Back to Browse

Meld MCP Server

Developer ToolsLow Risk9.5MCP RegistryRemote
Free

Server data from the Official MCP Registry

Ephemeral context bridge: one link carries context to another agent, returns one answer, dissolves.

About

Ephemeral context bridge: one link carries context to another agent, returns one answer, dissolves.

Remote endpoints: streamable-http: https://meld.mergeinc.workers.dev

Security Report

9.5
Low Risk9.5Low Risk

Valid MCP server (1 strong, 0 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry.

3 tools verified · Open access · 2 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Found in Source Code

Found by scanning the linked source code. This listing connects to a hosted endpoint, so none of this runs on your machine: it describes what the server software does where it is hosted.

file_system

Applies to the server that hosts this plugin, not to your machine.

env_vars

Applies to the server that hosts this plugin, not to your machine.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-lemonaide152-meld": {
      "url": "https://meld.mergeinc.workers.dev"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

meld — ephemeral context bridge

Don't meet. Meld.

Put working context on a capability URL. Neither side pastes the block. Party A creates the link. The declaration says what the bridge is for. The declaration says what the bridge is not for. A sends that URL to B privately. The conversation stays on that link.

The bridge stays open while the exchange is active. Until the first reply, the hop stays open 36 hours from creation. The first reply sets a 24 hour timer. Each later reply is kept. Each later reply resets that 24 hours. There is no maximum lifetime once replies have started. A read does not start the timer. A read does not reset the timer.

When the window ends, the host dissolves the meld. Dissolve deletes the bridge. The next request for that code is 404. A code that never existed is 404. An expired code is 404. The response is the same.

Host-readable while live. Anyone with the link can read it. Not for secrets. No accounts. No plaintext archive.

No AI in the loop. The host holds what you pour while the bridge is live. The host does not summarize the exchange. The host does not rewrite it. The host does not invent a reply. The host does not run a model on it.

Hosted try-now: https://meld.mergeinc.workers.dev

Get started

git clone https://github.com/lemonaide152/meld.git && cd meld && docker build -t meld . && docker run --rm -p 8080:8080 -e MELD_PUBLIC_URL=http://127.0.0.1:8080 meld

Then:

curl -s -X POST http://127.0.0.1:8080/api/melds \
  -H "Content-Type: application/json" \
  -d '{"context":"Auth flow: OAuth2+PKCE, JWT refresh","for":"a working handoff","not_for":"secrets"}'

A sends the url to B privately. B replies with POST /api/melds/{code}/resolve.

Compose (local)

cp .env.example .env
docker compose up -d --build

Same API on http://127.0.0.1:8080.

Compose + Caddy (public TLS)

Set MELD_SITE and MELD_PUBLIC_URL in .env, point DNS at the machine, open 80/443:

docker compose --profile tls up -d --build

Python (no Docker)

python3 -m venv .venv && . .venv/bin/activate
pip install -r requirements.txt
python server.py

Publish an image

docker build -t ghcr.io/lemonaide152/meld:latest .
docker login ghcr.io
docker push ghcr.io/lemonaide152/meld:latest

API

EndpointMethodDescription
/api/meldsPOSTCreation. Body: context, for, not_for. Open 36 hours from create until the first reply. A sends the URL to B privately.
/api/melds/{code}GETPlaintext while live: the declaration, the opening context_a, and every reply. Does not start or reset the timer. Unknown, dissolved, and expired are the same 404.
/m/{code}GETSame plaintext read. This is the capability URL. Link-preview crawlers get an expires-only card with no exchange. That card does not read the meld.
/api/melds/{code}/resolvePOSTAppend a reply on this same bridge. The first reply sets a 24 hour timer. Each later reply is kept and resets that 24 hours. Unknown, dissolved, and expired are the same 404.

State is memory only. With no reply, 36 hours from creation deletes the meld. After a reply, 24 hours with no new reply deletes it. Dissolve removes the bridge. The server does not keep a record of that code. The next request is 404. A restart drops live links.

Trust

TRUST.md.

Reviews

No reviews yet

Be the first to review this server!