handover
One agent writes it, another agent reads it. You only carry an 8-letter link between them.
For when a clipboard can't help: an agent on a server or in the cloud, a Windows PC and an iPhone, handing work to someone else, or two agents going back and forth. Copy a prompt below into your agent. Nothing to install, no account.
One-shot not encrypted
One piece of text, fetched once.
- Device A
“Hand this over with handover.tools.”
Your agent stores it and gives you a link like handover.tools/kvmtrhxp. Works in any agent that can run commands, such as Claude Code, Codex or Cursor. In a chat app that can't, add MCP first.
- Device B
Paste the link into its agent
Just handover.tools/kvmtrhxp, nothing else. The text arrives, and it can't be fetched again.No agent? Open the link in a browser. Agent only describes the page? Say “get” and the link.
- Device A, same conversation
“Revoke the handoff.”
Changed your mind before device B fetched it? Only the conversation that handed it off can revoke it; a new conversation can't.
Channel end-to-end encrypted
Two agents on two machines, round after round. You approve every message. Both agents need to run commands, such as Claude Code, because each machine runs a small local client.
- Machine A
“Open a handover.tools channel to review this project with my other machine.”
Say what the two agents will work on after “to”. Your agent sets up encryption and answers with a link like handover.tools/kvmtrhxp.
- Machine B
“Join handover.tools/kvmtrhxp.”
Its agent may ask before downloading and running the client; say yes. The two machines are paired. The link can't be used again.
- Each round
“Send it to the handover channel.”
“Fetch the handover channel.”
You read each draft before it goes. The other side only fetches when you ask. Saying “handover” lets a new conversation know which channel you mean.
- Either machine
“Close the handover channel.”
Every message is deleted from the server.
What happens to your data
| One-shot | Channel |
|---|
| Gone when | the first fetch (default) | either side closes it |
| Otherwise unreadable after | 60 minutes (the sender can allow up to 24 h) | 48 hours without use, 7 days at most |
| Delete it early | “Revoke the handoff.” Only in the conversation that sent it. | “Close the handover channel.” Either side can. |
| Can the server read it? | yes, while it is stored | no, it only holds ciphertext |
| A chat app previews the link | nothing happens: opening the link never uses it up | nothing happens: only the client can join |
| Your IP address | erased from our logs after 30 days | erased from our logs after 30 days |
Database backups can outlive a deletion for a while. For one-shot content that means a copy may exist after it stops being readable, which is why we say “unreadable”, not “destroyed”. For a channel, a backup holds only ciphertext.
Compared with clipboards and magic-wormhole
| Web clipboard¹ | magic-wormhole² | handover one-shot | handover channel |
|---|
| Built for | people, via a web form | people, at a terminal | agents (MCP, REST); web page as fallback | two agents on two machines |
| The receiver installs | nothing | the CLI, on both sides | nothing: any agent that can open a web page | a small client, on both machines |
| Both sides online at once | no | yes: the sender waits until the receiver connects | no: it waits up to 24 h | no: messages wait up to 48 h |
| Code | 6 digits | number and words | 8 letters | 8 letters, once per pairing |
| After it is read | stays until it expires | nothing is stored | gone after one fetch (default) | kept until either side closes it |
| Encrypted | no | end to end | no | end to end |
| Back and forth | no | no, one transfer | no | yes, a person approves each message |
| Ads | yes | none | none | none |
¹ online-clipboard.online, checked 2026-09. ² The magic-wormhole command-line tool; channel pairs the same way (SPAKE2). Each is better at something: wormhole for moving a file between two terminals you are sitting at, a clipboard site for pasting a snippet to a friend. handover is for agents, from any vendor, when the two sides are not online at the same time.
Is it safe?
- One-shot
- Stored as plaintext until it is fetched or expires. Don't put secrets in it.
- Channel
- Encrypted on your machines. The server relays ciphertext and never sees the last 5 letters of the link, so it can't read or impersonate.
- Both
- Nothing is sent without you asking, and agents treat what they receive as requests, not commands.
What each mode protects, and what we don't claim
Use it every day? Add MCP
Optional. It lets chat apps that can't run commands send, too, and saves your agent a lookup. The prompts above stay the same.
- Once per agent
“Add https://handover.tools/mcp as an MCP server.”
No account, no key. If the tools don't show up in that conversation, start a new one (in Claude Code, /mcp also loads them).