Boat House
REMOTE · MCP.BOATHOUSECLOUD.COM · SCANNED SEP 28
Deploy and share small apps with team login, persistent data, versioned updates and domains.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 41 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability81
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 4517 tokens (~110/item across 41 items; 41 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management37
- Stability observed for 11 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "deploy" implies "deploy" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 42 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities40
- Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
How do I install the Boat House MCP server?
Boat House is a hosted endpoint at https://mcp.boathousecloud.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.boathousecloud.com
claude mcp add --transport http com-boathousecloud-boathouse 'https://mcp.boathousecloud.com/mcp'
{
"mcpServers": {
"com-boathousecloud-boathouse": {
"url": "https://mcp.boathousecloud.com/mcp"
}
}
} {
"servers": {
"com-boathousecloud-boathouse": {
"type": "http",
"url": "https://mcp.boathousecloud.com/mcp"
}
}
} [mcp_servers.com-boathousecloud-boathouse] url = "https://mcp.boathousecloud.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-boathousecloud-boathouse": {
"type": "remote",
"url": "https://mcp.boathousecloud.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-boathousecloud-boathouse --url 'https://mcp.boathousecloud.com/mcp' --transport streamable-http
mcp_servers:
com-boathousecloud-boathouse:
url: "https://mcp.boathousecloud.com/mcp" {
"McpServers": {
"com-boathousecloud-boathouse": {
"Transport": "http",
"Url": "https://mcp.boathousecloud.com/mcp"
}
}
} assistant mcp add com-boathousecloud-boathouse -t streamable-http -u 'https://mcp.boathousecloud.com/mcp'
{
"mcpServers": {
"com-boathousecloud-boathouse": {
"type": "http",
"url": "https://mcp.boathousecloud.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.
- 25 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 23 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 0
- Stability: unverified → 0.03 ▲ functional
- 17 Sept 26 64
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 28 Sept 2026 · Probed https://mcp.boathousecloud.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.boathousecloud.com | CN=YE2,O=Let's Encrypt,C=US | 7 Sept 2026 | 6 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 5c060adfc7f583c648e66855d8bd53aed91 |
| SANs: mcp.boathousecloud.com | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.boathousecloud.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| boathousecloud.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000 |
| content-security-policy | frame-ancestors 'none'; base-uri 'self'; object-src 'none' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.boathousecloud.com/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.boathousecloud.com/mcp | HTTPS enforced | 301 | https://mcp.boathousecloud.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
access_requests ~66
Everyone waiting to be let into one of this workspace's tools: request id, email, tier asked for, and their message. Owners and tool admins.
| Name | Type | Req | Description |
|---|---|---|---|
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
allow_request ~81
Let a waiting person in at the tier they asked for. Their tool grant is made and they get an email saying what to do next. Owners and tool admins.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The request id from access_requests. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
billing ~73
The workspace's money: prepaid balance, whether it is paused, how fast running tools burn credit, how many days are left, whether a card is on file, and the last ledger lines.
| Name | Type | Req | Description |
|---|---|---|---|
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
capacity ~168
Quote additional app storage. Show the maximum extra monthly price and get owner approval before confirming. No automatic upgrade. Owners only.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | False or absent returns the quote and does nothing. True actually does it. |
| max_extra_monthly_cents | integer | – | Maximum extra monthly price from the approved quote, in cents. |
| quote_id | string | – | The exact capacity quote the owner approved. |
| storage_gb | integer | – | Requested total storage in whole GB; starts with a price quote. |
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
card_link ~66
A one-time link where a workspace owner types a card into Stripe. This is the only part of Boathouse that needs a browser. Owners only.
| Name | Type | Req | Description |
|---|---|---|---|
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
delete_tool ~142
Delete a tool: its container, its releases and its sharing. By default the tool's database and files are kept. purge true also destroys them forever, and then requires purge_confirm true as well.
| Name | Type | Req | Description |
|---|---|---|---|
| purge | boolean | – | Also destroy the tool's database and uploaded files. Irreversible. |
| purge_confirm | boolean | – | Must be true alongside purge, as a second confirmation. |
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
deploy ~303
Deploy a folder as a tool and make it live at https://<tool>.<workspace domain>. Send the whole folder in `files`, which MUST include a top-level Dockerfile whose process listens on $PORT (8080). Creates the tool on the first deploy; afterwards it replaces the running container. If you got these files from `pull`, pass the release number you pulled as `base` so a deploy someone else made in the meantime is not silently overwritten.
