@kentcdodds/agent-files
Mint short-lived R2 PUT URLs for agent file handoffs; public download via managed r2.dev.
- Utilities
- r2
- files
- agents
- handoff
- upload
- Version
- 0.0.0
- License
- Published
- September 22, 2026
- Pinned commit
ba0f573- Rating
- No ratings yet
- Forks
- 0
- Adaptation effort
- —
README
Agent docs@kentcdodds/agent-files
Intent
Give Cursor (and other) agents a tiny, durable way to exchange files without
shoving multi‑MB payloads through MCP base64 chunking or Dropbox. Mint a
short‑lived R2 PUT URL with a small MCP call, PUT the bytes with curl/fetch,
then share the public managed *.r2.dev download URL. Objects live in the
agent-files bucket on Kent’s Cloudflare account and are meant to expire after
about a week.
Prerequisites
- User secret
cloudflareApiToken(same token used by home-maintenance / stash) with permission to manage R2 on Cloudflare accounta41d50ecaf0ae0f86dd1824ef6729cb2. - Token must be able to call
https://api.cloudflare.com(R2 bucket create, managed public domain, temp-access-credentials).
Create or rotate the token in the Cloudflare dashboard: API Tokens. Prefer a custom token with Account → Cloudflare R2 → Edit (and Tokens → Read for parent key id resolution).
Setup
- Ensure
cloudflareApiTokenexists as a user secret in Kody (name only — never paste the value into chat or commits). - First successful
create-upload/uploadauto-ensures:- R2 bucket
agent-fileson accounta41d50ecaf0ae0f86dd1824ef6729cb2 - Managed public
*.r2.devdomain - Object lifecycle delete after ~7 days (best-effort; see below if it fails)
- R2 bucket
- No package-local secrets beyond the mounted user token.
Manual lifecycle (if auto-apply fails)
Dashboard → R2 → bucket agent-files → Settings → Object lifecycle → add a
rule that deletes objects after 7 days (empty prefix = whole bucket).
How it works
- Call
./create-uploadwith{ filename, confirm: true }(optionalcontentType,prefix,expiresInSeconds). - PUT file bytes to
upload.urlwith the returnedupload.headers(Content-Typemust match). - Hand
downloadUrlto whoever needs the file (Cursor cloud agent, human, …). - Optionally
./get/./deletebykey.
Prefer ./create-upload over ./upload. The latter accepts small
bytesBase64 payloads only and rejects oversized MCP bodies.
Done when
create-uploadwithconfirm: truereturnsupload.url+downloadUrl- A real PUT to
upload.urlsucceeds - GET
downloadUrlreturns 200 with the bytes ./get({ key })reportsfound: true./delete({ key, confirm: true })removes the object
Bucket / public URL base are created on first use; check the first
create-upload result’s downloadUrl host (e.g. https://pub-….r2.dev/…).
Report this listing
Log in to report this listing.