
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
srift-transfer
Advanced tools
Zero-config, zero-token peer-to-peer secure file transfer, encrypted chat, and Model Context Protocol (MCP) server for AI coding agents (Claude, Cursor, Windsurf, Continue, Zed) and developers. End-to-end AES-256-GCM encrypted.
Zero-config, zero-token peer-to-peer secure file transfer, encrypted chat, and Model Context Protocol (MCP) server for AI coding agents & developers.
Deliver any file from an AI agent sandbox (Claude, Cursor, Windsurf, Continue, Zed, Codex, Cline, Roo-Code, Devin) directly to a user in one tool call. End-to-end encrypted with AES-256-GCM. No cloud storage, no account signups, no API keys.
🌐 Web Platform: https://srift.app
📦 GitHub Repository: https://github.com/srivardhan113/SRIFT-Open_Source
🤖 AI Agent Hub: https://srift.app/ai-agents
AI coding agents run in sandboxed environments. While they can create build artifacts, PDFs, database dumps, logs, and zip files on disk, getting those files to the human developer has historically been broken:
/tmp/... or ~/.cache/...).SRIFT gives your agent a local headless daemon and toolset to seed files locally and generate a direct, encrypted download link:
srift quick-share ./dist/release-bundle.zip
# ↳ https://srift.app/d/7k3m9xq
The user opens the link in any web browser or runs curl -OJ https://srift.app/d/7k3m9xq or wget --content-disposition https://srift.app/d/7k3m9xq. The recipient needs nothing installed.
Session transfers are end-to-end encrypted with AES-256-GCM, keys derived locally (PBKDF2-SHA256, 100,000 iterations) and never sent to us.
⚠️ The sender's daemon must be alive for the link to work. SRIFT keeps no server-side copy — the daemon streams the file from your disk on demand. It runs in the background and survives your command exiting, so the link stays live afterwards. But if the daemon stops (machine sleeps or reboots, or
srift daemon stop) the link returns503 sender is offline. This is the direct trade-off for zero retention: nothing is stored, so nothing can be served once the source goes away. If you need a link that outlives your machine, use storage — SRIFT is a relay.
Public quick-share links are a deliberate exception, and it's worth being precise: the link is designed to be opened by any browser, curl or wget — clients that hold no key and run no SRIFT code. End-to-end encryption is therefore impossible on that path by definition. What SRIFT guarantees for quick-share is zero retention: bytes stream from the sender straight to the open HTTP response, are never written to SRIFT storage, and are served Cache-Control: no-store. If you need the relay to be unable to read the content, use a session transfer instead of a public link.
npm install -g srift-transfer
curl -fsSL https://srift.app/install.sh | sh
irm https://srift.app/install.ps1 | iex
powershell -NoProfile -ExecutionPolicy Bypass -Command "irm https://srift.app/install.ps1 | iex"
npx srift-transfer quick-share ./build/output.zip
SRIFT ships a native Model Context Protocol server exposing 14 agent tools, resources, and prompt templates over the local stdio/HTTP transports. The hosted endpoint exposes 8 of them (see below).
Run the auto-installer to print or register config into supported IDEs:
srift install-mcp # prints copy-paste config for all major clients
srift install-mcp --auto # writes directly into Claude Desktop config
Add to your %APPDATA%\Claude\claude_desktop_config.json (Windows) or ~/Library/Application Support/Claude/claude_desktop_config.json (macOS):
{
"mcpServers": {
"srift": {
"command": "srift",
"args": ["mcp"]
}
}
}
Add to ~/.cursor/mcp.json or workspace configuration:
{
"mcpServers": {
"srift": {
"command": "srift",
"args": ["mcp"]
}
}
}
Add to ~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"srift": {
"command": "srift",
"args": ["mcp"]
}
}
}
Add to ~/.continue/config.yaml:
mcpServers:
- name: srift
command: srift
args: ["mcp"]
Add to ~/.config/zed/settings.json:
{
"context_servers": {
"srift": {
"command": { "path": "srift", "args": ["mcp"] }
}
}
}
For web-based agents (ChatGPT, Claude.ai, Gemini, Perplexity) that cannot run local binaries.
The hosted endpoint exposes 8 of the 14 tools — session and peer orchestration only (
start_session,join_session,session_status,close_session,approve_join,reject_join,kick_user,list_transfers).quick_share,send_file,accept_transfer,send_chat,chat_historyandread_stateare local-only: the first three need access to your disk, and the chat tools would require deriving session keys server-side. Install the CLI if you need those.
