Security

MCPortal reads the open web for you and puts what it finds in front of your agent. Both are places someone could try something, so here is what MCPortal does about it.

Text from the web can't give your agent orders

Feeds, articles, docs pages, other people's notes: anything MCPortal didn't write reaches your agent marked as third-party text, inside a fence with a random id that the text itself can't close or fake. Your agent is told to report on it and never follow instructions inside it, including text addressed to AI agents. MCPortal's own tests try exactly that with poisoned content.

Your agent can't quietly rearrange or delete things

Changing your layout can't remove a portal unless that portal is named as one you asked to remove, and every change is reported back. Deleting your account isn't something your agent can do at all: it happens only on your account page, after you sign in again.

MCPortal only fetches from the public web

Every request MCPortal makes is checked when it connects, so a feed or a link can't point it at a private network, the server itself or a cloud provider's internal addresses, even through redirects or tricks with DNS. Requests have time and size limits, and pages are read with parsers built to stay fast on hostile input.

Sign-in

You sign in with GitHub, and MCPortal only learns your GitHub user ID and login. Apps like Claude connect through standard OAuth with PKCE, after MCPortal's own consent screen, which is tied to your browser so it can't be approved from another site. Tokens are short-lived, stored only as hashes, and bound to this server. A suspended account is cut off within seconds.

Your data

There are no ads, trackers or analytics. You can export everything in open formats or delete your account yourself. See the privacy policy for what's stored and for how long.

Report a security problem

If you find a security issue, please tell us privately at lbeezr@icloud.com (put "security" in the subject) before sharing it anywhere else. Include what you found, how to reproduce it, and what someone could do with it. Don't include real tokens or other people's data.

Machine-readable: /.well-known/security.txt.