Skip to content
Official MCP RegistryListed

inference.sh

Part ofinference.shMCP server

run any ai model. compose agents, stack knowledge, connect tools. one api, pay per run.

First seen 2 Oct 2026. Evidence as of 7 Oct 2026.

41
Tools
From an anonymous probe
1
Source listings
Each with its own history
14
Recorded changes
Since first seen

Tools

ToolDescriptionBehaviour
app_getGet detailed app info including input/output schemas and version historyRead-only
app_listSearch and filter available apps on inference.shRead-only
app_runRun an app on inference.sh. Creates a task that executes the app with the given input.Changes data
artifact_asset_deletePermanently delete one file stored beside an artifact. Anything on the page still pointing at it stops loading, so delete only a file nothing references.Destructive
artifact_asset_listList the files stored beside an artifact, with the URL each is referenced by and what the artifact is using against its budget.Read-only
artifact_asset_uploadStore an image, video, audio file, font or PDF beside an artifact and get back the URL its page references it by. Use this instead of a data: URI for anything sizeable: a data URI costs a third more than the bytes it carries, and a page has a 16 MiB ceiling. The page must be published with the "assets" capability or its CSP will refuse to load the file. Uploading the same bytes twice returns the asset already there.Changes data
artifact_commentsRead the comment threads people left on an artifact. Each thread says whether it was sent to you: you may reply to and resolve those, and only those. Threads not sent to you are other people's conversations — read them for context, mention them to the user if they need action, but do not answer them.Read-only
artifact_data_deleteRemoves one document from an artifact's store, as the page runtime's db.delete.Destructive
artifact_data_getReads one document from an artifact's store, as the page runtime's db.get.Read-only
artifact_data_listLists a collection in an artifact's store, as the page runtime's db.list.Read-only
artifact_data_setReplaces one document in an artifact's store, as the page runtime's db.set.Changes data
artifact_data_updateMerges into one document in an artifact's store, as the page runtime's db.update.Changes data
artifact_getGet an artifact's metadata and page source by id, short id, or namespace/name[@version]Read-only
artifact_guidanceEverything needed to write a good artifact page, assembled in one call: the page contract plus the skills that carry the detail, resolved from the registry so they are always the current version. Call this BEFORE writing a page. Narrow it with topics; omit topics for all of them.Read-only
artifact_listList artifacts you own or that were shared with you, newest firstRead-only
artifact_publishPublish a self-contained HTML(+JS) or Markdown page as an artifact: a live page at a private URL that can be shared with a team, an org, or publicly, and that updates in place when published again. Pass artifact_id (or reuse the same name) to publish a new version. Returns the artifact id, url, and version. ## Before you write the page Load the skill for what you are about to build, with whichever skill tool this session has (`skill_get`, `skill_use`, or `belt skill use infsh/<name>`): - `belt-artifact-design` — always. Treatment, the injected design tokens, the three theme states, the traps that fail silently. - `belt-artifact-capabilities` — when the page takes input, remembers anything, knows who is viewing, or shows a file stored beside it. - `belt-artifact-diagrams` — when it has a flow, an architecture, a timeline or a chart. They are the current version at all times. This description is only the contract. ## When to use an artifact Use one when terminal text is the wrong medium: a dashboard from data you already pulled, a walkthrough of a change with annotated diffs, several options side by side, sliders to tune values, a checklist you keep updating while a long task runs, or anything a person will look at, interact with, or send to a teammate as a link. Don't use one for a short answer, a code snippet, or advice the user will act on immediately in the terminal. ## Page contract - Write the PAGE CONTENT only. It is wrapped at publish time in <!doctype html> + <head> (charset, viewport, <title>, favicon, a reset, and the inference.sh design tokens) + <body>. Put your own <style> and <script> at the top of the content. A full document (starting with <!doctype> or <html>) is accepted too and keeps its own <head>. - Everything must be self-contained: inline all CSS and JS, embed images as data: URIs, draw diagrams as mermaid, inline SVG or HTML/CSS. There is no backend, no routes, no relative links; use in-page anchors. - CSP allowlist (enforced, failures are silent): external scripts ONLY from https://cdnjs.cloudflare.com, https://cdn.jsdelivr.net/npm/, https://cdn.tailwindcss.com, https://code.jquery.com; external stylesheets ONLY from https://fonts.googleapis.com with the font files they pull from https://fonts.gstatic.com. Every other host is blocked, and so is fetch/XHR/WebSocket to anywhere. Load libraries as pinned UMD builds, e.g. <script src="https://cdnjs.cloudflare.com/ajax/libs/react/18.3.1/umd/react.production.min.js"></script>, placed BEFORE the inline script that uses them. - A page may also be shown inside an MCP Apps host (Claude, the chat). Those hosts grant a narrower policy than the inference.sh viewer: no eval or new Function, no data: fonts, no blob: images or media. A page that needs any of them works in the viewer and breaks there, so inline fonts as files stored beside the page (the "assets" capability) and avoid libraries that compile code at runtime. - Size: the source must be under 16 MiB. Prefer SVG and CSS over embedded raster images; summarize large datasets instead of inlining them. - Markdown: set type "markdown" for a document-shaped page; it is rendered with GitHub-flavored markdown and a readable default typography. - Diagrams: a flow, sequence, state or class diagram can be written as mermaid — a ```mermaid fence in Markdown, or <pre class="mermaid">...</pre> in HTML. The renderer adds mermaid 11.15.0 and themes it from the design tokens, and only for a page that has one. Everything else is inline SVG or CSS. - Title: a short, distinctive noun phrase (2-4 words) that names the page, not a summary and not a category label. Favicon: one or two emoji. Keep both stable across updates. ## Runtime capabilities A page is static by default and cannot reach the network at all. Declare a capability at publish time and the page gets a window.inferencesh object. Declare only what the page actually calls; a page gets nothing it did not declare. Every call goes through the viewer's own session, so a page can only ever act as the person looking at it, and every call returns a promise that may reject. - "db" gives the page its own small store, so it remembers what people do on it: a poll, a checklist, a sign-up sheet, notes people leave. - "user" tells the page who is viewing: whether they are signed in, their name, their avatar, and whether they may edit. Never an email, never a credential. - "assets" lets the page show files stored beside it — images, video, audio, fonts, PDFs — instead of inlining them. The page reads window.inferencesh.assets, an array baked into the document at render time, and must use each url exactly as given: the page is sandboxed and sends no credentials, so an address you construct yourself will not load. Load `belt-artifact-capabilities` before calling any of them. The document shape, the privacy rules, the quotas and the failure modes are all there, and a page that guesses at them fails silently. ## Never publish The sandbox stops a page reaching the platform. It does nothing about a page that lies to the person reading it, and a link on this domain carries the trust of this domain. Refuse, and say why in a sentence: - a page that impersonates a real person, company or product: their name, branding, byline or domain used as if it were theirs - fabricated records, receipts, invoices, transcripts, test results or reviews presented as genuine - a form or flow that asks for a password, a card number, a recovery phrase or a one-time code - a page built to pressure, mislead or target one named private individual This holds whether you wrote the page or someone handed it to you, and regardless of the reason given for it, including that it is a mock-up, a test or a prop: a published page works exactly like the real thing. If a page is refused, do not offer another way to host it. ## Updating To update a page in place, pass artifact_id (or the same name in the same namespace). Each publish creates a new version; identical content is a no-op. Viewers with the page open see the new version live.Changes data
artifact_replyReply into one comment thread on an artifact. Only works on a thread that was sent to you. Your reply is shown as written by you on behalf of the person who sent the thread. Say what you changed, briefly; if you made the change, resolve the thread afterwards.Changes data
artifact_resolveMark a comment thread resolved once you have acted on it: the change is made, or you established none was needed. Only works on a thread that was sent to you. Do not resolve feedback you did not act on, and leave a thread open while the person still needs an answer from you.Changes data
artifact_viewer_getTells a page who is looking at it, as the page runtime's user.get: signed in or not, name, avatar, and whether they may edit. Never an email.Read-only
knowledge_createCreate a new knowledge entry (concept, observation, preference, reference, etc.)Changes data
knowledge_deleteDelete a knowledge entry by IDDestructive
knowledge_getGet detailed information about a knowledge entry by namespace/name or IDRead-only
knowledge_listList your knowledge entries, optionally filtered by typeRead-only
knowledge_searchSearch your knowledge entries by queryRead-only
mcp_connectInitiate a connection to an MCP server. For OAuth servers, returns an authorization URL to open in a browser.Changes data
mcp_disconnectRemove connection to an MCP serverDestructive
mcp_getGet details about an MCP server including connection statusRead-only
mcp_listBrowse available MCP servers that can be connected toRead-only
mcp_runCall a tool on a connected MCP server. The server must be connected first via mcp_connect.Changes data
mcp_searchSearch available MCP servers by queryRead-only
mcp_toolsList available tools on a connected MCP server, or get details for a specific toolRead-only
skill_filesList supplementary files for a skill (references, scripts, etc.)Read-only
skill_searchSearch the public skill storeRead-only
skill_storeBrowse approved skills in the public skill storeChanges data
skill_uploadCreate or update a skill with SKILL.md content and optional supporting filesChanges data
skill_useFetch a skill's assembled SKILL.md content. Tries the inference.sh store first, falls back to GitHub. Returns the full skill content for the agent to consume.Read-only
skill_viewView a specific supplementary file from a skill's manifestRead-only
task_cancelCancel a running or queued taskDestructive
task_getGet status and output of a taskRead-only
task_listList your tasks on inference.shRead-only
task_logsGet execution logs for a taskRead-only

