Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

mcphost

REMOTE · MCPHOST.DEV · SCANNED SEP 29

Host your MCP tool over streamable HTTP in one command.

Available components

+18 this week 88 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security92
Transport & Reachability100
Schema Quality & AI Usability75
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 17958 tokens (~132/item across 136 items; 136 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management77
  • Stability observed for 23 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 97% of tool parameters carry a description.Partial
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 0 of 23 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "host.tool_publish" implies "publish" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
  • An AI judge read all 137 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the mcphost MCP server?

mcphost is a hosted endpoint at https://mcphost.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcphost.dev

# add to Claude Code
claude mcp add --transport http dev-mcphost-mcphost 'https://mcphost.dev/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "dev-mcphost-mcphost": {
      "url": "https://mcphost.dev/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "dev-mcphost-mcphost": {
      "type": "http",
      "url": "https://mcphost.dev/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.dev-mcphost-mcphost]
url = "https://mcphost.dev/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "dev-mcphost-mcphost": {
      "type": "remote",
      "url": "https://mcphost.dev/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add dev-mcphost-mcphost --url 'https://mcphost.dev/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  dev-mcphost-mcphost:
    url: "https://mcphost.dev/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "dev-mcphost-mcphost": {
      "Transport": "http",
      "Url": "https://mcphost.dev/mcp"
    }
  }
}
# add to Vellum
assistant mcp add dev-mcphost-mcphost -t streamable-http -u 'https://mcphost.dev/mcp'
// mcp.json
{
  "mcpServers": {
    "dev-mcphost-mcphost": {
      "type": "http",
      "url": "https://mcphost.dev/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 29 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.

