ImageKit for AI agents

ImageKit is a media management platform for real-time image and video optimization, transformation, and delivery via CDN. Creative teams use it to generate this kind of asset on demand instead of by hand. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Design and imagesAPI keyMCP + RESTimagekit.io
AUDIT LOG · IMAGEKITPOLICY: acme-support
09:41:07 · claude · u_8f2read
imagekit.list_file_versions
List File Versions✓ allowed · 212ms
09:41:08 · claude · u_8f2read
imagekit.get_usage
Get Usage✓ allowed · 164ms
09:41:09 · claude · u_8f2write
imagekit.create_folder
Create Folder✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
imagekit.delete_file
Delete File✕ blocked · policy: deny
EVERY IMAGEKIT CALL, ON THE RECORD
01 · USE CASES

What agents do in ImageKit.

01

Check a file's metadata

Look up a media file's metadata and current tags before deciding how to transform it.

02

Move files into a folder

Move a batch of uploaded assets into the right folder to keep the media library organized.

03

Delete a file with confirmation

Delete a media file only after confirming it is not referenced on a live page.

02 · ACTIONS

26 ImageKit actions, graded by risk.

Every ImageKit action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

8

Look things up. Allowed by default.

  • imagekit.get_usage
    Get Usage
  • imagekit.get_file_details
    Get File Details
  • imagekit.get_file_metadata
    Get File Metadata
  • imagekit.list_file_versions
    List File Versions
  • imagekit.list_and_search_assets
    List and Search Media Assets
  • imagekit.get_file_version_details
    Get File Version Details
  • imagekit.list_custom_metadata_fields
    List Custom Metadata Fields
  • imagekit.get_authentication_parameters
    Get Upload Authentication Parameters

write

10

Create and change things. Allow, or ask the user first.

  • imagekit.create_folder
    Create Folder
  • imagekit.update_file_details
    Update File Details
  • imagekit.create_custom_metadata_field
    Create Custom Metadata Field
  • imagekit.update_custom_metadata_field
    Update Custom Metadata Field
  • imagekit.copy_folder
    Copy Folder
  • imagekit.move_folder
    Move Folder
  • imagekit.rename_file
    Rename File
  • imagekit.bulk_job_status
    Bulk Job Status
  • imagekit.bulk_move_files
    Bulk Move Files
  • imagekit.restore_file_version
    Restore File Version

destructive

8

Delete, cancel or archive. Ask first, or deny outright.

  • imagekit.delete_file
    Delete File
  • imagekit.delete_folder
    Delete Folder
  • imagekit.delete_file_version
    Delete File Version
  • imagekit.delete_multiple_files
    Delete Multiple Files
  • imagekit.delete_custom_metadata_field
    Delete Custom Metadata Field
  • imagekit.purge_cache
    Purge ImageKit Cache
  • imagekit.purge_status
    Check purge cache status
  • imagekit.bulk_remove_tags
    Bulk Remove Tags
03 · HOW IT WORKS

ImageKit in three steps.

  1. 01Your users connect ImageKitThey add their ImageKit api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Folder” can wait for the user, and “delete File” can be denied outright.
  3. 03Any agent can actYour agent calls ImageKit through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('imagekit', {
  read: 'allow',
  write: 'ask',        // create_folder
  destructive: 'deny',  // delete_file
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How ImageKit connects.

Users add their ImageKit api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same ImageKit connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use ImageKit from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

ImageKit and Arc0, answered.

Q01

Can I use ImageKit with Claude, ChatGPT or Cursor?

Yes. Connect ImageKit to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the ImageKit actions you allow.

Q02

How do users connect ImageKit?

Users add their ImageKit api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which ImageKit actions can my agent take?

26 in total: 8 read, 10 write and 8 destructive, such as “create Folder”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in ImageKit?

Yes. Actions like “delete File” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call ImageKit too?

Yes. The same ImageKit connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug ImageKit into your agent.

Your users connect ImageKit once, under your brand. Your agent gets 26 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan