Back to Browse

Artifacta MCP Server

Developer ToolsModerate5.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Artifact store for AI agents. Hosted OAuth at mcp.artifacta.io/mcp; local stdio via npm/PyPI.

About

Artifact store for AI agents. Hosted OAuth at mcp.artifacta.io/mcp; local stdio via npm/PyPI.

Remote endpoints: streamable-http: https://mcp.artifacta.io/mcp

Security Report

5.2
Moderate5.2Moderate Risk

This is a well-engineered MCP server for the Artifacta artifact store with strong security practices. Authentication is required via API keys or OAuth, permissions are appropriately scoped to network HTTP and environment variables, and the code demonstrates careful attention to security details like idempotency, file integrity checking, and proper error handling. Minor code quality observations around exception handling breadth do not materially affect the security posture. Supply chain analysis found 4 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 2 issues.

4 files analyzed · 9 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

What You'll Need

Set these up before or after installing:

Artifacta API key (ak_live_...) from https://app.artifacta.io/dashboard/keysRequired

Environment variable: ARTIFACTA_API_KEY

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Artifacta MCP Server

npm PyPI License: MIT

Official MCP server for Artifacta — an artifact store purpose-built for AI agents. Agents persist run outputs (files, reports, datasets, build results) with session and agent metadata, hand them off across sessions, and share them via expiring download links. Content-hash dedup means re-storing the same bytes is free.

Listed in the official MCP registry as io.artifacta/mcp.

Two implementations with the same tool surface, error contract, and path-confinement engine:

DirectoryPackageRuntime
typescript/@artifacta-mcp/mcpNode 20+
python/artifacta-mcpPython 3.10+

Install as a Claude Code plugin

For Claude Code, the fastest path is the plugin marketplace this repo doubles as — it wires up the hosted server and a skill that persists run outputs automatically:

/plugin marketplace add SagaPeak/artifacta-mcp
/plugin install artifacta@artifacta

This bundles the same hosted MCP connection as the Quick start below plus the persisting-outputs skill (/artifacta:persisting-outputs, or it auto-triggers when a session has outputs worth saving). Update the plugin with /plugin marketplace update artifacta. See the plugin setup guide.

Quick start

The fastest way to connect is the hosted server — no install, no API key:

claude mcp add --transport http artifacta https://mcp.artifacta.io/mcp

On first use your client self-registers via OAuth Dynamic Client Registration (PKCE) and opens a browser to authorize — no ak_live_ key to copy or store. See the hosted setup guide.

Local / CI (stdio)

For headless, air-gapped, or CI environments where a browser OAuth flow isn't available, run the package locally over stdio with an API key. Get a key at app.artifacta.io/dashboard/keys, then add to your MCP client config (Claude Desktop, Claude Code, Cursor, or any MCP client):

{
  "mcpServers": {
    "artifacta": {
      "command": "npx",
      "args": ["-y", "@artifacta-mcp/mcp"],
      "env": {
        "ARTIFACTA_API_KEY": "ak_live_..."
      }
    }
  }
}

Or run the Python implementation with pipx run artifacta-mcp.

See the per-package READMEs for config-file profiles, path confinement (--allow-path), destructive-tool gating (--allow-destructive), and troubleshooting: TypeScript · Python.

Tools

ToolDescription
whoamiVerify credentials; returns tenant and plan info
store_artifactUpload an artifact from inline content or a local path
request_upload_url / complete_uploadTwo-phase presigned upload for large files
get_artifactFetch artifact metadata by ID
get_artifact_download_urlGet a presigned download URL (1h expiry)
list_artifactsList/filter artifacts by session, agent, or metadata
list_sessionsList active sessions
seal_sessionSeal a session so no further artifacts can be added (gated behind --allow-destructive)
create_download_linkCreate a public expiring share link (gated behind --allow-destructive)
delete_artifactSoft-delete an artifact (gated behind --allow-destructive, same gate as create_download_link)
publish_artifactPublish an artifact as a public page at artifacta.io/a/{slug} (Artifact Pages); idempotent, unlisted by default
unpublish_artifactTake down an artifact's public page; the artifact itself is untouched; idempotent

Plus MCP resources for whoami, artifact metadata, artifact bytes, and sessions.

Safety defaults: local-file uploads are confined to an explicit --allow-path allow-list, and destructive tools (public share links, deletes, session seals) are hidden from clients that can't confirm writes unless --allow-destructive is passed. publish_artifact and unpublish_artifact are idempotent write operations, not destructive ones — they are not gated behind --allow-destructive.

Hosted OAuth connections (mcp.artifacta.io) add a second layer: the consent screen grants one of three scopes — artifacts:readartifacts:writeartifacts:destroy. All 13 tools are always advertised in tools/list; calling a tool the token wasn't granted for returns a tool error with code insufficient_scope naming the missing scope, and the fix is to re-authorize with the broader scope. Scope gating applies only to hosted OAuth — ak_live_ API keys and local stdio remain full-access, using --allow-destructive / confirmation flags instead.

Framework integrations

The Python package ships optional adapters for OpenAI Agents SDK (pip install 'artifacta-mcp[openai-agents]') and LangChain/LangGraph (pip install 'artifacta-mcp[langchain]').

Documentation

Full docs at docs.artifacta.io/mcp/overview.

Development

# TypeScript
cd typescript && npm install && npm test

# Python
cd python && python -m venv .venv && source .venv/bin/activate
pip install -e '.[dev]' && pytest

This repository is published from the Artifacta monorepo; issues and PRs are welcome here.

License

MIT — see LICENSE.

Reviews

No reviews yet

Be the first to review this server!