Install /host
Encrypted HTML hosting. Prefer local MCP (on-device encrypt) when the prototype is on disk, then remote MCP, then the CLI, then REST.
Trust
- Local MCP / CLI: encryption happens on your machine. The server never sees HTML. It stores the key so the share URL can stay short.
- Remote MCP: the server sees HTML only while handling that request. Prefer local MCP when the prototype lives on disk.
Remote MCP
Cloud agents that cannot spawn npx connect to Streamable HTTP. host takes HTML content, not a filesystem path. Headers are optional for anonymous host. A Bearer qhh_... key from the dashboard attaches the host to your account.
{
"mcpServers": {
"quickhtmlhost": {
"url": "https://quickhtmlhost.com/mcp",
"headers": { "Authorization": "Bearer qhh_..." }
}
}
}
CLI
npx @quickhtmlhost/cli host ./dist
export QHH_API_KEY=qhh_... # optional, from the dashboard
npx @quickhtmlhost/cli login
Cursor
Add to ~/.cursor/mcp.json or .cursor/mcp.json:
{
"mcpServers": {
"quickhtmlhost": {
"command": "npx",
"args": ["-y", "@quickhtmlhost/mcp"],
"env": { "QHH_API_KEY": "qhh_..." }
}
}
}
Then run /host or ask the agent to host the current prototype folder.
Claude Code / Claude Desktop
claude mcp add quickhtmlhost -- npx -y @quickhtmlhost/mcp
Or in claude_desktop_config.json use the same mcpServers block as Cursor.
VS Code Copilot
Add to .vscode/mcp.json (note the servers key):
{
"servers": {
"quickhtmlhost": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@quickhtmlhost/mcp"],
"env": { "QHH_API_KEY": "qhh_..." }
}
}
}
Windsurf
Add to ~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"quickhtmlhost": {
"command": "npx",
"args": ["-y", "@quickhtmlhost/mcp"],
"env": { "QHH_API_KEY": "qhh_..." }
}
}
}
What /host does
- Reads a folder (skips
.git,node_modules,.env*, and common secret files). - Zips and encrypts on-device with AES-256-GCM (bundled crypto; browsers also load
/crypto/v1.js). - Uploads ciphertext and the key, then returns a short URL with no fragment.
Remote MCP does the same zip/encrypt step in memory from the HTML you pass, then drops plaintext and the key.