
Company News
Jerod Santo Joins Socket as Head of Media
Allow myself to introduce... myself.
@honeycrisp/remote
Advanced tools
The remote gateway: the suite's governed MCP servers over loopback HTTP with bearer tokens, scopes, and principal-annotated audit — reach them from your own devices via your own tunnel
The suite's governed MCP servers, reachable beyond the terminal they run in — with the contract intact. One gateway process serves the mail and context tools over MCP streamable HTTP on loopback only; going further than this Mac is always an explicit, separate step you take with your own tunnel.
honeycrisp-remote token mint --label my-laptop # shown once, hashed on disk
honeycrisp-remote serve # foreground
honeycrisp-remote on | off | status # launchd lifecycle
Mounts appear at http://127.0.0.1:7811/mcp/mail and /mcp/context
(port configurable via remote.port in the suite's config.json; a
malformed config refuses to serve rather than guessing).
The gateway binds 127.0.0.1 and offers no way to bind wider. To reach it
from your own devices, share the port over your private network, e.g.:
tailscale serve --bg 7811
Public exposure (for cloud clients like claude.ai connectors) additionally
needs OAuth and is a separate design (docs/05, milestone M2) — a long
random path and a bearer token on a public URL is not that.
token mint shows the secret exactly once;
this Mac stores its SHA-256 and metadata (remote-tokens.json, mode 0600).
Verification is constant-time. Revocation takes effect on the next request
— even mid-session.read tokens can call only read tools; calls to anything else
are refused before the approval gate and leave an audit row naming the
token. --write tokens meet the same gate as local callers: dry-run unless
live mode is on, and per-action human approval either way. A stolen write
token cannot send mail — it can only ask, and the ask becomes an approval
request on channels the token holder doesn't control.token:<id> session:<id> — the audit DB answers who asked, not just what
ran.Any MCP client that speaks streamable HTTP:
{
"url": "http://127.0.0.1:7811/mcp/mail",
"headers": { "Authorization": "Bearer hc_…" }
}
Over a tailnet, replace the host with the Mac's tailnet name.
FAQs
The remote gateway: the suite's governed MCP servers over loopback HTTP with bearer tokens, scopes, and principal-annotated audit — reach them from your own devices via your own tunnel
We found that @honeycrisp/remote demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.

Security News
Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor.