Terms of Service
Draft — last updated 8 August 2026
This is a working draft, written directly from the decisions in our own build docs. It has not had a legal review pass yet — see /05-REPORT-DISCLOSURE-POLICY.md §10. Don't treat it as final.
1. What createmcps.com is
createmcps.com is a free tool that checks whether a Model Context Protocol (MCP) server conforms to the 2026-07-28 specification. It works two ways: by making live, read-only protocol requests to a server URL you provide, or by analyzing code or a server.json file you paste. By using the service, you agree to these terms.
2. What we will never do to your server
Probes are strictly read-only: we never call a real tool, read a real resource, or invoke a real prompt on a server we validate — only reserved sentinel names. Every probe passes through SSRF-safe admission control before anything is fetched.
3. Acceptable use
Don't use createmcps.com to probe a target you don't have permission to test, to circumvent rate limits and per-target quotas, or to attempt to defeat the admission-control protections. We may suspend access for abuse.
4. Reports and grades are not a certification
A grade or a “pass” on a rule is our best-effort automated assessment against a specific, dated ruleset version — it is not a guarantee, warranty, or certification of security or compliance. Findings can be disputed; see /security for how that works.
5. No warranty
The service is provided “as is,” without warranty of any kind. We don't guarantee it will be available, error-free, or that a clean report means your server has no other issues.
6. Changes
We may update these terms as the product changes. Material changes will update the date at the top of this page.
7. Contact
Questions about these terms: abuse@createmcps.com.