# serve (npm · @servelink/serve)

Public links for local services and static artifacts: live from your machine or hosted by Serve.

- Trust score: 77/100 (medium)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-21

## Components

- npm · `@servelink/serve`: 77/100 (this document), [markdown](https://verifymcp.io/servers/cc-servelink-serve/servelink-serve.md), [page](https://verifymcp.io/servers/cc-servelink-serve/servelink-serve)

## Channel facts

- Registry: `npm`
- Package: `@servelink/serve`
- Version: `0.8.8`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-21.

- **Supply Chain Security**: 100/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - No install/post-install scripts declared.
  - 0 of 5 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 35/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - License check failed: the license (SEE LICENSE IN LICENSE) isn't a recognized OSI-approved license.
  - Actively maintained (last published 13 days ago).
  - Publishes a security disclosure policy (SECURITY.md).
- **Schema Quality & AI Usability**: 78/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 2436 tokens (~143/item across 17 items; 17 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 57/100
  - Stability observed for 17 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (18% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 18 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the serve MCP server?

serve runs locally as an npm package, launched with npx -y @servelink/serve. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add cc-servelink-serve -- npx -y @servelink/serve
```

### Cursor

```json
{
  "mcpServers": {
    "cc-servelink-serve": {
      "command": "npx",
      "args": [
        "-y",
        "@servelink/serve"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "cc-servelink-serve": {
      "command": "npx",
      "args": [
        "-y",
        "@servelink/serve"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add cc-servelink-serve -- npx -y @servelink/serve
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "cc-servelink-serve": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@servelink/serve"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add cc-servelink-serve --command npx --arg -y --arg @servelink/serve
```

### Hermes

```yaml
mcp_servers:
  cc-servelink-serve:
    command: "npx"
    args: ["-y", "@servelink/serve"]
```

### Netclaw

```json
{
  "McpServers": {
    "cc-servelink-serve": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@servelink/serve"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add cc-servelink-serve -t stdio -c npx -a -y @servelink/serve
```

### Other

```json
{
  "mcpServers": {
    "cc-servelink-serve": {
      "command": "npx",
      "args": [
        "-y",
        "@servelink/serve"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-21 (score 77, +1)

No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-18 (score 76, +1)

No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-16 (score 75, +1)

No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-14 (score 74, +1)

No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-12 (score 73, +1)

No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-10 (score 72, +1)

No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-08 (score 71, +1)

No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-07 (score 70, +15)

- [security regression] Stability: 0.07 → unverified
- [security regression] Tool safety: pass → unverified
- [security improvement] Malware scan: unverified → pass
- [functional regression] Schema quality: 112 → 143
- [functional regression] Capabilities: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Tool coverage: 18
- [functional] First check of Schema quality: unverified
- [functional] Package version: 0.8.6 → 0.8.8

## MCP tools (17)

### `account_status` (~70 tokens)

Account status

Account-level state: plan, entitlement, and how much of the storage, transfer and publish allowance is used. Use this to check what the account may do or whether it is near a limit. For the links themselves (labels, URLs, protection state), use links instead. Owned links are unlimited by count.

### `create_viewer_grant` (~86 tokens)

Create viewer grant

Create a single-use owner-browser bypass grant (Pro plan required) and return a bypass URL for the link. Use it to open a protected link in the browser without sharing the link's viewer credential; it is not a general viewer-sharing credential. The grant is valid for two minutes after creation and can be used once.

Input parameters:

- `label` (string, required): Label of the link.

### `doctor` (~112 tokens)

Diagnostics

Run self-diagnostics when a link is unreachable or a call fails: config and identity fingerprint presence, account API health, relay health, and outbound UDP 443 (QUIC) reachability, each reported as a check result. The probes are best-effort and need no login; a UDP probe that sends but gets no reply is inconclusive, not proof of failure. For plan and quota, use account_status; for the account's link inventory, use links; for a single tunnel's state, use tunnel_status.

### `links` (~107 tokens)

List links

Inventory of every owned link (label) for the account, one record each: kind, URL, live/stale markers, protection status, last bound/viewer activity, and quarantine window. Use this to see what is currently served or published, or to find a label to act on. Live-tunnel capacity (live/max) and storage, transfer and publish-rate usage come along as context. For plan, entitlement and quota headroom, use account_status instead. Owned links are unlimited by count.

Output parameters:

- `count` (integer)
- `links` (null|array)
- `live_tunnels` (integer)
- `max_tunnels` (integer)
- `ok` (boolean)
- `publish` (object)
- `storage` (object)
- `transfer` (object)

### `list_tunnels` (~48 tokens)

List tunnels

List all active tunnels in this manager with their ports, labels, public URLs, uptime, state, and last error. To inspect a single tunnel, use tunnel_status with its port or label.

