HTML Cloud
cloud.htmlv0.4.1更新于 Oct 7, 2026
Share AI-generated HTML as a private, end-to-end encrypted link. Update it later at the same link.
概览
让助手把生成的 HTML 发布为私密的端到端加密链接,并可在同一链接上后续更新。
- 功能
- 该服务器提供两个工具:share_html 接收完整的自包含 HTML 文档(或本地 .html 文件路径),返回一个分享链接和一个私密编辑链接;update_html 使用编辑链接替换已有分享的内容,分享链接和有效期保持不变。页面有效期可设为 7 天、30 天或永不过期。HTML 在上传前于本地用 AES-256-GCM 加密,只有密文会发送到 html.cloud。
- 适用场景
- 适合助手生成 HTML 报告、摘要或幻灯片式页面,需要以链接形式交给他人而不是粘贴到对话中的场景,尤其适合不宜放在公开网址上的机密内容。也适合分享后需要修改、且希望同一链接显示新版本的场景。
- 运行要求
- 以 stdio 方式在本地运行,通过 npx 安装 npm 包 html-cloud-mcp,需要 Node.js 20+。也提供 Claude Desktop 扩展(.mcpb)。无需账号或 API 密钥。可选环境变量:HTML_CLOUD_PREFER 和 HTML_CLOUD_URL。分享或更新时需要访问 html.cloud 的网络连接。
安装
在 SourceWeft 中
- 打开 控制台中的 HTML Cloud,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
html-cloud-mcp
An MCP server that lets Claude and other AI assistants share the HTML they generate as a private, end-to-end encrypted link — no account, no public URL.
The assistant calls one tool, share_html, to share — and update_html to
change a page it already shared, at the same link. The HTML is encrypted locally
with AES-256-GCM before anything is uploaded; html.cloud
stores only ciphertext and cannot read it.
"Make me a one-page summary of this and share it privately." → the assistant generates the HTML, calls
share_html, and replies with a link."Actually, add a section on next steps." → the assistant revises the HTML, calls
update_htmlwith the edit link, and the link you already sent shows the new version.
Install
Claude Desktop (one-click)
Download the packaged extension (a .mcpb file) from
html.cloud/mcp and double-click it. If Claude Desktop
doesn't offer to install it, open Settings → Extensions, click Advanced
settings, and use Install Extension… under Extension Developer to pick the
file — dragging the file into the window is unreliable and may just attach it
to the chat.
About the install warning: Claude Desktop shows the same red "access to everything on your computer" box for every extension installed from a file rather than from its built-in directory. It is a statement about how extensions run, not about this one. The server is the ~250 lines in
bin/andlib/of this directory, it talks to a single host (html.cloud), and it uploads only ciphertext. Extensions installed from Claude's directory don't show the warning; getting listed there is in progress.
Cowork: the extension also works in Cowork sessions that are linked to the computer it is installed on — the desktop app proxies it into the session. A Cowork session running purely in the cloud, with no linked computer, will not see it.
Other MCP clients
Add it to your MCP client. For Claude Desktop, in claude_desktop_config.json:
For Claude Code:
Requires Node.js 20+.
The tools
share_html
Pass exactly one of html or path. path is for large pages: MCP hosts cap
the size of a tool argument, so a long report that the assistant has written to
disk is shared from the file rather than squeezed through the call. Only
.html/.htm files are accepted — the server shares web pages, not arbitrary
files from your computer.
Returns a share link (give it to anyone you want to read the file) and a private edit link (update the file, change the expiry, or delete it).
update_html
As with share_html, pass exactly one of html or path.
Replaces the content behind an existing share. The share link stays the same and the expiry is untouched, so anyone who already has the link sees the new version. The edit key unwraps the document's existing view key locally, the new HTML is encrypted under that same key, and only ciphertext is sent — the server never sees the content, before or after.
Example prompts
- "Make a one-page summary of this report as HTML and share it privately."
- "Turn these notes into a slide-style page and give me a link that expires in 7 days."
- "Add a next-steps section to the page you shared earlier." (the same link shows the new version)
How the encryption works
- Keys are generated inside this server process and never sent anywhere except inside the links it returns.
- The HTML is encrypted with AES-256-GCM before any network request. Only ciphertext is uploaded.
- The decryption key sits after the
#in the share link — that part of a URL is never transmitted to a server.
This is the same zero-knowledge model as the html.cloud website and CLI, using
the same crypto module (imported from the html-cloud
package — never reimplemented). Full explainer: html.cloud/security.
Configuration
The Claude Desktop extension asks this as a switch, Always share through
html.cloud, when you install it. For npx setups, set the env var in the
client config:
For Claude Code: claude mcp add html-cloud -e HTML_CLOUD_PREFER=always -- npx -y html-cloud-mcp.
Privacy Policy
Full policy: html.cloud/mcp-privacy.
- Collection. The server handles only the HTML the assistant passes to
share_htmlorupdate_html— inline, or as the one.htmlfile whose path the assistant passes. It reads nothing else from your computer and nothing from the conversation beyond the tool arguments. - Use and storage. The HTML is encrypted locally with AES-256-GCM. What is sent to html.cloud: the ciphertext, the chosen expiry, a copy of the page key encrypted with the edit key, and a hash of the edit key that authorises later updates (updates send the page id, the new ciphertext, and that proof). None of it lets the server read the page. Keys exist only in the links returned to you.
- Sharing. No third parties. The server talks to exactly one host, html.cloud, and only when you share or update a page. No analytics, no telemetry, no account.
- Retention. A page is unavailable from the moment its link expires (7 or 30 days, or never if you chose that) and its ciphertext is permanently deleted by a daily clean-up; deleting via the edit link removes it at once.
- Contact. Email [email protected] or open an issue at github.com/viljamilaurila/html-cloud.
Honest threat model
Anyone with the share link can read the file — the link is the credential. The server can expire or delete ciphertext but can never read it. See html.cloud/security for details and limitations.
Source: github.com/viljamilaurila/html-cloud · MIT
来源:mcp/README.md,提交 9066f9f
工具
0版本历史
1- v0.4.1最新Oct 7, 2026

