From a program
View as markdownThe connector is a standard MCP server, and nearly every tool has a REST twin under /api/v1 — saving, versions and state, settings, access, share links, the log, comments, the library — for CI and shell agents that can't ride the MCP session. Credentials have none: no credential makes another.
Tools
| Tool | What it does |
|---|---|
save_artifact |
Save a new site, a new version, or changes on one — live, staged or into the draft. |
list_artifacts / get_artifact |
Find artifacts and material; show one with its versions and picture. |
set_artifact_state |
Make a version live, roll back, take it offline, or bring a deleted one back. |
get_access / update_access |
Who can open it, and changing that — no new version. |
get_log |
What happened to an artifact or a workspace, and its traffic. |
update_artifact_settings |
Rename, retag, put it in the library, open or wipe the room — on up to fifty at once. |
upload_file |
Stage large files over the session — no credential. |
create_credential |
A standing credential (secret revealed here, once), or a single-use upload address for one large site or a batch of library files. |
update_workspace |
The handle, the defaults, and members — invite, remove, change a role. |
Large files
Files beyond the inline limits (25 MB/file, 50 MB total) need no credential at all when an agent holds the MCP session: upload_file declares the file (op start), sends base64 chunks (part) and seals it (complete) — then the save references it as { "path": "video.mp4", "upload": "up_…" }. Up to 4 GB per staged file, 5 GB per save.
From a shell
Open an upload address with create_credential — a single-use, minutes-lived URL scoped to one artifact's saves, or with library: true to the workspace's library; POST the save's JSON straight to it — or use a standing token. Tokens carry scopes chosen when minted: publish (the default — save and stage, never read back), read (details, files and drafts, the log, comments), and manage (state, settings, delete, access, share links, comments):
curl -X POST https://23artifacts.com/api/v1/artifacts \
-H "Authorization: Bearer <your token>" \
-H "Content-Type: application/json" \
-d @payload.json
Shell-staged large files go through the resumable upload API (bearer token or the session's ?session= query): POST /api/v1/uploads with the declared size, PUT .../parts/:n for each chunk, POST .../complete — then referenced from the save the same way.
Runtime
Artifacts serve on an isolated origin under a sandbox CSP: external https: scripts, styles, fonts, and fetch work (CDN libraries, Google Fonts); cookies, localStorage, and credentialed requests don't. Single-file HTML is the most robust shape.
Signed in here?
Browser requests — including the API reference's Test Request button — authenticate with your session automatically, no token needed. Tokens are for scripts, CI, and anywhere you aren't signed in.
Reference
Every REST endpoint, schema, and error code: API reference · OpenAPI document: /openapi.json