KeibiDrop MCP Server
io.github.KeibiSoft/keibidrop
P2P encrypted folder sync between machines—no cloud, only bytes you read move across the network.
What is the KeibiDrop MCP server?
KeibiDrop is an MCP server that enables two agents on different machines to share an encrypted folder peer-to-peer, with no cloud storage and end-to-end encryption. Files appear as a local folder (via FUSE) or can be transferred directly, and the relay server never reads your data.
KeibiDrop lets you mount another computer's files as a local folder on yours, or transfer files directly between machines. It uses post-quantum encryption, works through firewalls automatically, and only transfers the bytes you actually read. Perfect for remote work, DFIR triage, video editing on shared storage, or agents collaborating across machines.
How to install KeibiDrop
Copy-paste configuration for popular MCP clients.
Tools & capabilities
Tools this server exposes to the agent.
kd start— Start the KeibiDrop daemonkd show fingerprint— Get your device fingerprint for pairingkd register— Register a peer by their fingerprintkd create— Create a new shared roomkd join— Join an existing shared roomkd add— Add a file or folder to sharekd list— List all shared fileskd pull— Download a file from a peer
Use cases
- Mount a remote NAS or GPU box's files locally and work on them in any app without downloading first
- Share large datasets between agents on different machines with automatic relay fallback through firewalls
- Perform remote DFIR triage by mounting evidence shares read-only and extracting only the artifacts you need
- Edit video or photos stored on a studio server from a laptop anywhere, with files syncing on-demand
- Run two AI agents on separate machines that collaborate by sharing encrypted folders via MCP
KeibiDrop MCP server FAQ
KeibiDrop is a peer-to-peer file-sharing tool that mounts another computer's files as a local folder (FUSE) or transfers them directly. It uses post-quantum encryption, requires no cloud, and the relay server cannot read your data.
Yes. The Go engine, CLI, and mobile bindings are open source under the Mozilla Public License 2.0. The Rust UI and mobile apps are proprietary but the tool is free to download and use.
Download the mcpb binary from the GitHub releases page, then add it to your MCP client config. Run `kdmcp install` to print the config snippet for your MCP client.
No. Pairing happens once via fingerprint exchange (same network is one click, remote is a code swap in any chat). No account, no cloud, no subscription.
Post-quantum hybrid key exchange (ML-KEM-1024 + X25519) with AES-256-GCM or ChaCha20-Poly1305, plus forward secrecy via periodic re-keying. Full details in Security.md.
Yes, Android is supported via a custom F-Droid repository. iOS is coming soon. macOS, Linux, and Windows are fully supported.
README (reference)
Source of truth, from the repository.
Another computer's files show up as a folder on yours. Open and edit them in your own apps, with nothing to download first.
- Open a 40 GB file and start working instantly. Your edits sync back.
- End-to-end encrypted (post-quantum). No cloud, and the relay never reads your files.
- Same network: one click. Over the internet: swap a code once, then save the contact.
- Their files become a real folder on your machine. Open, edit,
git clone, anything. - macOS, Linux, Windows, Android. iOS coming soon. Open source engine (MPL-2.0).
Get it: Mac · Windows · Linux · Android · every click, per computer
Three steps: install it on both computers. Connect once: same Wi-Fi, turn on the switch; anywhere else, send your code in any chat and paste theirs. Then drop a file in, or open their files as a folder. How to use it, with a short clip for each step. The clips as a YouTube playlist.
<p align="center"> <a href="https://www.youtube.com/watch?v=2fIOOnN9HhQ"> <img src="demo-photos/how-to-use.gif" alt="Connecting two computers with a code: Copy my code, paste it in a chat, paste the other code, press Connect on both sides. Click to watch the two minute video on YouTube." width="700"> </a> <br><sub>Copy your code, send it in any chat, paste theirs, both press Connect. <b>Every step, click by click.</b></sub> </p> <p align="center"> <img src="demo-photos/initial-screen.png" alt="KeibiDrop connection screen" width="700"> </p>| Direct Transfer | Virtual Folder (FUSE) |
|---|---|
| <img src="demo-photos/connected-in-direct-transfer-mode.png" alt="Direct transfer mode" width="450"> | <img src="demo-photos/connected-as-virtual-filesystem.png" alt="Virtual filesystem mode" width="450"> |
| Drag files in. Your peer saves what they need. | Peer files appear as a folder. Open in any app. |
| Finder | Terminal (git) |
|---|---|
| <img src="demo-photos/as-filesystem-accessible-from-finder.png" alt="Shared files in Finder" width="450"> | <img src="demo-photos/as-filesystem-git-ops-work.png" alt="Git on FUSE mount" width="450"> |
Install
macOS
brew tap keibisoft/keibidrop
brew trust keibisoft/keibidrop
brew install keibidrop
Linux (Debian/Ubuntu)
wget -O keibidrop.deb $(curl -s https://api.github.com/repos/KeibiSoft/KeibiDrop/releases/latest \
| grep -o 'https://[^"]*_amd64\.deb')
sudo apt install ./keibidrop.deb
Windows
choco install keibidrop
Or download from GitHub Releases.
