100+ integrations are ready to connect to your AI.Connect your first MCP

Terms of Service

These Terms and Conditions govern your access to and use of PopMCP, including our website, web application, dashboards, hosted Model Context Protocol ("MCP") endpoints, provider connections, personal access tokens, hosted checkout flows, and related services we provide (collectively, the "Service").

Last updated: June 22, 2026

These Terms and Conditions govern your access to and use of PopMCP, including our website, web application, dashboards, hosted Model Context Protocol ("MCP") endpoints, provider connections, personal access tokens, hosted checkout flows, and related services we provide (collectively, the "Service").

PopMCP is a multi-tenant control plane that provisions hosted Streamable HTTP MCP servers from provider credentials that you supply and control. Each connection you create produces one stable hosted MCP URL that you can use in MCP-compatible clients such as Claude, ChatGPT, Cursor, Codex, Windsurf, and others. The Service provides transport and tooling between those clients and the third-party provider accounts you connect.

By creating an account, joining a workspace, connecting a provider, issuing a token, purchasing a subscription, or otherwise using any part of PopMCP, you agree to these Terms and Conditions. If you do not agree, do not use the Service. These Terms describe important allocations of risk and responsibility, including disclaimers of warranty, a limitation of liability, and your responsibility for all actions taken through your endpoints and tokens. Please read them carefully.

1. Acceptance of These Terms

These Terms and Conditions form a binding agreement between you and PopMCP. By accessing or using the Service, you accept these Terms for yourself and for any agency, organization, or other entity on whose behalf you act.

If you accept these Terms on behalf of an organization, you represent that you have authority to bind that organization, and references to "you" include that organization.

2. Who We Are

The Service is operated by PopMCP ("PopMCP," "we," "us," or "our"). You can reach us at support@popmcp.com, and questions about these Terms and Conditions may be sent to legal@popmcp.com. Our website is https://popmcp.com and the application is hosted at https://app.popmcp.com.

3. Definitions

The following terms have the meanings set out below wherever they appear in these Terms:

  • Service means the PopMCP website, web application, dashboards, hosted MCP server endpoints, tools, and related services we provide.
  • Agency means the top-level account (tenant) that owns one or more Organizations and their members.
  • Organization (or workspace) means a sub-account inside an Agency that represents a single connected provider environment.
  • Connection means a link you create between PopMCP and a third-party Provider using Credentials you supply.
  • Provider means a third-party service you connect (for example, your email, commerce, analytics, payments, or support tool).
  • Credentials means the API keys, OAuth tokens, or other secrets you provide so the Service can call a Provider on your behalf.
  • MCP Server or Endpoint means the hosted Streamable HTTP Model Context Protocol URL that PopMCP provisions for a Connection.
  • Access Token (or PAT) means a scoped personal access token used to authenticate requests to an Endpoint.
  • AI Client means any Model Context Protocol-compatible application (such as Claude, ChatGPT, Cursor, or Codex) that you connect to an Endpoint.
  • Full Catalog means the optional setting that exposes a Provider's complete set of mapped operations, including write and destructive actions.
  • You or Customer means the individual or entity that registers for or uses the Service.

4. Eligibility and Accounts

You may use the Service only if you can form a legally binding agreement, you are authorized to act for yourself and any organization you represent, and your use complies with applicable law and the rights of others.

Account sign-in uses Google OAuth through our authentication provider. You must provide accurate information, keep your sign-in method secure, and promptly notify us of any suspected unauthorized access. You are responsible for all activity that occurs under your account.

  • you must keep your authentication method and any personal access tokens confidential;
  • you must ensure that only authorized people can access your workspace, connections, and tokens;
  • you must promptly update account details when they change and revoke access you no longer intend to grant.

5. Agencies, Organizations, and Team Roles

The Service is organized around tenants. An Agency is the top-level tenant. An Organization is a sub-account inside an Agency that typically corresponds to a single connected provider account. Members hold roles such as owner, administrator, or member, and access is controlled by those roles.

Workspace membership may be governed by domain-based and invitation-based controls. For example, the first corporate-domain user to sign in may create and claim the Agency for that domain, and later users from the same domain may need an invitation before they can join. Invitations may carry a target email, a role, and an expiration.

