Documentation
Storage providers
mcpdrives speaks the S3 API with Signature Version 4, so it works with any service that offers an S3-compatible endpoint. Sixteen presets fill in the endpoint for you.
Providers
We run our storage test suite, which covers keys with special characters, ranged reads, conditional writes, server-side copy, multi-object delete, paging, multipart uploads and signed links, against Cloudflare R2 and MinIO. The other presets build the endpoint from each provider's documentation and have not been through the suite yet.
| Provider | Endpoint | Create-only writes | Our test suite |
|---|---|---|---|
| Cloudflare R2 | https://<account-id>.r2.cloudflarestorage.com | Enforced by the provider | Passed |
| Amazon S3 | https://s3.<region>.amazonaws.com | Enforced by the provider | Not run |
| MinIO | <your endpoint URL> | Enforced by the provider | Passed |
| Backblaze B2 | https://s3.<region>.backblazeb2.com | Checked first | Not run |
| Wasabi | https://s3.<region>.wasabisys.com | Checked first | Not run |
| Google Cloud Storage (HMAC) | https://storage.googleapis.com | Checked first | Not run |
| DigitalOcean Spaces | https://<region>.digitaloceanspaces.com | Checked first | Not run |
| Tigris | https://t3.storage.dev | Checked first | Not run |
| Hetzner Object Storage | https://<region>.your-objectstorage.com | Checked first | Not run |
| Scaleway Object Storage | https://s3.<region>.scw.cloud | Checked first | Not run |
| Akamai (Linode) Object Storage | https://<region>.linodeobjects.com | Checked first | Not run |
| Vultr Object Storage | https://<region>.vultrobjects.com | Checked first | Not run |
| Supabase Storage | https://<project-ref>.supabase.co/storage/v1/s3 | Checked first | Not run |
| Storj | https://gateway.storjshare.io | Checked first | Not run |
| Oracle Cloud Object Storage | https://<namespace>.compat.objectstorage.<region>.oraclecloud.com | Checked first | Not run |
| Other S3-compatible service | <your endpoint URL> | Checked first | Not run |
Choose Custom for any other service and enter its endpoint URL.
Connections
A connection stores one access key for one provider account. When you add it, mcpdrives lists a bucket with the key before saving, so a wrong secret, region or bucket name fails at once with the provider's error. You can mount any bucket the key can reach, in as many drives as you like. An account can hold up to 25 connections.
The secret is encrypted with AES-256-GCM under its own data key, which is in turn encrypted with a key derived from the service's master secret. The ciphertext is bound to your account and to that connection, and it is decrypted only inside your account's storage object for the request that needs it. The dashboard shows the last four characters of the key ID and never the secret.
Narrow keys
Give mcpdrives a key that can reach only what you plan to mount. mcpdrives enforces each mount's access, and a narrow key also limits what the key itself could do.
Amazon S3
An IAM policy that allows a key to work only under agents/ in one bucket:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:ListBucket"
],
"Resource": "arn:aws:s3:::my-bucket",
"Condition": {
"StringLike": {
"s3:prefix": [
"agents/*"
]
}
}
},
{
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:PutObject",
"s3:DeleteObject",
"s3:AbortMultipartUpload",
"s3:ListMultipartUploadParts"
],
"Resource": "arn:aws:s3:::my-bucket/agents/*"
}
]
}Cloudflare R2
In the Cloudflare dashboard, open R2, then Manage API tokens, and create a token with Object Read and Write permission scoped to the buckets you need. Use the token's access key ID and secret, and your account ID.
MinIO
Create an access key with a policy limited to the bucket, in the MinIO console or with mc admin policy.
One-time links
If someone else holds the key, create a one-time link from the Storage page. They open it, enter the key ID and secret, and mcpdrives checks the key against the bucket before saving it. The link works once and expires. An agent that you allowed to manage a drive can create the same kind of link with drive_manage, and a script can submit the key as JSON so the secret never enters a conversation:
curl -X POST https://cloud.mcpdrives.com/intake/mcpd_in_… \
-H 'content-type: application/json' \
-d "{\"accessKeyId\":\"$KEY_ID\",\"secretAccessKey\":\"$SECRET\"}"Endpoints
- Endpoints must use https and resolve to a public host. Literal private and loopback addresses are refused before any request.
- Buckets need no CORS settings. Agents fetch signed links with curl, and dashboard uploads go through mcpdrives.
- Path-style or virtual-host addressing follows each provider's preset.