MCP, API & CLI Subscription Service Terms
Version 2.4 — Publication date: 01/07/2026
These Service-Specific Terms (the “API, MCP and CLI Terms”) supplement and form an integral part of the Master Services Agreement (MSA) entered into between the SERVICE PROVIDER and the SERVICE RECIPIENT. They govern access to, use of and subscription to the SERVICE PROVIDER’s Application Programming Interfaces (APIs), components, servers or connectors based on the Model Context Protocol (MCP) and command-line tools (CLI), contracted through the corresponding Service Order. Capitalized terms not defined here have the meaning given to them in the MSA.
1. SCOPE AND LICENSE
1.1. Subscription license. Subject to compliance with the Contract, the SERVICE PROVIDER grants the SERVICE RECIPIENT, for the term of the Service Order, a limited, non-exclusive and non-transferable license to access and consume the specified APIs and MCP connectors, and to install and use the specified CLI tools. The license may be suspended or revoked only in the cases provided for in the Contract.
1.2. MCP components. MCP-based services enable the interconnection and exchange of context between Artificial Intelligence models and the SERVICE RECIPIENT’s repositories, databases or tools. The SERVICE PROVIDER supplies the technical integration architecture (MCP servers or clients) but assumes no liability for the autonomous behavior of third-party models that consume such context, except as provided in clause 4.2.
1.3. CLI tools. CLI tools are command-line applications that the SERVICE PROVIDER distributes for installation on the SERVICE RECIPIENT’s computers, servers or continuous integration environments, and that may interact with the SERVICE PROVIDER’s APIs, with the SERVICE RECIPIENT’s systems or with Third-Party Platforms. They are distributed through the channel indicated in the Service Order, such as a private package registry, a repository or an authenticated download. Unless the Service Order provides otherwise, their license is granted per User or per installation, in the number stated there.
1.4. Deployment modes. The Service Order will state whether the components are (a) hosted by the SERVICE PROVIDER; (b) self-hosted on the SERVICE RECIPIENT’s infrastructure; or (c) hybrid. For self-hosted components, the SERVICE RECIPIENT is responsible for their infrastructure, availability and security, and the availability levels in clause 6 apply only to components hosted by the SERVICE PROVIDER. CLI tools always run in the SERVICE RECIPIENT’s environments; the hosted services they consume are governed by the mode indicated.
1.5. Authorized users. The Services may be used by the employees and contractors of the SERVICE RECIPIENT and of the Affiliates named in the Service Order, as well as by the SERVICE RECIPIENT’s automated agents and continuous integration environments using service credentials in accordance with clause 3.2. Integrating the Services into products or services that the SERVICE RECIPIENT offers to third parties requires express authorization in the Service Order.
1.6. Documentation. The technical documentation published at https://docs.greyfieldstrata.com/ forms part of the Contract with respect to specifications, limits and integration requirements.
2. ACCEPTABLE USE AND CONSUMPTION LIMITS
2.1. Usage limits. Use of the APIs, MCP components and CLI tools is subject to the volume limits, call quotas, concurrency, bandwidth, Users and installations set out in the Service Order or in the technical documentation. API consumption by the CLI tools counts toward those limits.
2.2. Overages. When the SERVICE RECIPIENT exceeds the limits, the SERVICE PROVIDER may, as stated in the Service Order, (a) temporarily throttle or reject requests that exceed the limits; or (b) invoice the excess in accordance with clause 5.11 of the MSA.
2.3. Restrictions. In addition to the restrictions in clause 7.3 of the MSA, the SERVICE RECIPIENT undertakes not to: (a) reverse engineer, decompile or attempt to extract the source code of the SERVICE PROVIDER’s APIs, MCP architectures or CLI tools, except to the extent the law expressly permits; (b) use the Services in a way that degrades, overloads or interferes with the stability of the SERVICE PROVIDER’s servers; (c) circumvent the authentication mechanisms or the assigned tokens; (d) publish performance benchmarks without prior authorization; (e) transmit malicious code or unlawful content; (f) use the Services in breach of the usage policies of Artificial Intelligence model providers; (g) use the Services to make automated decisions that produce legal or similarly significant effects on natural persons without human review; or (h) redistribute the CLI tools or include them in software products or images distributed to third parties, unless authorized in the Service Order.
2.4. Suspension. Breach of this clause entitles the SERVICE PROVIDER to suspend the Services in accordance with clause 6.2 of the MSA.
3. SECURITY, TOKENS AND CREDENTIALS
3.1. Custody. The SERVICE PROVIDER will supply API keys, tokens or credentials to authenticate the components and the CLI tools. The SERVICE RECIPIENT is solely responsible for keeping them confidential within its systems, computers, environment variables and development workflows, including the credentials that the CLI tools store locally.
