MCP server file upload: how a local file reaches a tool
A remote MCP server can't read your disk. A tool gets only the arguments your client sends, so the file must sit at a URL the tool accepts.

A remote MCP server can't open files on your computer, because a tool call carries only a tool name and JSON arguments. To use a local file with a remote tool, the file has to reach the server another way, such as a URL the tool accepts or an upload flow the server offers and your client can complete. A local MCP server is different: it runs on your machine, so one built for files, such as the MCP guide's Filesystem Server, can read the folders you allow.
The protocol facts come from the MCP tools specification and its guides to remote and local servers. The example remote server is Sume's hosted MCP server, from MCP tools and gates. All were read on 2026-09-28.
Why can't a remote MCP tool open my file?
Because it runs somewhere else. The MCP guide describes remote servers as hosted on the internet rather than your local machine. To call a tool, the client sends a tools/call request with the tool's name and an arguments object. A path like /Users/me/photo.png inside those arguments is just text to a server on another computer.
Attaching the file in chat doesn't change that. The attachment goes to the model; the tool receives only what the model writes into the arguments.
What are the ways to get a file to an MCP tool?
Four, depending on the server:
| Route | How it works | On Sume's hosted server |
|---|---|---|
| Public HTTPS URL | Pass the file's URL as a tool argument | Image reference URLs must be public HTTPS; localhost, private-network, and non-HTTPS URLs are rejected |
| Output of an earlier job | Pass the server's own file URL back in | Media tools such as video_trim take this workspace's media.sume.com files |
| Server upload flow | Get an upload URL, PUT the bytes, confirm | Listed as assets_upload_url → PUT → assets_complete, but upload URLs are redacted from tool results, so an agent can't complete it from chat |
| Local server | A server running on your machine reads the directories you list | Not applicable: Sume's server is remote |
Can Sume's MCP server use my image?
Yes, if the image is online at a public HTTPS address. Sume's docs say hosted MCP cannot read files from your laptop, and that reference URLs for image generation must be public HTTPS. For video, the troubleshooting list says to check that reference images are accessible over public HTTPS. The API reference says to prefer public HTTPS media URLs in generation requests.
Editing tools are stricter. video_trim takes one clip that is already this workspace's media.sume.com artifact or asset, and there is no open-internet fetch. In practice that means a clip from an earlier Sume job, such as a generate_video result. Video editing MCP server covers those tools.
Why doesn't the upload flow work from chat?
The server hides the URL the agent would upload to. Sume's docs list the steps as create an upload URL, have the client PUT the bytes, then call assets_complete. In current code, the server replaces upload URLs in tool results with [redacted] to keep signed URLs out of agent transcripts, so the model never sees where to send the bytes. The matching REST routes are hidden from the public OpenAPI.
What about a local MCP server?
A local server can read your files directly. The MCP guide's Filesystem Server reads file contents and directory structures, limited to the paths you list in its config, and runs with your user account's permissions, so grant only directories you're comfortable with. It reads the file on your machine; it doesn't make the file reachable by a remote tool. Local vs remote MCP server compares the two.
Sources
Related posts
More in Developers
- MCP SSE vs Streamable HTTP: which transport to use
SSE is MCP's older, deprecated HTTP transport; Streamable HTTP replaced it with one endpoint that takes every message as a POST. Which to choose.
- MCP tool description: what to write and how long it can be
An MCP tool description is the text a model reads to pick and call a tool. What the spec says, where Claude Code cuts it short, and what to write.
- MCP tool exceeds maximum allowed tokens: the fix
Claude Code caps MCP tool output at 25,000 tokens by default. Raise it with MAX_MCP_OUTPUT_TOKENS, or make the tool return less data.
- MCP tool limit in VS Code, Claude Code, and Cursor
VS Code allows 128 enabled tools per chat request. Claude Code has no fixed cap and defers MCP tools. Cursor's MCP docs name no number.
Written by Sume