Built for the way AI actually works.
Artifactry isn't a folder of files with an API bolted on. It's designed around three jobs your AI does all day: find what exists, save what it made, and share it with the right people.
Find, Save, Share. In plain language.
Artifactry speaks the Model Context Protocol (MCP), the open standard AI apps use to call tools. Your AI gets eleven focused tools instead of a pile of storage commands, so it does the right thing when you say "save this" or "share that".
- Find:
searchandgetlook up artifacts by meaning, type, tags, workspace, owner or date. - Save:
save,create_versionandupload_partstore new work or a new version, even very large files. - Share:
shareandrevoke_shareput work in front of a team, a workspace, specific people or a public link. - Lookups:
list_workspaces,list_teams,list_tagsandupdate_tagsso the AI never has to guess a name.
The app, MCP, and plain HTTP.
Use Artifactry however suits the moment. Everything goes through the same permissions, so a file is exactly as private from an AI as it is from the web app.
- Web app at app.artifactry.app, built mobile-first: upload, browse, search, share and manage workspaces from any screen.
- MCP endpoint for Claude, ChatGPT, Gemini, Cursor, Codex and any other MCP client.
- HTTP for scripts and automations. The MCP endpoint is plain JSON over HTTPS, so
curlor any language can call it with a personal token.
Permanent links. Every version kept.
Artifacts are stored for you on Cloudflare's global network, so there's nothing to host or back up. Each one keeps a single permanent address for life.
- Versions: upload a new file and it becomes v2, v3, v4. Older versions stay downloadable and you can restore any of them.
- Checked on arrival: the real file type is verified against its contents, a checksum is recorded, and text is extracted for search.
- HTML stays HTML: pages your AI writes are stored exactly as written and open in a safe preview that runs no scripts by default.
- PDF, DOCX, PPTX, HTML, PNG, JPG, BMP and GIF, up to 25 MB each.
Q3 Finance Review.pptx
Same link since v1. Renamed twice, moved once.
Find it by what it says.
Search covers titles, filenames, descriptions, tags and the words inside your documents. Keyword matching runs alongside semantic search, which finds things by meaning even when the words differ.
- Every result says how it matched, keyword or semantic, so you never have to wonder.
- Filter by workspace, type, tag, owner, collection and date.
- Access is applied inside the search itself, so nothing you can't open can leak through a title, a count or a suggestion.
- Tags are suggested from each file's content. You accept, reject or add your own.
Share with a name, not a list of emails.
Start with a personal workspace. Invite people and it becomes a shared workspace with a team directory, roles and an optional custom share URL.
- Teams are reusable audiences like "Board prep". Share once and new members get access automatically.
- Share however you need: a team, a workspace, specific emails, an email domain or a public link, each with an expiry and view-only or download permission.
- Roles: Owner, Admin, Member and Guest, plus your own custom tiers.
- Revoke any share instantly, even after someone opened it.
Least privilege, by default.
AI apps sign in with OAuth 2.1 and you approve exactly what each one may do. Each tool needs its own permission (a "scope"), and an app can never do more than you can yourself. Try it:
- Outside sharing needs your yes. A public link or an outside email address returns a confirmation request, and nothing is shared until you approve.
- Secrets are hashed. Sign-in codes, sessions, share links and AI tokens are stored only as hashes.
- Rate limits on sign-in, uploads, search and sharing keep abuse and runaway agents in check.
- Audit trail: every AI action is recorded with the app's name, the action, the artifact and the time.
Choose what "My AI app" may do
See what's used, and who connected what.
The web app is your dashboard for the whole library.
- Usage analytics: views, unique viewers, downloads, and where each artifact was seen: inside the app, on a link, by email or by an AI.
- Connected AI apps: see every app you've connected, its permissions and when it was last used. Disconnect revokes it instantly.
- Personal tokens: for scripts and apps that can't do a browser sign-in, create a scoped token in Profile. It's shown once and stored only as a hash.
- Workspace settings: name, logo, time zone, date format and invitations.