I run an automated daily observatory here, wit Caddy logs piped into DuckDB, enriched through Censys, and summarized by a model. One of the things it does is flag user agents that don’t fit any existing classifier rule. Most of the new entries are just noise: random scanners, stale crawler strings, the occasional Log4Shell probe, etc. Yesterday’s run had one that was moderatly interesting: IronFountain-Leads/1.0 (+https://www.ironfountain.com). It was polite, making just two requests from one IP, and if their intent was to pique the interest of folks who do look at their site logs, it sure worked this time.
Iron Fountain bills itself as “Modern hosting. Built to flow.” The copy on the homepage is thick with words like “flow” and “conversation” and “your own ChatGPT or Claude account.” That sounds like another AI-washed static host charging extra for a chat widget — a burgeoning category that I’ve been mentally filing alongside vibe-coded landing pages and “Notion for [thing]” startups. There is, however, a bit more substance to site site than that.
The product itself is fairly ordinary static hosting – CDN, global edge, automatic HTTPS, forms with a private submissions inbox (i.e., the usual) – priced purely on bandwidth. The free Spring tier gives you 1 GB per month and one site, the $11/month Flow tier steps that to 10 GB with 20 revision slots and monthly snapshots, and the $18/month Cascade tier starts at 50 GB and goes up to 2,500 GB if you need a custom quote. There is no overage fees on paid plans, and you get one grace month at double your allowance before hosting pauses. The aforementioned “revision” model is having staging and production on separate environments, each with their own history, and a published revision is an explicit promotion action vs. an automatic push.
Every plan, including the free one, includes MCP and API access. You can point a Claude session or a ChatGPT plugin at your sites and ask it to read files, make changes, save a draft revision to staging, and then publish when you’re ready. The permission model is per-connection OAuth scopes, so you can grant an AI access to specific organizations or specific sites without handing it the keys to everything. The premise underlying Iron Fountain’s offering is that AI makes edits cheap enough that review and rollback become the scarce things. They productized staging, publish, and undo, while other/similar services tend to productize the editing experience. The AI connector is bundled since you BYOModel and you’re ultimately being charged for the bandwidth you consume vs the API calls hitting their service.
If you want to wire up the MCP connector, the config looks like this for a custom client:
"fountain": {
"type": "http",
"url": "https://app.ironfountain.com/mcp/hosting",
"auth": {
"type": "oauth",
"credentialId": "mcp_oauth:profile:default:https://app.ironfountain.com/mcp/hosting",
"tokenUrl": "https://app.ironfountain.com/oauth/token",
"clientId": "31010cf2-0660-478c-90d4-abf4857a9bbe",
"resource": "https://app.ironfountain.com/mcp/hosting"
},
"oauth": {
"clientId": "31010cf2-0660-478c-90d4-abf4857a9bbe"
}
}
The connector address is https://app.ironfountain.com/mcp/hosting and it uses OAuth authorization code flow with S256 PKCE and dynamic client registration, so you don’t need to create an API key or paste a secret anywhere. For Claude on the web, there’s a direct link that prefills the connector setup form. For Claude Code from the terminal:
claude mcp add --transport http --scope user ironfountain https://app.ironfountain.com/mcp/hosting
After that, /mcp, select ironfountain, complete the browser auth, approve which organizations it can see, and you’re done. The tool set is extensive – list_sites, read_files, save_revision, publish_revision, rollback_site, pin_revision, forms management, bandwidth reporting – enough that you could run a site entirely through an agent session if you wanted to.
The full docs cover the REST API which is the route to go if you’d rather wire up a script than route through an LLM/agent. API keys are per-org, never expire by default, and have the same permission scopes as the MCP connector. The workflow is the same either way: read the current revision, apply changes against a known base_revision_id, publish when you’re satisfied, and every prior revision stays available to roll back to while your plan’s retention keeps it.
I don’t have a site running on it yet (only did one test post), but the model is clean enough that I may use it for some side shenanigans. If the lead bot shows up in your logs, now you know what it is. However, you can get (at least at the time of this post — never know what the greedy billionaire-driven fake chipocalpse is going to do to prices) cheaper montly VPS hosting with almost no constraints, and often with a one-click “droplet” site set up button.
Sadly, the free tier and posting automation makes this a great service for phishing sites and malware/C2.