handover.tools

handover

One agent writes it, another agent reads it. You only carry an 8-letter link between them.

For when a clipboard can't help: an agent on a server or in the cloud, a Windows PC and an iPhone, handing work to someone else, or two agents going back and forth. Copy a prompt below into your agent. Nothing to install, no account.

One-shot not encrypted

One piece of text, fetched once.

  1. Device A

    “Hand this over with handover.tools.”

    Your agent stores it and gives you a link like handover.tools/kvmtrhxp. Works in any agent that can run commands, such as Claude Code, Codex or Cursor. In a chat app that can't, add MCP first.

  2. Device B

    Paste the link into its agent

    Just handover.tools/kvmtrhxp, nothing else. The text arrives, and it can't be fetched again.No agent? Open the link in a browser. Agent only describes the page? Say “get” and the link.

  3. Device A, same conversation

    “Revoke the handoff.”

    Changed your mind before device B fetched it? Only the conversation that handed it off can revoke it; a new conversation can't.

Channel end-to-end encrypted

Two agents on two machines, round after round. You approve every message. Both agents need to run commands, such as Claude Code, because each machine runs a small local client.

  1. Machine A

    “Open a handover.tools channel to review this project with my other machine.”

    Say what the two agents will work on after “to”. Your agent sets up encryption and answers with a link like handover.tools/kvmtrhxp.

  2. Machine B

    “Join handover.tools/kvmtrhxp.”

    Its agent may ask before downloading and running the client; say yes. The two machines are paired. The link can't be used again.

  3. Each round

    “Send it to the handover channel.”
    “Fetch the handover channel.”

    You read each draft before it goes. The other side only fetches when you ask. Saying “handover” lets a new conversation know which channel you mean.

  4. Either machine

    “Close the handover channel.”

    Every message is deleted from the server.

What happens to your data

One-shotChannel
Gone whenthe first fetch (default)either side closes it
Otherwise unreadable after60 minutes (the sender can allow up to 24 h)48 hours without use, 7 days at most
Delete it early“Revoke the handoff.” Only in the conversation that sent it.“Close the handover channel.” Either side can.
Can the server read it?yes, while it is storedno, it only holds ciphertext
A chat app previews the linknothing happens: opening the link never uses it upnothing happens: only the client can join
Your IP addresserased from our logs after 30 dayserased from our logs after 30 days

Database backups can outlive a deletion for a while. For one-shot content that means a copy may exist after it stops being readable, which is why we say “unreadable”, not “destroyed”. For a channel, a backup holds only ciphertext.

Compared with clipboards and magic-wormhole

Web clipboard¹magic-wormhole²handover one-shothandover channel
Built forpeople, via a web formpeople, at a terminalagents (MCP, REST); web page as fallbacktwo agents on two machines
The receiver installsnothingthe CLI, on both sidesnothing: any agent that can open a web pagea small client, on both machines
Both sides online at oncenoyes: the sender waits until the receiver connectsno: it waits up to 24 hno: messages wait up to 48 h
Code6 digitsnumber and words8 letters8 letters, once per pairing
After it is readstays until it expiresnothing is storedgone after one fetch (default)kept until either side closes it
Encryptednoend to endnoend to end
Back and forthnono, one transfernoyes, a person approves each message
Adsyesnonenonenone

¹ online-clipboard.online, checked 2026-09. ² The magic-wormhole command-line tool; channel pairs the same way (SPAKE2). Each is better at something: wormhole for moving a file between two terminals you are sitting at, a clipboard site for pasting a snippet to a friend. handover is for agents, from any vendor, when the two sides are not online at the same time.

Is it safe?

One-shot
Stored as plaintext until it is fetched or expires. Don't put secrets in it.
Channel
Encrypted on your machines. The server relays ciphertext and never sees the last 5 letters of the link, so it can't read or impersonate.
Both
Nothing is sent without you asking, and agents treat what they receive as requests, not commands.

What each mode protects, and what we don't claim

Use it every day? Add MCP

Optional. It lets chat apps that can't run commands send, too, and saves your agent a lookup. The prompts above stay the same.

  1. Once per agent

    “Add https://handover.tools/mcp as an MCP server.”

    No account, no key. If the tools don't show up in that conversation, start a new one (in Claude Code, /mcp also loads them).