3.2. Individual credentials. Credentials will be assigned per User or application, may not be shared and must be rotated in accordance with the technical documentation. Credentials used in continuous integration environments or by automated agents will be issued as service credentials separate from those of Users.
3.3. Preventive revocation. The SERVICE PROVIDER may immediately revoke or suspend any credential if it detects anomalous traffic patterns or suspects a leak, in order to protect its infrastructure and the SERVICE RECIPIENT’s data. It will inform the SERVICE RECIPIENT as soon as possible and issue new credentials once the risk has been addressed.
3.4. Compromised credentials. The SERVICE RECIPIENT will immediately report any suspected compromise of its credentials. Charges arising from the use of compromised credentials before such notice will be borne by the SERVICE RECIPIENT.
3.5. Integrity of the CLI tools. The SERVICE RECIPIENT will obtain the CLI tools only from the official channel indicated in the Service Order and, when the SERVICE PROVIDER supplies a signature or checksum, will verify their integrity. The SERVICE PROVIDER will not be liable for versions obtained from other sources or modified by third parties.
4. ARTIFICIAL INTELLIGENCE AND AGENTS
4.1. Third-party models. The Service Order will identify the Artificial Intelligence model providers to which the Services connect and who supplies the credentials. When the SERVICE RECIPIENT supplies its own credentials, it will contract directly with the model provider, bear its costs and terms, and the data sent to the model will flow under that direct relationship. When access to the model is provided by the SERVICE PROVIDER, its costs will be invoiced as Third-Party Charges and the SERVICE PROVIDER will disclose the provider used and its data processing policies.
4.2. Agent permissions and actions. MCP connectors will be configured with the minimum permissions necessary and, by default, in read-only mode. Write, delete or execute capabilities will be enabled only upon a written request from the SERVICE RECIPIENT specifying their scope. The SERVICE RECIPIENT is responsible for approving such capabilities and for requiring human confirmation of sensitive actions. The SERVICE PROVIDER will not be liable for actions carried out by models or agents within the permissions enabled by the SERVICE RECIPIENT, unless caused by a defect in the SERVICE PROVIDER’s components. The foregoing also applies when the CLI tools are invoked by models or automated agents: the credentials assigned to them will have the minimum permissions necessary, and the SERVICE RECIPIENT is responsible for the commands executed within those permissions.
4.3. Malicious instructions. The SERVICE RECIPIENT acknowledges that models may be manipulated through instructions injected into the content of data sources. The SERVICE PROVIDER will apply reasonable mitigation measures in its components, without guaranteeing that such risk is entirely prevented. The SERVICE RECIPIENT will limit data sources and permissions to what is strictly necessary.
4.4. Outputs. Outputs generated by models may be inaccurate or incomplete and are not guaranteed. The SERVICE RECIPIENT will subject them to human review before using them in decisions, in production deployments or in communications with third parties, in accordance with clause 11.4 of the MSA.
4.5. Compliance. The SERVICE RECIPIENT is responsible for ensuring that its use of the Services and the sending of data to models comply with applicable regulation, including obtaining the authorizations of the Data Subjects of Personal Data.
5. INTELLECTUAL PROPERTY AND DATA
5.1. Components. The APIs, endpoints, technical documentation, MCP server architecture, connectors, CLI tools and base code used to provide the subscription are Provider Tools owned exclusively by the SERVICE PROVIDER. The perpetual license in clause 9.4 of the MSA does not apply to them.
5.2. Context and data. The data, schemas and fragments of information that pass through the MCP connectors, are sent to the APIs or are processed by the CLI tools are Recipient Data owned exclusively by the SERVICE RECIPIENT. The SERVICE PROVIDER will not use them to train models or for purposes unrelated to the technical performance of the subscription, and will handle them in accordance with clause 10 of the MSA and, where applicable, the DPA.
5.3. Technical logs. The SERVICE PROVIDER will retain technical logs (request metadata, errors and consumption) for thirty (30) calendar days for operations, security, billing and support purposes, after which it will delete or anonymize them, except for billing records it must keep by law. The content of the context and of the requests will not be stored beyond what is necessary for their processing, unless the Service Order provides for temporary storage functions.
5.4. CLI tool telemetry. The CLI tools may send the SERVICE PROVIDER technical usage data, such as version, commands used without their arguments, errors and performance, for support and improvement purposes, without including Recipient Data. The technical documentation will indicate what data is collected and how to turn off its sending. Telemetry will be disabled when the Service Order so indicates.
