Uploadcare for AI agents
Uploadcare handles file uploading, storage, processing, and delivery for web and mobile apps, used by developers who don't want to run their own file infrastructure. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Uploadcare.
Get file info
Pull metadata for an uploaded file as a read-only check.
Run a virus scan on a file
Check an uploaded file for malware before it's used elsewhere.
Confirm before batch-deleting files
Check with the user before deleting multiple files at once, since that removes them from storage permanently.
34 Uploadcare actions, graded by risk.
Every Uploadcare action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
14Look things up. Allowed by default.
- uploadcare.list_filesList Uploadcare Files
- uploadcare.list_groupsList Uploadcare Groups
- uploadcare.get_file_infoGet Uploadcare File Info
- uploadcare.list_webhooksList Uploadcare Webhooks
- uploadcare.get_group_infoGet Uploadcare Group Info
- uploadcare.get_project_infoGet Uploadcare Project Info
- uploadcare.get_file_metadataGet File Metadata
- uploadcare.get_file_metadata_keyGet File Metadata Key Value
- uploadcare.get_url_upload_statusGet URL Upload Status
- uploadcare.get_clamav_scan_statusGet ClamAV Scan Status
- uploadcare.get_uploaded_file_infoGet Uploaded File Info
- uploadcare.get_file_group_info_uploadGet File Group Info (Upload API)
- uploadcare.get_aws_rekognition_execution_statusGet AWS Rekognition Execution Status
- uploadcare.check_aws_rekognition_moderation_statusCheck AWS Rekognition Moderation Status
write
13Create and change things. Allow, or ask the user first.
- uploadcare.create_webhookCreate Uploadcare webhook
- uploadcare.update_webhookUpdate Uploadcare webhook
- uploadcare.create_file_group_uploadCreate File Group (Upload API)
- uploadcare.update_file_metadata_keyUpdate File Metadata Key
- uploadcare.store_fileStore Uploadcare File
- uploadcare.image_mirrorMirror Uploadcare Image
- uploadcare.rotate_imageRotate Image
- uploadcare.copy_file_localCopy Uploadcare File to Local Storage
- uploadcare.upload_from_urlUpload File from URL
- uploadcare.store_batch_filesBatch Store Files
- uploadcare.store_single_fileStore Single Uploadcare File
- uploadcare.execute_clamav_scanExecute ClamAV virus scan
- uploadcare.start_multipart_uploadStart Multipart Upload
destructive
7Delete, cancel or archive. Ask first, or deny outright.
- uploadcare.delete_filesBatch Delete Uploadcare Files
- uploadcare.delete_groupDelete Uploadcare Group
- uploadcare.delete_webhookDelete Uploadcare Webhook
- uploadcare.delete_single_fileDelete Uploadcare File
- uploadcare.delete_webhook_by_urlDelete Uploadcare Webhook by URL
- uploadcare.delete_file_metadata_keyDelete File Metadata Key
- uploadcare.check_remove_bg_statusCheck Remove.bg Status
Uploadcare in three steps.
- 01Your users connect UploadcareThey add their Uploadcare api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create Uploadcare webhook” can wait for the user, and “batch Delete Uploadcare Files” can be denied outright.
- 03Any agent can actYour agent calls Uploadcare through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('uploadcare', { read: 'allow', write: 'ask', // create_webhook destructive: 'deny', // delete_files }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Uploadcare connects.
Users add their Uploadcare api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Uploadcare connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Uploadcare from any agent.
Uploadcare and Arc0, answered.
Can I use Uploadcare with Claude, ChatGPT or Cursor?
Yes. Connect Uploadcare to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Uploadcare actions you allow.
How do users connect Uploadcare?
Users add their Uploadcare api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Uploadcare actions can my agent take?
34 in total: 14 read, 13 write and 7 destructive, such as “create Uploadcare webhook”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Uploadcare?
Yes. Actions like “batch Delete Uploadcare Files” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Uploadcare too?
Yes. The same Uploadcare connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Uploadcare into your agent.
Your users connect Uploadcare once, under your brand. Your agent gets 34 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan