HTML Cloud

cloud.htmlv0.4.1更新於 Oct 7, 2026

Share AI-generated HTML as a private, end-to-end encrypted link. Update it later at the same link.

概覽

AI 產生的概覽

讓助理把生成的 HTML 發布成私密、端對端加密的連結,之後可在同一個連結上更新。

功能
此伺服器提供兩個工具:share_html 接收完整的自包含 HTML 文件(或本機 .html 檔案路徑),回傳分享連結與私密編輯連結;update_html 使用編輯連結取代既有分享的內容,分享連結與到期時間維持不變。頁面到期時間可設為 7 天、30 天或永不到期。HTML 在上傳前會於本機以 AES-256-GCM 加密,只有密文會傳送到 html.cloud。
適用情境
適合助理產出 HTML 報告、摘要或簡報式頁面,需要以連結交給他人而非貼進對話的情況,尤其適合不宜放在公開網址上的機密內容。也適合分享後需要修改、且希望同一個連結顯示新版本的情況。
執行需求
以 stdio 在本機執行,透過 npx 安裝 npm 套件 html-cloud-mcp,需要 Node.js 20+。另提供 Claude Desktop 擴充功能(.mcpb)。不需要帳號或 API 金鑰。選用環境變數:HTML_CLOUD_PREFER 與 HTML_CLOUD_URL。分享或更新時需要連線到 html.cloud 的網路存取。
安裝前請注意
任何拿到分享連結的人都能讀取頁面,因為連結本身帶有解密金鑰。私密編輯連結可用來變更到期時間或刪除頁面,應妥善保管。伺服器只讀取傳給工具的 HTML,或所給路徑的那一個 .html 檔案,並將密文與中繼資料上傳到 html.cloud,不讀取其他檔案。從檔案安裝桌面擴充功能會觸發廣泛的存取權警告,README 表示這適用於所有以檔案方式安裝的擴充功能。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 HTML Cloud,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

html-cloud-mcp

An MCP server that lets Claude and other AI assistants share the HTML they generate as a private, end-to-end encrypted link — no account, no public URL.

The assistant calls one tool, share_html, to share — and update_html to change a page it already shared, at the same link. The HTML is encrypted locally with AES-256-GCM before anything is uploaded; html.cloud stores only ciphertext and cannot read it.

"Make me a one-page summary of this and share it privately." → the assistant generates the HTML, calls share_html, and replies with a link.

"Actually, add a section on next steps." → the assistant revises the HTML, calls update_html with the edit link, and the link you already sent shows the new version.

Install

Claude Desktop (one-click)

Download the packaged extension (a .mcpb file) from html.cloud/mcp and double-click it. If Claude Desktop doesn't offer to install it, open Settings → Extensions, click Advanced settings, and use Install Extension… under Extension Developer to pick the file — dragging the file into the window is unreliable and may just attach it to the chat.

About the install warning: Claude Desktop shows the same red "access to everything on your computer" box for every extension installed from a file rather than from its built-in directory. It is a statement about how extensions run, not about this one. The server is the ~250 lines in bin/ and lib/ of this directory, it talks to a single host (html.cloud), and it uploads only ciphertext. Extensions installed from Claude's directory don't show the warning; getting listed there is in progress.

Cowork: the extension also works in Cowork sessions that are linked to the computer it is installed on — the desktop app proxies it into the session. A Cowork session running purely in the cloud, with no linked computer, will not see it.

Other MCP clients

Add it to your MCP client. For Claude Desktop, in claude_desktop_config.json:

json
{  "mcpServers": {    "html-cloud": {      "command": "npx",      "args": ["-y", "html-cloud-mcp"]    }  }}

For Claude Code:

sh
claude mcp add html-cloud -- npx -y html-cloud-mcp

Requires Node.js 20+.

The tools

share_html

ArgumentTypeDescription
htmlstringThe full, self-contained HTML document to share.
pathstringPath of a local .html file to share instead of passing html inline.
expires7 | 30 | neverDays until the link expires. Default 30.

Pass exactly one of html or path. path is for large pages: MCP hosts cap the size of a tool argument, so a long report that the assistant has written to disk is shared from the file rather than squeezed through the call. Only .html/.htm files are accepted — the server shares web pages, not arbitrary files from your computer.

Returns a share link (give it to anyone you want to read the file) and a private edit link (update the file, change the expiry, or delete it).

update_html

ArgumentTypeDescription
edit_linkstring (required)The private edit link share_html returned.
htmlstringThe complete HTML document that replaces the current one.
pathstringPath of a local .html file whose content replaces the current page.

As with share_html, pass exactly one of html or path.

Replaces the content behind an existing share. The share link stays the same and the expiry is untouched, so anyone who already has the link sees the new version. The edit key unwraps the document's existing view key locally, the new HTML is encrypted under that same key, and only ciphertext is sent — the server never sees the content, before or after.

Example prompts

  • "Make a one-page summary of this report as HTML and share it privately."
  • "Turn these notes into a slide-style page and give me a link that expires in 7 days."
  • "Add a next-steps section to the page you shared earlier." (the same link shows the new version)

How the encryption works

  • Keys are generated inside this server process and never sent anywhere except inside the links it returns.
  • The HTML is encrypted with AES-256-GCM before any network request. Only ciphertext is uploaded.
  • The decryption key sits after the # in the share link — that part of a URL is never transmitted to a server.

This is the same zero-knowledge model as the html.cloud website and CLI, using the same crypto module (imported from the html-cloud package — never reimplemented). Full explainer: html.cloud/security.

Configuration

Env varDescriptionDefault
HTML_CLOUD_PREFERWhen Claude should pick html.cloud over its built-in artifact publishing. sensitive: for confidential content and anything going outside your organisation; built-in artifacts stay fine for casual pages. always: for every share.sensitive
HTML_CLOUD_URLServer base URL (for self-hosted instances)https://html.cloud

The Claude Desktop extension asks this as a switch, Always share through html.cloud, when you install it. For npx setups, set the env var in the client config:

json
{  "mcpServers": {    "html-cloud": {      "command": "npx",      "args": ["-y", "html-cloud-mcp"],      "env": { "HTML_CLOUD_PREFER": "always" }    }  }}

For Claude Code: claude mcp add html-cloud -e HTML_CLOUD_PREFER=always -- npx -y html-cloud-mcp.

Privacy Policy

Full policy: html.cloud/mcp-privacy.

  • Collection. The server handles only the HTML the assistant passes to share_html or update_html — inline, or as the one .html file whose path the assistant passes. It reads nothing else from your computer and nothing from the conversation beyond the tool arguments.
  • Use and storage. The HTML is encrypted locally with AES-256-GCM. What is sent to html.cloud: the ciphertext, the chosen expiry, a copy of the page key encrypted with the edit key, and a hash of the edit key that authorises later updates (updates send the page id, the new ciphertext, and that proof). None of it lets the server read the page. Keys exist only in the links returned to you.
  • Sharing. No third parties. The server talks to exactly one host, html.cloud, and only when you share or update a page. No analytics, no telemetry, no account.
  • Retention. A page is unavailable from the moment its link expires (7 or 30 days, or never if you chose that) and its ciphertext is permanently deleted by a daily clean-up; deleting via the edit link removes it at once.
  • Contact. Email [email protected] or open an issue at github.com/viljamilaurila/html-cloud.

Honest threat model

Anyone with the share link can read the file — the link is the credential. The server can expire or delete ciphertext but can never read it. See html.cloud/security for details and limitations.

Source: github.com/viljamilaurila/html-cloud · MIT

來源:mcp/README.md,提交 9066f9f

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.4.1最新Oct 7, 2026