The most consequential pair for anyone running a hosted service. They diverge on exactly one thing.
They differ in 1 of the 5 ways you can ship software.
Runtime dependency, dynamically linked. A build-time-only dependency reaches no user and carries no distribution obligation, whichever license it uses.
| How you ship | AGPL-3.0-only | GPL-3.0-only | |
|---|---|---|---|
| Hosted SaaS | Obligation triggered | No obligation | They differ here |
| Distributed binary | Obligation triggered | Obligation triggered | Same |
| On-premises delivery | Obligation triggered | Obligation triggered | Same |
| Internal use only | No obligation | No obligation | Same |
| Published library | Obligation triggered | Obligation triggered | Same |
The one that catches SaaS companies. Section 13 extends copyleft across the network: if users interact with a modified version remotely, they must be offered the corresponding source of the whole work. The GPL "hosted service is not distribution" reasoning does not apply here.
Full obligations for AGPL-3.0-only
Strong copyleft, with added anti-tivoization and patent-retaliation terms over v2. Like v2, its obligations attach to distribution, not to operating a hosted service.
Full obligations for GPL-3.0-only
Want to know which of these your project actually depends on?
Check your whole manifest →LicenseGuard reports information derived from published license texts and dependency manifests. It is not legal advice and using it does not create an attorney-client relationship. Results reflect license metadata as declared; they do not identify every obligation or violation. Consult qualified counsel for decisions that matter.
Listed in the official MCP registry, on Glama and on Smithery. Source on GitHub (Apache-2.0).