mcphost
REMOTE · MCPHOST.DEV · SCANNED SEP 29
Host your MCP tool over streamable HTTP in one command.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security92
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability75
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 17958 tokens (~132/item across 136 items; 136 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management77
- Stability observed for 23 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 97% of tool parameters carry a description.Partial
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 23 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "host.tool_publish" implies "publish" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 137 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the mcphost MCP server?
mcphost is a hosted endpoint at https://mcphost.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcphost.dev
claude mcp add --transport http dev-mcphost-mcphost 'https://mcphost.dev/mcp'
{
"mcpServers": {
"dev-mcphost-mcphost": {
"url": "https://mcphost.dev/mcp"
}
}
} {
"servers": {
"dev-mcphost-mcphost": {
"type": "http",
"url": "https://mcphost.dev/mcp"
}
}
} [mcp_servers.dev-mcphost-mcphost] url = "https://mcphost.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"dev-mcphost-mcphost": {
"type": "remote",
"url": "https://mcphost.dev/mcp",
"enabled": true
}
}
} openclaw mcp add dev-mcphost-mcphost --url 'https://mcphost.dev/mcp' --transport streamable-http
mcp_servers:
dev-mcphost-mcphost:
url: "https://mcphost.dev/mcp" {
"McpServers": {
"dev-mcphost-mcphost": {
"Transport": "http",
"Url": "https://mcphost.dev/mcp"
}
}
} assistant mcp add dev-mcphost-mcphost -t streamable-http -u 'https://mcphost.dev/mcp'
{
"mcpServers": {
"dev-mcphost-mcphost": {
"type": "http",
"url": "https://mcphost.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Sept 26 +4
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 0
- Tool “host.docs.status” rewrote its description, which is the text the model reads security
- Tool “host.runs.list” rewrote its description, which is the text the model reads security
- Tool “host.runs.wait” rewrote its description, which is the text the model reads security
- Tool “host.usage” rewrote its description, which is the text the model reads security
- Schema quality: 12812 → 15524 ▼ functional
- New tool “host.docs.index_config” functional
- New tool “host.docs.reindex” functional
- New tool “host.docs.search” functional
- New tool “host.enduser.assertion_secret_rotate” functional
- New tool “host.enduser.audit” functional
- New tool “host.enduser.export” functional
- New tool “host.enduser.get” functional
- New tool “host.enduser.list” functional
- New tool “host.enduser.purge” functional
- New tool “host.enduser.revoke” functional
- New tool “host.enduser.unrevoke” functional
- New tool “host.enduser.whoami” functional
- New tool “host.progress” functional
- New tool “host.runs.part” functional
- New tool “host.share.caller_limit” functional
- New tool “host.share.caller_limit_remove” functional
- “host.runs.list” added an optional parameter “end_user_subject” cosmetic
- “host.runs.wait” added an optional parameter “until” cosmetic
- “host.state.delete” added an optional parameter “end_user” cosmetic
- “host.state.delete_rows” added an optional parameter “end_user” cosmetic
- “host.state.get” added an optional parameter “end_user” cosmetic
- “host.state.insert” added an optional parameter “end_user” cosmetic
- “host.state.list” added an optional parameter “end_user” cosmetic
- “host.state.query” added an optional parameter “end_user” cosmetic
- “host.state.set” added an optional parameter “end_user” cosmetic
- “host.usage” added an optional parameter “by” cosmetic
- “host.usage” added an optional parameter “cursor” cosmetic
- “host.usage” added an optional parameter “limit” cosmetic
- “host.usage” added an optional parameter “tool” cosmetic
- “host.usage” reworded the description of “window” cosmetic
- 26 Sept 26 +11
- Authorization: unverified → fail ▼ security
- Schema quality: 11217 → 12812 ▼ functional
- New tool “host.docs.delete” functional
- New tool “host.docs.get” functional
- New tool “host.docs.list” functional
- New tool “host.docs.purge” functional
- New tool “host.docs.put” functional
- New tool “host.docs.status” functional
- New tool “host.oauth.issuer_remove” functional
- New tool “host.oauth.issuer_set” functional
- New tool “host.oauth.issuers” functional
