Development Choices
Photo of Joseph Trasatti

Joseph Trasatti

Member of technical staff

Joseph builds full-stack systems at OpenAI, working on Codex and Deep Research. Before that he was a product engineer at Scale AI in New York, and started his career at Capital One — though he was already running his own projects by then, serving as CTO of moove and co-founding AlgoRaven while holding down a day job.

He holds degrees in engineering physics from Providence College and computer science from Columbia via their dual-degree program, and once captained a competitive League of Legends team as its shot-caller - arguably good preparation for coordinating systems under pressure.

Articles by Joseph Trasatti

Automatic tagging through an MCP server, kept usable

Run automatic tagging through the Analysis MCP server, then filter the returned candidates by a confidence threshold and an allowlist your taxonomy recognises, write the survivors to structured metadata fields that mark them as machine-written and dated, and budget the run because the add-on bills separately from base credits.

The Analysis MCP server: tagging, moderation, detection

Cloudinary's Analysis MCP server exposes automatic tagging, moderation, safety checks, object detection and recognition as per-asset tools an agent can call. Analysis features are add-ons billed outside base-plan credits, detection returns confidence scores rather than verdicts, the remote endpoint is on the SSE path, and results are most useful written back as structured metadata.

Asset Management MCP Server: Exposed Tools

The Asset Management MCP server lets an agent upload, search, rename, delete, organise and build transformation delivery URLs for images, videos and raw files. It uses Cloudinary’s API search expressions and published transformation rules. Because deletion is exposed, unattended connections should allowlist only the tools the project needs.

Set Stable Asset Names in No-Code Workflows

Use the external business key as the reconciliation anchor, keep editor-facing display names separate, and choose one collision rule. Configure public identifiers, suffixing, overwrite behavior, and folder placement as a single upload-preset policy. If identifiers are random, persist the returned identifier beside the external record instead of trying to reconstruct it later.

Automatic Format and Quality in No-Code Delivery

Automatic format selection chooses a delivery format from each request’s capabilities while leaving the source asset unchanged. Automatic quality then tunes compression for that asset’s content and chosen format. Because the same delivery URL can produce different encodings, CDN cache variation must include the negotiated format or the request headers that determine it.

Alt Text Generation in a Media Automation Flow

Generating alt text inside a media automation flow means the description is derived from the image and written back into the asset's metadata, so it travels with the asset. A working setup classifies decorative images out first, routes ambiguous assets to human review, and treats the accessibility conformance test as the pass condition.

Automating Asset Expiry and Retention Without Code

Automating asset expiry means writing an expiry date into a structured metadata field at upload, running a scheduled flow that restricts access when that date passes, and deleting only after a gap long enough to catch mistakes. Storage is billed as a current total, so the saving is immediate, but derived copies and backups may keep some of it.

Standardise Branding Across Media Without Editing Assets

Apply branding as a named transformation at delivery, not by editing stored files: the originals stay untouched, a rebrand is one edit, and an upload-time flow catches assets added outside the process. Express overlay placement per aspect ratio, and keep the rule written where designers can read it, or it will drift from the brand guide.

Enrich Asset Metadata Automatically at Upload

Enrich metadata in the upload path, not afterwards: upload-time enrichment costs one operation per asset, while backfilling re-reads and re-writes the whole library. Gate automatic tags with a confidence threshold and an allowlist, mark machine-written values as machine-written, keep the step re-runnable per subset, and judge it by whether a previously empty search now returns the right assets.

Automate UGC Moderation Before Publication

Route uploads into a moderation flow that holds each asset in a pending state and promotes it only after a check passes, so the delivery URL is never public while undecided. Because classification returns a confidence score rather than a verdict, define an explicit middle band for human review, then sample what the automation approved.

Trigger types for a hosted media automation

A hosted media automation starts from one of three trigger forms: a webhook call, a schedule, or an asset upload. Upload triggers fire once per asset and scale with ingest rate, schedules convert an unbounded stream into fixed batches, and webhooks let an external system decide when the work runs.

Automate Background Removal in No-Code Workflows

Treat background removal as a queued analysis job, keep the asset pending until completion arrives, deliver the cutout in an alpha-capable format instead of JPEG, and gate automatic publication on a review set covering hair, glass, shadows, and low-contrast products before publishing at scale.

Design branching conditions in no-code media flows

Normalize every metadata field before branching, then define non-overlapping predicates so each asset can reach only one side-effecting path. Route everything unmatched through a final else branch and make that path observable. Test canonical, case-variant, whitespace, absent, and unknown values before putting the flow into use.

Build a first media automation flow from blocks

Build a first MediaFlows automation by picking the trigger before anything else, starting from a PowerFlow template rather than a blank canvas, wiring blocks by their contracts, and putting retry and failure branches only on blocks that call outside the platform. Version one handles one asset end to end; every case comes later.

