Code that runs somewhere and holds credentials: a repo, an HTTPS endpoint, a container, or the buyer’s own machine over stdio. The gateway sits in front of it and handles OAuth, per-install keys, rate limits and the plan allowance, so anything with a subscription is priced here rather than on a skill.
Model a server listingFor publishers
List an MCP server, an Agent Skill, or both. Pick one of three pricing models and 88 cents of every dollar billed is yours. There is no listing fee, a free listing costs nothing at all, and the person installing you is charged nothing by us at any volume.
Publishing free costs nothing. There is no fee on it.
Our 12% is a share of what you are paid, so a listing that charges nothing is billed nothing — no listing fee, no Stripe Connect, no card, no company. It gets the same trust grade, the same scan and the same install flow as a paid one, and it stands on the leaderboard beside them: the board ranks by the calls we answered, and a listing installed straight from your own source is listed under the ranked ones rather than kept off. You can also hand us the server and let us run it — managed hosting is ours to operate, and the price of the listing is still yours to set.
Two surfaces, one set of pricing models
Servers and skills are listed, scanned, versioned and paid out the same way. What differs is what you upload and which pricing models make sense.
A folder of instructions — a SKILL.md plus reference files — that loads into the context window when the work matches. It holds no credentials and makes no calls of its own, so its marginal cost to you is zero and there is nothing for the gateway to meter: never per call. It is priced free or once — never by the month and never per call, because there is nothing to count and nothing to keep switched on. One price buys the folder and every update you ship inside it; the folder on a buyer’s disk stays theirs whatever happens next, because we cannot delete it and would not if we could.
Model a skill listing| Model | Which listings it suits | Used by |
|---|---|---|
| Free
Nothing, ever. Install it, call it as much as you like. |
Something you already run for another reason, or a listing you want depended on before you price it. Published from a public repository it lists as open source. |
307 servers
194 skills
|
| Subscription
Monthly plans you write yourself: a price, the calls a month it includes and a rate ceiling. The gateway enforces all three and refuses the call when a subscription lapses. |
Anything you want to be able to switch off. It is the only model that can be, which is why every paid listing here is one. |
290 servers
not on skills
|
| One-time
One charge, and the skill is theirs — the files, and every update you ship while it is listed. |
Skills. A skill is text an agent reads on the buyer's own machine: nothing passes through us, so there is nothing a lapsed subscription could switch off. One price, paid once, is the honest shape of that. |
0 servers
314 skills
|
You can change model on a new major version. Existing installs stay on the terms they bought until they move — see price changes.
What actually lands in your bank
Priced like Twilio Messaging — the middle server listing in the catalogue by price, 299th of 597, at Free — and set to 100 installs, which is a guess rather than a measurement: how many people install you is the thing this calculator is for. Change anything you like; nothing is rounded until it is printed.
Both models are open to servers. Of the 597 listed, 290 charge a subscription and the rest are free.
A free listing has no price. Everything else on this page still applies to it.
Nothing is billed, so this number decides your reach and nothing else.
1,500 calls a month per install — what a plan's allowance has to cover. A call that failed, timed out or was refused does not count against it: it costs the buyer nothing and earns you nothing.
| Gross revenue | nothing is billed | $0.00 |
| Platform fee | — | $0.00 |
| Stripe processing | — | −$30.00 |
A free listing bills nothing, so there is nothing to split. What it earns is distribution: the catalogue, the stacks, the search index, the version pinning and the analytics are identical to a paid listing, and cost you nothing.
A free listing is scanned, versioned, ranked and measured exactly like a paid one, and the studio shows it the same analytics.
On your machine, behind our gateway
Your server stays where it is. We never receive your code, never run a container for you and never bill you for compute. What we ask for is an HTTPS endpoint and a token it refuses calls without; buyers are handed our address instead of yours, and everything between them and you — the key, the plan, the rate limit, the invoice, the refund, the call log — is ours to run.
| Where it runs | Metered | What that means |
|---|---|---|
Your own HTTPS endpoint Wherever you already run it. We never see your code, your container or your bill. |
at any volume |
You give us the address and a token your endpoint refuses calls without. Buyers are given our address instead of yours, so the key they hold is ours to revoke, the plan they are on is ours to enforce, and the call log is one both of you can read. What reaches you is the same JSON-RPC the client sent, plus our token — nothing about your server has to change for us except that it stops answering strangers. |
A server we run for you Hand us the source at publication |
no separate bill |
You give us the source instead of an address, and we stand the server up behind its listing. The gateway address a buyer installs is the same either way, and so is the share — there is no hosting line and no charge per hour or per gigabyte. The listing waits until our address answers and refuses a call carrying no token, which is the same proof every other server here passes, and you can put an endpoint of your own in front later without republishing. |
The buyer’s own machine, over stdio Free and open-source listings only. Nothing passes through us, so nothing is metered. |
charged by nobody |
A local listing is a command the buyer runs. There is no endpoint, no gateway in the path and no call to count — which is why it is the one kind of listing that cannot be sold: there is nothing between the buyer and the software to bill for. |
We charge for being in the path of a call, not for the machine that answers it — the platform fee on what you sell, and nothing per hour, per gigabyte or per container. That is why the endpoint stays yours: the only thing this marketplace runs is the gateway in front of it, and the only thing it costs you is the share of a sale it made.
