What an assistant can do
- Answer questions. “Did Anna download the final set?”, “Which deliveries expire this week?”, “What is in the Harbour collection?”, “How much storage do I have left?”
- Share files as a link, if you allow it: text or small files it has, files already online at a URL (any size, Yungle fetches them), or files from your disk when the server runs locally.
- Read a link someone sent you and turn it into download URLs.
- Email a transfer, only if you ticked that permission, and only after you confirm each send.
Connect with no key
Yungle hosts the server athttps://yungle.co/mcp. You add it to your assistant, sign in to Yungle in the browser window it opens, and choose what it may do. There is no key to create or paste.
- Claude
- ChatGPT
- Claude Code
- Cursor
- VS Code
- Other clients
Yungle is in Claude’s connector directory.The connector then works in Claude on the web, desktop and mobile.
1
Open the listing
Go to claude.ai/directory/yungle and click Connect.
2
Sign in and choose permissions
Sign in to Yungle, tick what Claude may do, and click Allow.
Permissions and the consent screen
When you connect, Yungle shows a consent screen. It names the app (as the app calls itself; Yungle has not verified that name) and the address you will be sent back to. Check both, and only continue if you started the connection. Below that is one checkbox per permission, in plain words:
Emailing is off by default because an assistant can be steered by the text it reads, and a filename is text somebody else wrote. Without it, the assistant can still share links, but only you send email. Ticking it also grants link sharing.
A permission you leave unticked removes those tools entirely: the assistant cannot even try them.
To disconnect an app, go to Settings → API keys and remove it under Connected apps. An assistant can never reach your vault, billing or members.
Run it locally
The same server also runs on your machine over stdio. The hosted server is simpler, but a local one can do two things the hosted one cannot: share files straight from your disk (share_local_files) and save a link’s files into a folder (download_files).
A local server needs an API key, not a browser sign-in: a browser session expires within the hour, and the key is stored in your assistant’s config file in plain text. Give the assistant its own key with as little as it needs: the :read scopes to answer questions, plus transfers:write if it should share links. See Authentication for creating a key.
1
Install the CLI and save a key
2
Preview the change
--client, it installs into every supported assistant it finds: Claude Desktop, Claude Code, Cursor, Windsurf. To pick one, add --client claude-desktop (or claude-code, cursor, windsurf).3
Install
--allow-write, and always refuses a key with any other :write scope, since no tool uses them. It never overwrites a config file it cannot parse, and copies the previous contents to <config>.yungle-bak before any change.4
Restart your assistant
The assistant picks up the new server on its next start.
transfers:write adds the sharing tools, and send_transfer appears only for a key that may email.
Tools
Tools marked with write need the link-sharing permission (ortransfers:write on a key). With email allowed needs the email permission. Local only tools exist only when the server runs on your machine.
What it cannot do
- Email anyone without you.
send_transferexists only when you allowed emailing. Every send then asks you in your client, with the addresses and the note in front of you. A client that cannot ask gets the link back instead, and Yungle sends nothing. - Share a local file without you.
share_local_filesasks you to confirm the list first, and refuses when the client cannot ask. It refuses hidden files, including ones reached through a symlink. - Delete, revoke or invite. No tool does any of these, so a misread instruction cannot take a link away from a client. It also cannot open an upload request: it can list them, not create them.
- Read file contents. It sees names, sizes, types and download receipts. When asked, it returns download links; an assistant that can fetch URLs can follow them, as you could.
- Open your vault or end-to-end encrypted transfers. Their keys are derived in your browser and never reach Yungle. The vault is never listed.
Example: an agent hand-off
You connected Claude with the default permissions plus link sharing, and left emailing unticked.1
Ask about a delivery
You: “Has De Vries downloaded the Q3 report yet?”The assistant calls
list_transfers to find the transfer, then get_transfer_downloads. One visit counts as one download even when eight files were saved, so it counts distinct sessions and answers: “No. It was sent on Monday and expires on Friday; nobody has opened it.”2
Share a file that is already online
You: “Share the render in our S3 bucket with them:
https://renders.s3.eu-central-1.amazonaws.com/q3-final.mp4?X-Amz-Signature=…”The assistant calls share_from_urls. Yungle fetches the file itself, so its size does not matter, and get_import_status reports when it has arrived. The assistant hands you the link. Nobody is emailed.3
Send it yourself
Emailing is not allowed, so the assistant has no
send_transfer tool. You paste the link into your own email to De Vries.create_transfer returns one npx -y yungle-cli@latest put … command per file. Each command needs no key, can upload only its own file, and resumes if the connection drops. finalize_transfer then makes the link.
The server is open source (MIT): yungle-mcp on GitHub.
Next steps
Authentication
API keys and scopes for a local server.
CLI
Send and receive files from a terminal.
Download files
What the download links an assistant returns can do.
What the API cannot do
The vault, end-to-end transfers, and other limits.
