Veilfile

io.github.yourimaginationwillbefiredv1.0.0更新于 Oct 6, 2026

Private, expiring artifact hosting for AI agents. Upload via API or MCP; links die on their own.

已验证Streamable HTTP可网页运行Developer ToolsFiles & Storage

概览

AI 生成的概览

Veilfile 让助手把文件上传到私有且会自动过期的链接,并可列出或撤销这些文件。

功能
Veilfile 是面向智能体产物的托管存储服务。通过其 MCP 服务器提供 upload_artifact、list_artifacts 和 revoke_artifact,助手可以上传截图、日志包或 HAR 文件,并得到一个难以猜测、会自动过期的链接。上传内容会被扫描是否包含密钥特征并加以标记,同样的操作也可通过 REST API 完成。
适用场景
适合在 CI 或云会话中运行的编码智能体产出需要人工审阅的文件、而公共仓库或共享网盘又不合适的场景。也适合链接应在设定时间后失效的短期交付。
运行要求
远程 Streamable HTTP 端点,无需本地运行时。需要先在 Veilfile 控制台完成邮箱验证后签发的 API 密钥,以 Authorization 头按 Bearer vlf_... 形式发送。密钥只显示一次,必须自行保存。免费方案每月 100 次上传,最长有效期 7 天。
安装前请注意
Authorization 头携带的 bearer API 密钥可访问该账户下的文件,应作为机密保存,泄露后立即撤销。上传的文件会离开本机并由该服务存储,敏感内容应视为已披露给第三方。上传仅对密钥特征做标记而不拦截,泄露的凭据仍可能被发布。付费方案涉及 Stripe 计费。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Veilfile,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。

其他 MCP 客户端

把它添加到你客户端的 mcpServers 配置中。

{
  "mcpServers": {
    "veilfile": {
      "type": "http",
      "url": "https://veilfile.com/mcp"
    }
  }
}

README

Veilfile — private, ephemeral artifact hosting for AI agents

When a coding agent in CI or a cloud session produces a screenshot, log bundle, or HAR file for review, it needs a private URL to put it at — not a public repo. Veilfile is the sanctioned place: upload via API key (or MCP), get back an unguessable, expiring URL. Uploads are scanned for secret shapes and flagged (never blocked, never logged).

  • API: POST /api/v1/artifacts (multipart, Authorization: Bearer vlf_…) → {id, url, expires_at, size_bytes, secret_flags[]}. GET /a/<token> serves the file (the 256-bit token is the auth). List/revoke endpoints included.
  • MCP: hosted Streamable HTTP server at POST /mcp (upload_artifact, list_artifacts, revoke_artifact), same vlf_ keys.
  • Dashboard: session-auth React app at /app/ — API keys (raw key shown once), usage vs plan caps, artifact table with secret-flag badges + revoke, Stripe billing portal.
  • Landing page: / (public). Agent docs: /llms.txt, docs/API.md.

See SPEC.md for the product spec.

Plans

PlanPriceUploads/moMax TTLAPI keys
Free$01007 days1
Team$4/mo2,00090 days5
Scale$12/mo10,000365 daysunlimited

Quickstart (local dev)

bash
# Backendpython3 -m venv venv && ./venv/bin/pip install -r backend/requirements.txtexport DJANGO_DEBUG=True DJANGO_SECRET_KEY=dev-only-key./venv/bin/python backend/manage.py migrate./venv/bin/python backend/manage.py createsuperuser   # dashboard login./venv/bin/python backend/manage.py runserver          # :8000
# Frontend (separate terminal; proxied /api -> :8000)cd frontend && npm install && npm run dev               # :5173

Sign up at http://localhost:8000/accounts/signup/ (or log in), open /app/, create an API key, then:

bash
curl -H "Authorization: Bearer vlf_..." \     -F "[email protected]" \     http://localhost:8000/api/v1/artifacts/

Environment variables

No secrets are committed to this repo. Copy the names below into a local .env (gitignored) or your host's env config. Stripe stays in TEST mode until live keys are connected.

VariableRequiredDefaultNotes
DJANGO_SECRET_KEYprod—Required when DJANGO_DEBUG is false
DJANGO_DEBUGnoFalseSet True for local dev
DJANGO_ALLOWED_HOSTSprod—Comma-separated, e.g. veilfile.example.com
DATABASE_URLnosqliteProd: Postgres URL
DROP_BASE_URLprodhttp://localhost:8000Public URL; artifact links are built from it
DROP_STORAGEnolocallocal (dev) or s3 (prod)
DROP_LOCAL_DIRnobackend/media/artifactsLocal storage root
AWS_S3_ENDPOINT_URLprod (s3)—R2 endpoint, e.g. https://<acct>.r2.cloudflarestorage.com
AWS_S3_BUCKETprod (s3)—R2 bucket name
AWS_ACCESS_KEY_IDprod (s3)—R2 API token (access key)
AWS_SECRET_ACCESS_KEYprod (s3)—R2 API token (secret)
STRIPE_SECRET_KEYbilling—Test-mode secret key (sk_test_…)
STRIPE_WEBHOOK_SECRETbilling—Webhook signing secret (whsec_…)
STRIPE_PRICE_TEAMbilling—Price ID for the $4/mo Team plan (tax-inclusive)
STRIPE_PRICE_SCALEbilling—Price ID for the $12/mo Scale plan (tax-inclusive)
PORTprod8000Set by the host (Render)

Without Stripe vars, checkout/portal return 503 billing_not_configured and the dashboard shows a friendly note; everything else works.

Tests

bash
cd backend && DJANGO_DEBUG=True DJANGO_SECRET_KEY=dev-only-key \  ../venv/bin/python manage.py test# 73 tests: drop_core (34) + drop_billing (17) + drop_mcp (22)
bash
cd frontend && npm run build   # must succeed; assets resolve under /static/

Ops

  • TTL sweeper (daily cron): python backend/manage.py sweep_expired deletes expired artifacts (files + rows). Idempotent.
  • Storage: Render's disk is ephemeral — production must use DROP_STORAGE=s3 (Cloudflare R2).
  • MCP registries: launch checklist in docs/REGISTRIES.md.

Project layout

backend/  config/          Django settings/URLs (env-driven)  drop_core/       Workspace, APIKey (vlf_), Artifact, plans, storage,                   secret scan, agent API, key mgmt, sweeper  drop_billing/    Stripe checkout/portal/webhook (live, tax-inclusive, Managed Payments)  drop_mcp/        Streamable HTTP MCP server (POST /mcp)  templates/       login/logout/signup pagesfrontend/          React + Vite (base: '/static/'); / landing, /app/ dashboarddocs/              API.md, llms.txt (served at /llms.txt), REGISTRIES.mdDockerfile         multi-stage node -> python build, WhiteNoise + gunicornrender.yaml        Render deploy blueprint

Launch checklist

  1. Create Cloudflare R2 bucket + API token (S3-compatible).
  2. Create Stripe products/prices (Team $4, Scale $12, tax-inclusive) with product tax codes; note the price IDs.
  3. Deploy on Render (see render.yaml); set env vars incl. DROP_BASE_URL.
  4. Point Stripe webhook at https://<host>/api/v1/billing/webhook; set STRIPE_WEBHOOK_SECRET.
  5. Add daily cron: python backend/manage.py sweep_expired.
  6. List the MCP server per docs/REGISTRIES.md.

来源:README.md,提交 53a88ce

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.0.0最新Oct 6, 2026