# @shardflux/mcp

Persistent cloud workspaces for AI agents: run commands, edit files, use git and a browser.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.12.2
- **Author:** dev.shardflux
- **License:** Apache-2.0
- **npm:** @shardflux/mcp
- **Endpoints:** streamable-http https://mcp.shardflux.dev/mcp
- **Source:** https://docs.shardflux.dev/reference/mcp
- **Endpoint health:** reachable (last checked 2026-10-09T15:15:43.293Z, 1 sample) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the package rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 0 days

## Security scan

- **Status:** warnings
- **Scanned:** 2026-10-09T15:15:28.801Z
- **Version scanned:** 0.13.0
- **CVEs:** none found by OSV at scan time

## Tools

35 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `project_space_reader` — Open a read-only workspace to fetch saved project branches and transcripts.
- `credential_fill` — Fill the workspace browser from an approved vault item. Returns filled or a refusal, never the value.
- `credential_requests_list` — List pending login approvals, without credential values.
- `credential_request_deny` — Refuse a pending login request.
- `credential_request_fulfil` — Relay a credential already sealed to the workspace one-time public key. Accepts ciphertext only.
- `volume_open` — Create or reuse a project volume by name. Waits until available unless wait is false.
- `volume_list` — List project volumes, optionally including organization shared volumes.
- `agents_list` — List coding agent sessions in this project.
- `workspace_open` — Open a persistent workspace by key: creates it from the template on first use, reconnects (or resumes) it afterwards, never resets it. Waits until it is ready u
- `workspace_list` — List the workspaces of this API key’s project (key, state, template, active operation).
- `workspace_status` — Current state of one workspace (ready, mode, observed/desired state, grants, pending reason; tree_revision for a file-first workspace) and its most recent opera
- `workspace_idle` — Read idle policy and activity without waking or recording activity.
- `workspace_hint` — Stage a parked workspace ahead of an imminent VM tool call. Invoke explicitly when tool input starts; returns without waiting for restore. A suspended workspace
- `workspace_keepalive` — Prevent idle suspension for seconds; never shortens an existing keepalive.
- `workspace_set_retention` — Delete a persistent workspace after this many idle days (1..3650). null removes its own policy and follows the project default.
- `workspace_set_idle_policy` — Set adaptive, never or fixed:<seconds> (60..604800); default restores the inherited policy.
- `workspace_set_labels` — Replace all labels; an empty object clears them. Labels are searchable metadata, not secrets.
- `workspace_suspend` — Suspend a running workspace (full-state checkpoint; processes stop, files and state are kept, and the next tool call resumes it). Returns the suspend operation 
- `workspace_fork` — Fork a running or suspended workspace into a new key (an independent copy of its committed state). Returns the fork operation and the new workspace (with wait: 
- `workspace_upgrade` — Keep files, installed package files and home while moving to the supported current layout/base. One cold start ends memory and running processes. at next_resume
- `workspace_resize`
- `operation_wait` — Wait for a lifecycle operation (open, suspend, resume, fork, ...) to finish, up to timeout_ms. Returns the operation and the wait’s timing. With durable (a susp
- `workspace_expose_port`
- `workspace_list_ports` — The exposed ports of the workspace: {ports: [{port, url, created_at, callback}]}, ordered by port. callback is set when the port has a callback URL for webhooks
- `workspace_close_port` — Stop serving an exposed port: its URL stops answering and every link to it stops working at once. Idempotent (also when the port is not exposed). Returns {port,
- `workspace_port_link` — A link that opens an exposed port in a browser: give it to the person you work for, or open it yourself. Returns {url, expires_at}. Opening it starts a browser 
- `workspace_set_computer_use` — Switch computer use on or off for a workspace (inherit follows its template). While it is on, the computer tool drives the workspace desktop, which starts on th
- `workspace_computer_stream` — A link to watch the workspace desktop live in a browser (view only unless interactive): give it to the person you work for. Returns {url, expires_at, port, inte
- `workspace_computer_desktop` — The workspace desktop itself. status: whether it runs, its screen size and its viewers (never starts it). start: start it at a screen size (640x480 to 2560x1600
- `template_get` — A template this project can open: its versions (state, source, installed tools, immutable paths) and each version’s settings (env, open-time inputs, start comma
- `template_languages` — The languages (python, node, go, rust, java) and versions a base offers a recipe v2’s build.languages, e.g. base "ubuntu-24.04@1". included: the base already ha
- `template_build`
- `usage_summary`
- `send_feedback`
- `shardflux`

## Install

**Verdict: review** — Installable, but 1 thing to check first: No publisher has proved control of this listing; it is indexed, not vouched for.
**Cautions** (coverage gaps and advisories — never blocking)
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"mcp\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@shardflux/mcp\"\n      ],\n      \"env\": {\n        \"SHARDFLUX_API_KEY\": \"<YOUR_SHARDFLUX_API_KEY>\",\n        \"SHARDFLUX_WORKSPACE_KEY\": \"<YOUR_SHARDFLUX_WORKSPACE_KEY>\"\n      }\n    }\n  }\n}"
```
**Credentials it will ask for** (names only — Forge never holds a value):
- `SHARDFLUX_API_KEY` — Shardflux API Key (required)
- `SHARDFLUX_WORKSPACE_KEY` — Shardflux Workspace Key (optional)
Placeholders only. Forge never holds, brokers, or transmits a credential value — replace each <YOUR_NAME> in your own config file. Do not send a value back to Forge; no Forge endpoint accepts one.
- This entry needs 2 credentials (1 required). The generated config carries placeholders, so it will fail in the editor rather than at runtime if they are left unset.

## Blast radius

Moderate blast radius — runs locally and hosted; holds an api key.
- Floor 29, ceiling 29 (tier: moderate)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/%40shardflux%2Fmcp
- Install plan: https://forgeregistry.com/api/v1/packages/%40shardflux%2Fmcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/%40shardflux%2Fmcp
- HTML page: https://forgeregistry.com/registry/%40shardflux%2Fmcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