  • 28 Sept 26 +4
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 0
    • Tool “host.docs.status” rewrote its description, which is the text the model reads security
    • Tool “host.runs.list” rewrote its description, which is the text the model reads security
    • Tool “host.runs.wait” rewrote its description, which is the text the model reads security
    • Tool “host.usage” rewrote its description, which is the text the model reads security
    • Schema quality: 12812 → 15524 ▼ functional
    • New tool “host.docs.index_config” functional
    • New tool “host.docs.reindex” functional
    • New tool “host.docs.search” functional
    • New tool “host.enduser.assertion_secret_rotate” functional
    • New tool “host.enduser.audit” functional
    • New tool “host.enduser.export” functional
    • New tool “host.enduser.get” functional
    • New tool “host.enduser.list” functional
    • New tool “host.enduser.purge” functional
    • New tool “host.enduser.revoke” functional
    • New tool “host.enduser.unrevoke” functional
    • New tool “host.enduser.whoami” functional
    • New tool “host.progress” functional
    • New tool “host.runs.part” functional
    • New tool “host.share.caller_limit” functional
    • New tool “host.share.caller_limit_remove” functional
    • “host.runs.list” added an optional parameter “end_user_subject” cosmetic
    • “host.runs.wait” added an optional parameter “until” cosmetic
    • “host.state.delete” added an optional parameter “end_user” cosmetic
    • “host.state.delete_rows” added an optional parameter “end_user” cosmetic
    • “host.state.get” added an optional parameter “end_user” cosmetic
    • “host.state.insert” added an optional parameter “end_user” cosmetic
    • “host.state.list” added an optional parameter “end_user” cosmetic
    • “host.state.query” added an optional parameter “end_user” cosmetic
    • “host.state.set” added an optional parameter “end_user” cosmetic
    • “host.usage” added an optional parameter “by” cosmetic
    • “host.usage” added an optional parameter “cursor” cosmetic
    • “host.usage” added an optional parameter “limit” cosmetic
    • “host.usage” added an optional parameter “tool” cosmetic
    • “host.usage” reworded the description of “window” cosmetic
  • 26 Sept 26 +11
    • Authorization: unverified → fail ▼ security
    • Schema quality: 11217 → 12812 ▼ functional
    • New tool “host.docs.delete” functional
    • New tool “host.docs.get” functional
    • New tool “host.docs.list” functional
    • New tool “host.docs.purge” functional
    • New tool “host.docs.put” functional
    • New tool “host.docs.status” functional
    • New tool “host.oauth.issuer_remove” functional
    • New tool “host.oauth.issuer_set” functional
    • New tool “host.oauth.issuers” functional
    • New tool “host.table.describe” functional
    • New tool “host.table.model_set” functional
    • New tool “host.table.models” functional
  • 25 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 0
    • Tool “host.channel.open” rewrote its description, which is the text the model reads security
    • Tool “host.channel.post” rewrote its description, which is the text the model reads security
    • Tool “host.tool_call” rewrote its description, which is the text the model reads security
    • Tool “host.trigger.list” rewrote its description, which is the text the model reads security
    • Tool “host.trigger.replay” rewrote its description, which is the text the model reads security
    • Tool “host.trigger.set” rewrote its description, which is the text the model reads security
    • Tool “host.trigger.test” rewrote its description, which is the text the model reads security
    • Schema quality: 9975 → 11217 ▼ functional
    • New tool “host.channel.close” functional
    • New tool “host.channel.freeze” functional
    • New tool “host.channel.read” functional
    • New tool “host.channel.unfreeze” functional
    • New tool “host.tool_diff” functional
    • New tool “host.tool_history” functional
    • New tool “host.tool_rollback” functional
    • “host.channel.open” added an optional parameter “group” cosmetic
    • “host.tool_call” added an optional parameter “version” cosmetic
    • “host.trigger.replay” added an optional parameter “id” cosmetic
    • “host.trigger.replay” added an optional parameter “row_id” cosmetic
    • “host.trigger.set” added an optional parameter “channel_id” cosmetic
    • “host.trigger.set” added an optional parameter “name” cosmetic
    • “host.trigger.set” reworded the description of “args” cosmetic
    • “host.trigger.set” reworded the description of “kind” cosmetic
    • “host.trigger.set” reworded the description of “verify” cosmetic
    • “host.trigger.test” reworded the description of “body” cosmetic
    • “host.trigger.test” reworded the description of “id” cosmetic
    • “host.channel.open” made “name” optional cosmetic
    • “host.trigger.replay” made “run_id” optional cosmetic
  • 23 Sept 26 +1
    • Tool “host.tool_publish” rewrote its description, which is the text the model reads security
    • Tool “host.tool_run” rewrote its description, which is the text the model reads security
    • New tool “host.changelog” functional
    • New tool “host.channel.open” functional
    • New tool “host.channel.post” functional
    • New tool “host.export” functional
  • 20 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 29 Sept 2026 · Probed https://mcphost.dev/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=mcphost.dev CN=YE2,O=Let's Encrypt,C=US 6 Sept 2026 5 Dec 2026 ECDSA 256 ECDSA-SHA384 6d90eafb56dfa48bc01e1e08da1962e263e
SANs: mcphost.dev
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcphost.dev. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
dev. present 60074 8 Verified
mcphost.dev. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer resource_metadata="https://mcphost.dev/.well-known/oauth-protected-resource", scope="mcp"

Bearer resource_metadata="https://mcphost.dev/.well-known/oauth-protected-resource", scope="mcp"

Protected resource metadata

Document https://mcphost.dev/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://mcphost.dev
Authorisation server https://mcphost.dev

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcphost.dev/mcp Verified 200
http (plaintext) http://mcphost.dev/mcp HTTPS enforced 308 https://mcphost.dev/mcp
MCP tools · 136 exposed · ~17,493 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
billing.checkout ~109

Create (or reuse an open one for the same plan) a Stripe Checkout URL to upgrade this tenant, defaulting to the pro plan. Returns billing_unavailable if this host has no Stripe key configured -- call billing.plans first to check.