Bulk asset ingestion from a spreadsheet

A published CSV upload flow turns a one-off media migration into a spreadsheet job with no code to deploy. The work that decides whether it succeeds is row-level failure tracking, pacing against your plan's API allowance, and supplying metadata at creation time rather than in a second pass.

Exporting Asset Metadata for Review Outside the Platform

Export asset metadata to CSV when review at scale needs a spreadsheet: build a search expression that selects the rows, run the export from the media library, and treat the file as a dated snapshot. Keep the public ID as the identifier column so edits can be loaded back, and check for personal data before scheduling a recurring export.

Choosing Which MCP Servers a Project Needs

Start from the operations the project performs, not from the servers on offer. Most projects need one MCP server; a project that only delivers media needs none, because delivery URLs are plain URLs. Enable the configuration server only where settings genuinely change, and review the set whenever the project's phase changes.

Vendor CLI or MCP server for bulk asset work

For uniform work across thousands of assets the vendor CLI wins: one deterministic, re-runnable invocation and no per-item model tokens. An MCP server earns its cost only when handling differs per asset and something must judge what each one contains. Split the job — the model decides, a shell loop executes.

Diagnosing a CMS Media Plugin That Stops Delivering

When a CMS media plugin stops delivering, reproduce the delivery URL in a browser outside the CMS first: if it serves, the fault is the plugin, not storage or delivery. Then separate upload, storage and delivery failures, check for a cached stale URL, treat an empty asset picker as expired credentials, and record the plugin and platform version pair.

Product Imagery in a Commerce Platform Integration

A commerce platform integration attaches media to products inside the platform's own data model rather than by filename, defines the storefront's renditions as named transformations, and must be judged on how it handles variant sprawl and product deletion. Zoom and gallery views carry most of a store's media bandwidth, so that is where optimisation decisions matter.

Control concurrency in bursty no-code flows

Put every trigger into a queue, derive a stable key for the asset or external record, serialize work per key, and apply a separate global cap for shared dependencies. This keeps conflicting updates ordered without stopping unrelated work, while bounded retries, backlog alarms, and reconciliation expose overload instead of hiding it.

Connection References vs Environment Variables

Use connection references for connector credential bindings and environment variables for target-specific configuration such as URLs, identifiers, flags, or secret references. Both move with a solution, but each target supplies its own bindings and values. Keep credentials in managed connections or secret stores, never ordinary variable values.

Content-Aware Cropping vs Fixed Crop Rules

Use fixed crop rules when source composition is controlled and repeatability matters. Use content-aware gravity for a heterogeneous library because image analysis can adapt the focal region per asset. In production, pair automation with a fallback focal point or manual override whenever the detected subject may not match the editorial subject.

The Context Cost of Idle MCP Servers

Every connected MCP server loads its tool definitions into the context window at session start, whether or not a tool is called. The cost is both tokens and accuracy: a larger tool surface produces more plausible-but-wrong selections. Disabling unused servers is the coarse fix; a per-connection tool allowlist is the precise one.

Round-Tripping Assets Between Creative Tools and a Library

Round-tripping means a designer places assets from the media library directly inside Figma or Adobe tools and publishes finished exports back, so the library stays the source of record. The integration removes file transfer, not judgement: which system holds the latest version, and which export is approved, still has to be decided and written down.

Secrets exposed in MCP client config files

An MCP client config that authenticates with headers stores a plaintext API secret in a project or user-profile file that nothing protects by default. Project-scoped copies get committed because they look like configuration, not credentials. Use OAuth wherever a browser is reachable, and recover by rotating at the vendor rather than deleting the file.

Data Minimization in No-Code Media Flows

Minimize data at every block boundary: send only required fields, treat logs and errors as retained data stores, and document every media item and metadata field sent to external analysis services. Preserve enough identifiers for operation and debugging, but make every additional field an explicit, reviewed choice.

Diagnose Failed or Wrong MCP Tool Calls

Classify the failure before changing code: no tool call means discovery trouble, a rejected call points to credentials, limits, or protocol handling, and a plausible but wrong answer often means truncation. Reproduce the same request through REST, expose response headers, and keep the request ID that ties the failure to one vendor-side call.

Detect duplicate uploads without a manual audit

Detect duplicates by comparing image content, not file hashes: Cloudinary's duplicate detection add-on fingerprints each image so re-exports and resizes match. Run it as a flagging automation, never a deleting one, and budget it separately from base credits. For the same file uploaded twice, a deterministic public ID prevents the duplicate before detection is needed.

Discover and read MCP server resources

Discover resources by confirming the server advertises resource support, calling `resources/list`, choosing only the URI relevant to the current task, and sending `resources/read` for that URI. Then handle each returned item as text or base64-encoded binary according to its MIME type instead of loading the entire catalog into model context.

Environment Config MCP server settings

Cloudinary’s Environment Config MCP server changes product-environment configuration, not media files. It manages upload presets, upload mappings, named transformations, webhook notifications, and streaming profiles. Those shared settings can alter every later upload or delivery URL that references them, so configuration changes need a wider review and stronger change record than asset edits.

