From a program

From a program

View as markdown

The connector is a standard MCP server, and nearly every tool has a REST twin under /api/v1 — saving, versions and state, settings, access, share links, the log, comments, the library — for CI and shell agents that can't ride the MCP session. Credentials have none: no credential makes another.

Tools

Tool What it does
save_artifact Save a new site, a new version, or changes on one — live, staged or into the draft.
list_artifacts / get_artifact Find artifacts and material; show one with its versions and picture.
set_artifact_state Make a version live, roll back, take it offline, or bring a deleted one back.
get_access / update_access Who can open it, and changing that — no new version.
get_log What happened to an artifact or a workspace, and its traffic.
update_artifact_settings Rename, retag, put it in the library, open or wipe the room — on up to fifty at once.
upload_file Stage large files over the session — no credential.
create_credential A standing credential (secret revealed here, once), or a single-use upload address for one large site or a batch of library files.
update_workspace The handle, the defaults, and members — invite, remove, change a role.

Large files

Files beyond the inline limits (25 MB/file, 50 MB total) need no credential at all when an agent holds the MCP session: upload_file declares the file (op start), sends base64 chunks (part) and seals it (complete) — then the save references it as { "path": "video.mp4", "upload": "up_…" }. Up to 4 GB per staged file, 5 GB per save.

From a shell

Open an upload address with create_credential — a single-use, minutes-lived URL scoped to one artifact's saves, or with library: true to the workspace's library; POST the save's JSON straight to it — or use a standing token. Tokens carry scopes chosen when minted: publish (the default — save and stage, never read back), read (details, files and drafts, the log, comments), and manage (state, settings, delete, access, share links, comments):

curl -X POST https://23artifacts.com/api/v1/artifacts \
  -H "Authorization: Bearer <your token>" \
  -H "Content-Type: application/json" \
  -d @payload.json

Shell-staged large files go through the resumable upload API (bearer token or the session's ?session= query): POST /api/v1/uploads with the declared size, PUT .../parts/:n for each chunk, POST .../complete — then referenced from the save the same way.

Runtime

Artifacts serve on an isolated origin under a sandbox CSP: external https: scripts, styles, fonts, and fetch work (CDN libraries, Google Fonts); cookies, localStorage, and credentialed requests don't. Single-file HTML is the most robust shape.

Signed in here?

Browser requests — including the API reference's Test Request button — authenticate with your session automatically, no token needed. Tokens are for scripts, CI, and anywhere you aren't signed in.

Reference

Every REST endpoint, schema, and error code: API reference · OpenAPI document: /openapi.json