Skip to main content
Glama
vin-spiegel

htmldrop

by vin-spiegel

htmldrop turns any HTML, Markdown, PDF, or image artifact into a shareable link in seconds. Reports, dashboards, charts, demos — anything an agent (or a human) creates. Markdown/text/JSON render into a clean reader page; PDFs and images are served as-is. No git, no build, no dashboard.

Try it now: htmldrop.link — drag & drop an HTML file, paste HTML source, or POST to the API.

How it works

curl -X POST https://htmldrop.link/publish \
  -H "Content-Type: application/json" \
  -d '{"html":"<h1>Hello agents</h1>","title":"Demo"}'
{
  "url": "https://happy-otter-42.htmldrop.link",
  "id": "...",
  "subdomain": "happy-otter-42",
  "expires_at": "2026-07-17T00:00:00.000Z"
}

Every link gets its own subdomain, an auto-generated Open Graph preview card, and a TTL — shared artifacts don't live forever.

Related MCP server: dochost

Connect your agent (MCP)

The hosted MCP server lives at https://htmldrop.link/mcp (Streamable HTTP) and exposes one tool: publish_html.

Claude Code

claude mcp add --transport http htmldrop https://htmldrop.link/mcp

Claude Desktop

Claude Desktop speaks stdio, so bridge to the hosted server with mcp-remote. In claude_desktop_config.json:

{
  "mcpServers": {
    "htmldrop": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://htmldrop.link/mcp"]
    }
  }
}

Cursor

Cursor connects to a remote MCP URL directly. In .cursor/mcp.json:

{
  "mcpServers": {
    "htmldrop": { "url": "https://htmldrop.link/mcp" }
  }
}

Codex CLI

In ~/.codex/config.toml:

[mcp_servers.htmldrop]
command = "npx"
args = ["-y", "mcp-remote", "https://htmldrop.link/mcp"]

Self-hosted instance (npm, stdio)

Running your own htmldrop? The htmldrop-mcp package is a local stdio MCP server that publishes to your storage and domain:

{
  "mcpServers": {
    "htmldrop": {
      "command": "npx",
      "args": ["-y", "htmldrop-mcp"],
      "env": {
        "BASE_DOMAIN": "your-domain.example",
        "CLOUDFLARE_R2_ENDPOINT": "...",
        "CLOUDFLARE_R2_ACCESS_KEY_ID": "...",
        "CLOUDFLARE_R2_SECRET_ACCESS_KEY": "...",
        "CLOUDFLARE_R2_BUCKET_NAME": "..."
      }
    }
  }
}

publish_html tool

Argument

Type

Description

html

string

HTML content to publish (or use markdown / url)

markdown

string

Markdown content — rendered into a styled reader page

url

string

Remote HTML page to fetch and publish

title

string

Optional title for metadata and social cards

ttl_days

number

Days until the artifact expires

password

string

Optional password protection

owner_key

string

Optional key for higher limits and longer TTL

Full agent-facing docs live in AGENTS.md, also served at htmldrop.link/agents.md.

REST API

Endpoint

Body

Notes

POST /publish

JSON { html | markdown, title, ttl_days, password, url }

Primary endpoint

POST /publish/raw

raw body: text/html, text/markdown, text/plain, application/json, text/csv, application/pdf, image/*

Title via x-htmldrop-title header or ?title=

POST /publish/from-url

JSON { url, title, ttl_days, password }

Fetches and republishes a page

Pass an owner key in the x-htmldrop-key header for higher rate limits and a longer default TTL. (x-pin-key is still accepted for backwards compatibility.)

Self-hosting

git clone https://github.com/vin-spiegel/htmldrop.git
cd htmldrop
pnpm install
cp .env.example .env   # defaults work out of the box
pnpm dev               # http://localhost:3000

The only variable you need to set is BASE_DOMAIN. Everything else has a working default. Storage falls back to the local filesystem (./data) when no object store is configured — no database required.

Environment variables

Variable

Default

Description

BASE_DOMAIN

localhost

Base domain for artifact subdomains. The one value most self-hosters must set.

PORT

3000

HTTP port (usually set by your host)

NODE_ENV

development

Set to production when deploying

CLOUDFLARE_R2_ENDPOINT

S3-compatible endpoint. Set all four R2 vars to use object storage; leave all blank for filesystem

CLOUDFLARE_R2_ACCESS_KEY_ID

Object-storage access key

CLOUDFLARE_R2_SECRET_ACCESS_KEY

Object-storage secret key

CLOUDFLARE_R2_BUCKET_NAME

Bucket name

ANON_TTL_DAYS

7

TTL for anonymous publishes

KEY_TTL_DAYS

30

TTL for keyed publishes

MAX_HTML_SIZE_BYTES

26214400

Upload cap (25 MiB)

RATE_LIMIT_ANON_PER_MINUTE

10

Per-IP rate limit

RATE_LIMIT_KEY_PER_MINUTE

60

Per-owner-key rate limit

Any S3-compatible store works for the CLOUDFLARE_R2_* variables (Cloudflare R2, AWS S3, MinIO, …). On ephemeral/container hosts, either use object storage or mount a persistent volume at ./data, or artifacts are lost on redeploy.

