# How to Connect Wasabi Hot Cloud Storage to AI Agents via MCP Server

Connecting to a Wasabi MCP server gives AI agents structured tool access to cloud storage buckets without exposing static API keys. By pairing Wasabi hot storage with Fast.io workspaces, teams eliminate the token waste of raw bucket dumps and add fast semantic search across large document archives.

Source: https://fast.io/resources/wasabi-mcp-server/
Author: [Tom Langridge](https://fast.io/authors/tom-langridge/)
Last reviewed: 2026-09-25

## Why Raw Storage Connectors Create Context Bottlenecks

Dumping raw object storage keys and binary blobs into an AI model's context window degrades agent performance almost immediately. When an autonomous agent attempts to locate a single contract clause, incident log, or dataset across thousands of unstructured S3 objects, pulling entire files into prompt context consumes available token limits, creates latency spikes, and leads to navigation loops. The issue is not the capacity of the model, it is the absence of an intermediary structure that lets the model inspect, filter, and query storage before reading raw bytes.

A Wasabi MCP server is a Model Context Protocol service that exposes Wasabi hot cloud storage buckets to AI agents as structured filesystem tools for listing, reading, and querying objects.

Wasabi Hot Cloud Storage has become a standard tier for operational data, backups, and media archives because it eliminates egress fees and API request charges. While conventional cloud providers bill for every GET request and impose steep penalties for moving data out of their regions, Wasabi offers predictable pricing for high-volume storage. For development teams running autonomous agents that continuously ingest telemetry, audit trails, and document corpuses, this pricing model removes the financial friction of automated reads and writes.

Most tutorials show how to write basic boto3 S3 scripts that dump raw bucket objects into prompt context, ignoring that LLMs choke on unstructured bucket dumps without semantic indexing. Writing ad-hoc Python scripts with boto3 or the AWS SDK introduces three immediate problems:

1. Credential exposure: Hardcoding or passing static API credentials into local scripts risks leaking long-lived access keys to third-party model providers or agent logs.
2. Lack of runtime interoperability: A custom script written for one agent framework does not work cleanly inside developer environments like Cursor or desktop tools like Claude.
3. Unstructured context bloat: Raw SDK calls return verbose XML or JSON listings that flood context windows with metadata timestamps and storage class strings instead of actionable file contents.

The Model Context Protocol solves this integration boundary by standardizing how language models discover and invoke external tools. When connected to a Wasabi MCP server, an agent does not run opaque terminal commands or execute arbitrary Python code. Instead, it queries a typed interface to list buckets, inspect object prefixes, read specific byte ranges, or stage new outputs.

Many engineering teams already maintain primary business files across cloud providers like Google Drive, Dropbox, Box, or OneDrive while archiving heavy media and historical datasets in Wasabi. Native cloud drive connectors in tools like Claude Cowork provide direct access to active team files, but they slow down when searching through thousands of multi-page archives. Bridging Wasabi object storage with an intelligent coordination layer allows agents to interact with cold archives and active team workspaces through a unified interface. You can learn more about configuring [persistent storage for agents](/storage-for-agents/) across multi-model environments.

## How the Wasabi MCP Server Manages Authentication and Tools

The Model Context Protocol establishes an open, JSON-RPC-based standard that decouples tool execution from the underlying AI client. Rather than relying on proprietary plugins, any MCP-compliant client can discover available server capabilities dynamically. Wasabi provides an official hosted MCP server operating over Streamable HTTP, removing the need to manage local background daemons or configure complex reverse proxies.

Streamable HTTP provides a persistent, stateful communication channel over standard web protocols. While earlier MCP implementations often required launching local command-line tools via standard input and output (stdio), Streamable HTTP allows AI tools running locally or in cloud hosted environments to connect to a remote endpoint via standard HTTPS.

### Endpoint Structure and Service Boundaries

Wasabi divides its MCP capabilities across three distinct service paths rather than exposing an unpartitioned root endpoint. Each path corresponds to a distinct administrative scope:

1. Wasabi S3 (`https://mcp.wasabisys.dev/s3`): Provides object storage tools prefixed with `wasabi_s3_*`. These handle bucket inspection, object retrieval, multipart uploads, and deletions.
2. Wasabi IAM and STS (`https://mcp.wasabisys.dev/iam`): Provides identity tools prefixed with `wasabi_iam_*` and `wasabi_sts_*`. These manage user permissions, access policies, and temporary session tokens.
3. Wasabi WACM (`https://mcp.wasabisys.dev/wacm`): Exposes account governance tools prefixed with `wasabi_wacm_*` for the Wasabi Account Control Manager, allowing agents to monitor sub-account utilization and invoice metrics.

