Files.com

Browse, move and share files on a Files.com site; manage users and permissions.

Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.

Paste it into any MCP client. Setup docs

What the Files.com connector does

The Files.com MCP server connects a Files.com managed file transfer site to Claude, ChatGPT and any MCP-compatible agent. Anthropic's directory lists 61 tools that browse and move files, read every audit log, build share links, and create or delete users, groups and folder permissions. Sign-in is OAuth, and the token carries your whole account.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Files.com tools (61)

  • Copy_File
  • Create_Bundle
  • Create_Bundle_Notification
  • Create_Bundle_Recipient
  • Create_Folder
  • Create_Group
  • Create_Permission
  • Create_User
  • Delete_Bundle
  • Delete_Bundle_Notification
  • Delete_File
  • Delete_Group
  • Delete_Permission
  • Delete_User
  • Find_Automation
  • Find_Bundle
  • Find_Bundle_Notification
  • Find_File
  • Find_Group
  • Find_Remote_Server
  • Find_User
  • List_Action_Log
  • List_Api_Request_Log
  • List_Automation
  • List_Automation_Log
  • List_Bundle
  • List_Bundle_Download
  • List_Bundle_Notification
  • List_Bundle_Recipient
  • List_Bundle_Registration
  • List_Email_Log
  • List_Exavault_Api_Request_Log
  • List_External_Event
  • List_File_Migration_Log
  • List_For_File_History
  • List_For_Folder
  • List_For_Folder_History
  • List_For_User_History
  • List_Ftp_Action_Log
  • List_Group
  • List_History
  • List_Inbound_S3_Log
  • List_Logins_History
  • List_Outbound_Connection_Log
  • List_Permission
  • List_Public_Hosting_Request_Log
  • List_Remote_Server
  • List_Scim_Log
  • List_Settings_Change
  • List_Sftp_Action_Log
  • List_Sync_Log
  • List_User
  • List_Web_Dav_Action_Log
  • Move_File
  • Unzip_File
  • Update_Bundle
  • Update_Bundle_Notification
  • Update_Group
  • Update_User
  • Zip_File
  • Zip_List_Contents_File

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • No scopes exist at any layer. The server's RFC 9728 descriptor at https://app.files.com/.well-known/oauth-protected-resource/api/ai/mcp/v1 declares resource, authorization_servers and bearer_methods_supported and no scopes_supported. Its authorization server metadata declares no scopes_supported either. Nothing in the grant separates reading a folder from deleting a user. The account you sign in as is the entire permission boundary.
  • Six tools delete, and three of them delete non-file objects. Delete_User, Delete_Group and Delete_Permission change who can reach the site, not just what is on it. Files.com's Restore feature covers deleted files, folders and users, so those are reversible by a Site Administrator within the retention window; we found no equivalent documented recovery for a deleted permission or share link.
  • Deletion recovery depends on a setting you may not control. Files.com's retention default is 30 days, adjustable to 0 for immediate purge or 99999 to keep forever. Check the value on your site before letting an agent near Delete_File.
  • Create_Bundle_Recipient cannot be told not to send. The email is a hardcoded parameter in the published source, not a default you can override.
  • Every write inherits four protocols. Create_User and Update_User force SFTP, FTP, WebDAV and REST API access on. There is no way through these tools to make a user who can only use the web interface.
  • The listed endpoint is not the one you should use. Anthropic's directory publishes https://app.files.com/api/ai/mcp/v1; Files.com's documentation tells you to use your own site hostname. The listed URL answers an OAuth challenge, so it is live, but a per-site deployment is what the vendor documents.
  • Files.com documents its own hallucination problem. Its MCP prompts page states that AI "sometimes tries to fill in the blanks" and recommends adding explicit instructions such as telling the model to use only data from your site and insert no placeholder data. It also recommends coaching the agent never to delete without confirming first — advice a vendor only writes down because the failure happened.
  • Tools are not enforced read-only anywhere. The readOnlyHint and destructiveHint annotations are advisory metadata for the client. Files.com's own package notes that many clients let you disable individual tools, and on this connector that client-side toggle is the only per-tool control that exists.
  • Credentials are only checked when a tool runs. Files.com documents that connecting and listing tools succeed even with an invalid credential, and the 401 appears at first tool use. A successful connection is not proof of working access.
  • We did not read the hosted server's live tools/list. The endpoint returned 401 to an anonymous request, so the surface described here comes from the vendor's published source and Anthropic's directory, which agree. We could not confirm the hosted deployment runs version 1.0.80, and no prompts or resources capability could be observed either way.

Frequently asked questions

Can the Files.com MCP server delete my files?

Yes. Six of the 61 tools carry a delete verb, and Delete_File is one of them. Files.com holds deleted files for a configurable window so a Site Administrator can restore them, and its documentation gives the default as 30 days. Setting that window to zero makes deletion permanent, and Files.com advises against it.

Can Claude create a public share link to my Files.com files?

Yes, and nothing forces it to add protection. Create_Bundle takes password, expires_at and max_uses as optional parameters that all default to unset. A share link created without them is a URL anyone holding it can open without signing in, which makes it a credential in its own right.

Does creating a share link recipient send an email?

Yes, always. The tool is named Create_Bundle_Recipient, which reads like adding a row to a list. The published source hardcodes share_after_create to true before calling the API, under a comment labelling it a smart default. There is no parameter that turns the email off, so every call to this tool sends mail.

What OAuth permissions does the Files.com MCP server request?

None that narrow anything. Neither the server's RFC 9728 descriptor nor its OAuth authorization server metadata declared scopes_supported on 2026-08-22. Files.com documents the token as representing your login session, so the agent gets whatever you can do. Sign in as a site administrator and the agent inherits administrator rights.

How do I limit what the AI can do on my Files.com site?

Choose the account you sign in with. Files.com states the AI can perform the same actions as the account it authenticates with, so a regular non-admin user limits it to that user's folder permissions. There is no scope screen and no per-tool toggle at consent, so the account is the only boundary.

Can the connector change who can access a folder?

Yes. Create_Permission grants a user or group a named permission on a folder path, and the published source accepts admin among its values alongside full, readonly, writeonly, list and history. Delete_Permission removes one. Both run under whatever rights your signed-in account holds.

What is the Files.com MCP endpoint URL?

Your own site's hostname, not a shared one. Files.com documents the pattern as https://<mysite>.files.com/api/ai/mcp/v1/ or your custom domain with the same path. Anthropic's directory lists https://app.files.com/api/ai/mcp/v1, which returned an OAuth challenge on 2026-08-22, but the per-site form is what Files.com tells you to configure.

Why does Files.com sign-in fail with Couldn't Complete OAuth Redirect?

Your site refused to register the client. Files.com documents two causes: the client needs Dynamic Client Registration, which a Site Administrator must switch on because it ships disabled, or AI features are turned off site-wide. Claude Code, Claude desktop and mobile use CIMD instead and do not need that setting.

Sources

Use it in an agent

Put Files.com to work.

Connect Files.com once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.