ANVILNINE

DROPKILN / CHANGELOG

What shipped

Release notes and updates for Dropkiln. Version 1.0.0 originally shipped under the name Artifacts.

v1.0.0

Artifacts 1.0.0 #

First stable release. Publish HTML, JSX, Markdown, or a zip site and get an unguessable URL. Ships with a web UI, a CLI, and a built-in MCP server.

Artifacts 1.0.0 is the first stable release. Publish HTML pages, React components, Markdown, or zipped static sites to unguessable URLs on your own domain. Open source under the MIT license.

New

  • Four content types. HTML, JSX/TSX (one React component, no build step), Markdown, and zipped static sites.
  • Built-in MCP server. A streamable HTTP endpoint at /mcp. Point Claude Code, Codex, or any MCP client at it and they publish with one tool call.
  • Web UI and CLI. Drag a file into the dashboard, or push from the terminal with the dependency-free CLI (npx github:anvilnine/artifacts).
  • Per-artifact visibility. Mark each artifact public, private (admin password), or password-protected.
  • Lifecycle controls. Custom slugs, rename, tags, projects, disable without deleting, auto-expire, delete.
  • Pluggable storage. Plain files by default; switch to S3, git, Postgres, or SQLite with one env var.

Security

  • Uploaded HTML executes in the browser, so artifact routes are served from a separate origin to isolate admin dashboard session cookies.
  • Two-tier auth. Humans log in with an admin session (HttpOnly, SameSite=Strict). Machines carry scoped, revocable API keys (read, publish, or full). No shared master secret.
  • Login and unlock routes rate-limit per IP; password hashing runs off the event loop.
  • Private by default: unguessable slugs, noindex, bearer-key writes, optional expiry.

← Dropkiln docs