{
"mcpServers": {
"srift": {
"type": "streamable-http",
"url": "https://srift.app/mcp"
}
}
}
| Tool | Parameters | Description |
|---|---|---|
srift_quick_share | filePath (string), maxDownloads? (number), ttlMs? (number) | Primary tool. Seeds file and returns public https://srift.app/d/<token> download URL. |
srift_start_session | sessionName? (string), roomSecret? (string) | Starts a new peer session with host role; returns room code & URL. |
srift_join_session | sessionId (string), username? (string), roomSecret? (string) | Requests to join an existing session as a peer. |
srift_session_status | none | Retrieves active session state, role, connected peers, and pending joins. |
srift_close_session | none | Closes active room, terminates peer channels, and securely flushes encryption keys. |
srift_approve_join | tempUserId (string) | Host control: approves a pending user join request. |
srift_reject_join | tempUserId (string), reason? (string) | Host control: rejects a pending user join request. |
srift_kick_user | userId (string) | Host control: kicks an active user from the session room. |
srift_send_file | filePath (string), protocol? ("webtorrent" | "websocket") | Offers a file for direct peer-to-peer transfer to joined peers. |
srift_accept_transfer | fileId (string), saveDir? (string) | Accepts an inbound file offer and streams it to local disk. |
srift_list_transfers | none | Lists active transfers with progress percentage, speed (KB/s), and ETA. |
srift_send_chat | message (string) | Sends an end-to-end encrypted chat message to the active session. |
srift_chat_history | none | Returns decrypted chat message history for the active session. |
srift_read_state | none | Returns atomic snapshot of .srift-state.json (transfers, session, peers). |
srift://session/status, srift://transfers/active, srift://chat/messages, srift://workspace/state, srift://docs/quickstartsend_file_to_user, receive_file_from_user, start_collab_sessionAll CLI commands support --json for machine-readable JSON output suitable for subagents and CI/CD pipelines.
# Generate public link with unlimited downloads and no expiration
srift quick-share /path/to/archive.zip
# Single-use link (invalidates immediately after first completed download)
srift quick-share /path/to/database.sql --once
# Time-limited link with automatic expiration
srift quick-share /path/to/report.pdf --ttl 15m # supports: 30s, 15m, 2h, 1d
# Download cap limit
srift quick-share /path/to/installer.exe --max-downloads 5
# Manage active links
srift pubshare list # list all active public links and counters
srift pubshare revoke <token> # immediately revoke an active link
srift session start [--name "Project Review"] # create session as host
srift session join <session-id> # join existing room
srift session status # view peers and role
srift session close # teardown room & clear keys
srift send <file-path> # offer file to peers in room
srift receive <file-id> [--save-dir ./downloads] # accept incoming file transfer
srift list # list active transfers
srift monitor <file-id> [--json-stream] # live transfer progress stream
srift approve <user-id> # host: approve join request
srift reject <user-id> [--reason <msg>] # host: reject join request
srift kick <user-id> # host: kick participant
srift chat send "Analysis complete." # send encrypted message
srift chat history # view decrypted room history
srift daemon start # run daemon in foreground
srift daemon status # daemon status and port
srift daemon restart # restart daemon process
srift doctor # diagnostic health check
srift logs [--tail 100] # inspect daemon activity logs
srift reset # flush session state & keys
srift self-update # update to latest version
The SRIFT daemon auto-starts on port 3822 (default) on the local loopback interface (127.0.0.1). Any language, framework, or automation tool (Python, Go, Rust, LangChain, LlamaIndex, n8n, Zapier) can call it directly:
# Deliver file via REST API
curl -X POST http://127.0.0.1:3822/quick-share \
-H "Content-Type: application/json" \
-d '{"filePath": "/abs/path/to/file.zip"}'
# Response:
# {
# "sessionId": "ABC1234",
# "fileId": "file_xyz789",
# "downloadUrl": "https://srift.app/d/7k3m9xq",
# "fileName": "file.zip",
# "fileSize": 10485760
# }
Subscribe to real-time events without polling:
curl -N http://127.0.0.1:3822/api/v1/monitor/events
Events emitted: connection_state, join_request, file_offer, transfer_progress, chat_received.
127.0.0.1 only. Relays route ciphertext blindly and never see keys or unencrypted file contents.Set custom configuration options via environment variables or ~/.srift/config.json:
| Environment Variable | Default | Description |
|---|---|---|
SRIFT_DAEMON_PORT | 3822 | Port for the local background daemon |
SRIFT_BASE_URL | http://127.0.0.1:3822 | Base URL used by SDK clients to reach daemon |
SRIFT_NO_UPDATE_CHECK | 0 | Set to 1 to disable automatic update checks |
First-party, zero-dependency SDKs for accessing SRIFT from any programming language:
sdk/node (npm install srift)sdk/python (CPython 3.8+, PyPy, asyncio)sdk/go (Go 1.21+)sdk/rust (sync/async)sdk/java (Java 11+)sdk/dotnet (.NET 6+)sdk/shellllms.txt): https://srift.app/llms.txt| Surface | Link |
|---|---|
| npm | srift-transfer |
| MCP Registry | app.srift/srift |
| Smithery | srift/srift |
| Glama (connector) | app.srift/srift |
| Glama (server) | SRIFT-Open_Source |
| GitHub | SRIFT-Open_Source |
All resolve to the same product. Install srift-transfer; the command is srift.
MIT License © SRIFT
FAQs
Send any file as a download link from the CLI or an AI agent (MCP server). Encrypted P2P file transfer and chat, AgentNet for agent-to-agent. No account.
The npm package srift-transfer receives a total of 300 weekly downloads. As such, srift-transfer popularity was classified as not popular.
We found that srift-transfer demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.