The hosted SnapHost MCP endpoint gives your assistant a safe set of tools to publish and refresh sites over HTTP, with nothing to install. Connect it in the browser and your AI can keep a site live as it works.
SnapHost runs a remote MCP server at https://app.snaphost.ai/api/mcp. There is no binary to download, and an OAuth-capable client needs no token: on first connect a browser opens for you to click Authorize, and the connection lasts until you revoke it. The credential is negotiated machine-to-machine and never passes through the chat. How you add the server depends on the client you use.
Connectors live on your Claude account, so add SnapHost once in a web browser and the desktop app picks it up too. SnapHost is a custom connector: it is not in Claude’s connector directory, and it is not in the list you land on, which holds only the connectors you already have. You add it by pasting its URL.
https://app.snaphost.ai/api/mcp.No + on that page? Then it is a permission on your Claude account rather than a button you have not found yet, and which one you are decides what to do next.
Could you add a custom connector to our Claude organization?
Name: SnapHost
URL: https://app.snaphost.ai/api/mcp
Where: Claude Settings, then Organization settings, then Connectors, then Add.
It signs in with OAuth, so there is no API key or shared secret to distribute, and each
person who connects reaches only their own SnapHost workspaces. Once you have added it, we each
enable it from our own Connectors page.
What it does: SnapHost publishes documents as private, shareable websites. The connector
lets Claude publish and update those sites directly instead of me copying files around.If Claude answers without actually calling a SnapHost tool (for example by offering to write code or a test file instead), the connector is not enabled in that chat: start a fresh conversation and check the tools menu again.
While you wait on an Owner, or if the answer is no, the Claude desktop app can still run it as a local MCP server, which is configured on your own machine rather than on your Claude account. It talks to the same hosted endpoint and opens the same Authorize page, so there is still no token to paste. It needs Node.js installed.
Add this to claude_desktop_config.json (macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\), keeping any mcpServers entries already there, then quit and reopen the desktop app:
{
"mcpServers": {
"snaphost": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://app.snaphost.ai/api/mcp"]
}
}
}The first run opens your browser to authorize. If your workplace restricts local MCP servers too, that is another admin setting, and the remaining route is an agentic client such as Claude Code below.
Cursor and VS Code install the server from a link. Everything else is one command in a terminal: it finds the agent clients on your machine (Claude Code, Cursor, VS Code, Windsurf, Codex CLI, Gemini CLI) and configures each one. No token is involved either way; the browser Authorize flow starts on first use.
npx snaphost connect/plugin marketplace add snaphost-ai/snaphost
/plugin install snaphost@snaphostAn agentic client registers the server itself. On Claude Code it is one command, and the browser Authorize flow starts on first use:
claude mcp add --transport http snaphost https://app.snaphost.ai/api/mcpAny client that supports HTTP (Streamable) MCP with OAuth works the same way: point it at the endpoint URL and approve the browser prompt. The server advertises its authorization server at /.well-known/oauth-authorization-server and answers an unauthenticated request with a 401 pointing there.
If your assistant runs in a sandbox with a network allowlist (Claude Code on the web, some corporate setups), the MCP connection and the assistant’s shell are separate channels: the tools work while a plain HTTP request from the shell is refused. Nothing needs to change for that: a large bundle, or a single file, travels as numbered parts through the upload_bundle_part tool, on the same connection as every other call. Allowing app.snaphost.ai in the sandbox’s network settings only unlocks the faster route of one PUT from the shell; the storage host is optional.
For an MCP client that cannot do the browser flow, authenticate with a SnapHost API token sent as a bearer header. A token can publish and change your sites, so treat it like a password: pass it as an environment variable or request header, never paste it into a chat or commit it. Create one in the dashboard, export it, then add the server.
export SNAPHOST_TOKEN="<your token>"claude mcp add --transport http snaphost \
https://app.snaphost.ai/api/mcp \
--header "Authorization: Bearer $SNAPHOST_TOKEN"Any HTTP (Streamable) MCP connector works the same way: point it at the endpoint URL and send Authorization: Bearer <token>.
{
"mcpServers": {
"snaphost": {
"type": "http",
"url": "https://app.snaphost.ai/api/mcp",
"headers": {
"Authorization": "Bearer YOUR_API_TOKEN"
}
}
}
}Create one token per agent so you can revoke a single client without disrupting the others, and revoke it any time from the dashboard.
