Skip to main content
Glama

files_get_base64

Read-onlyIdempotent

Download one or more files server-side and return their content as base64-encoded strings. Use this to inspect images, PDFs, or any binary file attached to messages when you cannot access presigned S3 URLs directly. Supports up to 5 files per call, max 15 MB each. For large files batch in groups of 1-2 to avoid oversized responses. For images, pass variants to get processed copies instead of the original: rotate (clockwise) a photo taken sideways or upside down, enhance a faded print, or crop and enlarge a region with small text. Ask for both rotate 90 and 270 in one call when the text runs vertically and you cannot tell which way is up. An MCP client shows at most 5 images per response; the rest are listed, not shown.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
file_idsYesList of file IDs to fetch as base64 (max 5). Get IDs from files.info or message attachment_file_ids.
variantsNoImages only, optional. Each variant is applied to every requested image and returned as its own entry (max 4 variants). Keys: rotate (0, 90, 180, 270; clockwise), enhance (true = grayscale + auto-contrast), crop ([x0, y0, x1, y1], fractions 0..1 of the image after rotation; the region is enlarged). Example: [{"rotate": 90, "enhance": true}, {"rotate": 270, "enhance": true}].
in_workspaceNoRun this one call in this workspace id instead of the session's. Nothing is stored; other sessions are not affected.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • addedInput schema / properties / in_workspace
      Added value: +{
      +  "description": "Run this one call in this workspace id instead of the session's. Nothing is stored; other sessions are not affected.",
      +  "type": "integer"
      +}
  2. Added
  3. Removed
  4. First observed

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safety profile (readOnly, idempotent, non-destructive), and the description adds real behavior beyond them: hard limits (5 files, 15 MB each), batching advice to avoid oversized responses, the MCP client display cap of 5 images with extras listed-but-not-shown, and how variants expand into separate result entries.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core action in the first sentence, then layers limits, batching advice, variant guidance, and the display cap in a logical order. It is dense and runs long, but nearly every sentence carries actionable information rather than filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description compensates well by explaining that results arrive as base64 entries and that image rendering is capped by the client. Combined with file-size limits, batching guidance, and variant semantics, an agent has everything needed to call this correctly and interpret the result.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so a baseline of 3 is warranted, but the description adds genuine meaning: it explains why variants exist (sideways photos, faded prints, small text) and supplies a practical trick ('ask for both rotate 90 and 270... when you cannot tell which way is up') that the schema does not encode.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb, resource and output form: 'Download one or more files server-side and return their content as base64-encoded strings.' It further scopes itself to binary/message attachments when presigned S3 URLs aren't reachable, which separates it from the read-oriented siblings (files_read, files_info) without ambiguity.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear triggering context ('inspect images, PDFs, or any binary file... when you cannot access presigned S3 URLs directly') plus concrete operational guidance (max 5 per call, batch 1-2 for large files) and a usage heuristic for variant requests. It stops short of naming a sibling alternative explicitly, so it is strong but not a 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.