Terms of service
What you agree to when you buy something here, and what a publisher agrees to when they list it. Fourteen sections. The money is in 6, 7 and 8; the grounds for taking a listing down are in 9.
Who this is between
1.1These terms are between you and mcprush.com, the marketplace this page belongs to. “We” and “us” mean mcprush.com; “you” means whoever is using the account. Most accounts are a buyer and a publisher at some point, and the clauses that bind you are the ones describing what you are doing at the time.
1.2mcprush.com is the merchant of record for every sale on this marketplace. You buy from us. We buy from the publisher under a separate agreement, of which sections 5 and 8 are the substance. There is no contract of sale between a buyer and a publisher.
1.3That is why a refund is ours to give without asking the publisher first (6.6), why VAT, GST and US sales tax in 61 jurisdictions are ours to register, collect and remit (6.5), why a chargeback is defended by us with the gateway’s call log, and why nobody is ever invoiced by a publisher.
1.4It is not why the software works. The publisher writes it, licenses it and answers for it. We are the counterparty for the money and for what happens at the gateway. We are not the author of anything in the catalogue.
Accounts, seats and keys
2.1An account is free, and reading the catalogue needs no account at all. A seat is a person who can install, approve or hold credentials; a service account, a CI key or a bot is not a seat and is never counted as one.
2.2Anything called with a key issued to your account is your call, and it is billed to you. Keep keys where you would keep a password. Revoking one stops it at the gateway immediately; rotating one leaves the old secret alive for 24 hours, which is the window a nightly run needs to pick the new one up.
2.3Removing a person from a team revokes every key they hold in the same action and ends their sessions. There is no grace period, because the point of removing access is that it stops now.
2.4Closing an account deletes what we hold within 30 days. Invoices are kept for seven years, because tax law says so.
2.5The visitor / customer / publisher switcher in the corner of this site is a preview stored in your own browser. It is not a login, it grants nothing, and no clause here turns on what it is set to.
What a buyer gets
3.1Installing a listing buys a licence to use it on the publisher’s own terms. Those terms are printed on the listing and readable before you install, not after.
3.2We do not licence the software to you. We sell you access to it on the publisher’s behalf and we hold the payment relationship — 1.2.
3.3The licence covers your account and its seats. It does not move to another account and it is not resellable.
3.4Whatever your agent produces with a listing is yours. We claim nothing over it, and no publisher gets a claim over it by way of these terms.
3.5An open-source listing is governed by its own OSI licence. Where these terms and that licence disagree about the software, the licence wins; where they disagree about the money, this page wins.
3.6A buyer is charged the publisher’s listed price, at cost. We add nothing on top of it — 7.1.
When a listing goes away
4.1Deprecated means hidden from the catalogue and still answering. Everyone who has it keeps it, the listing carries a notice that it is no longer maintained, and the publisher can undo it.
4.2Unpublished means no new installs within the hour, and it cannot be undone from the studio. The name is held for 12 months before anyone else can take it.
4.3A superseded release stays servable for 90 days after its replacement ships. A pinned install therefore has a quarter to move, not a morning.
4.4When a plan is cancelled, a seat is removed or an install ends, what stops is the gateway. Keys are revoked, so anything proxied or authenticated through us stops answering at the end of the period already paid for. Files on your own machine stay yours — we do not reach into a laptop to disable a copy of anything.
4.5Files already on your machine stay yours. Withdrawal from the catalogue does not reach into a disk to delete a skill or a local server, and neither does the end of a subscription — what stops is the gateway and anything authenticated through it.
4.6A subscription does not move with a publisher who sets up elsewhere; buyers have to subscribe again wherever that is. When a publisher files a deprecation we tell their buyers they are leaving, rather than quietly cancelling them.
Listings we index rather than publish
5.1Two kinds of entry sit in this catalogue. A published listing is one whose publisher opened an account here and agreed to these terms; an indexed one is assembled from public sources — the Model Context Protocol registry, npm, PyPI, container registries and the projects’ own public repositories — and nobody has agreed to anything. An indexed entry is marked not claimed on its page, is always free, and is never delivered through our gateway.
