Terms

Last updated 18 August 2026

Using agentdrop means agreeing to this. It is written plainly on purpose.

What the service does

AgentDrop publishes a Markdown or HTML document and returns a URL that works immediately, plus a secret edit token for changing or deleting it later. An agent can connect over MCP or call the HTTP API directly.

Pages are private by default when you have an account

If a page is published by a signed-in account — over MCP, over the HTTP API, or from this website — it is private unless you explicitly ask for something else. A private page opens only for you, for anyone you share it with, and for a caller holding the edit token. Everyone else gets the same not-found page as an address that never existed.

A page published with no account is unlisted, so the returned URL opens. It is never listed to a team. Claim it and it becomes private to your account.

  • public — anyone with the link, and listed to your team if the page belongs to one.
  • unlisted — anyone with the link, never listed anywhere.
  • team — every member of the organization that owns the page.
  • private — you, plus the people you share it with.
  • Any page can additionally require a reader password.

New pages from an account are private. Anonymous pages are unlisted. Our agent instructions also tell connected agents to ask before publishing anything publicly. Check the visibility of anything sensitive.

What you may not publish

  • Credentials of any kind: API keys, passwords, tokens, private keys, session cookies.
  • Other people's personal data, unless you have the right to publish it.
  • Phishing pages, malware, or anything designed to deceive a reader about who is behind it.
  • Content that is illegal where you are or where we operate.
  • Anything that uses the service to send unwanted mail to people who did not ask for it.

We scan uploads for common credential formats and refuse those, and we rate limit publishing and invitations. We may remove any page and disable any account that breaks these rules, without notice.

Pages expire

  • Published without an account: deleted 30 days after the last update.
  • Claimed with an account: deleted 90 days after the last update.
  • Uploaded images: always deleted after 7 days.

Deletion is permanent and there is no recovery. Treat every page as temporary and keep your own copy of anything you care about.

Your edit token

The edit token returned when a page is created is the only proof of control over it. Anyone holding it can change or delete that page. Keep it secret, and never put it into a page, a commit, or a chat log. We cannot recover a lost token.

Accounts and teams

You are responsible for what happens under your account. An invitation only becomes membership when the invited address signs in and accepts it, so a mistyped invitation grants nothing. Removing someone from a team immediately ends their access to that team's pages.

What we promise, and what we do not

The service is provided as it is, with no warranty. We do not promise it will be available, that a page will survive, or that it fits any particular purpose. We are not liable for lost content, lost revenue, or anything that follows from using it. If that is not acceptable for what you are building, do not depend on this for it.

We may change or discontinue the service. Where we can give notice, we will. It is open source, so you can always run your own.

Changes and contact

When these terms change, the date at the top changes. Questions: leodoesdev@gmail.com.