AGPL-3.0-only vs MPL-2.0
Often lumped together as "copyleft to avoid". They are not remotely the same obligation.
Can you use them, and where?
They differ in 4 of the 5 ways you can ship software.
- Hosted SaaS: AGPL-3.0-only is obligation triggered, MPL-2.0 is no obligation. AGPL-3.0-only section 13 requires that users interacting with a modified version over a network be offered the corresponding source of the whole work. Your distribution model is hosted SaaS, which triggers that obligation. This is the clause that makes AGPL behave differently from GPL for hosted services.
- Distributed binary: AGPL-3.0-only is obligation triggered, MPL-2.0 is no obligation. AGPL-3.0-only carries the GPL-3.0 copyleft terms it is built on: distributing a work that incorporates it requires licensing the whole work under the same terms with corresponding source made available. Your distribution model is distributed binary or application, which is distribution and triggers that obligation. Section 13 additionally extends this over a network, so hosting the same code would not avoid it.
- On-premises delivery: AGPL-3.0-only is obligation triggered, MPL-2.0 is no obligation. AGPL-3.0-only carries the GPL-3.0 copyleft terms it is built on: distributing a work that incorporates it requires licensing the whole work under the same terms with corresponding source made available. Your distribution model is software delivered to a customer environment, which is distribution and triggers that obligation. Section 13 additionally extends this over a network, so hosting the same code would not avoid it.
- Published library: AGPL-3.0-only is obligation triggered, MPL-2.0 is no obligation. AGPL-3.0-only carries the GPL-3.0 copyleft terms it is built on: distributing a work that incorporates it requires licensing the whole work under the same terms with corresponding source made available. Your distribution model is a published library, which is distribution and triggers that obligation. Section 13 additionally extends this over a network, so hosting the same code would not avoid it.
Side by side
Runtime dependency, dynamically linked. A build-time-only dependency reaches no user and carries no distribution obligation, whichever license it uses.
| How you ship | AGPL-3.0-only | MPL-2.0 | |
| Hosted SaaS |
Obligation triggered |
No obligation |
They differ here |
| Distributed binary |
Obligation triggered |
No obligation |
They differ here |
| On-premises delivery |
Obligation triggered |
No obligation |
They differ here |
| Internal use only |
No obligation |
No obligation |
Same |
| Published library |
Obligation triggered |
No obligation |
They differ here |
AGPL-3.0-only
The one that catches SaaS companies. Section 13 extends copyleft across the network: if users interact with a modified version remotely, they must be offered the corresponding source of the whole work. The GPL "hosted service is not distribution" reasoning does not apply here.
Full obligations for AGPL-3.0-only
MPL-2.0
File-level weak copyleft. Modifications to MPL-licensed files must be released under MPL, but your own files in the same project are unaffected. This makes it unusually easy to combine with proprietary code.
Full obligations for MPL-2.0
LicenseGuard reports information derived from published license texts and dependency manifests.
It is not legal advice and using it does not create an attorney-client relationship.
Results reflect license metadata as declared; they do not identify every obligation or violation.
Consult qualified counsel for decisions that matter.
Listed in the
official MCP registry,
on Glama
and on Smithery.
Source on GitHub (Apache-2.0).