- New tool “host.table.describe” functional
- New tool “host.table.model_set” functional
- New tool “host.table.models” functional
- 25 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 0
- Tool “host.channel.open” rewrote its description, which is the text the model reads security
- Tool “host.channel.post” rewrote its description, which is the text the model reads security
- Tool “host.tool_call” rewrote its description, which is the text the model reads security
- Tool “host.trigger.list” rewrote its description, which is the text the model reads security
- Tool “host.trigger.replay” rewrote its description, which is the text the model reads security
- Tool “host.trigger.set” rewrote its description, which is the text the model reads security
- Tool “host.trigger.test” rewrote its description, which is the text the model reads security
- Schema quality: 9975 → 11217 ▼ functional
- New tool “host.channel.close” functional
- New tool “host.channel.freeze” functional
- New tool “host.channel.read” functional
- New tool “host.channel.unfreeze” functional
- New tool “host.tool_diff” functional
- New tool “host.tool_history” functional
- New tool “host.tool_rollback” functional
- “host.channel.open” added an optional parameter “group” cosmetic
- “host.tool_call” added an optional parameter “version” cosmetic
- “host.trigger.replay” added an optional parameter “id” cosmetic
- “host.trigger.replay” added an optional parameter “row_id” cosmetic
- “host.trigger.set” added an optional parameter “channel_id” cosmetic
- “host.trigger.set” added an optional parameter “name” cosmetic
- “host.trigger.set” reworded the description of “args” cosmetic
- “host.trigger.set” reworded the description of “kind” cosmetic
- “host.trigger.set” reworded the description of “verify” cosmetic
- “host.trigger.test” reworded the description of “body” cosmetic
- “host.trigger.test” reworded the description of “id” cosmetic
- “host.channel.open” made “name” optional cosmetic
- “host.trigger.replay” made “run_id” optional cosmetic
- 23 Sept 26 +1
- Tool “host.tool_publish” rewrote its description, which is the text the model reads security
- Tool “host.tool_run” rewrote its description, which is the text the model reads security
- New tool “host.changelog” functional
- New tool “host.channel.open” functional
- New tool “host.channel.post” functional
- New tool “host.export” functional
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 29 Sept 2026 · Probed https://mcphost.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcphost.dev | CN=YE2,O=Let's Encrypt,C=US | 6 Sept 2026 | 5 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 6d90eafb56dfa48bc01e1e08da1962e263e |
| SANs: mcphost.dev | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcphost.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| mcphost.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://mcphost.dev/.well-known/oauth-protected-resource", scope="mcp"
Bearer resource_metadata="https://mcphost.dev/.well-known/oauth-protected-resource", scope="mcp" Protected resource metadata
| Document | https://mcphost.dev/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://mcphost.dev |
| Authorisation server | https://mcphost.dev |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcphost.dev/mcp | Verified | 200 | |
| http (plaintext) | http://mcphost.dev/mcp | HTTPS enforced | 308 | https://mcphost.dev/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
billing.checkout ~109
Create (or reuse an open one for the same plan) a Stripe Checkout URL to upgrade this tenant, defaulting to the pro plan. Returns billing_unavailable if this host has no Stripe key configured -- call billing.plans first to check.
| Name | Type | Req | Description |
|---|---|---|---|
| plan | string | – | Which plan to check out; default: pro. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
billing.plans ~74
The plan catalog (price and quotas per plan) and whether Stripe billing is configured on this host. Anonymous callers get the same answer as tenants.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
billing.status ~62
This tenant's plan, usage against each quota, and when the daily call quota resets.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.agent.contact_accept ~85
Accept a pending contact request addressed to you: both you and the requester become accepted contacts, visible from either side via host.agent.contacts().