Folder Modes and Integration Access

Folder mode sets a no-code integration’s reach: either the full media library or one folder subtree. That boundary applies to every integration user. Choose it before bulk import. Dynamic folders keep asset identifiers separate from location, while changing an established mode turns organization work into a path migration.

Use Generative Fill Safely in No-Code Workflows

Treat generative fill as a derivative-making step, never evidence. Keep the untouched original, log the exact transformation and prompt, route any result that could change product shape, context, claims, or brand details to a human, and publish only an approved derivative whose lineage remains traceable.

Govern Upload Presets in No-Code Workflows

Treat each upload preset as a versioned contract: define its callers and product environment, centralize repeated upload behavior in it, wire flows to its stable name, test every effect, and migrate callers before deletion. Never repurpose an existing name while integrations may still depend on it.

Hand Over a No-Code Automation Safely

Transfer the flow only after the receiving team owns its credentials, alerts, rate-limit decisions, vendor contacts, recovery runbook, and escalation route. Name one service owner, move access into team-controlled systems, then have the new operators replay a representative failure and recover it before they accept production responsibility.

Media handling inside a headless CMS

Media handling inside a headless CMS means an app integration that surfaces the media library in the editor, so an entry stores a reference to a canonical asset rather than a file. The front end picks the rendition at delivery, folder mode sets what editors see, and the metadata schema decides whether the integration is used.

Call External APIs from No-Code HTTP Blocks

Configure the request from the downstream API’s contract: keep credentials in stored secrets, send the documented method and payload, accept only approved status codes and response shapes, and set timeout, retry, and idempotency rules according to whether repeating the operation can create additional side effects.

Idempotency Keys for No-Code API Actions

Give each business operation one stable idempotency key, persist the key, exact request, and outcome through the whole retry and replay window, and reuse them only for unchanged retries. Treat timeouts as unknown outcomes, not failures; reconcile before issuing a changed request or a new key.

Import and export no-code flows safely

Treat an exported flow as versioned configuration, not a complete deployment package. Remove secrets, record every external dependency, import the definition while disabled, and map destination connections, folders, presets, and webhook targets. Enable it only after fixed-fixture tests confirm that dependencies and outcomes work in the destination environment.

Incoming vs Eager Transformations in No-Code Pipelines

Use incoming transformations only when the stored asset itself must be changed and you accept losing discarded source detail. Use eager transformations when you must retain the uploaded original while preparing named delivery variants before first request. Never repeat the same operation at both stages: it wastes processing and may transform twice.

Loop safely over assets in no-code flows

Take a fixed snapshot of the assets before iteration, then process only that list. Record success or failure for every item so one bad asset does not erase completed work. Keep execution sequential or use deliberately small batches whose request rate stays below every downstream service’s current limit.

MCP Servers: Marketplace Plugin or Hand Configuration

Install MCP servers by marketplace plugin when you want servers and skills in one consent step and can live with a curated, lagging subset. Configure by hand when a server needs tool allowlists, header authentication or region selection. The two combine: plugin for the common path, one hand-written entry for the server that needs options.

MCP 2026-07-28’s Stateless Request Model

MCP revision 2026-07-28 makes each request self-describing: it removes the initialization handshake and protocol session identifier, and sends version and client capabilities with every call. Requests can reach any server instance. Stateful applications still work by passing server-minted handles explicitly in normal tool arguments.

MCP Argument Completion for Prompts and Resources

MCP completion lets a client request server-suggested values for a named argument within a specific prompt or resource template. The reference and argument travel together, so suggestions stay contextual. Returned values help users discover likely inputs; they do not grant access, authorize selection, or guarantee that the resulting prompt or resource request will validate.

MCP Client–Server Capability Negotiation

Capability negotiation sets the per-session protocol contract: clients declare the client-side features they can perform, and servers declare the server-side features they expose. Each side may use only advertised capabilities. Nested flags such as `listChanged` record narrower commitments, so list access does not imply change notifications.

Separate MCP Credentials by Environment

Keep development and production in separate Cloudinary product environments, authenticate each connection independently, and verify the returned environment identifier before any write. Prefer OAuth for human-operated connections; use header authentication only when one machine must hold multiple environments, with explicit profiles and a fail-closed runtime assertion.

Collect Structured Input with MCP Form Elicitation

Use form elicitation when an MCP server needs non-sensitive, structured choices from a user. Send an `elicitation/create` request with a restricted JSON schema, validate accepted content again on the server, and branch explicitly for accept, decline, and cancel. Never put passwords, access tokens, API keys, or other secrets in the form.

Secure Out-of-Band MCP URL Elicitation

MCP URL elicitation sends a user from the MCP client to a browser-based flow for OAuth, payments, or other sensitive interaction. The client displays the destination and tracks consent or completion, while credentials and other secrets go directly to the external service and remain outside the client and model context.

