Terms of Service
Effective July 13, 2026. Plain language on purpose. Questions: email us.
What changed
This is a complete set of terms that replaces our earlier early-access terms as Passport moves toward general availability. The substance you already relied on is unchanged: your data is yours, deletion is real, and our liability is capped at what you have paid us. This version simply spells out the rest plainly.
Accepting these terms and who may use Passport
These terms are a legal agreement between your organization and Ramish Syed, carrying on business as Passport, based in Alberta, Canada, the operator of the passportmcp.com service. By creating a workspace, signing in, or using the service, you agree to them.
Passport is a product for business and professional use, not for personal or household purposes, and you must be at least 16 and able to enter a contract. If you create or administer a workspace, you confirm that you are authorized to bind your organization to these terms, and "you" then means both you and that organization. The person who creates the workspace is its first admin and is responsible for who they invite.
What Passport is
Passport is a governed gateway between your team's AI clients (such as Claude, Cursor, and ChatGPT) and the MCP servers they use. Workspace policy decides which verified catalog apps members may connect; admins manage custom servers, company setup, and access by person or team. Passport brokers each call server-side so credentials never land in an AI client's configuration, and records every call in an attributable audit trail.
Plans range from a free tier to paid Pro and Enterprise tiers; single sign-on, SCIM provisioning, and SIEM streaming are available on the Enterprise plan. Passport can also be self-hosted in your own environment. The current features and limits are described on the pricing and product pages, and may evolve over time.
Accounts, admins, and members
A workspace has admins and members. Admins govern the workspace: they connect MCP servers, set access passes and per-tool policies, manage members, configure integrations, and control billing. Members use the MCP tools their admins have approved, through their own AI clients.
You are responsible for your account credentials and for activity under your workspace. Keep sign-in secure, use SSO or the controls we provide, and tell us promptly at security@passportmcp.com if you believe an account has been compromised. Admins are responsible for the members they invite and for scoping access appropriately; members are responsible for using only the access they have been granted.
Acceptable use
Use Passport to govern access to systems you are actually authorized to use. You agree not to: use it to attack, overload, probe, or gain unauthorized access to any system; upload or route unlawful content or data you have no right to handle; attempt to break tenant isolation or otherwise access another customer's data; circumvent, disable, or defeat the governance, guardrail, or audit controls the product enforces; resell or offer the service to third parties as your own; or use it in violation of applicable law or of the terms of the third-party services you connect.
You are responsible for respecting the terms of every MCP server and upstream provider your team connects through Passport. If you discover a security issue, please report it rather than exploit it; see the Security page for how. We may suspend or limit use that violates this section, with notice where practical and immediately where a violation is actively harmful.
Your data is yours
Everything in your workspace belongs to you: members, policies, connected-account credentials, and activity. We call this your customer data. You own it, and Passport claims no ownership of it.
We process your customer data only to provide and secure the service, as described in our Privacy Policy, which is part of these terms. You can export your activity and audit trails and a full workspace backup at any time, and you can delete the whole workspace whenever you choose. Deletion is real: the workspace document and its event log are purged, not soft-deleted.
Third-party services and connected accounts
The MCP servers and upstream services you connect are your own accounts with third parties. They are operated by those providers under their own terms and privacy policies, and those terms govern your use of those services. Passport brokers the credentials you grant so your AI clients never hold them, but we do not control those services and are not responsible for their availability, content, or conduct.
Catalog listings, logos, and vendor names identify those third-party services and imply no endorsement or affiliation. Verification badges describe the result of our automated probe of an endpoint at a point in time; they are not a warranty that a provider's service works, is secure, or is fit for your use.
Payment
The free plan is free. Paid plans are billed per member, monthly and in advance, through our payment processor Stripe; by subscribing you also agree to Stripe's terms for the payment itself. You authorize us, through Stripe, to charge your payment method for each billing period and for seat changes, which are prorated.
Prices are exclusive of taxes. You are responsible for any sales, use, GST or HST, VAT, or similar taxes, which Stripe may collect on our behalf. Fees are non-refundable except where required by law; because canceling keeps your plan active through the end of the paid period, we do not refund partial months. If a charge fails, we may suspend paid features until it is resolved. We may change prices with at least 30 days notice by email or changelog, and a change takes effect at your next renewal.
Term, cancellation, and termination
These terms apply for as long as you use Passport. You can cancel a paid plan yourself at any time from Settings through the Stripe portal, with no email required. Canceling stops the next charge and keeps your paid plan through the end of the current period, after which the workspace moves to the free plan. Your data stays until you delete the workspace.
