Cloudinary for AI agents
Cloudinary manages images and videos in the cloud, handling upload, transformation, and delivery through a CDN so media loads fast anywhere it's shown. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Cloudinary.
Create an image transformation
Create a transformation preset, such as a resized crop, for a product image.
Organize assets into folders
Create a folder to keep a campaign's media assets organized in one place.
Confirm before deleting resources
Confirm before deleting resources by tag, since every matching asset is removed at once.
109 Cloudinary actions, graded by risk.
Every Cloudinary action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
42Look things up. Allowed by default.
- cloudinary.get_tagsGet Resource Tags
- cloudinary.get_usageGet Usage
- cloudinary.get_configGet product environment config details
- cloudinary.list_imagesList Images
- cloudinary.list_videosList Video Assets
- cloudinary.get_triggersList Webhook Triggers
- cloudinary.search_assetsSearch Assets
- cloudinary.list_raw_filesList Raw Files
- cloudinary.search_foldersSearch Folders
- cloudinary.get_live_streamGet Live Stream
- cloudinary.get_video_viewsGet Video Views
- cloudinary.get_live_streamsGet Live Streams
- cloudinary.get_root_foldersGet Root Folders
- cloudinary.get_upload_presetGet Upload Preset
- cloudinary.get_transformationGet Transformation
- cloudinary.get_transformationsGet Transformations
write
47Create and change things. Allow, or ask the user first.
- cloudinary.create_folderCreate Folder
- cloudinary.update_folderUpdate Folder
- cloudinary.create_triggerCreate Trigger
- cloudinary.update_triggerUpdate Trigger
- cloudinary.create_slideshowCreate Slideshow
- cloudinary.create_live_streamCreate Live Stream
- cloudinary.update_live_streamUpdate Live Stream
- cloudinary.create_metadata_ruleCreate Metadata Rule
- cloudinary.create_upload_presetCreate Upload Preset
- cloudinary.update_metadata_ruleUpdate Metadata Rule
- cloudinary.update_resource_tagsUpdate Resource Tags
- cloudinary.update_upload_presetUpdate Upload Preset
- cloudinary.create_metadata_fieldCreate Metadata Field
- cloudinary.create_multi_resourceCreate Multi-Resource Animation
- cloudinary.create_transformationCreate Transformation
- cloudinary.create_upload_mappingCreate Upload Mapping
destructive
20Delete, cancel or archive. Ask first, or deny outright.
- cloudinary.delete_folderDelete Folder
- cloudinary.delete_triggerDelete Trigger
- cloudinary.delete_live_streamDelete Live Stream
- cloudinary.delete_metadata_ruleDelete Metadata Rule
- cloudinary.delete_upload_presetDelete Upload Preset
- cloudinary.delete_metadata_fieldDelete Metadata Field
- cloudinary.delete_upload_mappingDelete Upload Mapping
- cloudinary.delete_transformation2Delete Transformation (v2)
- cloudinary.delete_derived_resourcesDelete Derived Resources
- cloudinary.delete_resources_by_tagsDelete Resources by Tags
- cloudinary.delete_streaming_profileDelete Streaming Profile
- cloudinary.delete_live_stream_outputDelete Live Stream Output
- cloudinary.delete_resources_by_asset_idDelete Resources by Asset ID
- cloudinary.delete_resources_by_public_idDelete Resources by Public ID
- cloudinary.delete_asset_relations_by_asset_idDelete Asset Relations by Asset ID
- cloudinary.delete_asset_relations_by_public_idDelete Asset Relations by Public ID
Cloudinary in three steps.
- 01Your users connect CloudinaryThey add their Cloudinary api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create Folder” can wait for the user, and “delete Folder” can be denied outright.
- 03Any agent can actYour agent calls Cloudinary through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('cloudinary', { read: 'allow', write: 'ask', // create_folder destructive: 'deny', // delete_folder }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Cloudinary connects.
Users add their Cloudinary api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Cloudinary connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Cloudinary from any agent.
Cloudinary and Arc0, answered.
Can I use Cloudinary with Claude, ChatGPT or Cursor?
Yes. Connect Cloudinary to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Cloudinary actions you allow.
How do users connect Cloudinary?
Users add their Cloudinary api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Cloudinary actions can my agent take?
109 in total: 42 read, 47 write and 20 destructive, such as “create Folder”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Cloudinary?
Yes. Actions like “delete Folder” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Cloudinary too?
Yes. The same Cloudinary connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Cloudinary into your agent.
Your users connect Cloudinary once, under your brand. Your agent gets 109 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan