# shipsite.sh
> Static site hosting API for LLMs. Deploy sites with one API call. No git, no build steps, no dashboards. $0.10/site/day.
shipsite.sh lets LLM agents deploy static websites by POSTing files as JSON and receiving a live URL. Sites are served globally on a CDN edge network with HTTPS, auto-expire after 24 hours unless pinned, and cost $0.10 per site per day (prorated daily, billed monthly via Stripe). No free tier — payment is required before any deploys work.
API base URL: https://api.shipsite.sh
Authentication: Bearer sk_live_... (all endpoints except account creation)
IMPORTANT: API keys are shown only once when created and cannot be retrieved later. Store the key immediately. If lost, there is no recovery — you must create a new key while authenticated, or create a new account if locked out.
Keys are inert (return 402) until Stripe checkout completes.
FIRST: ask your user how comfortable they are with technical things (not at all / a little / developer). If they are not a developer, or you're unsure, follow the guided, no-jargon track in https://shipsite.sh/auth.md — do it all yourself in this conversation, never ask them to edit config files or start a new session. Developers can use the quick start below.
Quick start:
1. POST /v1/accounts with { "email": "you@example.com" } — returns api_key + setup_url
2. Open setup_url to complete Stripe checkout and activate the key
3. POST /v1/sites with Authorization: Bearer sk_live_... and { "files": { "index.html": "..." } } — returns { "url": "https://site_abc123.shipsite.sh" }
Endpoints:
- POST /v1/accounts (no auth): Create account. Body: { "email": "..." }. Returns: { "api_key": "sk_live_...", "setup_url": "https://checkout.stripe.com/...", "status": "pending" }. IMPORTANT: The api_key is shown only once — store it immediately.
- POST /v1/sites: Create a site. Body: { "files": { "path": "content" }, "name": "optional-slug", "meta": {} }. Text files as strings, binary files with "base64:" prefix. Returns: { "id": "site_...", "url": "https://....shipsite.sh", "expires_at": "..." }
- GET /v1/sites: List sites. Supports ?limit= and ?offset= pagination.
- GET /v1/sites/:id: Get site details (metadata, file list, expiry).
- PUT /v1/sites/:id: Update a site. Body accepts "files", "name", and/or "meta" (at least one required). Omitted files unchanged. Set a file to null to delete it. Set "name" to a string to add or change the vanity slug, or null to remove it.
- DELETE /v1/sites/:id: Delete a site immediately. Billing stops.
- POST /v1/sites/:id/pin: Remove auto-expiry. Site persists until deleted.
- POST /v1/sites/:id/unpin: Re-apply 24h TTL from current time.
- GET /v1/accounts/me: Get account status and active site count.
- GET /v1/accounts/me/keys: List all API keys (active and revoked) for the account.
- POST /v1/accounts/me/keys: Create a new API key. Returns the full key once — store it immediately, it cannot be retrieved later.
- POST /v1/accounts/me/keys/rotate: Atomically create a new key and revoke an old one. Body: { "revoke_key_id": "key_..." } (optional — omit to revoke the current key).
- DELETE /v1/accounts/me/keys/:id: Revoke an API key. Cannot revoke the last active key.
File encoding rules:
- Text files (.html, .css, .js, .svg, .json, .txt, .xml, .md): send as plain strings
- Binary files (.png, .jpg, .gif, .webp, .ico, .woff2, .pdf): "base64:" prefix + base64 content
Site name rules (optional "name" field on POST /v1/sites or PUT /v1/sites/:id):
- 3–63 characters, lowercase letters, numbers, and hyphens only
- Must start and end with a letter or number
- No consecutive hyphens (--)
- Globally unique — collisions return 409 with code "name_taken"
- Can be set at creation or added/changed/removed later via PUT
- Set to null in PUT to remove the name from an existing site
- Reserved names (cannot be used): api, www, app, admin, dashboard, billing, docs, help, support, status, blog, mail, smtp, ftp, cdn, assets, static, login, signup, auth, account, accounts, settings, config, setup, test, staging, dev, prod, internal
Site behavior:
- Served at https://{site_id}.shipsite.sh (or https://{name}.shipsite.sh if named)
- index.html served for / and as SPA fallback
- HTTPS on all sites, global CDN, CORS: Access-Control-Allow-Origin: *
- No injected content — sites served exactly as uploaded
- Auto-expire after 24 hours unless pinned
Limits: 1,000 active sites, 120 deploys/hour, 100 files/site, 15 MB total payload, 5 MB per file, 100,000 requests/site/day.
