Reference

Security and data

What ScopeMCP stores, what it never stores, and how the read-only guarantee is enforced.

The read-only guarantee

ScopeMCP cannot change your property, submit a sitemap, request indexing, or modify anything in your accounts. This is not a policy: the tool handlers in src/lib/mcp/handlers.ts contain no write path to any upstream API. Bing exposes SubmitUrl, SubmitFeed and RemoveSite; none of them are called anywhere in the codebase.

The OAuth scopes requested are the read-only variants, and only the scopes Google actually grants are stored — so a user who declines a scope gets a connection that works for what they allowed rather than one that fails on every call.

What is stored

  • OAuth tokens, AES-256-GCM encrypted at rest with a key derived from TOKEN_ENCRYPTION_KEY via HKDF. Never returned to a client, never logged.
  • Property metadata — the site identifiers your accounts can reach, so scopemcp_list_properties can answer without re-querying.
  • Report cache — performance reports for six hours, CrUX for twenty-four. This exists to stop repeated questions burning upstream quota.
  • Monitors, alerts and snapshots — only what you asked to be watched. Snapshots are what make "is this new?" answerable.
  • Competitor domains you track — the list of domains you entered. We never fetch their private data; we observe public result pages.

What is never stored

  • Page content. No tool fetches or retains your HTML.
  • Plaintext API keys. Only a SHA-256 hash is kept; the key is shown once at creation.
  • Any request body from an agent. Tool calls are not logged with their arguments.

Token handling

  • Encryption is AES-256-GCM with a per-message IV, so a tampered token fails to decrypt rather than returning garbage.
  • Tokens are refreshed automatically, sixty seconds before expiry, and the refreshed token is written back encrypted.
  • If a refresh fails the tool returns not_connected and asks you to reconnect. It never retries against a dead grant.
  • Sessions are server-side rows. The cookie carries a signed session id, not user data.

Sharing

A share link is a revocable, read-only pointer to one stored snapshot. It contains no tokens and no live access — revoking it makes the URL return 404 immediately. If you share a report that contains a competitor analysis, you are sharing that analysis, not granting anyone access to your accounts.

Self-hosting

If you would rather not trust a hosted deployment, run it yourself. You supply the OAuth apps, the database and the encryption key, and the only data that leaves your machine is what goes to Google, Microsoft and your own email provider.