| Name | Type | Req | Description |
|---|---|---|---|
| request_id | string | yes | The request to accept. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.agent.contact_deny ~89
Deny a pending contact request addressed to you. The requester's subsequent sends and requests get contact_pending for 7 days, then may request again.
| Name | Type | Req | Description |
|---|---|---|---|
| request_id | string | yes | The request to deny. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.agent.contact_request ~160
Request contact with a contacts-mode address; creates or returns the pending request. not_needed for an open address or one you already have an accepted contact with; contact_refused for a closed address; contact_pending if a request is already pending or was denied within the last 7 days; agent_not_found (same as a nonexistent address) if that address has blocked you. Quota contact_requests_per_day.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | An @handle or a bare namespace (t_...). |
| note | string | – | Optional note, up to 512 bytes. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.agent.contacts ~98
List your accepted contacts and every pending/decided contact request in either direction; status optionally narrows incoming/outgoing to one of pending, accepted, denied, expired.
| Name | Type | Req | Description |
|---|---|---|---|
| status | string | – | Filter incoming/outgoing requests to this status; omit for all. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.agent.contacts_import ~136
Request contact with up to 50 addresses at once (e.g. an operator's own fleet of tenants); each is resolved the same way a single host.agent.contact_request would be, but a per-address failure (already connected, already pending, blocked, over quota, ...) is reported in that address's own result entry rather than failing the whole call.
| Name | Type | Req | Description |
|---|---|---|---|
| addresses | array | yes | 1 to 50 @handle or t_... addresses. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.agent.lookup ~120
Resolve another agent's namespace or @handle to its public card (address, handle, display_name, description, tags, contact_policy, last_seen, source_class). Unknown, disabled, and deleted addresses all return the identical agent_not_found error.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | An @handle (e.g. "@indexer") or a bare namespace (t_...). |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.agent.mute ~114
Mute an address: its future messages are still stored and readable via host.msg.thread, but excluded from host.msg.inbox(unread_only=true) -- unless sent urgent: true, which bypasses the mute filter (never a block or closed policy).
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | The @handle or t_... namespace to mute. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.agent.profile_set ~245
Claim or update this tenant's agent-directory card: an optional unique @handle (^[a-z][a-z0-9_]{2,31}$, stored lower-case), a description, up to 16 tags, and a contact_policy (open, contacts, or closed). Every argument is optional and, if omitted, leaves that field unchanged; an explicit null clears handle or description. A taken handle fails with handle_taken (names no one); a reserved one fails with handle_reserved.
| Name | Type | Req | Description |
|---|---|---|---|
| contact_policy | string | – | What contact this tenant accepts; enforced by the inbox PRD. |
| description | string|null | – | Short blurb shown to other agents via lookup/search; up to 512 bytes; null clears it. |
| handle | string|null | – | Unique handle to claim, e.g. "indexer" (without the @); null clears it. |
| tags | array | – | Up to 16 tags of up to 32 bytes each, for host.agent.search. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.agent.search ~169
Find agents by exact tag or a case-insensitive substring of handle, display name, or description. Disabled tenants are excluded. Ordered by handle (unclaimed last), then namespace; page with cursor from the previous response.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque cursor from a previous host.agent.search response's cursor field; omit for the first page. |
| limit | integer | – | Max results per page, up to 50; default 50. |
| query | string | – | Substring to match; omit for no text filter. |
| tag | string | – | Exact tag to match; omit for no tag filter. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.agent.unmute ~68
Remove a mute.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | The @handle or t_... namespace to unmute. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.agent.whoami ~83
Return this tenant's own agent-directory address: namespace, handle (if claimed), display name, contact_policy and plan. Never a key hash, billing field, or call log.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.bridge_test ~124
Dry-run an unpublished http spec against its real upstream; for the other cases see host.quickstart.
| Name | Type | Req | Description |
|---|---|---|---|
| args | object | yes | Arguments to render into the spec, same shape as a real call. |
| spec | object | yes | An http-kind spec, not yet published, e.g. {"url": "https://api.example.com/items/{{id}}", "method": "GET"}. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.catalog.get ~84
Return one public tool's descriptor and args_schema by its full name (<namespace>.<name>).