Android
We host our own F-Droid repository. Open fdroid.keibisoft.com on your phone, scan the code, and check the fingerprint before you add it.
To add it by hand, use https://fdroid.keibisoft.com/fdroid/repo in F-Droid under Settings, Repositories. The fingerprint to check is on the same page.
Build from source
git clone https://github.com/KeibiSoft/KeibiDrop.git
cd KeibiDrop
make build-kd # CLI daemon
make build-cli # Interactive CLI
make build-rust # Desktop UI (needs Rust + Slint)
Quick start
Same network (LAN):
- Both peers launch KeibiDrop
- Devices discover each other automatically
- One click to connect
- Share files
Over the internet:
- Both peers launch KeibiDrop
- Copy your fingerprint and send it to your peer (Signal, Telegram, anything)
- Paste each other's fingerprints and connect
- Share files
Save a peer as a contact to skip the fingerprint exchange next time. On the same network, saved contacts connect with one click using pseudonyms.
It works through firewalls automatically. If direct connection fails, KeibiDrop falls back to an encrypted relay. No port forwarding, no router configuration.
Two modes
| Direct Transfer | Virtual Folder (FUSE) | |
|---|---|---|
| Speed | Up to ~660 MB/s | Up to ~276 MB/s |
| How it works | Add files, peer pulls them | Peer's files appear as a local folder |
| Setup | Nothing extra | Install macFUSE, fuse3, or WinFsp |
| Best for | Sending large files | Working on shared files, git repos |
How it works
- Peers exchange fingerprints (or discover each other on LAN)
- KeibiDrop finds the fastest path: LAN, direct IPv6, or encrypted relay
- Files transfer over an encrypted channel the relay cannot read
- Keys rotate automatically for forward secrecy
The encryption is post-quantum (ML-KEM-1024 + X25519) with AES-256-GCM or ChaCha20-Poly1305. Full protocol details in Security.md.
<details> <summary><strong>Three interfaces</strong></summary>
Desktop UI (Rust/Slint)
./keibidrop
Interactive CLI (terminal REPL)
./keibidrop-cli
Agent CLI (for scripts and AI agents, all output is JSON)
./kd start # Start daemon
./kd show fingerprint # Get your fingerprint
./kd register <peer-fingerprint> # Register peer
./kd create # Create room (or: kd join)
./kd add /path/to/file.zip # Share a file
./kd list # List shared files
./kd pull file.zip ~/Downloads/ # Download a file
</details>
<details>
<summary><strong>Configuration</strong></summary>
KeibiDrop reads ~/.config/keibidrop/config.toml. Environment variables override the config.
| Setting | Env var | Default |
|---|---|---|
| Relay server | KD_RELAY | https://keibidroprelay.keibisoft.com/ |
| Bridge relay | KD_BRIDGE | bridge.keibisoft.com:26600 |
| Save folder | KD_SAVE_PATH | ~/KeibiDrop/Received/ |
| FUSE mount | KD_MOUNT_PATH | ~/KeibiDrop/Mount/ |
| Inbound port | KD_INBOUND_PORT | 26431 |
| Disable FUSE | KD_NO_FUSE | false |
Post-quantum hybrid key exchange prevents future quantum computers from decrypting recorded traffic. Forward secrecy via periodic re-keying limits exposure if a session key is ever compromised.
By default, identity persists across sessions (so saved contacts keep working), encrypted with a per-install master key stored in the OS keychain (macOS Keychain Services, Linux Secret Service, Windows Credential Manager). Headless setups fall back to ~/.config/keibidrop/.master.key (mode 0600). Optional passphrase protection via Argon2id for users who back up config to the cloud. Incognito mode switches to ephemeral keys: a fresh keypair each session, anonymous, unlinkable, nothing written to disk.
