# Install /host — Quick HTML Host

Encrypted HTML prototype hosting. Visitors decrypt in the browser. Share URLs are short.

Preferred agent path: **local MCP** (on-device encrypt) → **remote MCP** (`https://quickhtmlhost.com/mcp`) → **CLI** → REST.

## Trust

- **Local MCP / CLI:** encryption happens on-device. The server never sees HTML. It stores the key so the share URL can stay short.
- **Remote MCP:** the server sees HTML **only while handling that request**. Prefer local MCP when the prototype lives on disk.

## Remote MCP

For cloud agents that cannot spawn `npx` or read the local disk. Connect to Streamable HTTP at `https://quickhtmlhost.com/mcp`. `host` takes `html` (stored as `index.html`) and/or `files` as `{ path, content }` pairs — not filesystem paths. Anonymous `host` is allowed and does not expire. A Bearer `qhh_...` key from [the dashboard](https://quickhtmlhost.com/dashboard) attaches the host to your account and is required for `list_hosts` / `delete_host`.

Headers are optional for anonymous host:

```json
{
  "mcpServers": {
    "quickhtmlhost": {
      "url": "https://quickhtmlhost.com/mcp",
      "headers": { "Authorization": "Bearer qhh_..." }
    }
  }
}
```

## CLI

Local encrypt, then POST ciphertext.

```
npx @quickhtmlhost/cli host ./dist
export QHH_API_KEY=qhh_...   # optional, from https://quickhtmlhost.com/dashboard
npx @quickhtmlhost/cli login
```

## Cursor

Add to `~/.cursor/mcp.json` or `.cursor/mcp.json`:

```json
{
  "mcpServers": {
    "quickhtmlhost": {
      "command": "npx",
      "args": ["-y", "@quickhtmlhost/mcp"],
      "env": { "QHH_API_KEY": "qhh_..." }
    }
  }
}
```

Then run `/host` or ask the agent to host the current prototype folder.

## Claude Code / Claude Desktop

```
claude mcp add quickhtmlhost -- npx -y @quickhtmlhost/mcp
```

Or in `claude_desktop_config.json` use the same `mcpServers` block as Cursor.

## VS Code Copilot

Add to `.vscode/mcp.json` (note the `servers` key):

```json
{
  "servers": {
    "quickhtmlhost": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@quickhtmlhost/mcp"],
      "env": { "QHH_API_KEY": "qhh_..." }
    }
  }
}
```

## Windsurf

Add to `~/.codeium/windsurf/mcp_config.json`:

```json
{
  "mcpServers": {
    "quickhtmlhost": {
      "command": "npx",
      "args": ["-y", "@quickhtmlhost/mcp"],
      "env": { "QHH_API_KEY": "qhh_..." }
    }
  }
}
```

## What /host does

Local MCP / CLI:

1. Reads a folder (skips `.git`, `node_modules`, `.env*`, and common secret files).
2. Zips and encrypts on-device with AES-256-GCM (bundled crypto; browsers also load `/crypto/v1.js`).
3. Uploads ciphertext and the key, then returns a short URL with no fragment.

Remote MCP encrypts the provided HTML/files in memory, persists ciphertext and the key, returns the same style of URL, then drops plaintext.

## Constraints

- Ciphertext cap: 10 MB
- 30 uploads / hour / IP
- Anonymous hosts do not expire
- `POST /v1/hosts` expects already-encrypted QHH1 ciphertext
- Do not scrape viewer URLs

See also: [OpenAPI](https://quickhtmlhost.com/openapi.json), [llms.txt](https://quickhtmlhost.com/llms.txt), [current crypto](https://quickhtmlhost.com/crypto/current.json).
