
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
portveil-mcp
Advanced tools
MCP server for Portveil: let AI assistants see your devices and move them between VPN locations.
Let an AI assistant see the devices on your Portveil account and move them between VPN locations.
"Move my scraper box to Finland." "Rotate every agent to a new location." "Which of my devices aren't protected right now?" "Rotate the scraper between the US and Finland every 15 minutes."
Moves are verified: a tool only reports success after the device has switched and the exit server in the new location confirms it sees that device.
| Tool | What it does | Needs |
|---|---|---|
list_devices | Every device: protected or not, where it exits, live speed (↓/↑ Mbps), remote control on/off | read |
list_locations | The locations you can move to | read |
get_device | One device's current state, including live speed and any rotation | read |
get_account | Plan and devices used | read |
list_activity | Recent moves, reconnects and changes, and which token made them | read |
move_device | Move a device to a country or city ("Finland", "US", "Helsinki") | control |
rotate_device | Move a device once to the next location | control |
start_rotation | Move a device automatically every N minutes (5–10080), optionally among chosen locations. Portveil runs the schedule, so the assistant can close | control |
stop_rotation | Turn scheduled rotation off | control |
reconnect_device | Re-establish a device's tunnel | control |
disconnect_device | Turn a device's VPN off (flagged destructive: a hint that tells well-behaved assistants to check with you first) | control |
add_device | Add a device. Phones and laptops (WireGuard app): creates it and saves its tunnel files locally, key never shown in chat. Linux servers and agent machines: gives the exact commands to run on that machine, which makes its own key and registers itself | admin (phones/laptops) |
update_device | Rename a device and/or turn its remote control on or off | admin |
remove_device | Remove a device for good (flagged destructive) | admin |
Tool names changed in 0.3.0 to one verb_noun pattern: device_status → get_device, account_info → get_account, recent_activity → list_activity, set_rotation → start_rotation.
Devices can be named loosely ("scraper" finds "Scraper box"); an ambiguous name returns the choices instead of guessing.
No account yet? Start free with just an email, no card.
acct_…).Claude Code
claude mcp add portveil -e PORTVEIL_ACCOUNT_ID=acct_… -e PORTVEIL_TOKEN=clt_… -- npx -y portveil-mcp
Claude Desktop (claude_desktop_config.json), Cursor (.cursor/mcp.json) and most other clients:
{
"mcpServers": {
"portveil": {
"command": "npx",
"args": ["-y", "portveil-mcp"],
"env": { "PORTVEIL_ACCOUNT_ID": "acct_…", "PORTVEIL_TOKEN": "clt_…" }
}
}
}
Hermes Agent: Hermes only installs npm packages older than 14 days, so install into its own folder and run it with node:
cd ~ && npm install --prefix ~/.hermes/mcp-servers/portveil portveil-mcp@0.4.3
echo 'PORTVEIL_TOKEN=clt_…' >> ~/.hermes/.env
hermes mcp add portveil --command node \
--env PORTVEIL_ACCOUNT_ID=acct_… 'PORTVEIL_TOKEN=${PORTVEIL_TOKEN}' \
--args ~/.hermes/mcp-servers/portveil/node_modules/portveil-mcp/dist/index.js
For Hermes to use it well (when to act, what to confirm first, how to add devices), also install the Portveil skill from ClawHub:
hermes skills install roybogs/portveil
(Source: skills/portveil/SKILL.md.)
Devices must be running the Portveil app or the Portveil agent with remote control on. Devices using the plain WireGuard app are shown but can't be moved.
https://api.portveil.com (override with PORTVEIL_API). It stores nothing.npm install
npm test # builds, then runs the tests against a fake Portveil API
FAQs
MCP server for Portveil: let AI assistants see your devices and move them between VPN locations.
The npm package portveil-mcp receives a total of 471 weekly downloads. As such, portveil-mcp popularity was classified as not popular.
We found that portveil-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.