Capability negotiation for MCP extensions

MCP extension negotiation is an explicit intersection of advertised client and server capabilities. An implementation may use an optional extension only when both sides name its vendor-prefixed identifier and agree on its contract. Third-party extensions need independent versioning, namespace ownership, and a useful core-protocol path when support is absent.

Header Routing for MCP Streamable HTTP

Header-based routing mirrors MCP protocol version, method, and named target into HTTP headers, letting gateways route, authorize, meter, and rate-limit requests without parsing JSON-RPC. The MCP server still has to compare every required header with the body and reject missing, malformed, or conflicting values before it dispatches the operation.

Manage MCP Sessions over Streamable HTTP

Capture any MCP-Session-Id returned with InitializeResult, send it on every later HTTP request, and treat 404 as an instruction to initialize again. Authenticate every request, bind an unpredictable session handle to that client, and send DELETE when finished; accept 405 when the server does not support client-initiated termination.

Icons and presentation metadata in MCP

The 2025-11-25 MCP specification lets servers attach optional icons to tools, resources, resource templates, and prompts. Each icon supplies a source URI and can add MIME type, size, and theme hints. These fields affect presentation only; capability behavior and client usability cannot depend on them.

MCP clients: IDE assistant vs desktop assistant

An IDE assistant and a desktop client reach the same MCP servers but differ in where the config lives, whether the model can see the code that consumes a call, how tool approval is granted, and whether a browser is reachable for OAuth. Pick the IDE for repository work, the desktop client for description-driven asset work.

MCP Initialization Lifecycle

MCP initialization is a three-message boundary: the client sends `initialize` first, the server returns a supported protocol version plus its capabilities and implementation details, and the client sends `notifications/initialized`. If the client cannot use the server-selected version, it must disconnect; normal requests start only after the final notification.

JSON-RPC Error or MCP Tool Failure?

A JSON-RPC `error` means the server could not process the protocol method; a successful JSON-RPC `result` whose tool payload has `isError: true` means the tool ran and rejected the domain operation. Correlate responses by request ID, expect no reply to notifications, and preserve error codes and data.

Structured logging notifications from MCP servers

Declare the server’s logging capability, emit `notifications/message` objects with a severity, optional logger name, and bounded structured data, then let the client set its minimum level with `logging/setLevel`. Keep raw logs out of the transport stream, route notifications separately, and redact credentials and tool payloads before emission.

Implement Multi Round-Trip Requests in MCP

Return `input_required` from the original MCP operation, let the client satisfy the embedded elicitation, sampling, or roots requests, then retry that operation with `inputResponses` and unchanged opaque `requestState`. Validate capability support, authorization, integrity, expiry, origin, replay, round limits, and response shape before resuming.

OAuth or API key headers for an MCP server

Use OAuth for a remote MCP server on a workstation with a browser: it binds one product environment per connection and keeps no secret in your config file. Use header authentication — one cloudinary-url header, or three — for headless CI, containers, or one machine serving several environments at once.

Implement Incremental OAuth Scopes for MCP

Start with only the scopes needed for ordinary MCP operations. When a protected operation returns an insufficient-scope challenge, parse its required scopes and resource metadata, explain the added access to the user, reauthorize only after consent, and retry once. Treat denial as a completed authorization outcome, not an error to bypass.

MCP Server vs Direct REST Integration: Which to Build

A direct REST integration is code you wrote: deterministic, testable, and reviewable, so uniform bulk work belongs there. An MCP server is a capability surface for a model, worth its per-item token cost only where the right call depends on what each item turns out to be. Build the REST path first; add MCP over it.

Validate Origins on MCP HTTP Servers

Validate the Origin header on every Streamable HTTP connection, reject invalid origins with HTTP 403, and bind local servers to 127.0.0.1 unless remote access is deliberate. Keep authentication on every exposed endpoint: an allowed browser origin limits where browser requests start, but it does not establish the caller’s identity.

Report progress for long-running MCP requests

Put a unique progress token in the request’s `_meta`, then echo it in every `notifications/progress` message. Increase `progress` monotonically, keep any supplied `total` consistent, and stop notifications when the operation ends. Treat updates as optional status signals, not proof that the request can run without a maximum timeout.

Define and validate arguments for MCP prompts

Define each prompt argument with a stable name, a useful description, and an explicit required flag. On every prompts/get call, validate the final argument map before rendering. Completion may suggest valid values and improve data entry, but direct callers can bypass it, so it cannot enforce the prompt’s contract.

Server-provided prompt templates in MCP

MCP servers can expose prompts as user-invoked templates. A client discovers them with `prompts/list`, retrieves one by name with `prompts/get`, and supplies any declared arguments. The server returns role-tagged messages that the client can present to the user or send to a model; prompts neither execute tools nor choose resources.

Diagnose MCP Protocol Version Mismatches

Log the initialize request and response, compare both protocolVersion values against the client’s supported set, and use the negotiated value on every later HTTP request. If the server selects a version the client cannot run, close the connection. Do not continue by assuming adjacent dated versions are compatible.

