Self-hosted, single-file HTML publishing with per-document access control, on Cloudflare's free tier. Publish a report you made in a chat and get back a URL — open to anyone you send it to, or locked to specific people. Whoever opens it installs nothing.
Cloudflare Access asks who you are. The Worker asks whether you may see this.Publishing and remembering become the same act.One command installs it. Your own Cloudflare account runs it.
Two reasons to care
Adopt it for either half. Most people arrive for the first.
The simple half
A genuinely nice way to put a file behind a URL.
Publish the formats that are miserable to share anywhere else — live, interactive HTML and rendered Markdown — behind a small, real access model, straight from the chat where you made them. No "client" concept required.
The differentiator
One durable portal per client, that reads back as memory.
Every artifact you make for someone lands in one place they bookmark once. Six months later your AI assistant can search it — "what did we decide about the migration?" — and get the document back. Nothing else does this.
Publish & share
Get a link. Choose exactly who can open it.
Three sharing modes cover real needs without a permissions matrix — right-sized for one operator, not enterprise-shaped. Pick one and see what your recipient actually gets.
🔓—
Who can open it
—
What they do
—
Cloudflare seat cost
—
—
Finally, HTML & Markdown
The formats that suck to share elsewhere — Drive won't render HTML, Markdown shows up as raw text. PageVault serves them as proper, styled, live documents.
Readers register nowhere
The person opening your document installs nothing, creates no account, signs into no third-party app. They click a link and read.
Download raw or as PDF
Hand back the original file, or a single continuous-page PDF — a long infographic exports as one page, no pagination slicing a chart in half.
Publish from the chat
A remote MCP server means you publish from the surface where you made the thing — no separate upload step, no file shuffling. Or drop a file into the console from your browser, or push it from the CLI.
Friction-free deploy
Up in minutes on a free Cloudflare account: one npm install -g pagevault provisions and deploys with no clone — and there's a matching teardown, so you can test it because you can undo it.
Know whether it landed
Secured documents record who opened what, and when — a rolling three-month window you read from your own machine. No IP addresses, no user agents, no third-party analytics.
No lock-in, ever
A human-readable folder tree of every portal and document. Your work is never trapped in the tool — export the whole system and read it with your eyes.
The client concept
The link is not the unit. The client is.
Add someone to a client's team once and they can open everything you've sent that client — one change, not fourteen edits across fourteen emails. And the collection doesn't just sit there. It answers questions.
Northwind Labs6 documents · 3 people · one URL they bookmark once
Ask the portal something — your AI runs it over MCP
Illustrative. In practice this is search_portal and read_document — the same MCP tools that publish into the portal can read the whole corpus back.
★ The collection reads back
Your published work doubles as a searchable memory. Six months in, "what did we decide about the V2 migration?" is answerable from the portal. Publishing and remembering are the same act.
★ One portal per client
Not one link per document. Add someone to a client's team once and they can open everything — no more digging through Gmail for the January doc.
Zero onboarding for them
The client needs no account, no app, no registration. Onboarding their whole team is a few emails on your side and nothing on theirs.
Cross-client isolation is absolute
Being in one client's portal grants nothing in another's. The failure that would end a consulting business is designed out, not patched.
Public or private collections
A portal can be a private client vault, an email-gated team space, or a fully public showcase — same model, one axis of difference.
Draft in place, safely
Stage a document inside a client's portal the client cannot see — even if a link was already minted. Republishing names the document it is about to replace and refuses without an explicit confirm.
Under the hood
The Worker is the whole product.
One Cloudflare Worker, MIT-licensed, small enough to read in a sitting. That auditability is the value: the security isn't a black box you're asked to trust — it's code you can read, fork, and own.
One authorization function
Access answers "who are you?"; the Worker answers "may you see this?" in one pure, testable function that verifies the signed token itself — never trusting a header or a cookie.
Double sandbox, enforced by a test
LLM-generated JS runs sealed — it can't read your cookies, touch the page, or phone home. Isolation is set on both the served bytes and the iframe, and the build fails if the one dangerous flag ever appears in the repo.
Two path-scoped Access apps
The owner console and the client-facing routes can't be reached with each other's tokens. A privilege boundary, not a config detail.
The API token never hits the browser
Two independent defenses on every state-changing endpoint. A stolen cookie buys an attacker nothing.
Public ≠ unsandboxed
A public artifact is more exposed, not less — same sandbox, plus noindex so it stays out of search.
Seats are spent deliberately
Only people who actually authenticate consume one of Cloudflare's 50 free seats. Public and capability-link readers cost none — so the people who read once never crowd out the people who come back.
Economics
$0, plus a domain you already own.
One Worker, no server, no database, no invoice — against $19–$479/mo for a client-portal SaaS. And you only climb the deploy ladder as far as you actually need.
PageVault
$0 / free tier
SuiteDash
$19 / mo
Copilot
$39 / mo
Data-room / enterprise portal
up to $479 / mo
Public — links anyone you send them to can open, your own domain optional→Secured — named people, and client portals
Two tiers, both free. Documents carry across untouched when you climb, and Public undoes cleanly. Public and capability-link readers cost zero Cloudflare seats — gate the people who come back, link the people who read once.
The honest part
What it deliberately isn't.
The whole competitive claim is "we are not an all-in-one." Every feature past that line would weaken it. So here is what PageVault refuses to be — stated as plainly as everything else.
Not a client-portal SaaS
No invoicing, contracts, e-sign, CRM, or tasks. If you need the business suite, SuiteDash or Copilot is the right tool and it isn't close.
Not multi-tenant
One operator, one owner per portal. A team that needs shared ownership forks it.
No comments or live presence
That's jonesphillip/sharehtml's lane, credited for three ideas PageVault borrows. If the doc is a conversation, use that.
No client upload
That would demand virus scanning, quotas, and double the permission model. Out of scope on purpose.
A small class of docs breaks
Anything relying on localStorage, IndexedDB, or same-origin fetch won't run in the sandbox. The trade: a few documents break so that no document can steal a session.
The portal bet is unproven
It pays off across many engagements with one client. Below about five, a folder of links may be simpler — and we'll say so rather than pretend otherwise.