mcphost
REMOTE · MCPHOST.DEV · SCANNED SEP 29
Host your MCP tool over streamable HTTP in one command.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security92
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability75
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 17958 tokens (~132/item across 136 items; 136 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management77
- Stability observed for 23 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 97% of tool parameters carry a description.Partial
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 23 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "host.tool_publish" implies "publish" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 137 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the mcphost MCP server?
mcphost is a hosted endpoint at https://mcphost.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcphost.dev
claude mcp add --transport http dev-mcphost-mcphost 'https://mcphost.dev/mcp'
{
"mcpServers": {
"dev-mcphost-mcphost": {
"url": "https://mcphost.dev/mcp"
}
}
} {
"servers": {
"dev-mcphost-mcphost": {
"type": "http",
"url": "https://mcphost.dev/mcp"
}
}
} [mcp_servers.dev-mcphost-mcphost] url = "https://mcphost.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"dev-mcphost-mcphost": {
"type": "remote",
"url": "https://mcphost.dev/mcp",
"enabled": true
}
}
} openclaw mcp add dev-mcphost-mcphost --url 'https://mcphost.dev/mcp' --transport streamable-http
mcp_servers:
dev-mcphost-mcphost:
url: "https://mcphost.dev/mcp" {
"McpServers": {
"dev-mcphost-mcphost": {
"Transport": "http",
"Url": "https://mcphost.dev/mcp"
}
}
} assistant mcp add dev-mcphost-mcphost -t streamable-http -u 'https://mcphost.dev/mcp'
{
"mcpServers": {
"dev-mcphost-mcphost": {
"type": "http",
"url": "https://mcphost.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Sept 26 +4
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 0
- Tool “host.docs.status” rewrote its description, which is the text the model reads security
- Tool “host.runs.list” rewrote its description, which is the text the model reads security
- Tool “host.runs.wait” rewrote its description, which is the text the model reads security
- Tool “host.usage” rewrote its description, which is the text the model reads security
- Schema quality: 12812 → 15524 ▼ functional
- New tool “host.docs.index_config” functional
- New tool “host.docs.reindex” functional
- New tool “host.docs.search” functional
- New tool “host.enduser.assertion_secret_rotate” functional
- New tool “host.enduser.audit” functional
- New tool “host.enduser.export” functional
- New tool “host.enduser.get” functional
- New tool “host.enduser.list” functional
- New tool “host.enduser.purge” functional
- New tool “host.enduser.revoke” functional
- New tool “host.enduser.unrevoke” functional
- New tool “host.enduser.whoami” functional
- New tool “host.progress” functional
- New tool “host.runs.part” functional
- New tool “host.share.caller_limit” functional
- New tool “host.share.caller_limit_remove” functional
- “host.runs.list” added an optional parameter “end_user_subject” cosmetic
- “host.runs.wait” added an optional parameter “until” cosmetic
- “host.state.delete” added an optional parameter “end_user” cosmetic
- “host.state.delete_rows” added an optional parameter “end_user” cosmetic
- “host.state.get” added an optional parameter “end_user” cosmetic
- “host.state.insert” added an optional parameter “end_user” cosmetic
- “host.state.list” added an optional parameter “end_user” cosmetic
- “host.state.query” added an optional parameter “end_user” cosmetic
- “host.state.set” added an optional parameter “end_user” cosmetic
- “host.usage” added an optional parameter “by” cosmetic
- “host.usage” added an optional parameter “cursor” cosmetic
- “host.usage” added an optional parameter “limit” cosmetic
- “host.usage” added an optional parameter “tool” cosmetic
- “host.usage” reworded the description of “window” cosmetic
- 26 Sept 26 +11
- Authorization: unverified → fail ▼ security
- Schema quality: 11217 → 12812 ▼ functional
- New tool “host.docs.delete” functional
- New tool “host.docs.get” functional
- New tool “host.docs.list” functional
- New tool “host.docs.purge” functional
- New tool “host.docs.put” functional
- New tool “host.docs.status” functional
- New tool “host.oauth.issuer_remove” functional
- New tool “host.oauth.issuer_set” functional
- New tool “host.oauth.issuers” functional
- New tool “host.table.describe” functional
- New tool “host.table.model_set” functional
