Connect VehiclePhoto to Claude, Cursor and any MCP client
Ask an agent to send a vehicle photo, start one processing step and return a signed result without leaving your client. The live Streamable HTTP endpoint uses the same scoped bearer keys and account boundaries as REST v1.
https://vehiclephoto.com/api/mcpLive tool registry
What an agent can do
Start with the result you need, then let the client choose from the five live operations below. The surface is intentionally ID-based: an agent can verify its connection, ingest one public photo, process that known photo, and retrieve a known photo or job without gaining an inventory-wide browse command.
Every row comes from the server registry used by the endpoint. Names, descriptions and required scopes are rendered from MCP_TOOLS, so this page does not maintain a second handwritten tool list.
| Name | Description | Required scope |
|---|---|---|
| whoami | Verify the API key and return its rooftop, group, scopes, and key id. | No additional scope |
| get_asset | Retrieve one paginated, tenant-scoped asset with signed image URLs. | read |
| get_job | Poll one tenant-scoped processing job and retrieve its signed result URL. | read |
| ingest_image_url | Import one public image URL and attach it by optional VIN or stock number. | ingest |
| process_image | Run the first and only supplied recipe step on a previously imported image. | process |
Authentication
Use one scoped key
Sign in, then mint a key in API keys. Copy the secret when it appears because it is shown once.
Choose ingest when the agent should send a public image URL, process when it should start a recipe step, and read when it should retrieve known photos or jobs. whoami needs no additional scope after the key itself has authenticated.
Pass the one-time secret as Authorization: Bearer <KEY> on the Streamable HTTP request. Authentication uses an API key today; this endpoint does not advertise OAuth. A missing, invalid or revoked key returns HTTP 401 with WWW-Authenticate: Bearer.
The key resolves to one account boundary before the protocol handler reads the request. Tool-specific scope checks happen again at dispatch, so a valid read-only key cannot ingest or process a photo.
Keep the secret in the MCP client configuration or its secret mechanism, never in a shared file. If a key is exposed, mint a replacement in the app, update each client, and revoke the old key.
Setup
Connect your client
- Step 1
Create a scoped key
Sign in, open API keys, create a named key with read, ingest and process only when those operations are needed, and copy the secret shown once.
- Step 2
Add the endpoint
Configure https://vehiclephoto.com/api/mcp as a remote Streamable HTTP server and send the key in the Authorization header.
- Step 3
Verify the boundary
Ask the client to call whoami first. Check the returned account boundary, key ID and scopes before asking it to work with a photo.
- Step 4
Try one workflow
Begin with a public image URL, keep the returned image ID, request one processing step, then poll the returned job ID until a signed result is available.
Claude Code
claude mcp add --transport http vehiclephoto https://vehiclephoto.com/api/mcp --header "Authorization: Bearer <KEY>"Claude Desktop
{
"mcpServers": {
"vehiclephoto": {
"type": "http",
"url": "https://vehiclephoto.com/api/mcp",
"headers": {
"Authorization": "Bearer <KEY>"
}
}
}
}Cursor
{
"mcpServers": {
"vehiclephoto": {
"url": "https://vehiclephoto.com/api/mcp",
"headers": {
"Authorization": "Bearer <KEY>"
}
}
}
}Examples
Try these prompts
- “Verify this VehiclePhoto connection and tell me which scopes it has before taking any action.”
- “Ingest this public vehicle-photo URL, attach the VIN I provide, and return the new image ID.”
- “Run the background_replace capability on this image ID with one recipe step, then give me the job ID.”
- “Check this job ID. If it has finished, return the signed result URL and summarize the status without changing anything else.”
- “Retrieve this photo ID with a small page size and explain which returned URL is temporary.”
Boundaries
Know the limits
The MCP endpoint shares the REST limiter: 60 authenticated requests per 60-second window for each key. One token is spent before MCP dispatch. When the bucket is empty, the server returns HTTP 429 and Retry-After.
The server is stateless Streamable HTTP. It does not open a long-lived GET stream, accept subscription streams, or keep protocol sessions between requests; each POST carries the context needed for that exchange.
The registry exposes five operations and one OpenAPI resource. It does not expose inventory-wide list tools. get_asset and get_job require supplied IDs, while process_image accepts one supplied recipe step for one previously imported image.
ingest_image_url accepts a public URL and retains the same server-side URL safety checks as REST v1. Private, loopback, link-local and multicast destinations are refused before an image is fetched.
Processing still follows the account credit and trial rules. A tool error is returned as structured MCP error content; transport authentication and rate-limit failures remain HTTP 401 or 429 responses.
Sources
- https://vehiclephoto.com/api/mcp — VehiclePhoto Streamable HTTP MCP endpoint; authenticated POST requests expose the registry documented above.
- https://vehiclephoto.com/api/v1/openapi.json — The REST v1 OpenAPI document also served by the MCP openapi resource.
FAQ
Questions answered
Is this a live MCP server?
Yes. https://vehiclephoto.com/api/mcp accepts authenticated Streamable HTTP POST requests and registers the same five tools shown on this page.
Which scopes should I choose?
Use read for get_asset and get_job, ingest for ingest_image_url, and process for process_image. whoami has no extra tool scope, but every call still requires a valid bearer key.
Does the server support OAuth?
Authentication uses a scoped API key today. Put the secret in the Authorization bearer header and rotate it from the API keys screen if it is ever exposed.
Can an agent list inventory?
No. The MCP surface mirrors the live ID-based REST operations and does not publish list tools. Supply a known photo or job ID when you want to retrieve a result.
Where is the API schema?
Read the openapi MCP resource or fetch https://vehiclephoto.com/api/v1/openapi.json. Both expose the same REST v1 OpenAPI document.
Keep exploring