New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

portveil-mcp

Package Overview
Dependencies
Maintainers
1
Versions
9
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

portveil-mcp

MCP server for Portveil: let AI assistants see your devices and move them between VPN locations.

latest
Source
npmnpm
Version
0.4.3
Version published
Weekly downloads
471
Maintainers
1
Weekly downloads
 
Created
Source

Portveil MCP server

Let an AI assistant see the devices on your Portveil account and move them between VPN locations.

"Move my scraper box to Finland." "Rotate every agent to a new location." "Which of my devices aren't protected right now?" "Rotate the scraper between the US and Finland every 15 minutes."

Moves are verified: a tool only reports success after the device has switched and the exit server in the new location confirms it sees that device.

Tools

ToolWhat it doesNeeds
list_devicesEvery device: protected or not, where it exits, live speed (↓/↑ Mbps), remote control on/offread
list_locationsThe locations you can move toread
get_deviceOne device's current state, including live speed and any rotationread
get_accountPlan and devices usedread
list_activityRecent moves, reconnects and changes, and which token made themread
move_deviceMove a device to a country or city ("Finland", "US", "Helsinki")control
rotate_deviceMove a device once to the next locationcontrol
start_rotationMove a device automatically every N minutes (5–10080), optionally among chosen locations. Portveil runs the schedule, so the assistant can closecontrol
stop_rotationTurn scheduled rotation offcontrol
reconnect_deviceRe-establish a device's tunnelcontrol
disconnect_deviceTurn a device's VPN off (flagged destructive: a hint that tells well-behaved assistants to check with you first)control
add_deviceAdd a device. Phones and laptops (WireGuard app): creates it and saves its tunnel files locally, key never shown in chat. Linux servers and agent machines: gives the exact commands to run on that machine, which makes its own key and registers itselfadmin (phones/laptops)
update_deviceRename a device and/or turn its remote control on or offadmin
remove_deviceRemove a device for good (flagged destructive)admin

Tool names changed in 0.3.0 to one verb_noun pattern: device_status → get_device, account_info → get_account, recent_activity → list_activity, set_rotation → start_rotation.

Devices can be named loosely ("scraper" finds "Scraper box"); an ambiguous name returns the choices instead of guessing.

Setup

No account yet? Start free with just an email, no card.

  • In the Portveil dashboard, create an API token. Choose control scope to let the assistant move devices, or read to let it only look. Don't give it your account key.
  • Note your account ID (acct_…).
  • Add the server to your assistant:

Claude Code

claude mcp add portveil -e PORTVEIL_ACCOUNT_ID=acct_… -e PORTVEIL_TOKEN=clt_… -- npx -y portveil-mcp

Claude Desktop (claude_desktop_config.json), Cursor (.cursor/mcp.json) and most other clients:

{
  "mcpServers": {
    "portveil": {
      "command": "npx",
      "args": ["-y", "portveil-mcp"],
      "env": { "PORTVEIL_ACCOUNT_ID": "acct_…", "PORTVEIL_TOKEN": "clt_…" }
    }
  }
}

Hermes Agent: Hermes only installs npm packages older than 14 days, so install into its own folder and run it with node:

cd ~ && npm install --prefix ~/.hermes/mcp-servers/portveil portveil-mcp@0.4.3
echo 'PORTVEIL_TOKEN=clt_…' >> ~/.hermes/.env
hermes mcp add portveil --command node \
  --env PORTVEIL_ACCOUNT_ID=acct_… 'PORTVEIL_TOKEN=${PORTVEIL_TOKEN}' \
  --args ~/.hermes/mcp-servers/portveil/node_modules/portveil-mcp/dist/index.js

For Hermes to use it well (when to act, what to confirm first, how to add devices), also install the Portveil skill from ClawHub:

hermes skills install roybogs/portveil

(Source: skills/portveil/SKILL.md.)

Devices must be running the Portveil app or the Portveil agent with remote control on. Devices using the plain WireGuard app are shown but can't be moved.

Security

  • Use a scoped API token. Every action it takes is recorded in your account's activity log with the token that made it, and you can revoke it in the dashboard at any time.
  • The server talks only to https://api.portveil.com (override with PORTVEIL_API). It stores nothing.

Development

npm install
npm test        # builds, then runs the tests against a fake Portveil API

Keywords

mcp

FAQs

Package last updated on 27 Sep 2026

Related posts