# Quick HTML Host

> Encrypted HTML prototype hosting. Local MCP and the CLI encrypt on-device so the server never sees HTML. Share URLs are short; the server stores the key so visitors do not need a `#k=` fragment. Remote MCP at https://quickhtmlhost.com/mcp encrypts in memory for that request.

Preferred agent path: **local MCP** (on-device encrypt) → **remote MCP** (`https://quickhtmlhost.com/mcp`) → **CLI** → REST.

## Docs

- [Markdown docs](https://quickhtmlhost.com/docs.md)
- [HTML docs](https://quickhtmlhost.com/docs)
- [OpenAPI](https://quickhtmlhost.com/openapi.json)
- [Current crypto](https://quickhtmlhost.com/crypto/current.json)
- [MCP discovery](https://quickhtmlhost.com/.well-known/mcp.json)

## MCP

- Local stdio (preferred when the prototype is on disk): `npx -y @quickhtmlhost/mcp`
- Remote Streamable HTTP: `POST https://quickhtmlhost.com/mcp` (optional `Authorization: Bearer qhh_...`)

## CLI

`npx @quickhtmlhost/cli host ./dist`

## Constraints

- Ciphertext cap: 10 MB
- Rate limit: 30 uploads / hour / IP
- Anonymous hosts do not expire (sign in to list and delete them from the dashboard)
- `POST /v1/hosts` expects **already-encrypted** QHH1 ciphertext — use MCP or CLI unless you implement `@quickhtmlhost/crypto`
- Do not scrape or index viewer URLs (`/p/...`, `/:shortId`, or `{id}.` subdomains). Hosted pages stay encrypted at rest and `noindex`.

## Trust

- Local MCP / CLI: encryption on-device; the server never sees HTML. The key is stored so the share link stays short.
- Remote MCP: the server sees HTML **only while handling that request**. Prefer local MCP when the prototype lives on disk.