Error format: { "error": { "code": "...", "message": "Actionable description of what went wrong, why, and how to fix it.", "details": { ... } } }
Common codes: payment_required (402), rate_limited (429), validation_error (400), not_found (404).
## Documentation
- [Full documentation (llms-full.txt)](https://shipsite.sh/llms-full.txt): This file plus the full text of every page linked below, in one fetch
- [API Reference](https://shipsite.sh/#api): Full endpoint details, examples, and file encoding rules
- [Agent registration (auth.md)](https://shipsite.sh/auth.md): How an agent registers, gets an API key, and uses it
- [Terms of Service](https://shipsite.sh/terms): Acceptable use policy, DMCA process, prohibited content
## MCP Server
- [@shipsite/mcp](https://www.npmjs.com/package/@shipsite/mcp): MCP server package for Claude Code, Cursor, and Windsurf
MCP config:
{
"mcpServers": {
"shipsite": {
"command": "npx",
"args": ["@shipsite/mcp"],
"env": { "SHIPSITE_API_KEY": "sk_live_..." }
}
}
}
Tools: deploy_site, list_sites, get_site, delete_site, pin_site, unpin_site, rename_site, create_account, get_account, list_keys, create_key, rotate_key, revoke_key
## Optional
- [Homepage](https://shipsite.sh/): Marketing site with visual examples and pricing breakdown
- [Pricing examples](https://shipsite.sh/#pricing): 1 site/30 days = $3, 10 sites/30 days = $30, 1 site/2 hours = $0.10
---
## Agent registration (auth.md)
Source: https://shipsite.sh/auth.md
Agent registration and credential guide for shipsite.sh, a static hosting API for LLM agents.
### Audience
AI agents acting on behalf of a human who will pay for hosting. There is no free tier: a human must complete payment setup before any API call works.
### Step 0: Find out how comfortable your user is (agents: do this first)
Before registering, ask the user one plain question, for example:
> "Quick question so I explain things at the right level: how comfortable are you with technical stuff like APIs and config files? (a) Not at all, just do it for me, (b) A little, (c) I'm a developer."
Pick the track from their answer. If they seem confused by the question, or by anything you say later, switch to the guided track. If you can't ask, default to the guided track; it works for everyone.
- **(a) or (b) or unsure: Guided track.** Follow "Guided track" below.
- **(c) Developer: Developer track.** Follow "Developer track" below.
### Guided track (novice users)
Rules for you, the agent:
- Do the work yourself. Never ask the user to edit config files, run commands, install anything, or start a new session. Everything below works inside this one conversation. Do not use the MCP server setup; it requires editing config and restarting, which is where people get lost.
- Use plain words. Don't say "API", "key", "token", "endpoint" or "JSON" to the user. Say "your shipsite account" and "your site".
- Tell the user what you're about to do in one sentence before each step, and what they need to do (if anything) in one sentence after.
- Give one instruction at a time. Never hand the user a list of steps.
Steps:
1. Ask for the user's email address. Say it will be used to create their shipsite account.
2. Register (see "Registration" below). The response contains a secret called `api_key` that is shown only once. Save it yourself right away, somewhere you can read it back later, such as a file named `.shipsite-key` in the current working folder (and add it to `.gitignore` if there is one). If you cannot store anything, tell the user: "Please copy this long secret code and save it in your password manager (like 1Password, Bitwarden or iCloud Keychain), not in a notes app or email. I'll need it if we lose this conversation." Never print it again afterwards.
3. Tell the user the only thing they have to do: "Please open this link and add a payment card. Hosting costs about 10 cents per day per site, and you can delete a site anytime to stop charges." Give them `setup_url`. Do not try to pay for them.
4. Once they say they're done, check by calling `GET /v1/accounts/me` with the saved secret. `status: "active"` means it worked. A 402 means payment isn't finished yet; gently ask them to try the link again.
5. Deploy their site (`POST /v1/sites`) and give them the live link. Remind them that sites disappear after 24 hours unless you "keep" (pin) them, and offer to do it.