- New tool “host.table.models” functional
- 25 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 0
- Tool “host.channel.open” rewrote its description, which is the text the model reads security
- Tool “host.channel.post” rewrote its description, which is the text the model reads security
- Tool “host.tool_call” rewrote its description, which is the text the model reads security
- Tool “host.trigger.list” rewrote its description, which is the text the model reads security
- Tool “host.trigger.replay” rewrote its description, which is the text the model reads security
- Tool “host.trigger.set” rewrote its description, which is the text the model reads security
- Tool “host.trigger.test” rewrote its description, which is the text the model reads security
- Schema quality: 9975 → 11217 ▼ functional
- New tool “host.channel.close” functional
- New tool “host.channel.freeze” functional
- New tool “host.channel.read” functional
- New tool “host.channel.unfreeze” functional
- New tool “host.tool_diff” functional
- New tool “host.tool_history” functional
- New tool “host.tool_rollback” functional
- “host.channel.open” added an optional parameter “group” cosmetic
- “host.tool_call” added an optional parameter “version” cosmetic
- “host.trigger.replay” added an optional parameter “id” cosmetic
- “host.trigger.replay” added an optional parameter “row_id” cosmetic
- “host.trigger.set” added an optional parameter “channel_id” cosmetic
- “host.trigger.set” added an optional parameter “name” cosmetic
- “host.trigger.set” reworded the description of “args” cosmetic
- “host.trigger.set” reworded the description of “kind” cosmetic
- “host.trigger.set” reworded the description of “verify” cosmetic
- “host.trigger.test” reworded the description of “body” cosmetic
- “host.trigger.test” reworded the description of “id” cosmetic
- “host.channel.open” made “name” optional cosmetic
- “host.trigger.replay” made “run_id” optional cosmetic
- 23 Sept 26 +1
- Tool “host.tool_publish” rewrote its description, which is the text the model reads security
- Tool “host.tool_run” rewrote its description, which is the text the model reads security
- New tool “host.changelog” functional
- New tool “host.channel.open” functional
- New tool “host.channel.post” functional
- New tool “host.export” functional
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 29 Sept 2026 · Probed https://mcphost.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcphost.dev | CN=YE2,O=Let's Encrypt,C=US | 6 Sept 2026 | 5 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 6d90eafb56dfa48bc01e1e08da1962e263e |
| SANs: mcphost.dev | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcphost.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| mcphost.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://mcphost.dev/.well-known/oauth-protected-resource", scope="mcp"
Bearer resource_metadata="https://mcphost.dev/.well-known/oauth-protected-resource", scope="mcp" Protected resource metadata
| Document | https://mcphost.dev/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://mcphost.dev |
| Authorisation server | https://mcphost.dev |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcphost.dev/mcp | Verified | 200 | |
| http (plaintext) | http://mcphost.dev/mcp | HTTPS enforced | 308 | https://mcphost.dev/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
host.state.table_create ~193
Declare (or replace the schema of) a table in this tenant's state store. schema is {"column": "text"|"integer"|"real"|"boolean"|"json"}; primary_key, if given, must name one of schema's columns -- an insert whose row matches an existing row's primary_key value replaces it.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Table name to declare, or replace the schema of. |
| primary_key | string | – | Column name (must be in schema) whose matching value replaces an existing row on insert; optional. |
| schema | object | yes | Column name to type map, each type one of text|integer|real|boolean|json, e.g. {"id": "integer"}. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.state.table_drop ~76
Drop a declared table and every row it holds.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Name of the declared table to drop, with every row it holds. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.table.append ~133
Append one row (an object) or several (an array of objects) to a declared table. Each row is validated against the table's schema first -- a type mismatch fails the whole call with table_schema_violation and writes nothing.
