Deploy static sites on Hostsmith - give it a file, get a live HTTPS URL. EU/US residency.
SaferSkills independently audited mcp-server (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Official Model Context Protocol server for the Hostsmith hosting platform.
Static hosting for agents - give it a file, get a live URL. Claude Code shipping an HTML report. Cursor previewing a generated demo. Claude Desktop publishing a one-pager. One MCP call → public HTTPS URL in seconds. No repo, no CI, no build step. Custom domains, private sites, EU or US data residency.
Deploy a page from Claude Code and get a live URL
| Tool | Description |
|---|---|
list_sites | List all sites in your account for a given data partition |
get_site | Get details of a specific site |
create_site | Create a new site |
delete_site | Delete a site |
list_domains | List available domains (shared and custom) |
get_account | Get account info, subscription plan, and usage |
deploy_files | Deploy inline file contents to a site |
deploy_create_upload | Start a direct upload for binaries / large files |
deploy_finalize | Commit a deploy started with deploy_create_upload |
Authentication is via OAuth 2.0. Static access tokens are not supported.
Open Settings → Connectors → Add custom connector and enter:
https://mcp.hostsmith.net/mcpClaude Desktop runs the OAuth flow in your browser to authorize the connector against your Hostsmith account.
Add this entry to your MCP client's config:
{
"mcpServers": {
"hostsmith": {
"command": "npx",
"args": ["-y", "@hostsmith/mcp-server"]
}
}
}The first tool call triggers an OAuth flow in your browser to authorize the server against your Hostsmith account.
Any MCP client that supports remote Streamable HTTP transport can point directly at the hosted server:
{
"mcpServers": {
"hostsmith": {
"url": "https://mcp.hostsmith.net/mcp"
}
}
}The client handles the OAuth flow automatically - you'll be redirected to Hostsmith to authorize access.
Click the badge to add the remote Hostsmith server (https://mcp.hostsmith.net/mcp) to Cursor. The first tool call triggers OAuth in your browser.
Run the server in HTTP mode and have your MCP client perform OAuth against it:
npx @hostsmith/mcp-server http{
"mcpServers": {
"hostsmith": {
"url": "http://localhost:3100/mcp"
}
}
}| Variable | Default | Description |
|---|---|---|
HOSTSMITH_URL | https://hostsmith.net | Hostsmith app URL (OAuth endpoints). |
HOSTSMITH_API_DOMAIN | - | Override the upstream API domain across both partitions. The server prepends us.api. and eu.api. to the value you set. Example: HOSTSMITH_API_DOMAIN=staging.example.com routes calls to https://us.api.staging.example.com and https://eu.api.staging.example.com. Use this to point at a staging or proxied API host. |
HOSTSMITH_BASE_URL | - | Override the API base URL with a single fixed value, bypassing partition selection entirely. |
PORT | 3100 | HTTP server port. |
MCP_BASE_URL | http://localhost:$PORT | Public URL of the MCP server, used in OAuth metadata. |
The MCP transport and OAuth flow run in your client's app process and need no agent-sandbox configuration - if your MCP client connected, those paths are working.
The one place sandboxed agents commonly fail is the upload PUT during deploy_create_upload + deploy_finalize: the bytes go from the agent's shell to the partition API host. From the agent terminal, allow outbound HTTPS (port 443) to:
us.api.hostsmith.net (for sites in the us partition)eu.api.hostsmith.net (for sites in the eu partition)Sandbox-specific snippets (Cursor sandbox.json, Claude Code settings.json, Codex config.toml, generic firewall guidance) live in the Network access docs.
MCP_BASE_URL matches the URL your MCP client uses to reach the server.partition arg; if you omit it, the partition is inferred from your access token.npx @modelcontextprotocol/inspector npx -y @hostsmith/mcp-server http to browse tools interactively.Deeper material lives at hostsmith.net/docs/mcp.
See CONTRIBUTING.md (including the Releases section for the version-stamping flow). Security issues: see SECURITY.md.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.