> For the complete documentation index, see [llms.txt](https://mcp-test-kitchen-docs.cakewalk.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mcp-test-kitchen-docs.cakewalk.security/reference/data-handling.md).

# Data Handling

What the server records when you point a client at it, what it redacts and how long it keeps anything.

You are pointing a real client at a service somebody else runs, so here is what that service keeps.

***

## What Is Recorded

One entry per request: the method, the phase, the duration, the HTTP status, whether your client cancelled, the JSON-RPC request id, the protocol revision your client declared, the scenario that was active, the params your client sent and the email you signed in with.

Entries are scoped to the account that made them. You see your own and nobody else's.

***

## Headers Are Redacted by Default

Six headers are recorded with their real values.

```
accept
content-type
content-length
host
user-agent
mcp-protocol-version
```

Every other header is stored with its value replaced by `[redacted]`. The header name is kept so you can see what your client sent; the value is not.

Your `Authorization` header falls outside the allowlist, so your token is never written to the record.

***

## Params Are Summarized

The server does not keep the params object your client sent. It keeps a summary, and what the summary holds depends on the method.

| Method          | What is kept                                                                        |
| --------------- | ----------------------------------------------------------------------------------- |
| `initialize`    | The protocol version, and your client's name and version                            |
| `tools/call`    | The tool name only                                                                  |
| Everything else | The params object, if it is an object of 512 characters or fewer. Otherwise nothing |

**Tool arguments are never recorded.** A `tools/call` summary holds the name of the tool and nothing else, so the `message` argument on `run_configured_test_scenario` and the arguments you pass to the `compat.sdk_v2` tools do not reach the record.

The one case to keep in mind is the third row. Params on other methods are stored verbatim when they are small enough, so a resource URI or a prompt argument does land in the record.

***

## Your Token

Your personal access token is encrypted at rest and returned to you only through the console. **Regenerate** replaces it and the previous token stops working immediately.

***

## Retention

Entries are deleted after seven days. A background job runs every fifteen minutes and removes anything past the cutoff.

Nothing warns you before an entry expires, so pull anything you want to keep into your own tracker while it is there.

***

## Deleting Your Data

Two controls, with different scopes.

**Clear all** in the Messages pane deletes your observations and nothing else. Your token and your scenario selection survive.

**Erase everything** deletes your observations, your saved scenario selection and your token, and terminates your active sessions. It runs as a single transaction and cannot be undone. You keep console access, and you receive a new token the next time you ask for one.

***

## Where It Runs

The server is hosted, and the source is not public today. Everything above describes the hosted service.