5.2What we hold on an indexed entry is metadata: the name, the description its authors published, the version, the repository or package address, and the author’s public handle as attribution. We do not host, mirror, modify or redistribute software indexed this way. Hosting is something a publisher asks us for on their own listing, at publication; an entry nobody has claimed is never one of them. Its install command points at its own origin, so it reaches a buyer from the author’s own source, under the author’s own licence, on a request we are not party to.
5.3An indexed entry is not an endorsement, a partnership or a claim of affiliation in either direction. Names, logos and marks belong to whoever owns them and are used only to identify the software they name. Nothing on an indexed page is written in the author’s voice: a description is quoted from what they published, and everything else on it is ours and says so.
5.4If it is yours, you have three options and you do not have to justify choosing any of them. Claim it — prove control of the source and the entry becomes a published listing under these terms, with the account and its figures yours. Correct it — tell us what is wrong and we fix it. Remove it — we delist it. Claiming starts from the button on the entry; correction and removal go to support@mcprush.com or the contact form. We act on a removal within 5 working days and we do not ask for a reason.
5.5The same address takes a copyright or trade-mark complaint from anyone, whether or not the entry is yours, and a complaint that identifies the work, the entry and the right is acted on the same way. Removing something on request is not an admission that listing it was unlawful, and we may say publicly that an entry was removed at its author’s request.
5.6A trust grade on an indexed entry is the output of an automated scan of public source code. It is a measurement of a snapshot of code against published rules, not a statement about a person, a company or their competence, and it can be wrong about a moving target. Whoever the code belongs to may ask for a rescan, and the grade is replaced by whatever the rescan finds.
5.7We give no warranty of any kind on indexed software and we are not a party to its licence: what a buyer installs is governed by the licence the author published with it, between the two of them. Sections 12 and 13 apply to an indexed entry as they do to everything else on this site.
5.8An indexed entry carries no price and never will while it is one. We take nothing on it, we route nothing for it, and the account behind it has no balance — there is nothing to pay out and nothing being earned in anybody’s name.
What a publisher agrees to
6.1The manifest is the promise: every tool declared by name, description and input schema, and each one marked for whether calling it writes anything anywhere. The scan measures what the code can actually reach against what you declared.
6.2No undeclared writes. A tool that can write says so before install, not on first use. A tool declared read-only that writes anything is a policy breach rather than a bug, and it is ground (a) in 9.1.
6.3No description drift after install. Any change to a tool name, description or input schema is a new version by definition; every release is diffed word by word against the last and the diff is published on the listing. Changing what a tool tells the model without cutting a release is the same breach as 5.2.
6.4A tool description that instructs the model to do something the tool does not do — read an unrelated file, echo an environment variable, ignore a prior instruction — is refused. That refusal is not appealable, because the same text is what a prompt-injection attack looks like.
6.5Every listing published through this platform is scanned on publish and on every release: static analysis, capability flow, a secret scan with a liveness check, a word-level description diff, a dependency audit, and egress watched over the first 200 real calls. There is no way to publish around it, there is no fee for it, and the grade is published either way.
6.6The egress allowlist names every host the code can reach, including the one a dependency phones home to. Anything else is refused at the gateway and written to the buyer’s audit trail.
6.7A support contact a person answers, and a stated response window. “Best effort” is a valid window. Silence is not.
6.8A price rise takes 30 days’ notice to existing installs and applies to new ones at once. A cut applies to everybody at once.
6.9The gateway health-checks every listing every 30 seconds and marks it degraded after two consecutive failures. Calls made while it is degraded do not count against the buyer's allowance. A subscription keeps billing unless you are down for more than 24 hours in a calendar month, at which point the month is credited to the buyer and deducted from your next payout.
6.10You warrant that you have the right to publish what you publish, and that the name, mark or tagline does not read as an official integration you do not own.
6.11A listing belongs to the publishing account, not to the person who typed it. When someone leaves a team, nothing is withdrawn from a buyer because the author left.