Owners and administrators are responsible for managing members, invitations, roles, connections, instances, and tokens within their tenant, and for the conduct of users they invite or authorize. Actions taken by any member or invited user are treated as actions taken by your tenant.

6. The Service

PopMCP provisions a hosted MCP endpoint for each verified provider connection. Depending on your configuration, the Service may include:

  • hosted Streamable HTTP MCP servers reachable at a stable URL, scoped by personal access token;
  • a curated core of named provider tools, on-demand tool search and discovery tools, and a raw_operation escape hatch for operations outside the curated set;
  • an optional exposeFullCatalog toggle that surfaces the connected provider's full mapped operation surface, and an optional READ_ONLY access mode that filters the exposed set to read-only operations;
  • an optional account-level IP allowlist that lets a workspace owner restrict which IP addresses or ranges may reach the account's hosted MCP endpoints across all of its workspaces;
  • workspace administration, team collaboration, per-token rate limiting, usage analytics, and subscription management.

We may add, change, suspend, or discontinue features, tools, connectors, limits, and configuration options at any time. We do not guarantee that any feature, tool, or operation will always be available, uninterrupted, or error free.

7. Buyer-Owned Credentials and Your Responsibility for Them

The Service operates exclusively on credentials that you bring and control. When you create a connection, you supply your own provider API key, token, or OAuth grant for an account you already own or are authorized to use. PopMCP does not provide, resell, or sponsor the underlying provider accounts; it connects to accounts that remain entirely yours.

You are solely responsible for deciding which credentials you connect, for confirming that you are permitted to connect them, and for the scope of access those credentials carry at the provider. A credential you connect may grant broad access to the corresponding provider account, including the ability to read, create, modify, and delete data.

  • you represent that you own or are authorized to use every credential you connect and to instruct PopMCP to make provider requests with it on your behalf;
  • you are responsible for the permissions and scope each credential carries at the provider, including any write or destructive capability;
  • you must rotate, revoke, or disconnect credentials when they should no longer be used, and you remain responsible until you do so.

We describe how we protect stored credentials in our Privacy Policy and Security Overview. Those protections do not change the fact that the underlying account, its data, and every action taken with your credentials remain your responsibility.

8. MCP Endpoints, Tokens, and Third-Party Provider Actions

This section is important. The hosted MCP endpoints and tokens that PopMCP provisions can be used to perform real operations against your connected provider accounts. Depending on the exposed tools, your access mode, and whether you enable the full catalog, those operations can include actions that write, update, overwrite, or permanently DELETE data and that incur cost, consume quota, or trigger irreversible changes in the connected account.

PopMCP provides transport and tooling. It does not decide which operations to run. Operations are initiated by you, by your team, by the personal access tokens you issue and share, and by the AI clients, assistants, and autonomous agents you connect to your endpoint. AI clients may select and invoke tools automatically, including consequential or destructive tools, without a human reviewing each call.

You are responsible for actions taken through your endpoints and tokens

You are solely responsible for, and PopMCP is not liable for, any data loss, deletion, corruption, modification, unwanted change, cost, charge, quota or rate-limit consumption, account suspension, or other consequence resulting from actions performed through your MCP endpoints or tokens, whether those actions are performed by you, your team, your invited users, your AI clients or agents, or any third party who obtains access to your URL or tokens.

  • you control who receives your MCP URLs and tokens, and any holder of a valid URL and token can act against your connected provider account up to the exposed tool set;
  • you control whether to enable the full catalog and whether to use read-only mode, and you accept the increased risk of enabling write access or the full operation surface;
  • you are responsible for supervising your AI clients and agents and for the actions they take through the Service, including destructive actions taken autonomously;
  • you are responsible for complying with each provider's own terms, acceptable use rules, and API and rate limits when you use the Service against that provider;
  • you are responsible for configuring any optional security controls you choose to use, such as IP allowlisting, and for keeping allowed addresses current; these controls are provided "as is," may not prevent all unauthorized access, and should not be relied on as your only safeguard, and PopMCP is not responsible for blocked requests, loss of access, or other consequences arising from how you configure or rely on them.

