Least privilege
Runtime-specific capabilities remain separate. Cloud relays requests but cannot silently broaden Local policy or bypass exact approval.
MCPDO keeps capability ownership, policy, approval, verification, and activity at the runtime that executes the work.
Runtime-specific capabilities remain separate. Cloud relays requests but cannot silently broaden Local policy or bypass exact approval.
Do not place account tokens, OAuth tokens, private keys, bootstrap secrets, or pairing secrets in support messages, screenshots, logs, or repositories.
Core V1 is self-hosted-first with no mandatory TopHive telemetry or cloud proxy. The site stores its own operational records and OAuth validation hashes.