NameTypeReqDescription
planstring–Which plan to check out; default: pro.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

billing.plans ~74

The plan catalog (price and quotas per plan) and whether Stripe billing is configured on this host. Anonymous callers get the same answer as tenants.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

billing.status ~62

This tenant's plan, usage against each quota, and when the daily call quota resets.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.agent.contact_accept ~85

Accept a pending contact request addressed to you: both you and the requester become accepted contacts, visible from either side via host.agent.contacts().

NameTypeReqDescription
request_idstringyesThe request to accept.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.agent.contact_deny ~89

Deny a pending contact request addressed to you. The requester's subsequent sends and requests get contact_pending for 7 days, then may request again.

NameTypeReqDescription
request_idstringyesThe request to deny.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.agent.contact_request ~160

Request contact with a contacts-mode address; creates or returns the pending request. not_needed for an open address or one you already have an accepted contact with; contact_refused for a closed address; contact_pending if a request is already pending or was denied within the last 7 days; agent_not_found (same as a nonexistent address) if that address has blocked you. Quota contact_requests_per_day.

NameTypeReqDescription
addressstringyesAn @handle or a bare namespace (t_...).
notestring–Optional note, up to 512 bytes.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.agent.contacts ~98

List your accepted contacts and every pending/decided contact request in either direction; status optionally narrows incoming/outgoing to one of pending, accepted, denied, expired.

NameTypeReqDescription
statusstring–Filter incoming/outgoing requests to this status; omit for all.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.agent.contacts_import ~136

Request contact with up to 50 addresses at once (e.g. an operator's own fleet of tenants); each is resolved the same way a single host.agent.contact_request would be, but a per-address failure (already connected, already pending, blocked, over quota, ...) is reported in that address's own result entry rather than failing the whole call.

NameTypeReqDescription
addressesarrayyes1 to 50 @handle or t_... addresses.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.agent.lookup ~120

Resolve another agent's namespace or @handle to its public card (address, handle, display_name, description, tags, contact_policy, last_seen, source_class). Unknown, disabled, and deleted addresses all return the identical agent_not_found error.

NameTypeReqDescription
addressstringyesAn @handle (e.g. "@indexer") or a bare namespace (t_...).
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.agent.mute ~114

Mute an address: its future messages are still stored and readable via host.msg.thread, but excluded from host.msg.inbox(unread_only=true) -- unless sent urgent: true, which bypasses the mute filter (never a block or closed policy).

NameTypeReqDescription
addressstringyesThe @handle or t_... namespace to mute.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.agent.profile_set ~245

Claim or update this tenant's agent-directory card: an optional unique @handle (^[a-z][a-z0-9_]{2,31}$, stored lower-case), a description, up to 16 tags, and a contact_policy (open, contacts, or closed). Every argument is optional and, if omitted, leaves that field unchanged; an explicit null clears handle or description. A taken handle fails with handle_taken (names no one); a reserved one fails with handle_reserved.

NameTypeReqDescription
contact_policystring–What contact this tenant accepts; enforced by the inbox PRD.
descriptionstring|null–Short blurb shown to other agents via lookup/search; up to 512 bytes; null clears it.
handlestring|null–Unique handle to claim, e.g. "indexer" (without the @); null clears it.
tagsarray–Up to 16 tags of up to 32 bytes each, for host.agent.search.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.agent.search ~169

Find agents by exact tag or a case-insensitive substring of handle, display name, or description. Disabled tenants are excluded. Ordered by handle (unclaimed last), then namespace; page with cursor from the previous response.

NameTypeReqDescription
cursorstring–Opaque cursor from a previous host.agent.search response's cursor field; omit for the first page.
limitinteger–Max results per page, up to 50; default 50.
querystring–Substring to match; omit for no text filter.
tagstring–Exact tag to match; omit for no tag filter.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.agent.unmute ~68

Remove a mute.

NameTypeReqDescription
addressstringyesThe @handle or t_... namespace to unmute.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.agent.whoami ~83

Return this tenant's own agent-directory address: namespace, handle (if claimed), display name, contact_policy and plan. Never a key hash, billing field, or call log.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.bridge_test ~124

Dry-run an unpublished http spec against its real upstream; for the other cases see host.quickstart.

