# shotpipe-mcp **Hosted, SSRF-safe, cached screenshots and Open Graph images for AI agents — no headless Chrome to run.** An [MCP](https://modelcontextprotocol.io) server that lets an agent screenshot any URL and *see the result*, or mint a social-card image, by calling [Shotpipe](https://shotpipe.io). It's the thing a local browser tool can't be: - **No Chrome in your agent's sandbox.** Rendering happens on Shotpipe's infrastructure. Nothing to install, no memory to babysit, no OOM at 2am. - **Safe on untrusted URLs.** Agents point at URLs their users typed. Shotpipe resolves DNS itself, pins the IP, re-checks every redirect, and refuses private / loopback / cloud-metadata hosts — so a hostile link **can't turn your renderer into an SSRF hole.** - **Cached.** The first capture renders; every identical one after is served from the edge in milliseconds and costs nothing. Ad and cookie-consent banners are stripped by default. ## Install ```jsonc // Claude Desktop (claude_desktop_config.json), Claude Code (.mcp.json), // Cursor, Cline, or any MCP client: { "mcpServers": { "shotpipe": { "command": "npx", "args": ["-y", "shotpipe-mcp"], "env": { "SHOTPIPE_KEY": "k_your_key", "SHOTPIPE_SECRET": "your_signing_secret" } } } } ``` Get a free key at **[shotpipe.io/signup](https://shotpipe.io/signup)** (no card) or run `npx shotpipe-init`. Self-hosting Shotpipe? Set `SHOTPIPE_BASE_URL`. ## Tools ### `screenshot` Screenshot a URL and return the **image** (so the model can see it) plus a permanent, shareable signed URL. `url` (required) · `format` png\|jpeg\|pdf · `width` · `height` · `dpr` · `full_page` · `selector` · `dark` · `omit_background` · `block_ads` · `block_banners` · `wait_for` · `delay` · `quality` · `fresh` ### `og_image` Build a signed social-card URL from a hosted template. Returns the **URL only** by default and renders nothing — the image renders lazily on the first crawler hit, so agent/build time stays fast. Drop it into ``. Pass `render: true` to also get a preview image. `title` (required) · `template` · `author` · `tag` · `accent` · `logo` · `width` · `height` · `dpr` · `render` ## How it works The signing secret never leaves the process — every request is HMAC-signed locally, exactly like Shotpipe's other clients. The server just builds a signed URL and (for `screenshot`) fetches the bytes. MIT · [shotpipe.io](https://shotpipe.io)