Money
Two prices exist here: the publisher’s, which a buyer pays, and ours, which a publisher pays. Nothing is added to the first to fund the second.
| Line | Paid by | Goes to | Amount |
|---|---|---|---|
| The listing price | Buyer | Publisher, through us | the publisher sets it |
| Platform fee | Publisher | mcprush | 12% of net |
| Card processing | Publisher | Stripe | 2.9% + 30¢ per charge |
| A disputed charge | Publisher | Stripe | $15, won or lost |
| Publisher’s share | — | Publisher | 88% → 85.1% net |
| Marketplace access | Buyer | — | $0 |
| A team seat | Buyer | mcprush | $9 per month, 3 seats |
| Sales tax, VAT, GST | Buyer | Tax authority, through us | added at checkout |
7.1The price is the publisher’s. A buyer pays it at cost, on one invoice a month covering every listing that account uses. A card and a billing address are entered on our own pages, into fields Stripe serves in its own frame: no page here has a card field of its own, and nothing sends you to a payment page somewhere else to finish.
7.2The platform fee is 12% of net revenue — gross less refunds and chargebacks. The publisher keeps 88%. There is no listing fee, and a free listing costs nothing at all.
7.3Card processing is Stripe’s 2.9% + 30¢ per charge, and it goes to Stripe rather than to us. Of a dollar billed, 88 cents is the publisher’s before processing and 85.1 cents lands. Stripe charges $15 on a disputed charge, at the moment the buyer’s bank opens the case and whether it is later won or lost. The same fee falls on a debit from a US bank account, which is disputed at the account holder’s own bank rather than at a card scheme: the holder of a personal account has up to 60 calendar days from the statement to do it, so a bank debit stays reversible for considerably longer than a card payment. It is charged on the account the payment was taken on, which is ours, and passed to the publisher of the disputed listing on the next run; that sits on the same side of the ledger as the processing fee.
7.4Buyers pay $0 for the marketplace itself: the catalogue, the gateway, the scan on every release and the whole trust layer are funded by the 12%. Pro is $9 a month with three seats in it, then $3 for each seat past them, prorated to the day in both directions.
7.5Prices are in USD and exclude VAT, GST and US sales tax. We add them at checkout and remit them as merchant of record, in 61 jurisdictions. A publisher’s payout is already net of them, and a publisher invoices nobody.
7.6A subscription is fully refundable within 14 days of a first charge, and prorated in both directions after that. A refund goes back the way the money came: to the original card, within five working days, or to the bank account a debit was taken from, which the banks take longer over than a card does.
7.7We return our 12% on a refund, so a refund costs the publisher their 88% of the sale rather than all of it. That 88% is of gross: Stripe keeps its processing fee when a charge is reversed, and it was deducted from the publisher’s side when the charge was made (6.3), so it is not recovered by anybody. A refunded sale therefore costs the publisher the fee they had already paid on it, and costs us the 12% we had already earned.
7.8Failed calls, timeouts and anything the gateway rejects are never billed. A cached repeat inside 15 minutes is free.
7.9A cycle that owes less than $1 is not charged: the balance carries into the next invoice and appears on it as a separate line. Stripe’s 30¢ makes a charge under a dollar cost more to collect than it yields, and collecting it anyway would take the difference out of the publisher’s share. Nothing expires while it waits.
7.10An unpaid invoice is retried three times over 14 days. After that the account’s installs stop until it is settled. You hear from us before that happens, every time.
7.11A buying account may hold a balance: money paid to us in advance through Stripe. It is spent before the card on the account is charged — an invoice takes what it can from the balance and only the remainder reaches the card. A balance is not a deposit and buys nothing by itself: it does not expire, is not forfeited on cancellation, earns no interest, and is refundable in full to the card or bank account it came from for as long as the account exists. It is money we hold and not revenue we have earned, and a top-up is charged at face value: no fee is taken from it on the way in.