### `protect_link` (~163 tokens)

Protect link

Enable capability token and readable secret protection on an owned link (Pro plan required). Returns the share URL (with #cap=...) and the human-readable secret code. If label is omitted, the first owned link returned by links is protected. If ttl is omitted, protection lasts 24 hours. Calling this on an already-protected link replaces the existing credentials, so previous share URLs stop working. To rotate credentials instead, use renew_link; to change only the duration, use update_ttl.

Input parameters:

- `label` (string): Label of the link to protect (optional; defaults to the first owned link returned by links).
- `ttl` (string): Optional protection duration (e.g. 24h, 3d, 7d); defaults to 24 hours.

### `release_link` (~61 tokens)

Release link

Release (free) an owned link by label. Fails with remote_link while the label still has a published artifact; unpublish it with stop_remote first. Returns confirmation and the account's usage.

Input parameters:

- `label` (string, required): Label of the link to release.

### `renew_link` (~112 tokens)

Renew link protection

Rotate the capability token and secret code for a link (Pro plan required): fresh credentials are minted and the countdown restarts, and the previous credentials stop working immediately. If ttl is omitted, protection defaults to 24 hours. For a duration-only change without rotating credentials, use update_ttl instead.

Input parameters:

- `label` (string, required): Label of the link to renew.
- `ttl` (string): Optional updated duration (e.g. 24h, 3d, 7d); defaults to 24 hours.

### `revoke_link` (~85 tokens)

Revoke link credentials

Immediately revoke the active secret code and capability token for a link while keeping owner access intact. The link stays protected, so the old share URL and secret stop working; no new credentials are minted. To open the link to everyone instead, use unprotect_link; to mint fresh credentials, use renew_link.

Input parameters:

- `label` (string, required): Label of the link whose credentials should be revoked.

### `serve` (~342 tokens)

Serve file / dir / port -> public link

Publish a local resource to a public HTTPS URL. Pass path to serve a file or directory (auto-hosted, no separate server needed), or port to expose an already-running dev server. Set residency to "remote" to publish the path to serve's storage so the URL works with the machine off. Do NOT start your own static file server; pass exactly one of path or port. Returns the public url, label, and residency, with label_kind and status for live links (or version, size_bytes, and kind for remote publishes); served_path and protection fields appear when set; usage comes along as context.

Input parameters:

- `name` (string): Optional requested subdomain; an existing local link is reused if omitted.
- `path` (string): Local file or directory to serve via an auto-hosted static server (mutually exclusive with port).
- `port` (number): Local port of an already-running server to expose (mutually exclusive with path).
- `protect` (boolean): Optional boolean; if true, enables capability token and secret code protection on the link.
- `replace` (boolean): When residency is remote and a published artifact occupies the requested name, true replaces the existing published artifact at that name (Pro); false returns a residency_conflict you must resolve wi…
- `residency` (string): Residency of the served link. "local" (default) serves from the agent's machine (a tunnel); "remote" publishes the path to serve's storage so the URL stays live with the machine off.
- `ttl` (string): Optional duration for the link protection (e.g. 24h, 3d, 7d).

Output parameters:

- `expires_at` (string)
- `kind` (string)
- `label` (string)
- `label_kind` (string)
- `ok` (boolean)
- `port` (integer)
- `protected` (boolean)
- `readable_secret` (string)
- `recycled_from` (string)
- `replaced_tunnel` (boolean)
- `residency` (string)
- `served_path` (string)
- `share_url` (string)
- `size_bytes` (integer)
- `status` (string)
- `suffixed_from` (string)
- `url` (string)
- `usage` (object)
- `version` (string)

### `serve_file` (~289 tokens)

Serve file / directory -> public link

Serve a local file or directory and get a public shareable URL. Pass the file or directory path to path to have it auto-hosted and tunneled. Use this when the user asks to share/serve a file, markdown document, image, or artifact. Set residency to "remote" to publish to serve's storage so the URL works with the machine off. Do not start your own static server. To expose an already-running dev server by port instead, use the serve tool.

Input parameters:

- `name` (string): Optional requested subdomain; an existing local link is reused if omitted.
- `path` (string, required): Local file or directory to serve via an auto-hosted static server.
- `protect` (boolean): Optional boolean; if true, enables capability token and secret code protection on the link.
- `replace` (boolean): When residency is remote and a published artifact occupies the requested name, true replaces the existing published artifact at that name (Pro); false returns a residency_conflict you must resolve wi…
- `residency` (string): Residency of the served link. "local" (default) serves from the agent's machine (a tunnel); "remote" publishes the path to serve's storage so the URL stays live with the machine off.
- `ttl` (string): Optional duration for the link protection (e.g. 24h, 3d, 7d).

