Security
OnlyMCP holds two kinds of things worth protecting: your content, meaning skills, agents and memory that an AI client reads as instructions, and the credentials of the servers you connect. This page says how both are protected, in plain words, and what is not claimed.
Every row belongs to one account
Every skill, agent, memory file and connection belongs to exactly one account or one team. The rule is enforced in the database itself, by row level security in Postgres, and it denies by default: a query that forgets to name the account finds nothing instead of everything. The application reaches the database through a role that cannot switch this rule off.
Credentials of connected servers
- A token you store for a connected server is encrypted at rest (AES-256-GCM) and decrypted only at the moment OnlyMCP calls that server for you.
- It is never sent to a client and never shown again. The dashboard shows its last four characters, so you can tell two apart.
- For a server that signs in through OAuth, OnlyMCP never sees your password. The tokens it receives are encrypted the same way.
Outgoing calls
OnlyMCP calls the servers you connect, so an address you enter becomes something the server fetches. That is why the address must use https, why it is checked after the name is resolved, why private and internal networks are refused, why redirects are refused instead of followed, and why the check runs again at the moment of every call. OnlyMCP does not start programs on anybody’s behalf.
Devices and sign-in
- Every connected device, token and authorized app is listed on its own and can be revoked on its own. The tokens of a blocked account stop working immediately.
- Passwords are stored as scrypt hashes, and sign-in is rate limited.
- The command line tool keeps its token in the keychain of your operating system.
What is not claimed
Your content is encrypted in transit (TLS), not end to end: OnlyMCP has to read a skill to serve it to your client, and it searches your memory for you. OnlyMCP brings no AI of its own, so it sends nothing you store to a model; your AI client reads it when it calls a tool.
- Content is not encrypted at rest by the application. Skills, agents and memory are stored in the database as they are; the application encrypts only the credentials of connected servers.
- The outgoing-call guard has a short gap. An address is checked after its name is resolved, but the connection resolves the name again, so a name that switches to a private address in between (DNS rebinding) is not caught. The window is short, and the https rule and the refusal of redirects still apply.
- The operator can reach production data. An administrator can sign in as another account, for at most an hour at a time. Changes made in the admin area, and changes to tokens, connections, teams and billing made in such a session, are recorded in an audit log under the administrator’s name; reading content is not recorded.
Reporting a vulnerability
Write to admin@frnc.cloud. There is no bug bounty programme.