7.12A referral pays a share of the platform fee we actually collect from the account introduced — 20% of our 12%, for twelve months from that account’s first settled payment — and pays nothing at any earlier moment. A sign-up, a click, a free install and a trial that never converts are all worth nothing. Each accrual is held for 30 days against the refund and chargeback window; money returned to the buyer takes the share with it. A referrer earns nothing on an account they control, on a listing that charges nothing, or where the account was reached by bidding on our name. A buyer’s share is credited against their next invoice; a publisher’s is added to their payout balance. We may close the programme to new referrals at any time; what has already been earned is still paid.
7.13Pro may be tried for seven days without a card, once per account. Nothing is charged during it and it ends by itself — the account returns to Free rather than to an invoice. Enterprise is not a published price: its limits, its terms and its billing are the contract signed with that account, and where that contract and this page disagree, the contract governs for that account alone.
7.14An order may be paid by US bank debit instead of a card. A debit is not instant: it takes about four business days to clear, nothing is installed until it does, and if it is returned — for want of funds, or an account that has been closed — the order says so and nothing is taken. It stays reversible longer than a card, too: the holder of a personal account has up to 60 calendar days from the statement to dispute one at their own bank (6.3, 8.2). A card is charged and installed in the same minute, and is the right choice for anything that cannot wait.
The cap
8.1Every subscription plan carries a monthly call allowance and a rate limit, both stated on the listing before purchase. Exhausting the allowance refuses further calls for the period; it never produces a charge above the subscription.
8.2The cap is enforced at the gateway, before the publisher’s code runs. A call over the cap is refused and returns a normal MCP error the agent can reason about, rather than a silence or a bigger bill.
8.3A refused call is not billed. Not to the buyer, and not counted as revenue to the publisher. Nothing accrues above the cap to be collected later.
8.4Raising a cap takes effect on the next call and never retroactively. Calls refused while the cap was lower stay refused and stay unbilled.
8.5There is an alert at 80% of a cap, and an anomaly alert against your own 14-day baseline. Both are a courtesy. What stops the spend is the cap.
8.6Caps can be set per server, per stack or per team. Where two apply to one call, the lower one decides.
Payouts
9.1Payouts run through Stripe Connect. Every Friday we transfer a publisher’s share for the week that closed the Sunday before into their own connected account, and Stripe pays it out from there to the bank account it holds for them. The account is opened in Stripe’s onboarding, rendered inside the studio rather than somewhere we send you, and keeping it in good standing with Stripe is a condition of being paid — and of listing anything priced, since a publisher without one can publish free listings and nothing else.
9.2A refund, a chargeback or a bank debit returned after it settled is netted off the next run rather than clawed back out of a publisher’s bank account, which we could not reach in any case: we hold no bank details for anybody. What is netted is the 88% of gross, not the 85.1% that landed — Stripe keeps its processing fee on a reversed charge, and its $15 dispute fee (6.3) is netted whether the case is won or lost. Both sit on the same side of the ledger as the processing fee itself. A debit returned inside the 60 days a personal account has to dispute one is netted the same way, on the run after it comes back.
9.3A new publisher holds 10% for the first 60 days against refunds and chargebacks. It is released in full after that.
9.4We raise a self-billed invoice on the publisher’s behalf for each settlement, so the books carry one document per payout. A 1099-K, or its equivalent where one is owed, is filed by us through Stripe and delivered to the connected account.
9.5Being paid needs a valid tax form — a W-9, a W-8BEN or a W-8BEN-E — collected by Stripe during Connect onboarding and held there with the bank details and the identity documents. No copy of any of the three reaches us: what we hold is the connected account id and its payout status. Where a TIN stops matching the records it is checked against, 24% is withheld until it matches again. Where Stripe suspends payouts on an account, we cannot pay it, and the balance is held rather than routed around them.
9.6A publisher account with no owner cannot be paid. Until ownership is transferred the balance is held rather than paid to a guess.
9.7Money owed on a listing frozen under section 9 is held for the length of the freeze and paid on the first run after it clears. A freeze is not a forfeiture, and we do not keep the 12% on a sale we later unwind.
Freezing, suspension and removal
Section 4 is a publisher choosing to go. This one is us taking a listing down, which is the harder half to write and the half worth reading.
