Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

mcphost

REMOTE · MCPHOST.DEV · SCANNED SEP 29

Host your MCP tool over streamable HTTP in one command.

Available components

+18 this week 88 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security92
Transport & Reachability100
Schema Quality & AI Usability75
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 17958 tokens (~132/item across 136 items; 136 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management77
  • Stability observed for 23 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 97% of tool parameters carry a description.Partial
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 0 of 23 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "host.tool_publish" implies "publish" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
  • An AI judge read all 137 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the mcphost MCP server?

mcphost is a hosted endpoint at https://mcphost.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcphost.dev

# add to Claude Code
claude mcp add --transport http dev-mcphost-mcphost 'https://mcphost.dev/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "dev-mcphost-mcphost": {
      "url": "https://mcphost.dev/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "dev-mcphost-mcphost": {
      "type": "http",
      "url": "https://mcphost.dev/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.dev-mcphost-mcphost]
url = "https://mcphost.dev/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "dev-mcphost-mcphost": {
      "type": "remote",
      "url": "https://mcphost.dev/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add dev-mcphost-mcphost --url 'https://mcphost.dev/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  dev-mcphost-mcphost:
    url: "https://mcphost.dev/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "dev-mcphost-mcphost": {
      "Transport": "http",
      "Url": "https://mcphost.dev/mcp"
    }
  }
}
# add to Vellum
assistant mcp add dev-mcphost-mcphost -t streamable-http -u 'https://mcphost.dev/mcp'
// mcp.json
{
  "mcpServers": {
    "dev-mcphost-mcphost": {
      "type": "http",
      "url": "https://mcphost.dev/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 29 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.

  • 28 Sept 26 +4
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 0
    • Tool “host.docs.status” rewrote its description, which is the text the model reads security
    • Tool “host.runs.list” rewrote its description, which is the text the model reads security
    • Tool “host.runs.wait” rewrote its description, which is the text the model reads security
    • Tool “host.usage” rewrote its description, which is the text the model reads security
    • Schema quality: 12812 → 15524 ▼ functional
    • New tool “host.docs.index_config” functional
    • New tool “host.docs.reindex” functional
    • New tool “host.docs.search” functional
    • New tool “host.enduser.assertion_secret_rotate” functional
    • New tool “host.enduser.audit” functional
    • New tool “host.enduser.export” functional
    • New tool “host.enduser.get” functional
    • New tool “host.enduser.list” functional
    • New tool “host.enduser.purge” functional
    • New tool “host.enduser.revoke” functional
    • New tool “host.enduser.unrevoke” functional
    • New tool “host.enduser.whoami” functional
    • New tool “host.progress” functional
    • New tool “host.runs.part” functional
    • New tool “host.share.caller_limit” functional
    • New tool “host.share.caller_limit_remove” functional
    • “host.runs.list” added an optional parameter “end_user_subject” cosmetic
    • “host.runs.wait” added an optional parameter “until” cosmetic
    • “host.state.delete” added an optional parameter “end_user” cosmetic
    • “host.state.delete_rows” added an optional parameter “end_user” cosmetic
    • “host.state.get” added an optional parameter “end_user” cosmetic
    • “host.state.insert” added an optional parameter “end_user” cosmetic
    • “host.state.list” added an optional parameter “end_user” cosmetic
    • “host.state.query” added an optional parameter “end_user” cosmetic
    • “host.state.set” added an optional parameter “end_user” cosmetic
    • “host.usage” added an optional parameter “by” cosmetic
    • “host.usage” added an optional parameter “cursor” cosmetic
    • “host.usage” added an optional parameter “limit” cosmetic
    • “host.usage” added an optional parameter “tool” cosmetic
    • “host.usage” reworded the description of “window” cosmetic
  • 26 Sept 26 +11
    • Authorization: unverified → fail ▼ security
    • Schema quality: 11217 → 12812 ▼ functional
    • New tool “host.docs.delete” functional
    • New tool “host.docs.get” functional
    • New tool “host.docs.list” functional
    • New tool “host.docs.purge” functional
    • New tool “host.docs.put” functional
    • New tool “host.docs.status” functional
    • New tool “host.oauth.issuer_remove” functional
    • New tool “host.oauth.issuer_set” functional
    • New tool “host.oauth.issuers” functional
    • New tool “host.table.describe” functional
    • New tool “host.table.model_set” functional
    • New tool “host.table.models” functional
  • 25 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 0
    • Tool “host.channel.open” rewrote its description, which is the text the model reads security
    • Tool “host.channel.post” rewrote its description, which is the text the model reads security
    • Tool “host.tool_call” rewrote its description, which is the text the model reads security
    • Tool “host.trigger.list” rewrote its description, which is the text the model reads security
    • Tool “host.trigger.replay” rewrote its description, which is the text the model reads security
    • Tool “host.trigger.set” rewrote its description, which is the text the model reads security
    • Tool “host.trigger.test” rewrote its description, which is the text the model reads security
    • Schema quality: 9975 → 11217 ▼ functional
    • New tool “host.channel.close” functional
    • New tool “host.channel.freeze” functional
    • New tool “host.channel.read” functional
    • New tool “host.channel.unfreeze” functional
    • New tool “host.tool_diff” functional
    • New tool “host.tool_history” functional
    • New tool “host.tool_rollback” functional
    • “host.channel.open” added an optional parameter “group” cosmetic
    • “host.tool_call” added an optional parameter “version” cosmetic
    • “host.trigger.replay” added an optional parameter “id” cosmetic
    • “host.trigger.replay” added an optional parameter “row_id” cosmetic
    • “host.trigger.set” added an optional parameter “channel_id” cosmetic
    • “host.trigger.set” added an optional parameter “name” cosmetic
    • “host.trigger.set” reworded the description of “args” cosmetic
    • “host.trigger.set” reworded the description of “kind” cosmetic
    • “host.trigger.set” reworded the description of “verify” cosmetic
    • “host.trigger.test” reworded the description of “body” cosmetic
    • “host.trigger.test” reworded the description of “id” cosmetic
    • “host.channel.open” made “name” optional cosmetic
    • “host.trigger.replay” made “run_id” optional cosmetic
  • 23 Sept 26 +1
    • Tool “host.tool_publish” rewrote its description, which is the text the model reads security
    • Tool “host.tool_run” rewrote its description, which is the text the model reads security
    • New tool “host.changelog” functional
    • New tool “host.channel.open” functional
    • New tool “host.channel.post” functional
    • New tool “host.export” functional
  • 20 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 29 Sept 2026 · Probed https://mcphost.dev/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=mcphost.dev CN=YE2,O=Let's Encrypt,C=US 6 Sept 2026 5 Dec 2026 ECDSA 256 ECDSA-SHA384 6d90eafb56dfa48bc01e1e08da1962e263e
SANs: mcphost.dev
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcphost.dev. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
dev. present 60074 8 Verified
mcphost.dev. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer resource_metadata="https://mcphost.dev/.well-known/oauth-protected-resource", scope="mcp"