Cancel in-flight MCP requests safely

Send a `notifications/cancelled` notification containing the original request ID only from the party that issued that request. Treat cancellation as advisory: stop costly work when possible, suppress the original response after accepting cancellation, and tolerate completion winning the race before the notification arrives.

Subscribe to MCP Resource Changes

After initialization, inspect the server’s `resources` capability and subscribe only when `subscribe` is `true`. Treat `notifications/resources/updated` as invalidation: read the named URI again for current content. Send `resources/unsubscribe` when interest ends, and clear every remaining subscription when the session terminates so the server retains no stale state.

Parameterized resource templates in MCP servers

An MCP resource template advertises an RFC 6570 URI pattern for a resource family that a server cannot sensibly enumerate. The client discovers the template, obtains values for its variables from a user or model, expands them into one concrete URI, and sends that URI—not the template—to `resources/read`.

MCP Roots as Filesystem Boundaries

MCP roots let a client declare which filesystem locations matter to a session. Servers can request that list and, when capability negotiation permits it, receive change notifications. Roots guide server behavior; they do not restrict the server process, so real filesystem boundaries still require operating-system permissions or sandboxing.

Server-Initiated Sampling in MCP

MCP sampling lets a server request a model completion through the client, so the server needs no user model credentials. The client chooses the model, decides whether to approve the request, and controls prompt context. Because requests travel server to client, clients must validate and authorize them instead of executing them as commands.

Use Tools Inside MCP Sampling Requests

Advertise `sampling.tools` from the client, then have the server send tool definitions and a deliberate `auto`, `required`, or `none` choice. The client applies its own approval and policy. When the model returns tool use, the server executes it, appends matched results, and samples again until completion.

Surviving Version Changes in a Hosted MCP Server

A hosted MCP server updates on the vendor's schedule, so the tool surface a project depends on can change between two runs of the same code. The guards are a versioned endpoint path where one exists, a startup assertion of the tools you expect, and the vendor's release notes treated as part of the integration.

Discover MCP Servers and Cache Results Safely

Call `server/discover` before normal requests when you need revisions and capabilities up front, cache only complete results under their method, parameters, TTL, and scope, and invalidate on subscribed change notifications. Keep private entries partitioned by authorization context; an expired TTL means stale, not proof that the underlying data remained unchanged.

Retry and Backoff for Agent-Driven MCP Calls

Retry agent-driven MCP calls in the transport layer, not in the model's reasoning. Retry only 429 and 5xx responses, use exponential backoff with full jitter, cap attempts per account rather than per worker, and make uploads idempotent before retrying them, because a repeated upload that already succeeded creates a duplicate asset instead of an error.

Seeing What an Agent Did Through an MCP Server

Seeing what an agent did through an MCP server means keeping four things together: the tool-call arguments (intent), the tool results (effect), the vendor request ID that links each call to a vendor-side record, and a trace ID carried from the triggering task. Retain them for weeks, because the question always arrives days after the change.

Routing MCP Server Calls to a Specific API Region

An MCP server connection to Cloudinary can carry a cloudinary-region header that selects which API region the server calls. It is set once per connection, alongside the credential headers, and applies to every tool call on that connection. A wrong value does not error; it returns results for a different product environment.

Running MCP-Driven Work in CI Instead of Locally

To run MCP-driven work in CI, authenticate the server with header credentials from the CI secret store, assemble the client config at run time, restrict the tool allowlist because no human approves calls, assert on the resulting state rather than the steps taken, and budget calls against rate limits shared with developers on the same account.

Remote vs local MCP servers for vendor integrations

Remote and local MCP servers expose the same tools, so the choice is about distribution: a remote server is a URL needing no runtime and defaults to OAuth, while a local one keeps credentials on the machine but makes every developer install and update it. Egress restrictions settle it: they rule remote out.

Run an MCP Server over stdio

Configure the MCP client to launch the server command, pass credentials through the subprocess environment, and exchange newline-delimited JSON-RPC on stdin and stdout. Keep stdout exclusive to protocol messages; send diagnostics through MCP logging notifications or stderr. A clean initialization exchange proves the stdio transport is wired correctly.

MCP transport: /mcp against the deprecated /sse path

Cloudinary's remote MCP servers are reached at a /mcp endpoint over stateless Streamable HTTP, the transport documented for new configurations. The older /sse path is deprecated everywhere except the Analysis server, and still accepts POST as an alias, so stale configs keep working while pointing at a path scheduled for removal.

Listen for MCP Change Notifications

In MCP revision 2026-07-28, a client opens `subscriptions/listen`, requests only notification types that both it wants and the server advertises, and treats stream completion differently from failure. On an unexpected close, it reconnects with bounded backoff, invalidates the affected cache, and refetches authoritative state.

