Skip to main content
Glama
Managed-Digital-LLC

justdrop-mcp

justdrop-mcp

Give your AI agent a way to hand you files — live, end-to-end encrypted, nothing stored.

justdrop-mcp is an MCP (Model Context Protocol) server for JustDrop. Your agent creates a room, you scan a QR or open a link on any device, and the files move — encrypted before they leave the machine, decrypted only on yours, gone when the room closes. No account on either end. The receiving device needs nothing installed: just a browser.

You:    "drop dist/report.pdf to my phone"
Agent:  Room code: brave-otter-4821
        Link: https://justdrop.ai/app#join=brave-otter-4821
        [QR code]
You:    *scan, tap, done — the room self-destructs*

It works the other way too: "grab the screenshot from my phone" gives you a QR; whatever you drop from the phone lands decrypted in your working directory, and the agent keeps working with it.

Install

Requires Node.js 20+.

claude mcp add justdrop -- npx -y justdrop-mcp

Or in .mcp.json / any MCP client config:

{
  "mcpServers": {
    "justdrop": {
      "command": "npx",
      "args": ["-y", "justdrop-mcp"],
      "env": {
        "JUSTDROP_ROOT": "C:/path/to/allowed/folder"
      }
    }
  }
}

Related MCP server: vnsh-mcp

Tools

Tool

What it does

drop

Send files/folders. Returns room code + link + QR immediately; the transfer runs automatically when the recipient opens the link. Pass room_code to send into an existing room instead.

receive

Receive files into a directory. Creates a room (code + link + QR) and saves anything dropped into it, decrypted, automatically. Pass room_code to join a room someone else created.

status

Live progress: peer presence, per-file state, saved paths.

cancel

Destroys a room this session created (files + metadata deleted), or leaves a joined room.

Configuration

Env var

Default

Meaning

JUSTDROP_BASE_URL

https://justdrop.ai

Backend to talk to (point at http://localhost:3000 for local dev).

JUSTDROP_ROOT

server's working directory

The only directory the server may read from / save into.

JUSTDROP_DEFAULT_EXPIRY_MINUTES

60

Room lifetime when a tool doesn't specify one (1–1440).

Safety model

An MCP server that reads local files is a prompt-injection target, so the guardrails are structural, not polite suggestions:

  • Root jail — every path (sent or saved) must resolve inside JUSTDROP_ROOT. Anything else is refused.

  • Credential refusal — dotfiles (.env, .npmrc, …), SSH/TLS keys, keystores, cloud credential files, and shell histories are never sent, even when named explicitly. There is no override flag.

  • Explicit manifests — every drop result lists exactly which files were queued, so the user sees what's leaving.

  • Server-side blocklist parity — extensions JustDrop rejects (.exe, .bat, …) are refused up front with a hint to zip instead.

  • Ephemeral by default — rooms carry an expiry (default 60 min) and self-destruct after delivery.

How the transfer works

  1. drop creates a room and registers an RSA-2048 public key; the tool returns the code/link/QR immediately.

  2. When the recipient opens the link, their browser registers its own key. Rooms are one-to-one by design — treat the room code like the secret it is.

  3. Each file gets a fresh AES-256-GCM key, encrypted for both parties' RSA keys. The encrypted blob is relayed through short-lived signed URLs — the relay never sees plaintext or keys.

  4. Delivery is observed live; the room (and everything in it) is destroyed afterwards.

Files are encrypted in one shot in memory (format parity with the web app), so very large files need commensurate RAM. The hard cap is 2GB per file.

Local development

npm install
npm run verify   # builds, boots ../justdrop-simple dev server, runs both test suites

# or piecewise, against a server you started yourself:
npm run build
node test/e2e.mjs http://localhost:3000        # core roundtrip (both directions + SSE)
node test/mcp-smoke.mjs http://localhost:3000  # full MCP stdio protocol exercise

License

MIT

Available Tools

1 tool
statusCheck a transferA

Shows the live status of a JustDrop transfer started with drop or receive: peer presence, per-file progress, saved paths, and errors. Call with no room_code to list all transfers in this session.

ParametersJSON Schema
NameRequiredDescriptionDefault
room_codeNoRoom code returned by drop/receive

TDQS

A4.2/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations provided, so description carries full burden. It describes the data shown but does not explicitly state it is read-only, nor does it disclose any behavioral traits like rate limits or authentication. The implication is non-destructive, but could be more explicit.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences; no redundant words. Front-loaded with the main action and details, then calling modes. Every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the simple tool (one optional param, no output schema), the description covers the key aspects: what status information is included and how to call. It does not detail the output format, but lists contents, which is sufficient.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Parameter schema has 100% coverage describing room_code. The description adds context that omitting room_code lists all transfers, which adds value beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Description clearly states it shows live status of a JustDrop transfer and lists included details (peer presence, per-file progress, saved paths, errors). It also distinguishes two calling modes, making the purpose precise and unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Description explains when to use the tool (after drop or receive) and how to call it with or without room_code. Since there are no sibling tools, no explicit when-not-to is needed, but it could include a note about prerequisites.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

TDQS

A4/5.0
Disambiguation5/5

Only one tool exists, so there is no ambiguity between tools.

Naming Consistency5/5

With a single tool, naming consistency is trivially perfect.

Tool Count2/5

A single tool for a file transfer server is too few; essential operations like initiating a drop or receive are missing.

Completeness2/5

The server only provides a status tool, lacking the core drop and receive tools needed to perform file transfers.

Maintenance

ActivitySlowing
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables sharing and reading encrypted files (text, images, logs) for AI workflows, with automatic 24-hour expiration and host-blind security.
    1,132
    155
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to securely transfer files between machines via encrypted, expiring share links, with tools for upload, download, status checks, and link management.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Secure file exchange MCP server enabling AI agents to upload, share, fetch, and revoke files with SHA-256 verification, malware scanning, expiry, access restrictions, and human approval workflows.
    12
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Managed-Digital-LLC/justdrop-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server