Agent-first image hosting — upload images and get instant CDN URLs.
Déduit des transports déclarés par cette annonce (streamable-http). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.
La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.
Lu depuis un véritable échange MCP initialize → tools/list contre l’endpoint déclaré. Aucun outil n’a été invoqué — tools/list est l’appel d’introspection en lecture seule que le protocole prévoit pour cela. Cela reflète ce que le serveur annonçait à cet instant ; un endpoint hébergé n’est figé sur aucune version et peut changer sans préavis.
https://mcp.pixelvault.dev/mcp8 outils · 259 mshttps://mcp.pixelvault.dev/mcp/oauthauthentification requiseget_imageGet metadata (CDN URL, size, MIME type, dimensions) for one PixelVault image by id. Maps to GET /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop…Get metadata (CDN URL, size, MIME type, dimensions) for one PixelVault image by id. Maps to GET /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop…
| Paramètre | Type | Description |
|---|---|---|
| id* | string | Image id to fetch, e.g. img_abc123 |
list_imagesList images in your PixelVault project, most recent first. Maps to GET /v1/images with pagination. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop), ?fmt=webp…List images in your PixelVault project, most recent first. Maps to GET /v1/images with pagination. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop), ?fmt=webp…
| Paramètre | Type | Description |
|---|---|---|
| page | integer | Page number (default 1) |
| per_page | integer | Items per page (default 20, max 100) |
delete_imageprivilégiéPermanently delete one PixelVault image by id. Maps to DELETE /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header.Permanently delete one PixelVault image by id. Maps to DELETE /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header.
| Paramètre | Type | Description |
|---|---|---|
| id* | string | Image id to delete, e.g. img_abc123 |
upload_imageprivilégiéUpload an image to PixelVault and get an instant CDN URL. Maps to POST /v1/images. Provide exactly one of `source_url` (a public http(s) URL the server fetches) or `data` (base64-encoded bytes); optional `folder`, `filename`, and `expires_in` (seconds, for an auto-expiring image). Max 5 MB; JPG/PNG…Upload an image to PixelVault and get an instant CDN URL. Maps to POST /v1/images. Provide exactly one of `source_url` (a public http(s) URL the server fetches) or `data` (base64-encoded bytes); optional `folder`, `filename`, and `expires_in` (seconds, for an auto-expiring image). Max 5 MB; JPG/PNG…
| Paramètre | Type | Description |
|---|---|---|
| source_url | string | Public http(s) URL of an image to fetch and upload. Provide this OR data. |
| data | string | Base64-encoded image bytes (data URLs accepted). Provide this OR source_url. |
| folder | string | Optional folder/path prefix for the image. |
| filename | string | Optional original filename, e.g. photo.png. |
| expires_in | integer | Optional time-to-live in seconds. The image is auto-deleted after this many seconds (must be 60–2,592,000, i.e. 1 minute to 30 days). Omit for a permanent imag… |
upload_batchprivilégiéUpload many images (1–50) in one call, grouped into a collection — e.g. a CI run or a set of generated variants. Maps to POST /v1/images/batch. Each item is `data` (base64) or `source_url` (server-fetched, SSRF-guarded), with optional `filename`/`metadata`. Set `visibility: "private"` to get a sign…Upload many images (1–50) in one call, grouped into a collection — e.g. a CI run or a set of generated variants. Maps to POST /v1/images/batch. Each item is `data` (base64) or `source_url` (server-fetched, SSRF-guarded), with optional `filename`/`metadata`. Set `visibility: "private"` to get a sign…
| Paramètre | Type | Description |
|---|---|---|
| images* | array | 1–50 images to upload into the collection. |
| type | string | Collection type/discriminator (e.g. ci_build, generation). Default 'batch'. |
| name | string | Idempotency key — re-running with the same (type, name) upserts the same collection. |
| visibility | string | 'private' returns a signed URL per image (free plan: up to 100 private images); 'public' returns a plain CDN URL. Default 'public'. |
| expires_in | integer | Image deletion TTL in seconds (60–2,592,000). Omit for permanent. |
| sign_expires_in | integer | Signature lifetime for private URLs in seconds (60–2,592,000, default 7 days). |
| metadata | object | Freeform collection metadata, e.g. { commit, pr_number, branch }. |
sign_urlMint a time-limited signed URL for a private image. Maps to POST /v1/images/:id/sign-url. Provide `id` and optional `expires_in` (seconds, default 3600). The signature binds the image, so the URL can't be replayed against another image; strip it and the CDN returns 403. Deleting the image revokes i…Mint a time-limited signed URL for a private image. Maps to POST /v1/images/:id/sign-url. Provide `id` and optional `expires_in` (seconds, default 3600). The signature binds the image, so the URL can't be replayed against another image; strip it and the CDN returns 403. Deleting the image revokes i…
