image-relay-mcp
Fetches images from Hugging Face Space outputs, allowing Claude to retrieve image content directly through the MCP connector.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@image-relay-mcpfetch the image from https://my-hf-space.hf.space"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
image-relay-mcp
A tiny MCP server with one job: fetch an image from an allowed host (Hugging Face Space outputs) server-side, and hand it back as inline image content — so Claude gets the bytes directly through the MCP connector, without going through its code-execution sandbox's domain-restricted network.
Tested locally with @modelcontextprotocol/sdk v1.29 and Node 18+.
Why this works
Claude's code-execution sandbox (the one used to build files) only has
outbound access to a small package-manager allowlist. Custom MCP
connectors are a separate path — they run on your own server, so they
have normal internet access. This tool exploits that: it does the
fetching on your infrastructure, then returns the result as an MCP
image content block, which Claude can read directly from the tool
result.
Related MCP server: MCP Fetch
Files
server.js— the whole thing. One tool:fetch_image({ url }).test-client.mjs— local smoke test, talks tolocalhost:3000/mcp.package.json— two dependencies:@modelcontextprotocol/sdk,express.
Security notes (read before deploying)
Host allowlist:
ALLOWED_HOST_SUFFIXESinserver.jsrestricts which domains this will fetch from. It ships set to.hf.spaceandhuggingface.co. Don't widen this to arbitrary URLs — an open fetch-any-URL relay is an SSRF vector.Optional auth: set the
RELAY_AUTH_TOKENenv var on your host to require aAuthorization: Bearer <token>header. Recommended once this is public, since anyone with the URL could otherwise call it.Size cap: hard-capped at 15MB per image (
MAX_BYTES) so nothing huge gets base64-encoded into a response.Stateless by design (
sessionIdGenerator: undefined) — no server-side session state to leak or clean up.
Run locally
npm install
npm start
# listening on :3000, POST /mcp
node test-client.mjs # optional smoke testDeploy (pick one — all have a free tier)
Any plain Node 18+ host works, since this only needs express + fetch.
Render (easiest, free web service):
Push this folder to a GitHub repo.
render.com → New → Web Service → connect the repo.
Build command:
npm install. Start command:npm start.Once live, your MCP endpoint is
https://<your-app>.onrender.com/mcp.
Railway / Fly.io: same idea — Node buildpack, expose $PORT, start
command npm start.
Your own VPS: npm install --production && RELAY_AUTH_TOKEN=xxx npm start
behind a reverse proxy (Caddy/nginx) for TLS.
Connect it to Claude
claude.ai → Settings → Connectors → Add custom connector
URL:
https://<your-deployed-host>/mcpIf you set
RELAY_AUTH_TOKEN, add it as a header/auth value when the connector setup prompts for one.In a chat: "use my image-relay connector to fetch <hf.space url>" — or just paste the url once it's a named tool Claude can see.
Note: custom connectors require a paid Claude plan (Pro or above).
This server cannot be deployed
Maintenance
Related MCP Connectors
Show holiday photos from Vercel Blob inline in Claude chats.
Prompt-injection scanning and safe webpage fetching for AI agents reading untrusted content.
Agent-first image hosting — upload images and get instant CDN URLs.
- GrabbitOAuthlive.grabbit
Screenshot any URL as a hosted image. No local browser; handles bot walls and full-page captures.
Related MCP Servers
- AlicenseBqualityDmaintenanceEnables AI assistants to download images from URLs and perform basic image optimization tasks.26 npm17Apache 2.0
- AlicenseAqualityDmaintenanceModel Context Protocol server that enables Claude Desktop (or any MCP client) to fetch web content and process images appropriately.1281 npmMIT
- AlicenseAqualityDmaintenanceA Model Context Protocol server that enables fetching and processing images from URLs, local file paths, and numpy arrays, returning them as base64-encoded strings with proper MIME types.121MIT
- AlicenseNot gradedqualityDmaintenanceSecurely fetches web content, extracts links and metadata, and downloads files through a sandboxed MCP server without JavaScript execution. Includes prompt-injection detection and comprehensive HTML sanitization for safe web data retrieval.2MIT