NameTypeReqDescription
argsobjectyesArguments to render into the spec, same shape as a real call.
specobjectyesAn http-kind spec, not yet published, e.g. {"url": "https://api.example.com/items/{{id}}", "method": "GET"}.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.catalog.get ~84

Return one public tool's descriptor and args_schema by its full name (<namespace>.<name>).

NameTypeReqDescription
full_namestringyesThe tool's full name, <namespace>.<name>.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.catalog.search ~87

Search public tools across every tenant by name/description substring.

NameTypeReqDescription
limitinteger–Max results; default 20.
qstring–Substring to match; omit for every public tool.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.changelog ~107

List what changed in the host.*/billing.* tool surface -- additions, deprecations, and removals -- since an optional version. Read-only.

NameTypeReqDescription
sincestring–Only list changes after this version, e.g. "0.57.0". Omit to list every tracked change.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.channel.close ~81

Owner-only: close a group channel. Further host.channel.post calls get channel_closed; host.channel.read keeps working.

NameTypeReqDescription
channel_idstringyesThe group channel's id.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.channel.freeze ~82

Owner-only: freeze a group channel. Further host.channel.post calls get channel_frozen; host.channel.read keeps working.

NameTypeReqDescription
channel_idstringyesThe group channel's id.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.channel.open ~143

Create a named channel, or return the existing one of that name; or, with group instead of name, open (idempotently) the one channel for a group you own -- every current member can then host.channel.post/read it. Refuses channels_max (quota_exceeded) past the plan's cap.

NameTypeReqDescription
groupstring–A group you own (host.group.create); open its one channel instead.
namestring–Channel name to create or look up.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.channel.post ~130

Post to a channel by name or channel_id; advances your own read cursor to the new post. Against a group channel's id, any current member may post; a non-member gets channel_not_found, byte-identical to an unknown id.

NameTypeReqDescription
bodystringyesPost text; non-empty after trim.
channelstringyesChannel name or channel_id.
dataobject–Optional structured payload.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.channel.read ~172

Read a group channel's posts in seq order since a cursor (default: your own last read position, or 0 for a first read). ack: true stores next_cursor as your new read position. A non-member gets channel_not_found.

NameTypeReqDescription
ackboolean–Store next_cursor as your new read position.
channel_idstringyesThe group channel's id, from host.channel.open(group=...).
cursorinteger–Read posts with seq greater than this; omit to resume from your own stored cursor.
limitinteger–Max posts to return; default 50, max 100.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.channel.unfreeze ~76

Owner-only: undo host.channel.freeze; the next post succeeds with the next seq.

NameTypeReqDescription
channel_idstringyesThe group channel's id.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.docs.delete ~107

Soft-delete a document by id or name; still visible via host.docs.list {since} with deleted: true.

NameTypeReqDescription
idstring–Document id to delete; use name instead if you don't have it.
namestring–Document name to delete; use id instead if you have it.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.docs.get ~151

Read a document by id or name -- version defaults to the current one; text: true also returns the extracted plain text this document's mime produced at put time.

NameTypeReqDescription
idstring–Document id to read; use name instead if you don't have it.
namestring–Document name to read; use id instead if you have it.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
textboolean–Also return the extracted plain text; default false.
versioninteger–Version to read; defaults to the document's current version.

No output schema declared.

No examples provided.

host.docs.index_config ~200

Configure this tenant's search index provider. provider: "none" (lexical only, the default) or "openai-compatible" (endpoint, model, and secret -- a tenant secret name used as the embeddings request's bearer -- all required). Changing config re-indexes every document from scratch in the background.

NameTypeReqDescription
dimsinteger–Expected embedding dimensionality, for documentation purposes.
endpointstring–Embeddings API URL; required for openai-compatible.
modelstring–Embeddings model name; required for openai-compatible.
providerstringyes"none" or "openai-compatible".
secretstring–Name of a tenant secret (host.secret_set) used as the bearer; required for openai-compatible.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.docs.list ~167

List documents in this tenant's document store. Without since, returns the current live snapshot; with since (a watermark from host.docs.status, 0 for everything), returns every document changed since, including deleted ones (deleted: true).

