# handover

One agent writes it, another agent reads it. You only carry an 8-letter link between them. For when a clipboard can't help: an agent on a server or in the cloud, a Windows PC and an iPhone, handing work to someone else, or two agents going back and forth. Two modes:

- **One-shot**: one piece of text, fetched once. Not encrypted.
- **Channel**: two agents on two machines, many rounds, end-to-end encrypted.

Copy a prompt into your agent. Nothing to install, no account.

## One-shot

1. "Hand this over with handover.tools." → the agent gives you a link like handover.tools/kvmtrhxp.
   Works in any agent that can run commands (Claude Code, Codex, Cursor…). In a chat app that can't, add MCP first (below).
2. On the other device, paste the link to its agent: handover.tools/kvmtrhxp
   If an agent only describes the page instead of fetching, say "get handover.tools/kvmtrhxp".
   Opening that link never uses the code up, so a chat app's link preview can't burn it.
   No agent at all: open the same link in a browser.
- Changed your mind before it was fetched: "Revoke the handoff." Only the conversation that handed it off can revoke it.

## Channel

Both agents must be able to run commands: channel encrypts on your machines with a small client.
1. Machine A: "Open a handover.tools channel to review this project with my other machine." (say what the agents will work on) → a link.
2. Machine B: "Join handover.tools/kvmtrhxp." The agent may ask before downloading and running the client; say yes.
3. Every round: "Send it to the handover channel." (after reading the draft) / "Fetch the handover channel."
- Done: "Close the handover channel."

## Use it every day? Add MCP (optional)

"Add https://handover.tools/mcp as an MCP server." Lets chat apps that can't run commands send too.
No account, no key. If the tools don't show up in that conversation, start a new one (in Claude Code, /mcp also loads them).

## What happens to your data

|  | One-shot | Channel |
|---|---|---|
| Gone when | the first fetch (default) | either side closes it |
| Otherwise unreadable after | 60 minutes (the sender can allow up to 24 h) | 48 hours without use, 7 days at most |
| Delete it early | “Revoke the handoff.” Only in the conversation that sent it. | “Close the handover channel.” Either side can. |
| Can the server read it? | yes, while it is stored | no, it only holds ciphertext |
| A chat app previews the link | nothing happens: opening the link never uses it up | nothing happens: only the client can join |
| Your IP address | erased from our logs after 30 days | erased from our logs after 30 days |

Database backups can outlive a deletion for a while. For one-shot content that means a copy may exist after it stops being readable, which is why we say “unreadable”, not “destroyed”. For a channel, a backup holds only ciphertext.

## Compared with clipboards and magic-wormhole

|  | Web clipboard¹ | magic-wormhole² | handover one-shot | handover channel |
|---|---|---|---|---|
| Built for | people, via a web form | people, at a terminal | agents (MCP, REST); web page as fallback | two agents on two machines |
| The receiver installs | nothing | the CLI, on both sides | nothing: any agent that can open a web page | a small client, on both machines |
| Both sides online at once | no | yes: the sender waits until the receiver connects | no: it waits up to 24 h | no: messages wait up to 48 h |
| Code | 6 digits | number and words | 8 letters | 8 letters, once per pairing |
| After it is read | stays until it expires | nothing is stored | gone after one fetch (default) | kept until either side closes it |
| Encrypted | no | end to end | no | end to end |
| Back and forth | no | no, one transfer | no | yes, a person approves each message |
| Ads | yes | none | none | none |

¹ online-clipboard.online, checked 2026-09. ² The magic-wormhole command-line tool; channel pairs the same way (SPAKE2). Each is better at something: wormhole for moving a file between two terminals you are sitting at, a clipboard site for pasting a snippet to a friend. handover is for agents, from any vendor, when the two sides are not online at the same time.

Security details: /security.md
