Terms of Service
FSS MCP Hub Terms of Service
Effective date:
Last updated:
1. Operator and scope
These Terms govern access to and use of the FSS MCP Hub, operated by:
Finite Software Systems Ltd.
Bulgarian name: ФИНИТ Софтуер Системс ЕООД
UIC / Company No.: 175276896
VAT No.: BG175276896
- Registered office: 4 Gorotzvet Street, 1421 Sofia, Bulgaria
- Contact and management address: 180 Vitosha Boulevard, 1408 Sofia, Bulgaria
- Email: info@finite-soft.com
- Telephone: +359 2 439 21 00
In these Terms, “FSS”, “we” and “us” mean Finite Software Systems Ltd.
The “Hub” means the public website at mcp.finite-soft.com and the account, authentication, OAuth 2.0, OpenID Connect, authorisation, client-registration and related security functions provided from that service.
By creating or accepting a Hub account, signing in, authorising an application, registering a client, or otherwise using the Hub, you agree to these Terms.
2. Relationship with connected applications
The Hub is a shared identity and access service for applications operated or supported by FSS. The first public product using it as an identity provider is brainattic.
These Terms govern the Hub's account, login and authorisation functions. They do not replace the terms, privacy policy, data-processing agreement, acceptable-use rules, subscription or order that applies to a connected application.
For example:
- these Terms govern the login and access credentials issued by the Hub; and
- the brainattic Terms of Service govern the brainattic knowledge-base service and its customer content.
Authorisation by the Hub does not itself create a right to use every connected application. Access remains subject to the application's registration, organisation, tenant, workspace, subscription and permission rules.
If a connected application's terms conflict with these Terms, these Terms govern the Hub layer and the application-specific terms govern the application's own service and content.
3. Intended users and authority
The Hub is designed for business and organisational use.
You must provide accurate information and use the Hub only where you are authorised to do so. If you act for an organisation, you represent that you have authority to use its applications, tenants, workspaces and permissions and, where you accept these Terms for the organisation, authority to bind it.
Any mandatory rights that apply to a consumer are not excluded by these Terms.
4. Current Hub functions
The Hub currently supports functions including:
- password login and password recovery;
- optional sign-in with Google where configured;
- account invitation and application-initiated self-registration;
- email verification for password self-registration;
- OAuth 2.0 authorisation-code, refresh-token and supported client-credential flows;
- OpenID Connect discovery, ID tokens and UserInfo responses;
- registered application and resource-server scopes;
- per-user application grants, tenant or workspace bindings and resource-specific attributes;
- dynamically registered OAuth or MCP clients where enabled;
- access, refresh and identity credentials;
- remembered client approvals that users can withdraw for future authorisation prompts;
- administrator-managed accounts, access grants, identity links, clients and security controls; and
- operational and security auditing.
The Hub may refuse a request that does not satisfy its client-registration, redirect-URI, scope, account, resource, tenant, security or protocol rules.
5. Accounts and credentials
You must keep your account, email account, password, client secrets, tokens, devices and client applications secure.
You must not:
- share a personal account with another person;
- disclose passwords, client secrets, access tokens, refresh tokens, verification links or invitation links to an unauthorised person;
- place credentials in public repositories, public prompts, screenshots, logs or support messages;
- use credentials after they have expired or been revoked;
- use a credential for a different client, application, audience, resource, tenant or purpose from the one for which it was issued; or
- attempt to bypass expiry, rotation, signature, PKCE,
state,nonce, audience, scope, tenant or other access controls.
You are responsible for activity performed through credentials under your control, except to the extent that applicable law places responsibility on FSS.
The authenticated account page currently permits display-name and password changes, language selection, email-verification resend where applicable, logout, and withdrawal of remembered application approvals. The account email is read-only there and is changed administratively.
The Hub does not currently provide a self-service account-deletion or Google-unlink function. Requests for those actions must be made to FSS.
6. Sign-in with Google
Where Google sign-in is available, you may choose Continue with Google instead of or in addition to a Hub password.
By choosing it, you ask Google to provide the Hub with the standard OpenID Connect identity information described in the FSS MCP Hub Privacy Policy. The current Hub implementation uses Google's stable subject identifier, email address, email-verification assertion and display name, where provided, to authenticate and link the account.
FSS does not receive your Google password and does not persist Google access or refresh tokens in the current implementation.
Your use of Google is governed by Google's own terms and privacy policy. Google controls the availability and operation of its service. FSS may add, remove or suspend an upstream sign-in provider where required for security, technical, contractual or legal reasons.
A Google identity is linked only where the Hub's account-collision, email-verification and security rules permit it.
7. Applications, claims and scopes
A registered application or client may request identity claims, scopes and access to a specific application or resource server.
