Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

mcphost

REMOTE · MCPHOST.DEV · SCANNED SEP 29

Host your MCP tool over streamable HTTP in one command.

Available components

+18 this week 88 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security92
Transport & Reachability100
Schema Quality & AI Usability75
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 17958 tokens (~132/item across 136 items; 136 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management77
  • Stability observed for 23 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 97% of tool parameters carry a description.Partial
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 0 of 23 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "host.tool_publish" implies "publish" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
  • An AI judge read all 137 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the mcphost MCP server?

mcphost is a hosted endpoint at https://mcphost.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcphost.dev

# add to Claude Code
claude mcp add --transport http dev-mcphost-mcphost 'https://mcphost.dev/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "dev-mcphost-mcphost": {
      "url": "https://mcphost.dev/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "dev-mcphost-mcphost": {
      "type": "http",
      "url": "https://mcphost.dev/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.dev-mcphost-mcphost]
url = "https://mcphost.dev/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "dev-mcphost-mcphost": {
      "type": "remote",
      "url": "https://mcphost.dev/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add dev-mcphost-mcphost --url 'https://mcphost.dev/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  dev-mcphost-mcphost:
    url: "https://mcphost.dev/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "dev-mcphost-mcphost": {
      "Transport": "http",
      "Url": "https://mcphost.dev/mcp"
    }
  }
}
# add to Vellum
assistant mcp add dev-mcphost-mcphost -t streamable-http -u 'https://mcphost.dev/mcp'
// mcp.json
{
  "mcpServers": {
    "dev-mcphost-mcphost": {
      "type": "http",
      "url": "https://mcphost.dev/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 29 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.