10.1Grounds. We freeze or remove a listing for any of:
(a)a capability or a write the manifest does not declare;
(b)a tool description that instructs the model beyond what the tool does;
(c)network egress outside the declared allowlist;
(d)a live credential in the repository, until the key is rotated and the old one is dead;
(e)a name or mark that reads as an official integration the publisher does not own;
(f)a plan allowance so small that the listing cannot be used inside it;
(g)a skill that tries to override the client’s system prompt, disable a safety behaviour, or hide what the agent is doing;
(h)fraud, or manufacturing the call volume that ranking is built on;
(i)a legal demand we are obliged to act on, which we tell the publisher about unless we are forbidden to.
10.2A security report freezes a listing automatically while it is read. The freeze is a holding action rather than a finding, and it is not published as one.
10.3After that a person decides, not the scanner. The decision is written to the publisher, names the file, the line or the call it turns on, and says what would clear it.
10.4We answer a frozen listing within one working day. If that day passes with no decision written, the freeze lifts on its own. We can freeze on a report because we then have to be quick about it.
10.5A freeze stops new installs. Existing installs keep working, unless the finding is that they are the risk — in which case the listing stops answering and every buyer who has it is told why within the hour, in plain words rather than on a status page.
10.6Removal ends new installs and ends the agreement for that listing. Buyers who paid for it are refunded the unused part of the period, and they are told that we removed it — not that the publisher left. Those are different events and we do not blur them.
10.7Appeal by replying to the decision. It is read by the person who made it and by one who did not, and answered within two working days. The refusal in 5.4 is the one thing that cannot be appealed. Where we were wrong we say so wherever the freeze was visible, and the listing’s ranking is put back where it stood.
10.8An account, as opposed to a listing, is suspended only for non-payment (6.10), for fraud, or for repeating a breach after a written decision. We do not suspend an account to win an argument about a clause.
10.9If we are the ones stopping: we may close the marketplace, or drop a whole category, on 90 days’ notice to everyone it affects. Payouts run to the end of that period, buyers are refunded the unused part of anything prepaid, and nobody has to sign anything to get either.
Reviews, ranking and what you write
11.1The reviewer owns their words; the listing carries the score. A publisher cannot delete a review and cannot pay to have one removed. We remove one only for personal data, for abuse, or where it is plainly about a different product.
11.2One public reply per review. Transfer a listing and the reviews go with it; delist it and they go dark with it.
11.3Ranking uses how many separate readers opened your listing page over the preceding 30 days, counted once per reader per day, with your own team and any client identifying itself as a robot excluded, and with the current day left out so that the order does not move while somebody is reading it. It never uses downloads. Manufacturing that readership, by any means, is ground (h) in 9.1.
11.4You keep the copyright in what you write here — the listing, the README, a review, a reply. You give us the right to show it on this site and to quote it in search results, and nothing beyond that.
Data, and what may be taken from this site
12.1A publisher sees counts, versions, clients and failure codes for their own listing. They do not see the arguments a buyer sent or the content that came back, and a buyer can decline even the counts.
12.2Taking the catalogue in bulk is a breach of these terms — scraping the pages, automating a browser against them, or collecting the listings, their prices or their publishers by any other means. A key reaches your own account, and if you want an agent to reach a listing, install it.
12.3We do not sell what the gateway sees, and we do not train anything on the content that passes through it.
12.4What we do with personal data, and on which lawful basis, is the privacy notice — it is part of these terms and it is written to be read rather than survived. Two things from it belong here: the public pages carry no analytics at all today — the gate is built and no measurement id is configured behind it, so nothing loads whatever you answer. If that changes, Google Analytics is what goes behind it, off until you accept it and reversible from Cookies in the footer of every pagethe public pages carry Google Analytics, which is off until you accept it and reversible from Cookies in the footer of every page; and no page behind a login reports to it at all. Refusing changes nothing about what the account can do.
12.5Where you are a controller in your own right — an organisation whose members use this platform — our data processing agreement applies, including the European Commission’s standard contractual clauses and the UK and Swiss addenda. It is available on request on every plan, including Free, and we do not charge for it or make it a sales conversation. The sub-processor list is published in the privacy notice and changes with 30 days’ notice, which is enough time to object before it takes effect.