Depending on the request and the permissions assigned to the account, the Hub may issue:
- a stable user subject identifier;
- display name, preferred username, profile-image URL and language under the
profilescope; - email address and verification status under the
emailscope; - account-role values;
- resource-server access scopes;
- a target audience or resource; and
- namespaced tenant, workspace or other resource-specific attributes.
The Hub limits issuance using the client's registered scope configuration, user grants, resource-server catalog, account status and tenant or workspace bindings.
You must review an authorisation request before approving it. You must not approve access for a client you do not recognise or trust.
FSS may refuse or narrow a request where the client, redirect URI, requested scope, resource, account grant or security state is invalid or unauthorised.
8. Remembered approvals and revocation
The Hub may remember an approval so that a later request from the same client can proceed without displaying the same approval screen again.
A signed-in user can withdraw a remembered approval from the account page. Under the current implementation, this causes a future authorisation request to prompt again. It does not by itself revoke access or refresh tokens already issued to the client.
Contact FSS where immediate revocation of existing credentials is required. FSS may revoke or expire token records, refresh paths, clients, accounts or access grants through the available administrative controls.
Revoking the Hub in Google Account settings affects future Google authorisation. It does not by itself delete the local Hub account or its local identity-link record.
9. OAuth and MCP clients
Where enabled, the Hub may allow compatible clients to register dynamically or may resolve approved external client metadata.
A client operator must:
- provide accurate client name and redirect information;
- use only redirect URIs that it controls or is authorised to use;
- request only scopes needed for the client function;
- use PKCE and the required client-authentication method;
- keep a client secret confidential where one is issued;
- avoid deceptive names, logos or metadata;
- avoid repeated or excessive registrations; and
- stop using a deactivated, removed or unauthorised client.
FSS may deactivate, prune, refuse or remove stale, duplicate, misleading, insecure or abusive clients. Ownerless dynamically registered clients become prune candidates after the configured inactivity period. The normal pruning behavior may deactivate rather than immediately delete them.
Registration of a client does not mean that FSS endorses, audits or guarantees that client.
10. Acceptable use
You must not use the Hub to:
- violate applicable law or the rights of another person;
- impersonate another person or organisation;
- submit false identity, account, application or client information;
- gain or attempt to gain unauthorised access to an account, application, repository, database, tenant, workspace or service;
- obtain or use another person's password, token, session, invitation or verification link;
- evade authentication, authorisation, rate limits, tenant isolation or other security controls;
- probe, scan or test the Hub or connected applications without written permission;
- register a deceptive or malicious client or redirect URI;
- introduce malware, harmful code, spam, phishing or credential-theft content;
- disrupt, overload or degrade the Hub or a connected application;
- use identity claims for unrelated tracking, advertising, surveillance or profiling;
- sell, sublicense or resell Hub access without a written agreement; or
- assist another person in doing any of these things.
You must also comply with the terms and acceptable-use rules of each connected application and third-party identity provider you use.
11. Organisation and administrator controls
An authorised FSS or organisation administrator may, depending on the service arrangement:
- create, invite, activate, deactivate or delete a Hub account;
- manage the account email, name, type, administrator status and language;
- assign or revoke application, resource-server, tenant, workspace, repository, database or tool access;
- add or remove resource-specific attributes;
- register, activate, deactivate or modify clients;
- revoke identity-provider links in the administrative flows that support it;
- clear login lockouts;
- rotate client secrets or signing keys; and
- inspect audit and access information permitted to that administrator.
Removal from one application or tenant does not necessarily delete the Hub account if it remains required for another connected application.
FSS may act on a properly authenticated instruction from an authorised customer or application administrator, subject to the applicable product agreement and law.
12. Security actions and suspension
FSS may restrict, suspend, deactivate or terminate an account, client, token, session, identity link or access grant where reasonably necessary because of:
- suspected account or credential compromise;
- an invalid, expired, replayed or revoked credential;
- unauthorised, abusive or prohibited activity;
- a breach of these Terms or connected-application terms;
- a request from an authorised organisation or application administrator;
- expiration or removal of a required application, tenant or scope grant;
- a material security issue;
- a threat to another user, connected application or FSS system;
- maintenance or service discontinuation; or
- a legal or regulatory requirement.
Where practicable and safe, FSS will provide notice. Immediate action may be taken where delay could expose an account, application, system or other person to harm.
13. Account closure and connected data
You may request closure of the Hub account by contacting info@finite-soft.com.
Closing or deleting a Hub account may:
- end Hub sessions;
- prevent future sign-in;
- make existing refresh paths unusable or require administrative revocation;
- remove local identity-provider links where the account deletion cascades to them;
- remove account-level grants and bindings; and
- end access to more than one connected application.
Because the same Hub identity may serve several applications, FSS may need to coordinate closure with the relevant application or organisation.
Deleting the Hub account does not automatically determine the retention of data held by each connected application. Application content and records are handled under the application's own terms and privacy policy.