Bearer resource_metadata="https://mcphost.dev/.well-known/oauth-protected-resource", scope="mcp"

Protected resource metadata

Document https://mcphost.dev/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://mcphost.dev
Authorisation server https://mcphost.dev

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcphost.dev/mcp Verified 200
http (plaintext) http://mcphost.dev/mcp HTTPS enforced 308 https://mcphost.dev/mcp
MCP tools · 136 exposed · ~17,493 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
host.state.table_create ~193

Declare (or replace the schema of) a table in this tenant's state store. schema is {"column": "text"|"integer"|"real"|"boolean"|"json"}; primary_key, if given, must name one of schema's columns -- an insert whose row matches an existing row's primary_key value replaces it.

NameTypeReqDescription
namestringyesTable name to declare, or replace the schema of.
primary_keystring–Column name (must be in schema) whose matching value replaces an existing row on insert; optional.
schemaobjectyesColumn name to type map, each type one of text|integer|real|boolean|json, e.g. {"id": "integer"}.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.state.table_drop ~76

Drop a declared table and every row it holds.

NameTypeReqDescription
namestringyesName of the declared table to drop, with every row it holds.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.table.append ~133

Append one row (an object) or several (an array of objects) to a declared table. Each row is validated against the table's schema first -- a type mismatch fails the whole call with table_schema_violation and writes nothing.

NameTypeReqDescription
rows–yesOne row (an object) or several (an array of objects), each validated against the table's schema.
tablestringyesName of the declared table to append to.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.table.create ~209

Declare a table in this tenant's SQL table store -- a different store from host.state.*'s key-value namespace and its own tables: use host.state.* for a handful of small values, host.table.* when you want real SQL (joins, aggregates, read-only queries) over rows. columns is {"column": "text"|"integer"|"real"| "timestamp"|"boolean"|"json"}; primary_key, if given, must name one of columns's own entries.

NameTypeReqDescription
columnsobjectyesColumn name to type map, each type one of text|integer|real|timestamp|boolean|json, e.g. {"id": "integer"}.
namestringyesTable name to declare.
primary_keystring–Column name (must be in columns); optional.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.table.describe ~151

Return the generated semantic model for a declared table: per column its inferred type, null share, distinct count, min/max or top values, and role (key|category|measure|date|id|text); per table its row count, candidate primary key, detected foreign keys, and suggested measures/dimensions. Refreshes after append/create within 30s; a call right after a write returns the previous model with stale: true rather than blocking.

