uploads.sh
uploads.sh is a file-hosting service for sharing screenshots, recordings, and other files, especially into GitHub pull requests and issues. It provides hosted public file URLs and tools for agents and humans, with invitation-based workspace access.
uploads.sh exposes a workspace-scoped REST API at `api.uploads.sh`, a hosted streamable-HTTP MCP server at `agents.uploads.sh/mcp`, and an `uploads` CLI; the API and CLI use a workspace bearer token, while the hosted MCP accepts either that bearer token or OAuth 2.1 via well-known discovery.
- uploads.sh hosted MCP serverdetected
- uploads.sh REST APIdetected
- uploads CLIdeclared
Get invited to an uploads.sh workspace, then run `uploads login` after installing the CLI: npm install -g @buildinternet/uploads && uploads login. The command opens a browser device sign-in flow (GitHub or magic link), lets you choose --workspace <name> if needed, and saves UPLOADS_TOKEN plus UPLOADS_API_URL and UPLOADS_WORKSPACE to the shared config. As a non-interactive fallback, supply the saved token via the UPLOADS_TOKEN environment variable. Token details and scopes are documented in auth.md.
Point your MCP client at the server URL and approve access in the browser. The server supports OAuth Dynamic Client Registration (RFC 7591), so the client registers itself automatically — no developer-portal app, client_id, or client_secret to create.
Sign in at https://uploads.sh/login (GitHub or email magic link). You need access to a workspace: create one at https://uploads.sh/account/workspaces/new (requires a linked GitHub account) or accept an invitation from a workspace admin. Then:
```bash
npm install -g @buildinternet/uploads
uploads login
```
uploads login runs a browser device-authorization flow and saves UPLOADS_TOKEN (with UPLOADS_API_URL and UPLOADS_WORKSPACE) to the shared config file; the raw token is never printed. Pass --workspace <name> if the account can reach more than one. Tokens look like up_<workspace>_…, are scoped to a single workspace, carry files:read and files:write by default (files:delete must be granted by an admin), and expire after 90 days. Full details: https://uploads.sh/auth.md
Applies only to https://agents.uploads.sh/mcp — the REST API does not accept OAuth tokens in v1. The authorization server is https://auth.uploads.sh (issuer https://auth.uploads.sh/api/auth). It supports PKCE and dynamic client registration (RFC 7591), so an MCP client can register itself with no manual setup, and it is discoverable from the MCP endpoint via RFC 9728:
```bash
curl -s https://agents.uploads.sh/.well-known/oauth-protected-resource
curl -s https://auth.uploads.sh/.well-known/oauth-authorization-server
```
A human signs in and grants scopes (files:read, files:write, files:delete) at https://uploads.sh/oauth/consent. Each grant is scoped to exactly one workspace, carried in the token's workspace claim; a token minted without one is refused with a workspace_required error. There is no OIDC surface. Full details: https://uploads.sh/auth.md
conventions · 5/8 published
- integrations.json✓https://uploads.sh/.well-known/integrations.json
- llms.txt✓https://uploads.sh/llms.txt
- API catalog✓https://uploads.sh/.well-known/api-catalog
- OpenAPI document✓https://uploads.sh/openapi.json
- MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✓https://uploads.sh/.well-known/agent-skills/index.json
Publish these signals → /publishing