Connecting to an invalid generic path such as `/mcp` will return an error. Clients must configure the exact endpoint corresponding to the required service.

### Two-Layer Security and Authentication Model

Granting an AI agent direct access to cloud infrastructure requires strict credential isolation. The Wasabi MCP server uses a two-layer security model to ensure permanent credentials never enter the AI client's runtime context.

```
+------------------+         OAuth 2.0 Flow        +-------------------------+
|                  |  -------------------------->  |                         |
|    AI Client     |   Short-Lived Access Token    |    Wasabi MCP Server    |
| (Claude, Cursor) |  <--------------------------  |   (mcp.wasabisys.dev)   |
|                  |                               |                         |
+------------------+                               +-------------------------+
                                                                |
                                                                | Encrypted
                                                                | Server-Side Keys
                                                                v
                                                   +-------------------------+
                                                   |                         |
                                                   |    Wasabi Hot Cloud     |
                                                   |         Storage         |
                                                   |                         |
                                                   +-------------------------+
```

Layer 1 governs the link between the AI client and the MCP server. When a client initiates a connection to `https://mcp.wasabisys.dev/s3`, the server returns an HTTP 401 challenge containing an OAuth discovery header. The client registers dynamically and opens a browser window for user authentication. Upon successful sign-in, the client receives a short-lived, scoped OAuth bearer token. The client runtime never encounters raw access keys.

Layer 2 governs the link between the MCP server and the Wasabi storage backend. During the initial browser authorization, the user registers their Wasabi Access Key ID and Secret Access Key within the secure Wasabi web portal. The server encrypts these keys at rest. When the agent triggers an approved tool call, such as `wasabi_s3_get_object`, the server retrieves the encrypted key, signs the S3 request using standard AWS Signature Version 4, executes the operation against Wasabi, and returns the formatted response to the agent.

### Differences Between AWS S3 MCP and Wasabi MCP

While Wasabi implements the S3 API standard, its MCP integration differs from generic AWS S3 implementations in several practical ways:

* Cost predictability: Standard AWS S3 MCP servers generate high API costs when an agent issues thousands of `ListObjectsV2` calls during broad file searches. Wasabi charges zero fees for API requests, allowing high-frequency agent polling without billing surprises.
* Zero egress fees: Agents retrieving multi-gigabyte datasets for local processing do not incur bandwidth egress charges.
* Endpoint abstraction: Generic S3 MCP tools expect AWS regional endpoints by default and require custom overrides to point to Wasabi endpoints such as `s3.us-central-1.wasabisys.com`. Wasabi's MCP server routes directly to the correct regional storage cluster automatically.
* Native OAuth proxy: Community AWS MCP implementations typically require hardcoding `AWS_ACCESS_KEY_ID` and `AWS_SECRET_ACCESS_KEY` into local JSON configuration files on disk. Wasabi MCP relies on remote OAuth tokens and encrypted server-side key management.

## Four Steps to Configure Claude and Cursor for Wasabi Storage

Connecting an AI client to Wasabi Hot Cloud Storage follows a standardized four-step workflow:

1. Create Wasabi API credentials and a target storage bucket in the Wasabi management console.
2. Configure MCP server JSON or connector parameters in your chosen AI interface.
3. Connect Fast.io workspace sync for indexed retrieval across complex document sets.
4. Execute tool calls from Claude or Cursor to inspect buckets and retrieve objects.

### Step 1: Setting Up Wasabi Credentials and Buckets

Before establishing the connection, create an IAM user with restricted privileges in the Wasabi console:

1. Log in to the Wasabi Management Console and navigate to Users under Identity and Access Management.
2. Click Create User, specify a username such as `agent-storage-user`, and select Programmatic Access.
3. Assign an IAM policy restricting the user to specific buckets. A least-privilege policy prevents autonomous agents from accessing unrelated organizational archives.
4. Generate an Access Key ID and Secret Access Key. Store these credentials in a password manager for the upcoming browser handshake.
5. Create a target bucket in your desired geographic region, for example `agent-reports-us-east`.

### Step 2: Configuring Claude for Wasabi MCP

Anthropic's Claude supports remote MCP servers across its desktop, web, and command-line interfaces. Detailed setup notes are documented in the [Wasabi documentation on Claude integration](https://docs.wasabi.com/docs/claude-with-wasabi-mcp).

