Policies
How keys and limits work on the MCP server, what you can rely on, how changes are announced and what is logged about your tool calls.
The server accepts only MCP keys, created in the MCP console and sent as Authorization: Bearer YOUR_API_KEY or X-API-Key: YOUR_API_KEY. Data API and widget keys are refused with 401. Creating or rotating a key needs a verified email address; the key is shown once, can expire after 30, 90 or 365 days or never, and Free, Starter and Pro allow 2, 5 and 10 live keys.
Each plan has a monthly number of tool calls - Free 2,500, Starter 50,000, Pro 250,000 - and a burst limit of 30, 60 or 120 requests a minute. The burst limit counts every request to /mcp; the monthly quota counts only tool calls, including calls that end in an error such as an unknown coin. The month is the calendar month in UTC on Free and runs from your renewal day on paid plans.
Over the monthly quota, a tool answers rate_limited (HTTP 429) with the limit, usage and reset time; over the burst limit, the request itself gets HTTP 429. A tool your plan does not include answers plan_required naming the plan that unlocks it.
The contract is the tool names, their inputs and their results. All tools are read-only: none can change your account or any data. Every tool answers from the Data API v1, so results follow its rules - decimal-string prices, rates and supplies, and the same validation - and come as JSON text plus structuredContent. Errors read code (HTTP status): message.
The server reports itself as Bitculator 1.0.0 in serverInfo and in /.well-known/mcp/server-card.json, and answers in the MCP protocol version the client asks for, from 2024-11-05 to 2025-11-25.
These never happen without notice:
These can happen at any time and are logged in the changelog:
A tool or input scheduled for removal is announced in the changelog and its description says so from that day. Removal happens no sooner than six months after the announcement.
Each tool call is recorded with your account, the key, the tool's data endpoint and the billing period, plus a daily count, to enforce your quota and show your usage. These records are kept for 12 months. The JSON-RPC messages themselves and your client's details are not stored.
When a tool fails with a server error, part of the internal response is written to the server log so the error can be fixed.
If you believe you have found a security vulnerability in bitculator.com, the Data API, the MCP server or the SDKs, email contact@bitculator.com with the affected URL or endpoint, steps to reproduce and the impact you see. You will hear back within three business days.
Please keep the report private until it is fixed, do not access or alter data that is not yours, and do not run denial-of-service or automated scanning against production. Reports made in good faith under these terms will not be met with legal action. There is no paid bounty programme; credit is given on request.
The same contact is published machine-readably at /.well-known/security.txt (RFC 9116).
Live component status, open incidents and the last 30 days of outages are on the status page and at /status.json.