  • 28 Sept 26 +4
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 0
    • Tool “host.docs.status” rewrote its description, which is the text the model reads security
    • Tool “host.runs.list” rewrote its description, which is the text the model reads security
    • Tool “host.runs.wait” rewrote its description, which is the text the model reads security
    • Tool “host.usage” rewrote its description, which is the text the model reads security
    • Schema quality: 12812 → 15524 ▼ functional
    • New tool “host.docs.index_config” functional
    • New tool “host.docs.reindex” functional
    • New tool “host.docs.search” functional
    • New tool “host.enduser.assertion_secret_rotate” functional
    • New tool “host.enduser.audit” functional
    • New tool “host.enduser.export” functional
    • New tool “host.enduser.get” functional
    • New tool “host.enduser.list” functional
    • New tool “host.enduser.purge” functional
    • New tool “host.enduser.revoke” functional
    • New tool “host.enduser.unrevoke” functional
    • New tool “host.enduser.whoami” functional
    • New tool “host.progress” functional
    • New tool “host.runs.part” functional
    • New tool “host.share.caller_limit” functional
    • New tool “host.share.caller_limit_remove” functional
    • “host.runs.list” added an optional parameter “end_user_subject” cosmetic
    • “host.runs.wait” added an optional parameter “until” cosmetic
    • “host.state.delete” added an optional parameter “end_user” cosmetic
    • “host.state.delete_rows” added an optional parameter “end_user” cosmetic
    • “host.state.get” added an optional parameter “end_user” cosmetic
    • “host.state.insert” added an optional parameter “end_user” cosmetic
    • “host.state.list” added an optional parameter “end_user” cosmetic
    • “host.state.query” added an optional parameter “end_user” cosmetic
    • “host.state.set” added an optional parameter “end_user” cosmetic
    • “host.usage” added an optional parameter “by” cosmetic
    • “host.usage” added an optional parameter “cursor” cosmetic
    • “host.usage” added an optional parameter “limit” cosmetic
    • “host.usage” added an optional parameter “tool” cosmetic
    • “host.usage” reworded the description of “window” cosmetic
  • 26 Sept 26 +11
    • Authorization: unverified → fail ▼ security
    • Schema quality: 11217 → 12812 ▼ functional
    • New tool “host.docs.delete” functional
    • New tool “host.docs.get” functional
    • New tool “host.docs.list” functional
    • New tool “host.docs.purge” functional
    • New tool “host.docs.put” functional
    • New tool “host.docs.status” functional
    • New tool “host.oauth.issuer_remove” functional
    • New tool “host.oauth.issuer_set” functional
    • New tool “host.oauth.issuers” functional
    • New tool “host.table.describe” functional
    • New tool “host.table.model_set” functional
    • New tool “host.table.models” functional
  • 25 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 0
    • Tool “host.channel.open” rewrote its description, which is the text the model reads security
    • Tool “host.channel.post” rewrote its description, which is the text the model reads security
    • Tool “host.tool_call” rewrote its description, which is the text the model reads security
    • Tool “host.trigger.list” rewrote its description, which is the text the model reads security
    • Tool “host.trigger.replay” rewrote its description, which is the text the model reads security
    • Tool “host.trigger.set” rewrote its description, which is the text the model reads security
    • Tool “host.trigger.test” rewrote its description, which is the text the model reads security
    • Schema quality: 9975 → 11217 ▼ functional
    • New tool “host.channel.close” functional
    • New tool “host.channel.freeze” functional
    • New tool “host.channel.read” functional
    • New tool “host.channel.unfreeze” functional
    • New tool “host.tool_diff” functional
    • New tool “host.tool_history” functional
    • New tool “host.tool_rollback” functional
    • “host.channel.open” added an optional parameter “group” cosmetic
    • “host.tool_call” added an optional parameter “version” cosmetic
    • “host.trigger.replay” added an optional parameter “id” cosmetic
    • “host.trigger.replay” added an optional parameter “row_id” cosmetic
    • “host.trigger.set” added an optional parameter “channel_id” cosmetic
    • “host.trigger.set” added an optional parameter “name” cosmetic
    • “host.trigger.set” reworded the description of “args” cosmetic
    • “host.trigger.set” reworded the description of “kind” cosmetic
    • “host.trigger.set” reworded the description of “verify” cosmetic
    • “host.trigger.test” reworded the description of “body” cosmetic
    • “host.trigger.test” reworded the description of “id” cosmetic
    • “host.channel.open” made “name” optional cosmetic
    • “host.trigger.replay” made “run_id” optional cosmetic
  • 23 Sept 26 +1
    • Tool “host.tool_publish” rewrote its description, which is the text the model reads security
    • Tool “host.tool_run” rewrote its description, which is the text the model reads security
    • New tool “host.changelog” functional
    • New tool “host.channel.open” functional
    • New tool “host.channel.post” functional
    • New tool “host.export” functional
  • 20 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 29 Sept 2026 · Probed https://mcphost.dev/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=mcphost.dev CN=YE2,O=Let's Encrypt,C=US 6 Sept 2026 5 Dec 2026 ECDSA 256 ECDSA-SHA384 6d90eafb56dfa48bc01e1e08da1962e263e
SANs: mcphost.dev
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcphost.dev. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
dev. present 60074 8 Verified
mcphost.dev. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer resource_metadata="https://mcphost.dev/.well-known/oauth-protected-resource", scope="mcp"

Bearer resource_metadata="https://mcphost.dev/.well-known/oauth-protected-resource", scope="mcp"

Protected resource metadata

Document https://mcphost.dev/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://mcphost.dev
Authorisation server https://mcphost.dev

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcphost.dev/mcp Verified 200
http (plaintext) http://mcphost.dev/mcp HTTPS enforced 308 https://mcphost.dev/mcp
MCP tools · 136 exposed · ~17,493 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
host.msg.inbox ~123

Every unread-or-read message across every thread you participate in, excluding your own sends, ordered oldest first; page with cursor from the previous response's next_cursor.

NameTypeReqDescription
cursorstring–Opaque; omit for the first page.
limitinteger–Up to 100; default 50.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
unread_onlyboolean–Filter to messages not yet acked.

No output schema declared.

No examples provided.

host.msg.reply ~180

Reply in a thread you participate in; appends with the next seq. Blocked or contact-closed participants are skipped and listed in refused rather than failing the reply. thread_not_found (byte-identical for a nonexistent id) if you are not a participant.

NameTypeReqDescription
bodystringyesMessage text; non-empty after trim.
dataobject–Optional structured payload.
dedupe_keystring–Resend with the same key within 24h to get back the original message_id instead of a duplicate.
in_reply_tostring–The message_id this replies to.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
thread_idstringyesThe thread to reply in.

No output schema declared.

