawl and fastCRW are data from vendors themselves (Exa; Parallel; fastCRW). Website openbenchmarks.com He calls himself independent, but his methodology and owners could not be verified, so we do not use his figures.

How many tokens does the search spend in Claude Code?

There are no exact measurements for each MCP search server, but the rule is simple: snippets are cheaper than full pages. A token is a unit of text that the model considers the amount of context and the cost of work.

The guidelines are set by the documentation: the output of the MCP tool is limited to 25,000 tokens, a warning appears after 10,000 (Claude Code documentation for MCP). This means that several "fat" page extracts quickly fill in the context.

  • The built-in WebSearch returns only headers and URLs, and each page read is worth another WebFetch call. True, WebFetch returns a retelling prepared by a small model, and not the entire page (Tools reference).
  • Servers with snippets — short fragments of text next to the link (SearXNG, Brave, Tavily in basic mode) — save moves. It is reasonable to call full-text modes (extract, crawl, "LLM context") only for selected URLs.
  • The most expensive option is browser automation. Microsoft itself calls the Playwright CLI mode more economical than the MCP mode (playwright-mcp), and Anthropic warns that integration with Chrome by default increases context consumption (documentation by Claude in Chrome).
  • If the search tool is disabled (for example, when using a third-party ANTHROPIC_BASE_URL, that is, when working through a gateway), descriptions of all MCP tools are loaded into the context immediately. Tool search is a mechanism that loads tool descriptions only as needed. For servers with dozens of tools, this is noticeable. For Bright Data, the set can be shortened using the GROUPS or TOOLS variables (brightdata-mcp).

How many tools the server adds: Bright Data — about 69, Firecrawl — 25, Jina — about 21. For Russian users who often work through the gateway, the last point is especially important: an extra server eats up the context even before the first request.

Which search to choose for Claude Code: cheat sheet

If you have Docker — your own SearXNG with the mcp-searxng server; if you don't want to install anything — Tavily or Exa via a remote endpoint; from Russia with payment in rubles — Yandex Search API. The remaining cases are in the table. Data as of September 17, 2026.

The situationThe choiceWhy
There is Docker, you need a free search without vendor limitsSearXNG + mcp-searxng (enable json format in the SearXNG settings)Without a key: there are no keys and quotas, requests do not go through a third party, the most active project
Do not install anything, work for free all the timeTavily (1000 credits per month) or Exa ($10 per month) via remote HTTP endpointA free tariff with monthly replenishment, the card is not needed (for Exa — according to the retelling, the vendor clearly does not write this), Exa responds even without a key
Try it right now, without registrationParallel Search MCP, Exa without a key, You.com ?profile=free, Firecrawl without a keyOne command claude mcp add --transport http
You need to extract pages and crawl sitesFirecrawl (1000 credits per month) or Crawl4AI on your serverCrawl4AI is free, but it doesn't search by itself: you need a pair of "search + Crawl4AI"
Without Docker and without accountsduckduckgo-mcp-server[browser], free-search-mcp, agent-search-mcp, wigoloAll this is scraping: captchas and breakdowns are possible
You need to add up some free quotasmcp-omnisearch with Tavily, Exa, Brave keysAggregator: providers without a key are simply skipped
Sites with a username and JS applicationsPlaywright MCP (--extension mode) or Claude in Chrome (paid plan only)A real browser; expensive by tokens
Google search results for freeGemini API with grounding: without payment up to 500 requests per day on Gemini 2.5 Flash and Flash-Lite (remember that at the free level the data is used by Google)Google scrapers are fragile and violate the rules of using the service
User from Russia, need freeYour own SearXNG or agent-search-mcp (there is Yandex)Payment and registration with foreign services are not required
A user from Russia who needs high-quality Russian issuanceYandex Search API + official MCP (488 RUBLES with VAT per 1000 requests per day)For a fee, payment via Yandex Cloud
Work through Amazon Bedrock or a third-party gatewayAny search MCP instead of WebSearch; in "deny" permissions: ["WebSearch"]Server WebSearch is not available there, the ban removes useless attempts to call it
Do not useGemini CLI on a free account, Bing Search API, new Google Custom Search keys, pskov 9/web-search, ContextXClosed, abandoned, or opaque

Why well-known services were included in "do not use": Bing Search API was disabled on 08/11/2025, Google Custom Search is closed to new customers and stops working on 01/01/2027, free Gemini CLI stopped serving requests on 06/18/2026. The full table of closed services with sources is in the previous article of the series.

