ICP MCP

ICP MCP App Operator Terms

Effective date: September 2, 2026 · Version 1.1

These App Operator Terms ("Terms") are an agreement between DFINITY Stiftung, Genferstrasse 11, 8002 Zürich, Switzerland ("DFINITY Foundation", "we") and you, the operator of an application on the Internet Computer, about making that application available through the ICP MCP server (the "Service") at mcp.internetcomputer.org, together with any pre-release deployments of the same software that we operate. The Service lets an AI assistant, acting for a user who has authorized it through Internet Identity, discover applications on the Internet Computer, read the interfaces they publish, and submit queries and actions to them.

These Terms govern the relationship between us and application operators only. Use of the Service by end users is governed separately by the ICP MCP User Terms: end users are not parties to these Terms, these Terms give them no rights or obligations, and neither document makes you and any end user contractual counterparties of each other. These Terms are versioned and interpreted on their own: in them a "user" is an end user of the Service, an "assistant" is the AI assistant acting for that user under an authorization they granted through Internet Identity, a "query" is a read-only call to a canister, and an "action" or "state-changing call" is a call that can change a canister's state. How the Service handles personal data is described in the ICP MCP Privacy Policy. Before September 1, 2026, one document titled "ICP MCP Terms of Service" covered both relationships; these Terms replace its application-developer provisions.

1. The Operator

The "operator" of an application is the person or entity legally authorized to operate it and to declare its canisters: to publish at the application's origin, to decide what its canisters expose, and to take on obligations for it. That may be a company, a foundation, an individual, or the legal entity or authorized representative acting for a project. Only the operator can accept these Terms for an application, and whoever accepts them on an operator's behalf represents that they are authorized to bind that operator. If you develop an application but do not operate it, these Terms are for its operator to accept, not you.

2. Participation

Under these Terms you permit us, through the Service and on behalf of users who have authorized their AI assistants through Internet Identity, to:

Participation is free of charge in both directions: we charge you nothing for it, and we owe you nothing for it.

3. Acceptance and Registration

Publishing your application's manifest is what accepts these Terms: it is the act by which whoever is authorized to publish at that origin accepts them, as the service discoverability instructions state, and it is sufficient on its own. Publishing a valid manifest opts the application into participation and makes its declared canisters eligible for the metadata retrieval, query calls, and state-changing calls described in section 2. Nothing further is required of you. Without a valid manifest, the Service may fetch and describe the application's public website, but it will not retrieve canister metadata or submit query or state-changing calls to the application's canisters.

Registration is optional. It is not a condition of participation. It is how an operator tells us who they are, so that we can reach them with the notices these Terms provide for (sections 10, 11, and 14), and so that there is a record of who accepted and of which version, which publication alone does not show. To register, email mcp@dfinity.org with: the operator's legal name and country; the name, role, and email address of the representative accepting these Terms; the application's origin domain or domains; the canister IDs its manifest declares; the URL of the application's own privacy policy, so that we can present it to users considering the application; and the version of these Terms being accepted, as shown at the top of this page. We confirm the registration and record the operator's identity, the accepted version, the time of the registration itself, the time we first observe the manifest published at a declared origin, the declared domains and canisters, and that privacy-policy URL. Acceptance takes effect on publication, and we can record only when we first observed it, not when you published; the registration is your confirmation of who accepted, and of which version. What we do with that information is described in the ICP MCP Privacy Policy. We may offer further registration channels; a registration made through any channel we offer has the same effect.

If you have registered, keep the registration accurate: tell us when the application adds an origin domain or a declared canister, when the accepting representative changes, or when the application's privacy-policy URL changes, so that the record continues to describe the application we are exposing to users. Where the manifest format supports declaring the operator and the accepted terms version, keep those declarations consistent with your registration.

Section 10 applies to every application, registered or not: participation is not a right, and we may suspend or limit it. If the discoverability instructions and these Terms describe acceptance or registration differently, these Terms prevail for the agreement between you and us.

4. Activation by the Manifest

The manifest is the switch, and the whole of it. Your application participates while a valid manifest is published at /.well-known/ic-architecture on its origin: publishing the manifest activates participation under these Terms. Removing the manifest deactivates participation and, once the Service observes the removal, stops new canister metadata retrieval, query calls, and state-changing calls under section 2; this works whether or not you have registered. The Service may continue fetching the application's public website and manifest path over HTTPS to determine whether participation is active and to describe publicly available information. Serving the manifest is your ongoing statement that its contents are current and that participation is intended, and the representations in section 5 are repeated each time it is served.