The server exposes a small, focused set of tools. Each one maps to an action you could take in the dashboard, so there are no surprises.
| Tool | Effect | What it does |
|---|---|---|
Publish site publish_site | Write | Publish a site from HTML, a bundle, or a single document (Markdown, a notebook, a PDF, a Word, PowerPoint or Excel file, a CSV, an image, a video, an audio, a Mermaid diagram, a text file or a React component) and return its stable link. Pass a slug to update the same site in place on later calls. A Word, PowerPoint or Excel file is shown as its page alone unless include_original is true; the result reports original_included and any render_notices. |
Update site update_site | Write | Replace the contents of an existing site by id without changing its link, visibility, or allowlist. A new version of a Word, PowerPoint or Excel file keeps offering, or withholding, the file for download as the live version does, unless include_original says otherwise. |
Create bundle upload create_bundle_upload | Write | Start an upload for a bundle too large to inline, or for a single non-zip file sent as it is with its filename, then publish or update with the upload_id it returns. |
Upload bundle part upload_bundle_part | Write | Send the .zip, or a single file, in numbered slices over the MCP connection itself, so an AI with no network access of its own can still publish a multi-file site or a lone document. A bundle can also be PUT to the upload URL where the AI can reach it. |
Get site content get_site_content | Read | Fetch a site’s current entry document by id so your AI can read it, edit it, and push it back with update_site. A site rendered from a file returns its page; original: true returns the file itself when the page offers it. |
List workspaces list_workspaces | Read | List the workspaces the connection can act in: your personal space and every workspace you belong to, with your role in each. Pass a workspace_id to any other tool to act there. A read without one acts in your personal space; a write without one is refused when you belong to more than one workspace. |
List sites list_sites | Read | List the non-deleted sites in one workspace (the personal space unless a workspace_id is passed) with their status, visibility, links, and expiry. Filter by visibility, status, link expiry state, or sites expiring within N days. |
Get site get_site | Read | Fetch one site’s status, visibility, current version, view count, and the allowlist it’s shared with. Reports whether the page offers the uploaded file for download (original_included) and whether that can be changed (original_withholdable). |
Set visibility set_visibility | Write | Switch a site between public and a verified allowlist. |
List allowlist list_allowlist | Read | Show who a private site is currently shared with before you change it. |
Add to allowlist add_to_allowlist | Write | Add emails and/or domains to a private site’s allowlist without dropping anyone already on it. |
Remove from allowlist remove_from_allowlist | Destructive | Take specific emails and/or domains off a private site’s allowlist, leaving everyone else. |
Set allowlist set_allowlist | Write | Replace a private site’s entire allowlist with a new set of emails and/or domains (overwrites the existing list). |
Set render options set_render_options | Write | Set per-site delivery: deep-link routing and auto-refresh on update (free) and the external-origin allowlist (paid). include_original false stops a Word, PowerPoint or Excel site offering its file, as a new version rendered from the file it holds. |
Add external origins add_external_origins | Write | Trust external https origins a site loads from (CDN scripts, font hosts, embeds) without replacing the ones already allowed (paid). Publish and update flag blocked origins automatically. |
Set link expiry set_link_expiry | Write | Set or clear an expiry on a site’s share link. Setting one needs Pro; clearing one works on every plan. |
Set view password set_view_password | Write | Protect a site behind a view password, so the link alone is not enough to open it. The password is never echoed back. |
Clear view password clear_view_password | Destructive | Remove a site’s view password so anyone who may view it can open the link without one. |
List access requests list_access_requests | Read | List people waiting for approval to view a private site. |
Approve access request approve_access_request | Write | Approve a pending access request: the requester is allowlisted and can view the site. |
Deny access request deny_access_request | Destructive | Deny a pending access request: the requester is not allowlisted and still cannot view the site. |
Delete site delete_site | Destructive | Delete a site: purge its content and make the link non-viewable. |
List versions list_versions | Read | List a site’s versions newest-first with their size and timestamp. |
Roll back site rollback_site | Destructive | Restore a prior version as the current content; the link stays the same. |
The effect column is what the server tells your AI through MCP tool annotations: a read never changes anything, a write creates or changes a site, and a destructive tool removes or reverts something. Clients use these to decide what to ask you before running.
Install the SnapHost plugin and your assistant gets ready-made commands (/snaphost:connect, /snaphost:workspace, /snaphost:publish, /snaphost:update, /snaphost:share, and /snaphost:data) that drive these same tools, so you skip explaining them every time.
Give publish_site a slug and the publish becomes idempotent: the first call creates the site, and every later call with the same slug updates it in place at the same URL. Anyone already viewing is told a new version is available and gets it with one click on Refresh, so your assistant can iterate while an audience follows along.
update_site and rollback_site work the same way: the share link, visibility, and allowlist all stay put. Pair it with a custom domain on Pro and your audience always has one stable address, with no manual uploads and no broken links.
Every tool reports failures as a structured result with a stable code and a human-readable message, mirroring the REST API. An assistant can branch on the code (drop a disallowed file on bundle_invalid, prompt for an upgrade on plan_limit) instead of parsing prose.
{
"code": "bundle_invalid",
"message": "Disallowed file type in bundle: script.exe"
}The same hosted server is published as ai.snaphost/snaphost in the official MCP registry, and listed on Smithery, Glama, and npm. The registry entry, the Claude Code plugin, and the listing maintainers live in the public repository at github.com/snaphost-ai/snaphost.