| Name | Type | Req | Description |
|---|---|---|---|
| rows | – | yes | One row (an object) or several (an array of objects), each validated against the table's schema. |
| table | string | yes | Name of the declared table to append to. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.table.create ~209
Declare a table in this tenant's SQL table store -- a different store from host.state.*'s key-value namespace and its own tables: use host.state.* for a handful of small values, host.table.* when you want real SQL (joins, aggregates, read-only queries) over rows. columns is {"column": "text"|"integer"|"real"| "timestamp"|"boolean"|"json"}; primary_key, if given, must name one of columns's own entries.
| Name | Type | Req | Description |
|---|---|---|---|
| columns | object | yes | Column name to type map, each type one of text|integer|real|timestamp|boolean|json, e.g. {"id": "integer"}. |
| name | string | yes | Table name to declare. |
| primary_key | string | – | Column name (must be in columns); optional. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.table.describe ~151
Return the generated semantic model for a declared table: per column its inferred type, null share, distinct count, min/max or top values, and role (key|category|measure|date|id|text); per table its row count, candidate primary key, detected foreign keys, and suggested measures/dimensions. Refreshes after append/create within 30s; a call right after a write returns the previous model with stale: true rather than blocking.
| Name | Type | Req | Description |
|---|---|---|---|
| table | string | yes | Name of the declared table to describe. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.table.drop ~75
Drop a declared table and every row it holds.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Name of the declared table to drop, with every row it holds. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.table.list ~69
List this tenant's declared tables, each with its current row count, plus the tenant's whole table-store byte usage.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.table.model_set ~161
Annotate a declared table or one of its columns -- the next describe merges this back in (an annotation's role wins over the inferred one; unit/description are added; hidden marks a column to omit from a summary). key must be one of role, unit, description, hidden.
| Name | Type | Req | Description |
|---|---|---|---|
| column | string | – | Column name to annotate; omit for a table-level annotation. |
| key | string | yes | One of role, unit, description, hidden. |
| table | string | yes | Name of the declared table to annotate. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| value | – | yes | The annotation's value. |
No output schema declared.
No examples provided.
host.table.models ~74
List every declared table that has a computed semantic model, each with its version, staleness, row count and when it was last computed.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.table.query ~134
Run a single read-only SQL SELECT (CTEs allowed) against this tenant's own tables. Structurally rejected (not by string matching): anything but exactly one SELECT statement, a result over 1,000 rows, or a query running past 5 seconds -- each refusal names the rule or bound it hit.
| Name | Type | Req | Description |
|---|---|---|---|
| sql | string | yes | A single read-only SELECT statement (CTEs allowed) over this tenant's own declared tables. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.table.schema ~87
Return one table's columns, types, row count and byte count, without running a query -- how an agent discovers its own table shape.
| Name | Type | Req | Description |
|---|---|---|---|
| table | string | yes | Name of the declared table to describe. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.tool_call ~277
Invoke a tool this tenant has already published, by its local name -- the same real, metered call as calling it directly by its namespaced name (<namespace>.<name>), for a session that has no way to see its own namespaced tool name yet. Unlike host.tool_test, this counts toward host.usage and appears in host.tool_logs. Pass async: true for a tool that needs more than the call deadline: returns {run_id, status: "queued"} immediately instead of running inline -- see host.runs.get/wait. Pass version to pin the call to one of host.tool_history's versions instead of whichever is current.
| Name | Type | Req | Description |
|---|---|---|---|
| args | object | yes | Arguments to pass, validated against the tool's own args_schema. |
| async | boolean | – | Run as a job instead of inline: returns {run_id, status} within ~50ms under the plan's job_max_s deadline; default false. |
| name | string | yes | Local name of the tool to invoke. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| version | integer | – | Pin the call to this version instead of whichever is current; see host.tool_history. An unknown version is an argument error. |
No output schema declared.
