mcphost
REMOTE · MCPHOST.DEV · SCANNED SEP 29
Host your MCP tool over streamable HTTP in one command.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security92
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability75
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 17958 tokens (~132/item across 136 items; 136 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management77
- Stability observed for 23 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 97% of tool parameters carry a description.Partial
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 23 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "host.tool_publish" implies "publish" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 137 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the mcphost MCP server?
mcphost is a hosted endpoint at https://mcphost.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcphost.dev
claude mcp add --transport http dev-mcphost-mcphost 'https://mcphost.dev/mcp'
{
"mcpServers": {
"dev-mcphost-mcphost": {
"url": "https://mcphost.dev/mcp"
}
}
} {
"servers": {
"dev-mcphost-mcphost": {
"type": "http",
"url": "https://mcphost.dev/mcp"
}
}
} [mcp_servers.dev-mcphost-mcphost] url = "https://mcphost.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"dev-mcphost-mcphost": {
"type": "remote",
"url": "https://mcphost.dev/mcp",
"enabled": true
}
}
} openclaw mcp add dev-mcphost-mcphost --url 'https://mcphost.dev/mcp' --transport streamable-http
mcp_servers:
dev-mcphost-mcphost:
url: "https://mcphost.dev/mcp" {
"McpServers": {
"dev-mcphost-mcphost": {
"Transport": "http",
"Url": "https://mcphost.dev/mcp"
}
}
} assistant mcp add dev-mcphost-mcphost -t streamable-http -u 'https://mcphost.dev/mcp'
{
"mcpServers": {
"dev-mcphost-mcphost": {
"type": "http",
"url": "https://mcphost.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Sept 26 +4
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 0
- Tool “host.docs.status” rewrote its description, which is the text the model reads security
- Tool “host.runs.list” rewrote its description, which is the text the model reads security
- Tool “host.runs.wait” rewrote its description, which is the text the model reads security
- Tool “host.usage” rewrote its description, which is the text the model reads security
- Schema quality: 12812 → 15524 ▼ functional
- New tool “host.docs.index_config” functional
- New tool “host.docs.reindex” functional
- New tool “host.docs.search” functional
- New tool “host.enduser.assertion_secret_rotate” functional
- New tool “host.enduser.audit” functional
- New tool “host.enduser.export” functional
- New tool “host.enduser.get” functional
- New tool “host.enduser.list” functional
- New tool “host.enduser.purge” functional
- New tool “host.enduser.revoke” functional
- New tool “host.enduser.unrevoke” functional
- New tool “host.enduser.whoami” functional
- New tool “host.progress” functional
- New tool “host.runs.part” functional
- New tool “host.share.caller_limit” functional
- New tool “host.share.caller_limit_remove” functional
- “host.runs.list” added an optional parameter “end_user_subject” cosmetic
- “host.runs.wait” added an optional parameter “until” cosmetic
- “host.state.delete” added an optional parameter “end_user” cosmetic
- “host.state.delete_rows” added an optional parameter “end_user” cosmetic
- “host.state.get” added an optional parameter “end_user” cosmetic
- “host.state.insert” added an optional parameter “end_user” cosmetic
- “host.state.list” added an optional parameter “end_user” cosmetic
- “host.state.query” added an optional parameter “end_user” cosmetic
- “host.state.set” added an optional parameter “end_user” cosmetic
- “host.usage” added an optional parameter “by” cosmetic
- “host.usage” added an optional parameter “cursor” cosmetic
- “host.usage” added an optional parameter “limit” cosmetic
- “host.usage” added an optional parameter “tool” cosmetic
- “host.usage” reworded the description of “window” cosmetic
- 26 Sept 26 +11
- Authorization: unverified → fail ▼ security
- Schema quality: 11217 → 12812 ▼ functional
- New tool “host.docs.delete” functional
- New tool “host.docs.get” functional
- New tool “host.docs.list” functional
- New tool “host.docs.purge” functional
- New tool “host.docs.put” functional
- New tool “host.docs.status” functional
- New tool “host.oauth.issuer_remove” functional
- New tool “host.oauth.issuer_set” functional
- New tool “host.oauth.issuers” functional
- New tool “host.table.describe” functional
- New tool “host.table.model_set” functional
- New tool “host.table.models” functional
- 25 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 0
- Tool “host.channel.open” rewrote its description, which is the text the model reads security
- Tool “host.channel.post” rewrote its description, which is the text the model reads security
- Tool “host.tool_call” rewrote its description, which is the text the model reads security
- Tool “host.trigger.list” rewrote its description, which is the text the model reads security
- Tool “host.trigger.replay” rewrote its description, which is the text the model reads security
- Tool “host.trigger.set” rewrote its description, which is the text the model reads security
