U

uploads.sh hosted MCP server

MCP detected 2026-07-22

Details
Endpoint
https://agents.uploads.sh/mcp
Transport
streamable-http
Docs
https://uploads.sh/docs/agents
Authentication
OAuth 2.0 oauth2 detected 2026-07-22
OAuth · resolves from well-known metadata
OAuth 2.0 — self-onboarding

Point your MCP client at the server URL and approve access in the browser. The server supports OAuth Dynamic Client Registration (RFC 7591), so the client registers itself automatically — no developer-portal app, client_id, or client_secret to create.

uploads.sh workspace token bearer declared Get token ↗
Authorization: Bearer <credential>

Sign in at https://uploads.sh/login (GitHub or email magic link). You need access to a workspace: create one at https://uploads.sh/account/workspaces/new (requires a linked GitHub account) or accept an invitation from a workspace admin. Then:

```bash

npm install -g @buildinternet/uploads

uploads login

```

uploads login runs a browser device-authorization flow and saves UPLOADS_TOKEN (with UPLOADS_API_URL and UPLOADS_WORKSPACE) to the shared config file; the raw token is never printed. Pass --workspace <name> if the account can reach more than one. Tokens look like up_<workspace>_…, are scoped to a single workspace, carry files:read and files:write by default (files:delete must be granted by an admin), and expire after 90 days. Full details: https://uploads.sh/auth.md

uploads.sh OAuth 2.1 (hosted MCP only) oauth2 declared
OAuth · resolves from well-known metadata

Applies only to https://agents.uploads.sh/mcp — the REST API does not accept OAuth tokens in v1. The authorization server is https://auth.uploads.sh (issuer https://auth.uploads.sh/api/auth). It supports PKCE and dynamic client registration (RFC 7591), so an MCP client can register itself with no manual setup, and it is discoverable from the MCP endpoint via RFC 9728:

```bash

curl -s https://agents.uploads.sh/.well-known/oauth-protected-resource

curl -s https://auth.uploads.sh/.well-known/oauth-authorization-server

```

A human signs in and grants scopes (files:read, files:write, files:delete) at https://uploads.sh/oauth/consent. Each grant is scoped to exactly one workspace, carried in the token's workspace claim; a token minted without one is refused with a workspace_required error. There is no OIDC surface. Full details: https://uploads.sh/auth.md