No examples provided.
host.tool_diff ~95
Return a unified diff between two published versions of one of this tenant's tools.
| Name | Type | Req | Description |
|---|---|---|---|
| from | integer | yes | The earlier version number. |
| name | string | yes | Local name of the tool. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| to | integer | yes | The later version number. |
No output schema declared.
No examples provided.
host.tool_history ~89
List every published version of one of this tenant's tools, newest first, each with its creation time, source_sha256, and whether it's the current one.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Local name of the tool. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.tool_list ~52
List this tenant's published tools.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.tool_logs ~95
Return the most recent log lines for one of this tenant's tools.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max lines to return, most recent first; default 20. |
| name | string | yes | Local name of the tool whose log lines to return. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.tool_publish ~272
Publish a tool of a registered kind (chain, echo, http, python, wasm) under this tenant's namespace. Call host.quickstart(kind) first for a filled-in example spec and the full publish-to-call sequence. Name must match ^[a-z][a-z0-9_]{1,40}$; a rejection names the failing field and a corrected example. Try host.tool_test before a real call.
| Name | Type | Req | Description |
|---|---|---|---|
| kind | string | yes | Which registered kind to publish under, e.g. echo, http, python. |
| name | string | yes | Local name for the new tool; must match ^[a-z][a-z0-9_]{1,40}$. |
| scopes | array | – | OAuth scopes a token must carry (directly, or via mcp) to reach this tool: catalogued names from host.oauth.scopes, or the built-ins read/write. At most 8. Omit (or [] ) to require only mcp -- unaffe… |
| spec | object | yes | The kind-specific spec object; see host.quickstart(kind) for a filled-in example. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.tool_remove ~68
Remove a published tool by its local name.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Local name of the tool to remove. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.tool_rollback ~122
Make an earlier published version of one of this tenant's tools current again -- the next host.tool_call (or namespaced call) runs that version's source. See host.tool_history for the valid version numbers.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Local name of the tool to roll back. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| version | integer | yes | The version number (from host.tool_history) to make current. |
No output schema declared.
No examples provided.
host.tool_run ~106
Debug-run a published python tool: result.payload plus duration_ms and exit_code; for the other cases see host.quickstart.
| Name | Type | Req | Description |
|---|---|---|---|
| args | object | yes | Arguments to pass, same shape as a real call. |
| name | string | yes | Local name of the already-published python tool to debug-run. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.tool_share ~212
Share one of this tenant's published tools with everyone (visibility: "public") or with a named group this tenant owns (visibility: "group", group: <name>). The tool keeps running in this tenant's own sandbox with this tenant's own secrets; a caller reaches it as <this tenant's namespace>.<name>.
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | – | Catalog-facing blurb; shown by host.catalog.search/get. |
| expose_spec | boolean | – | Default false. When true, any tenant this tool is shared with may call host.tool_spec_shared to read its (redacted) spec. |
| group | string | – | Required when visibility is "group"; must already exist (host.group.create). |
| name | string | yes | Local name of the tool to share. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| visibility | string | yes | "public" or "group". |
No output schema declared.
No examples provided.
host.tool_spec_shared ~114
Read a shared tool's kind and redacted spec -- only works when the owner shared it with expose_spec: true. The spec never carries env values or secret references (see host.tool_share's expose_spec).
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| tool | string | yes | "<owner_namespace>.<name>", the same qualified name host.tool_call uses for a shared tool. |
No output schema declared.
