SEAL for MCP

Your agent seals the file. The link comes to you.

Model Context Protocol server for Claude, Cursor, Cline and any MCP host.

npx -y sealnet-mcp@latest

Works with Claude · Cursor · Cline

Antique brass navigation compass

By default, the link stays out of the chat.

Letting an AI agent share files is useful; letting it hold the links is a leak waiting to happen, because anything in the model’s context can end up in a log, a transcript or the next tool call. sealnet-mcp keeps the link out of that context: in handoff mode the model creates the seal and receives an opaque handle. The share link goes to your clipboard; on a machine without one it goes to a permission-locked local file, which an agent allowed to read files there can read too.

When you genuinely need the model to pass a link onward, forward mode exists as an explicit opt-in, fenced by a 30-minute TTL cap, single read and a required recipient address, with every use written to an encrypted audit log.

Connect the agent to your SEAL inbox once, with seal_pair, and files go there instead: nothing to copy, no link in the chat, no file left on the agent’s machine. Every seal it makes also waits in your inbox, where you open its page or revoke it.

Your inbox first

After seal_pair the file goes to your SEAL inbox; before it, to your clipboard or a private file. The model sees a receipt.

Fenced forwarding

Opt-in, TTL ≤ 30 min, single read, recipient address required.

Encrypted state

One key per agent: from SEAL_SEED, the OS keychain or a 0600 file; the state file is encrypted with it.

One config entry, the whole tool set.

  1. Add the server

    One entry in claude_desktop_config.json or ~/.cursor/mcp.json: npx -y sealnet-mcp@latest. Production defaults are baked in, so there are no environment variables.

  2. Nothing to set up

    The first start creates the agent’s key: in the OS keychain, or in a 0600 file where there is none. Set SEAL_SEED to give the agent the same key in a container or a cloud session.

  3. Ask the agent

    “Seal build/report.pdf for 1 day and give it to me.” The agent calls seal_share; the file appears in your inbox, or the URL on your clipboard when no inbox is connected.

  4. Stay in control

    seal_request asks you for a key or a folder through a system dialog, so nothing is pasted into the chat; seal_list, seal_revoke and seal_open keep you in charge of the rest.

Self-hosted SEAL? Point SEAL_MCP_BACKEND_URL and SEAL_MCP_PUBLIC_HOST at your deployment. The two origins are independent and never derived from each other.

Questions, answered.

Who is this for?
Anyone letting an AI agent touch real files: developers with coding agents, analysts with research assistants, teams automating document flows. The agent gets the capability to share; the link goes to you, not into the chat.
Does the model see the link?
No. With your inbox connected the model gets a handle and the file goes to your inbox; in handoff mode the link goes to your clipboard or a private file. SEAL keeps the link out of the chat; it does not stop an agent from reading files you let it read.
Which hosts are supported?
Anything that speaks MCP over stdio: Claude Desktop, Claude Code, Cursor, Cline and compatible hosts.
Where does state live?
In an encrypted state file under your config directory. Owner tokens are inside it; the file alone, without the agent’s key, revokes nothing.
npx -y sealnet-mcp@latest

Works with Claude · Cursor · Cline

Read the documentation

One seal. Every platform.