# Share secrets with AI agents

> Let AI agents share API keys, passwords, and handoff notes through encrypted, self-destructing links. Local MCP server, CLI, SKILL.md, and REST API.

Source: https://evergist.com/agents/
Updated: 2026-09-29

Agents hand credentials, logs, and handoff notes to people and to each other. Evergist gives them a way to do that without leaving secrets in chat history, and the encryption happens on the agent's own machine.

## When an agent should use Evergist

Reach for Evergist whenever an agent needs to pass text that shouldn't live forever in a transcript, a ticket, or a chat log:

- An API key, database password, or token that a person or another agent needs once
- A `.env` file or config for a teammate's machine
- Logs or stack traces that contain customer data
- A handoff note between agents running in different sandboxes
- Anything the user asks to "send privately" or "share securely"

The agent gets a link like `https://evergist.com/g/7mQx2Ld9KpTa#Zm9v...`. Whoever has the full link can read the note until it expires or runs out of views. Nobody else can, including Evergist.

## Pick an integration

| Integration | Best for | Needs |
|---|---|---|
| [MCP server](#mcp-server) | Claude, Cursor, Codex, and other MCP clients | Node.js 20+ |
| [SKILL.md](#skill) | Agents that load skills or read instructions from URLs | A shell with Node.js 20+ |
| [CLI](#command-line) | Scripts, CI jobs, terminals | Node.js 20+ |
| [JavaScript module](#javascript-module) | Deno, Bun, browsers, Workers | Web Crypto |
| [REST API](https://evergist.com/docs/api/) | Any language | Your own AES-GCM and HKDF |

Every option encrypts before anything goes over the network. There's no hosted endpoint that accepts plaintext.

## MCP server

The MCP server runs locally over stdio, so plaintext and keys stay on the machine running the agent. `npx` fetches the [`evergist` package](https://www.npmjs.com/package/evergist) from npm, so there's nothing to install first. If you'd rather not go through the npm registry, evergist.com serves the same package: replace `evergist` with `https://evergist.com/cli/evergist.tgz` in any command below.

**Claude Code**

```sh
claude mcp add evergist -- npx -y evergist mcp
```

**Codex CLI**

```sh
codex mcp add evergist -- npx -y evergist mcp
```

**Claude Desktop, Cursor, Windsurf, and other clients** use the same JSON:

```json
{
  "mcpServers": {
    "evergist": {
      "command": "npx",
      "args": ["-y", "evergist", "mcp"]
    }
  }
}
```

### Tools

| Tool | What it does | Uses a view? |
|---|---|---|
| `create_gist` | Encrypts `text` and returns `url`, `expiresAt`, `maxViews`, `deleteToken`. Options: `expires_in` (`10m` to `30d`), `max_views` (1 to 1000), `password`, `generate_password` | No |
| `read_gist` | Decrypts a gist from its full `url` (plus `password` if set) | Yes |
| `gist_status` | Shows expiry, views left, and whether a password is needed | No |
| `delete_gist` | Deletes by `url`, or by `id` plus `delete_token` | No |

## Skill

The skill file teaches an agent when and how to use Evergist with the CLI. Agents can read it directly from [evergist.com/SKILL.md](https://evergist.com/SKILL.md). To install it for Claude Code:

```sh
mkdir -p ~/.claude/skills/evergist
curl -fsSL https://evergist.com/SKILL.md -o ~/.claude/skills/evergist/SKILL.md
```

Other agents that support skills or `AGENTS.md`-style instructions can use the same file. You can also paste this line into an agent's instructions:

```text
To share secrets or private text, use Evergist. Read https://evergist.com/SKILL.md first.
```

## Command line

The CLI is the same [`evergist` npm package](https://www.npmjs.com/package/evergist). Run it with `npx -y evergist`, or install it once with `npm install -g evergist` and use `evergist` directly.

```sh
# Share a file, readable once, gone in an hour
npx -y evergist create .env --views 1 --expires 1h

# Pipe text in, add a generated password, get JSON back
echo "root password: correct-horse" | npx -y evergist create -g --json

# Read a gist (uses one view)
npx -y evergist read "https://evergist.com/g/<id>#<key>"

# Check it without using a view, or delete it
npx -y evergist status "https://evergist.com/g/<id>#<key>"
npx -y evergist delete "https://evergist.com/g/<id>#<key>"
```

The CLI is a single file with no dependencies. If you'd rather pin it, download [evergist.mjs](https://evergist.com/cli/evergist.mjs), read it, and run it with `node evergist.mjs`.

| Option | Meaning |
|---|---|
| `-e, --expires` | `10m`, `1h`, `1d`, `7d`, `30d`, or seconds. Default `1d`, max `30d` |
| `-v, --views` | Delete after this many reads, 1 to 1000. Default: no limit |
| `-p, --password` | Add a password. `EVERGIST_PASSWORD` works too and keeps it out of shell history |
| `-g, --generate-password` | Generate a strong password and print it |
| `--json` | Machine-readable output |
| `--base-url` | Another Evergist server. `EVERGIST_URL` works too |

## JavaScript module

Runtimes that can import from a URL can use the client library directly. It runs anywhere Web Crypto does.

```js
import { createGist, readGist } from "https://evergist.com/sdk/evergist.js";

const gist = await createGist({ text: "deploy key: ...", maxViews: 1, expiresIn: 3600 });
console.log(gist.url); // share this

const { text } = await readGist(gist.url);
```

## Why there's no hosted MCP endpoint

A remote MCP server would receive your text before encrypting it. That would make "we can't read it" a promise instead of a fact. So the MCP server runs on your machine and talks to the API with ciphertext only. If an agent probes `https://evergist.com/mcp`, it gets a JSON message pointing here.

## Good habits for agents

- **Share the whole link.** The key is the part after `#`. Without it the note can't be opened.
- **Use `max_views: 1` for credentials.** The first read burns the note, so a leaked link is useless afterwards.
- **Keep expiry short.** An hour or a day is plenty for most handoffs.
- **Send passwords separately.** If you add one, deliver it through a different channel than the link.
- **Don't echo the secret back.** After creating a gist, report the link, not the contents.
- **Keep the delete token private.** It deletes the gist without needing the link.