Secure, expiring artifact storage and handoff for AI agents.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
Secure temporary file sharing for AI agents and humans.
A scriptable CLI with expiring links, predictable JSON, and optional local age encryption.
aispace.sh is a bot-friendly file drop for outputs that are too large, structured, or temporary for chat. The open-source client is deliberately easy to automate: one binary, stable exit codes, streaming uploads, and share URLs printed on a predictable final line.
Sealed transfers, agent identities, device pairing, and adaptive durable-first intent are experimental surfaces. Ordinary uploads and durable R2 storage continue to work alongside them.
The hosted service is operated separately. This repository contains the client, agent skill, and integration examples—not the server, billing system, deployment configuration, or customer data.
Install the latest release:
Authenticate with a key created in the aispace dashboard, then store a file:
On a Pro account, add a separately expiring public handoff:
The URL is printed last on its own line, making it easy for an agent or shell script to capture.
Add --json for a stable machine-readable response. An abridged response looks like:
Other installation channels:
Pin the shell installer with AISPACE_VERSION=v1.2.3. Release binaries support macOS, Linux, and
Windows on amd64 and arm64. The shell installer supports macOS and Linux; use npm on Windows.
The repository includes a reusable Codex-compatible skill. Clone the repository and link the skill into your personal Codex skills directory:
Restart Codex, then ask it to use aispace when it needs to hand you a report, archive, image, or
other generated artifact. The skill defaults to account-private storage unless you request a public
link, prefers short expirations, and treats encryption identities as credentials.
The native CLI also exposes ten typed MCP tools over local stdio. Create a separately scoped bot key in the dashboard, export it in the environment that launches Codex, and add:
Run codex mcp list to verify the connection. The ChatGPT desktop app, Codex CLI, and Codex IDE
extension on the same host share this configuration. Keep the key in a secret store or injected
environment; never put its expanded value in a committed project file or command argument. See
docs/CLI.md for Claude Code and generic-host examples.
For custom agent runtimes, docs/LLM_USAGE.md includes a system-prompt snippet,
OpenAI/Anthropic-compatible tool schemas, and a reference Python handler. See examples
for runnable shell, CI, and encrypted-handoff recipes.
Follow docs/SECURE_HANDOFFS.md for sealed bundles, trusted agent
inboxes, device pairing, adaptive R2 fallback, and recovery. The complete command reference is in
docs/CLI.md; the HTTP contract is in docs/API.md.
upload accepts --name, --expires, --content-type, --sha256, --link, --link-expires,
--max-downloads, --private, --shared, --encrypt, --recipient, and --identity-out.
Uploads stream from disk. Encrypted uploads use age X25519 locally and store ciphertext as
<name>.age; the secret identity is never sent to the API.
transfer create uses aispace-sealed-v1: AES-256-GCM authenticated chunks and an encrypted
manifest support multiple files, ranged retry, and a verified receipt. transfer receive accepts
the secret from its prompt, --token-file, or AISPACE_TRANSFER_TOKEN; avoid putting a full
fragment link or token in a process argument on shared systems.
transfer create --json omits bearer links and tokens unless --include-secret is explicit, and
secret-inclusive JSON must be redirected rather than written to a terminal. handoff encode
likewise accepts the protected prompt, --token-file, or AISPACE_TRANSFER_TOKEN.
With --json, errors also remain structured and are written to stderr. upload --link --json
returns {"file": File, "link": ShareLink}; encrypted uploads add an "encryption" object.
Precedence: flag > environment > config file > default.
| Setting | Flag | Env | File key | Default |
|---|---|---|---|---|
| API key | --key | AISPACE_KEY | key | — |
| Server | --url | AISPACE_URL | url | https://aispace.sh |
AISPACE_AGE_IDENTITY supplies a decryption identity when decrypt --identity-file is omitted.
It is deliberately not accepted as a command-line value.
Config file: $XDG_CONFIG_HOME/aispace/config.json (default ~/.config/aispace/config.json), written with
mode 0600. A warning is printed if the file is readable by others. AISPACE_CONFIG overrides the path.
Durations (--expires, --link-expires) accept Go syntax plus a d suffix: 30m, 24h, 7d, 1d12h,
or a bare number of seconds. Omitting them uses the server defaults (7 days for files, 1 hour for
Pro public links).
File visibility controls authenticated key access. A public link is a separate capability: creating one requires a Pro account and makes that one file available to anyone holding the URL.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/aispace)<a href="https://allmcps.com/mcp/aispace"><img src="https://allmcps.com/api/badge/aispace?style=directory" alt="Aispace on AllMCPs" /></a>