U

uploads.sh

uploads.sh is a file-hosting service for sharing screenshots, recordings, and other files, especially into GitHub pull requests and issues. It provides hosted public file URLs and tools for agents and humans, with invitation-based workspace access.

3 integrations · MCP · REST · CLI

uploads.sh exposes a workspace-scoped REST API at `api.uploads.sh`, a hosted streamable-HTTP MCP server at `agents.uploads.sh/mcp`, and an `uploads` CLI; the API and CLI use a workspace bearer token, while the hosted MCP accepts either that bearer token or OAuth 2.1 via well-known discovery.

discovered 2mo ago
MCP servers1
REST · OpenAPI1
CLI1
Credentials
uploads.sh workspace tokenbearerGet token ↗

Get invited to an uploads.sh workspace, then run `uploads login` after installing the CLI: npm install -g @buildinternet/uploads && uploads login. The command opens a browser device sign-in flow (GitHub or magic link), lets you choose --workspace <name> if needed, and saves UPLOADS_TOKEN plus UPLOADS_API_URL and UPLOADS_WORKSPACE to the shared config. As a non-interactive fallback, supply the saved token via the UPLOADS_TOKEN environment variable. Token details and scopes are documented in auth.md.

OAuth 2.0oauth2
OAuth 2.0 — self-onboarding

Point your MCP client at the server URL and approve access in the browser. The server supports OAuth Dynamic Client Registration (RFC 7591), so the client registers itself automatically — no developer-portal app, client_id, or client_secret to create.

uploads.sh workspace tokenbearerGet token ↗

Sign in at https://uploads.sh/login (GitHub or email magic link). You need access to a workspace: create one at https://uploads.sh/account/workspaces/new (requires a linked GitHub account) or accept an invitation from a workspace admin. Then:

```bash

npm install -g @buildinternet/uploads

uploads login

```

uploads login runs a browser device-authorization flow and saves UPLOADS_TOKEN (with UPLOADS_API_URL and UPLOADS_WORKSPACE) to the shared config file; the raw token is never printed. Pass --workspace <name> if the account can reach more than one. Tokens look like up_<workspace>_…, are scoped to a single workspace, carry files:read and files:write by default (files:delete must be granted by an admin), and expire after 90 days. Full details: https://uploads.sh/auth.md

uploads.sh OAuth 2.1 (hosted MCP only)oauth2

Applies only to https://agents.uploads.sh/mcp — the REST API does not accept OAuth tokens in v1. The authorization server is https://auth.uploads.sh (issuer https://auth.uploads.sh/api/auth). It supports PKCE and dynamic client registration (RFC 7591), so an MCP client can register itself with no manual setup, and it is discoverable from the MCP endpoint via RFC 9728:

```bash

curl -s https://agents.uploads.sh/.well-known/oauth-protected-resource

curl -s https://auth.uploads.sh/.well-known/oauth-authorization-server

```

A human signs in and grants scopes (files:read, files:write, files:delete) at https://uploads.sh/oauth/consent. Each grant is scoped to exactly one workspace, carried in the token's workspace claim; a token minted without one is refused with a workspace_required error. There is no OIDC surface. Full details: https://uploads.sh/auth.md

conventions · 5/8 published

Publish these signals → /publishing