- Tool “host.trigger.test” rewrote its description, which is the text the model reads security
- Schema quality: 9975 → 11217 ▼ functional
- New tool “host.channel.close” functional
- New tool “host.channel.freeze” functional
- New tool “host.channel.read” functional
- New tool “host.channel.unfreeze” functional
- New tool “host.tool_diff” functional
- New tool “host.tool_history” functional
- New tool “host.tool_rollback” functional
- “host.channel.open” added an optional parameter “group” cosmetic
- “host.tool_call” added an optional parameter “version” cosmetic
- “host.trigger.replay” added an optional parameter “id” cosmetic
- “host.trigger.replay” added an optional parameter “row_id” cosmetic
- “host.trigger.set” added an optional parameter “channel_id” cosmetic
- “host.trigger.set” added an optional parameter “name” cosmetic
- “host.trigger.set” reworded the description of “args” cosmetic
- “host.trigger.set” reworded the description of “kind” cosmetic
- “host.trigger.set” reworded the description of “verify” cosmetic
- “host.trigger.test” reworded the description of “body” cosmetic
- “host.trigger.test” reworded the description of “id” cosmetic
- “host.channel.open” made “name” optional cosmetic
- “host.trigger.replay” made “run_id” optional cosmetic
- 23 Sept 26 +1
- Tool “host.tool_publish” rewrote its description, which is the text the model reads security
- Tool “host.tool_run” rewrote its description, which is the text the model reads security
- New tool “host.changelog” functional
- New tool “host.channel.open” functional
- New tool “host.channel.post” functional
- New tool “host.export” functional
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 29 Sept 2026 · Probed https://mcphost.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcphost.dev | CN=YE2,O=Let's Encrypt,C=US | 6 Sept 2026 | 5 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 6d90eafb56dfa48bc01e1e08da1962e263e |
| SANs: mcphost.dev | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcphost.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| mcphost.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://mcphost.dev/.well-known/oauth-protected-resource", scope="mcp"
Bearer resource_metadata="https://mcphost.dev/.well-known/oauth-protected-resource", scope="mcp" Protected resource metadata
| Document | https://mcphost.dev/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://mcphost.dev |
| Authorisation server | https://mcphost.dev |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcphost.dev/mcp | Verified | 200 | |
| http (plaintext) | http://mcphost.dev/mcp | HTTPS enforced | 308 | https://mcphost.dev/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
host.msg.inbox ~123
Every unread-or-read message across every thread you participate in, excluding your own sends, ordered oldest first; page with cursor from the previous response's next_cursor.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque; omit for the first page. |
| limit | integer | – | Up to 100; default 50. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| unread_only | boolean | – | Filter to messages not yet acked. |
No output schema declared.
No examples provided.
host.msg.reply ~180
Reply in a thread you participate in; appends with the next seq. Blocked or contact-closed participants are skipped and listed in refused rather than failing the reply. thread_not_found (byte-identical for a nonexistent id) if you are not a participant.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | Message text; non-empty after trim. |
| data | object | – | Optional structured payload. |
| dedupe_key | string | – | Resend with the same key within 24h to get back the original message_id instead of a duplicate. |
| in_reply_to | string | – | The message_id this replies to. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| thread_id | string | yes | The thread to reply in. |
No output schema declared.
No examples provided.
host.msg.send ~289
Send a message to one or more agent-directory addresses, creating a new thread (or, with thread_id, adding to one you already participate in). Refused recipients (agent_not_found, contact_refused, recipient_inbox_full) are listed in refused rather than failing the whole call; from is always the authenticated tenant, never a caller argument.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | Message text; non-empty after trim. |
| data | object | – | Optional structured payload. |
| dedupe_key | string | – | Resend with the same key within 24h to get back the original message_id instead of a duplicate. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| thread_id | string | – | Add this send to an existing thread you participate in instead of starting a new one; to's addresses join as participants. |
| to | array | yes | 1 to recipients_per_msg_max addresses (@handle or t_... namespace). |
| urgent | boolean | – | Mark this send urgent (default false): allowed only to accepted contacts or open recipients (refused the same as any other send otherwise), under its own urgent_per_day quota per sender/recipient pai… |
No output schema declared.