NameTypeReqDescription
tablestringyesName of the declared table to describe.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.table.drop ~75

Drop a declared table and every row it holds.

NameTypeReqDescription
namestringyesName of the declared table to drop, with every row it holds.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.table.list ~69

List this tenant's declared tables, each with its current row count, plus the tenant's whole table-store byte usage.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.table.model_set ~161

Annotate a declared table or one of its columns -- the next describe merges this back in (an annotation's role wins over the inferred one; unit/description are added; hidden marks a column to omit from a summary). key must be one of role, unit, description, hidden.

NameTypeReqDescription
columnstring–Column name to annotate; omit for a table-level annotation.
keystringyesOne of role, unit, description, hidden.
tablestringyesName of the declared table to annotate.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
value–yesThe annotation's value.

No output schema declared.

No examples provided.

host.table.models ~74

List every declared table that has a computed semantic model, each with its version, staleness, row count and when it was last computed.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.table.query ~134

Run a single read-only SQL SELECT (CTEs allowed) against this tenant's own tables. Structurally rejected (not by string matching): anything but exactly one SELECT statement, a result over 1,000 rows, or a query running past 5 seconds -- each refusal names the rule or bound it hit.

NameTypeReqDescription
sqlstringyesA single read-only SELECT statement (CTEs allowed) over this tenant's own declared tables.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.table.schema ~87

Return one table's columns, types, row count and byte count, without running a query -- how an agent discovers its own table shape.

NameTypeReqDescription
tablestringyesName of the declared table to describe.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.tool_call ~277

Invoke a tool this tenant has already published, by its local name -- the same real, metered call as calling it directly by its namespaced name (<namespace>.<name>), for a session that has no way to see its own namespaced tool name yet. Unlike host.tool_test, this counts toward host.usage and appears in host.tool_logs. Pass async: true for a tool that needs more than the call deadline: returns {run_id, status: "queued"} immediately instead of running inline -- see host.runs.get/wait. Pass version to pin the call to one of host.tool_history's versions instead of whichever is current.

NameTypeReqDescription
argsobjectyesArguments to pass, validated against the tool's own args_schema.
asyncboolean–Run as a job instead of inline: returns {run_id, status} within ~50ms under the plan's job_max_s deadline; default false.
namestringyesLocal name of the tool to invoke.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
versioninteger–Pin the call to this version instead of whichever is current; see host.tool_history. An unknown version is an argument error.

No output schema declared.

No examples provided.

host.tool_diff ~95

Return a unified diff between two published versions of one of this tenant's tools.

NameTypeReqDescription
fromintegeryesThe earlier version number.
namestringyesLocal name of the tool.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
tointegeryesThe later version number.

No output schema declared.

No examples provided.

host.tool_history ~89

List every published version of one of this tenant's tools, newest first, each with its creation time, source_sha256, and whether it's the current one.

NameTypeReqDescription
namestringyesLocal name of the tool.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.tool_list ~52

List this tenant's published tools.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.tool_logs ~95

Return the most recent log lines for one of this tenant's tools.

NameTypeReqDescription
limitinteger–Max lines to return, most recent first; default 20.
namestringyesLocal name of the tool whose log lines to return.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.tool_publish ~272

Publish a tool of a registered kind (chain, echo, http, python, wasm) under this tenant's namespace. Call host.quickstart(kind) first for a filled-in example spec and the full publish-to-call sequence. Name must match ^[a-z][a-z0-9_]{1,40}$; a rejection names the failing field and a corrected example. Try host.tool_test before a real call.

NameTypeReqDescription
kindstringyesWhich registered kind to publish under, e.g. echo, http, python.
namestringyesLocal name for the new tool; must match ^[a-z][a-z0-9_]{1,40}$.
scopesarray–OAuth scopes a token must carry (directly, or via mcp) to reach this tool: catalogued names from host.oauth.scopes, or the built-ins read/write. At most 8. Omit (or [] ) to require only mcp -- unaffe…
specobjectyesThe kind-specific spec object; see host.quickstart(kind) for a filled-in example.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.tool_remove ~68

Remove a published tool by its local name.

NameTypeReqDescription
namestringyesLocal name of the tool to remove.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.tool_rollback ~122

Make an earlier published version of one of this tenant's tools current again -- the next host.tool_call (or namespaced call) runs that version's source. See host.tool_history for the valid version numbers.