Full protocol description: Security.md
</details>Troubleshooting
See TROUBLESHOOTING.md.
Contributing
See CONTRIBUTING.md.
License
Go engine, CLI, and mobile bindings: Mozilla Public License 2.0 (per-file copyleft)
Rust UI, mobile apps, and brand assets: Proprietary - see LICENSING.md
Desktop UI built with Slint
Built by KeibiSoft SRL.
By trade
Remote DFIR triage
Mount an evidence share read only across NAT and extract the artifact set you need, with no inbound port, native on Windows, and no kernel driver on the evidence machine. There is a write-up and a DFIR page.
Post-production handoff
<p align="center"> <a href="https://www.youtube.com/watch?v=k8b_6quIqx0"> <img src="demo-photos/resolve-nas-demo.gif" alt="DaVinci Resolve playing a clip that lives on a NAS 400 km away, then jumping to the next clip, which is there when the playhead lands on it. Click to watch the two minute demo on YouTube." width="700"> </a> <br><sub><b>How to edit in DaVinci Resolve, Premiere Pro or Final Cut while traveling.</b> Your footage stays on the studio NAS, you open it on demand from the app, no waiting for a download or an upload. Click for the two minute demo.</sub> </p>Mount the camera originals. No proxy transcode before the handoff, and no relink after it. The Resolve setup, step by step.
Datasets on a rented GPU box
Mount the workstation that holds the data. No bucket, and no upload before the first batch.
An always-on box: NAS, mini PC, home server
<p align="center"> <img src="demo-photos/nas-demo.gif" alt="Two terminals. Left: a container on a NAS prints its code and Peer connected. Right: a laptop adds the box as a contact, connects, lists the shared folder and hashes one photo through the mount" width="900"> </p>A session needs both machines online, and a NAS, a mini PC or a home server is online all the time. The container in docker/ runs the serving side on that box from plain Docker with the stock kernel. Your laptop mounts the folder from anywhere and reads on demand, so only the bytes a program reads cross the wire. In that run the box, a container on a server in Timisoara, served 161 files to a laptop in Bucharest; the laptop paired once, listed the folder and hashed one photo. Setup is one compose file, in the guide. An Unraid template is in docker/unraid/.
Photographers and editors
The raws and the footage stay on the box at the studio. The laptop mounts the folder, Lightroom or Resolve opens the files from the mount, and each file moves only when it is opened; a 1 MiB read out of a big file moves one 16 MiB block. The catalog stays on the laptop, as the post-production page and the video and audio guide describe. Set the share read only when the box is the archive and the laptop must change nothing.
Agents, and the data they work on
<p align="center"> <img src="demo-photos/agents-mcp-demo.gif" alt="Two agents pairing over MCP: the laptop offers a 2,184 file dataset in place, the gpu box lists it and reads shards off the mount" width="900"> </p>Two agents, one per machine, each driving a KeibiDrop peer through the MCP server. The laptop offers a folder where it sits. The gpu box mounts it, lists 2,184 files six folders deep, and checksums 24 shards. In that run 88,581 bytes crossed the network out of 6,784,286 on disk, because that is what it opened. The whole thing, pairing included, took 12.5 seconds.
Build it with make build-kdmcp, then kdmcp install prints the config snippet for your MCP client. Sending stays off until KD_SHARE_ROOT names one directory to send from, so a receiving agent cannot be talked into shipping files out.
Links
- Website
- Documentation
- Compared with sshfs - measured on a 200 ms link
- Compared with sixteen tools - LucidLink, Strada, Syncthing, Resilio Sync, rclone, WeTransfer, LocalSend, PairDrop, KDE Connect and more, one table each
- Technical deep dive
- Blog posts (53 posts on FUSE, crypto, performance)
- FAQ
- Comparison with alternatives
- About and credentials
Related MCP servers
Permanent on-chain memory for AI agents on Lightchain via a one-time unlock.
Repair or replace? Get device repair costs, local shops, trade-in values.
View repository →
million
Operate a self-hosted Solana whale tracker and copy-trading deck: positions, rules, token checks.

MCP server for Digilent WaveForms instruments (oscilloscope, AWG, logic analyzer).

sigrok MCP Server
Wraps sigrok-cli for signal analysis: capture data, decode protocols, and query instruments.

OpenTakeoff
Construction takeoff engine for AI agents and estimators: load plans, set scale, measure, count, export with full provenance.

