Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI โ†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE โ†— (opens in a new tab)
  • llms.txt โ†— (opens in a new tab)
  • Catalog JSON โ†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub โ†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
ยฉ 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. ๐Ÿ”’ Security
  3. Qurl MCP
Qurl MCP logo
Health: ActiveRecent health check succeeded.Last checked 9/9/2026, 8:16:27 PM

Qurl MCP

User RatingsBe the first to rate and review this MCP server!
View Repository4 GitHub StarsTotal stargazers on GitHub for the source repository (4 stars).Visit Website
securityaccess-controlsecure-linksfile-sharingmcp

Creates, resolves, audits, and rotates expiring, scope-limited qURLs for AI agent access.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag โ€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON โ–พ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "layervai-qurl-mcp": {
      "command": "npx",
      "args": [
        "@layervai/qurl-mcp"
      ]
    }
  }
}

๐Ÿ’ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing Alternatives๐Ÿ”’ More in Security

Overview

qURL MCP exposes tools for creating, managing, resolving, and sharing secure access links through local stdio or authenticated HTTP mode. It supports qURL lifecycle management, token and session controls, and uploading text or files to mint links. Use it when an agent needs controlled, expiring access to protected resources.

Use cases

โ€ขCreate expiring access links for protected resources
โ€ขResolve access tokens into target URLs
โ€ขRotate or revoke qURL tokens and sessions
โ€ขUpload text or files and mint shareable qURLs
โ€ขAudit current links, usage, and active sessions

Key features

โ€ขCreate, list, read, update, extend, and delete qURLs
โ€ขMint links and batch-create multiple qURLs
โ€ขResolve and revoke access tokens
โ€ขList and terminate active qURL sessions
โ€ขUpload local files, base64 file content, or text
โ€ขExpose qURL lists and usage through MCP resources

Capabilities & Tool Schemas

Inspect callable tools, capabilities, and parameters exposed to AI agents by Qurl MCP.

Extracted Tool Capabilities
Create, list, read, update, extend, and delete qURLs
Mint links and batch-create multiple qURLs
Resolve and revoke access tokens
List and terminate active qURL sessions
Upload local files, base64 file content, or text
Expose qURL lists and usage through MCP resources

Documentation Overview

@layervai/qurl-mcp

npm version

โš ๏ธ Renamed from @layerv/qurl-mcp in v0.4.0. The old package is deprecated and will not receive further updates. If you're using @layerv/qurl-mcp@0.3.x, swap the scope in your MCP client config โ€” same binary, same API key, no other changes.

A qURL MCP Server that supports both local stdio mode and remote HTTP mode for creating, managing, resolving, and sharing secure access links.

Overview

qURL MCP exposes qURL capabilities to MCP clients, GPTs, ChatGPT, and other remote integrations.

It currently supports:

  • creating, reading, updating, and deleting qURLs
  • resolving access tokens
  • managing qURL tokens and sessions
  • uploading text or file content and generating qURLs
  • serving public legal pages
  • serving a configurable MP4 video playback page

Runtime Modes

ModePurposeStart CommandTypical Use Case
stdioLocal subprocess MCP servernpm run startClaude Desktop, Cursor, Codex, and other local MCP clients
httpAuthenticated remote MCP servernpm run start:httpRemote agent runtimes behind HTTPS

Feature Map

qURL Management Tools

ToolDescription
create_qurlCreate a new qURL
resolve_qurlResolve an access token into a protected target URL
list_qurlsList qURL resources
get_qurlFetch details for a single qURL
delete_qurlDelete a qURL
extend_qurlExtend qURL expiration
update_qurlUpdate qURL metadata or expiration
mint_linkMint a new access link for an existing resource
batch_create_qurlsCreate multiple qURLs in one request
revoke_qurl_tokenRevoke a specific token
update_qurl_tokenUpdate a specific token
list_qurl_sessionsList active access sessions
terminate_qurl_sessionsTerminate one or all active sessions