NameTypeReqDescription
namestringyesLocal name of the tool to roll back.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
versionintegeryesThe version number (from host.tool_history) to make current.

No output schema declared.

No examples provided.

host.tool_run ~106

Debug-run a published python tool: result.payload plus duration_ms and exit_code; for the other cases see host.quickstart.

NameTypeReqDescription
argsobjectyesArguments to pass, same shape as a real call.
namestringyesLocal name of the already-published python tool to debug-run.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.tool_share ~212

Share one of this tenant's published tools with everyone (visibility: "public") or with a named group this tenant owns (visibility: "group", group: <name>). The tool keeps running in this tenant's own sandbox with this tenant's own secrets; a caller reaches it as <this tenant's namespace>.<name>.

NameTypeReqDescription
descriptionstring–Catalog-facing blurb; shown by host.catalog.search/get.
expose_specboolean–Default false. When true, any tenant this tool is shared with may call host.tool_spec_shared to read its (redacted) spec.
groupstring–Required when visibility is "group"; must already exist (host.group.create).
namestringyesLocal name of the tool to share.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
visibilitystringyes"public" or "group".

No output schema declared.

No examples provided.

host.tool_spec_shared ~114

Read a shared tool's kind and redacted spec -- only works when the owner shared it with expose_spec: true. The spec never carries env values or secret references (see host.tool_share's expose_spec).

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
toolstringyes"<owner_namespace>.<name>", the same qualified name host.tool_call uses for a shared tool.

No output schema declared.

No examples provided.

host.tool_test ~104

Dry-run an already-published tool by name, no calls row written; for the other cases see host.quickstart.

NameTypeReqDescription
argsobjectyesArguments to pass, same shape as a real call.
namestringyesLocal name of the already-published tool to dry-run.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.tool_unshare ~69

Take a shared tool back to private.

NameTypeReqDescription
namestringyesLocal name of the tool to unshare.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.trigger.fire ~86

Run a schedule once right now, for testing -- recorded as trigger: "schedule" with manual: true, independent of next_unix or pause state.

NameTypeReqDescription
idstringyesThe trigger id.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.trigger.get ~73

Read one trigger's current schedule, next_unix, last_run_id and last_status.

NameTypeReqDescription
idstringyesThe trigger id.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.trigger.list ~105

List this tenant's triggers (optionally filtered by tool), each with next_unix, last_run_id and last_status (schedule), url/verify/unverified (event), or url/name/verify with no secret (webhook).

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
toolstring–Only triggers on this tool name.

No output schema declared.

No examples provided.

host.trigger.pause ~69

Stop a trigger from firing until resumed; still counts toward schedules_max.

NameTypeReqDescription
idstringyesThe trigger id.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.trigger.remove ~70

Delete a trigger outright (frees its schedules_max slot, unlike pause).

NameTypeReqDescription
idstringyesThe trigger id.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.trigger.replay ~212

Re-run a past event- or message-triggered run's exact stored event/envelope (no re-verification -- the original delivery already passed it). The new run's trigger_ref names the original run id. For a webhook trigger, pass id (the trigger) and row_id (an inbox_<name> row id, e.g. from POST /hook/...'s own response or host.state.query) instead of run_id -- a paused delivery has no run to replay from.

NameTypeReqDescription
idstring–kind="webhook" only: the trigger id (paired with row_id).
row_idinteger–kind="webhook" only: the inbox_<name> row id to replay (paired with id).
run_idstring–The event- or message-triggered run id to replay.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.trigger.resume ~83

Re-enable a paused trigger; if its scheduled time already passed, the next tick fires it once (a missed firing is never replayed).

NameTypeReqDescription
idstringyesThe trigger id.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.trigger.set ~675

Run a published tool on a cron schedule (5-field: minute hour day-of-month month day-of-week, UTC), give it a public webhook URL (kind="event"): a signed POST to that URL runs the tool with the event as its argument, fire it whenever this tenant receives a message (kind="message"): the tool runs with the message envelope as its argument, or give it an inbound-inbox URL (kind="webhook"): a verified POST lands as a row in state table inbox_<name> and fires the tool with that row as its argument -- the response carries {url, secret} once (host.trigger.get afterwards never returns the secret again). Each firing/delivery is a run visible in host.runs.list(trigger="schedule"|"event"|"message"|"webhook"). Refuses schedules_max (trigger_quota_exceeded, shared by schedule and webhook triggers), event_triggers_max (shared by event and message triggers) or a too-short schedule interval (trigger_interval_too_short); an invalid expression or verify config fails trigger_invalid naming the field.

