Veilfile

io.github.yourimaginationwillbefiredv1.0.0Updated Oct 6, 2026

Private, expiring artifact hosting for AI agents. Upload via API or MCP; links die on their own.

VerifiedStreamable HTTPWeb executableDeveloper ToolsFiles & Storage

Overview

AI-generated overview

Veilfile lets an assistant upload files to a private, expiring URL and list or revoke those artifacts.

What it does
Veilfile is a hosted artifact store for agent output. Through its MCP server it exposes upload_artifact, list_artifacts and revoke_artifact, so an assistant can push a screenshot, log bundle or HAR file and receive back an unguessable link that expires on its own. Uploads are scanned for secret shapes and flagged, and the same operations are also available over a REST API.
When to use it
Useful when a coding agent running in CI or a cloud session produces a file that a human needs to review, and a public repository or shared drive is not appropriate. It fits short-lived handoffs where the link should stop working after a set time.
Requirements
A remote Streamable HTTP endpoint; no local runtime is needed. An API key issued in the Veilfile dashboard after email verification, sent as the Authorization header in the form Bearer vlf_... . The key is shown once, so it must be stored. Free plan allows 100 uploads per month with a 7-day maximum TTL.
Before you install
The Authorization header carries a bearer API key that grants access to the account's artifacts; store it as a secret and revoke it if exposed. Uploaded files leave the user's machine and are stored by the service, so anything sensitive should be considered disclosed to a third party. Uploads are only flagged for secret shapes, not blocked, so a leaked credential can still be published. Paid plans involve Stripe billing.

Installation

In SourceWeft

  1. Open Veilfile in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "veilfile": {
      "type": "http",
      "url": "https://veilfile.com/mcp"
    }
  }
}

README

Veilfile — private, ephemeral artifact hosting for AI agents

When a coding agent in CI or a cloud session produces a screenshot, log bundle, or HAR file for review, it needs a private URL to put it at — not a public repo. Veilfile is the sanctioned place: upload via API key (or MCP), get back an unguessable, expiring URL. Uploads are scanned for secret shapes and flagged (never blocked, never logged).

  • API: POST /api/v1/artifacts (multipart, Authorization: Bearer vlf_…) → {id, url, expires_at, size_bytes, secret_flags[]}. GET /a/<token> serves the file (the 256-bit token is the auth). List/revoke endpoints included.
  • MCP: hosted Streamable HTTP server at POST /mcp (upload_artifact, list_artifacts, revoke_artifact), same vlf_ keys.
  • Dashboard: session-auth React app at /app/ — API keys (raw key shown once), usage vs plan caps, artifact table with secret-flag badges + revoke, Stripe billing portal.
  • Landing page: / (public). Agent docs: /llms.txt, docs/API.md.

See SPEC.md for the product spec.

Plans

PlanPriceUploads/moMax TTLAPI keys
Free$01007 days1
Team$4/mo2,00090 days5
Scale$12/mo10,000365 daysunlimited

Quickstart (local dev)

bash
# Backendpython3 -m venv venv && ./venv/bin/pip install -r backend/requirements.txtexport DJANGO_DEBUG=True DJANGO_SECRET_KEY=dev-only-key./venv/bin/python backend/manage.py migrate./venv/bin/python backend/manage.py createsuperuser   # dashboard login./venv/bin/python backend/manage.py runserver          # :8000
# Frontend (separate terminal; proxied /api -> :8000)cd frontend && npm install && npm run dev               # :5173

Sign up at http://localhost:8000/accounts/signup/ (or log in), open /app/, create an API key, then:

bash
curl -H "Authorization: Bearer vlf_..." \     -F "[email protected]" \     http://localhost:8000/api/v1/artifacts/

Environment variables

No secrets are committed to this repo. Copy the names below into a local .env (gitignored) or your host's env config. Stripe stays in TEST mode until live keys are connected.

VariableRequiredDefaultNotes
DJANGO_SECRET_KEYprod—Required when DJANGO_DEBUG is false
DJANGO_DEBUGnoFalseSet True for local dev
DJANGO_ALLOWED_HOSTSprod—Comma-separated, e.g. veilfile.example.com
DATABASE_URLnosqliteProd: Postgres URL
DROP_BASE_URLprodhttp://localhost:8000Public URL; artifact links are built from it
DROP_STORAGEnolocallocal (dev) or s3 (prod)
DROP_LOCAL_DIRnobackend/media/artifactsLocal storage root
AWS_S3_ENDPOINT_URLprod (s3)—R2 endpoint, e.g. https://<acct>.r2.cloudflarestorage.com
AWS_S3_BUCKETprod (s3)—R2 bucket name
AWS_ACCESS_KEY_IDprod (s3)—R2 API token (access key)
AWS_SECRET_ACCESS_KEYprod (s3)—R2 API token (secret)
STRIPE_SECRET_KEYbilling—Test-mode secret key (sk_test_…)
STRIPE_WEBHOOK_SECRETbilling—Webhook signing secret (whsec_…)
STRIPE_PRICE_TEAMbilling—Price ID for the $4/mo Team plan (tax-inclusive)
STRIPE_PRICE_SCALEbilling—Price ID for the $12/mo Scale plan (tax-inclusive)
PORTprod8000Set by the host (Render)

Without Stripe vars, checkout/portal return 503 billing_not_configured and the dashboard shows a friendly note; everything else works.

Tests

bash
cd backend && DJANGO_DEBUG=True DJANGO_SECRET_KEY=dev-only-key \  ../venv/bin/python manage.py test# 73 tests: drop_core (34) + drop_billing (17) + drop_mcp (22)
bash
cd frontend && npm run build   # must succeed; assets resolve under /static/

Ops

  • TTL sweeper (daily cron): python backend/manage.py sweep_expired deletes expired artifacts (files + rows). Idempotent.
  • Storage: Render's disk is ephemeral — production must use DROP_STORAGE=s3 (Cloudflare R2).
  • MCP registries: launch checklist in docs/REGISTRIES.md.

Project layout

backend/  config/          Django settings/URLs (env-driven)  drop_core/       Workspace, APIKey (vlf_), Artifact, plans, storage,                   secret scan, agent API, key mgmt, sweeper  drop_billing/    Stripe checkout/portal/webhook (live, tax-inclusive, Managed Payments)  drop_mcp/        Streamable HTTP MCP server (POST /mcp)  templates/       login/logout/signup pagesfrontend/          React + Vite (base: '/static/'); / landing, /app/ dashboarddocs/              API.md, llms.txt (served at /llms.txt), REGISTRIES.mdDockerfile         multi-stage node -> python build, WhiteNoise + gunicornrender.yaml        Render deploy blueprint

Launch checklist

  1. Create Cloudflare R2 bucket + API token (S3-compatible).
  2. Create Stripe products/prices (Team $4, Scale $12, tax-inclusive) with product tax codes; note the price IDs.
  3. Deploy on Render (see render.yaml); set env vars incl. DROP_BASE_URL.
  4. Point Stripe webhook at https://<host>/api/v1/billing/webhook; set STRIPE_WEBHOOK_SECRET.
  5. Add daily cron: python backend/manage.py sweep_expired.
  6. List the MCP server per docs/REGISTRIES.md.

Source: README.md at commit 53a88ce

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.0.0LatestOct 6, 2026