No examples provided.

host.msg.send ~289

Send a message to one or more agent-directory addresses, creating a new thread (or, with thread_id, adding to one you already participate in). Refused recipients (agent_not_found, contact_refused, recipient_inbox_full) are listed in refused rather than failing the whole call; from is always the authenticated tenant, never a caller argument.

NameTypeReqDescription
bodystringyesMessage text; non-empty after trim.
dataobject–Optional structured payload.
dedupe_keystring–Resend with the same key within 24h to get back the original message_id instead of a duplicate.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
thread_idstring–Add this send to an existing thread you participate in instead of starting a new one; to's addresses join as participants.
toarrayyes1 to recipients_per_msg_max addresses (@handle or t_... namespace).
urgentboolean–Mark this send urgent (default false): allowed only to accepted contacts or open recipients (refused the same as any other send otherwise), under its own urgent_per_day quota per sender/recipient pai…

No output schema declared.

No examples provided.

host.msg.thread ~117

Every message in one thread you participate in, ordered by seq; thread_not_found if you are not (or no longer) a participant.

NameTypeReqDescription
cursorstring–The seq to resume after; omit for the start.
limitinteger–Up to 100; default 50.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
thread_idstringyesThe thread to read.

No output schema declared.

No examples provided.

host.msg.unblock ~67

Remove a block.

NameTypeReqDescription
addressstringyesThe @handle or t_... namespace to unblock.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.msg.wait ~158

Long-poll for a new message until one past cursor arrives or timeout_s elapses (max 25s), returning the same shape as host.msg.inbox either way -- for a client with no polling loop of its own. On timeout, messages is empty and next_cursor is unchanged.

NameTypeReqDescription
cursorstring–Opaque; omit to wait for the next message from now.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
timeout_sinteger–Max seconds to wait, capped at 25; default 20.
unread_onlyboolean–Filter to messages not yet acked.

No output schema declared.

No examples provided.

host.oauth.audit ~146

Page this tenant's OAuth auth audit log (authorize/consent/token/refresh/revoke/ policy_change/approved/denied/refused events), newest additions last. Optional since/until (unix seconds) and event filters; limit defaults to 50, max 500; cursor resumes from a previous page's cursor field.

NameTypeReqDescription
cursorstring––
eventstring––
limitinteger––
sinceinteger––
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
untilinteger––

No output schema declared.

No examples provided.

host.oauth.audit_export ~127

Export this tenant's OAuth auth audit log for since..until as JSON lines (one object per line, same fields host.oauth.audit pages). Refuses export_too_large (with a suggested narrower window) past 50 MiB.

NameTypeReqDescription
sinceintegeryesStart of the export window, unix seconds (inclusive).
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
untilintegeryesEnd of the export window, unix seconds (exclusive).

No output schema declared.

No examples provided.

host.oauth.client_approve ~88

Approve a pending client (from host.oauth.pending): its next /oauth/authorize reaches consent directly.

NameTypeReqDescription
client_idstringyesThe client_id to approve, as listed by host.oauth.pending.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.client_deny ~87

Deny a pending client (from host.oauth.pending): every later authorize attempt reads client_not_allowed.

NameTypeReqDescription
client_idstringyesThe client_id to deny, as listed by host.oauth.pending.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.doctor ~104

Diagnose this tenant's OIDC provider setup: discovery reachable, jwks_uri reachable, per-tenant resource metadata, whether the callback URL is listed in the provider's discovery document (when exposed), and a dry-run authorize URL. One line per check with ok|fail and a fix.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.grant_revoke ~90

Revoke one hosted-authorization-server grant by id (from host.oauth.grants): its access tokens fail within 60s and its refresh tokens stop rotating.

NameTypeReqDescription
idintegeryesThe grant id.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.grants ~105

List the OAuth clients currently connected to this tenant through mcphost's own hosted authorization server (host.oauth.issuer_set is for a tenant's own bring-your-own issuer instead): each grant's client_name, method (cimd|dcr), resource, created_at and last_used_at.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.issuer_remove ~79

Remove one of this tenant's registered OAuth issuers; bearer JWTs from it stop authenticating immediately.