Upload Tools

ToolModeDescription
upload_file_qurlstdioUpload a local file and mint a qURL
upload_file_data_qurlstdio/HTTPUpload base64 file content and mint a qURL
upload_text_qurlstdio/HTTPUpload text content and mint a qURL

upload_file_qurl is intentionally stdio-only. It can read any supported PDF/image that the local MCP process user can access, so agents should invoke it only for a path the user explicitly selected for sharing. Do not expose it to untrusted prompts or autonomous agents: prompt injection could otherwise select another readable PDF/image on the host. Run stdio under an OS account whose filesystem access is limited to intended shareable content. HTTP mode never registers this host-file tool. The byte/text tools are also available in stdio so local clients can share in-chat attachments without first materializing them at a known host path. Connector upload and qURL minting are separate operations. If minting fails after upload, the connector currently has no delete endpoint; the server logs the orphaned resource_id for operator cleanup and returns the mint failure. HTTP upload attempts remain bounded by the per-IP and per-credential MCP rate limits; stdio operators should separately constrain autonomous retry loops. Upload validation binds the declared media type to the filename plus format start/end markers; it is not a malware scanner or full PDF/image decoder. For polyglot resistance, a PDF's final %%EOF marker must be followed only by ASCII whitespace; producer output with other trailing bytes is rejected even if a permissive PDF reader would accept it. JPEG validation checks framing and terminal markers rather than decoding image segments. The authenticated connector must independently decode or otherwise fully validate content before storage when semantic media validity matters. It must also preserve the declared safe media type and serve downloads with X-Content-Type-Options: nosniff rather than inferring an executable type. There is intentionally no application-level path allowlist: symlinks and time-of-check/time-of-use races make a lexical prefix check a misleading security boundary. Use a dedicated OS account, container, or read-only mount whose readable files are already limited to the intended sharing directory. The final path component is opened with O_NOFOLLOW; intermediate directory symlinks retain normal filesystem behavior under this trusted-local-user boundary.

MCP Resources

URIDescription
qurl://linksCurrent qURL list
qurl://usageCurrent quota and usage information

MCP Prompts

PromptDescription
secure_a_serviceSecure service integration prompt
audit_linksLink audit prompt
rotate_accessAccess rotation prompt

Quick Start

1. Install Dependencies

Terminal
npm install

For a local stdio-only source install, use npm install --omit=optional; this omits the AWS SDK. HTTP deployments using the DynamoDB credential quota must use the ordinary install so the optional SDK is packaged.

2. Build

Terminal
npm run build

3. Start

Local stdio mode:

Terminal
npm run start

Remote HTTP mode:

Terminal
npm run start:http

MCP Client Example

If you want to use this server in stdio mode with a local MCP client:

config.json
{
  "mcpServers": {
    "qurl": {
      "command": "npx",
      "args": ["@layervai/qurl-mcp"],
      "env": { "QURL_API_KEY": "lv_live_xxx" }
    }
  }
}

Configuration Files

Copy the tracked examples to create local configuration files:

bash
cp qurl-mcp.config.example.json qurl-mcp.config.json
cp qurl-mcp.http.example.json qurl-mcp.http.json

The local files are gitignored so credentials and machine-specific paths are not committed.

Their responsibilities are:

FilePurpose
qurl-mcp.config.jsonShared runtime config used by both stdio and http modes
qurl-mcp.http.jsonHTTP-only server listener and public access config

qurl-mcp.config.json Reference

Shared Core Settings

FieldPurpose
maxUploadFileDataBytesLimits decoded and local file uploads (default 10mb)
defaultQurlApiUrlBase URL of the qURL backend API
defaultQurlConnectorUrlBase URL of the upload connector

Shared settings have these environment overrides. Environment values take precedence over the shared config file. The process caches resolved shared settings but automatically invalidates that cache when the file metadata or any relevant environment value changes.