Experimental MCP Tasks for Deferred Results

MCP tasks, introduced in the 2025-11-25 specification and still experimental, wrap a request in a durable, receiver-managed state machine. The requestor gets a task identifier and state metadata, polls with `tasks/get`, and retrieves the original deferred result with `tasks/result`, without holding the initial transport request open.

Bind OAuth Tokens to the Intended MCP Server

Include the MCP server’s canonical URI as the OAuth `resource` in both authorization and token requests. Configure the server to accept only tokens issued for that audience, then obtain separate upstream credentials rather than forwarding the client token. Test wrong-audience tokens and passthrough paths before release.

MCP Tool Behavior Annotations and Trust Limits

MCP tool annotations describe whether a tool is read-only, destructive, idempotent, or open-world. They are server-supplied hints, not proof. Clients may use them to explain likely effects in approval prompts, but authorization and execution policy must come from verified server identity, trusted configuration, and enforced permissions.

Define structured output schemas for MCP tools

Declare an MCP tool’s outputSchema as the machine-readable contract, return a matching structuredContent object alongside useful human-readable content, and validate the object on both server and client. Treat field removals, renames, type changes, and newly required fields as compatibility breaks even when the accompanying text still makes sense.

MCP tool results that overflow the context window

MCP listing tools return results sized to the library, not to the client's remaining context, and clients truncate rather than reject oversized results, so a cut-off JSON payload can be read as a complete answer. The fix is to request less — paginate with max_results and a cursor, and select only the fields the task needs.

The transformation rules file behind Cloudinary's MCP tools

Cloudinary's transformation rules file is a published, versioned, machine-readable constraint set describing which URL transformation parameters exist and how they combine. The MCP transformation tools build URLs from it rather than from a model's recall, so impossible combinations fail before delivery. It states what is expressible, not what is cheap or sensible.

Media handling in no-code app builders

No-code builders handle media in two ways: a pre-built integration wires upload and delivery into the app while it is being created, and transformation URLs work in any builder that renders an image source. The integration route imposes one shared credential and cannot sign requests, so signed uploads and token-authenticated delivery stay out of reach.

Configure the MediaFlows MCP Server in a Client

MediaFlows connects over a versioned endpoint at https://mediaflows.mcp.cloudinary.com/v2/mcp and authenticates with three custom headers — cld-cloud-name, cld-api-key and cld-secret — instead of OAuth. Configure those in your MCP client, verify the server lists workflow tools, and treat every call as an edit to automation rather than to a single asset.

Migrate MCP 2025-11-25 to 2026-07-28

Treat the move to MCP 2026-07-28 as a wire migration: replace initialization and session assumptions with discovery and per-request metadata, move callbacks to MRTR and list changes to subscriptions/listen, and stop extending deprecated roots, sampling, and logging. Test each protocol era separately, pin strict paths, and record every fallback.

Driving content moderation from an agent via an MCP server

Run moderation from an agent by uploading each asset held back from public delivery, calling the Analysis MCP server for a verdict and confidence, auto-approving above one threshold, auto-rejecting below another, and routing the middle band plus anything contextual to a person. Record every decision against the asset and sample what passed, not what was flagged.

Monitoring No-Code Workflow Webhooks

Treat webhook delivery as a separate state from the no-code flow run. Correlate each run with delivery attempts, deduplicate on the event identifier before causing side effects, and record response status, attempt number, latency, and a redacted destination so failures can be diagnosed without leaking credentials.

Produce multilingual asset metadata with automation

Generate each served locale’s description directly from the image, store it in a dedicated metadata field, and track completion per language. Route decorative images around generation so every locale emits an empty alt attribute. Leave unsupported locales empty, and retry one failed language without touching successful descriptions.

Named Transformations via an MCP Server: Create and Update

A named transformation gives a transformation chain one stable name that delivery URLs reference instead of restating. Through an MCP server an agent can create one and later update it, which changes every URL using it at once. Cached derived assets do not regenerate until invalidated or re-requested, so verify before and after every update.

Who Can Edit an Automation, and What That Lets Them Change

Anyone who can edit a media automation flow can change what happens to every asset that passes through it from then on, including overwriting metadata that other flows or people wrote. Roles that separate editors from administrators start above the free tier, so on a free plan everyone with access holds the same power.

Route assets through approval in a media flow

Represent approval as structured asset metadata, block public delivery while review is pending, and make the media library’s filtered view the working queue. Add deadlines and escalation paths so items cannot stall indefinitely, then write the approver and decision time back to each asset for later audit.

What a hosted media automation costs to run

A hosted media automation is free to run; the work it does is not. Every transformation, gigabyte stored or delivered that a flow performs draws the base plan's credits, add-on features it calls bill as separate invoice lines, and per-asset triggers over bulk imports multiply operations. Price it against a developer, a deployment target and someone carrying a pager.

Error handling and retries in a media automation

Make a hosted media automation survive failure by separating retryable errors from terminal ones, spacing retries with jittered backoff so they do not re-form the burst that broke things, routing every unrecoverable asset to a tag, folder or notification someone will work through, and refusing to let any branch report success it did not earn.

