Cloudinary MCP

Live

OAUTH 2.0

MEDIA

Media

Connects AI agents to Cloudinary's asset management platform, enabling upload, search, transformation, and organization of media assets through natural...

  • Acts as the user: Every tool call runs as the authorizing user. Access and audit trail stay intact.
  • Credentials stay vaulted: AES-256 encrypted, resolved at request time, never stored in LLM context.
  • Scoped before every call: Per-user permissions enforced automatically. 90-day audit trail included.
Cloudinary MCP
agent · Acme Q3
Run
Asset Rename in Cloudinary MCP
cloudinarymcp_asset_rename
85ms
Message Claude...

Cloudinary MCP tools for AI agents

CALL ANY TOOL
12 tools covering asset, create.
cloudinarymcp_list_tags
List tags
Retrieves a list of tags currently applied to assets in your Cloudinary account Retrieves a comprehensive list of all tags that exist in your product environment for assets of the specified type. [Cloudinary Admin API documentation](https://cloudinary.com/documentation/admin_api)
Parameters
Name
Type
Required
Description
resource_type
string
Required
The type of resource (image, video, or raw).
max_results
integer
Optional
Maximum number of results to return (1-500).
next_cursor
string
Optional
Cursor for pagination.
prefix
string
Optional
Limit the returned tags to those that start with the specified prefix.
cloudinarymcp_search_assets
Search assets
cloudinarymcp_list_files
List files
cloudinarymcp_search_folders
Search folders
cloudinarymcp_list_images
List images
cloudinarymcp_get_tx_reference
Get tx reference
cloudinarymcp_list_videos
List videos
cloudinarymcp_get_asset_details
Get asset details
cloudinarymcp_create_folder
Create folder
cloudinarymcp_get_usage_details
Get usage details
cloudinarymcp_create_asset_relations
Create asset relations
cloudinarymcp_get_generation_task
Get generation task
cloudinarymcp_move_folder
Move folder
cloudinarymcp_sign_upload
Sign upload
cloudinarymcp_asset_rename
Asset rename
cloudinarymcp_asset_update
Asset update
cloudinarymcp_upload_asset
Upload asset
cloudinarymcp_generate_image
Generate image
cloudinarymcp_transform_asset
Transform asset
cloudinarymcp_generate_archive
Generate archive
cloudinarymcp_manage_asset_tags
Manage asset tags
cloudinarymcp_visual_search_assets
Visual search assets
cloudinarymcp_manage_asset_context
Manage asset context
cloudinarymcp_download_asset_backup
Download asset backup
cloudinarymcp_manage_asset_metadata
Manage asset metadata
cloudinarymcp_generate_image_from_images
Generate image from images
cloudinarymcp_delete_asset
Delete asset
cloudinarymcp_delete_folder
Delete folder
cloudinarymcp_delete_derived_assets
Delete derived assets
cloudinarymcp_delete_asset_relations
Delete asset relations
Build your Agent
Same auth pattern across every framework.
Python · LlamaIndex
from langchain_mcp_adapters.client import MultiServerMCPClient
from scalekit import ScalekitClient

client = ScalekitClient(env_url=ENV_URL, client_id=CLIENT_ID, client_secret=SECRET)
token = client.agent.get_token(user_id="user_id", connector="cloudinarymcp")

