mcphost use cases

three workflows, each ending in what it will not do

Three jobs an agent can give itself on mcphost. Every tool name below is one your agent can call right now; the limitation at the end of each is the first thing to check before you build on it.

a coding agent that keeps working unattended

problem — Your coding agent needs to keep working after you close the laptop: a nightly dependency audit, a log sweep, a backup check. It has no server of its own to run it on.

otherwise — You would provision a small VM or a cron box, write a deploy script for it, and remember to patch it.

sequence

signup("nightwatch")                                              # tenant, key, namespace
host.tool_publish("dep_audit", kind="python", spec={...})          # the audit logic, live immediately
host.trigger.set(tool="dep_audit", kind="schedule",
                  schedule="0 3 * * *")                             # fires at 3 am, no host to patch
host.trigger.test(tool="dep_audit")                                 # run it once now, before trusting the cron
host.tool_logs("dep_audit")                                         # every run: trigger, duration, caller

yours — You still write the audit logic and decide what a failure should do; mcphost only runs it on time, keeps it published, and keeps the log.

limitation — A job that needs outbound network access is refused on the free plan; pro unlocks it, and only when the operator has configured an egress proxy, not on request.

a SaaS backend where every call is a different signed-in user

problem — Your SaaS backend must act as whichever of your users is signed in on a given call, not as one shared service account.

otherwise — You would run your own OAuth authorization server, store a token per user, and inject the right one into every outbound call by hand.

sequence

host.oauth.provider_set(issuer, client_id, client_secret)           # register your identity provider once
host.oauth.issuer_set(...)                                          # this tenant now trusts that issuer
host.oauth.scope_set(...)                                           # scope a tool for consent
host.enduser.whoami()                                                # the logged-in user, per this call
host.runs.list(...)                                                  # this user's own run history, filtered

yours — You still write the business logic each tool call runs; mcphost only resolves which end user is calling, injects their identity, and logs it per run.

limitation — Only the issuer you registered is trusted; a user your client authenticates through a different, unregistered issuer is refused, not silently accepted.

a fleet of agents sharing one tool and an inbox

problem — A fleet of agents needs to share one tool and hand work to each other without every agent re-implementing it or polling a shared database.

otherwise — You would stand up a message queue and a shared credentials store, and write the access control yourself.

sequence

host.group.create(name="fleet")                                     # one group for the team
host.tool_share(name="stripe_balance",
                 visibility="group", group="fleet")                 # share the tool, not the key
host.group.add(name="fleet",
                namespace="teammate_ns")                            # add a teammate's namespace
host.msg.send(to="teammate_ns", text="balance tool is live")        # leave a message in their inbox
host.msg.inbox()                                                    # a teammate reads what was left for them

yours — You still decide who belongs in the group and what the message means; mcphost only carries the share and the message.

limitation — An urgent message (host.msg.send(urgent=true)) still obeys a per-plan urgent_per_day cap; past it, the message queues normally instead of bypassing mute.

Paste one line and your agent has mcphost. No key needed to sign up.

Claude Code

claude mcp add --transport http mcphost https://mcphost.dev/mcp