FSS may retain limited information where required by law or necessary for security, abuse prevention, audit investigation or legal claims, as described in the Hub Privacy Policy.
14. Fees
The Hub does not currently present a separate public subscription or payment function.
A connected application may be free, paid, pilot, subscription-based or governed by a separate order. Its charges and payment terms are governed by its own terms and commercial agreement.
FSS will not impose a separate Hub fee unless applicable commercial terms are communicated and agreed where required.
15. Intellectual property
FSS and its licensors own the Hub software, interfaces, documentation, designs, names, logos and other protected materials.
Subject to these Terms, FSS grants you a limited, non-exclusive, non-transferable and revocable right to use the Hub for authorised access to registered applications.
You may not copy, sell, lease, distribute, modify, reverse engineer or create derivative works from the Hub except where FSS has agreed or mandatory law permits it.
These Terms do not grant ownership of another user's data, an application's customer content, a repository, database, tenant, workspace or connected service.
16. Third-party services and clients
The Hub interoperates with services and software that FSS does not control, including Google, browsers, MCP clients and connected applications.
Third-party services are governed by their own terms and policies. To the extent permitted by law, FSS is not responsible for a third party's independent processing, availability, account decisions, security or changes outside FSS's reasonable control.
A connected application's presence in the Hub does not make FSS responsible for all of that application's content or conduct. Responsibility is allocated by the applicable application terms, customer agreement and law.
17. Availability and changes
FSS may maintain, update, modify or discontinue parts of the Hub. The Hub may be temporarily unavailable because of maintenance, security work, identity-provider failure, network failure, software defects or events outside FSS's reasonable control.
Unless a written service agreement states otherwise, the Hub has no separate service-level or uptime guarantee.
FSS will use reasonable efforts to restore material functions and avoid unnecessary disruption, but does not promise uninterrupted or error-free operation.
18. Disclaimers
To the maximum extent permitted by law, the Hub is provided “as is” and “as available.”
FSS does not warrant that:
- the Hub or a third-party identity provider will always be available;
- every browser, MCP client or application will be compatible;
- every requested scope or authorisation will be granted;
- every connected application will remain registered;
- operation will be uninterrupted or error-free; or
- the Hub will be free from every security vulnerability.
Nothing in these Terms excludes a warranty or right that cannot lawfully be excluded.
19. Liability
To the maximum extent permitted by law, FSS is not liable under these Terms for indirect, incidental, special, consequential or punitive loss, or for lost profit, revenue, opportunity, goodwill or anticipated savings.
Any specific liability cap or service commitment agreed in a connected application's order, subscription or other written agreement applies to that service according to its terms. These Hub Terms do not create a new or higher cap or commitment.
Nothing in these Terms excludes or limits liability that cannot lawfully be excluded or limited, including liability for fraud, fraudulent misrepresentation, wilful misconduct, or death or personal injury caused by negligence where applicable.
20. Privacy
The FSS MCP Hub Privacy Policy explains how the Hub processes account, Google sign-in, session, token, client, audit and application-access data.
Connected applications may process additional data under their own privacy policies and, where applicable, data-processing agreements.
21. Changes to these Terms
FSS may update these Terms to reflect changes to the Hub, connected applications, identity providers, legal requirements or security practices.
The current version will show its last-updated date. For a material change, FSS will provide notice where appropriate. Where applicable law or the service relationship requires renewed acceptance, continued access may depend on that acceptance.
Changes do not apply retroactively to conduct completed before they became effective, except where required by law or expressly agreed.
22. Governing law and disputes
These Terms are governed by the laws of the Republic of Bulgaria, without prejudice to mandatory law.
A dispute involving a business user is subject to the competent courts in Sofia, Bulgaria, according to the applicable jurisdictional rules.
Where mandatory consumer jurisdiction or another mandatory right applies, it remains unaffected.
Before formal proceedings, the parties should make reasonable efforts to resolve the matter through the contact details below.
23. General
These Terms, the Hub Privacy Policy and the applicable connected-application agreements form the agreement relevant to your use of the Hub and those applications.
If a provision is unenforceable, the remaining provisions continue to apply. A delay in exercising a right is not a waiver.
You may not assign these Terms without FSS's written consent. FSS may assign them to an affiliate or successor in connection with a transfer or reorganisation of the Hub, subject to applicable law.
The parties are independent contractors. These Terms do not create a partnership, joint venture, employment or agency relationship.
FSS is not responsible for delay caused by events outside its reasonable control.
24. Contact
Finite Software Systems Ltd.
Contact address: 180 Vitosha Boulevard, 1408 Sofia, Bulgaria
Registered office: 4 Gorotzvet Street, 1421 Sofia, Bulgaria
Email: info@finite-soft.com
Telephone: +359 2 439 21 00