Apache 2.0Pre-1.0 · managed cloud and self-hosted previewsRead the open-source commitment

Open-source commitment

The whole MCP-native roadmap stays open.

LiteMCP Composer is licensed under Apache 2.0. Current code and future security, identity, policy, audit, high-availability, and on-prem work are intended to mature in public—not behind closed feature gates.

Project covenant

Portable by architecture and by policy.

These boundaries are part of the product definition and should be reviewable in source, tests, and release artifacts.

01

One open roadmap

Available, preview, and planned gateway, registry, policy, identity, audit, and deployment work stays public.

02

No license server

Self-hosted operation never requires a cloud account, activation server, or call-home path.

03

Portable state

Configuration export exists in preview; complete cross-target import and execution remains an acceptance gate.

04

Open compatibility

SDKs and gateway fixtures are public; the connector and named-client compatibility matrix is planned.

05

Visible security process

The disclosure policy and limitations are public; signed releases, revocation feeds, and supported release lines remain planned.

06

Optional telemetry

The current slice has no telemetry exporter; any future self-hosted export must be opt-in and documented field by field.

Governance

Trust needs a public operating record.

The project is being established with a public roadmap, contribution process, security policy, release notes, and a maintainer path. Foundation governance can be evaluated after meaningful ecosystem participation exists.

  • 01
    Public roadmap

    Priorities, validation gates, and known limitations are visible.

  • 02
    Reviewable releases

    Signed manifests, checksums, SBOMs, and rollback notes are release gates, not current artifacts.

  • 03
    Contributor credit

    Connector and core contributors retain visible attribution and a maintainer path.

  • 04
    No payload economy

    Diagnostics do not require customer tool arguments or responses.

Inspect the architecture, then help prove the exit test.

Portability is achieved only when a cloud-exported configuration executes on the self-hosted target without proprietary conversion; that live test is still pending.