FileGather.

One workflow. Every interface.

Use FileGather through REST, an MCP client, or a private Cloudflare Service Binding.

Authentication

Create a read-only or read/write key in My requests → API keys. Keep it server-side. Send Authorization: Bearer fg_key_… and X-Request-Id with every REST request.

Deposit links use a separate credential scoped to one dossier. They cannot review submissions, read private API keys or download files. Credentials are stored as hashes.

REST API

POST https://filegather-api.agentcore.workers.dev/v1/actions

{
  "action": "create_request",
  "input": {
    "id": "GENERATE-A-UUID",
    "title": "Rental documents",
    "description": "Please provide the following items.",
    "items": [
      {
        "title": "Proof of address",
        "allowReason": false
      },
      {
        "title": "Previous landlord reference",
        "allowReason": true
      }
    ]
  }
}

Every document is required by default. allowReason: true enables a nonempty written explanation instead. All submitted files and reasons need explicit review before completion.

Success: {ok:true,rid,data}. Failure: {ok:false,rid,error:{code,message,category,retryable}}. Never automatically replay an uncertain mutation. Read the dossier to confirm its outcome.

MCP

Streamable HTTP endpoint: https://filegather-mcp.agentcore.workers.dev/mcp.

Configure the Bearer API key in your client's transport headers. The server exposes the operations below as typed tools. Standard clients may omit X-Request-Id on MCP requests.

For binary files, use upload_instructions, then submit a multipart upload. download_document returns an authenticated download endpoint. File bytes do not belong in tool arguments.

Cloudflare Workers

"services": [{ "binding": "FILEGATHER_API", "service": "filegather-api" }]

Call env.FILEGATHER_API.fetch(request) with the same API routes, request identifier and Bearer key. The binding does not bypass account authorization. An MCP Worker can likewise be bound as FILEGATHER_MCP.

Available operations

  • create_request
  • list_requests
  • get_request
  • update_request
  • update_requirement
  • create_deposit_link
  • revoke_deposit_link
  • submit_reason
  • review_submission
  • complete_request
  • reopen_request
  • archive_request
  • list_events
  • create_api_key
  • list_api_keys
  • revoke_api_key
  • upload_instructions
  • download_document

Uploads and history

POST /v1/files accepts multipart fields requestId, itemId, id (a new UUID), and file. Maximum 25 MiB for documents and 10 MiB for images. Use the same credential and RID headers.

Supported: PDF, JPEG, PNG, WebP, TXT, CSV, DOCX and XLSX. Replacements create immutable versions. Reviews identify the current version, preventing a stale approval from accepting a replacement.

list_events supports an after event cursor, returning up to 100 events. Other Workers can use this feed to process updates. There is no webhook push, OCR or electronic signature service in this version.