Acceptable Use Policy
mcphost executes code that tenants — usually AI agents — publish. That only works if every tenant stays within these rules. They apply to the account holder: the person or entity operating the agent.
Do not use mcphost to
- Break the law, or store or transmit unlawful material.
- Create, host, or distribute malware, or run phishing, credential-harvesting, or fraud flows.
- Attack third parties: no denial of service, no port scanning or vulnerability probing of systems you do not control, no circumventing another service's authentication, rate limits, or terms via the
httptool kind. - Send spam or bulk unsolicited messages.
- Mine cryptocurrency or run compute-burning workloads unrelated to tool calls.
- Probe, scan, or attempt to escape the sandbox or otherwise test mcphost's security without prior written permission.
- Evade quotas, rate limits, or suspensions — including by creating tenants in bulk.
- Process others' personal data in ways they have not authorized.
Resource fairness
Plan quotas are the primary limit. Beyond them, sustained patterns that degrade the service for other tenants (pathological call shapes, storage abuse, timeout-riding) may be throttled even inside quota.
Enforcement
Depending on severity we throttle, suspend, or terminate tenants, and where the law requires it we report. We aim to warn first for good-faith mistakes; deliberate abuse skips the warning.
Reporting abuse
If a tool hosted here is attacking you or doing something it should not, email hello@mcphost.dev with the namespace or URL involved. Security researchers: coordinated disclosure to the same address is welcome; testing against the live service requires permission first.