What is the outcome of the series?

In a year and a half, free web search for agents has shifted from "generous corporations" to "their infrastructure." Free entries that were held on major platforms (Bing API, Google Custom Search, free Brave plan, Gemini CLI, free OAuth in Qwen Code) were closed one by one. Gemini CLI and Qwen — in just two months of 2026: Qwen on April 15, Gemini CLI on June 18.

The surviving free tariffs are startup marketing funnels (Tavily, Exa, Firecrawl, Parallel). They are generous while companies are growing and their terms change without warning. This is what happened to Brave: in February 2026, he removed the free plan and began to demand a card.

A sustainable strategy is built in two layers. The basis is something that depends only on you: your own SearXNG. On top — one or two cloud endpoints with a monthly quota in case the meta search runs into a captcha. Any instruction older than six months should be checked against the list of closed services.

At the same time, the quality almost does not depend on the choice among the leaders: the first four APIs in the only independent benchmark are indistinguishable. The real difference is given by three things that are usually not compared in reviews:

  1. how much text does the server return to the context;
  2. who sees your requests;
  3. how much you trust the server code.

For a Russian—speaking user, the main gap is the complete absence of benchmarks on Russian queries. The most honest way is to check SearXNG, multi-engine servers with Yandex and Yandex Search API on your own typical queries.

If you need to deploy such a search and connect AI agents to the company's infrastructure with reasonable access rights, we will help with the setup.

How we do it

  1. Audit of tasks and restrictions

    We find out what tasks the agents solve, through which provider and gateway the model works, whether there is access to services from Russia and what data the agent should not see or send outside.

    List of search requirements: output language, volume of requests, acceptable external services

  2. Search Selection

    We compare cloud APIs with free quota, Yandex Search API and our own SearXNG. We check candidates for your typical requests, including Russian-speaking ones, and estimate the consumption of tokens.

    The chosen scheme: the basis and backup option with justification

  3. Deployment in your contour

    We raise the SearXNG and MCP servers in Docker on your server or in the Russian cloud, fix the versions of the packages, connect them to Claude Code and other agents with the required scope.

    A working search for team agents without dependence on one vendor

  4. Rights and protection against prompt injection

    We restrict automatic permissions to Bash and write files, close access to the internal network to fetch servers, remove keys from repositories, set up isolation in containers.

    A consistent rights policy for agents and a clear threat model

  5. Support

    We monitor server updates and free pricing terms, update versions after verification, and help developers with search failures and captchas.

    The search continues to work when vendors change the conditions

Discuss the task

Set up a search for AI agents in Russia

Tell us how you connect the model and what data the agent sees. We will offer a search (Yandex Search API or your own SearXNG) and security rules.

What will happen after the application

  1. We will respond within a working day
  2. Let's clarify the task and limitations
  3. We will offer a solution and pilot terms

Is it more convenient in the messenger?

+79262103289Employees respond from 9:00 to 23:00 Moscow time, every day

We will answer where it is more convenient for you

Diagram, photo, or technical specification — up to 10 MB

We use contacts only to respond to a request

Frequent questions

Does the built-in WebSearch work in Claude Code from Russia?

Officially, Russia is not included in the list of countries where Anthropic services work, and there is no official answer about the work of WebSearch in unsupported regions. Server WebSearch is most likely not performed through third-party gateways. Therefore, Russian users should connect a search MCP server, for example, their own SearXNG.

What free search in Russian can be connected to Claude Code?

There is no popular free Russian search MCP server without a key for September 2026. Russian-language issuance is provided free of charge by your SearXNG with the mcp-searxng server and multi-engine servers without keys: lennney/agent-search-mcp includes Yandex in its eight engines. The sources do not report the stability of the Yandex engine and the frequency of captchas for Russian IP.

How much does the Yandex Search API cost for an AI agent?

