Reference
Security and data
What ScopeMCP stores, what it never stores, and how the read-only guarantee is enforced.
The read-only guarantee
ScopeMCP cannot change your property, submit a sitemap, request indexing, or modify anything in your accounts. This is not a policy: the tool handlers in src/lib/mcp/handlers.ts contain no write path to any upstream API. Bing exposes SubmitUrl, SubmitFeed and RemoveSite; none of them are called anywhere in the codebase.
The OAuth scopes requested are the read-only variants, and only the scopes Google actually grants are stored — so a user who declines a scope gets a connection that works for what they allowed rather than one that fails on every call.
What is stored
- OAuth tokens, AES-256-GCM encrypted at rest with a key derived from
TOKEN_ENCRYPTION_KEYvia HKDF. Never returned to a client, never logged. - Property metadata — the site identifiers your accounts can reach, so
scopemcp_list_propertiescan answer without re-querying. - Report cache — performance reports for six hours, CrUX for twenty-four. This exists to stop repeated questions burning upstream quota.
- Monitors, alerts and snapshots — only what you asked to be watched. Snapshots are what make "is this new?" answerable.
- Competitor domains you track — the list of domains you entered. We never fetch their private data; we observe public result pages.
What is never stored
- Page content. No tool fetches or retains your HTML.
- Plaintext API keys. Only a SHA-256 hash is kept; the key is shown once at creation.
- Any request body from an agent. Tool calls are not logged with their arguments.
Token handling
- Encryption is AES-256-GCM with a per-message IV, so a tampered token fails to decrypt rather than returning garbage.
- Tokens are refreshed automatically, sixty seconds before expiry, and the refreshed token is written back encrypted.
- If a refresh fails the tool returns
not_connectedand asks you to reconnect. It never retries against a dead grant. - Sessions are server-side rows. The cookie carries a signed session id, not user data.
Self-hosting
If you would rather not trust a hosted deployment, run it yourself. You supply the OAuth apps, the database and the encryption key, and the only data that leaves your machine is what goes to Google, Microsoft and your own email provider.