Skip to main content
Glama

Upload image

upload_image
Destructive

Upload an image into a project by fetching a public http(s) URL server-side. The target is the URL you pass and nothing else: Morpha's Worker fetches it with a plain HTTP GET, following redirects, and identifies itself as "Morpha/1.0 (+https://morphareels.ai; hello@morphareels.ai)". No third-party API is involved. The worker downloads the .png/.jpg/.jpeg/.gif/.webp/.svg, stores it in the project's asset bucket under a new id, and returns { filename, name, sizeBytes, contentType }: pass the returned filename (the file's id, never shown to a person) to add_image_layer, and name is what people see. This tool does not search for images: pass a direct image file URL, such as one the person has given you, and respect the licence its source states. The url must be a direct, publicly-fetchable http(s) link (not an auth-walled page). SVGs are rejected if they carry a , an inline event handler, a , a javascript: URL, or an external resource reference — supply a static, self-contained SVG. Buffered in Worker memory, so capped at 16 MB. For a file on the caller's own disk, use create_upload_link instead. Reference: https://morphareels.ai/docs/tools#uploadimageurl-name

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlYesDirect, publicly-fetchable http(s) URL of the image file (.png/.jpg/.jpeg/.gif/.webp/.svg).
nameNoOptional display name, what people see (e.g. Logo.png). Defaults to the URL's file name. It never decides where the file is stored.
projectIdYesProject to add the image to.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
okYesWhether the call succeeded.
dataNoThe payload, shaped by the tool.
noteNoWhat to do next when not ready.
errorNoWhy it failed.
statusNoFor cache-backed readers: whether the answer was ready.
editorUrlNoOpens this project in the editor.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changed
    • removedInput schema / properties / filename
      Removed value: -{
      -  "description": "Optional stored filename (.png/.jpg/.jpeg/.gif/.webp/.svg). Defaults to the basename of the URL path; sanitised to lowercase a-z0-9._-.",
      -  "type": "string"
      -}
    • addedInput schema / properties / name
      Added value: +{
      +  "description": "Optional display name, what people see (e.g. Logo.png). Defaults to the URL's file name. It never decides where the file is stored.",
      +  "type": "string"
      +}
  2. Changed2 schema fields changed
    • removedInput schema / properties / anonymousToken
      Removed value: -{
      -  "description": "The token create_anonymous_account returned. This connection has no Morpha key, so every call carries it.",
      -  "type": "string"
      -}
    • changedInput schema / required
      Previous value: -[
      -  "projectId",
      -  "url",
      -  "anonymousToken"
      -]New value: +[
      +  "projectId",
      +  "url"
      +]
  3. Changed1 schema field changed
    • changedOutput schema / (root)
      Previous value: -nullNew value: +{
      +  "description": "The result envelope every Morpha tool returns.",
      +  "properties": {
      +    "data": {
      +      "description": "The payload, shaped by the tool.",
      +      "type": [
      +        "object",
      +        "array",
      +        "string",
      +        "number",
      +        "boolean",
      +        "null"
      +      ]
      +    },
      +    "editorUrl": {
      +      "description": "Opens this project in the editor.",
      +      "type": "string"
      +    },
      +    "error": {
      +      "description": "Why it failed.",
      +      "type": "string"
      +    },
      +    "note": {
      +      "description": "What to do next when not ready.",
      +      "type": "string"
      +    },
      +    "ok": {
      +      "description": "Whether the call succeeded.",
      +      "type": "boolean"
      +    },
      +    "status": {
      +      "description": "For cache-backed readers: whether the answer was ready.",
      +      "enum": [
      +        "ready",
      +        "not-ready"
      +      ],
      +      "type": "string"
      +    }
      +  },
      +  "required": [
      +    "ok"
      +  ],
      +  "type": "object"
      +}
  4. Changed2 schema fields changed
    • addedInput schema / properties / anonymousToken
      Added value: +{
      +  "description": "The token create_anonymous_account returned. This connection has no Morpha key, so every call carries it.",
      +  "type": "string"
      +}
    • changedInput schema / required
      Previous value: -[
      -  "projectId",
      -  "url"
      -]New value: +[
      +  "projectId",
      +  "url",
      +  "anonymousToken"
      +]
  5. First observed

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description discloses the server-side fetch mechanism, User-Agent, redirect handling, no third-party API, storage under a new id, SVG sanitization rules, and the 16 MB memory cap. Annotations only provide the generic safety flags, so this rich behavioral detail is the description's own contribution and is not contradicted by any annotation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Longer than necessary, but front-loads the core operation and each sentence carries operational detail (allowed formats, rejection rules, cap, alternative). The only mild redundancy is repeating that the URL must be public, which appears in both schema and prose.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a tool that fetches arbitrary URLs, the description accounts for what can go wrong (auth-walled URLs, SVG threats, size cap), what happens after upload (returned filename for add_image_layer), and the alternative for local files. With an output schema also present, nothing an agent needs to call it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, but description adds substantive meaning beyond each property: url must be direct/public and supports only specific formats; name is display-only, defaults to the URL filename, and never determines storage; projectId is the target project. It also clarifies the returned filename vs name mapping.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description immediately states the verb and resource: 'Upload an image into a project by fetching a public http(s) URL server-side.' It also explicitly contrasts with related tools by adding 'This tool does not search for images' and naming create_upload_link, so an agent can distinguish it from upload_audio and search-like tools without opening schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives explicit when-to-use conditions: pass a direct, publicly-fetchable image URL, and 'For a file on the caller's own disk, use create_upload_link instead.' It also states when not to use it (not for auth-walled pages or search) and notes to respect source licence, which is far beyond a generic list.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources