Security
Read-only, and provably so.
Most tools in this category ask you to trust a sentence on a marketing page. This one is checked by reading the code, and the code has no write path in it.
No write path exists
The tool handlers contain no code that mutates anything. Bing exposes SubmitUrl, SubmitFeed and RemoveSite; none of them are called. Google exposes sitemap submission and index requests; neither is called. This is a property of the code rather than a policy you have to trust.
Read-only OAuth scopes only
We request webmasters.readonly and analytics.readonly. On sign-in we ask only for openid, email and profile, so connecting your account never looks like a permissions escalation. Which connections get created is decided by the scopes Google actually granted, not the ones we requested.
Tokens encrypted at rest
OAuth tokens are sealed with AES-256-GCM under a key derived from TOKEN_ENCRYPTION_KEY via HKDF, with a fresh IV per message. A tampered token fails to decrypt rather than returning garbage. Tokens are never returned to a client and never written to a log.
Sessions live server-side
The session cookie carries a signed session id and nothing else. The session row holds the reference. Revoking is a delete.
PKCE everywhere
Every authorization request sends a PKCE S256 challenge. The state parameter is a signed JWT bound to the flow, so a forged callback cannot attach an attacker account to your workspace.
Share links grant no access
A share link is a revocable pointer to one stored snapshot. It carries no token and no live access. Revoke it and the URL returns 404 immediately.
Where your data goes
ScopeMCP talks to a fixed list of upstream hosts. It has no third-party analytics, no advertising pixels, and no session replay. If you configure an email provider, that is the one addition, and it is optional.
www.googleapis.comoauth2.googleapis.comsearchconsole.googleapis.comanalyticsdata.googleapis.comanalyticsadmin.googleapis.comapi.resend.comssl.bing.comapi.bing.comRun it yourself
Self-hosting removes the trust question entirely. You supply the OAuth apps, the database and the encryption key; the only traffic is to the providers you configured.
git clone https://github.com/you/scopemcp
cd scopemcp
cp .env.example .env
# generate your two secrets
openssl rand -hex 32 # TOKEN_ENCRYPTION_KEY
openssl rand -hex 32 # AUTH_SECRET
npm install
npm run db:push
npm run dev