E2E AES-256-GCM
Encryption and decryption happen only on the client, via WebCrypto. A random IV per chunk; the server never sees plaintext.
End-to-end encrypted · Self-hosted
Send large files encrypted end-to-end. You hold the key, nobody else reads it.
An internal WeTransfer clone with 100% in-browser AES-256-GCM encryption. The server never sees your files in the clear — or the key.
How it works
Your browser generates an AES-256 key and encrypts every chunk (WebCrypto) before upload. The server only moves opaque bytes.
You share a short link like /t/ABC123#k=… Fragments (#) are never sent to the server: only whoever has the full link can decrypt.
Pick a 1 to 30 day expiry or enable single download: once consumed, the link and objects are purged.
Features
Encryption and decryption happen only on the client, via WebCrypto. A random IV per chunk; the server never sees plaintext.
Decide when the link dies. Database TTL + a physical job that cleans the objects in S3.
Turn on burn-after-read or a download cap. When consumed, the transfer becomes deleted and storage is purged.
Your files in your S3 (MinIO), your metadata in MongoDB. No third parties, no external storage providers.
A Model Context Protocol server (streamable-http) so your agents can create transfers, upload encrypted data and get links.
A versioned public REST contract, an interactive Scalar reference and llms.txt so any LLM knows how to integrate.
The app is one click away. Integrations for agents and developers, too.
MCP config (JSON) for your client:
{
"mcpServers": {
"cargoffer-file-transfer": {
"url": "https://mcp.file-transfer.cargoffer.com/mcp",
"headers": {
"Authorization": "Bearer TU_TOKEN"
}
}
}
}