Give Cursor stable web assets.
DropIMG lets coding agents upload and replace logos, heroes, favicons, SVGs, product images, and web fonts while your app keeps the same /m/… URL. Replace the asset — not the code.
Temporary Drops are included for disposable screenshots used in PRs, chat, issues, and debugging.
Connect over MCP with DropIMG OAuth. No token paste is needed for a normal install.
This is the Cursor Marketplace plugin for the production DropIMG MCP at https://dropimg.io/mcp. It is not generic blob storage, a CDN replacement, a stock photo service, or video/PDF hosting.
- Permanent app assets with semantic paths (
homepage/hero,branding/logo) - Stable aliases — replace the file, keep the URL
- Replacement without rewriting application code
- Coding-agent workflow over MCP
- Temporary Drops when you need a disposable screenshot for GitHub, PRs, Slack, or debugging
User: Replace the homepage hero.
Cursor
→ finds homepage/hero
→ calls replace_media_asset
→ uploads new bytes
→ stable URL stays unchanged
→ application code does not change
Web Assets: JPEG, PNG, WebP, GIF, AVIF, sanitized SVG, ICO, WOFF, WOFF2.
Drops (temporary): PNG, JPEG, WebP, GIF.
Not supported: PDF, video, audio, ZIP/TAR, HTML/JS/CSS, source, EXE, TTF/OTF/EOT, arbitrary blobs.
- Install DropIMG Web Assets from the Cursor Marketplace, or load this repository as a local plugin.
- Connect MCP. Cursor uses DropIMG's existing OAuth flow against
https://dropimg.io/mcp(dynamic client registration). Sign in on dropimg.io when prompted. - Create a Web Assets project at dropimg.io/app/media if you do not have one yet.
You should not need to paste a token for a normal install.
Project keys (dropimg_pk_*) are for project-scoped CI/automation. They cannot create projects and are not the default Cursor install credential.
Account API tokens (dropimg_api_*) work as a Bearer fallback if OAuth is unavailable. Do not commit them.
Drops: upload_image, get_image, list_images, delete_image
Web Assets: list_media_projects, create_media_project, list_media_assets, get_media_asset, upload_media_asset, replace_media_asset
Agent behavior lives in the DropIMG Web Assets skill. Web Assets writes use upload intents — bytes go over HTTP, not JSON-RPC.
A DropIMG account is required. This plugin does not ship an API key, OAuth client secret, or token. Do not put dropimg_api_… keys in mcp.json.
Cursor authenticates with OAuth against https://dropimg.io/mcp. If you are signed out, DropIMG sends you through magic-link login, then back to the consent screen.
- Public
/m/...aliases are public. Knowledge of the URL is access. - Do not store secrets or confidential files as Web Assets.
- SVG is sanitized server-side.
- Project keys and API tokens are private credentials.
- Never invent
/m/{org}/{project}/{path}— use the URL DropIMG returns. - MCP traffic is configured only to
https://dropimg.io/mcp.
Free, Developer, and Pro plans: dropimg.io/pricing