NameTypeReqDescription
issuerstringyesThe issuer to remove.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.issuer_set ~167

Register (or update) an OAuth issuer for this tenant: bearer JWTs with iss equal to issuer, a matching aud, verified against jwks_url, authenticate as this tenant. Up to 3 issuers per tenant; an issuer already registered by another tenant is refused issuer_already_registered.

NameTypeReqDescription
audiencestringyesThe JWT `aud` claim value to require.
issuerstringyesThe JWT `iss` claim value to match, e.g. https://issuer.example.com.
jwks_urlstringyesURL this host fetches the issuer's JWKS from.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.issuers ~69

List this tenant's registered OAuth issuers with their audience, jwks_url, and JWKS fetch age.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.pending ~58

List clients awaiting approval under this tenant's clients: approve policy.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.policy ~82

This tenant's current hosted-authorization-server client and session policy (host.oauth.policy_set's own field shape); the documented defaults for a tenant that has never called host.oauth.policy_set.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.policy_set ~256

Set this tenant's hosted-authorization-server client and session policy. Every field is optional and, when omitted, keeps its current (or default) value: clients (any|allowlist|approve, default any), allowlist (client_id or CIMD-host strings, for allowlist mode), access_ttl_s (300..3600, default 3600), refresh_ttl_s (3600..2592000, default 2592000), max_grant_age_s (a refresh past this many seconds since consent fails invalid_grant/grant_expired; null clears it), reconsent_after_s (a refresh past this many seconds since consent fails invalid_grant/reconsent_required and the next authorize shows consent again; null clears it).

NameTypeReqDescription
access_ttl_sinteger––
allowlistarray––
clientsstring––
max_grant_age_sinteger––
reconsent_after_sinteger––
refresh_ttl_sinteger––
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.provider ~78

This tenant's registered OIDC identity provider (issuer, client_id, endpoints, scopes, flags) -- null if none is set. Never carries the client secret.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.provider_remove ~82

Remove this tenant's OIDC identity provider: every federated grant it produced is revoked immediately, and the per-tenant resource falls back to key/claim (owner) login.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.provider_set ~278

Register (or update) this tenant's own OIDC identity provider: end users who connect to this tenant's per-tenant resource log in through it. Fetches the issuer's discovery document once (https only) and stores authorization_endpoint, token_endpoint, and jwks_uri. client_secret is encrypted at rest and never shown again.

NameTypeReqDescription
claims_mapobject–Optional {"email": "<claim name>", "name": "<claim name>"} override; defaults to the claim names themselves.
client_idstringyesThe client id your provider issued for mcphost.
client_secretstringyesThe client secret your provider issued for mcphost; encrypted at rest and never shown again.
issuerstringyesThe provider's issuer URL, e.g. https://your-idp.example.com.
owner_loginboolean–Default false: also allow this tenant's own key/claim login on its per-tenant resource.
require_verified_emailboolean–Default true: refuse login when the provider reports email_verified: false.
scopesarray–Default ["openid", "email", "profile"].
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.revoke_all ~74

Revoke every one of this tenant's live grants, refresh tokens and pending clients at once: access tokens fail within 60s.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.scope_set ~135

Declare (or update) one scope this tenant's tools may require: name (a catalogued name, or the built-ins read/write) and a human-readable description shown on the OAuth consent page. Up to 32 catalog entries per tenant.

NameTypeReqDescription
descriptionstringyesHuman-readable text shown on the OAuth consent page.
namestringyes^[a-z][a-z0-9_:.-]{0,40}$
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.scopes ~58

List this tenant's own scope catalog: name and description.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.trusted_issuer_remove ~81

Remove one of this tenant's trusted identity-assertion issuers; its assertions stop authenticating immediately.

NameTypeReqDescription
issuerstringyesThe issuer to remove.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.trusted_issuer_set ~221

Register (or update) an identity-assertion issuer for this tenant's enterprise-managed auth: identity assertions with iss equal to issuer, from client_id, verified against jwks_url, mint a token for the employee they name -- no consent screen. Up to 4 trusted issuers per tenant; a 5th is refused quota_trusted_issuers; an issuer already trusted by another tenant is refused issuer_already_registered.