| Name | Type | Req | Description |
|---|---|---|---|
| full_name | string | yes | The tool's full name, <namespace>.<name>. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.catalog.search ~87
Search public tools across every tenant by name/description substring.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max results; default 20. |
| q | string | – | Substring to match; omit for every public tool. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.changelog ~107
List what changed in the host.*/billing.* tool surface -- additions, deprecations, and removals -- since an optional version. Read-only.
| Name | Type | Req | Description |
|---|---|---|---|
| since | string | – | Only list changes after this version, e.g. "0.57.0". Omit to list every tracked change. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.channel.close ~81
Owner-only: close a group channel. Further host.channel.post calls get channel_closed; host.channel.read keeps working.
| Name | Type | Req | Description |
|---|---|---|---|
| channel_id | string | yes | The group channel's id. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.channel.freeze ~82
Owner-only: freeze a group channel. Further host.channel.post calls get channel_frozen; host.channel.read keeps working.
| Name | Type | Req | Description |
|---|---|---|---|
| channel_id | string | yes | The group channel's id. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.channel.open ~143
Create a named channel, or return the existing one of that name; or, with group instead of name, open (idempotently) the one channel for a group you own -- every current member can then host.channel.post/read it. Refuses channels_max (quota_exceeded) past the plan's cap.
| Name | Type | Req | Description |
|---|---|---|---|
| group | string | – | A group you own (host.group.create); open its one channel instead. |
| name | string | – | Channel name to create or look up. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.channel.post ~130
Post to a channel by name or channel_id; advances your own read cursor to the new post. Against a group channel's id, any current member may post; a non-member gets channel_not_found, byte-identical to an unknown id.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | Post text; non-empty after trim. |
| channel | string | yes | Channel name or channel_id. |
| data | object | – | Optional structured payload. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.channel.read ~172
Read a group channel's posts in seq order since a cursor (default: your own last read position, or 0 for a first read). ack: true stores next_cursor as your new read position. A non-member gets channel_not_found.
| Name | Type | Req | Description |
|---|---|---|---|
| ack | boolean | – | Store next_cursor as your new read position. |
| channel_id | string | yes | The group channel's id, from host.channel.open(group=...). |
| cursor | integer | – | Read posts with seq greater than this; omit to resume from your own stored cursor. |
| limit | integer | – | Max posts to return; default 50, max 100. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.channel.unfreeze ~76
Owner-only: undo host.channel.freeze; the next post succeeds with the next seq.
| Name | Type | Req | Description |
|---|---|---|---|
| channel_id | string | yes | The group channel's id. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.docs.delete ~107
Soft-delete a document by id or name; still visible via host.docs.list {since} with deleted: true.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | – | Document id to delete; use name instead if you don't have it. |
| name | string | – | Document name to delete; use id instead if you have it. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.docs.get ~151
Read a document by id or name -- version defaults to the current one; text: true also returns the extracted plain text this document's mime produced at put time.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | – | Document id to read; use name instead if you don't have it. |
| name | string | – | Document name to read; use id instead if you have it. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| text | boolean | – | Also return the extracted plain text; default false. |
| version | integer | – | Version to read; defaults to the document's current version. |
No output schema declared.
No examples provided.
host.docs.index_config ~200
Configure this tenant's search index provider. provider: "none" (lexical only, the default) or "openai-compatible" (endpoint, model, and secret -- a tenant secret name used as the embeddings request's bearer -- all required). Changing config re-indexes every document from scratch in the background.
| Name | Type | Req | Description |
|---|---|---|---|
| dims | integer | – | Expected embedding dimensionality, for documentation purposes. |
| endpoint | string | – | Embeddings API URL; required for openai-compatible. |
| model | string | – | Embeddings model name; required for openai-compatible. |
| provider | string | yes | "none" or "openai-compatible". |
| secret | string | – | Name of a tenant secret (host.secret_set) used as the bearer; required for openai-compatible. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.docs.list ~167
List documents in this tenant's document store. Without since, returns the current live snapshot; with since (a watermark from host.docs.status, 0 for everything), returns every document changed since, including deleted ones (deleted: true).