| Name | Type | Req | Description |
|---|---|---|---|
| base | integer | – | The release number these files were pulled from. The deploy is refused with STALE_BASE if a newer release is live. |
| base64 | object | – | Optional binary files: relative path -> base64 of the bytes. |
| files | object | yes | The folder: relative path -> the file's text content, e.g. {"Dockerfile": "FROM python:3.12-slim\n...", "app.py": "..."}. No leading slash and no '..' in paths. |
| name | string | – | Human name for the tool, used when it is created (e.g. 'CRCS Finance'). |
| note | string | – | Why this release exists; shown in the release list. |
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
domain_attach ~119
Bring a domain the workspace already owns elsewhere: Boathouse starts answering on it and returns the DNS records to make at the current DNS host. Optionally point it at one tool at the same time. Owners only.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | A full domain name you control, e.g. 'crcstools.com'. |
| tool | string | – | Optional: the tool the bare domain and www should open. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
domain_buy ~172
Buy a domain through Boathouse's registrar and point it at this box, paid from the workspace's prepaid balance. Without confirm it only returns the quote (cost now, renewal price, your balance) and buys nothing. Owners only.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | False or absent returns the quote and does nothing. True actually does it. |
| domain | string | yes | The domain to buy, e.g. 'crcstools.com'. |
| max_cost_cents | integer | – | Maximum approved total, including Boathouse's margin. Required to confirm. |
| quote_id | string | – | The quote_id from the dry run. Required to confirm; reuse it on retries. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
domain_check ~101
Ask the registrar whether a domain is free and what it costs per year. Buys nothing. total_cents is the price the workspace pays (registrar_cents plus Boathouse's margin_cents); show that one.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | A full domain name, e.g. 'crcstools.com'. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
domain_detach ~69
Stop serving a domain. The registration itself is untouched and domain_attach brings it back. Owners only.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | A domain the workspace answers on. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
domain_dns ~68
The DNS records the registrar currently holds for a domain Boathouse bought or manages. Changes nothing.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | A domain the workspace answers on. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
domain_point ~98
Make a domain (and its www) open one tool instead of the workspace's tool list. An empty tool clears it. Owners only.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | A domain the workspace answers on. |
| tool | string | – | The tool to open, or an empty string to show the tool list again. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
domain_primary ~70
Make one of the workspace's domains the primary one: the address tool URLs and emails use. Owners only.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | A domain the workspace answers on. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
domain_renewal_set ~151
Set automatic renewal and a maximum prepaid renewal charge. Quote the change first, then require explicit approval with confirm true. Turning renewal off lets the domain expire. Owners only.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | False or absent returns the quote and does nothing. True actually does it. |
| domain | string | yes | A domain owned through this organization, including detached domains. |
| enabled | boolean | yes | True renews from prepaid credit; false lets the domain expire. |
| max_cost_cents | integer | – | Approved maximum per renewal including the service fee; required when enabling. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
domain_renewals ~54
Read domain expiry dates, renewal status, spending limits and billing problems. Owners only.
| Name | Type | Req | Description |
|---|---|---|---|
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
domain_repoint ~81
Rewrite a Boathouse-managed domain's DNS records to point at this Boathouse again (after a move, or if someone changed them). Owners only.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | A domain the workspace answers on. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
domains_list ~67
The addresses this workspace answers on: the free <workspace>.boathousecloud.com address, the primary domain, and every custom domain with its DNS state.
| Name | Type | Req | Description |
|---|---|---|---|
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
get_tool ~94
One tool in detail: URL, container state, current release, who it is visible to, and the list of people it has been shared with.
| Name | Type | Req | Description |
|---|---|---|---|
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
list_tools ~78
Every tool in the workspace with its state (running/absent), current release, public URL and who can see it. A 'tool' is one small web app Boathouse runs behind the workspace login.
| Name | Type | Req | Description |
|---|---|---|---|
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
logs ~122
The tool container's recent log lines, newest last. Use this to find out why a tool is failing.
| Name | Type | Req | Description |
|---|---|---|---|
| since | integer | – | Unix seconds: only lines after this moment. |
| tail | integer | – | How many lines from the end (default 200, max 5000). |
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
prices ~64
What Boathouse charges, in plain words: one organization plan for up to five lightweight tools, shared limits, storage, and the domain margin.
| Name | Type | Req | Description |
|---|---|---|---|
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
pull ~123
Fetch the exact source folder a release was built from, so you can edit it and deploy it back. Returns the release number and the files as text (binary files come back base64 encoded). Tool admins only.
| Name | Type | Req | Description |
|---|---|---|---|
| release | integer | – | Which release to fetch. Defaults to the live one. |
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
referral ~68
This person's referral code and link, the deal in words, and what each referred workspace has earned them so far (10% of usage charges, paid monthly in cash).
| Name | Type | Req | Description |
|---|---|---|---|
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
releases ~103
The last 20 releases of a tool: number, status (live/superseded/failed), when, who and the note. A failed release shows the last line of its build log.
| Name | Type | Req | Description |
|---|---|---|---|
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
request_access ~126
Ask to be let into a tool in someone else's workspace, at viewer, editor or admin. Its owners get an email with one Allow button; nobody there runs a command. The person is emailed when it is allowed.
