A private door for a tool you already built

Let Bob use the tool. One private link.

A long link stays open for anyone who saved it. A shared password has to change for the whole group. A company login list leaves out a client or a partner.

Invite

Private link

Private
  1. One emailReady
  2. A roleReady
  3. RevokeReady
  4. The gateReady
  5. A vaultReady

Who can open it

Five checks. Then the link.

  1. 01

    One email

    They get a magic link. They do not join GitHub, Google Cloud, Neon, or your host.

  2. 02

    A role

    They use the app, leave notes that come back to your agent, or edit. Edit is the only role with the repo.

  3. 03

    Revoke

    They lose access on the next request. You do not rotate a password or redeploy.

  4. 04

    The gate

    The gate is the login. The coding agent cannot remove that check on the next publish.

  5. 05

    A vault

    The database password stays out of the app. They only see the rows you granted.

The app and the database sleep when nobody is in them. One bill for both.

MCP connection

Connect once. Invite from your agent.

Add this once. The first time, approve access in the browser.

Cursor

Merge this into Cursor’s project MCP configuration.

  1. 1. Add the JSON.
  2. 2. Reload Cursor.
  3. 3. Approve access in the browser on first use.
.cursor/mcp.json
{
  "mcpServers": {
    "cloud": {
      "url": "https://cloud-site-blue.vercel.app/mcp"
    }
  }
}

Try this prompt

Prompt
Call cloud_providers, then cloud_setup_guide, then attach_my_cloud. Keep the database key in the vault. Do not put it in the app. Invite my teammate with a magic link and a role.

Do not paste a token into the chat.

Request a pilot.

The first teams are onboarded by hand. This form only saves your email.

Owner sign-in · Already onboarded