According to the Yandex AI Studio tariffs, as of September 2026, 1,000 synchronous requests cost 488 rubles during the day and 366 rubles at night, deferred requests cost 30.50 rubles and 25.41 rubles, and requests with a generative response cost 5080 rubles (prices include VAT). There is no separate free limit, but you can use a one-time Yandex Cloud start-up grant. It has not been confirmed whether it applies to the Search API.

What is tool poisoning in MCP?

Tool poisoning is an attack in which harmful instructions are hidden in the description of the MCP server tool: the model sees and executes them, but the user does not. Invariant Labs described it together with shadowing and rug pull attacks. The first public PoC in April 2025 pumped out the contents of a private repository without user participation.

How to protect Claude Code from prompt injection via search?

Use the official vendor servers or the code you have read and fix the package versions instead of @latest. Do not combine the search MCP with wide automatic permissions for Bash and file recording, do not give fetch servers access to the internal network and start working with web services in a container or virtual machine. Periodically check permissions with the /permissions command.

Which search API for AI agents is the best in terms of quality?

In the only independent AIMultiple benchmark (8 APIs, 100 English—language queries, updated 09/16/2026), the first four places — Brave Search, Firecrawl, Exa and Parallel Search Pro - are statistically indistinguishable. They differ more in latency: from 669 ms for Brave to 13.6 s for Parallel Search Pro. There are no benchmarks in Russian.

How many tokens can the response of the search MCP server take?

In Claude Code, the output of the MCP tool is limited to 25,000 tokens, a warning appears after 10,000. Servers with snippets consume significantly less than full-text page extraction or browser automation. When working through a third-party gateway, tool search can be turned off, and descriptions of all tools immediately get into context.

Sources

  1. Anthropic: List of supported countries — anthropic.com , verified on 09/17/2026.
  2. Claude Help Center: where Claude is available — support.claude.com , verified on 09/17/2026.
  3. yandex/yandex-search-mcp-server — github.com , verified on 09/17/2026.
  4. Yandex AI Studio: Search API pricing rules (prices in rubles) — aistudio.yandex.ru , verified on 09/17/2026.
  5. Yandex AI Studio: Search API pricing (prices in dollars) — aistudio.yandex.ru , verified on 09/17/2026.
  6. Yandex Cloud: initial grant — cloud.yandex.ru , verified on 09/17/2026.
  7. altrr2/yandex-tools-mcp, README — raw.githubusercontent.com , verified on 09/17/2026.
  8. punkpeye/awesome-mcp-servers, README — raw.githubusercontent.com , verified on 09/17/2026.
  9. Documentation Claude Code: MCP — code.claude.com , verified on 09/17/2026.
  10. Documentation Claude Code: Security — code.claude.com , verified on 09/17/2026.
  11. Invariant Labs: tool poisoning attacks in MCP — invariantlabs.ai , verified on 09/17/2026.
  12. Cloud Security Alliance: a research note on tool poisoning in MCP — labs.cloudsecurityalliance.org , verified on 09/17/2026.
  13. OWASP MCP Top 10 — owasp.org , verified on 09/17/2026.
  14. OWASP MCP Top 10 (review) — practical-devsecops.com , secondary source, verified 09/17/2026.
  15. Agentic Search: Benchmark 8 Search APIs for Agents — aimultiple.com , published on 05/25/2026, updated on 09/16/2026, verified on 09/17/2026.
  16. Exa: comparison with Tavily — exa.ai , vendor data, verified on 09/17/2026.
  17. Parallel: benchmarks — parallel.ai , vendor data, verified on 09/17/2026.
  18. fastCRW: search APIs for AI agents — fastcrw.com , vendor data, verified on 09/17/2026.
  19. Documentation Claude Code: Tools reference — code.claude.com , verified on 09/17/2026.
  20. microsoft/playwright-mcp — github.com , verified on 09/17/2026.
  21. Claude Code Documentation: Chrome — code.claude.com , verified on 09/17/2026.
  22. brightdata/brightdata-mcp — github.com , verified on 09/17/2026.

Name the code in the first message

This way we will find your question faster and understand where you came from.