5. Authority and Control

By accepting these Terms, and for as long as your application's manifest is published, you represent that:

6. Your Published Interface

Assistants act on what your application publishes about itself, and users rely on what assistants tell them, so accuracy is an obligation here, not a courtesy:

7. Security

You are responsible for operating your application securely: for control of its origin and of the accounts that can change what it serves, for the security and upgrade paths of its canisters, and for the integrity of its discoverability files. If your origin or a declared canister is compromised in a way that could affect users of the Service, mitigate promptly: removing the manifest is the fastest way to stop new canister metadata retrieval, query calls, and state-changing calls, from the point the Service observes the removal (section 4), and it works whether or not you have registered. It does not stop the Service fetching the application's public website or describing publicly available information, so ask us to suspend its participation at mcp@dfinity.org if it should not be presented to users at all. Vulnerabilities in the Service itself should be reported through the Internet Computer bug bounty, not exploited or disclosed publicly.

8. Personal Data

Requests that users direct at your application through the Service carry personal data: query and call arguments, per-application identities, and whatever your canisters return. For processing each party determines independently, each party acts as an independent controller. Nothing in these Terms appoints either party as the other's processor. The parties' roles ultimately depend on the processing actually performed and applicable law. You are responsible for handling the personal data that reaches your application lawfully under the data-protection law that applies to you, and for keeping an accurate privacy policy available to your application's users, at the URL you gave us if you registered one. The ICP MCP Privacy Policy describes what the Service discloses to your application; it does not govern what your application then does with it.

9. Participation Rules

You will not make available through the Service an application that: impersonates a person, an organization, or another application, or misrepresents its operator; is designed to deceive or defraud users, or to facilitate unlawful activity; or interferes with the Service, with other applications' participation, or with the mechanisms users rely on to authorize and revoke access. You will not use participation to probe the Service for vulnerabilities outside the bug bounty's rules, and not to collect data about users beyond what their individual requests carry.

The Service is distributed through AI assistant platforms and their connector directories, and their policies constrain what the Service may expose. We may publish additional technical and content requirements for participation, and may decline or limit participation that puts users, the Service, or its distribution at risk.

10. Suspension and Delisting

We may suspend or end your application's participation, in whole or in part, at any time: remove it from discovery, stop describing it, or stop invoking it. We will do so in particular on a breach of these Terms, a security or legal risk, or harm to users, to the Service, or to its distribution, and where reasonably practical we will tell the registered operator why. Participation is not a right: no application is guaranteed discovery, listing, or invocation, and the Service's tools and coverage can change as described in the User Terms.

11. Term and Termination

These Terms apply from your acceptance until terminated. You can deactivate participation at any time by removing the manifest (section 4), and terminate the agreement by notice to mcp@dfinity.org. We may terminate with reasonable notice to the registered operator, or without notice where section 10 justifies ending participation immediately. Termination stops discovery and new invocations; it does not undo actions already executed on the Internet Computer, and sections 8, 12, 13, and 15 survive it.

12. Disclaimer of Warranties

The Service is provided "as is" and "as available", without warranties of any kind, whether express or implied. We do not promise that the Service is available, that your application is discovered or invoked at any volume, or that assistants describe or use it in any particular way, and we may change, suspend, or discontinue the Service or any of its tools at any time.

13. Limitation of Liability

To the maximum extent permitted by law, DFINITY Foundation is not liable for damages arising from participation under these Terms, including indirect or consequential damages and lost profits, whether resulting from the Service's behaviour, unavailability, change, or discontinuation, from what assistants or users do with your application, or from suspension, delisting, or termination. You are responsible for your application and for what it does with the requests it receives. Nothing in these Terms excludes or limits liability that cannot be excluded under applicable law, including liability under Swiss law for damage caused by unlawful intent or gross negligence.

14. Changes to These Terms

These Terms are versioned and updated independently of the ICP MCP User Terms. When we update them, we change the version and effective date at the top of this page, and for changes that materially affect your rights or obligations we give registered operators reasonable advance notice before they take effect. If you do not accept an updated version, end participation under section 11 before it takes effect; keeping your application's manifest published after that constitutes acceptance of the updated version, and for material changes we may ask you to register your acceptance again.

15. Governing Law and Jurisdiction

These Terms are governed by Swiss substantive law, excluding its conflict of law rules. The exclusive place of jurisdiction is Zürich, Switzerland.

16. Contact

Registrations, notices, and questions about these Terms: mcp@dfinity.org. For everything else, see Support.