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | – | – | Opaque pagination cursor from a previous list call's next_cursor. |
| limit | integer | – | Max documents to return; default 100. |
| prefix | string | – | Only list documents whose name starts with this prefix. |
| since | integer | – | Return documents changed since this watermark (a host.docs.status seq); omit for the current live snapshot only. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.docs.purge ~142
Drop stored versions of a document older than older_than_versions versions back from its current one -- get {version: <a dropped version>} then reads not found.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | – | Document id to purge old versions of; use name instead if you don't have it. |
| name | string | – | Document name to purge old versions of; use id instead if you have it. |
| older_than_versions | integer | yes | How many versions back from the current one to keep. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.docs.put ~254
Write (or, for an already-used name, create a new version of) a document in this tenant's document store. mime is detected from name and content when omitted; allowed mimes are text/plain, text/markdown, application/json, text/csv. content (or content_base64 for arbitrary bytes) must be at most MCPHOST_DOC_MAX_BYTES (default 2 MiB). Identical content to the current version is a no-op that repeats the current version.
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | – | Document content as text; use content_base64 instead for arbitrary bytes. |
| content_base64 | string | – | Document content, base64-encoded; use content instead for plain text. |
| metadata | – | – | Arbitrary caller metadata stored alongside the document; any JSON value. |
| mime | string | – | One of text/plain, text/markdown, application/json, text/csv; detected from name/content when omitted. |
| name | string | yes | Document name; same name on a later put creates a new version of the same id. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.docs.reindex ~110
Force this tenant's search index to re-chunk (and re-embed, if a provider is configured) one document (document_id) or, without document_id, every document, on the indexer's next tick.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | – | Reindex only this document; omit to reindex every document. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.docs.search ~177
Ranked passage search over this tenant's document store. Lexical (BM25) by default; embeddings mode (set via host.docs.index_config) ranks by cosine and falls back to lexical (index.mode: "lexical-fallback") if the provider call fails. Returns [{document_id, name, version, chunk_no, offset, text, score}] plus an index block naming the mode and how stale the index is.
| Name | Type | Req | Description |
|---|---|---|---|
| filter | object | – | Restrict results to documents matching prefix and/or name. |
| k | integer | – | Max results to return, 1-20; default 5. |
| query | string | yes | Search query text. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.docs.status ~106
This tenant's document store counters: documents, bytes, text_bytes, the current change watermark, this plan's document/byte quotas, and an index block (mode, indexed_watermark, lag_seconds, pending_documents, chunks, rebuilding, quota_chunks_reached) describing the search index's own freshness.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.enduser.assertion_secret_rotate ~119
Generate and store a new per-tenant secret for signing end_user_assertion (HS256 compact JWS, claims sub/iat/exp with exp <= iat + 3600). Returns the secret once; it is never shown again and never appears in host.secret_list. Assertions signed with any prior secret stop verifying immediately -- no overlap window.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.enduser.audit ~145
One end user's calls (tool, outcome, run_id, impersonated) merged with its revoke/unrevoke/purge control-plane events, newest first, paged by cursor.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque; resume after a previous response's cursor. |
| limit | integer | – | Max entries per page (default 50, max 1000). |
| since | integer | – | Only entries at or after this unix timestamp. |
| subject | string | yes | The end user's subject. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.enduser.export ~93
Export one end user's state rows and call history as a bundle at /exports/<run_id>, the same envelope host.export returns (download_url, size_bytes, expires_unix).
| Name | Type | Req | Description |
|---|---|---|---|
| subject | string | yes | The end user's subject. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.enduser.get ~102
One end user's roster row (subject, issuer, first_seen, last_seen, calls_total, revoked_at, revoked_by, purged_at) plus its live state_rows, vault_connections, and runs_30d counts.
| Name | Type | Req | Description |
|---|---|---|---|
| subject | string | yes | The end user's subject. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.enduser.list ~180
List this tenant's end users with last-seen and call counts, newest last-seen first. Optional since (unix seconds, filters last_seen), revoked (bool), limit (default 50, max 1000), and cursor (from a previous page's cursor field).
