MCP
Veilfile hosts a Streamable HTTP MCP server at POST https://veilfile.com/mcp. It speaks JSON-RPC 2.0. Auth is your API key on every request:
Authorization: Bearer <key>
Keys start with vlf_. The server exposes three tools: upload_artifact, list_artifacts, revoke_artifact.
Claude Code
claude mcp add --transport http veilfile https://veilfile.com/mcp \
--header "Authorization: Bearer $VEILFILE_API_KEY"
Your shell expands the variable before Claude Code sees it.
Codex
codex mcp add veilfile --url https://veilfile.com/mcp --bearer-token-env-var VEILFILE_API_KEY
Or in ~/.codex/config.toml:
[mcp_servers.veilfile]
url = "https://veilfile.com/mcp"
bearer_token_env_var = "VEILFILE_API_KEY"
Antigravity
In ~/.gemini/config/mcp_config.json (Antigravity uses serverUrl):
{
"mcpServers": {
"veilfile": {
"serverUrl": "https://veilfile.com/mcp",
"headers": { "Authorization": "Bearer $VEILFILE_API_KEY" }
}
}
}
If the variable is not expanded, paste the key value directly.
Gemini CLI
In ~/.gemini/settings.json (Gemini CLI uses httpUrl for Streamable HTTP):
{
"mcpServers": {
"veilfile": {
"httpUrl": "https://veilfile.com/mcp",
"headers": { "Authorization": "Bearer $VEILFILE_API_KEY" }
}
}
}
Cursor
In ~/.cursor/mcp.json (Cursor expands ${env:...}, so the raw key never sits in the file):
{
"mcpServers": {
"veilfile": {
"url": "https://veilfile.com/mcp",
"headers": { "Authorization": "Bearer ${env:VEILFILE_API_KEY}" }
}
}
}
Or install in one click (uses the config above; you paste your own key in Cursor):
VS Code
In .vscode/mcp.json (remote entries need "type": "http"; VS Code prompts for the key once and stores it):
{
"servers": {
"veilfile": {
"type": "http",
"url": "https://veilfile.com/mcp",
"headers": { "Authorization": "Bearer ${input:veilfile_key}" }
}
},
"inputs": [
{ "type": "promptString", "id": "veilfile_key", "description": "Veilfile API key", "password": true }
]
}
Windsurf
In ~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"veilfile": {
"serverUrl": "https://veilfile.com/mcp",
"headers": { "Authorization": "Bearer ${env:VEILFILE_API_KEY}" }
}
}
}
Refresh from the Cascade panel after saving.
Other clients
Point any MCP client at https://veilfile.com/mcp over Streamable HTTP. The client must send Authorization: Bearer <key> on every request, with the key read from the VEILFILE_API_KEY environment variable or your secret manager. Header configuration differs per client. Check its docs.
When a secret is flagged
Uploads are scanned for secret-shaped content. The scan warns. It never blocks. A flagged upload is stored and its link works.
If secret_flags is non-empty in the upload response, do not share the link. Ask the user whether to keep or revoke the upload. Flagged responses also carry a warning field with this instruction.
For never-host semantics, check secret_flags in every upload response. Call revoke_artifact (or DELETE /api/v1/artifacts/<id>) when it is non-empty.
No MCP? Use REST
Any agent that can make HTTP calls can use the REST API instead. See the API reference.