NameTypeReqDescription
argsobject–Arguments passed to the tool on each firing/delivery (kind="schedule"/"event" only -- a message trigger's whole argument is the message envelope and a webhook trigger's whole argument is the stored i…
channel_idstring–kind="message": scope this trigger to one group channel's posts (host.channel.open's channel_id) instead of ordinary host.msg.send/reply deliveries.
dedupe_headerstring–kind="event": a header (e.g. X-GitHub-Delivery) whose repeated value within 24h answers 202 with the original run id instead of running again.
fromstring–kind="message": only fire for messages from this address (@handle or t_... namespace); omit to fire for any sender.
kindstring–"schedule" (default), "event", "message" or "webhook".
namestring–kind="webhook": letters/digits/underscore -- becomes the inbox_<name> state table each accepted delivery is stored in.
schedulestring–kind="schedule": 5-field cron expression (minute hour day-of-month month day-of-week), UTC. Supports *, lists, ranges and steps.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
toolstringyesThe published tool this trigger runs.
tzstring–kind="schedule" P1: only "UTC" (or omitted) works today.
verify––kind="event": {scheme: "hmac-sha256"|"hmac-sha1"|"token"|"none", header, secret (a host.secret_set name), prefix?, timestamp_header?, tolerance_s?, allow_unverified? (required true for scheme "none")…

No output schema declared.

No examples provided.

host.trigger.test ~294

Dry-run an event trigger's verify config against a payload you supply, without exposing its real URL -- verifies the signature exactly as POST /hooks/... would, then runs the tool with the event as its argument. On a message trigger, runs the tool with a synthetic envelope (test: true, no messages row created). On a webhook trigger, builds and self-signs a synthetic body exactly like a real sender would, then stores and fires it through the same path POST /hook/... uses (one inbox row, one run). The run is marked test: true. A wrong signature fails signature_invalid, naming the header it checked.

NameTypeReqDescription
body––kind="event"/"webhook": the payload to verify and run with -- any JSON value. kind="message": the synthetic envelope's body text.
data––kind="message": the synthetic envelope's data payload.
fromstring–kind="message": the synthetic envelope's from address; default "@test".
headersobject–kind="event": header name -> string value, e.g. {"X-Hub-Signature-256": "sha256=..."}.
idstringyesThe event, message or webhook trigger id.
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

host.usage ~287

Calls, errors and duration percentiles for this tenant over a window. Pass `by` ("tool", "caller", or "end_user") for a breakdown instead of the plain per-tenant summary: "caller" (only valid for a tool this tenant has shared) shows which tenant called in and how much; "end_user" shows which identified end user called, with the caller tenant folded into the key when the call crossed tenants. Breakdown rows cap at 1000 per page; pass the returned `cursor` back to page further.

NameTypeReqDescription
bystring–"tool", "caller", or "end_user" -- omit for the plain per-tenant summary.
cursorstring–Resume a breakdown after this page's last key.
limitinteger–Max breakdown rows per page (1-1000, default 1000).
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.
toolstring–Scope the breakdown to one local tool name. Required when by is "caller".
windowstring–Time window to summarize, e.g. "24h"/"1d"/"7d"/"30d"; default 24h ("1d" when `by` is given).

No output schema declared.

No examples provided.

host.whoami ~67

Return the calling tenant's identity, including key_age_s and key_rotated_at for auditing credential hygiene.

NameTypeReqDescription
tenant_keystring–The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins.

No output schema declared.

No examples provided.

signup ~139

Create a tenant and receive a bearer key and namespace. Unauthenticated. Recommended: pass handoff: true to receive a short-lived, single-use handoff_token instead of the raw key -- redeem it once with host.redeem to get the key, so a transcript of this call and the redeem call, if it leaks, carries a dead credential. The raw-key path (handoff omitted) stays fully supported.

NameTypeReqDescription
handoffboolean–Recommended: true to receive a handoff_token (redeem via host.redeem) instead of the raw key. Default false (raw key, unchanged).
namestringyesdisplay name

No output schema declared.

No examples provided.

Common questions

What is the mcphost MCP server?

mcphost is an MCP server listed in the public MCP registry as dev.mcphost/mcphost. Host your MCP tool over streamable HTTP in one command. This page covers its hosted endpoint (https://mcphost.dev/mcp).

Is the mcphost MCP server safe to use?

mcphost scores 88 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the mcphost MCP server expose?

mcphost exposes 136 tools: signup, host.whoami, host.redeem, host.key_rotate, host.self_offboard, and 131 more. Their descriptions and schemas cost roughly 17,493 tokens of context every time the server is loaded.

Does the mcphost MCP server require authentication?

Yes. mcphost asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the mcphost MCP server still maintained?

mcphost is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.