ICP MCP App Operator Terms
Effective date: September 1, 2026 · Version 1.0
These App Operator Terms ("Terms") are an agreement between DFINITY
Stiftung, Genferstrasse 11, 8002 Zürich, Switzerland ("DFINITY
Foundation", "we") and you, the operator of an application on the Internet
Computer, about making that application available through the ICP MCP server
(the "Service") at mcp.internetcomputer.org, together with any
pre-release deployments of the same software that we operate. The Service
lets an AI assistant, acting for a user who has authorized it through
Internet Identity, discover applications on the Internet Computer, read the
interfaces they publish, and submit queries and actions to them.
These Terms govern the relationship between us and application operators only. Use of the Service by end users is governed separately by the ICP MCP User Terms: end users are not parties to these Terms, these Terms give them no rights or obligations, and neither document makes you and any end user contractual counterparties of each other. Words defined in the User Terms carry the same meaning here, and how the Service handles personal data is described in the ICP MCP Privacy Policy. Before September 1, 2026, one document titled "ICP MCP Terms of Service" covered both relationships; these Terms replace its application-developer provisions.
1. The Operator
The "operator" of an application is the person or entity legally authorized to operate it and to declare its canisters: to publish at the application's origin, to decide what its canisters expose, and to take on obligations for it. That may be a company, a foundation, an individual, or the legal entity or authorized representative acting for a project. Only the operator can accept these Terms for an application, and whoever accepts them on an operator's behalf represents that they are authorized to bind that operator. If you develop an application but do not operate it, these Terms are for its operator to accept, not you.
2. Participation
Under these Terms you permit us, through the Service and on behalf of users who have authorized their AI assistants through Internet Identity, to:
- discover and read the metadata your application publishes: its manifest
at
/.well-known/ic-architecture, the Candid interface metadata of its declared canisters, and the API documentation its canisters return (get_api_doc); - index and cache that metadata, and describe your application and its API to assistants and their users, including in any listing of participating applications we publish;
- submit queries and, for users who authorized actions, state-changing calls to your declared canisters, signed with the per-application identities Internet Identity issues for those users; and
- fetch your application's published files from its origin as needed to keep the above current, and to verify the declarations described in section 5.
Participation is free of charge in both directions: we charge you nothing for it, and we owe you nothing for it.
3. Acceptance and Registration
These Terms are accepted by an authorized representative of the operator in an affirmative step, before or alongside publication of the manifest. To register, email mcp@dfinity.org with: the operator's legal name and country; the name and role of the representative accepting these Terms; the application's origin domain or domains; the canister IDs its manifest declares; and the version of these Terms being accepted, as shown at the top of this page. We confirm the registration and record the operator's identity, the accepted version, the time of acceptance, and the declared domains and canisters. We may offer further registration channels; a registration made through any channel we offer has the same effect.
Where the manifest format supports declaring the operator and the accepted terms version, keep those declarations consistent with your registration.
If an application's manifest is published without a completed registration, we treat the publication itself, as the service discoverability instructions state, as acceptance of these Terms by conduct by whoever is authorized to publish at that origin. Acceptance by conduct proves less about who accepted, so we may limit an unregistered application's participation, or make registration a condition of it. If the discoverability instructions and these Terms describe acceptance differently, these Terms prevail for the agreement between you and us.
4. Activation by the Manifest
Registration alone changes nothing technically. Your application
participates while its manifest is published at
/.well-known/ic-architecture on its origin: publishing the
manifest activates participation under these Terms, and removing it
deactivates participation. Serving the manifest is your ongoing statement
that its contents are current and that participation is intended, and the
representations in section 5 are repeated each time it is served.
5. Authority and Control
By accepting these Terms, and for as long as your application's manifest is published, you represent that:
- you are the application's operator as described in section 1, and you control the origin where the manifest is published;
- every canister the manifest declares is operated by you or under your authority, and you are entitled to grant the permissions in section 2 for it; and
- the declarations in your discoverability files, including any derivation origin, remain accurate as the application changes.
6. Your Published Interface
Assistants act on what your application publishes about itself, and users rely on what assistants tell them, so accuracy is an obligation here, not a courtesy:
- The manifest, the interface metadata, and the API documentation must accurately identify the application, must accurately describe what its methods do, and must be kept in sync with the application as it changes. Where they identify the operator, that identification must match your registration (section 3), which remains the authoritative record of who operates the application.
