veilfile

agent setup

MCP

Veilfile hosts a Streamable HTTP MCP server at POST https://veilfile.com/mcp. It speaks JSON-RPC 2.0. Auth is your API key on every request:

Authorization: Bearer <key>

Keys start with vlf_. The server exposes three tools: upload_artifact, list_artifacts, revoke_artifact.

Claude Code

claude mcp add --transport http veilfile https://veilfile.com/mcp \
  --header "Authorization: Bearer $VEILFILE_API_KEY"

Your shell expands the variable before Claude Code sees it.

Codex

codex mcp add veilfile --url https://veilfile.com/mcp --bearer-token-env-var VEILFILE_API_KEY

Or in ~/.codex/config.toml:

[mcp_servers.veilfile]
url = "https://veilfile.com/mcp"
bearer_token_env_var = "VEILFILE_API_KEY"

Antigravity

In ~/.gemini/config/mcp_config.json (Antigravity uses serverUrl):

{
  "mcpServers": {
    "veilfile": {
      "serverUrl": "https://veilfile.com/mcp",
      "headers": { "Authorization": "Bearer $VEILFILE_API_KEY" }
    }
  }
}

If the variable is not expanded, paste the key value directly.

Gemini CLI

In ~/.gemini/settings.json (Gemini CLI uses httpUrl for Streamable HTTP):

{
  "mcpServers": {
    "veilfile": {
      "httpUrl": "https://veilfile.com/mcp",
      "headers": { "Authorization": "Bearer $VEILFILE_API_KEY" }
    }
  }
}

Cursor

In ~/.cursor/mcp.json (Cursor expands ${env:...}, so the raw key never sits in the file):

{
  "mcpServers": {
    "veilfile": {
      "url": "https://veilfile.com/mcp",
      "headers": { "Authorization": "Bearer ${env:VEILFILE_API_KEY}" }
    }
  }
}

Or install in one click (uses the config above; you paste your own key in Cursor):

Add to Cursor

VS Code

In .vscode/mcp.json (remote entries need "type": "http"; VS Code prompts for the key once and stores it):

{
  "servers": {
    "veilfile": {
      "type": "http",
      "url": "https://veilfile.com/mcp",
      "headers": { "Authorization": "Bearer ${input:veilfile_key}" }
    }
  },
  "inputs": [
    { "type": "promptString", "id": "veilfile_key", "description": "Veilfile API key", "password": true }
  ]
}

Windsurf

In ~/.codeium/windsurf/mcp_config.json:

{
  "mcpServers": {
    "veilfile": {
      "serverUrl": "https://veilfile.com/mcp",
      "headers": { "Authorization": "Bearer ${env:VEILFILE_API_KEY}" }
    }
  }
}

Refresh from the Cascade panel after saving.

Other clients

Point any MCP client at https://veilfile.com/mcp over Streamable HTTP. The client must send Authorization: Bearer <key> on every request, with the key read from the VEILFILE_API_KEY environment variable or your secret manager. Header configuration differs per client. Check its docs.

When a secret is flagged

Uploads are scanned for secret-shaped content. The scan warns. It never blocks. A flagged upload is stored and its link works.

If secret_flags is non-empty in the upload response, do not share the link. Ask the user whether to keep or revoke the upload. Flagged responses also carry a warning field with this instruction.

For never-host semantics, check secret_flags in every upload response. Call revoke_artifact (or DELETE /api/v1/artifacts/<id>) when it is non-empty.

No MCP? Use REST

Any agent that can make HTTP calls can use the REST API instead. See the API reference.