mcp = MultiServerMCPClient({
    "cloudinarymcp": {
        "url": "https://mcp.scalekit.com/cloudinarymcp",
        "headers": {"Authorization": "Bearer " + token}
    }
})
tools = await mcp.get_tools()
import OpenAI from "openai";
const token = await client.agent.getToken({ userId: "user_id", connector: "cloudinarymcp" });
// Connect to MCP at https://mcp.scalekit.com/cloudinarymcp
import Anthropic from "@anthropic-ai/sdk";
const token = await client.agent.getToken({ userId: "user_id", connector: "cloudinarymcp" });
// Connect to MCP at https://mcp.scalekit.com/cloudinarymcp
from google.adk.agents import LlmAgent
token = client.agent.get_token(user_id="user_id", connector="cloudinarymcp")
# Connect to MCP at https://mcp.scalekit.com/cloudinarymcp
Try these prompts
Paste any prompt into your agent to get started.
Finds images in your asset library based on visual similarity or content?
SEE HOW AUTH WORKS
User authorises once. Every agent call after uses their token with scope enforcement.
1
Authorize
Your user connects
Cloudinary MCP
once. We tie it to their identity and the meetings they approved — no shared bot account, no org-wide access
Who:
user ‘A’
when:
Once per user
access:
Limited to user
2
Store
Their
Cloudinary MCP
token lives in a vault scoped to them. User A's meetings are never reachable by an agent acting for user B, even on the same connection
vault:
encrypted
scope:
per-user
tokens:
auto-refreshed
3
Resolve
When your agent calls a
Cloudinary MCP
tool, we fetch the right token server-side. It never touches your agent, never appears in the LLM context, never shows up in your logs
speed:
~40ms
check:
before every call
seen by:
nobody
4
Audit
Every
Cloudinary MCP
tool call is logged — who triggered it, which meeting was fetched, what came back. 90 days of history, tied to the user who authorized it
history:
90 days
export:
SIEM-ready
logged:
every call
Test other agents
See the same per-user auth pattern across other connectors.
GTM and RevOps Teams
Competitive intelligence briefing agent
Scans Gong calls for competitor mentions, matches each one to its Notion battlecard, and DMs every affected rep a single Slack digest per cycle. Every call runs as the PMM who owns the briefing, never a shared bot.
GTM and RevOps Teams
Outbound prospecting agent
Searches Apollo for prospects matching your ICP, scores and ranks them, drafts personalized outreach in Gmail, and logs every send to Google Sheets. Mail goes out as the rep, not from a shared inbox.
GTM and RevOps Teams
CRM AI agent
Reads the Granola transcript after every call, extracts next steps and updates the HubSpot record, drafts the follow-up in Gmail, and confirms in Slack, all on the rep's own delegated OAuth.
Support and Ops Teams
Meeting prep
Pulls agenda, participant context, and open action items before every meeting.
Test other agents
See the same per-user auth pattern across other connectors.
SALES
Outbound prospecting agent
Search Apollo for ICP matches, rank them, draft personalised Gmail outreach, and log every send to Google Sheets.
GTM
Competitive intelligence briefing agent
Scan Gong calls for competitor mentions, match each one to its Notion battlecard, and DM every affected rep a single Slack digest.
GTM
CRM AI agent
Turn each Granola call transcript into a HubSpot record update, a drafted Gmail follow-up, and a Slack recap.
OPS
Meeting prep agent
Assemble the agenda, HubSpot attendee history, and open action items from Gmail before every meeting on the calendar.
Why Scalekit
Secure your agent's access. Connectors ship in minutes
01.
Shared tokens break per-user analytics
A shared token looks fine in a demo. In production every call looks like a service account. Scalekit resolves the real user credential.
“Our agents act across Salesforce, Gong, Google Drive, and more, on behalf of every customer. Scalekit behind the scenes meant we can keep adding tools without ever rebuilding how credentials or tool calling work.”
Venu Madhav Kattagoni
Head of Engineering / Von
FAQs
Frequently Asked Questions

Does the agent access Cloudinary as the user or as a shared key?
As the user. Each workspace member authorizes once and Scalekit resolves their credential at request time. Audit logs attribute every action to that user, not a shared service account.

Where is the Cloudinary OAuth token stored?
In Scalekit's managed AES-256 token vault, namespaced per tenant. Refresh is automatic. Revocation is a single dashboard action. Tokens never appear in prompts, logs, or LLM context.

Can I limit what the agent is allowed to do in Cloudinary?
Yes. Pass a tool name filter to listScopedTools so the media agent only sees the subset you authorize. Pre-API-call scope checks block out-of-policy actions before the request reaches Cloudinary.

What happens when a user revokes Cloudinary access?
The connection is invalidated on the next tool call. Subsequent requests for that user fail closed with a clear error. Other users in the tenant remain unaffected. The event is logged for audit.

Which media assets can the agent transform or delete?
Only assets the authorizing user can manage in Cloudinary. Uploads, renames, and deletions follow the user's product environment permissions, and destructive tools can be filtered out entirely.

Start in your coding agent
Up and running in one command
Install the Scalekit skill in your editor of choice. Connector, auth, tools, prompt, all wired up
Claude Code REPL
/plugin marketplace add scalekit-inc/claude-code-authstack
/plugin install agentkit@scalekit-auth-stack
Cursor Code REPL
# ~/.cursor/mcp.json
{
""mcpServers"": {
""cloudinarymcp"": {
""url"": ""https://mcp.scalekit.com/cloudinarymcp"",
""headers"": { ""Authorization"": ""Bearer $SCALEKIT_TOKEN"" }
}
}
}
Codex Code REPL
# ~/.codex/config.toml
[mcp_servers.cloudinarymcp]
url = ""https://mcp.scalekit.com/cloudinarymcp""
auth_env = ""SCALEKIT_TOKEN""
Copilot Code REPL
# .vscode/mcp.json
{
""servers"": {
""cloudinarymcp"": {
""url"": ""https://mcp.scalekit.com/cloudinarymcp"",
""type"": ""http""
}
}
}