assets_download_url MCP tool: a short-lived link for an uploaded asset

The hosted MCP tool assets_download_url returns a short-lived signed URL for a first-party asset. Use it only when asked, and never echo the URL in a report.

3 min readSume
All posts

assets_download_url is the read tool in the hosted MCP Assets group that returns a short-lived download URL for an asset you uploaded to Sume. Use it only when the user asks to retrieve that file, and use the URL only for that download. Do not repeat a signed URL in a report or a log (MCP tools and gates).

The Assets tools in one table

Hosted MCP can not read files from your laptop. The upload flow is: create an upload URL, have the client PUT the bytes, then call assets_complete.

Source: docs.sume.com, read 2026-10-06.
ToolKind
assets_list, assets_getRead
assets_download_urlRead
assets_create, assets_upload_url, assets_completeWrite, with idempotency_key

Rules for an agent

  • Call assets_get to check that an upload is finished. Use assets_download_url only if the user wants the file back.
  • Treat the signed URL like a password that expires. Keep it out of thread messages and tickets.
  • Request a new URL when it expires, instead of saving the old one.
  • For a generated file, read the output of the run, not this tool.

Sources

Related posts

More in Agents

All Agents posts

Written by Sume