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | – | One line the owners see, e.g. who you are and why. |
| target | string | yes | <workspace>/<tool>, for example chloe/db. |
| tier | string | – | Default viewer. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
restart ~76
Restart the tool's container with its current release and current secrets.
| Name | Type | Req | Description |
|---|---|---|---|
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
rollback ~113
Put an earlier release back in service. With no `to`, goes back to the release before the live one. This rolls back the software, never the database.
| Name | Type | Req | Description |
|---|---|---|---|
| to | integer | – | Release number to restore. Defaults to the previous one. |
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
secrets_delete ~93
Remove one secret from a tool. It disappears on the tool's next restart or deploy.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | The secret's name. |
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
secrets_list ~92
The names of a tool's secrets (API keys and the like), when each was last set and by whom. Values are never returned.
| Name | Type | Req | Description |
|---|---|---|---|
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
secrets_set ~138
Set one secret on a tool. It is injected as an environment variable of that name and the tool is restarted. Names are UPPER_SNAKE_CASE. Never echo the value back to the user.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | UPPER_SNAKE_CASE environment variable name, e.g. STRIPE_KEY. |
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| value | string | yes | The secret value. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
set_access ~165
Set who a tool is open to by default: 'members' means anyone in the workspace (at the given tier), 'listed' means only the people it has been explicitly shared with. Use 'listed' for anything sensitive.
| Name | Type | Req | Description |
|---|---|---|---|
| mode | string | yes | members (anyone in the workspace), listed (only people shared with), or public (anyone on the internet may read; writes still need sign-in). |
| tier | string | – | The tier workspace members get when mode is 'members'. |
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
share ~201
Give one person access to one tool by email, at a tier: viewer (read only; the gateway blocks their writes), editor (may change the data), admin (may change the software, secrets, sharing). If the person is new, Boat House emails a secure invitation when email is configured. Check emailed in the result; if delivery failed, share the invitation page so the person can request their secure email.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | The person's email address. | |
| labels | array | – | Optional app-specific words passed to the tool as headers (e.g. ['consultant']). Labels are not permissions. |
| tier | string | – | viewer, editor or admin. Default viewer. |
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
topup ~162
Open secure Stripe checkout to add prepaid hosting credit; the owner completes payment there. Without confirm it only quotes and returns operation_id. Confirm the same cents and operation_id after user approval; reuse the ID on retries. Between $5.00 (500) and $1,000.00 (100000). Owners only.
| Name | Type | Req | Description |
|---|---|---|---|
| cents | integer | yes | Amount in cents, e.g. 2000 for $20.00. |
| confirm | boolean | – | False or absent returns the quote and does nothing. True actually does it. |
| operation_id | string | – | The payment quote ID, required when confirming or retrying. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
unshare ~90
Take away one person's access to one tool. They keep their workspace account.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | The person's email address. | |
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
usage ~81
Check storage, memory, CPU and the reason an app is paused. Tool admins only.
| Name | Type | Req | Description |
|---|---|---|---|
| tool | string | yes | The tool's short name, for example 'finance', or 'acme/finance' to select its workspace. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
users_add ~123
Add a person to the workspace, or change their role. owner = may spend money, buy domains and manage people, and is admin on every tool; member = may see tools open to members and deploy their own; guest = sees only what is explicitly shared with them. Returns a one-time invite link for someone new. Owners only.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | The person's email address. | |
| role | string | – | Default member. |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
users_invite ~104
Resend an invitation to someone in the workspace. New accounts confirm their mailbox through the emailed link; established accounts receive a normal sign-in URL. Password recovery is self-service on that page, and only the account holder's mailbox receives a reset link. Check emailed before offering a fallback.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | The person's email address. | |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
users_list ~59
Everyone in the workspace: role (owner, member or guest), name, and whether they have set a password yet.
| Name | Type | Req | Description |
|---|---|---|---|
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
users_remove ~70
Remove a person from the workspace. Their sessions, project keys, invites and tool grants stop working immediately. Owners only.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | The person's email address. | |
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
whoami ~75
Who this project key belongs to: the email, the workspace, the domain its tools live on, and the prepaid balance. Call it first if you are not sure which workspace you are acting in.
| Name | Type | Req | Description |
|---|---|---|---|
| workspace | string | – | Workspace slug to act in. Use this when you belong to several workspaces; whoami lists them. |
No output schema declared.
No examples provided.
What is the Boat House MCP server?
Boat House is an MCP server listed in the public MCP registry as com.boathousecloud/boathouse. Deploy and share small apps with team login, persistent data, versioned updates and domains. This page covers its hosted endpoint (https://mcp.boathousecloud.com/mcp).
Is the Boat House MCP server safe to use?
Boat House scores 69 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Boat House MCP server expose?
Boat House exposes 41 tools: whoami, list_tools, get_tool, deploy, pull, and 36 more. Their descriptions and schemas cost roughly 4,369 tokens of context every time the server is loaded.
Does the Boat House MCP server require authentication?
No. We connected to Boat House without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Boat House MCP server still maintained?
Boat House is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.