Warranties, and what a scan can promise
13.1We warrant the parts that are ours. Metering is reconciled against the gateway’s call records daily and any drift above 0.1% is raised as an incident. A failed call is never billed. A cap is enforced before a publisher’s code runs. A payout is what the ledger says, and the figure on a Friday statement is the figure we transfer to the connected account that day; when Stripe moves it on to a bank is Stripe’s timing rather than a number we produce. Where a number we produced is wrong we correct it and refund the difference, because merchant of record means a wrong number is ours.
13.2A scan is evidence about a build, not a promise about behaviour. It reads source, manifest, dependencies and tool descriptions, and it watches egress over the first 200 real calls — which says what a server did over 200 calls, not what it can never do. It cannot prove the absence of a bug, it cannot read intent, and it cannot tell you whether a tool that is allowed to write should be trusted with your repository.
13.3A grade describes the version it names. A listing that was clean a year ago is not evidence about the release you are installing today, which is why every release is scanned again rather than inheriting the last result.
13.4We do not warrant that a listing is fit for your purpose, that it will still be published next month, or that a model driving it will call it sensibly. The first two are the publisher’s; the third is yours.
13.5Beyond 12.1, the marketplace and the catalogue are provided as they are.
Liability
14.1Neither of us is liable to the other for indirect or consequential loss: lost profit, lost data, the cost of the run that failed, the hours spent finding out why.
14.2Our total liability to a buyer over any 12 months is capped at what that account paid through us in those 12 months, seats included.
14.3Our total liability to a publisher over any 12 months is capped at the fees we charged them in the same period — our 12%, not their 88%. We do not keep a fee for a service we failed to provide, and we do not underwrite their business either.
14.4A publisher indemnifies us against a claim that their listing infringes someone’s rights, and against a claim arising from something their code did outside the capabilities it declared.
14.5None of this limits liability for fraud, for death or personal injury caused by negligence, or for anything else that cannot be limited by the law that applies to you. Rights you have by statute stay yours.
Disputes, law, and changes to this page
15.1Raise it with us first, from the account it concerns. Billing and refunds are answered in one working day, a listing frozen by a report in one, account and access in two. Payout questions are read by the people who run the settlement rather than by a first line that forwards them.
15.2If that does not settle it, these terms are governed by the laws of the State of Delaware, without regard to its conflict-of-laws rules, and the state and federal courts sitting in Wilmington have jurisdiction. Where the law where you live gives you a forum you cannot be made to give up, you keep it.
15.3There is no arbitration clause on this page and no class-action waiver. We would rather be sued in public than quietly.
15.4A material change — the split in 6.2, the schedule in 8.1, what the cap does in section 7, or the grounds in 9.1 — is emailed to every account it affects and takes effect 30 days later. Anything else, including a clearer sentence or a corrected typo, takes effect when it is published.
15.5Every version is kept. The date at the top of this page is the one that counts, and the table below says what changed and when.
15.6If a clause turns out to be unenforceable, the rest stand, and that one is read as narrowly as it takes to make it work.
15.7We may transfer these terms to whoever takes over the business, and we will say so before it happens. You may not transfer yours without asking us.
15.8Not enforcing a clause once does not waive it.
15.9A question about a clause goes to legalmcprush.com. Anything about an account, an invoice or a listing goes through the account it concerns, where it reaches somebody who can already see it.
| Version | In force from | What changed |
|---|---|---|
| 6 | 1 Sep 2026 | Analytics under consent, and the DPA stated as available (11.4, 11.5) |
| 5 | 6 Jul 2026 | A refused call stated as unbilled on both sides (7.3) |
| 4 | 12 Feb 2026 | A freeze given a one-working-day expiry (9.4) |
| 3 | 4 Sep 2025 | Merchant of record; tax registration moved to us |
| 2 | 19 Mar 2025 | Payouts moved from monthly to weekly (8.1) |
| 1 | 2 Nov 2024 | First published |