Security

Read-only, and provably so.

Most tools in this category ask you to trust a sentence on a marketing page. This one is checked by reading the code, and the code has no write path in it.

No write path exists

The tool handlers contain no code that mutates anything. Bing exposes SubmitUrl, SubmitFeed and RemoveSite; none of them are called. Google exposes sitemap submission and index requests; neither is called. This is a property of the code rather than a policy you have to trust.

Read-only OAuth scopes only

We request webmasters.readonly and analytics.readonly. On sign-in we ask only for openid, email and profile, so connecting your account never looks like a permissions escalation. Which connections get created is decided by the scopes Google actually granted, not the ones we requested.

Tokens encrypted at rest

OAuth tokens are sealed with AES-256-GCM under a key derived from TOKEN_ENCRYPTION_KEY via HKDF, with a fresh IV per message. A tampered token fails to decrypt rather than returning garbage. Tokens are never returned to a client and never written to a log.

Sessions live server-side

The session cookie carries a signed session id and nothing else. The session row holds the reference. Revoking is a delete.

PKCE everywhere

Every authorization request sends a PKCE S256 challenge. The state parameter is a signed JWT bound to the flow, so a forged callback cannot attach an attacker account to your workspace.

Share links grant no access

A share link is a revocable pointer to one stored snapshot. It carries no token and no live access. Revoke it and the URL returns 404 immediately.

Where your data goes

ScopeMCP talks to a fixed list of upstream hosts. It has no third-party analytics, no advertising pixels, and no session replay. If you configure an email provider, that is the one addition, and it is optional.

www.googleapis.comoauth2.googleapis.comsearchconsole.googleapis.comanalyticsdata.googleapis.comanalyticsadmin.googleapis.comapi.resend.comssl.bing.comapi.bing.com

Run it yourself

Self-hosting removes the trust question entirely. You supply the OAuth apps, the database and the encryption key; the only traffic is to the providers you configured.

self-host
git clone https://github.com/you/scopemcp
cd scopemcp
cp .env.example .env

# generate your two secrets
openssl rand -hex 32   # TOKEN_ENCRYPTION_KEY
openssl rand -hex 32   # AUTH_SECRET

npm install
npm run db:push
npm run dev