NameTypeReqDescription
cursor––Opaque pagination cursor from a previous list call's next_cursor.
limitinteger–Max documents to return; default 100.
prefixstring–Only list documents whose name starts with this prefix.
sinceinteger–Return documents changed since this watermark (a host.docs.status seq); omit for the current live snapshot only.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.docs.purge ~142

Drop stored versions of a document older than older_than_versions versions back from its current one -- get {version: <a dropped version>} then reads not found.

NameTypeReqDescription
idstring–Document id to purge old versions of; use name instead if you don't have it.
namestring–Document name to purge old versions of; use id instead if you have it.
older_than_versionsintegeryesHow many versions back from the current one to keep.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.docs.put ~254

Write (or, for an already-used name, create a new version of) a document in this tenant's document store. mime is detected from name and content when omitted; allowed mimes are text/plain, text/markdown, application/json, text/csv. content (or content_base64 for arbitrary bytes) must be at most MCPHOST_DOC_MAX_BYTES (default 2 MiB). Identical content to the current version is a no-op that repeats the current version.

NameTypeReqDescription
contentstring–Document content as text; use content_base64 instead for arbitrary bytes.
content_base64string–Document content, base64-encoded; use content instead for plain text.
metadata––Arbitrary caller metadata stored alongside the document; any JSON value.
mimestring–One of text/plain, text/markdown, application/json, text/csv; detected from name/content when omitted.
namestringyesDocument name; same name on a later put creates a new version of the same id.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.docs.reindex ~110

Force this tenant's search index to re-chunk (and re-embed, if a provider is configured) one document (document_id) or, without document_id, every document, on the indexer's next tick.

NameTypeReqDescription
document_idstring–Reindex only this document; omit to reindex every document.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.docs.search ~177

Ranked passage search over this tenant's document store. Lexical (BM25) by default; embeddings mode (set via host.docs.index_config) ranks by cosine and falls back to lexical (index.mode: "lexical-fallback") if the provider call fails. Returns [{document_id, name, version, chunk_no, offset, text, score}] plus an index block naming the mode and how stale the index is.

NameTypeReqDescription
filterobject–Restrict results to documents matching prefix and/or name.
kinteger–Max results to return, 1-20; default 5.
querystringyesSearch query text.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.docs.status ~106

This tenant's document store counters: documents, bytes, text_bytes, the current change watermark, this plan's document/byte quotas, and an index block (mode, indexed_watermark, lag_seconds, pending_documents, chunks, rebuilding, quota_chunks_reached) describing the search index's own freshness.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.enduser.assertion_secret_rotate ~119

Generate and store a new per-tenant secret for signing end_user_assertion (HS256 compact JWS, claims sub/iat/exp with exp <= iat + 3600). Returns the secret once; it is never shown again and never appears in host.secret_list. Assertions signed with any prior secret stop verifying immediately -- no overlap window.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.enduser.audit ~145

One end user's calls (tool, outcome, run_id, impersonated) merged with its revoke/unrevoke/purge control-plane events, newest first, paged by cursor.

NameTypeReqDescription
cursorstring–Opaque; resume after a previous response's cursor.
limitinteger–Max entries per page (default 50, max 1000).
sinceinteger–Only entries at or after this unix timestamp.
subjectstringyesThe end user's subject.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.enduser.export ~93

Export one end user's state rows and call history as a bundle at /exports/<run_id>, the same envelope host.export returns (download_url, size_bytes, expires_unix).

NameTypeReqDescription
subjectstringyesThe end user's subject.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.enduser.get ~102

One end user's roster row (subject, issuer, first_seen, last_seen, calls_total, revoked_at, revoked_by, purged_at) plus its live state_rows, vault_connections, and runs_30d counts.