Against running it yourself
You can host your own server, take your own payments and keep 100%. It is a real option and this is what it costs — not in money, in the eight things that become yours. The right-hand column is what you are paying 12% to not do.
| What it takes | On mcprush | On your own |
|---|---|---|
| Where it runs | Today a paid listing runs on your own infrastructure and reaches buyers through our gateway. | Your machine, your uptime, your 3am. |
| Taking money | Stripe, with us as merchant of record. Cards, invoices, dunning, refunds and chargeback defence filed with the gateway’s own call log. | Your Stripe account, your dunning emails, your chargeback evidence. |
| Sales tax and VAT | Registered and remitted in every jurisdiction we sell into. You get one self-billed invoice a month and an annual statement. | Yours to register for, collect and file, in every country a buyer happens to be in. |
| What the buyer pays | Your price. We add $0.00 to it on every plan, at any volume — the fee comes out of your side, never on top of theirs. | Your price plus whatever your billing stack adds to it. |
| Being found | A catalogue, search, category pages, stacks and the clients’ own install flows. Buyers arrive already knowing what your server does. | Your README, your posts, your launch day. |
| Allowances and limits | Plan allowances and rate limits, enforced at the gateway, and a failed call that is never billed. All of it decided before the request reaches you. | Yours to build, and the first support ticket is about the bill. |
| Trust, in public | A scan on every release, a graded report, a diff of every tool description, and a signature buyers can verify. | Your word for it. |
| When something breaks | One invoice, one support desk. A charge that looks wrong is ours to answer, because we are the merchant of record. | Yours, including the ones that turn out to be Stripe’s. |
The row that is not on this table is the one worth saying out loud: you can leave. Your listing is your code, the buyers are yours to tell, and nothing here holds a version you cannot cut yourself. The 12% buys the 8 rows above for as long as they are worth more to you than they cost — which is the only basis on which anybody should be paying it.
Submit, scan, review, publish
Most listings go live the same day. Nothing below needs a company, a Stripe Connect account or a price: you can satisfy every line, run the scan and read the whole report before deciding whether to publish at all.
| Step | Typical time | What happens |
|---|---|---|
01 Submit |
10 minutes |
Point the studio at a repository, a published npm package or PyPI project, a container image or an HTTPS endpoint — or paste a SKILL.md. It reads your manifest, lists the tools it found, and names the required fields that are missing. |
02 Automated scan |
4–20 minutes |
The six passes listed below, over source, dependencies, secrets and every tool description. You get the full report whether you publish or not. |
03 Review |
6 working hours, median |
Most listings skip it and publish straight from a clean scan. A human is pulled in by an unresolved finding, a new egress destination, a paid model on a first listing, or a name close to one that exists. Two working days is the worst case. |
04 Publish |
5 minutes |
Live in the catalogue within five minutes of approval and in the search index within fifteen. The trust grade and the scan report are public from the first minute, including when they are unflattering. |
05 Every release after |
per version |
Steps 2 to 4 again, over the diff, usually under two minutes. A clean scan goes to 5% of new installs for 48 hours while the error rate is watched, and then to everyone — the staging is ours to run, not yours to babysit. If a version turns out wrong you hold it, which puts new installs back on the one before it, or withdraw it entirely. |
A rejection names the file and the line and tells you what would pass. The most common one, and the only one that is not appealable, is a tool description that instructs the model to do something the tool does not do — the same text a prompt-injection attack is made of.
8 things, checked at submission
- A manifest declaring every tool: name, description, input schema, and whether calling it writes anything anywhere.
- An egress allowlist naming every host your code can reach, including anything a dependency phones home to.
- The auth method — none, a key you issue, or OAuth 2.1 with each scope written in a sentence a buyer can read.
- A licence: an OSI identifier for open source, terms readable before install rather than after for commercial.
- A README with a section on what the listing does not do. The catalogue renders it, and buyers read it.
- A support contact a person answers and a stated response window. "Best effort" is a valid window; silence is not.
- For a skill: a SKILL.md with front-matter name and description, its trigger phrases, and its token weight — measured for you at submission.
- For anything paid: a Stripe Connect account, onboarded inside the studio. None of it is needed to run the scan.
6 passes, run on every release
- Static analysis of source, manifest and every dependency at the version you locked.
- Capability flow — what each tool can actually reach (filesystem, network, process, credentials) against what it declares.
- Secret scan across repository and image, with a liveness check: rotating the key clears it, deleting the line does not.
- A word-level diff of every tool name, description and input schema against your previous release.
- Dependency audit against known advisories, producing a grade from A+ to C that is published either way.
- Egress observation over the first 200 real calls, compared with the allowlist you declared at submission.
88 / 12, every Friday
The split is the same on every model and does not change with volume. Buyers are charged by mcprush.com as merchant of record; you are paid through Stripe Connect.