Production needs a wildcard DNS record (*.your-domain) pointing at the server so artifact subdomains resolve.

Deploy to Railway

railway login
railway init --name htmldrop
railway up

Then set BASE_DOMAIN and (optionally) the R2 variables in the Railway dashboard, and attach your domain plus its wildcard.

Safety defaults

  • Artifacts are served with X-Robots-Tag: noindex, nofollow, noarchive

  • New HTML artifacts use a versioned CSP sandbox: inline scripts work, while external network requests/assets, forms, popups, and top-level navigation are blocked

  • Per-IP and per-key rate limits

  • Everything expires via TTL

  • Optional password protection per artifact

See SECURITY.md for vulnerability and abuse reporting.

Development

pnpm dev        # run with tsx
pnpm test       # vitest
pnpm run build  # tsc -> dist/

License

MIT

Available Tools

1 tool
publish_htmlAInspect

Publish an HTML or markdown artifact (or fetch a remote HTML page) and get a shareable URL. Markdown is rendered into a clean reader page. Useful for sharing reports, dashboards, visualizations, or any document produced by an agent.

ParametersJSON Schema
NameRequiredDescriptionDefault
urlNoURL of an HTML page to fetch and publish. Provide one of html, markdown, or url.
htmlNoHTML content to publish. Provide one of html, markdown, or url.
titleNoOptional page title for the published artifact.
markdownNoMarkdown content to publish; rendered into a styled reader page. Provide one of html, markdown, or url.
passwordNoOptional password protection for the artifact.
ttl_daysNoOptional custom TTL in days. Anonymous tier defaults to 7 days.
owner_keyNoOptional owner key for higher limits and ownership.

TDQS

A3.8/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must disclose behavioral traits. It mentions that Markdown is 'rendered into a clean reader page' and that publishing yields a 'shareable URL,' but it omits important behaviors such as the default TTL of 7 days for anonymous tier, password protection options, and ownership semantics. The description also does not mention potential side effects or limitations, leaving the agent unaware of constraints like expiration or access control.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences, with the first stating the core function and the second listing use cases. It is front-loaded, using specific terms like 'publish' and 'shareable URL' immediately. There is no fluff or redundant information, making it concise and well-structured.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description covers the primary purpose and output ('get a shareable URL'), and the schema handles parameter details. It does not explain the return structure or the effects of optional fields like ttl_days and password, but given the moderate complexity and absence of an output schema, the description is largely sufficient. However, it could be more complete by mentioning that published artifacts have a default TTL and can be password-protected, which are important operational details.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has 100% parameter description coverage, so the baseline is 3. The description adds minimal parameter-related context beyond the schema, such as clarifying that 'Markdown is rendered into a clean reader page.' However, it does not elaborate on the relationships between parameters (e.g., that html, markdown, and url are mutually exclusive alternatives), which the schema already conveys via the anyOf constraint. The description does not significantly enrich the schema's parameter meanings.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's function: 'Publish an HTML or markdown artifact (or fetch a remote HTML page) and get a shareable URL.' This is a specific verb+resource combination that unambiguously describes the action and output. Although no siblings are listed, the description is self-sufficient and leaves no doubt about the tool's purpose.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides clear context for when to use the tool: 'Useful for sharing reports, dashboards, visualizations, or any document produced by an agent.' This indicates appropriate scenarios but does not explicitly mention alternatives or exclusions. Since there are no sibling tools, the absence of explicit alternatives is acceptable, but the description could benefit from stating when not to use it (e.g., for non-publishable content).

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool updatev0.1.0
    • First observedpublish_html

TDQS

A3.9/5.0

Scored across 1 tool

Disambiguation5/5

With only one tool, there is no possibility of ambiguity. The tool's purpose is clearly defined and distinct by default.

Naming Consistency5/5

With a single tool, naming is trivially consistent. The verb_noun pattern (publish_html) is clear and appropriate.

Tool Count3/5

One tool is on the borderline of being too thin. While it may suffice for a simple publishing server, it feels minimal and could benefit from additional tools (e.g., list, delete).

Completeness3/5

The tool covers basic publishing and fetching, but lacks management capabilities like listing, updating, or deleting published content, which are notable gaps for a complete service.

Maintenance

ActivitySlowing
ResponsivenessWithin a week

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    Enables users to upload files and generate tracked, shareable links directly from AI agents like Claude Desktop or Cursor. It supports publishing various file formats including text, PDFs, and images, while providing tools for artifact management and analytics.
    8
    45 npm
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Publish Markdown or HTML to a shareable link from your AI assistant, then list, inspect, update or delete your pages. Six tools cover publishing, page management and account usage. Connect through hosted Streamable HTTP with OAuth, or use an API key for headless clients.
    6
    1
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables sharing artifacts (HTML, files, sites) with password protection and custom branding on your own domain, directly from any AI agent.
    8
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables publishing and updating web artifacts (HTML, Markdown, CSV, Mermaid) to get stable public URLs that update in place; supports lifecycle management like expiry and restoration.
    7
    23 npm
    MIT