For Claude Desktop and Claude.ai custom connectors:

1. Open Claude Settings and select Connectors.
2. Click Add custom connector.
3. Enter a descriptive name, such as `Wasabi S3`.
4. Enter the remote server URL: `https://mcp.wasabisys.dev/s3`.
5. Click Connect. Claude will open your browser and redirect to `mcp.wasabisys.dev/s3`.
6. Sign in with your Wasabi account credentials and add your Access Key ID and Secret Access Key.
7. Return to Claude. Under Tool permissions, review the tool group actions. Set read-only tools to Always Allow and configure destructive write or delete actions to Needs Approval.

For Claude Code CLI, run the following configuration command in your terminal:

```bash
claude mcp add --transport http wasabi-s3 https://mcp.wasabisys.dev/s3
```

On first invocation, Claude Code triggers the browser-based OAuth flow to establish your session token. You can verify active tools within a session by running the `/mcp` command.

### Step 3: Configuring Cursor via Project Configuration

Cursor provides native support for remote MCP servers over Streamable HTTP. You can configure Wasabi MCP at the project level or globally across all workspaces.

Create or update `.cursor/mcp.json` in your project root with the following configuration:

```json
{
  "mcpServers": {
    "Wasabi S3": {
      "url": "https://mcp.wasabisys.dev/s3"
    }
  }
}
```

Save the file and open Cursor Settings under Tools and MCP Servers. Cursor detects the new configuration and displays an authentication prompt. Click Authorize to complete the browser sign-in at `mcp.wasabisys.dev`. Once approved, Cursor displays a green indicator alongside the registered tool count, confirming that tools like `wasabi_s3_list_buckets` and `wasabi_s3_get_object` are active.

### Step 4: Executing Structured Tool Calls

Once configured, the agent invokes storage operations using structured JSON arguments. When you ask Claude or Cursor to inspect your archives, the model generates a structured tool call:

```json
{
  "name": "wasabi_s3_list_objects",
  "arguments": {
    "bucket": "agent-reports-us-east",
    "prefix": "2026/q3/",
    "max_keys": 25
  }
}
```

The MCP server executes the request against Wasabi's S3 API and returns a structured array containing object names, sizes, and timestamps. The agent reads this structured response to plan its subsequent steps without downloading unneeded files.

## How Fast.io Adds Semantic Retrieval to Wasabi Buckets

Connecting an agent directly to an S3 bucket solves data mobility, but it does not solve knowledge retrieval. When an agent needs to answer complex questions across hundreds of business reports, policy documents, or customer agreements, raw S3 operations hit a structural ceiling.

Consider an agent asked to identify contract termination terms across five hundred vendor agreements stored in Wasabi. Using raw S3 MCP tools, the agent must execute `wasabi_s3_list_objects`, iterate through hundreds of file paths, and issue separate `wasabi_s3_get_object` calls for each document. A single multi-page PDF can consume tens of thousands of prompt tokens. Reading fifty files exhausts the model's active memory, drives up token costs, and introduces hallucination risks as earlier context is truncated.

Object storage provides durable bit storage, but language models require an intelligent workspace that understands document structure and semantics.

### The Fast.io Hybrid Storage Architecture

The solution is a layered architecture that pairs Wasabi Hot Cloud Storage with Fast.io intelligent workspaces:

* Wasabi Hot Cloud Storage acts as the high-capacity, zero-egress repository for raw media, data lakes, and deep archives.
* Fast.io acts as the active collaboration and intelligence layer where agents and humans collaborate on versioned, indexed documents.

```
+-------------------------------------------------------------------------+
|                               Fast.io                                   |
|                                                                         |
|  +---------------------+   +---------------------+   +---------------+  |
|  |   Full-Text Index   |   | Semantic Embeddings |   | Metadata View |  |
|  +---------------------+   +---------------------+   +---------------+  |
+-------------------------------------------------------------------------+
       ^                                                     |
       | One-Time Cloud Import / Scheduled Sync              | Fast.io MCP
       | (Dropbox, Box, OneDrive, Google Drive)              | (/mcp)
       |                                                     v
+-------------------------------+                  +-------------------+
|       Wasabi Hot Cloud        |                  |     AI Agent      |
|            Storage            |                  | (Claude / Cursor) |
|   (Zero Egress Archive)       |                  +-------------------+
+-------------------------------+
```

Teams ingest or import files from their existing storage systems into an organization-owned Fast.io workspace. Fast.io supports cloud import from Google Drive, Dropbox, Box, and OneDrive via OAuth without requiring local disk transfers. For active synchronization, folders can sync into a Fast.io workspace one-way or two-way, on a schedule or on demand. Google Drive imports today with sync coming soon; sync is never real-time.