Environment variableConfig field
MCP_MAX_UPLOAD_FILE_DATA_BYTESmaxUploadFileDataBytes
QURL_API_URLdefaultQurlApiUrl
QURL_CONNECTOR_URLdefaultQurlConnectorUrl
QURL_SMTP_HOSTsmtp.host
QURL_SMTP_PORTsmtp.port
QURL_SMTP_SECUREsmtp.secure
QURL_SMTP_USERNAMEsmtp.username
QURL_SMTP_PASSWORDsmtp.password
QURL_SMTP_FROM_EMAILsmtp.fromEmail
QURL_SMTP_FROM_NAMEsmtp.fromName
QURL_SMTP_ALLOWED_RECIPIENTSsmtp.allowedRecipients
QURL_SMTP_ALLOWED_RECIPIENT_DOMAINSsmtp.allowedRecipientDomains
QURL_SMTP_MAX_RECIPIENTS_PER_MESSAGEsmtp.maxRecipientsPerMessage
QURL_SMTP_MAX_RECIPIENTS_PER_HOURsmtp.maxRecipientsPerHour
QURL_PUBLIC_VIDEO_FILE_PATHpublicVideo.filePath
QURL_PUBLIC_VIDEO_TITLEpublicVideo.title
QURL_PUBLIC_VIDEO_PAGE_PATHpublicVideo.pagePath

Read the full README โ†’View source on GitHub โ†’

Related MCP Servers

View all in Security View all alternatives
  • Volta MCP Server logoVolta MCP Server

    Burn-after-read encrypted notes for AI agents. Create and read self-destructing notes via Volta Notes with AES-256-GCM E2E encryption โ€” the decryption key never leaves the URL fragment. Secure credential handoff between users and agents without secrets appearing in chat history.

    ๐Ÿ”’ Security3 views
    Compare vs Volta MCP Server โ†’
  • Apktool MCP Server logoApktool MCP Server

    APKTool MCP Server is a MCP server for the Apk Tool to provide automation in reverse engineering of Android APKs.

    ๐Ÿ”’ Security3 views
    Compare vs Apktool MCP Server โ†’
  • Shield logoShield

    Local guardrail proxy for AI coding agents. Wraps any MCP server (stdio or Streamable HTTP) and blocks destructive tool calls โ€” DROP TABLE, rm -rf, force-push โ€” before they execute. MCP supply-chain protection: TOFU tool-catalog pinning against rug pulls, plus tool-description and tool-result scanning for tool poisoning and prompt injection. 51 starter rules, approval gates, audit logging. Single binary, Apache-2.0.

    ๐Ÿ”’ Security3 views
    Compare vs Shield โ†’
  • Mobb Vibe Shield MCP logoMobb Vibe Shield MCP

    Mobb Vibe Shield identifies and remediates vulnerabilities in both human and AI-written code, ensuring your applications remain secure without slowing development.

    ๐Ÿ”’ Security2 views
    Compare vs Mobb Vibe Shield MCP โ†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks โ€” not a rating.

GitHub stars
4
Stargazers on the source repository.
npm downloads
151
Package downloads in the last 30 days.
Last commit
4d ago
Most recent push to the default branch.
Directory activity
1 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet โ€” be the first to share how this listing worked for you.

Frequently Asked Questions about Qurl MCP

It supports local stdio mode and authenticated remote HTTP mode.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewQurl MCP AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/layervai-qurl-mcp?style=directory)](https://allmcps.com/mcp/layervai-qurl-mcp)
HTML Embed
<a href="https://allmcps.com/mcp/layervai-qurl-mcp"><img src="https://allmcps.com/api/badge/layervai-qurl-mcp?style=directory" alt="Qurl MCP on AllMCPs" /></a>

Technical Specs & Signals

Category๐Ÿ”’Security
PricingBring your own API key (usage-based cost)
More technical detailsExpand โ–พ
TransportSTDIO
RuntimeNode.js
AuthAPI key
ClientsClaude Desktop, Cursor
Last updatedSep 7, 2026
11/11 checks healthy over the last 33d
Views1
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars4
GitHub Star CountTotal stargazers on GitHub representing community popularity (4 stars).
Last commit4d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 7, 2026
npm downloads151/mo
Monthly npm DownloadsAverage monthly package installs recorded from npm registry statistics.
56Quality signal: Good ยท 56/100How this signal is calculated โ–พ
Server availabilityNot measured

Not scored for repo-hosted servers โ€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools25/30
Adoption & activity7/15
Community engagement0/10

A guidance signal from public completeness & health data โ€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 27d ago via OSV.dev ยท @layervai/qurl-mcp (npm)

โ˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server โ†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge โ€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it โ€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in ๐Ÿ”’ Security โ†’Best MCP servers for Security โ†’Alternatives to Qurl MCP โ†’Install in Claude DesktopInstall in CursorInstall in VS Code