No examples provided.
host.tool_test ~104
Dry-run an already-published tool by name, no calls row written; for the other cases see host.quickstart.
| Name | Type | Req | Description |
|---|---|---|---|
| args | object | yes | Arguments to pass, same shape as a real call. |
| name | string | yes | Local name of the already-published tool to dry-run. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.tool_unshare ~69
Take a shared tool back to private.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Local name of the tool to unshare. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.trigger.fire ~86
Run a schedule once right now, for testing -- recorded as trigger: "schedule" with manual: true, independent of next_unix or pause state.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The trigger id. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.trigger.get ~73
Read one trigger's current schedule, next_unix, last_run_id and last_status.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The trigger id. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.trigger.list ~105
List this tenant's triggers (optionally filtered by tool), each with next_unix, last_run_id and last_status (schedule), url/verify/unverified (event), or url/name/verify with no secret (webhook).
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| tool | string | – | Only triggers on this tool name. |
No output schema declared.
No examples provided.
host.trigger.pause ~69
Stop a trigger from firing until resumed; still counts toward schedules_max.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The trigger id. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.trigger.remove ~70
Delete a trigger outright (frees its schedules_max slot, unlike pause).
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The trigger id. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.trigger.replay ~212
Re-run a past event- or message-triggered run's exact stored event/envelope (no re-verification -- the original delivery already passed it). The new run's trigger_ref names the original run id. For a webhook trigger, pass id (the trigger) and row_id (an inbox_<name> row id, e.g. from POST /hook/...'s own response or host.state.query) instead of run_id -- a paused delivery has no run to replay from.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | – | kind="webhook" only: the trigger id (paired with row_id). |
| row_id | integer | – | kind="webhook" only: the inbox_<name> row id to replay (paired with id). |
| run_id | string | – | The event- or message-triggered run id to replay. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.trigger.resume ~83
Re-enable a paused trigger; if its scheduled time already passed, the next tick fires it once (a missed firing is never replayed).
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The trigger id. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.trigger.set ~675
Run a published tool on a cron schedule (5-field: minute hour day-of-month month day-of-week, UTC), give it a public webhook URL (kind="event"): a signed POST to that URL runs the tool with the event as its argument, fire it whenever this tenant receives a message (kind="message"): the tool runs with the message envelope as its argument, or give it an inbound-inbox URL (kind="webhook"): a verified POST lands as a row in state table inbox_<name> and fires the tool with that row as its argument -- the response carries {url, secret} once (host.trigger.get afterwards never returns the secret again). Each firing/delivery is a run visible in host.runs.list(trigger="schedule"|"event"|"message"|"webhook"). Refuses schedules_max (trigger_quota_exceeded, shared by schedule and webhook triggers), event_triggers_max (shared by event and message triggers) or a too-short schedule interval (trigger_interval_too_short); an invalid expression or verify config fails trigger_invalid naming the field.
| Name | Type | Req | Description |
|---|---|---|---|
| args | object | – | Arguments passed to the tool on each firing/delivery (kind="schedule"/"event" only -- a message trigger's whole argument is the message envelope and a webhook trigger's whole argument is the stored i… |
| channel_id | string | – | kind="message": scope this trigger to one group channel's posts (host.channel.open's channel_id) instead of ordinary host.msg.send/reply deliveries. |
| dedupe_header | string | – | kind="event": a header (e.g. X-GitHub-Delivery) whose repeated value within 24h answers 202 with the original run id instead of running again. |
| from | string | – | kind="message": only fire for messages from this address (@handle or t_... namespace); omit to fire for any sender. |
| kind | string | – | "schedule" (default), "event", "message" or "webhook". |
| name | string | – | kind="webhook": letters/digits/underscore -- becomes the inbox_<name> state table each accepted delivery is stored in. |
| schedule | string | – | kind="schedule": 5-field cron expression (minute hour day-of-month month day-of-week), UTC. Supports *, lists, ranges and steps. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| tool | string | yes | The published tool this trigger runs. |
| tz | string | – | kind="schedule" P1: only "UTC" (or omitted) works today. |
| verify | – | – | kind="event": {scheme: "hmac-sha256"|"hmac-sha1"|"token"|"none", header, secret (a host.secret_set name), prefix?, timestamp_header?, tolerance_s?, allow_unverified? (required true for scheme "none")… |
No output schema declared.