No examples provided.
host.msg.thread ~117
Every message in one thread you participate in, ordered by seq; thread_not_found if you are not (or no longer) a participant.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | The seq to resume after; omit for the start. |
| limit | integer | – | Up to 100; default 50. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| thread_id | string | yes | The thread to read. |
No output schema declared.
No examples provided.
host.msg.unblock ~67
Remove a block.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | The @handle or t_... namespace to unblock. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.msg.wait ~158
Long-poll for a new message until one past cursor arrives or timeout_s elapses (max 25s), returning the same shape as host.msg.inbox either way -- for a client with no polling loop of its own. On timeout, messages is empty and next_cursor is unchanged.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque; omit to wait for the next message from now. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| timeout_s | integer | – | Max seconds to wait, capped at 25; default 20. |
| unread_only | boolean | – | Filter to messages not yet acked. |
No output schema declared.
No examples provided.
host.oauth.audit ~146
Page this tenant's OAuth auth audit log (authorize/consent/token/refresh/revoke/ policy_change/approved/denied/refused events), newest additions last. Optional since/until (unix seconds) and event filters; limit defaults to 50, max 500; cursor resumes from a previous page's cursor field.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | – |
| event | string | – | – |
| limit | integer | – | – |
| since | integer | – | – |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| until | integer | – | – |
No output schema declared.
No examples provided.
host.oauth.audit_export ~127
Export this tenant's OAuth auth audit log for since..until as JSON lines (one object per line, same fields host.oauth.audit pages). Refuses export_too_large (with a suggested narrower window) past 50 MiB.
| Name | Type | Req | Description |
|---|---|---|---|
| since | integer | yes | Start of the export window, unix seconds (inclusive). |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| until | integer | yes | End of the export window, unix seconds (exclusive). |
No output schema declared.
No examples provided.
host.oauth.client_approve ~88
Approve a pending client (from host.oauth.pending): its next /oauth/authorize reaches consent directly.
| Name | Type | Req | Description |
|---|---|---|---|
| client_id | string | yes | The client_id to approve, as listed by host.oauth.pending. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.client_deny ~87
Deny a pending client (from host.oauth.pending): every later authorize attempt reads client_not_allowed.
| Name | Type | Req | Description |
|---|---|---|---|
| client_id | string | yes | The client_id to deny, as listed by host.oauth.pending. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.doctor ~104
Diagnose this tenant's OIDC provider setup: discovery reachable, jwks_uri reachable, per-tenant resource metadata, whether the callback URL is listed in the provider's discovery document (when exposed), and a dry-run authorize URL. One line per check with ok|fail and a fix.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.grant_revoke ~90
Revoke one hosted-authorization-server grant by id (from host.oauth.grants): its access tokens fail within 60s and its refresh tokens stop rotating.
| Name | Type | Req | Description |
|---|---|---|---|
| id | integer | yes | The grant id. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.grants ~105
List the OAuth clients currently connected to this tenant through mcphost's own hosted authorization server (host.oauth.issuer_set is for a tenant's own bring-your-own issuer instead): each grant's client_name, method (cimd|dcr), resource, created_at and last_used_at.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.issuer_remove ~79
Remove one of this tenant's registered OAuth issuers; bearer JWTs from it stop authenticating immediately.
| Name | Type | Req | Description |
|---|---|---|---|
| issuer | string | yes | The issuer to remove. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.issuer_set ~167
Register (or update) an OAuth issuer for this tenant: bearer JWTs with iss equal to issuer, a matching aud, verified against jwks_url, authenticate as this tenant. Up to 3 issuers per tenant; an issuer already registered by another tenant is refused issuer_already_registered.
