# hosting_generateUploadURLV1

Generate a file browser upload URL with authentication credentials for uploading files directly to a website's file storage. Returns url, auth_key and rest_auth_key. Use these to upload a file to the website's public_html directory via the TUS resumable upload protocol (TUS 1.0.0). Send X-Auth: {auth_key} and X-Auth-Rest: {rest_auth_key} headers on every request below. 1. Create the upload: POST to {url}/{relative_file_path}?override=true with headers upload-length: {file size in bytes} and upload-offset: 0. Expect 201 Created. 2. Upload the file: send the file bytes to the same location (any TUS 1.0.0 client, or PATCH requests with an upload-offset header tracking progress) until complete. relative_file_path is the destination path inside public_html, e.g. app.zip. Instead of a TUS client, plain curl also works: FILE=app.zip SIZE=$(stat -f%z "$FILE") # stat -c%s on Linux curl -i -X POST "{url}/${FILE}?override=true" \ -H "X-Auth: {auth_key}" \ -H "X-Auth-Rest: {rest_auth_key}" \ -H "Tus-Resumable: 1.0.0" \ -H "Upload-Length: ${SIZE}" \ -H "Upload-Offset: 0" -> 201 Created curl -i -X PATCH "{url}/${FILE}?override=true" \ -H "X-Auth: {auth_key}" \ -H "X-Auth-Rest: {rest_auth_key}" \ -H "Tus-Resumable: 1.0.0" \ -H "Content-Type: application/offset+octet-stream" \ -H "Upload-Offset: 0" \ --data-binary "@${FILE}" -> 204 No Content, Upload-Offset response header equals SIZE when done

Agent View of the PolicyLayer registry record for `hosting_generateUploadURLV1`. HTML page: https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-generateuploadurlv1

## Facts

- Tool: `hosting_generateUploadURLV1`
- Server: Hostinger Api (`hostinger-api-mcp`) — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp.md
- Install: `npx -y hostinger-api-mcp`
- Homepage: https://github.com/hostinger/api-mcp-server
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 2 (2 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `domain` | string | yes | Website domain |
| `username` | string | yes | Account username |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "hosting_generateUploadURLV1",
    "arguments": {
      "domain": "<domain>",
      "username": "<username>"
    }
  }
}
```

## Why hosting_generateUploadURLV1 is rated Medium

Creates files in website storage; reversible via deletion but high impact if abused for malicious payloads.

From the tool's own definition: "Generate upload URL, uploading files directly to website's public_html directory"

Risk signals: Bulk/mass operation — affects multiple targets

## Use case

AI agents use hosting_generateUploadURLV1 to create or update resources in Hostinger Api, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Hostinger Api environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Hostinger Api:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "hosting_generateUploadURLV1": {
      "limits": [
        {
          "counter": "hosting_generateuploadurlv1_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Hostinger Api (381)

- `agency-hosting_clearWebsiteCacheV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-clearwebsitecachev1.md
- `agency-hosting_deleteWebsiteCronJobV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deletewebsitecronjobv1.md
- `agency-hosting_deleteWebsiteDatabaseUserV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deletewebsitedatabaseuserv1.md
- `agency-hosting_deleteWebsiteDatabaseV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deletewebsitedatabasev1.md
- `agency-hosting_deleteWebsiteV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deletewebsitev1.md
- `agency-hosting_deployNodeStaticWebsite` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deploynodestaticwebsite.md
- `agency-hosting_deployPhpApplication` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deployphpapplication.md
- `billing_deletePaymentMethodV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/billing-deletepaymentmethodv1.md
- `DNS_deleteDNSRecordsV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/dns-deletednsrecordsv1.md
- `DNS_resetDNSRecordsV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/dns-resetdnsrecordsv1.md
- `domains_cancelPendingIRTPVerificationV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/domains-cancelpendingirtpverificationv1.md
- `domains_deleteDomainForwardingV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/domains-deletedomainforwardingv1.md
- `domains_deleteWHOISProfileV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/domains-deletewhoisprofilev1.md
- `ecommerce_cancelAnOrderV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/ecommerce-cancelanorderv1.md
- `ecommerce_deleteAProductV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/ecommerce-deleteaproductv1.md
- `ecommerce_deleteAProductVariantV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/ecommerce-deleteaproductvariantv1.md
- `ecommerce_deleteStoreV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/ecommerce-deletestorev1.md
- `hosting_clearNode_jsRuntimeLogsV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-clearnode-jsruntimelogsv1.md
- `hosting_clearWebsiteCacheV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-clearwebsitecachev1.md
- `hosting_deleteAccountCronJobV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deleteaccountcronjobv1.md
- `hosting_deleteAccountDatabaseV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deleteaccountdatabasev1.md
- `hosting_deleteDatabaseRemoteConnectionV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletedatabaseremoteconnectionv1.md
- `hosting_deleteWebsiteParkedDomainV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewebsiteparkeddomainv1.md
- `hosting_deleteWebsiteRedirectV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewebsiteredirectv1.md
- `hosting_deleteWebsiteSubdomainV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewebsitesubdomainv1.md
- `hosting_deleteWebsiteV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewebsitev1.md
- `hosting_deleteWordPressInstallationV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewordpressinstallationv1.md
- `hosting_deployStaticSiteArchiveV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deploystaticsitearchivev1.md
- `hosting_importWordPressWebsiteV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-importwordpresswebsitev1.md
- `hosting_startNode_jsBuildV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-startnode-jsbuildv1.md
- …and 351 more: https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-hostinger-hostinger-api-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-hostinger-hostinger-api-mcp