NameTypeReqDescription
audiencestring–Expected assertion `aud`, when the provider signs one other than this host's own issuer URL.
client_idstringyesThe pre-registered enterprise client id allowed to use this issuer's grant.
issuerstringyesThe identity assertion's `iss` claim value to match.
jwks_urlstringyesURL this host fetches the issuer's JWKS from.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.oauth.trusted_issuers ~71

List this tenant's trusted identity-assertion issuers with their jwks_url, client_id and audience.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.progress ~184

Report (or merge in) counters and/or pct/msg on a run, by id. Each named counter (items_processed, items_total, bytes_out, custom.<k>) is monotonic on its own -- a lower value than what's already stored fails validation with nothing written. Read back via host.runs.get/wait/list's counters field.

NameTypeReqDescription
countersobject–items_processed?, items_total?, bytes_out?, custom?: {k: number} -- each key monotonic.
msgstring–A free-text progress message.
pctinteger–0-100 percent complete, free text.
run_idstringyesThe run id to report progress on.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.quickstart ~146

Return the shortest ordered sequence of calls to a working tool of `kind`, with your namespace and a filled-in example already substituted in, plus the current limits and a try_before_call table naming the one dry-run tool for each case. Read-only. Call this before host.tool_publish if you're not sure what a spec should look like. Unauthenticated callers get the signup step first.

NameTypeReqDescription
kindstringyesWhich registered kind to return a worked example for, e.g. echo, http, python.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.redeem ~123

Exchange a signup(handoff: true) handoff_token for the tenant key it was issued for. Single-use: a second redemption fails with handoff_token_redeemed; past its expiry it fails with handoff_token_expired. Unauthenticated -- the token itself is the proof.

NameTypeReqDescription
handoff_tokenstringyesThe handoff_token signup(handoff: true) returned.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.registry_publish ~69

Publish this tenant's server.json to the configured MCP registry (requires --registry-url and admin.tenant_verify_namespace first).

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.runs.cancel ~93

Stop a queued or running job: its sandbox process is killed within ~2s and the run reads cancelled. A run that already finished fails with run_not_cancellable.

NameTypeReqDescription
run_idstringyesThe run id to cancel.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.runs.get ~96

Read one run's status, progress and (once done) result by id -- the same run a host.tool_call(..., async=true) or a scheduled/triggered execution created.

NameTypeReqDescription
run_idstringyesThe run id to read.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.runs.list ~176

List this tenant's recent runs, newest first, optionally filtered by tool, status (queued|running|done|error|timeout|cancelled), trigger (call|job|schedule|event|chain) or end_user_subject (the end user, if any, the run ran as).

NameTypeReqDescription
end_user_subjectstring–Only runs that ran as this end user's subject.
limitinteger–Max runs to return; default 20.
statusstring–Only runs in this status.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
toolstring–Only runs of this tool name.
triggerstring–Only runs of this trigger kind.

No output schema declared.

No examples provided.

host.runs.part ~133

Read part n of a run's result (host.runs.get/wait inline only part 0). A run whose whole result fit inline reads back parts: 1, n: 0 with the full result. n past the last part fails with not_found.

NameTypeReqDescription
ninteger–The 0-based part index; default 0.
run_idstringyesThe run id to read a part of.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.runs.purge ~110

Delete the stored results of every done run finished at or before before_unix; each then reads done with result: null, purged: true. Frees state_bytes_max quota the results were counted against.

NameTypeReqDescription
before_unixintegeryesPurge results of runs finished at or before this unix timestamp.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.runs.wait ~167

Long-poll one run until it finalizes, until: {counter, gte} is reached, or timeout_s elapses (max 25s), returning its current status either way -- for a client with no polling loop of its own.

NameTypeReqDescription
run_idstringyesThe run id to wait on.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
timeout_sinteger–Max seconds to wait, capped at 25; default 20.
untilobject–{counter: <name>, gte: <n>} -- return as soon as that counter reaches n, even while the run is still running.

No output schema declared.

No examples provided.

host.secret_list ~56

List this tenant's secret names (never their values).

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.secret_set ~95

Store an encrypted secret value under this tenant's namespace.

NameTypeReqDescription
namestringyesSecret name, referenced from a spec as secret.<name>.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
valuestringyesThe secret value; stored AES-256-GCM encrypted, never returned.

No output schema declared.