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque; resume after a previous response's cursor. |
| limit | integer | – | Max rows per page (default 50, max 1000). |
| revoked | boolean | – | true: only revoked end users; false: only active ones; omit for both. |
| since | integer | – | Only end users last seen at or after this unix timestamp. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.enduser.purge ~113
Delete a revoked end user's scoped state and vault-token rows, de-identify its calls rows (kept, never deleted), and set purged_at. Requires the end user to be revoked first (revoke_required otherwise). Returns {state_rows, vault_tokens} counts.
| Name | Type | Req | Description |
|---|---|---|---|
| subject | string | yes | The end user's subject. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.enduser.revoke ~95
Revoke an end user: its next identified call is refused with end_user_revoked, no tool runs, and its vault-token connections are disconnected.
| Name | Type | Req | Description |
|---|---|---|---|
| reason | string | – | – |
| subject | string | yes | The end user's subject. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.enduser.unrevoke ~75
Reverse a prior host.enduser.revoke; the end user's calls succeed again.
| Name | Type | Req | Description |
|---|---|---|---|
| subject | string | yes | The end user's subject. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.enduser.whoami ~97
The end user (if any) this call itself carries: {subject, issuer, method, verified_at} from the OAuth bearer's sub/iss or a verified end_user_assertion; null when the call carries no verified end-user identity.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.export ~158
Build a downloadable .tar.gz of everything this tenant owns: tool sources, state, secret NAMES (never values), run/thread history and usage, plus a manifest.json re-publishable via host.tool_publish. Runs as a background job (poll host.runs.get with the returned run_id) -- calling this again while one is already running returns that same run_id rather than starting a second one. The finished run's result carries a download_url valid 24 hours.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| tools | array | – | Local names of the tools to include; every tool when omitted. |
No output schema declared.
No examples provided.
host.group.add ~79
Add a tenant (by namespace) to a group this tenant owns.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Group name. |
| namespace | string | yes | Member tenant's namespace. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.group.create ~72
Create a named group this tenant owns, for host.tool_share(visibility: "group").
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Group name. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.group.list ~55
List the groups this tenant owns and their members.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.group.remove ~79
Remove a tenant (by namespace) from a group this tenant owns.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Group name. |
| namespace | string | yes | Member tenant's namespace. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.key_rotate ~97
Issue a new tenant key and invalidate the current one immediately: every other call using the old key fails as unauthenticated from this point on. Returns the new key exactly once -- use it (as tenant_key or Authorization) for every call after this one.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.msg.ack ~88
Mark messages as read for you; unread_only inbox reads stop returning them. Per-recipient -- a sender never sees others' receipts.
| Name | Type | Req | Description |
|---|---|---|---|
| message_ids | array | yes | message_ids to mark read for you. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.msg.block ~104
Block an address: its future sends to you are refused agent_not_found, byte-identical to sending to a nonexistent address. You can still send to it. Block lists are never exposed to the blocked party.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | The @handle or t_... namespace to block. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
What is the mcphost MCP server?
mcphost is an MCP server listed in the public MCP registry as dev.mcphost/mcphost. Host your MCP tool over streamable HTTP in one command. This page covers its hosted endpoint (https://mcphost.dev/mcp).
Is the mcphost MCP server safe to use?
mcphost scores 88 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the mcphost MCP server expose?
mcphost exposes 136 tools: signup, host.whoami, host.redeem, host.key_rotate, host.self_offboard, and 131 more. Their descriptions and schemas cost roughly 17,493 tokens of context every time the server is loaded.
Does the mcphost MCP server require authentication?
Yes. mcphost asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the mcphost MCP server still maintained?
mcphost is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.