- Descriptions must not present a state-changing operation as read-only or harmless, conceal a fee or transfer a method performs, or otherwise mislead about a method's effect.
- Published metadata and documentation describe your API to an assistant; they must not attempt to manipulate the assistant beyond correct use of that API, for example by instructing it to ignore its user, change its safety behaviour, exfiltrate data, or avoid or disparage other applications.
7. Security
You are responsible for operating your application securely: for control of its origin and of the accounts that can change what it serves, for the security and upgrade paths of its canisters, and for the integrity of its discoverability files. If your origin or a declared canister is compromised in a way that could affect users of the Service, mitigate promptly: removing the manifest is the fastest way to stop new invocations, and we can also suspend your application's participation on request at mcp@dfinity.org. Vulnerabilities in the Service itself should be reported through the Internet Computer bug bounty, not exploited or disclosed publicly.
8. Personal Data
Requests that users direct at your application through the Service carry personal data: query and call arguments, per-application identities, and whatever your canisters return. For personal data that reaches your application, you are an independent controller, not our processor: you decide what your application records and does with it, we do not process it on your instructions, and you do not process it on ours. You are responsible for handling that data lawfully under the data-protection law that applies to you, and for keeping an accurate privacy policy available to your application's users. The ICP MCP Privacy Policy describes what the Service discloses to your application; it does not govern what your application then does with it.
9. Participation Rules
You will not make available through the Service an application that: impersonates a person, an organization, or another application, or misrepresents its operator; is designed to deceive or defraud users, or to facilitate unlawful activity; or interferes with the Service, with other applications' participation, or with the mechanisms users rely on to authorize and revoke access. You will not use participation to probe the Service for vulnerabilities outside the bug bounty's rules, and not to collect data about users beyond what their individual requests carry.
The Service is distributed through AI assistant platforms and their connector directories, and their policies constrain what the Service may expose. We may publish additional technical and content requirements for participation, and may decline or limit participation that puts users, the Service, or its distribution at risk.
10. Suspension and Delisting
We may suspend or end your application's participation, in whole or in part, at any time: remove it from discovery, stop describing it, or stop invoking it. We will do so in particular on a breach of these Terms, a security or legal risk, or harm to users, to the Service, or to its distribution, and where reasonably practical we will tell the registered operator why. Participation is not a right: no application is guaranteed discovery, listing, or invocation, and the Service's tools and coverage can change as described in the User Terms.
11. Term and Termination
These Terms apply from your acceptance until terminated. You can deactivate participation at any time by removing the manifest (section 4), and terminate the agreement by notice to mcp@dfinity.org. We may terminate with reasonable notice to the registered operator, or without notice where section 10 justifies ending participation immediately. Termination stops discovery and new invocations; it does not undo actions already executed on the Internet Computer, and sections 8, 12, 13, and 15 survive it.
12. Disclaimer of Warranties
The Service is provided "as is" and "as available", without warranties of any kind, whether express or implied. We do not promise that the Service is available, that your application is discovered or invoked at any volume, or that assistants describe or use it in any particular way, and we may change, suspend, or discontinue the Service or any of its tools at any time.
13. Limitation of Liability
To the maximum extent permitted by law, DFINITY Foundation is not liable for damages arising from participation under these Terms, including indirect or consequential damages and lost profits, whether resulting from the Service's behaviour, unavailability, change, or discontinuation, from what assistants or users do with your application, or from suspension, delisting, or termination. You are responsible for your application and for what it does with the requests it receives. Nothing in these Terms excludes or limits liability that cannot be excluded under applicable law, including liability under Swiss law for damage caused by unlawful intent or gross negligence.
14. Changes to These Terms
These Terms are versioned and updated independently of the ICP MCP User Terms. When we update them, we change the version and effective date at the top of this page, and for changes that materially affect your rights or obligations we give registered operators reasonable advance notice before they take effect. If you do not accept an updated version, end participation under section 11 before it takes effect; keeping your application's manifest published after that constitutes acceptance of the updated version, and for material changes we may ask you to register your acceptance again.
15. Governing Law and Jurisdiction
These Terms are governed by Swiss substantive law, excluding its conflict of law rules. The exclusive place of jurisdiction is Zürich, Switzerland.
16. Contact
Registrations, notices, and questions about these Terms: mcp@dfinity.org. For everything else, see Support.