Veilfile

io.github.yourimaginationwillbefiredv1.0.0更新於 Oct 6, 2026

Private, expiring artifact hosting for AI agents. Upload via API or MCP; links die on their own.

已驗證Streamable HTTP可網頁執行Developer ToolsFiles & Storage

概覽

AI 產生的概覽

Veilfile 讓助理把檔案上傳到私有且會自動過期的連結,並可列出或撤銷這些檔案。

功能
Veilfile 是針對代理產物的託管儲存服務。透過其 MCP 伺服器提供 upload_artifact、list_artifacts 與 revoke_artifact,助理可以上傳截圖、日誌包或 HAR 檔案,並取得一個難以猜測、會自動過期的連結。上傳內容會被掃描是否含有機密特徵並加以標記,相同操作也可透過 REST API 完成。
適用情境
適合在 CI 或雲端工作階段中執行的編碼代理產出需要人工檢視的檔案、而公開儲存庫或共享雲端硬碟又不合適的情境。也適合連結應在設定時間後失效的短期交付。
執行需求
遠端 Streamable HTTP 端點,不需要本機執行環境。需要先在 Veilfile 儀表板完成電子郵件驗證後核發的 API 金鑰,以 Authorization 標頭依 Bearer vlf_... 形式送出。金鑰只顯示一次,必須自行保存。免費方案每月 100 次上傳,最長有效期 7 天。
安裝前請注意
Authorization 標頭攜帶的 bearer API 金鑰可存取該帳號下的檔案,應視為機密保存,外洩後立即撤銷。上傳的檔案會離開本機並由該服務儲存,敏感內容應視為已揭露給第三方。上傳僅標記機密特徵而不攔阻,外洩的憑證仍可能被發布。付費方案涉及 Stripe 計費。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Veilfile,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "veilfile": {
      "type": "http",
      "url": "https://veilfile.com/mcp"
    }
  }
}

README

Veilfile — private, ephemeral artifact hosting for AI agents

When a coding agent in CI or a cloud session produces a screenshot, log bundle, or HAR file for review, it needs a private URL to put it at — not a public repo. Veilfile is the sanctioned place: upload via API key (or MCP), get back an unguessable, expiring URL. Uploads are scanned for secret shapes and flagged (never blocked, never logged).

  • API: POST /api/v1/artifacts (multipart, Authorization: Bearer vlf_…) → {id, url, expires_at, size_bytes, secret_flags[]}. GET /a/<token> serves the file (the 256-bit token is the auth). List/revoke endpoints included.
  • MCP: hosted Streamable HTTP server at POST /mcp (upload_artifact, list_artifacts, revoke_artifact), same vlf_ keys.
  • Dashboard: session-auth React app at /app/ — API keys (raw key shown once), usage vs plan caps, artifact table with secret-flag badges + revoke, Stripe billing portal.
  • Landing page: / (public). Agent docs: /llms.txt, docs/API.md.

See SPEC.md for the product spec.

Plans

PlanPriceUploads/moMax TTLAPI keys
Free$01007 days1
Team$4/mo2,00090 days5
Scale$12/mo10,000365 daysunlimited

Quickstart (local dev)

bash
# Backendpython3 -m venv venv && ./venv/bin/pip install -r backend/requirements.txtexport DJANGO_DEBUG=True DJANGO_SECRET_KEY=dev-only-key./venv/bin/python backend/manage.py migrate./venv/bin/python backend/manage.py createsuperuser   # dashboard login./venv/bin/python backend/manage.py runserver          # :8000
# Frontend (separate terminal; proxied /api -> :8000)cd frontend && npm install && npm run dev               # :5173

Sign up at http://localhost:8000/accounts/signup/ (or log in), open /app/, create an API key, then:

bash
curl -H "Authorization: Bearer vlf_..." \     -F "[email protected]" \     http://localhost:8000/api/v1/artifacts/

Environment variables

No secrets are committed to this repo. Copy the names below into a local .env (gitignored) or your host's env config. Stripe stays in TEST mode until live keys are connected.

VariableRequiredDefaultNotes
DJANGO_SECRET_KEYprod—Required when DJANGO_DEBUG is false
DJANGO_DEBUGnoFalseSet True for local dev
DJANGO_ALLOWED_HOSTSprod—Comma-separated, e.g. veilfile.example.com
DATABASE_URLnosqliteProd: Postgres URL
DROP_BASE_URLprodhttp://localhost:8000Public URL; artifact links are built from it
DROP_STORAGEnolocallocal (dev) or s3 (prod)
DROP_LOCAL_DIRnobackend/media/artifactsLocal storage root
AWS_S3_ENDPOINT_URLprod (s3)—R2 endpoint, e.g. https://<acct>.r2.cloudflarestorage.com
AWS_S3_BUCKETprod (s3)—R2 bucket name
AWS_ACCESS_KEY_IDprod (s3)—R2 API token (access key)
AWS_SECRET_ACCESS_KEYprod (s3)—R2 API token (secret)
STRIPE_SECRET_KEYbilling—Test-mode secret key (sk_test_…)
STRIPE_WEBHOOK_SECRETbilling—Webhook signing secret (whsec_…)
STRIPE_PRICE_TEAMbilling—Price ID for the $4/mo Team plan (tax-inclusive)
STRIPE_PRICE_SCALEbilling—Price ID for the $12/mo Scale plan (tax-inclusive)
PORTprod8000Set by the host (Render)

Without Stripe vars, checkout/portal return 503 billing_not_configured and the dashboard shows a friendly note; everything else works.

Tests

bash
cd backend && DJANGO_DEBUG=True DJANGO_SECRET_KEY=dev-only-key \  ../venv/bin/python manage.py test# 73 tests: drop_core (34) + drop_billing (17) + drop_mcp (22)
bash
cd frontend && npm run build   # must succeed; assets resolve under /static/

Ops

  • TTL sweeper (daily cron): python backend/manage.py sweep_expired deletes expired artifacts (files + rows). Idempotent.
  • Storage: Render's disk is ephemeral — production must use DROP_STORAGE=s3 (Cloudflare R2).
  • MCP registries: launch checklist in docs/REGISTRIES.md.

Project layout

backend/  config/          Django settings/URLs (env-driven)  drop_core/       Workspace, APIKey (vlf_), Artifact, plans, storage,                   secret scan, agent API, key mgmt, sweeper  drop_billing/    Stripe checkout/portal/webhook (live, tax-inclusive, Managed Payments)  drop_mcp/        Streamable HTTP MCP server (POST /mcp)  templates/       login/logout/signup pagesfrontend/          React + Vite (base: '/static/'); / landing, /app/ dashboarddocs/              API.md, llms.txt (served at /llms.txt), REGISTRIES.mdDockerfile         multi-stage node -> python build, WhiteNoise + gunicornrender.yaml        Render deploy blueprint

Launch checklist

  1. Create Cloudflare R2 bucket + API token (S3-compatible).
  2. Create Stripe products/prices (Team $4, Scale $12, tax-inclusive) with product tax codes; note the price IDs.
  3. Deploy on Render (see render.yaml); set env vars incl. DROP_BASE_URL.
  4. Point Stripe webhook at https://<host>/api/v1/billing/webhook; set STRIPE_WEBHOOK_SECRET.
  5. Add daily cron: python backend/manage.py sweep_expired.
  6. List the MCP server per docs/REGISTRIES.md.

來源:README.md,提交 53a88ce

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.0.0最新Oct 6, 2026