Every HTML file your agent makes gets a private link. One command. Nothing to pay us.
A link that opens on any device. Locked behind a sign-in the Worker checks on every request. Ready the moment your agent publishes, with nothing for you to do after a one-time setup. All of it in your own Cloudflare account.
htmlgate costs nothing. Cloudflare bills your own account for what you use.
$ htmlgate publish report.html --title "October close"
https://html.example.com/d/q7Rk2mXa9LpB
$ htmlgate public q7Rk2mXa9LpB # only if you want to
Right now you have three bad options.
Your agent hands you dashboards, reports, prototypes and pull request diffs as .html files, with charts that move and tables that filter. To share one, you pick a bad option.
Drop the file in chat, and nobody opens it on their phone. Push it to a public host, and anyone holding the link can read your numbers. Take a screenshot, and the interactive chart becomes a picture of a chart.
htmlgate is the fourth option: every file gets a stable address behind a sign-in you control. You send the link. Done.
Three steps from zero to publishing
You do the first one once. The other two become your agent's routine.
Install it in your account
pnpm run setupcreates the database, the bucket, the Worker and the Cloudflare Access sign-in. Run it again any time: it updates in place and never takes anything offline.Give your agent a token
One per machine or per agent, made on the token page. If one leaks, revoke it there and it stops working on its next request.
Your agent publishes
htmlgate publish file.htmlreturns the URL. To update it without changing the link, publish with--slug: the same address gets a new Version, and the latest 20 are kept.
Everything you get
Each piece below is something you would otherwise build, secure and keep running yourself. The price for all of it is in the next section.
Gated by default
Every Drop starts visible only to the people on your list, after they sign in through Cloudflare Access. Want one open to the world? htmlgate public. Changed your mind? htmlgate gate closes it again from the next request.
Your account, your keys
You install it in your own Cloudflare account. Nobody else holds your credentials, including the person who wrote htmlgate.
Agent HTML in a sandbox
Every Drop runs isolated, in an opaque origin. Its scripts cannot read the Viewer's cookies or act as the Viewer.
Off the list, out the door
The Worker checks your list on every request. Remove someone and they lose access on their next one.
Built for agents
A CLI with --output json, documented exit codes, and a ready-made skill that teaches your agent to publish on its own.
Version history
Every update with --slug becomes a new Version at the same URL. The latest 20 are kept, each with its own link.
The catch: what it costs
htmlgate charges nothing. What can cost money is Cloudflare, on your own bill, for what you use.
- Workers. The free plan should be enough, but it is untested. Version 0.1 runs on the paid plan.
- R2, where the files live. You turn on the subscription once in the dashboard. It includes 10 GB-month free; past that, Cloudflare bills storage and operations. htmlgate stops at 5 GB by default.
- Zero Trust, the sign-in. It has a free plan, and Cloudflare still asks for payment details.
Who this is not for
- You want a public website with SEO and a pretty domain. Use a static site host.
- Several people will publish, each with their own account. In 0.1, whoever installs it is the only Author.
- You don't have a Cloudflare account and don't want one.
- Your files go past 2 MiB. That is the limit for each Drop.
Questions everyone asks
Is it open source?
Yes, under the MIT license. The repository goes public at version 0.1. The command-line client is a fork of htmlbin-cli, also MIT.
Do I need to be a developer?
You need to be comfortable in a terminal: install Node 26 and pnpm, sign in to Cloudflare and run setup. If you already use a coding agent, it can do this with you.
What if a token leaks?
Revoke it on the token page: it stops on its next request. Then list public Drops with htmlgate list --public and check who last changed each one. Revoking does not undo what the token already did.
Can a Drop steal data from the people who open it?
It runs isolated, with no access to the Viewer's cookies or session. It can still send what it contains to another site. The isolation protects the Viewer; what goes inside a Drop is the publisher's call.
What is "Sign in" up top?
It is the Instance of the person who wrote htmlgate, at app.htmlgate.com. Only invited people get in. Yours lives in your own account, at the address you choose.
Is this htmlbin?
It was inspired by htmlbin, and its client is a fork of htmlbin-cli. It is not htmlbin and is not affiliated with htmlbin.dev.
Stop pasting screenshots. Send links.
You need a Cloudflare account with R2 and Zero Trust turned on, Node 26, pnpm, and the wrangler and cf CLIs signed in to that same account. The rest is below, and the operator guide explains every step.
git clone https://github.com/mneves75/htmlgate
cd htmlgate && pnpm install
cp instance.example.json instance.json # edit: your name, your email, who may open Drops
pnpm run setup
pnpm run token create laptop # prints the token once
pnpm run build:cli && npm install -g ./packages/cli
htmlgate login https://your-instance.example.com
The repository goes public at version 0.1. The operator guide explains every step and what it changes in your account.