You may end the agreement entirely by deleting your workspace, or by asking us to delete it. We may suspend or terminate access for a material breach of these terms, and will give notice and a chance to cure where practical. On termination, your right to use the service stops; sections that by their nature should survive (such as data ownership, disclaimers, liability limits, indemnity, and governing law) continue to apply.
Our intellectual property, and your feedback
Passport, including its software, gateway, catalog, documentation, and brand, is and remains our property and that of our licensors. These terms grant you a limited, non-exclusive, non-transferable right to use the service during your subscription, and nothing here transfers any of our intellectual property to you.
If you send us feedback, ideas, or suggestions, you grant us a perpetual, worldwide, royalty-free license to use them to improve the service, without obligation or attribution to you. We will not identify you as the source in public materials without your consent.
Confidentiality
Each of us may learn non-public information of the other in connection with the service. Each party will protect the other's confidential information with reasonable care and use it only to perform under these terms. This does not cover information that is public through no fault of the receiver, was already known or independently developed, or must be disclosed by law, and does not override how we handle your customer data, which the Privacy Policy governs.
Warranties and disclaimer
We aim for boring reliability: health checks, backups, tested restores, and an honest status page. We do not yet offer a formal service-level agreement.
Except as expressly stated, the service is provided "as is" and "as available," without warranties of any kind, whether express, implied, or statutory, including any implied warranties of merchantability, fitness for a particular purpose, and non-infringement, to the fullest extent the law allows. In particular, Passport routes tool calls that your AI clients decide to make; we do not warrant that those calls, or the outputs of any AI client or upstream service, are accurate, complete, or error-free. You are responsible for deciding what your AI clients are allowed to do and for configuring the access passes and guardrails accordingly.
Limitation of liability
To the fullest extent permitted by law, neither party is liable for any indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, data, or goodwill, even if advised of the possibility.
Our total liability for all claims arising out of or relating to the service is capped at the amount you paid us in the 12 months before the event giving rise to the claim; for a free workspace, that amount is zero. These limits do not apply to your payment obligations, to either party's liability for breach of its confidentiality obligations or infringement of the other's intellectual property, to the indemnity below, or to liability that cannot be excluded or limited under applicable law.
Indemnity
You will defend and indemnify Passport against third-party claims, and reasonable costs and damages finally awarded, that arise from your customer data, your use of the service in breach of these terms or of law, or your use of the third-party services you connect. We will promptly tell you about the claim, let you control its defense (with our reasonable cooperation), and not settle anything that admits fault on our behalf without our consent.
This obligation is meant to be reasonable and mutual in spirit: we stand behind our own right to provide the service, and neither of us is asking the other to cover problems that are our own to fix.
Changes to the service and to these terms
Passport is actively developed, so features may be added, changed, or retired. We will avoid materially degrading the core service you rely on without reason, and we keep a dated changelog of what ships.
We may update these terms as the product grows. Material changes get notice by email to workspace admins and a dated changelog entry, and the effective date above always reflects the current version. If you keep using Passport after a change takes effect, you accept the updated terms; if you do not agree, you may cancel and delete your workspace.
Governing law
These terms are governed by the laws of the Province of Alberta, Canada, and the federal laws of Canada that apply there, without regard to conflict-of-laws rules. You and Passport agree to the exclusive jurisdiction of the courts located in Alberta, Canada for any dispute, while remaining free to seek urgent injunctive relief where necessary.
General
You may not assign these terms without our consent; we may assign them to a successor in connection with a merger, acquisition, or sale of the business. If any provision is found unenforceable, the rest stays in effect and the provision is narrowed to the minimum change needed. Our not enforcing a right is not a waiver of it.
These terms, together with the Privacy Policy and any order or plan details, are the entire agreement between us about the service and supersede prior discussions. Neither party is liable for delays or failures caused by events beyond its reasonable control, such as outages of upstream providers, network or infrastructure failures, or force majeure. Notices to you may be sent by email or in-product; notices to us go to the contact address below.
Contact
Questions about these terms, or anything else, go to hello@passportmcp.com. Security reports go to security@passportmcp.com.
In keeping with building this product in the open, we will say plainly that these terms were prepared in good faith without outside legal counsel so far, and if anything here materially concerns you we would rather hear it and fix it than stand on boilerplate, so please write to us at hello@passportmcp.com.