Skip to main content
Glama
GlaserIngo

Stript MCP Bridge

by GlaserIngo
README.md
# Stript MCP Bridge

`@stript/mcp` is a local [Model Context Protocol](https://modelcontextprotocol.io) server that lets
Claude (Desktop and Code) anonymize documents through the **Stript** desktop app **on your own
machine** — so personal data never enters the conversation.

> **Requires the Stript desktop app** with **AI integrations** enabled in Settings. The bridge does
> nothing on its own; it is a thin, local client to the app.

## What it does

Claude hands the bridge a *local reference* — a file path, the clipboard, or an existing Stript
document id. The bridge asks the **local** Stript app to detect personal data and replace it with
consistent placeholders like `[PERSON_1]`. Only the anonymized text is returned to the conversation.
Restored (real-PII) output is written to your clipboard or a local file and is **never** returned to
the model.

## Install

**Claude Desktop** — install the signed `Stript.mcpb` from the Stript app
(Settings → *Install for Claude Desktop*), or from `https://downloads.stript.io/Stript.mcpb`.

**Claude Code:**

```bash
claude mcp add stript -- npx -y @stript/mcp
```

### Allowed folders (required before file access)

Stript reads files only from folders you explicitly allow. There is **no default folder list**:
until you allow at least one folder, the bridge starts and `stript_status` works, but every
file-reading tool answers with guidance instead of file content (fail-closed).

- **Claude Desktop**: set *Folders Stript may read documents from* in the extension settings.
- **Claude Code / npx**: set `STRIPT_MCP_ALLOWED_DIRS` (path-separator-joined list of absolute
  paths), e.g. `STRIPT_MCP_ALLOWED_DIRS="$HOME/Documents:$HOME/Desktop"`.

Keep the list as narrow as your workflow allows. Relative paths and unresolved placeholders are
ignored rather than guessed.

## Tools

| Tool | Purpose | Nature |
|------|---------|--------|
| Check the Stript app status | Confirm the app is running and reachable | read-only |
| Anonymize a document with Stript | Detect + replace PII in a file on disk | writes anonymized output |
| Anonymize the clipboard text with Stript | Same, for the current clipboard (opt-in; Claude asks first) | writes anonymized output |
| Fetch a Stript anonymization result | Retrieve a completed result | read-only |
| Restore original values into placeholder text | Put the real values back (to clipboard or a local file) | writes locally, never to chat |
| Restore original values into a file | Restore a full file on disk | writes locally, never to chat |

## How it works — privacy by design

- The bridge talks **only to `127.0.0.1`**: the Stript app's local backend and a loopback broker
  inside the signed app. It makes **no external network calls** with your content.
- A **per-launch, scope-restricted token** gates every call; ports and token rotate on each launch.
- **Restored real values never enter tool results** — they are written to your clipboard or a local
  file only.
- New documents meter through the same local path as the app; the bridge keeps only a small **local**
  usage-metering mirror and nothing else persistent.

## Privacy Policy

Stript is local-first. From the [Stript Privacy Policy](https://stript.io/en/privacy):

> "Your documents are processed exclusively on your own device."
>
> "No document content, file name, path, document identifier, source commitment, mapping, detection
> result, entity information, or export activity is transmitted to us or any third party."

**This bridge inherits that guarantee:**

- **Collects and transmits no document content.** All detection and anonymization run locally in the
  Stript app; the bridge only shuttles data between Claude and the local app over loopback.
- **Stores nothing** beyond a local usage-metering mirror on your own machine.
- **Shares nothing** with third parties — it makes no off-device network calls.

The broader Stript product's data handling — optional account email, payment processing via Lemon
Squeezy, hosting and privacy-preserving analytics via Cloudflare, transactional email via Resend, and
the associated retention periods and contact details — is described in full in the
[Privacy Policy](https://stript.io/en/privacy). Direct privacy questions to the contact listed there.

## Build from source

```bash
npm ci
npm run build     # bundles dist/index.js (esm, node20)
npm test          # vitest
npm run check     # tsc --strict (bridge + card UI)
```

## License

[MIT](LICENSE). The Stript desktop app this bridge connects to is a separate, proprietary product.

TDQS

A4.4/5.0

Scored across 5 tools

Disambiguation4/5

The tools are largely distinct: anonymize_file initiates new processing, fetch_result retrieves existing results, restore and restore_file handle inverse operations for text and files, and status checks the app state. Some minor overlap exists between anonymize_file and fetch_result (both return anonymized content) and between the two restore tools, but the descriptions provide sufficient differentiation.

Naming Consistency3/5

All tools share the 'stript_' prefix and use snake_case, but the pattern is inconsistent: most are verb_noun (stript_anonymize_file, stript_fetch_result, stript_restore_file), while stript_restore lacks an object and stript_status is a noun rather than a verb. This makes the naming somewhat predictable but not uniform.

Tool Count5/5

With 5 tools, the server is well-scoped for its purpose: anonymize, fetch result, restore (both text and file), and check status. This is within the ideal 3-15 range and each tool serves a necessary step in the Stript workflow without unnecessary bloat.

Completeness5/5

The tool set covers the full lifecycle: anonymizing files, fetching results (including waiting for review), restoring placeholders in AI responses or files, and checking system status. There are no obvious dead ends or missing operations for the stated purpose of bridging Stript anonymization into MCP.

Maintenance

ActivityMaintained
ResponsivenessNo issues