No examples provided.
host.trigger.test ~294
Dry-run an event trigger's verify config against a payload you supply, without exposing its real URL -- verifies the signature exactly as POST /hooks/... would, then runs the tool with the event as its argument. On a message trigger, runs the tool with a synthetic envelope (test: true, no messages row created). On a webhook trigger, builds and self-signs a synthetic body exactly like a real sender would, then stores and fires it through the same path POST /hook/... uses (one inbox row, one run). The run is marked test: true. A wrong signature fails signature_invalid, naming the header it checked.
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | – | kind="event"/"webhook": the payload to verify and run with -- any JSON value. kind="message": the synthetic envelope's body text. |
| data | – | – | kind="message": the synthetic envelope's data payload. |
| from | string | – | kind="message": the synthetic envelope's from address; default "@test". |
| headers | object | – | kind="event": header name -> string value, e.g. {"X-Hub-Signature-256": "sha256=..."}. |
| id | string | yes | The event, message or webhook trigger id. |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
host.usage ~287
Calls, errors and duration percentiles for this tenant over a window. Pass `by` ("tool", "caller", or "end_user") for a breakdown instead of the plain per-tenant summary: "caller" (only valid for a tool this tenant has shared) shows which tenant called in and how much; "end_user" shows which identified end user called, with the caller tenant folded into the key when the call crossed tenants. Breakdown rows cap at 1000 per page; pass the returned `cursor` back to page further.
| Name | Type | Req | Description |
|---|---|---|---|
| by | string | – | "tool", "caller", or "end_user" -- omit for the plain per-tenant summary. |
| cursor | string | – | Resume a breakdown after this page's last key. |
| limit | integer | – | Max breakdown rows per page (1-1000, default 1000). |
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
| tool | string | – | Scope the breakdown to one local tool name. Required when by is "caller". |
| window | string | – | Time window to summarize, e.g. "24h"/"1d"/"7d"/"30d"; default 24h ("1d" when `by` is given). |
No output schema declared.
No examples provided.
host.whoami ~67
Return the calling tenant's identity, including key_age_s and key_rotated_at for auditing credential hygiene.
| Name | Type | Req | Description |
|---|---|---|---|
| tenant_key | string | – | The key `signup` returned. Required only when this connection carries no Authorization: Bearer header -- when both are present, the header wins. |
No output schema declared.
No examples provided.
signup ~139
Create a tenant and receive a bearer key and namespace. Unauthenticated. Recommended: pass handoff: true to receive a short-lived, single-use handoff_token instead of the raw key -- redeem it once with host.redeem to get the key, so a transcript of this call and the redeem call, if it leaks, carries a dead credential. The raw-key path (handoff omitted) stays fully supported.
| Name | Type | Req | Description |
|---|---|---|---|
| handoff | boolean | – | Recommended: true to receive a handoff_token (redeem via host.redeem) instead of the raw key. Default false (raw key, unchanged). |
| name | string | yes | display name |
No output schema declared.
No examples provided.
What is the mcphost MCP server?
mcphost is an MCP server listed in the public MCP registry as dev.mcphost/mcphost. Host your MCP tool over streamable HTTP in one command. This page covers its hosted endpoint (https://mcphost.dev/mcp).
Is the mcphost MCP server safe to use?
mcphost scores 88 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the mcphost MCP server expose?
mcphost exposes 136 tools: signup, host.whoami, host.redeem, host.key_rotate, host.self_offboard, and 131 more. Their descriptions and schemas cost roughly 17,493 tokens of context every time the server is loaded.
Does the mcphost MCP server require authentication?
Yes. mcphost asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the mcphost MCP server still maintained?
mcphost is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.