Once documents land in a Fast.io workspace, Intelligence Mode auto-indexes every file for semantic search without requiring an external vector database or complex chunking pipelines.

### Semantic Search via the Fast.io MCP Server

The [Fast.io remote MCP server](/storage-for-agents/) operates over Streamable HTTP at `https://mcp.fast.io/mcp` (or `https://mcp.fast.io/mcp/key` when authenticating via a static bearer token header). The Fast.io server exposes a consolidated `storage` tool driven by specific actions, including `search`, `list`, and `details`.

Instead of pulling full files into prompt memory, the agent calls the `storage` tool with the `search` action:

```json
{
  "name": "storage",
  "arguments": {
    "action": "search",
    "search": "liability cap exceptions for intellectual property",
    "files_scope": ["agreements/"]
  }
}
```

The unified search engine executes a hybrid query combining keyword matching and vector embeddings. It returns the precise paragraphs containing the answer alongside document citations and version metadata. The agent receives only the relevant excerpt, reducing token consumption while maintaining complete answer fidelity.

In multi-document audit benchmarks across identical test corpora, Fastio was measured the fastest and the lowest cost of the cloud storage providers tested (published at [multi-document audit benchmarks](https://fast.io/benchmarks/)).

### Structured Document Extraction with Metadata Views

When workflows require structured analysis across varied document formats, Fast.io provides [Metadata Views](/product/document-data-extraction/).

Users define the fields they need extracted in natural language, such as contract effective dates, renewal terms, total values, or governing jurisdictions. AI designs a typed schema supporting Text, Integer, Decimal, Boolean, URL, JSON, and Date & Time formats. The system processes incoming documents automatically and populates a structured, sortable view.

Agents query these structured tables directly through the Fast.io MCP server. Rather than parsing raw text inside a prompt, an agent inspects typed columns to filter agreements expiring in the next ninety days or find invoices exceeding a specified threshold.

Metadata Views work across PDFs, scanned invoices, images, and presentation decks without manual OCR configuration. When new columns are added, the workspace extracts the additional data without reprocessing the original files.

## Troubleshooting and Operational Best Practices for Production

Operating autonomous agents against production cloud storage requires strict operational guardrails, sensible permission boundaries, and systematic error handling.

### Tool Permission Scoping and Safeguards

Storage operations fall into two fundamental categories: safe read operations and destructive write operations. AI clients provide granular settings to control tool execution:

* Read-only operations (`wasabi_s3_list_buckets`, `wasabi_s3_list_objects`, `wasabi_s3_get_object`): Set these tools to Always Allow. Agents require unimpeded ability to inspect bucket structures and read file contents to complete analytical tasks.
* Destructive operations (`wasabi_s3_put_object`, `wasabi_s3_delete_object`): Set these tools to Ask permission first or Needs approval. An autonomous agent attempting to clean up a directory could inadvertently delete critical historical archives if prompted with ambiguous instructions. Requiring manual confirmation ensures human-in-the-loop validation for state changes.

In high-consequence environments, configure your Wasabi IAM policy with Object Lock enabled on sensitive buckets. Wasabi Object Lock prevents objects from being deleted or overwritten during a defined retention period, guaranteeing data immutability regardless of tool permissions.

### Troubleshooting Common Connection Issues

When deploying Wasabi MCP across development teams, engineers occasionally encounter connection hurdles:

1. Repeated OAuth popups or authorization loops: This typically happens when the AI client configuration uses an invalid root URL. Ensure your client specifies the full service path, such as `https://mcp.wasabisys.dev/s3`. Do not configure a generic `/mcp` path.
2. Local loopback redirect failures in CLI tools: CLI utilities like Claude Code and the Codex CLI use loopback addresses (`http://localhost/callback` or `http://127.0.0.1:<port>`) for OAuth redirects. If your machine runs strict firewall rules or binds port 80, the browser cannot return the authorization token. Ensure loopback communication is permitted.
3. Missing WACM credentials: Tools prefixed with `wasabi_wacm_*` require dedicated Wasabi Account Control Manager API keys. Using a standard S3 access key will result in an authorization error. Configure WACM credentials in the WACM Connect tab of the Wasabi MCP web dashboard.
4. Large object timeouts: The Model Context Protocol is optimized for structured text and metadata exchanges. Attempting to pass multi-gigabyte video files or disk images directly through MCP tool outputs will cause client memory errors. For large binary transfers, have the agent generate presigned URLs or stage transfers using dedicated CLI tooling.