Version Control for Visual-Canvas Automations

Version control for a visual automation canvas is the set of procedures that stand in for the diff, branch and pull request the canvas does not have: an owner per flow, a changelog kept beside it, announced structural edits, and a duplicate taken before each change as the rollback point. Regulated logic belongs in code.

Enforce a Media Format Policy in No-Code Uploads

Enforce a media format policy in three layers: restrict accepted inputs in the upload preset, normalize storage with a concrete incoming format, and apply `f_auto` only to delivery requests. Keeping validation, conversion, and browser-aware selection separate prevents rejected files from being mistaken for convertible ones.

Social Publishing Without Writing an Integration

Publishing media to social platforms without an integration means using partner-built connectors inside a media automation, so posting becomes a configured step rather than per-network OAuth code. The automation's real work is producing per-platform derivatives, gating an irreversible publish behind approval, alerting on expired credentials, and naming assets so platform analytics can be attributed back.

Set Upload Size, Dimension, and Duration Limits

Set file bytes, image dimensions, video duration, and allowed formats as separate rules. Mirror them in the no-code interface for immediate feedback, but enforce them in the server-side upload preset. Normalize dimensions only when altered source media remains valid; otherwise reject the upload and explain which rule failed.

Build a No-Code Video Transcoding Pipeline

Build the flow as an asynchronous state machine: accept and validate the upload, request every required rendition eagerly, wait for the eager completion notification, verify each expected output, then publish. Define codec, container, resolution, bitrate, and streaming manifest separately so the workflow cannot hide incompatible or missing deliverables behind one quality control.

Observability for No-Code Media Flows

Operational observability pairs a flow’s visual definition with execution records showing what ran. Each record should capture the trigger, redacted block data, timing, retries, and outcome. A correlation identifier must follow every webhook and API call, connecting the no-code run to downstream logs and traces.

Recovering No-Code Workflows from Partial Failure

Recover a partially failed no-code workflow by classifying each completed step as retryable, compensable, or irreversible; recording durable outcomes and compensation state; and routing each failure class to a bounded retry, compensation path, or manual review. Never replay an uncertain side effect unless duplicate execution is known to be safe.

Keep Product Media in Step With a PIM

Keep the PIM authoritative for product records and the media platform authoritative for renditions. Join them on a stable product identifier, use the published Akeneo sync flow where it fits, distinguish missing media from failed syncs, and choose event-driven or scheduled runs by counting the operations each catalogue change creates.

PowerFlows or EasyFlows: Canvas vs Natural Language

PowerFlows give you a drag-and-drop canvas with step-by-step control over branching and third-party calls; EasyFlows describe the same automation in a sentence and run sooner. Pick the canvas when the workflow needs a branch a sentence cannot express — custom integration especially. Pick natural language for standardised branding, asset expiry and auto-tagging.

Private vs Authenticated Assets in No-Code Flows

Choose private delivery when the original is secret but approved derivatives may be public; add strict transformations when only controlled derivatives may be exposed. Choose authenticated delivery when every original and derivative needs signed access. Treat a defined access window as a separate access-control decision, not as a reason by itself to prefer either type.

Promoting a MediaFlows Automation from Test to Production

Promote a MediaFlows flow by treating it as a rebinding exercise: list every environment-specific value the flow references, copy it into production with the trigger disabled, rebind presets, folders, metadata field external IDs and webhook URLs, verify each branch, and only then enable it. Keep both environments' schemas identical so this stays a checklist rather than a rewrite.

Prompt Injection Through MCP Tool Results

MCP tool results can carry hostile instructions inside ordinary asset data. Treat every result as untrusted input, expose only necessary tools, use scoped short-lived credentials, require human approval for irreversible actions, and log every call’s arguments and result. Pattern matching cannot reliably stop an attacker who can continually rewrite the payload.

Surface MCP Rate-Limit and Request-ID Headers

Set the `cloudinary-embed-headers` option to true in your MCP client configuration. Every tool result then returns a `_headers` object carrying the feature's rate-limit ceiling, the remaining allowance, the reset timestamp and a request ID. The agent can pace itself before it hits a limit, and each call becomes traceable in a support ticket.

Fix rate limits in no-code automations

Count downstream calls across every loop and parallel branch, not by visible blocks alone. On a 429, wait for Retry-After when it is present; otherwise retry with jittered backoff. Set a maximum retry age tied to the business event, then stop, record, and route work that has become stale.

Configure responsive images without application code

Configure the media service to produce several intrinsic widths, then map those URLs into the no-code platform’s responsive-image fields with accurate selection hints. Keep width and height attributes on the rendered image. CSS may control display size, but it cannot reduce the bytes transferred for an already selected source.

