Server data from the Official MCP Registry
Agent-native hosting: deploy any folder to a live URL in one command. No approve tool.
About
Agent-native hosting: deploy any folder to a live URL in one command. No approve tool.
Security Report
The openpouch MCP server demonstrates solid security fundamentals with proper authentication, reasonable permission scoping, and generally safe code practices. However, there are several moderate-severity issues: credential exposure through environment variables, insufficient input validation on some paths, and container escape risks through unsanitized user code execution. The architecture is sound but implementation details need hardening. Supply chain analysis found 3 known vulnerabilities in dependencies (2 critical, 0 high severity). Package verification found 1 issue (1 critical, 0 high severity).
4 files analyzed ยท 15 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
Unverified package source
We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-openpouch-openpouch": {
"args": [
"-y",
"openpouch-monorepo"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
openpouch ๐ฆ
We never ask if you're human.
The agent-native hosting platform โ built for coding agents, not walled against them. Your coding agent says "deploy this," and it does: one command, no account, no dashboard, no CAPTCHA. openpouch runs your app on its own infrastructure and hands your human back a live URL and a plain-language summary.

Your app is the joey; openpouch carries it safely. ๐ฆ
Status: live. openpouch and @openpouch/mcp are on npm, and the instant lane (npx openpouch deploy) is live on openpouch's own infrastructure โ static sites and real Node.js apps in hardened containers, with server-side build-on-deploy. Free previews are anonymous and ephemeral; apps saved to a free account stay live while they're used (usage-based persistence), and paid tiers add persistent /data volumes, always-on apps and more capacity (openpouch upgrade โ payment itself is always a human moment, never an agent action). APIs are still young and feedback shapes them โ issues welcome.
Works with any agent harness โ Claude Code, Codex, OpenClaw, Hermes, Cursor, or none at all: plain CLI with --json everywhere, plus an MCP server. Setup snippets per harness: docs/HARNESSES.md.
Why
AI coding agents already initiate >30% of weekly deployments on major platforms โ but every platform is human-first with agent features bolted on. Agents fight browser OAuth, interactive prompts, account-wide tokens, human-prose logs, and they lose deployment truth between sessions. The humans operating them have no policy layer: nothing enforces "previews are autonomous, production needs my approval."
openpouch is the missing combination: open source + agent-native + governed deployment lifecycle.
Quickstart
Deploy any folder to a live URL in one command โ no account, no provider key, no setup:
npx openpouch deploy
You get a live https://<slug>.openpouch.sh preview plus a claim link. The agent deploys autonomously; a human claims the preview via the link (unclaimed previews vanish after 72 h). openpouch writes the deployment truth (deploy.manifest.json, deploy.evidence.json, DEPLOYMENT.md) back into your repo, so any agent can pick up where the last one left off.
Prefer your own provider? openpouch can also drive Render or Vercel (BYO): openpouch init detects your project and maps the existing service, then openpouch preview / openpouch prod run the same governed pipeline (previews autonomous, production gated behind a human approval). The product itself, though, is openpouch's own hosting โ see docs/INDEX.md.
What agents say
We commission independent agent harnesses to test openpouch end-to-end (build an app from scratch, deploy, verify, report) โ their own words:
"OpenPouch currently feels genuinely agent-native." โ OpenClaw, rating it 9/10 for agent-native usability
"Already very agent-native for the tested use case โฆ no dashboard, no account, no CAPTCHA." โ Codex (translated)
Hermes' end-to-end run: all 23 core checks passed โ source-only upload, server-side build, healthy dynamic app, zero browser errors.
These are commissioned test runs we publish honestly, not organic reviews โ full methodology lives in the harness reports the agents wrote themselves. Friction reports from your agent are the feedback we value most: file a harness report.
What it is
Agent-native hosting: your app runs on openpouch's own infrastructure, wrapped in a governed, agent-readable deployment lifecycle. Every surface is built for agents โ CLI, MCP, the file formats, the claim pages โ with zero human-verification walls.
- CLI (
openpouch deploy/init/inspect/plan/preview/prod/approve/verify/logs/rollback/list/delete/signup/activate/whoami/feedback) โ zero-config detection,--jsoneverywhere, meaningful exit codes, machine-readable errors with fix hints, and a plain-languagesummaryto relay to your (possibly non-technical) human - MCP server โ the same capabilities as native tools in any MCP-capable agent harness
- Open file formats in the user's repo (the "package.json of deployment"):
deploy.manifest.jsonโ project config, environments, build/start, healthchecks, env-var manifest (names/status, never values)deploy.policy.jsonโ what agents may do per environment; approval rulesDEPLOYMENT.md+deploy.evidence.jsonโ what is live (URL, commit, time, smoke results, rollback anchor)
- Optional BYO adapters โ point openpouch at your own Render or Vercel instead, same governed lifecycle; the product is openpouch's own hosting, not a layer over other clouds
Safety, non-negotiable: read-only by default; previews can be autonomous; production requires a signed, single-use approval granted by a human in an interactive terminal; no destructive action class in the governed/production lane (the only delete is openpouch delete โ owner-scoped self-service removal of your own ephemeral instant preview, not approval-gated by design); secret values never enter model context; full audit trail. Because we run untrusted code on our own infra, abuse is controlled with agent-compatible means (accounts/quotas, rate/resource limits, egress filtering, takedown) โ never CAPTCHAs.
The instant lane (openpouch deploy) is live โ static sites and dynamic Node apps both run today, free previews included. Since 0.3.0, self-service billing is live too: free-account apps use usage-based persistence (they stay live while they're used), and paid tiers add persistent /data volumes, always-on apps and higher capacity. The open-source core (CLI, MCP, adapters, run-d) stays complete and self-hostable forever.
Monorepo layout (actual)
packages/
core/ # manifest & policy schemas, evidence writer, adapter interface
cli/ # openpouch binary (compiled dist + plain-Node launcher)
mcp/ # MCP server over the same core (stdio; every capability except approve โ human-only)
adapter-render/ # Render API adapter (live-verified)
adapter-vercel/ # Vercel API adapter (live-verified incl. redeploy)
adapter-run/ # instant-lane adapter (openpouch-run) + instantDeploy
run/ # run-d โ instant-lane host daemon + account/API-key/quota subsystem
docs/ # product & rebuild-grade documentation (start: docs/INDEX.md)
llms.txt # agent-facing entry point (llmstxt.org format)
Documentation rule (release gate)
All documentation must be complete enough that any developer or AI harness can understand and functionally rebuild the project from the docs alone: business rules, data model with units, full API reference, workflows, architecture, test gates, and a rebuild guide with acceptance criteria โ derived from actual code, with an index separating current truth from history.
Community
- Contributing โ light-weight guide; docs improvements are a first-class contribution, and
good first issuemarks mentored entry points. - Discussions โ Q&A, ideas, and Show & Tell (post what your agent deployed).
- Harness feedback โ your agent hit friction? That's a bug in our product; reports written by the agent itself are welcome.
- Security โ private disclosure via GitHub Security Advisories or security@openpouch.dev. Never a public issue.
License
Apache-2.0 (decided 2026-06-12; explicit patent grant โ see LICENSE and NOTICE).
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Paperclip
Freeby Paperclipai ยท Developer Tools
Trending hip-hop artist momentum scores across four cultural dimensions.
Git
Freeby Modelcontextprotocol ยท Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno ยท Developer Tools
Toleno Network MCP Server โ Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace ยท Developer Tools
Create, build, and publish Python MCP servers to PyPI โ conversationally.
MCP Marketplace
Freeby mcp-marketplace ยท Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft ยท Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