| Name | Type | Req | Description |
|---|---|---|---|
| audience | string | yes | The JWT `aud` claim value to require. |
| issuer | string | yes | The JWT `iss` claim value to match, e.g. https://issuer.example.com. |
| jwks_url | string | yes | URL this host fetches the issuer's JWKS from. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.issuers ~69
List this tenant's registered OAuth issuers with their audience, jwks_url, and JWKS fetch age.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.pending ~58
List clients awaiting approval under this tenant's clients: approve policy.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.policy ~82
This tenant's current hosted-authorization-server client and session policy (host.oauth.policy_set's own field shape); the documented defaults for a tenant that has never called host.oauth.policy_set.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.policy_set ~256
Set this tenant's hosted-authorization-server client and session policy. Every field is optional and, when omitted, keeps its current (or default) value: clients (any|allowlist|approve, default any), allowlist (client_id or CIMD-host strings, for allowlist mode), access_ttl_s (300..3600, default 3600), refresh_ttl_s (3600..2592000, default 2592000), max_grant_age_s (a refresh past this many seconds since consent fails invalid_grant/grant_expired; null clears it), reconsent_after_s (a refresh past this many seconds since consent fails invalid_grant/reconsent_required and the next authorize shows consent again; null clears it).
| Name | Type | Req | Description |
|---|---|---|---|
| access_ttl_s | integer | – | – |
| allowlist | array | – | – |
| clients | string | – | – |
| max_grant_age_s | integer | – | – |
| reconsent_after_s | integer | – | – |
| refresh_ttl_s | integer | – | – |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.provider ~78
This tenant's registered OIDC identity provider (issuer, client_id, endpoints, scopes, flags) -- null if none is set. Never carries the client secret.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.provider_remove ~82
Remove this tenant's OIDC identity provider: every federated grant it produced is revoked immediately, and the per-tenant resource falls back to key/claim (owner) login.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.provider_set ~278
Register (or update) this tenant's own OIDC identity provider: end users who connect to this tenant's per-tenant resource log in through it. Fetches the issuer's discovery document once (https only) and stores authorization_endpoint, token_endpoint, and jwks_uri. client_secret is encrypted at rest and never shown again.
| Name | Type | Req | Description |
|---|---|---|---|
| claims_map | object | – | Optional {"email": "<claim name>", "name": "<claim name>"} override; defaults to the claim names themselves. |
| client_id | string | yes | The client id your provider issued for mcphost. |
| client_secret | string | yes | The client secret your provider issued for mcphost; encrypted at rest and never shown again. |
| issuer | string | yes | The provider's issuer URL, e.g. https://your-idp.example.com. |
| owner_login | boolean | – | Default false: also allow this tenant's own key/claim login on its per-tenant resource. |
| require_verified_email | boolean | – | Default true: refuse login when the provider reports email_verified: false. |
| scopes | array | – | Default ["openid", "email", "profile"]. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.revoke_all ~74
Revoke every one of this tenant's live grants, refresh tokens and pending clients at once: access tokens fail within 60s.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.scope_set ~135
Declare (or update) one scope this tenant's tools may require: name (a catalogued name, or the built-ins read/write) and a human-readable description shown on the OAuth consent page. Up to 32 catalog entries per tenant.
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | yes | Human-readable text shown on the OAuth consent page. |
| name | string | yes | ^[a-z][a-z0-9_:.-]{0,40}$ |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.scopes ~58
List this tenant's own scope catalog: name and description.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.trusted_issuer_remove ~81
Remove one of this tenant's trusted identity-assertion issuers; its assertions stop authenticating immediately.
| Name | Type | Req | Description |
|---|---|---|---|
| issuer | string | yes | The issuer to remove. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.trusted_issuer_set ~221
Register (or update) an identity-assertion issuer for this tenant's enterprise-managed auth: identity assertions with iss equal to issuer, from client_id, verified against jwks_url, mint a token for the employee they name -- no consent screen. Up to 4 trusted issuers per tenant; a 5th is refused quota_trusted_issuers; an issuer already trusted by another tenant is refused issuer_already_registered.
| Name | Type | Req | Description |
|---|---|---|---|
| audience | string | – | Expected assertion `aud`, when the provider signs one other than this host's own issuer URL. |
| client_id | string | yes | The pre-registered enterprise client id allowed to use this issuer's grant. |
| issuer | string | yes | The identity assertion's `iss` claim value to match. |
| jwks_url | string | yes | URL this host fetches the issuer's JWKS from. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.oauth.trusted_issuers ~71
List this tenant's trusted identity-assertion issuers with their jwks_url, client_id and audience.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.progress ~184
Report (or merge in) counters and/or pct/msg on a run, by id. Each named counter (items_processed, items_total, bytes_out, custom.<k>) is monotonic on its own -- a lower value than what's already stored fails validation with nothing written. Read back via host.runs.get/wait/list's counters field.