### Multi-Agent File Persistence and Ownership Transfer

When multiple autonomous agents coordinate on complex projects, storing intermediate outputs directly in a shared workspace prevents data loss between execution sessions.

Fast.io provides persistent version history for every file, ensuring concurrent agent writes remain completely auditable. If two coding agents modify a configuration file or dataset simultaneously, team members can review earlier revisions or inspect the append-only audit log to verify which agent initiated the change.

Once an agent completes a deliverable, such as an audit report or processed data extract, it can stage the file inside a branded client share link or transfer ownership of the workspace directly to a human colleague. Creating an account is free; doing real work requires an organization on a paid subscription. Every organization starts with a 14-day free trial, which requires a credit card. Review our subscription tiers on the [Fast.io pricing](/pricing/) page.

## Frequently asked questions

### How do I connect Wasabi storage to an AI agent via MCP?

You connect an AI agent to Wasabi storage by adding Wasabi's hosted Streamable HTTP endpoint at https://mcp.wasabisys.dev/s3 to your client configuration. The client initiates an OAuth 2.0 handshake that opens your browser to sign in and register your Wasabi API access keys securely on the server. Once authenticated, the agent receives structured tools like wasabi_s3_list_buckets and wasabi_s3_get_object without storing permanent keys in the client.

### Can Claude or Cursor access Wasabi buckets directly?

Yes. Both Claude and Cursor natively support remote Model Context Protocol connections over Streamable HTTP. In Claude, you configure a custom connector pointing to https://mcp.wasabisys.dev/s3. In Cursor, you add the server URL under mcpServers in your .cursor/mcp.json file. Both tools authenticate through browser-based OAuth 2.0 and let models list, read, and write objects using structured tools.

### What is the difference between AWS S3 MCP and Wasabi MCP?

While both use S3-compatible APIs, Wasabi MCP provides dedicated access to Wasabi Hot Cloud Storage with zero egress fees and zero API request charges. Wasabi's official MCP server operates as an OAuth-protected hosted service over Streamable HTTP with separate endpoints for S3, IAM, and WACM account governance, whereas standard AWS S3 MCP servers often run as local stdio processes requiring hardcoded credentials.

### How does semantic search differ from raw S3 object listing in AI workflows?

Raw S3 object listing via wasabi_s3_list_objects only returns file keys, byte sizes, and timestamps. To locate specific answers, an agent must download full files into its prompt, consuming massive context tokens. Semantic search, such as Fast.io's Intelligence Mode, indexes document contents upon arrival, allowing the agent to run meaning-based queries via the storage tool with the search action and retrieve exact relevant passages with citations.

### Do I need to store Wasabi API keys in my local MCP configuration file?

No. The official hosted Wasabi MCP server uses a two-layer security model. Your client configuration only contains the server URL at https://mcp.wasabisys.dev/s3. During the initial connection, the server initiates an OAuth 2.0 flow where you authenticate and save your Wasabi Access Key and Secret Key in an encrypted server dashboard. The client only receives a temporary, scoped OAuth token.

### Can AI agents write and delete files in Wasabi buckets via MCP?

Yes, the Wasabi S3 MCP server provides tools for object creation (wasabi_s3_put_object) and deletion (wasabi_s3_delete_object). In clients like Claude, you can configure tool approval permissions so that read operations execute automatically while write and delete operations require explicit human confirmation.

## Sources

- [Wasabi Documentation: Claude With Wasabi MCP](https://docs.wasabi.com/docs/claude-with-wasabi-mcp) — Wasabi provides an OAuth-protected MCP server that allows AI clients to interact with cloud storage without directly handling permanent access keys.

## About Fast.io

Fast.io provides shared workspaces where people and AI agents work on the same files, with built-in semantic search and citation-backed chat over what they hold. Agents reach it through a remote MCP server at https://mcp.fast.io/mcp, a REST API at https://api.fast.io/current/, and a command line client published on npm as @vividengine/fastio-cli.
