files.upload_file
Reserve a direct upload slot for a local file. Pass the desired file_name. To place a file in folders, use a path in file_name (folder/subfolder/.../name). Optionally pass retention_days (default 7, minimum 1). The name may omit an extension. Vee3 returns an upload_code. Install the Vee3 CLI once...
This record as markdown: /tools/io-github-vee3io-vee3/files.upload-file.md
What files.upload_file does on Vee3
AI agents use files.upload_file to create or update resources in Vee3, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Vee3 environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
file_name | string | Yes | Desired file name or path for the uploaded file. Use folder/subfolder/.../file_name to organize files in folders. Extension is optional and is replaced based on |
retention_days | object | — | How many days to keep the file after upload completes. Default 7. Billing uses size and this retention. |
Parameters from the server's own tool schema.
Why files.upload_file is rated Medium
Uploads a local file to remote storage, creating new data reversibly.
From the tool's definition Reserve a direct upload slot for a local file
Risk signalsAdmin/system-level operation
Attacks that exploit this kind of access
The rule that runs files.upload_file safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Vee3, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For files.upload_file, this is the rule to start with:
files.upload_file stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Vee3, apply this rule, and every files.upload_file call is checked against it from then on.
Questions about files.upload_file
Reserve a direct upload slot for a local file. Pass the desired file_name. To place a file in folders, use a path in file_name (folder/subfolder/.../name). Optionally pass retention_days (default 7, minimum 1). The name may omit an extension. Vee3 returns an upload_code. Install the Vee3 CLI once with npm install -g @vee3/cli (requires Node 18+), then run vee3-upload {upload_code} {file_path} in the terminal. The CLI resolves the code to a signed upload URL, streams the local file to Vee3 storage, and prints the stored file_name after the upload finishes. Use that file_name in files.list_uploaded_files and other capabilities. The CLI does not need an API key. If installation fails with a TLS or certificate error (common on networks that inspect HTTPS traffic), use Node 22.15 or newer and run with NODE_OPTIONS=--use-system-ca, or configure npm to trust your network's root certificate. Files can be up to 2 GB. Retention is chosen at reserve time (default 7 days). After the upload is detected, Vee3 bills max(1, ceil(size_gibibytes * retention_days * 2)) tokens. Upload codes can be resolved within 60 minutes of reserve. Use files.list_uploaded_files to list stored uploads for follow-up work. Cost = 0 tokens to reserve. After upload completes, billing is max(1, ceil(size_gibibytes * retention_days * 2)) tokens. It is categorised as a Write tool in the Vee3 MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
files.upload_file accepts 2 parameters: file_name, retention_days. Required: file_name. The full parameter table on this page comes from the server's own tool schema.
Register the Vee3 MCP server in PolicyLayer and add a rule for files.upload_file: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Vee3. Nothing to install.
files.upload_file is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the files.upload_file rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for files.upload_file. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
files.upload_file is provided by the Vee3 MCP server (https://mcp.vee3.io/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Vee3, and thousands of servers like it.
This server
Across the catalogue