
Veilfile
io.github.yourimaginationwillbefiredv1.0.0更新于 Oct 6, 2026
Private, expiring artifact hosting for AI agents. Upload via API or MCP; links die on their own.
概览
Veilfile 让助手把文件上传到私有且会自动过期的链接,并可列出或撤销这些文件。
- 功能
- Veilfile 是面向智能体产物的托管存储服务。通过其 MCP 服务器提供 upload_artifact、list_artifacts 和 revoke_artifact,助手可以上传截图、日志包或 HAR 文件,并得到一个难以猜测、会自动过期的链接。上传内容会被扫描是否包含密钥特征并加以标记,同样的操作也可通过 REST API 完成。
- 适用场景
- 适合在 CI 或云会话中运行的编码智能体产出需要人工审阅的文件、而公共仓库或共享网盘又不合适的场景。也适合链接应在设定时间后失效的短期交付。
- 运行要求
- 远程 Streamable HTTP 端点,无需本地运行时。需要先在 Veilfile 控制台完成邮箱验证后签发的 API 密钥,以 Authorization 头按 Bearer vlf_... 形式发送。密钥只显示一次,必须自行保存。免费方案每月 100 次上传,最长有效期 7 天。
安装
在 SourceWeft 中
- 打开 控制台中的 Veilfile,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"veilfile": {
"type": "http",
"url": "https://veilfile.com/mcp"
}
}
}README
Veilfile — private, ephemeral artifact hosting for AI agents
When a coding agent in CI or a cloud session produces a screenshot, log bundle, or HAR file for review, it needs a private URL to put it at — not a public repo. Veilfile is the sanctioned place: upload via API key (or MCP), get back an unguessable, expiring URL. Uploads are scanned for secret shapes and flagged (never blocked, never logged).
- API:
POST /api/v1/artifacts(multipart,Authorization: Bearer vlf_…) →{id, url, expires_at, size_bytes, secret_flags[]}.GET /a/<token>serves the file (the 256-bit token is the auth). List/revoke endpoints included. - MCP: hosted Streamable HTTP server at
POST /mcp(upload_artifact,list_artifacts,revoke_artifact), samevlf_keys. - Dashboard: session-auth React app at
/app/— API keys (raw key shown once), usage vs plan caps, artifact table with secret-flag badges + revoke, Stripe billing portal. - Landing page:
/(public). Agent docs:/llms.txt,docs/API.md.
See SPEC.md for the product spec.
Plans
Quickstart (local dev)
Sign up at http://localhost:8000/accounts/signup/ (or log in), open
/app/, create an API key, then:
Environment variables
No secrets are committed to this repo. Copy the names below into a local
.env (gitignored) or your host's env config. Stripe stays in TEST mode
until live keys are connected.
Without Stripe vars, checkout/portal return 503 billing_not_configured and the
dashboard shows a friendly note; everything else works.
Tests
Ops
- TTL sweeper (daily cron):
python backend/manage.py sweep_expireddeletes expired artifacts (files + rows). Idempotent. - Storage: Render's disk is ephemeral — production must use
DROP_STORAGE=s3(Cloudflare R2). - MCP registries: launch checklist in
docs/REGISTRIES.md.
Project layout
Launch checklist
- Create Cloudflare R2 bucket + API token (S3-compatible).
- Create Stripe products/prices (Team $4, Scale $12, tax-inclusive) with product tax codes; note the price IDs.
- Deploy on Render (see
render.yaml); set env vars incl.DROP_BASE_URL. - Point Stripe webhook at
https://<host>/api/v1/billing/webhook; setSTRIPE_WEBHOOK_SECRET. - Add daily cron:
python backend/manage.py sweep_expired. - List the MCP server per
docs/REGISTRIES.md.
来源:README.md,提交 53a88ce
工具
0版本历史
1- v1.0.0最新Oct 6, 2026

