qURL runs on your own machine — the client starts it, so there is no endpoint to ping. 238 installs a week from npm. Last commit 21 Sep 2026.
Mint, resolve, audit, and rotate scope-limited expiring access links (qURLs) for AI agents.
Today is the operative word: we check qURL every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add qurl-mcp -- npx -y @layervai/qurl-mcp
{
"mcpServers": {
"qurl-mcp": {
"args": [
"-y",
"@layervai/qurl-mcp"
],
"command": "npx"
}
}
}
[mcp_servers.qurl-mcp]
command = "npx"
args = ["-y", "@layervai/qurl-mcp"]
{
"mcpServers": {
"qurl-mcp": {
"args": [
"-y",
"@layervai/qurl-mcp"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"qurl-mcp": {
"args": [
"-y",
"@layervai/qurl-mcp"
],
"command": "npx"
}
}
}
This one needs environment variables set before it will start:
QURL_API_KEY (API key for the qURL API with qurl:read, qurl:write, and/or qurl:resolve scopes. Obtain from https://layerv.ai.), QURL_API_URL (qURL API base URL. Defaults to https://api.layerv.ai. Override only for testing against a non-production qURL backend.), QURL_CONNECTOR_URL (Connector base URL used by local-file, file-data, and text-to-PDF upload tools before minting a qURL.), QURL_MCP_CONFIG (Optional path to a shared qURL MCP config file. Both stdio and HTTP modes can read SMTP, connector, and default API settings from this file.), MCP_MAX_UPLOAD_FILE_DATA_BYTES (Maximum decoded/local upload size. Accepts bytes or units such as 10mb; capped at 100mb.), QURL_SMTP_HOST (SMTP hostname for optional qURL link delivery.), QURL_SMTP_PORT (SMTP port for optional qURL link delivery.), QURL_SMTP_SECURE (Whether SMTP uses an implicit TLS connection (true/false).), QURL_SMTP_USERNAME (SMTP authentication username.), QURL_SMTP_PASSWORD (SMTP authentication password or app-specific credential.), QURL_SMTP_FROM_EMAIL (Validated sender email address for qURL delivery.), QURL_SMTP_FROM_NAME (Optional sender display name for qURL delivery.), QURL_SMTP_ALLOWED_RECIPIENTS (Optional comma-separated exact recipient allowlist.), QURL_SMTP_ALLOWED_RECIPIENT_DOMAINS (Optional comma-separated recipient-domain allowlist.), QURL_SMTP_MAX_RECIPIENTS_PER_MESSAGE (Maximum recipients in one delivery request (default 10).), QURL_SMTP_MAX_RECIPIENTS_PER_HOUR (Maximum attempted recipients per qURL key per fixed hourly window (default 100).).
The author declared them in the registry entry; get the values from the project itself.
AEO scoring, llms.txt audit, and agent-readiness checks for AI agents.
OAuth 2.1 short-link tools for AI agents with scoped tokens, approvals, audit logs, and revocation.
X.509 identity, risk scoring, and audit logging for AI agents. MiCA + EU AI Act compliant.
X.509 identity, risk scoring, and audit logging for AI agents. MiCA + EU AI Act compliant.
Permission gateway for AI agents: scoped MCP endpoints over 27 services, audited and revocable.
Credential broker for AI agents: scoped, revocable API access with policy enforcement and audit.
Safe, read-only Postgres and MySQL access for AI agents. Audit log + column-level controls.
Find, compare, and audit software for AI agents. Scored registry of tools and MCP servers.
Answers built from our own checks of this server.