PluginBench
MCP Server
Maintained
MIT

io.github.maxtechera/hushdrop MCP Server

io.github.maxtechera/hushdrop

Share AI-built artifacts on your own domain with zero-knowledge encryption and password protection.

What is the io.github.maxtechera/hushdrop MCP server?

Hushdrop is an open-source, self-hosted artifact sharing server that lets AI agents publish files, HTML pages, and sites to branded, password-protected links on your own domain. It uses client-side AES-256 encryption for zero-knowledge security and works as an MCP server, CLI tool, or web interface without requiring account setup.

Hushdrop enables AI agents and developers to quickly share work—reports, dashboards, proposals, PDFs—via branded, encrypted links on their own domain. Unlike closed SaaS alternatives, it's open-source, self-hostable on Vercel Blob for free, supports anonymous drops, and integrates natively with Claude, Cursor, and other AI agents via MCP or CLI.

How to install io.github.maxtechera/hushdrop

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • BLOB_READ_WRITE_TOKEN
    secret

    Vercel Blob token for self-hosting on your own domain. Optional.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "hushdrop": {
      "command": "npx",
      "args": [
        "-y",
        "hushdrop-mcp"
      ],
      "env": {
        "BLOB_READ_WRITE_TOKEN": "<YOUR_BLOB_READ_WRITE_TOKEN>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • publish_html — Publish raw HTML as a branded, password-protected link
  • publish_file — Publish a local file with optional branded download page
  • update_site — Replace a drop's content in place without changing the URL
  • list_sites — List all published drops
  • delete_site — Delete a published drop
  • set_password — Update or set a password on a hosted drop
  • set_expiry — Set auto-expiration time for a drop
  • set_email_gate — Restrict access to a drop by email domain
  • set_feedback — Configure feedback settings for a drop

Use cases

  • Publish AI-generated reports and dashboards to a branded link in seconds from your terminal or agent
  • Share client work or sensitive documents with password protection and zero-knowledge encryption
  • Create time-limited or burn-after-read drops that auto-expire or self-destruct after first view
  • Host multi-file static sites and PDFs on your own domain with a single command
  • Restrict access to drops by email domain or revocable guest links

io.github.maxtechera/hushdrop MCP server FAQ

What is Hushdrop?

Hushdrop is an open-source artifact sharing tool that publishes files and HTML pages to branded, password-protected links on your own domain using client-side AES-256 encryption. It works as an MCP server for AI agents, a CLI tool, or a web interface.

Is Hushdrop free?

Yes, Hushdrop is MIT-licensed and free. Self-hosting costs only your Vercel Blob usage (typically pennies). The hosted tier on hushdrop.dev is also free with a GitHub or magic-link account.

How do I use it with Claude or Cursor?

Install via `/plugin marketplace add maxtechera/hushdrop` in Claude Code, or run `npx hushdrop-install` to register the MCP server in Cursor, Codex, Copilot, or other agents. Then agents can publish directly via the `drops` MCP tools.

Do I need to create an account?

No. You can drop files anonymously with `npx hushdrop <file>` (24-hour links). A free GitHub/magic-link account on hushdrop.dev gives persistent links. Self-hosting requires only a Vercel Blob token (no account).

Is it really zero-knowledge?

Yes, for locked drops. AES-256 encryption runs in your browser before upload; the server stores only ciphertext. Passwords are stored locally in `~/.hushdrop/manifest.json`, never uploaded.

Can I self-host on my own domain?

Yes. Click the Deploy with Vercel button to auto-provision a Blob store, then run `hush init --domain share.yoursite.com` to point your CLI and agents at your instance.

README (reference)

Source of truth, from the repository.

<div align="center">

Hushdrop

Share what your AI builds — on your own domain.

Open-source, self-hosted artifact sharing. Drop a file, an HTML page, or a whole site and get a branded, password-protected (zero-knowledge AES-256) link on your own domain in ~1 second — from your terminal or any AI agent. The open-source alternative to Stacktree.

npm downloads CI license: MIT stars

Live demo → · Docs · Try in browser · vs Stacktree

Deploy with Vercel

Hushdrop — share what your AI builds, on your own domain

</div>

Quick start

The core way to use Hushdrop is from your agent — it publishes what it builds to your own domain.

Claude Code (recommended — auto-updates via the plugin marketplace):

/plugin marketplace add maxtechera/hushdrop
/plugin install hushdrop

Cursor · Codex · Copilot · Gemini · 20+ Agent Skills hosts:

npx skills add maxtechera/hushdrop-skill

No install — open hushdrop.dev/try, drop an HTML file, get a link. No account.

One-off from the terminal — zero install, zero setup, no account:

npx hushdrop report.html       # → https://hushdrop.dev/u/xxxx (+ password, copied) — no setup, no account

Free hosted account — persistent links on your own handle (hushdrop.dev/you/<slug>):

npx hushdrop login                       # passwordless: GitHub or magic link
npx hushdrop report.html                 # → https://hushdrop.dev/you/report-a1b2 (persistent)

Your own domain — self-host on your Vercel Blob (free, MIT, your URL + brand forever):

# one-click: the "Deploy with Vercel" button above auto-provisions a Blob store — then:
npx hushdrop-install                         # wire your agents + CLI
hush deploy --domain share.yoursite.com   # or do it from a local clone

No dashboard required. Two commands to try; one more to own.

Why this exists

Anthropic shipped artifact sharing so teams could hand each other the things they make with AI. It's great — and it's locked to their surface, their domain, their account. Stacktree does the agent-native version, but it's a closed SaaS: your content sits on their servers, custom domains and limits are paywalled, and you can't audit or self-host it.

I make things all day with agents: reports, proposals, guides, dashboards, whole little sites. I wanted to hand someone a link that's mine — my domain, my brand, my keys — in the time it takes to type one command, without uploading client work to someone else's server. So hush does exactly that: terminal-native, zero-knowledge, on your own domain, usable from any agent. MIT.

Hushdrop vs. the alternatives

HushdropStacktreesend.cotiiny.host
Your own domain✅ free❌❌paid
Zero-knowledge AES-256✅✅files only❌
Open-source / self-host✅ MIT❌❌❌
CLI + MCP (agent-native)✅partial❌❌
Anonymous, no-account drop✅❌✅✅
Burn-after-read / email-gate✅partialpartial❌
Pricefree / self-hostpaidfreemiumfreemium

Full write-ups: vs Stacktree · vs Send · vs ShareDuo

Features

  • 🔒 Zero-knowledge — branding + AES-256 happen client-side; the server only stores ciphertext.
  • 🌐 Your domain, your brand — colors, logo, social cards flow into the unlock gate + previews.
  • 🤖 Agent-native — one CLI command or 9 MCP tools; any agent that runs a shell can publish.
  • ⏱️ Auto-expire & burn-after-read — --expire 7d, --burn, server-enforced cleanup.
  • 📧 Email-gate & revocable share links — restrict by domain, mint/revoke guest links.
  • 📦 Anything static — HTML, Markdown (rendered), PDFs, images, multi-file zips → sites.
  • 🚀 One-click self-host — Deploy to Vercel auto-provisions Blob; no DB to run.

What you can drop

You runYou get
hush report.htmlBranded, AES-256-locked page at yourdomain.com/<slug> (+ auto password)
hush notes.mdMarkdown → rendered, branded HTML page
hush report.html -p secretYour own password
hush report.html --no-lockBranded page, no password — renders for anyone with the link
hush report.html --expire 7dAuto-expire (7d/24h/2w/date); enforce with hush gc
hush report.html --burnBurn-after-read — self-destructs on first view
hush report.html --email-gate acme.comOnly viewers with that email domain can open it
hush deck.pdf --pageA branded download page wrapping the file
hush site.zipMulti-file static site at yourdomain.com/<slug>/
hush -s q3 deck.htmlForce the slug

CLI reference

CommandDoes
hush <file>Publish (managed / hosted / self-host, auto-detected)
hush login / whoami / logoutPasswordless hosted account (GitHub or magic link)
hush list / rm <slug> / gcList, delete, garbage-collect drops
hush share <slug> [--revoke]Mint / revoke a revocable guest link
hush claim <url>Move an anonymous /u/ drop into your account
hush set-expiry / set-email-gate / set-password / set-feedbackManage a hosted drop
hush init / setup / deployConfigure + self-host on your own domain
hush migrateRe-home hosted drops onto your own Blob

Use it from any AI agent

npx hushdrop-install registers the drops MCP server into your detected agents (Claude Code, Codex, Cursor, Windsurf, OpenCode, Amp), puts hush on your PATH, and prints config for GUI clients.