Restrict the tools an MCP server exposes

Cloudinary's remote MCP servers accept a cloudinary-tools header holding a comma-separated allowlist, so one connection advertises three tools instead of the server's full set. Enforcement is server-side, unlike a client-side toggle. Fewer tool definitions load into context, the model chooses between four plausible tools rather than forty, and an unadvertised delete tool cannot be called.

Reconciling What a Per-Event Media Automation Missed

Every per-event media automation misses some events. Reconcile by running a scheduled job that queries for assets still in the wrong state, reuses the live path's logic, and is idempotent so already-handled assets are safe to reprocess. Track how many assets each run repairs: zero means relax the schedule, a growing count means the live path is broken.

Schema Contracts for Custom No-Code Connectors

Define each connector action in OpenAPI, constrain its request and response bodies with JSON Schema, and preserve released shapes as contracts. Test shared fixtures against the provider and the generated action before every release. If a field is removed, renamed, narrowed, or newly required, publish a new connector version for incompatible flows.

Manage Secrets in No-Code Automation Flows

Store each credential in a secret store and bind blocks to its name, never its value. Check successful and failed runs, exports, and screenshots for disclosure. For rotation, create the replacement, update every reference, test the flow, then revoke the old secret. If redaction cannot be proved, keep the credential outside the flow.

Use service-principal ownership for production flows

Use an organization-controlled non-human identity for production flow ownership when both the automation platform and its connectors support it. Then verify four independent bindings: flow owner, connection owner, connection reference, and target-system permissions. Apply least privilege, record rotation and emergency-transfer procedures, and alert before any credential expires.

Signed vs Unsigned Presets for No-Code Uploads

Use an unsigned preset when the no-code client must upload directly and a fixed policy can govern every file. Use a signed preset when a trusted backend is available and each upload needs broader parameters. Unsigned flows must treat the exposed preset name as callable and enforce strict guardrails.

Strict Transformation Allowlists for No-Code Media

Strict transformation allowlists stop a no-code delivery flow from creating arbitrary derived media from unfamiliar URL parameters. Approved and eagerly generated variants still deliver; unknown transformation strings fail. The control limits transformation abuse, but every new crop, size, format, or parameter ordering must be approved and released with the site change.

Define a structured metadata schema through MCP

Define the schema backward from the searches and automation branches it must support. Use typed, validated fields for important values, controlled lists for branchable categories, and conditional rules for context-specific details. Keep every field defensible, because uploader patience—not API capacity—sets the practical limit on metadata completeness.

Structured Metadata MCP Server: Schema-Shaped Asset Data

The Structured Metadata MCP server lets an agent create typed metadata fields, set their values and define conditional rules on a Cloudinary product environment by describing the schema rather than clicking through settings. Fields carry stable external IDs that code and search expressions reference, so the metadata becomes something automations can filter and branch on.

Testing a Media Automation Before It Touches Real Assets

Test a media automation in a separate product environment, because a flow that writes metadata writes it wherever it is pointed and a folder is not a boundary. Feed it a representative asset set, exercise the failure branches instead of the happy path, and point any external call at something deliberately broken before the flow runs on real assets.

Set up time-limited media access in no-code

Give the asset a token baseline, add an anonymous rule with explicit start and end times for the public window, and generate signed URLs when access must also follow time, IP, or path limits. Use synchronized clocks and cache rules that cannot outlive the window, then test both boundaries through every delivery layer.

Automating deletion of user-generated media

Automating UGC deletion means adding a scheduled delete step downstream of moderation with a grace period for appeals, making the step remove derived versions and backups as well as the original, and writing a log of every deletion. Storage is a current total, so the credit reduction appears immediately once the automation runs.

Agent skills against MCP servers for one integration

A skill is instruction text that steers a model toward correct patterns; an MCP server is an execution surface for operations against a live account. Cloudinary ships both as complementary layers. Skills cost context per turn and carry no credentials; servers cost context per tool definition and need an authenticated connection. Neither substitutes for the other.

Hosted visual flow or hand-written webhook handler?

A hand-written webhook handler needs a deployment target, a secret store, retry logic and an on-call owner before its first event; a hosted visual flow needs none of those but has no diff, no branch and no pull request. Pick the repository for single-owner logic, the canvas when more than one role edits it.

Webhook replay protection for no-code automations

Verify each webhook against the provider signature using the untouched body, then reject validly signed deliveries outside a short recency window. Atomically record the provider event or delivery identifier before work begins, and make every downstream action idempotent so authentic retries cannot repeat side effects.

Verifying Webhook Signatures Before a Media Flow Acts

Verify a webhook's signature and timestamp before any step of a media automation reads the payload. The endpoint is a public URL, the signature is derived from the payload and a shared secret, and a valid signature on an old timestamp is a replay. Reject on either failure, then let the flow branch.

When a media automation should become code

A media automation should move from a visual canvas into code when a mistake in it costs more than the convenience of editing it without a developer. Branch count, loops carrying state across iterations, logic that needs test assertions and per-run cost at volume are the signals; the usual end state is a flow routing to one coded step.