Output parameters:

- `expires_at` (string)
- `kind` (string)
- `label` (string)
- `label_kind` (string)
- `ok` (boolean)
- `port` (integer)
- `protected` (boolean)
- `readable_secret` (string)
- `recycled_from` (string)
- `replaced_tunnel` (boolean)
- `residency` (string)
- `served_path` (string)
- `share_url` (string)
- `size_bytes` (integer)
- `status` (string)
- `suffixed_from` (string)
- `url` (string)
- `usage` (object)
- `version` (string)

### `stop_all_tunnels` (~33 tokens)

Stop all tunnels

Stop every active tunnel, revoking all public URLs. To stop a single tunnel, use stop_tunnel instead.

### `stop_remote` (~75 tokens)

Stop remote (unpublish)

Unpublish a remote link, deleting its stored artifact bytes immediately and returning the link to local residency. Use links to see published (remote) links. To stop a live tunnel, use stop_tunnel instead; this tool only removes published bytes.

Input parameters:

- `label` (string, required): Label of the published (remote) link to unpublish.

### `stop_tunnel` (~97 tokens)

Stop tunnel

Stop (tear down) the tunnel for a local port or link label, revoking its public URL. Idempotent. To change a live tunnel's port or label, stop it here and then call serve again with the new settings; there is no in-place reconfiguration.

Input parameters:

- `label` (string): Link label of the tunnel to stop (alternative to port).
- `port` (number): Local port of the tunnel to stop.

### `tunnel_status` (~83 tokens)

Tunnel status

Return the status of a single tunnel identified by its local port or its link label, including public URL, uptime, state, and last error. To see every active tunnel at once, use list_tunnels instead.

Input parameters:

- `label` (string): Link label of the tunnel to inspect (alternative to port).
- `port` (number): Local port of the tunnel to inspect.

### `unprotect_link` (~94 tokens)

Unprotect link

Clear protection on an owned link, returning it to public access. Use this to open up a protected link so anyone with the URL can view it. To keep the link protected but invalidate its current credentials, use revoke_link; to free the label entirely (and fail while a remote artifact is still published), use release_link. Requires ownership of the link.

Input parameters:

- `label` (string, required): Label of the link to unprotect.

### `update_ttl` (~103 tokens)

Update link TTL

Change the protection duration (TTL) of an already-protected link (Pro plan required) without rotating its credentials. The link must currently be protected with an unexpired credential; expired protection must be renewed first with renew_link. The expiration is recalculated from the new duration, not extended from the previous expiry.

Input parameters:

- `label` (string, required): Label of the link.
- `ttl` (string, required): New TTL duration (e.g. 48h, 7d).

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/cc-servelink-serve/servelink-serve#diagnostics

## Score history

- 2026-09-21: 77
- 2026-09-20: 76
- 2026-09-19: 76
- 2026-09-18: 76
- 2026-09-17: 75
- 2026-09-16: 75
- 2026-09-15: 74
- 2026-09-14: 74
- 2026-09-13: 73
- 2026-09-12: 73
- 2026-09-11: 72
- 2026-09-10: 72
- 2026-09-09: 71
- 2026-09-08: 71
- 2026-09-07: 70
- 2026-09-06: 55
- 2026-09-05: 69
- 2026-09-04: 69

## Common questions

### What is the serve MCP server?

serve is an MCP server listed in the public MCP registry as cc.servelink/serve. Public links for local services and static artifacts: live from your machine or hosted by Serve. This page covers its npm package (@servelink/serve).

### Is the serve MCP server safe to use?

serve scores 77 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 21 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the serve MCP server expose?

serve exposes 17 tools: account_status, create_viewer_grant, doctor, links, list_tunnels, and 12 more. Their descriptions and schemas cost roughly 1,960 tokens of context every time the server is loaded.

### Is the serve MCP server still maintained?

serve is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- npm package: https://www.npmjs.com/package/@servelink/serve
- Socket report: https://socket.dev/npm/package/@servelink/serve
- Repository: https://github.com/servelink-swyftlabs/serve-mcp
- Website: https://servelink.cc/
- Changelog RSS feed: https://verifymcp.io/servers/cc-servelink-serve/servelink-serve.xml
- Changelog JSON feed: https://verifymcp.io/servers/cc-servelink-serve/servelink-serve.json
- HTML version of this page: https://verifymcp.io/servers/cc-servelink-serve/servelink-serve
