Review what your agents plan. Agents drop docs and small apps; you comment on the exact spot and share the ones worth sharing. Built with ViteHub.
Website · ViteHub · ViteHub docs · Source
- Agents drop their work over MCP: a plan in Markdown, an HTML report, or a small static app made of files. They sign in through your browser once; there are no keys.
- Every drop starts private. Only its owner (and the workspace's editors and admins) can open it.
- People review it full screen: select text or click a spot in an image to comment. The owner shares a link that can view, comment, or edit.
- The agent reads the open comments and drops the next version. Older versions stay in history.
Under the hood:
- Auth is Better Auth through
vite-hub/auth: GitHub sign-in, admin roles, and an OAuth 2.1 provider that MCP clients sign in through (dynamic client registration, PKCE, JWT access tokens bound to/mcp). - Database is D1 through
vite-hub/database: drops, app files, and comments. - Blob stores every file at
/f/<key>. Old/i/<key>links redirect there. - Markdown renders through Comark, and HTML runs in a sandbox with an opaque origin.
- Code images come from Shiki as SVG; a single Browser screenshot action turns them into PNG, and an hourly Schedule deletes them.
- MCP is nitro-mcp-toolkit: one file per tool and prompt in
server/mcp/, both protocol revisions, and the Skills extension. - Skills are defined once in
skills/and served over MCP (skills/list,skill://resources), at/.well-known/agent-skills/(Discovery v0.2.0), and at the older/.well-known/skills/. - Logs are evlog wide events: one structured line per request with the caller, the agent, what it did, and why it failed. Workers Logs is on, so they're queryable in the Cloudflare dashboard.
-
Sign in at drop.vitehub.dev with GitHub.
-
Add Drop's MCP server to your agent:
claude mcp add --transport http --scope user drop https://drop.vitehub.dev/mcp
The first time it connects, the client opens Drop in your browser. Allow it, and the agent acts as you. The
/agentspage has the setup for Codex, Cursor, VS Code, and other clients, and lists the agents you've connected. -
Ask your agent to drop a plan. It answers with the review link.
MCP tools: list_drops, read_drop, list_comments, create_doc, publish_app, create_code_image, plus the address_feedback prompt. The vitehub-drop skill comes with the server (skills/list); it's also published at /.well-known/agent-skills/ for agents that discover skills over HTTP. The /docs page has the details.
Drop is a Nuxt app on Cloudflare Workers. drop.vitehub.dev is one instance anyone can use; you can run your own. Anyone with a GitHub account can sign in and joins as a Member. The GitHub users in DROP_ADMINS join as Admin, and admins change roles on /members:
| Role | What they can do |
|---|---|
| Admin | Everything, plus members. |
| Editor | Edit and share any drop. |
| Member | Their own drops. This is the default. |
-
Create a GitHub OAuth app with the callback
https://<your-domain>/api/auth/callback/github. To use another sign-in provider, edit server/auth.ts. -
Create the Cloudflare resources.
pnpm install pnpm exec wrangler d1 create vitehub-drop # copy the id into CLOUDFLARE_D1_DATABASE_ID pnpm exec wrangler r2 bucket create vitehub-drop pnpm build
The KV namespace (Drop's render cache) has no ID to fill in: Wrangler creates it on the first deploy.
-
Fill
.envfrom .env.example, with your GitHub user id (gh api users/<login> --jq .id) inDROP_ADMINS. Then deploy. Deploy applies the D1 migrations, then publishes the Worker with.envas its secrets:pnpm run deploy
-
Run the smoke test. It checks the public pages, the OAuth discovery documents, and that
/mcpasks for sign-in:DROP_URL=https://<your-domain> pnpm test:e2e:deployed
pnpm install
pnpm dev # http://localhost:3000
pnpm db:migrate # once, and after schema changes (pnpm db:generate writes new migrations)Local dev has no GitHub app, so nuxt dev also allows email and password sign-in: open /?signin=1. Files go to .vitehub/data/blob, and rate limits are off.
The hand mark is Twemoji via Iconify, licensed under CC BY 4.0.