Last updated: October 4, 2026
Before connecting an MCP service you should know what it can access, how your key is protected, and what we log. This is how the RegAI Legal MCP (https://mcp.regai.tw/mcp) is designed.
The MCP server only searches public laws (the Ministry of Justice's Laws & Regulations Database) and court decisions (published by the Judicial Yuan).
Every tool is read-only: it never changes data, never connects to other outside services, and has no access to documents you uploaded to the RegAI web app, your chat history, or any other account data. Each tool is marked read-only (readOnlyHint) and non-destructive (destructiveHint: false) per the MCP standard.
Tools return official public text — statutes, court decisions, and the parties' statements quoted in those decisions — not arbitrary web content. The server also tells AI agents explicitly that returned text is material to cite, not instructions.
Because the tools can't write anything or reach any other service, instruction-like text inside a document can't be used to change data or send information anywhere through this service. We still recommend keeping "confirm before running tools" switched on in your AI assistant — a good habit with any MCP service.
Each account has one API key (regai_live_…, 256 random bits). The server matches keys by their hash; so that you can view your key again after signing in, it is also stored encrypted with AES-256-GCM. You can regenerate your key (the old one stops working immediately) or revoke it at any time on your account page.
Send the key in a header: Authorization: Bearer YOUR_KEY. The ?key= URL parameter is kept only for assistants whose connector screen accepts nothing but a URL; URLs can linger in app settings and logs, so if a key was ever shared or exposed, regenerate it right away.
AI assistants that support OAuth (such as Claude and ChatGPT) can connect by signing in with your RegAI account, with no key to copy. Sign-in happens on regai.tw; the assistant never sees your email code or LINE login. The consent screen shows which app is asking and where you'll be sent back, and nothing is granted until you click Allow.
After you allow it, the app's access token (rgat_…) lasts 1 hour, works only for the RegAI Legal MCP and is accepted only in a header. Its refresh token (rgrt_…) lasts 90 days and is replaced every time it's used. If a refresh token that was already used shows up again, we treat it as leaked and revoke that app's access at once. Tokens are stored only as hashes.
The flow follows the MCP authorization specification (OAuth 2.1, built on OAuth 2.0): PKCE (S256) is required, the return address must exactly match one the app registered, and tokens are bound to this service. You can disconnect any app at any time under "Connected apps" on your account page, effective immediately.
The service is served over HTTPS; plain HTTP is redirected to HTTPS. Always use the https:// address so your key is never sent unencrypted before the redirect.
Every account has rate limits and a monthly quota to prevent abuse, and accounts can be suspended for violating the Terms.
For billing, quotas and security we record the time, tool type and number of each call.
For apps connected by signing in, we keep the app's name and address, when it was connected and last used, and hashes of its tokens, to show and manage your connections.
We don't log the content of your queries. Server logs keep only a keyed hash of a query — a fingerprint that can't be read back as text — for troubleshooting, such as spotting the same query failing repeatedly. Error messages never return internal system details. See our Privacy Policy.
If you find a security concern, please email security@regai.tw and we'll get back to you promptly.