If something fails, explain it in one plain sentence and fix it yourself. Don't paste raw errors at the user. If you start a new session later, read the saved secret from `.shipsite-key` instead of registering again (a second registration with the same email returns 409).
### Developer track
You can be terse. Registration returns the key once; export it as `SHIPSITE_API_KEY` or configure the MCP server:
```json
{
"mcpServers": {
"shipsite": {
"command": "npx",
"args": ["@shipsite/mcp"],
"env": { "SHIPSITE_API_KEY": "sk_live_..." }
}
}
}
```
The MCP client must be restarted to pick up new env, so register via REST first (or the `create_account` tool), have the human complete `setup_url`, then restart once with the key in place. Plain REST needs no restart: `curl -H "Authorization: Bearer $SHIPSITE_API_KEY" https://api.shipsite.sh/v1/sites -d '{"files":{"index.html":"
hi
"}}'`. Use `name` for a vanity slug, `pin` to disable the 24h expiry, and rotate keys with `POST /v1/accounts/me/keys/rotate`. Spec: https://shipsite.sh/openapi.json.
### Credential type
Static API key (bearer token), prefixed `sk_live_`. There is no OAuth server, so no OAuth protected resource or authorization server metadata is published.
### Registration
Method: `email` (the human's email address; no email verification step).
```
POST https://api.shipsite.sh/v1/accounts
Content-Type: application/json
{"email": "human@example.com"}
```
Response (201):
```json
{
"id": "acc_...",
"api_key": "sk_live_...",
"setup_url": "https://checkout.stripe.com/...",
"status": "pending"
}
```
- `api_key` is shown once. Store it securely; it cannot be retrieved later.
- The key is inert until the human opens `setup_url` and completes Stripe checkout. Until then authenticated calls return 402 with a fresh payment link.
- Ask the human to open `setup_url`. Do not attempt to complete payment yourself.
- 409 `account_exists`: the email is already registered. Use the existing key or contact support@shipsite.sh.
- 429: account creation is rate limited per IP. Retry after the `Retry-After` interval.
### Using the credential
Send the key on every authenticated request:
```
Authorization: Bearer sk_live_...
```
Base URL: `https://api.shipsite.sh`. Manage keys with `GET/POST /v1/accounts/me/keys`, `POST /v1/accounts/me/keys/rotate`, and `DELETE /v1/accounts/me/keys/{id}`.
### Claiming and revocation
There is no separate claim step: the registering email owns the account. Revoke a key with `DELETE /v1/accounts/me/keys/{id}`.
### References
- Full API docs: https://shipsite.sh/llm
- OpenAPI spec: https://shipsite.sh/openapi.json
- API catalog: https://shipsite.sh/.well-known/api-catalog
---
## API Reference
Source: https://shipsite.sh/#api
Base URL: `https://api.shipsite.sh`
#### Authentication
All requests (except account creation) require an API key in the Authorization header.
```
Authorization: Bearer sk_live_...
```
#### Endpoints
`POST` `/v1/accounts`
Create account (no auth needed)
`POST` `/v1/sites`
Create a site
`GET` `/v1/sites`
List your sites
`GET` `/v1/sites/:id`
Get site details
`PUT` `/v1/sites/:id`
Update files, name, or metadata
`DELETE` `/v1/sites/:id`
Delete a site
`POST` `/v1/sites/:id/pin`
Pin site (no auto-expire)
`POST` `/v1/sites/:id/unpin`
Unpin site (re-enable 24h TTL)
`GET` `/v1/accounts/me`
Get account status
`GET` `/v1/accounts/me/keys`
List API keys
`POST` `/v1/accounts/me/keys`
Create new API key
`POST` `/v1/accounts/me/keys/rotate`
Rotate key (create + revoke)
`DELETE` `/v1/accounts/me/keys/:id`
Revoke an API key
#### Full Example
create an account
```
POST https://api.shipsite.sh/v1/accounts
{ "email": "you@example.com" }
# Response:
{
"id": "acc_x8k2m",
"api_key": "sk_live_a1b2c3d4...",
"setup_url": "https://checkout.stripe.com/...",
"status": "pending"
}
# Save the api_key now — it is shown only once and cannot be retrieved later
# Open setup_url to activate your key
```
deploy a site
```
POST https://api.shipsite.sh/v1/sites
Authorization: Bearer sk_live_a1b2c3d4...