| Paramètre | Type | Description |
|---|---|---|
| id* | string | Image id to mint a signed URL for, e.g. img_abc123. |
| expires_in | integer | Signature lifetime in seconds (60–2,592,000). Default 3600 (1 hour). |
transform_imageBuild an on-the-fly transform URL for a PixelVault image (resize, crop, format/quality, AI background removal, blur/sharpen/rotate/flip, brightness/contrast/saturation, and same-project watermark tiling). Provide exactly one of `url` (a PixelVault CDN URL) or `id` (an image id, resolved via the API…Build an on-the-fly transform URL for a PixelVault image (resize, crop, format/quality, AI background removal, blur/sharpen/rotate/flip, brightness/contrast/saturation, and same-project watermark tiling). Provide exactly one of `url` (a PixelVault CDN URL) or `id` (an image id, resolved via the API…
| Paramètre | Type | Description |
|---|---|---|
| url | string | Absolute CDN URL of a PixelVault image, as returned by upload_image / get_image / list_images. Provide this OR id. |
| id | string | PixelVault image id (e.g. img_abc123); its CDN URL is resolved via the API. Provide this OR url. Requires an API key when used. |
| size | string | Named size preset: s=256px, m=640px, l=1280px, social=1200x630 OG card. Wins over width/height. |
| width | integer | Target width in px (1..4000). Snapped UP to the nearest allowed step. scale-down never upscales. |
| height | integer | Target height in px (1..4000). Snapped UP to the nearest allowed step. |
| fit | string | Resize mode. scale-down (default) never enlarges; contain/cover/crop/pad resize to the exact box and may upscale. Only meaningful alongside width/height. |
| format | string | Output format. auto negotiates WebP/AVIF from the client's Accept header. |
| quality | string | Output quality. auto lets Cloudflare choose. |
| segment | string | AI background removal (BiRefNet): foreground keeps the subject and makes the background transparent. Output is forced to PNG unless an opaque background is set… |
| background | string | Fill color behind a removed (segment) or padded (fit=pad) background: hex (#ffaa00), rgb()/rgba(), or a common CSS color name. No effect otherwise. |
| gravity | string | Crop anchor, only with fit=cover|crop: face, left, right, top, bottom, auto, or 'XxY' coords 0.0-1.0. face enables zoom. |
| zoom | number | Face-crop tightness 0.0-1.0, only with gravity=face. |
| blur | number | Gaussian blur (0-250); snapped to the nearest of 10/30/60/120. <=0 is ignored. |
| sharpen | number | Sharpen strength (0-10); snapped to the nearest of 1/3/5. |
| rotate | number | Rotate clockwise; rounded to the nearest right angle (90/180/270). |
| flip | string | Mirror horizontally (h), vertically (v), or both (hv). |
| brightness | number | Brightness multiplier 0-2 (1=no change); snapped to 0.5/0.75/1.25/1.5/2. |
| contrast | number | Contrast multiplier 0-2 (1=no change); snapped to 0.5/0.75/1.25/1.5/2. |
| saturation | number | Saturation multiplier 0-2 (1=no change, 0=grayscale); snapped to 0/0.5/1.5/2. |
| tile | string | Filename (optionally folder-prefixed, with extension) of another image in the SAME project to tile edge-to-edge as a watermark, e.g. watermark.png. |
rescue_imgurrisque d’injectionScan a web page for hotlinked Imgur images and return a PixelVault rescue URL for each — a proxy that lazily rehosts the image on first request, keeping it working through the UK Imgur block. The anonymous rescue tier is a durable ~30-day edge cache (see `cache_ttl_days` in the result), not permane…Scan a web page for hotlinked Imgur images and return a PixelVault rescue URL for each — a proxy that lazily rehosts the image on first request, keeping it working through the UK Imgur block. The anonymous rescue tier is a durable ~30-day edge cache (see `cache_ttl_days` in the result), not permane…
ot permanent storage. Maps to POST /v1/imgur-scan (server-side page fetch; no API key required). Provide `page_url`…| Paramètre | Type | Description |
|---|---|---|
| page_url* | string | Public https:// URL of a page to scan for hotlinked Imgur images. |
8 outils sur 8 ont publié une description.
Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.
Agent-first image hosting — upload images and get instant CDN URLs.
Les noms cliquables ouvrent l’index Forge de toutes les entrées observées exposant cet outil. Parcourir tous les outils indexés.
Cette entrée ne publie aucun paquet npm : Forge n'a donc pas d'arbre de dépendances pour elle. C'est une lacune de couverture — pas une affirmation qu'elle n'a aucune dépendance.