
Veilfile
io.github.yourimaginationwillbefiredv1.0.0Updated Oct 6, 2026
Private, expiring artifact hosting for AI agents. Upload via API or MCP; links die on their own.
Overview
Veilfile lets an assistant upload files to a private, expiring URL and list or revoke those artifacts.
- What it does
- Veilfile is a hosted artifact store for agent output. Through its MCP server it exposes upload_artifact, list_artifacts and revoke_artifact, so an assistant can push a screenshot, log bundle or HAR file and receive back an unguessable link that expires on its own. Uploads are scanned for secret shapes and flagged, and the same operations are also available over a REST API.
- When to use it
- Useful when a coding agent running in CI or a cloud session produces a file that a human needs to review, and a public repository or shared drive is not appropriate. It fits short-lived handoffs where the link should stop working after a set time.
- Requirements
- A remote Streamable HTTP endpoint; no local runtime is needed. An API key issued in the Veilfile dashboard after email verification, sent as the Authorization header in the form Bearer vlf_... . The key is shown once, so it must be stored. Free plan allows 100 uploads per month with a 7-day maximum TTL.
Installation
In SourceWeft
- Open Veilfile in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"veilfile": {
"type": "http",
"url": "https://veilfile.com/mcp"
}
}
}README
Veilfile — private, ephemeral artifact hosting for AI agents
When a coding agent in CI or a cloud session produces a screenshot, log bundle, or HAR file for review, it needs a private URL to put it at — not a public repo. Veilfile is the sanctioned place: upload via API key (or MCP), get back an unguessable, expiring URL. Uploads are scanned for secret shapes and flagged (never blocked, never logged).
- API:
POST /api/v1/artifacts(multipart,Authorization: Bearer vlf_…) →{id, url, expires_at, size_bytes, secret_flags[]}.GET /a/<token>serves the file (the 256-bit token is the auth). List/revoke endpoints included. - MCP: hosted Streamable HTTP server at
POST /mcp(upload_artifact,list_artifacts,revoke_artifact), samevlf_keys. - Dashboard: session-auth React app at
/app/— API keys (raw key shown once), usage vs plan caps, artifact table with secret-flag badges + revoke, Stripe billing portal. - Landing page:
/(public). Agent docs:/llms.txt,docs/API.md.
See SPEC.md for the product spec.
Plans
Quickstart (local dev)
Sign up at http://localhost:8000/accounts/signup/ (or log in), open
/app/, create an API key, then:
Environment variables
No secrets are committed to this repo. Copy the names below into a local
.env (gitignored) or your host's env config. Stripe stays in TEST mode
until live keys are connected.
Without Stripe vars, checkout/portal return 503 billing_not_configured and the
dashboard shows a friendly note; everything else works.
Tests
Ops
- TTL sweeper (daily cron):
python backend/manage.py sweep_expireddeletes expired artifacts (files + rows). Idempotent. - Storage: Render's disk is ephemeral — production must use
DROP_STORAGE=s3(Cloudflare R2). - MCP registries: launch checklist in
docs/REGISTRIES.md.
Project layout
Launch checklist
- Create Cloudflare R2 bucket + API token (S3-compatible).
- Create Stripe products/prices (Team $4, Scale $12, tax-inclusive) with product tax codes; note the price IDs.
- Deploy on Render (see
render.yaml); set env vars incl.DROP_BASE_URL. - Point Stripe webhook at
https://<host>/api/v1/billing/webhook; setSTRIPE_WEBHOOK_SECRET. - Add daily cron:
python backend/manage.py sweep_expired. - List the MCP server per
docs/REGISTRIES.md.
Source: README.md at commit 53a88ce
Tools
0Version history
1- v1.0.0LatestOct 6, 2026