| Name | Type | Req | Description |
|---|---|---|---|
| counters | object | – | items_processed?, items_total?, bytes_out?, custom?: {k: number} -- each key monotonic. |
| msg | string | – | A free-text progress message. |
| pct | integer | – | 0-100 percent complete, free text. |
| run_id | string | yes | The run id to report progress on. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.quickstart ~146
Return the shortest ordered sequence of calls to a working tool of `kind`, with your namespace and a filled-in example already substituted in, plus the current limits and a try_before_call table naming the one dry-run tool for each case. Read-only. Call this before host.tool_publish if you're not sure what a spec should look like. Unauthenticated callers get the signup step first.
| Name | Type | Req | Description |
|---|---|---|---|
| kind | string | yes | Which registered kind to return a worked example for, e.g. echo, http, python. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.redeem ~123
Exchange a signup(handoff: true) handoff_token for the tenant key it was issued for. Single-use: a second redemption fails with handoff_token_redeemed; past its expiry it fails with handoff_token_expired. Unauthenticated -- the token itself is the proof.
| Name | Type | Req | Description |
|---|---|---|---|
| handoff_token | string | yes | The handoff_token signup(handoff: true) returned. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.registry_publish ~69
Publish this tenant's server.json to the configured MCP registry (requires --registry-url and admin.tenant_verify_namespace first).
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.runs.cancel ~93
Stop a queued or running job: its sandbox process is killed within ~2s and the run reads cancelled. A run that already finished fails with run_not_cancellable.
| Name | Type | Req | Description |
|---|---|---|---|
| run_id | string | yes | The run id to cancel. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.runs.get ~96
Read one run's status, progress and (once done) result by id -- the same run a host.tool_call(..., async=true) or a scheduled/triggered execution created.
| Name | Type | Req | Description |
|---|---|---|---|
| run_id | string | yes | The run id to read. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.runs.list ~176
List this tenant's recent runs, newest first, optionally filtered by tool, status (queued|running|done|error|timeout|cancelled), trigger (call|job|schedule|event|chain) or end_user_subject (the end user, if any, the run ran as).
| Name | Type | Req | Description |
|---|---|---|---|
| end_user_subject | string | – | Only runs that ran as this end user's subject. |
| limit | integer | – | Max runs to return; default 20. |
| status | string | – | Only runs in this status. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| tool | string | – | Only runs of this tool name. |
| trigger | string | – | Only runs of this trigger kind. |
No output schema declared.
No examples provided.
host.runs.part ~133
Read part n of a run's result (host.runs.get/wait inline only part 0). A run whose whole result fit inline reads back parts: 1, n: 0 with the full result. n past the last part fails with not_found.
| Name | Type | Req | Description |
|---|---|---|---|
| n | integer | – | The 0-based part index; default 0. |
| run_id | string | yes | The run id to read a part of. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.runs.purge ~110
Delete the stored results of every done run finished at or before before_unix; each then reads done with result: null, purged: true. Frees state_bytes_max quota the results were counted against.
| Name | Type | Req | Description |
|---|---|---|---|
| before_unix | integer | yes | Purge results of runs finished at or before this unix timestamp. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.runs.wait ~167
Long-poll one run until it finalizes, until: {counter, gte} is reached, or timeout_s elapses (max 25s), returning its current status either way -- for a client with no polling loop of its own.
| Name | Type | Req | Description |
|---|---|---|---|
| run_id | string | yes | The run id to wait on. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| timeout_s | integer | – | Max seconds to wait, capped at 25; default 20. |
| until | object | – | {counter: <name>, gte: <n>} -- return as soon as that counter reaches n, even while the run is still running. |
No output schema declared.
No examples provided.
host.secret_list ~56
List this tenant's secret names (never their values).
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.secret_set ~95
Store an encrypted secret value under this tenant's namespace.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Secret name, referenced from a spec as secret.<name>. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| value | string | yes | The secret value; stored AES-256-GCM encrypted, never returned. |
No output schema declared.