{
"files": {
"index.html": "\n...",
"style.css": "body { font-family: sans-serif }",
"logo.png": "base64:iVBORw0KGgo..."
},
"name": "my-project"
}
# Response:
{
"id": "site_a7x9k2",
"url": "https://my-project.shipsite.sh",
"expires_at": "2026-02-21T12:00:00Z"
}
```
#### MCP Server
Use shipsite.sh as a tool in Claude Code, Cursor, or any MCP-compatible agent.
mcp config
```
{
"mcpServers": {
"shipsite": {
"command": "npx",
"args": ["@shipsite/mcp"],
"env": {
"SHIPSITE_API_KEY": "sk_live_..."
}
}
}
}
```
#### File Encoding
Text files (`.html`, `.css`, `.js`, `.svg`, `.json`, `.txt`, `.xml`, `.md`) — send as plain strings.
Binary files (`.png`, `.jpg`, `.gif`, `.webp`, `.ico`, `.woff2`, `.pdf`) — prefix with `base64:` followed by base64-encoded content.
---
## Frequently Asked Questions
Source: https://shipsite.sh/#faq
Common questions about shipsite.sh
#### What makes ShipSite different?
We treat LLMs as the primary interface for static site deploys. Instead of the usual rigamarole of provisioning tokens, configuring access, and wiring credentials into your agentic setup, your LLM can request a token and hand you a simple Stripe checkout link. Once you pay and activate, your LLM handles everything else — from idea to live URL with minimal friction.
#### How do I deploy a website with an AI agent?
Add the shipsite.sh MCP server to your AI tool (Claude Code, Cursor, Windsurf) and your agent can deploy sites directly. Or use the REST API — your agent POSTs files as JSON to `POST /v1/sites` and gets back a live URL in under a second.
#### What kinds of sites can I host?
Any static site — HTML, CSS, JavaScript, images, fonts, PDFs. Single-page apps work too (index.html is served as a fallback). No server-side code, no databases, no build steps. You send ready-to-serve files.
#### Is there a free tier?
No. All accounts require payment setup via Stripe before any deploys work. This keeps the platform abuse-free and the service reliable. At $0.10/day per site, a quick deploy costs a dime.
#### How long do sites stay live?
Sites auto-expire after 24 hours by default. Pin a site to keep it live indefinitely — it stays up until you delete it. Billing runs either way at $0.10/day.
#### What's the MCP server?
MCP (Model Context Protocol) lets AI agents use external tools natively. The `@shipsite/mcp` package exposes shipsite.sh as a set of tools — deploy, list, delete, pin, rename — that agents in Claude Code, Cursor, and Windsurf can call directly.
#### Can I use a custom domain?
Not yet. Sites are served at `{id}.shipsite.sh` (or `{name}.shipsite.sh` if you set a vanity slug). You can add or change the slug anytime via `PUT /v1/sites/:id`. Custom domains may come in a future version.
#### How is billing calculated?
$0.10 per site per day, prorated. If a site exists for any part of a day, that's one site-day. Usage is metered daily and billed monthly through Stripe. Deleting a site stops billing immediately. No egress fees, no hidden costs.
---
## Terms of Service
Source: https://shipsite.sh/terms
Effective date: February 20, 2026
These Terms of Service ("Terms") govern your use of shipsite.sh ("the Service"), operated by shipsite.sh ("we", "us", "our"). By accessing or using the Service, you agree to be bound by these Terms. If you do not agree, do not use the Service.
### 1. Service Description
shipsite.sh is a static site hosting service accessible via API. Users deploy websites by sending files through the API and receive publicly accessible URLs. The Service may also be used through MCP-compatible tools and LLM agents.
### 2. Account and API Keys
You must provide a valid email address and complete payment setup to use the Service. You are responsible for safeguarding your API key and for all activity that occurs under your account, whether initiated by you directly or by automated tools (including LLM agents) acting on your behalf.
### 3. User Content
You retain ownership of all content you deploy through the Service ("Your Content"). You are solely responsible for Your Content and represent that:
- You have all necessary rights, licenses, and permissions to deploy it.
- It does not infringe any third party's intellectual property, privacy, or other rights.
- It complies with all applicable laws and these Terms.
