Hosted vs self-hosted MCP: who should run your server?

Choose hosted MCP when you want a provider to operate the service. Choose self-hosted MCP when you need control over its infrastructure or network placement and can maintain it. Either model still needs identity checks, tool permissions, and a clear policy for data sent to AI clients.

What do hosted, self-hosted, and local MCP mean?

A hosted MCP server runs as a service operated by a provider. A self-hosted MCP server runs on infrastructure your organization operates. A local MCP server runs on a person’s computer, often as a process launched by the AI client. A self-hosted server can also be remote: remote describes how the client connects, not who owns the infrastructure.

Compare the operational tradeoffs

DecisionHosted MCPSelf-hosted MCP
Service operationThe provider runs and updates the service.Your team owns hosting, updates, monitoring, and recovery.
Network accessConfirm which API endpoints the service can reach.You choose network placement and outbound access.
Team permissionsEvaluate the provider’s user, group, and tool controls.Build or configure those controls in your deployment.
CredentialsReview provider storage, ownership, rotation, and revocation.Your team operates secret storage and credential lifecycle.
Data handlingReview both the MCP provider and the AI client.Review your server, its dependencies, and the AI client.
CostService subscription plus separate AI and app costs.Infrastructure, engineering, support, and separate AI and app costs.

When is hosted MCP a good fit?

Hosted MCP fits teams that want shared access to business apps without operating another integration service. Check supported operations, client compatibility, permission controls, audit history, and the recovery path when a provider connection expires. A hosted endpoint alone does not establish any of these controls.

Stackyapper is a hosted MCP access layer. An administrator connects apps, grants tools to workspaces, groups, or people, and reviews activity in Audit. Stackyapper checks access again before each request and keeps connected-app credentials out of AI clients. See how it works and the current app directory.

When is self-hosted MCP a better fit?

Self-hosting can fit an organization with private-network requirements, custom server behavior, or infrastructure policies that exclude an external service. Budget for authentication, per-tool authorization, secret management, provider changes, monitoring, and incident response. Confirm that the chosen AI clients can reach and authenticate to your deployment.

Does self-hosting keep all data inside the company?

No. Self-hosting controls where the MCP server runs. If it returns information to an external AI client, that information leaves the server and is subject to the client’s data policies. Map the whole path from the business system through the MCP server to the AI client before deciding.

What should you test before choosing?

Use the same small test for both options: give one person one read tool, retrieve a known record, check the activity record, then remove the grant and confirm the next request is denied. Add a second app only after the first connection works. Use the business access-control checklist to evaluate the remaining controls.

Sources and next steps