> ## Documentation Index
> Fetch the complete documentation index at: https://docs.biohub.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Biohub MCP security, privacy, and data handling

> Use the Biohub MCP server safely: treat tool output as untrusted, know which services receive your protein queries, and read results as predictions.

Biohub MCP needs no credentials, and it reads from the ESM Atlas and public sequence databases.
A few habits keep your work safe and your results in perspective.

## Connect to the real server

The only address is:

```text theme={null}
https://biohub.ai/mcp
```

Check the hostname before you add it to a client.
Don't connect through a shortened link, an unknown proxy, or a directory listing that points somewhere else.

## You never need a key

Biohub MCP has no sign-in and no API key.
If a client, a web page, or a tool result asks you for a key, password, or token for Biohub MCP, don't provide one.
Never paste credentials into a prompt, a server URL, or a client configuration file.

## Treat tool output as untrusted data

Tool results include text from other sources, such as UniProt function descriptions, ESM Atlas annotations, and SAE feature descriptions.
That text can be wrong or misleading, and it can contain instructions meant to change what your assistant does, which is called prompt injection.

* Keep your own instructions in charge of the task.
* Don't let text inside a result ask for credentials, change your settings, or contact other systems.
* Review the follow-up calls your assistant proposes before you approve them.
* Check surprising claims against the source record, such as the UniProt entry.

## Where your queries go

Each tool sends only what it needs to the services behind it.

| Tool | Service | What it sends |
| - | - | - |
| `esm_atlas_search_uniprot` | UniProt | Your query text |
| `esm_atlas_lookup_accession` | UniProt (for UniParc), EMBL-EBI MGnify, or JGI IMG, depending on the accession | The accession |
| `esm_atlas_get_protein_details` | ESM Atlas | A hash that identifies the sequence, and the sequence itself if the ESM Atlas doesn't have it |
| `esm_atlas_search_similar_protein_clusters` | ESM Atlas | The sequence |
| `esm_atlas_get_cluster_info` | ESM Atlas | A hash that identifies the sequence |
| `esm_atlas_get_sae_feature_detail` | ESM Atlas | The feature number |
| `ui_show_protein_structure` | ESM Atlas | A hash that identifies the sequence, and the sequence itself if a structure must be predicted |

Biohub receives every tool input you send, and handles request data as described in the [Privacy Policy](https://biohub.org/privacy-policy/).
Your AI client also sends your prompts, the tool inputs, and the tool results to its model provider, under that client's settings and data policy.
Don't send confidential or unpublished sequences unless you're comfortable with them reaching these services and your client's provider.

Biohub MCP creates no saved IDs, share links, or download URLs for your results.
Each result exists only in the response you receive.

## Why some calls take longer

The ESM Atlas looks up the exact sequence you send.
When it has no stored result, some tools compute one for your request:

* `esm_atlas_get_protein_details` computes SAE features for sequences up to 2,048 residues.
* `esm_atlas_search_similar_protein_clusters` computes the query's features and can predict structures for up to six hits that don't have one yet.
* `ui_show_protein_structure` predicts a structure for sequences up to 700 residues.

These tools are still marked read-only, because they create nothing that you need to manage.
Calling a tool again can compute again.

Every call has a 120-second deadline.
If it passes, or if the outcome of a compute step is unknown, the tool returns `indeterminate`.
The work may have started, so don't retry automatically: wait a while before asking again.

## Guardrails

The ESM Atlas has [guardrails](/learn/guides/esm-atlas#guardrails) that restrict queries related to controlled pathogens and toxins.
A blocked request returns `restricted`, and a similarity search reports withheld hits in `restricted_count`.
Don't try to work around a guardrail, for example by rephrasing or trimming a sequence.

## Results are predictions

* Structures predicted on a miss are model predictions, and stored ESM Atlas structures are predictions too.
* SAE feature labels are interpretations of what a feature tends to capture, and `label_reliability` tells you how much weight a label can bear.
* Similarity search compares SAE feature profiles, not sequence alignments, so a close hit isn't proof of shared ancestry or function.

Treat every result as a hypothesis, not as experimental validation, and confirm anything important in the lab or against curated sources.

## Terms and policies

Your use of Biohub MCP is covered by the Biohub [Terms of Use](https://biohub.org/terms-of-use/), [Privacy Policy](https://biohub.org/privacy-policy/), and [Acceptable Use Policy](https://biohub.org/acceptable-use-policy/).