We have no obligation to monitor Your Content, but reserve the right to review, remove, or disable access to any content at any time, for any reason, without notice.
### 4. Acceptable Use Policy
You agree not to use the Service to host, distribute, or facilitate any of the following:
- **Malware and malicious code** — viruses, trojans, ransomware, cryptominers, keyloggers, or any software designed to harm users or systems.
- **Phishing and fraud** — sites that impersonate other services, collect credentials deceptively, or facilitate scams.
- **Illegal content** — any material that violates applicable local, state, national, or international law.
- **Child sexual abuse material (CSAM)** — absolutely prohibited; will be reported to law enforcement immediately.
- **Harassment and threats** — content that threatens, harasses, doxxes, or incites violence against individuals or groups.
- **Hate speech** — content that promotes violence or discrimination based on race, ethnicity, religion, gender, sexual orientation, disability, or other protected characteristics.
- **Intellectual property infringement** — pirated software, unauthorized copyrighted material, or trademark violations.
- **Spam and abuse** — bulk messaging, click fraud, SEO manipulation, or using the Service solely for redirect/proxy purposes.
- **Non-consensual intimate imagery** — including AI-generated or manipulated content.
Use of automated tools (including LLM agents) to deploy content does not reduce your responsibility for what is deployed. You are accountable for all content on your account regardless of how it was created or uploaded.
### 5. DMCA and Takedown Requests
We respect intellectual property rights and comply with the Digital Millennium Copyright Act (DMCA). If you believe content hosted on the Service infringes your copyright, send a takedown notice to **abuse@shipsite.sh** including:
- Identification of the copyrighted work.
- The URL of the infringing content on our Service.
- Your contact information.
- A statement of good faith belief that the use is unauthorized.
- A statement, under penalty of perjury, that the information is accurate and you are the rights holder or authorized agent.
- Your physical or electronic signature.
We maintain a **repeat infringer policy**. Accounts that are the subject of repeated valid takedown notices will be terminated.
### 6. Law Enforcement and Legal Requests
We will comply with valid legal requests including court orders, subpoenas, and law enforcement requests. We may disclose account information and content when required by law or when we believe in good faith that disclosure is necessary to protect safety or prevent illegal activity.
### 7. Termination and Suspension
We may suspend or terminate your account at any time, with or without notice, for any reason, including but not limited to violation of these Terms. Upon termination:
- Your API key will be deactivated.
- Your hosted sites may be immediately removed.
- You are not entitled to a refund for the current billing period.
You may close your account at any time by contacting us.
### 8. Payment and Billing
The Service is billed on a usage basis at the rates displayed at the time of account creation. Usage is metered daily and billed monthly through Stripe. You are responsible for all charges incurred under your account. We reserve the right to change pricing with 30 days notice.
### 9. Disclaimer of Warranties
**THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE, OR THAT ANY DEFECTS WILL BE CORRECTED.**
### 10. Limitation of Liability
**TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, DATA, BUSINESS OPPORTUNITIES, OR GOODWILL, ARISING OUT OF OR RELATED TO YOUR USE OF THE SERVICE.**
**OUR TOTAL LIABILITY FOR ANY CLAIM ARISING FROM THESE TERMS OR THE SERVICE SHALL NOT EXCEED THE GREATER OF (A) THE AMOUNTS YOU PAID TO US IN THE SIX MONTHS PRECEDING THE CLAIM, OR (B) ONE HUNDRED U.S. DOLLARS ($100).**
### 11. Indemnification
You agree to indemnify, defend, and hold harmless shipsite.sh and its operators, officers, and agents from any claims, damages, losses, liabilities, and expenses (including reasonable legal fees) arising from:
- Your Content or your use of the Service.
- Your violation of these Terms.
- Your violation of any applicable law or third-party rights.
### 12. Governing Law
These Terms are governed by the laws of the State of California, without regard to conflict of law principles. Any disputes shall be resolved in the courts located in San Francisco County, California.
### 13. Changes to These Terms
We may update these Terms at any time. Material changes will be noted by updating the effective date at the top of this page. Continued use of the Service after changes take effect constitutes acceptance of the revised Terms.
### 14. Contact
For abuse and takedown requests: **abuse@shipsite.sh**
For account and billing support: **support@shipsite.sh**