We strongly recommend treating MCP URLs and tokens as secrets, scoping access narrowly, restricting access by IP address where your clients connect from stable networks, using read-only mode where write access is not required, leaving the full catalog disabled unless you need it, and maintaining your own backups of any provider data you cannot afford to lose. PopMCP is not a backup service and does not guarantee that provider actions can be undone.

9. Acceptable Use

Your use of the Service must comply with our Acceptable Use Policy, which is incorporated into these Terms. Among other things, you must not use the Service for unlawful, fraudulent, infringing, or abusive purposes, must respect the terms and limits of each provider you connect, and are responsible for the conduct of your AI agents.

We may investigate suspected violations and may suspend, restrict, or terminate access where we reasonably believe the Acceptable Use Policy has been breached.

10. Fees, Billing, and Auto-Renewal

Paid plans require a subscription. Checkout, invoicing, stored payment methods, subscription management, and renewals are handled through our payment processor, Stripe. Fees, taxes, billing intervals, and plan limits are presented at checkout and in the application.

  • subscriptions are offered on monthly or annual intervals and renew automatically for the selected interval until auto-renewal is cancelled;
  • the workspace owner or designated billing owner is responsible for plan selection, upgrades, downgrades, add-ons, taxes, cancellations, and payment disputes for the tenant;
  • we may restrict application access and hosted MCP serving when a subscription is unpaid, lapsed, suspended, disputed, refunded, or over applicable limits.

Refunds, cancellation timing, plan-change effects, and related billing rules are described in our separate Refund and Cancellation Policy.

11. Intellectual Property and Feedback

As between you and PopMCP, you retain ownership of your accounts, credentials, connected provider data, prompts, configurations, and other information you submit to or process through the Service. PopMCP retains ownership of the Service, including its software, connector implementations, tool catalogs, interfaces, design, branding, and documentation, which are protected by applicable intellectual property laws.

Except for the limited right to use the Service under these Terms, no rights are granted to you. If you provide feedback, ideas, or suggestions about the Service, we may use them without restriction or compensation to you.

12. Third-Party Services and No Provider Affiliation

The Service depends on third-party services, including the providers you connect, our authentication provider, our payment processor, hosting and infrastructure vendors, and email and analytics vendors. Your use of any third-party service is also governed by that party's own terms and policies.

PopMCP is not affiliated with, endorsed by, or sponsored by the providers you connect. Provider names are used only to identify the services with which a connection interoperates. Providers control their own APIs, permissions, availability, limits, pricing, and data, and may change, restrict, or discontinue access at any time.

  • we are not responsible for provider outages, API changes, deprecations, account suspensions, billing, or data restrictions imposed by a provider;
  • we are not responsible for the accuracy, completeness, or behavior of data returned by, or operations performed against, a connected provider;
  • your relationship with each provider, including your compliance with its terms, remains solely between you and that provider.

13. Confidentiality

Each party may receive non-public information from the other in connection with the Service. The receiving party will use such information only to perform under these Terms and will protect it with reasonable care, except where disclosure is required by law or necessary to operate, secure, or support the Service.

You are responsible for protecting your own secrets, including credentials, MCP URLs, and tokens. Treating these as confidential is a condition of safe use of the Service.

14. Disclaimers of Warranty

THE SERVICE IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS. TO THE MAXIMUM EXTENT PERMITTED BY LAW, POPMCP DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NONINFRINGEMENT, AND ANY WARRANTY THAT THE SERVICE WILL BE UNINTERRUPTED, SECURE, ERROR FREE, OR THAT ANY PROVIDER OPERATION WILL SUCCEED, BE ACCURATE, BE COMPLETE, OR BE REVERSIBLE.

WITHOUT LIMITING THE FOREGOING, POPMCP DOES NOT WARRANT AND IS NOT RESPONSIBLE FOR THE RESULTS OF ANY OPERATION PERFORMED AGAINST A CONNECTED PROVIDER ACCOUNT, INCLUDING ANY WRITE, UPDATE, OR DELETE ACTION INITIATED BY YOU, YOUR TEAM, YOUR AI CLIENTS OR AGENTS, OR ANY THIRD PARTY USING YOUR ENDPOINT OR TOKENS. POPMCP DOES NOT PROVIDE LEGAL, TAX, ACCOUNTING, OR OTHER PROFESSIONAL ADVICE.

15. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, POPMCP AND ITS AFFILIATES, OFFICERS, EMPLOYEES, CONTRACTORS, AND LICENSORS WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS OPPORTUNITY, AND WILL NOT BE LIABLE FOR ANY DATA LOSS, DELETION, MODIFICATION, COST, OR OTHER CONSEQUENCE OF ACTIONS PERFORMED THROUGH YOUR MCP ENDPOINTS OR TOKENS, EVEN IF ADVISED OF THE POSSIBILITY OF THOSE DAMAGES.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, POPMCP'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE SERVICE OR THESE TERMS WILL NOT EXCEED THE GREATER OF: (A) THE AMOUNTS YOU PAID TO POPMCP FOR THE SERVICE DURING THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM; OR (B) ONE HUNDRED U.S. DOLLARS (US $100).

These limitations apply to all claims, whether based in contract, tort, statute, or otherwise. Some jurisdictions do not allow certain exclusions or limitations, so parts of this section may not apply to you; in that case, our liability is limited to the maximum extent permitted by law.

16. Indemnification

You agree to defend, indemnify, and hold harmless PopMCP and its affiliates, officers, employees, contractors, and licensors from and against any claims, liabilities, damages, losses, and expenses, including reasonable legal fees, arising out of or related to:

  • your use of the Service and any operation performed through your MCP endpoints or tokens;
  • the credentials, connections, and provider accounts you connect, and the data within them;
  • actions taken by your team, your invited users, your AI clients or agents, or any third party using your endpoint or tokens;
  • your violation of these Terms, the Acceptable Use Policy, a provider's terms, or applicable law or third-party rights.

17. Suspension and Termination

You may stop using the Service at any time and may cancel renewal through the application. We may suspend, restrict, or terminate access, including individual connections, endpoints, or tokens, immediately where we reasonably believe that:

  • you violated these Terms or the Acceptable Use Policy;
  • your use creates legal, fraud, security, abuse, or operational risk;
  • a provider, law, or regulation requires it, or amounts remain overdue after reasonable notice where applicable.

On termination, your right to use the Service and hosted endpoints ends. Provisions that by their nature should survive will continue to apply, including those concerning ownership, payment obligations, disclaimers, limitation of liability, indemnification, and dispute resolution.

18. Changes to the Service and These Terms

We may change or retire features, connectors, tool catalogs, limits, pricing, and packaging from time to time. We may also update these Terms. If we make material changes, we may notify you through the Service, by email, or by updating the "Last updated" date above.

Continued use of the Service after updated Terms take effect means you accept the revised Terms, unless applicable law requires a different process.

19. Governing Law and Disputes

To the extent permitted by law, these Terms and any non-contractual disputes arising out of or relating to them are governed by the laws of the jurisdiction where PopMCP is established, without regard to conflict of laws rules, and except where mandatory law in your jurisdiction provides otherwise.

The parties will first attempt to resolve any dispute informally by contacting legal@popmcp.com. Where permitted by applicable law, any dispute that is not resolved informally will be resolved by binding arbitration on an individual basis, and you and PopMCP waive any right to participate in a class or representative proceeding. Where arbitration or a class waiver is not enforceable, disputes will be brought exclusively in the courts having competent jurisdiction over PopMCP, except to the extent mandatory law allows or requires otherwise.

20. Miscellaneous

These Terms, together with the policies referenced in them, are the entire agreement between you and PopMCP regarding the Service. If any provision is found unenforceable, the remaining provisions stay in effect. Our failure to enforce a provision is not a waiver.

You may not assign these Terms without our consent. We may assign them in connection with a merger, financing, acquisition, or sale of assets. There are no third-party beneficiaries except as expressly stated.

21. Contact Us

Questions about these Terms and Conditions may be sent to:

PopMCP

legal@popmcp.com