Safe folder access for ChatGPT and Claude: read, write and search files, risky tools opt-in.
Give ChatGPT and Claude access to the folders you choose — and nothing else.
FreeRDC is an MCP server for file work with AI assistants. It reads, writes, searches and edits files and documents inside the folders you approve, and refuses everything outside them. Anything that can run commands, click the screen or shut the machine down is off unless you turn it on.
Demo video ·
Website ·
Privacy ·
Listed on the official MCP Registry as io.github.danielarif26/freerdc
.. traversal and
symlink escapes are rejected before any file is touched. Protected paths such
as device keys are denied even inside a root.STOP file kill switch.freerdc-0.1.0.mcpb from
Releases.Requires macOS and Node.js 22+. Details and privacy policy:
mcpb/README.md.
Run the server locally and reach it privately through OpenAI Secure MCP Tunnel.
Do not expose the local listener to the public internet. See
docs/OPENAI-INTEGRATION.md and
docs/DEPLOYMENT.md.
The hosted connector is in review for the ChatGPT app directory. Until it is
listed, add it in ChatGPT developer mode with the MCP URL
https://freerdc.sjaman.deno.net/mcp.
Connect FreeRDC in ChatGPT. The sign-in page shows a 10-character pairing code (letters A–Z and digits 2–9).
Download freerdc-agent-hosted.mjs from
Releases.
Requires Node.js 22+.
Pair this computer, choosing the folder ChatGPT may use:
node freerdc-agent-hosted.mjs connect --server https://freerdc.sjaman.deno.net/mcp --code YOUR_CODE --device-id my-mac --root /absolute/allowed/folder
Keep the agent running while you use FreeRDC:
node freerdc-agent-hosted.mjs run --device-id my-mac
The pairing code expires after about 10 minutes. The agent is a prebuilt binary; its source is not included in this repository.
Requires Node.js 22+, npm and Git.
npm ci
npm run build
node packages/server/dist/src/cli.js --root /absolute/allowed/folder --port 8787
The server binds to 127.0.0.1 only, requires at least one explicit root,
stores state under ~/.freerdc, and leaves process tools disabled. Create
~/.freerdc/STOP to activate the kill switch. Pick the narrowest folder that
fits the task — never add credentials, caches or unrelated projects to a root.
macOS or Linux:
curl -fsSLo install.sh https://raw.githubusercontent.com/danielarif26/freerdc/main/install.sh
sh install.sh
Windows PowerShell:
Invoke-WebRequest https://raw.githubusercontent.com/danielarif26/freerdc/main/install.ps1 -OutFile install.ps1
.\install.ps1
The installers follow the mutable main branch. For higher assurance, review a
commit or tag and pin it with FREERDC_REF=<tag-or-commit>. Rerun with
--uninstall (macOS/Linux) or -Uninstall (Windows) to remove an
installer-managed copy.
| Package | Purpose |
|---|---|
@freerdc/protocol | Wire schemas, RPC contracts, errors, redaction, negotiation |
@freerdc/guard | Path containment, protected-path denylist, concurrency primitives |
@freerdc/agent | Filesystem, process policy, RPC dispatcher, authenticated connector |
@freerdc/server | MCP tools, HTTP host, OAuth, audit log, runtime CLI |
npm run typecheck && npm run build && npm test
SECURITY.md.Released under AGPL-3.0-or-later. See
docs/EDITIONS.md for what the Community Edition includes.
This listing does not have a supported local package template. Use the maintainer’s documentation for its hosted endpoint, authentication, and client-specific setup. No install command has been inferred.