claude mcp add hushdrop -- npx -y hushdrop-mcp        # Claude Code
codex  mcp add hushdrop -- npx -y hushdrop-mcp         # Codex
{ "mcpServers": { "hushdrop": { "command": "npx", "args": ["-y", "hushdrop-mcp"] } } }

MCP tools (9 — vs Stacktree's 7)

ToolPurpose
publish_htmlPublish raw HTML → branded, password-protected link
publish_filePublish a local file (optionally a branded download page)
update_siteReplace a drop's content in place (same URL)
list_sites / delete_siteList / delete drops
set_password / set_expiry / set_email_gate / set_feedbackManage a hosted drop

How it works

  1. Read your file and detect its type.
  2. Brand (HTML) — inject favicon, OG/Twitter card, and a subtle corner badge before </body>.
  3. Encrypt (if locking) — StatiCrypt (AES-256, client-side) behind your branded unlock gate. The badge is baked in before encryption, so it survives.
  4. Upload to Vercel Blob under a clean key.
  5. Serve — yourdomain.com/<slug> proxies the blob via middleware.js, rewriting headers so encrypted HTML decrypts + renders (not downloads) and CSP doesn't block the unlock script. Drops are noindex, nofollow, noai.
  6. Report — URL (+ password) printed and copied to your clipboard.

Serving is a dumb transparent proxy; all branding + encryption happen client-side at upload. The server only ever stores ciphertext.

Self-host

Deploy with Vercel

The Deploy button clones the repo and auto-provisions a Blob store (it injects BLOB_READ_WRITE_TOKEN; the app derives its store from the token, so it just works). Then npx hushdrop-install + hush init --domain share.yoursite.com to point your CLI + agents at your instance. Self-host is token-only, free, unlimited — no account needed. Full walkthrough in skill/SETUP.md.

Configuration

FileHoldsCommitted?
skill/brand/brand.jsonPresentation — name, colors, owner, social links. Edit to rebrand.yes
~/.hushdrop/config.jsonInfra — domain, blob host, Vercel project. Written by hush init.no
~/.hushdrop/.envYour BLOB_READ_WRITE_TOKEN.no

FAQ

Is it really zero-knowledge? Yes — for locked drops, AES-256 runs in your browser before upload; the server stores only ciphertext. Managed vs. hosted vs. self-host? Managed = anonymous, 24h, no account. Hosted = free account, persistent links on hushdrop.dev/you/…. Self-host = your own domain + Blob. Does it need Vercel? Only to self-host. The managed + hosted tiers need nothing but npx. How is this different from Stacktree? Same agent-native idea, but open-source, self-hostable, your own domain free, and anonymous (no account). See the comparison. Can agents use it without MCP? Yes — it's a single CLI; any agent that runs a shell command can publish. Is it free? Yes. MIT. Self-host costs only your own (usually pennies) Vercel Blob usage.

Security

  • Locked HTML is genuinely AES-256 encrypted in the browser — use long passwords; strong against casual access, not a vault.
  • Raw files are protected by an unguessable slug; use --page -p <password> for a gated download.
  • Passwords are stored in ~/.hushdrop/manifest.json on your machine only — never uploaded.

See SECURITY.md to report a vulnerability.

Contributing

PRs welcome — see CONTRIBUTING.md. It's a few hundred lines of readable Node + HTML, no build step.

<div align="center">

MIT · Built by Max Techera · GitHub · Instagram · hushdrop.dev

</div>

Related MCP servers

Seeds, governs and navigates a memory_bank knowledge base: gated writes, routing, drift vs code

0
TypeScript
MIT
View repository →
DOdotrepo logo

dotrepo

Active

Trust-aware repository facts for agents: build, test, docs, license, and security, no scraping.

1
Rust
MIT
View repository →

ADHD system of record for agents: tasks, goals, loops, calendar, focus stats.

View repository →

Git hosting for AI agents: repos, changes, focused diffs, reviews, issues, code search.

0
TypeScript
View repository →
BOBopMarket logo

BopMarket

Maintained

AI agent marketplace — search, buy, sell, and track products across 5 platforms

1
Python
MIT
View repository →

Developer-workflow MCP server for Catalyst React framework: migration guidance, debugging, and task planning.

87
JavaScript
MIT
View repository →