No examples provided.
host.self_offboard ~142
Permanently close your own account: disables the tenant, cancels any active Stripe subscription (pro plan), and stops your key from authenticating anything further -- same as an admin-disabled tenant. Idempotent: an already-offboarded key gets the same tenant_disabled/tenant_key_invalid error every other host.*/ billing.* call already gets from it, not a crash. This does not scrub historical usage/signup records -- those stay for audit, same as today's admin-disabled tenants.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.share.caller_limit ~150
Cap how many successful calls a caller tenant may make per UTC day into one of this tenant's shared tools. The tool must already be shared. Exceeding the cap fails the call with quota_caller (never runs it); this tenant's own calls to the tool are unaffected.
| Name | Type | Req | Description |
|---|---|---|---|
| caller_tenant | string | yes | The caller's namespace to cap. |
| calls_per_day | integer | yes | Max successful calls per UTC day for this caller. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| tool | string | yes | Local name of the shared tool. |
No output schema declared.
No examples provided.
host.share.caller_limit_remove ~90
Remove a caller_limit set by host.share.caller_limit.
| Name | Type | Req | Description |
|---|---|---|---|
| caller_tenant | string | yes | The caller's namespace whose limit to remove. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| tool | string | yes | Local name of the shared tool. |
No output schema declared.
No examples provided.
host.state.delete ~122
Delete one key from this tenant's key-value state namespace.
| Name | Type | Req | Description |
|---|---|---|---|
| end_user | string|null | – | "self" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value. |
| key | string | yes | Key to delete from this tenant's key-value state namespace. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.state.delete_rows ~160
Delete rows from a declared table matching an optional where filter (same grammar as host.state.query); omitting where deletes every row in the table.
| Name | Type | Req | Description |
|---|---|---|---|
| end_user | string|null | – | "self" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value. |
| table | string | yes | Name of the declared table to delete rows from. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| where | string | – | Optional filter, same grammar as host.state.query; omit to delete every row. |
No output schema declared.
No examples provided.
host.state.get ~138
Read one key from this tenant's key-value state namespace. Returns found: false (not an error) if the key was never set.
| Name | Type | Req | Description |
|---|---|---|---|
| end_user | string|null | – | "self" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value. |
| key | string | yes | Key to read from this tenant's key-value state namespace. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.state.insert ~180
Insert one row (an object) or several (an array of objects) into a declared table. Each row is validated against the table's schema first -- a type mismatch fails the whole call with state_schema_violation and writes nothing.
| Name | Type | Req | Description |
|---|---|---|---|
| end_user | string|null | – | "self" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value. |
| rows | – | yes | One row (an object) or several (an array of objects), each validated against the table's schema. |
| table | string | yes | Name of the declared table to insert into. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.state.list ~148
List keys (with their current values) in this tenant's key-value state namespace, optionally filtered by prefix.
| Name | Type | Req | Description |
|---|---|---|---|
| end_user | string|null | – | "self" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value. |
| limit | integer | – | Max keys to return; default 100. |
| prefix | string | – | Only list keys starting with this prefix; default: all keys. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.state.query ~223
Read rows from a declared table, optionally filtered (where: "field op value", ops = != < <= > >=, clauses joined by ' and '), ordered (order_by: "field" or "field desc") and capped (limit).
| Name | Type | Req | Description |
|---|---|---|---|
| end_user | string|null | – | "self" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value. |
| limit | integer | – | Max rows to return; optional. |
| order_by | string | – | Optional "field" or "field desc" to sort by. |
| table | string | yes | Name of the declared table to read from. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| where | string | – | Optional filter, e.g. "age > 21"; ops are != < <= > >=, clauses joined by ' and '. |
No output schema declared.
No examples provided.
host.state.set ~162
Write one key in this tenant's key-value state namespace; value may be any JSON value. Overrun of the plan's state_bytes_max quota fails with state_quota_exceeded and writes nothing.
| Name | Type | Req | Description |
|---|---|---|---|
| end_user | string|null | – | "self" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value. |
| key | string | yes | Key to write in this tenant's key-value state namespace. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| value | – | yes | Any JSON value to store under key. |
No output schema declared.
No examples provided.
What is the mcphost MCP server?
mcphost is an MCP server listed in the public MCP registry as dev.mcphost/mcphost. Host your MCP tool over streamable HTTP in one command. This page covers its hosted endpoint (https://mcphost.dev/mcp).
Is the mcphost MCP server safe to use?
mcphost scores 88 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the mcphost MCP server expose?
mcphost exposes 136 tools: signup, host.whoami, host.redeem, host.key_rotate, host.self_offboard, and 131 more. Their descriptions and schemas cost roughly 17,493 tokens of context every time the server is loaded.
Does the mcphost MCP server require authentication?
Yes. mcphost asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the mcphost MCP server still maintained?
mcphost is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.