6. AVAILABILITY AND SERVICE LEVELS
6.1. Commitment. With respect to the production endpoints it hosts, the SERVICE PROVIDER commits to a monthly availability of ninety-nine percent (99.0%) under the standard plan and ninety-nine point five percent (99.5%) under the extended plan. The Service Order will state the plan contracted. The availability levels do not apply to the CLI tools, which run in the SERVICE RECIPIENT’s environments, but to the hosted endpoints they consume.
6.2. Calculation. Availability is calculated as the percentage of minutes in the measurement period during which the endpoint was available, excluding the events in clause 6.3. Under the standard plan, the measurement period comprises the minutes of the calendar month within support business hours and, under the extended plan, all minutes of the month. An endpoint is considered unavailable when it returns server errors or fails to respond for more than five (5) consecutive minutes, according to the SERVICE PROVIDER’s monitoring.
6.3. Exclusions. The following do not count as unavailability: (a) scheduled maintenance notified at least seventy-two (72) hours in advance, up to eight (8) hours per month; (b) emergency maintenance required for security reasons; (c) failures of Third-Party Platforms, including Artificial Intelligence model providers; (d) failures of the SERVICE RECIPIENT’s networks or systems; (e) throttling due to overages or suspension under the Contract; (f) force majeure; and (g) beta features.
6.4. Service credits. If monthly availability falls below the commitment, the SERVICE RECIPIENT will be entitled to the following credits on the monthly fee of the affected Service:
| Standard plan | Extended plan | Credit |
|---|---|---|
| Below 99.0% and at or above 98.0% | Below 99.5% and at or above 99.0% | 5% |
| Below 98.0% and at or above 96.0% | Below 99.0% and at or above 97.0% | 10% |
| Below 96.0% | Below 97.0% | 25% |
Credits must be requested within thirty (30) calendar days after the end of the month and will be applied to the next invoice; they are not payable in cash except upon termination of the Contract. Credits are the exclusive remedy in accordance with clause 12.6 of the MSA.
6.5. Repeated failure. If availability is below 96.0% under the standard plan, or below 97.0% under the extended plan, for three (3) consecutive months or four (4) months within any twelve (12) month period, the SERVICE RECIPIENT may terminate the affected Service without penalty, with a pro rata refund of amounts prepaid and unused.
7. SUPPORT
7.1. Plans. Support will be provided through the email address soporte@greyfieldstrata.com. Under the standard plan, support is provided during business hours, Monday to Friday, 8:00 to 18:00, Colombia time, excluding public holidays; incidents affecting the availability of hosted production endpoints will be responded to within four (4) business hours and other requests within one (1) business day. Under the extended plan, incidents affecting that availability will be handled on a 24x7 basis, with a response within two (2) hours.
7.2. Measurement rules. A response means the first diagnosis issued by a person on the SERVICE PROVIDER’s team, not the automatic acknowledgment of receipt. The count is suspended while waiting for information or actions from the SERVICE RECIPIENT or for action by a third party, including Artificial Intelligence model providers.
7.3. CLI tools. For the CLI tools, support covers the versions supported under clause 8 and the operating systems indicated in the technical documentation.
8. VERSIONS, CHANGES AND DEPRECATION
8.1. Versioning. The APIs and the CLI tools are identified by versions. The SERVICE PROVIDER will maintain support for the current major version and for at least one (1) previous major version.
8.2. Compatible changes. The SERVICE PROVIDER may introduce backward-compatible changes, such as new endpoints or optional fields, without prior notice.
8.3. Breaking changes and deprecation. Breaking changes will be notified in accordance with clause 15.3 of the MSA and the deprecation of versions in accordance with its clause 15.4, except when they are required for security reasons or imposed by a third party, in which case they will be notified as far in advance as possible.
8.4. Updating the CLI tools. The SERVICE RECIPIENT will keep the CLI tools on a supported version. The SERVICE PROVIDER may require an update to a version that fixes a security vulnerability, and unsupported versions may stop connecting to the SERVICE PROVIDER’s services.
9. BETA FEATURES
Features identified as beta, preview or experimental are offered as is, without service levels, may be modified or discontinued at any time and must not be used in production environments unless the SERVICE RECIPIENT expressly assumes that risk.
10. THIRD-PARTY COMPONENTS
Third-party and open-source components included in the Services are governed by their respective licenses, in accordance with clause 9.7 of the MSA.
11. EFFECTS OF TERMINATION
Upon termination of the subscription: (a) the SERVICE PROVIDER will revoke the credentials and end access to the Services; (b) technical logs will be deleted in accordance with clause 5.3 and Recipient Data in accordance with the DPA and clause 10.7 of the MSA; and (c) the SERVICE RECIPIENT will uninstall from its computers and environments the self-hosted components and the SERVICE PROVIDER’s CLI tools within fifteen (15) calendar days and, upon request, certify so in writing.