MIT vs AGPL-3.0-only
The two ends of the range, for when the question is simply "how bad is this".
Can you use them, and where?
They differ in 4 of the 5 ways you can ship software.
- Hosted SaaS: MIT is no obligation, AGPL-3.0-only is obligation triggered. AGPL-3.0-only section 13 requires that users interacting with a modified version over a network be offered the corresponding source of the whole work. Your distribution model is hosted SaaS, which triggers that obligation. This is the clause that makes AGPL behave differently from GPL for hosted services.
- Distributed binary: MIT is no obligation, AGPL-3.0-only is obligation triggered. AGPL-3.0-only carries the GPL-3.0 copyleft terms it is built on: distributing a work that incorporates it requires licensing the whole work under the same terms with corresponding source made available. Your distribution model is distributed binary or application, which is distribution and triggers that obligation. Section 13 additionally extends this over a network, so hosting the same code would not avoid it.
- On-premises delivery: MIT is no obligation, AGPL-3.0-only is obligation triggered. AGPL-3.0-only carries the GPL-3.0 copyleft terms it is built on: distributing a work that incorporates it requires licensing the whole work under the same terms with corresponding source made available. Your distribution model is software delivered to a customer environment, which is distribution and triggers that obligation. Section 13 additionally extends this over a network, so hosting the same code would not avoid it.
- Published library: MIT is no obligation, AGPL-3.0-only is obligation triggered. AGPL-3.0-only carries the GPL-3.0 copyleft terms it is built on: distributing a work that incorporates it requires licensing the whole work under the same terms with corresponding source made available. Your distribution model is a published library, which is distribution and triggers that obligation. Section 13 additionally extends this over a network, so hosting the same code would not avoid it.
Side by side
Runtime dependency, dynamically linked. A build-time-only dependency reaches no user and carries no distribution obligation, whichever license it uses.
| How you ship | MIT | AGPL-3.0-only | |
| Hosted SaaS |
No obligation |
Obligation triggered |
They differ here |
| Distributed binary |
No obligation |
Obligation triggered |
They differ here |
| On-premises delivery |
No obligation |
Obligation triggered |
They differ here |
| Internal use only |
No obligation |
No obligation |
Same |
| Published library |
No obligation |
Obligation triggered |
They differ here |
MIT
The most widely used permissive license. It grants nearly unrestricted use in exchange for keeping the copyright notice and license text with the software. There is no source-disclosure requirement and no patent clause.
Full obligations for MIT
AGPL-3.0-only
The one that catches SaaS companies. Section 13 extends copyleft across the network: if users interact with a modified version remotely, they must be offered the corresponding source of the whole work. The GPL "hosted service is not distribution" reasoning does not apply here.
Full obligations for AGPL-3.0-only
LicenseGuard reports information derived from published license texts and dependency manifests.
It is not legal advice and using it does not create an attorney-client relationship.
Results reflect license metadata as declared; they do not identify every obligation or violation.
Consult qualified counsel for decisions that matter.
Listed in the
official MCP registry,
on Glama
and on Smithery.
Source on GitHub (Apache-2.0).