No examples provided.

host.self_offboard ~142

Permanently close your own account: disables the tenant, cancels any active Stripe subscription (pro plan), and stops your key from authenticating anything further -- same as an admin-disabled tenant. Idempotent: an already-offboarded key gets the same tenant_disabled/tenant_key_invalid error every other host.*/ billing.* call already gets from it, not a crash. This does not scrub historical usage/signup records -- those stay for audit, same as today's admin-disabled tenants.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.share.caller_limit ~150

Cap how many successful calls a caller tenant may make per UTC day into one of this tenant's shared tools. The tool must already be shared. Exceeding the cap fails the call with quota_caller (never runs it); this tenant's own calls to the tool are unaffected.

NameTypeReqDescription
caller_tenantstringyesThe caller's namespace to cap.
calls_per_dayintegeryesMax successful calls per UTC day for this caller.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
toolstringyesLocal name of the shared tool.

No output schema declared.

No examples provided.

host.share.caller_limit_remove ~90

Remove a caller_limit set by host.share.caller_limit.

NameTypeReqDescription
caller_tenantstringyesThe caller's namespace whose limit to remove.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
toolstringyesLocal name of the shared tool.

No output schema declared.

No examples provided.

host.state.delete ~122

Delete one key from this tenant's key-value state namespace.

NameTypeReqDescription
end_userstring|null–"self" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value.
keystringyesKey to delete from this tenant's key-value state namespace.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.state.delete_rows ~160

Delete rows from a declared table matching an optional where filter (same grammar as host.state.query); omitting where deletes every row in the table.

NameTypeReqDescription
end_userstring|null–"self" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value.
tablestringyesName of the declared table to delete rows from.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
wherestring–Optional filter, same grammar as host.state.query; omit to delete every row.

No output schema declared.

No examples provided.

host.state.get ~138

Read one key from this tenant's key-value state namespace. Returns found: false (not an error) if the key was never set.

NameTypeReqDescription
end_userstring|null–"self" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value.
keystringyesKey to read from this tenant's key-value state namespace.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.state.insert ~180

Insert one row (an object) or several (an array of objects) into a declared table. Each row is validated against the table's schema first -- a type mismatch fails the whole call with state_schema_violation and writes nothing.

NameTypeReqDescription
end_userstring|null–"self" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value.
rows–yesOne row (an object) or several (an array of objects), each validated against the table's schema.
tablestringyesName of the declared table to insert into.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.state.list ~148

List keys (with their current values) in this tenant's key-value state namespace, optionally filtered by prefix.

NameTypeReqDescription
end_userstring|null–"self" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value.
limitinteger–Max keys to return; default 100.
prefixstring–Only list keys starting with this prefix; default: all keys.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.state.query ~223

Read rows from a declared table, optionally filtered (where: "field op value", ops = != < <= > >=, clauses joined by ' and '), ordered (order_by: "field" or "field desc") and capped (limit).

NameTypeReqDescription
end_userstring|null–"self" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value.
limitinteger–Max rows to return; optional.
order_bystring–Optional "field" or "field desc" to sort by.
tablestringyesName of the declared table to read from.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
wherestring–Optional filter, e.g. "age > 21"; ops are != < <= > >=, clauses joined by ' and '.

No output schema declared.

No examples provided.

host.state.set ~162

Write one key in this tenant's key-value state namespace; value may be any JSON value. Overrun of the plan's state_bytes_max quota fails with state_quota_exceeded and writes nothing.

NameTypeReqDescription
end_userstring|null–"self" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value.
keystringyesKey to write in this tenant's key-value state namespace.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
value–yesAny JSON value to store under key.

No output schema declared.

No examples provided.

Common questions

What is the mcphost MCP server?

mcphost is an MCP server listed in the public MCP registry as dev.mcphost/mcphost. Host your MCP tool over streamable HTTP in one command. This page covers its hosted endpoint (https://mcphost.dev/mcp).

Is the mcphost MCP server safe to use?

mcphost scores 88 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the mcphost MCP server expose?

mcphost exposes 136 tools: signup, host.whoami, host.redeem, host.key_rotate, host.self_offboard, and 131 more. Their descriptions and schemas cost roughly 17,493 tokens of context every time the server is loaded.

Does the mcphost MCP server require authentication?

Yes. mcphost asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the mcphost MCP server still maintained?

mcphost is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.