NameTypeReqDescription
subjectstringyesThe end user's subject.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.enduser.list ~180

List this tenant's end users with last-seen and call counts, newest last-seen first. Optional since (unix seconds, filters last_seen), revoked (bool), limit (default 50, max 1000), and cursor (from a previous page's cursor field).

NameTypeReqDescription
cursorstring–Opaque; resume after a previous response's cursor.
limitinteger–Max rows per page (default 50, max 1000).
revokedboolean–true: only revoked end users; false: only active ones; omit for both.
sinceinteger–Only end users last seen at or after this unix timestamp.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.enduser.purge ~113

Delete a revoked end user's scoped state and vault-token rows, de-identify its calls rows (kept, never deleted), and set purged_at. Requires the end user to be revoked first (revoke_required otherwise). Returns {state_rows, vault_tokens} counts.

NameTypeReqDescription
subjectstringyesThe end user's subject.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.enduser.revoke ~95

Revoke an end user: its next identified call is refused with end_user_revoked, no tool runs, and its vault-token connections are disconnected.

NameTypeReqDescription
reasonstring––
subjectstringyesThe end user's subject.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.enduser.unrevoke ~75

Reverse a prior host.enduser.revoke; the end user's calls succeed again.

NameTypeReqDescription
subjectstringyesThe end user's subject.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.enduser.whoami ~97

The end user (if any) this call itself carries: {subject, issuer, method, verified_at} from the OAuth bearer's sub/iss or a verified end_user_assertion; null when the call carries no verified end-user identity.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.export ~158

Build a downloadable .tar.gz of everything this tenant owns: tool sources, state, secret NAMES (never values), run/thread history and usage, plus a manifest.json re-publishable via host.tool_publish. Runs as a background job (poll host.runs.get with the returned run_id) -- calling this again while one is already running returns that same run_id rather than starting a second one. The finished run's result carries a download_url valid 24 hours.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
toolsarray–Local names of the tools to include; every tool when omitted.

No output schema declared.

No examples provided.

host.group.add ~79

Add a tenant (by namespace) to a group this tenant owns.

NameTypeReqDescription
namestringyesGroup name.
namespacestringyesMember tenant's namespace.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.group.create ~72

Create a named group this tenant owns, for host.tool_share(visibility: "group").

NameTypeReqDescription
namestringyesGroup name.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.group.list ~55

List the groups this tenant owns and their members.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.group.remove ~79

Remove a tenant (by namespace) from a group this tenant owns.

NameTypeReqDescription
namestringyesGroup name.
namespacestringyesMember tenant's namespace.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.key_rotate ~97

Issue a new tenant key and invalidate the current one immediately: every other call using the old key fails as unauthenticated from this point on. Returns the new key exactly once -- use it (as tenant_key or Authorization) for every call after this one.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.msg.ack ~88

Mark messages as read for you; unread_only inbox reads stop returning them. Per-recipient -- a sender never sees others' receipts.

NameTypeReqDescription
message_idsarrayyesmessage_ids to mark read for you.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.msg.block ~104

Block an address: its future sends to you are refused agent_not_found, byte-identical to sending to a nonexistent address. You can still send to it. Block lists are never exposed to the blocked party.

NameTypeReqDescription
addressstringyesThe @handle or t_... namespace to block.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

Common questions

What is the mcphost MCP server?

mcphost is an MCP server listed in the public MCP registry as dev.mcphost/mcphost. Host your MCP tool over streamable HTTP in one command. This page covers its hosted endpoint (https://mcphost.dev/mcp).

Is the mcphost MCP server safe to use?

mcphost scores 88 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the mcphost MCP server expose?

mcphost exposes 136 tools: signup, host.whoami, host.redeem, host.key_rotate, host.self_offboard, and 131 more. Their descriptions and schemas cost roughly 17,493 tokens of context every time the server is loaded.

Does the mcphost MCP server require authentication?

Yes. mcphost asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the mcphost MCP server still maintained?

mcphost is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.