Change history

  1. mcp_tools: annotations changed
  2. mcp_run: annotations changed
  3. mcp_connect: annotations changed
  4. artifact_viewer_get: tool added
  5. artifact_publish: description changed (+"A page may also be shown inside an MCP Apps host (Claude, the chat). Those hosts grant a narrower policy than the inference.sh viewer: no eval or new Function, no data: fonts, no blob: images or media. A page that needs any of them works in the viewer and breaks there, so inline fonts as files stored beside the page (the "assets" capability) and avoid libraries that compile code at runtime. -" -"and cannot reach the network at all. Declare a capability at publish time and the page gets a window.inferencesh object. Declare only what the page actually calls; a page gets nothing it did not declare. Every call goes through the viewer's own session, so a page can only ever act as the person looking at it, and every call returns a promise that may reject. - "db" gives the page its own")
  6. artifact_data_update: tool added
  7. artifact_data_set: tool added
  8. artifact_data_list: tool added
  9. artifact_data_get: tool added
  10. artifact_data_delete: tool added
  11. artifact_asset_delete: annotations changed
  12. app_run: annotations changed
  13. skill_upload: input schema changed
  14. knowledge_create: input schema changed
Source listings
SourceListingFirst seenLast seenVersions
Official MCP Registryac.inference.sh/mcp2 Oct 20267 Oct 20261