MCPLow riskUnclaimed

qURL

Mint, resolve, audit, and rotate scope-limited expiring access links (qURLs) for AI agents.

layervailayervai/qurl-mcp★ 4Updated Sep 19, 2026

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "io.github.layervai/qurl-mcp",
  "description": "Mint, resolve, audit, and rotate scope-limited expiring access links (qURLs) for AI agents.",
  "title": "qURL",
  "repository": {
    "url": "https://github.com/layervai/qurl-mcp",
    "source": "github"
  },
  "version": "0.5.0",
  "websiteUrl": "https://layerv.ai",
  "packages": [
    {
      "registryType": "npm",
      "identifier": "@layervai/qurl-mcp",
      "version": "0.5.0",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "API key for the qURL API with qurl:read, qurl:write, and/or qurl:resolve scopes. Obtain from https://layerv.ai.",
          "isRequired": true,
          "format": "string",
          "isSecret": true,
          "name": "QURL_API_KEY"
        },
        {
          "description": "qURL API base URL. Defaults to https://api.layerv.ai. Override only for testing against a non-production qURL backend.",
          "format": "string",
          "default": "https://api.layerv.ai",
          "name": "QURL_API_URL"
        },
        {
          "description": "Connector base URL used by local-file, file-data, and text-to-PDF upload tools before minting a qURL.",
          "format": "string",
          "name": "QURL_CONNECTOR_URL"
        },
        {
          "description": "Optional path to a shared qURL MCP config file. Both stdio and HTTP modes can read SMTP, connector, and default API settings from this file.",
          "format": "string",
          "name": "QURL_MCP_CONFIG"
        },
        {
          "description": "Maximum decoded/local upload size. Accepts bytes or units such as 10mb; capped at 100mb.",
          "format": "string",
          "default": "10mb",
          "name": "MCP_MAX_UPLOAD_FILE_DATA_BYTES"
        },
        {
          "description": "SMTP hostname for optional qURL link delivery.",
          "format": "string",
          "name": "QURL_SMTP_HOST"
        },
        {
          "description": "SMTP port for optional qURL link delivery.",
          "format": "string",
          "name": "QURL_SMTP_PORT"
        },
        {
          "description": "Whether SMTP uses an implicit TLS connection (true/false).",
          "format": "string",
          "name": "QURL_SMTP_SECURE"
        },
        {
          "description": "SMTP authentication username.",
          "format": "string",
          "isSecret": true,
          "name": "QURL_SMTP_USERNAME"
        },
        {
          "description": "SMTP authentication password or app-specific credential.",
          "format": "string",
          "isSecret": true,
          "name": "QURL_SMTP_PASSWORD"
        },
        {
          "description": "Validated sender email address for qURL delivery.",
          "format": "string",
          "name": "QURL_SMTP_FROM_EMAIL"
        },
        {
          "description": "Optional sender display name for qURL delivery.",
          "format": "string",
          "name": "QURL_SMTP_FROM_NAME"
        },
        {
          "description": "Optional comma-separated exact recipient allowlist.",
          "format": "string",
          "name": "QURL_SMTP_ALLOWED_RECIPIENTS"
        },
        {
          "description": "Optional comma-separated recipient-domain allowlist.",
          "format": "string",
          "name": "QURL_SMTP_ALLOWED_RECIPIENT_DOMAINS"
        },
        {
          "description": "Maximum recipients in one delivery request (default 10).",
          "format": "string",
          "default": "10",
          "name": "QURL_SMTP_MAX_RECIPIENTS_PER_MESSAGE"
        },
        {
          "description": "Maximum attempted recipients per qURL key per fixed hourly window (default 100).",
          "format": "string",
          "default": "100",
          "name": "QURL_SMTP_MAX_RECIPIENTS_PER_HOUR"
        }
      ]
    }
  ]
}

Permissions

DeclaredDetected
Runs code—node
Installs—npm:@layervai/qurl-mcp@0.5.0
Runs install scripts—None
NetworkNoneNone
Needs credentialsQURL_API_KEYQURL_SMTP_PASSWORDQURL_SMTP_USERNAMEQURL_API_KEYQURL_SMTP_PASSWORDQURL_SMTP_USERNAME
Outside the workspace—None
Agent tools—None

Checks

Low risk · Nothing worth a warning was found.

Not reviewed by a person · Checked by rules; the model review is not switched on yet.

Versions

  1. #10.5.0latestOct 7, 2026