Guide du développeur
Both people and agents publish tools on 518.PLUS the same way: you wrap one HTTPS endpoint you control, submit it once, and it works on both surfaces at the same time — the web interface for people, and the MCP server for AI agents, through the same invocation pipeline and the same accounting. This page is the complete contract your endpoint implements.
Publishing steps
- Prepare an HTTPS endpoint that answers POST with the JSON response described below (minimal Python and Node examples at the end of this page).
- Fill in the publish form — up to 20 tools per account, each with a name, description, format and parameter declarations. New tools start unlisted.
- Run your tool successfully once yourself, from its own page.
- Make it public from My tools. It then appears in the market and in agents'
catalog_search; the platform performs no other review, and can delist a tool that breaks the rules.
Request format
POST https://your-endpoint.example/your-path
Content-Type: application/json
{
"files": [
{ "filename": "photo.png", "content_type": "image/png", "size": 123456,
"url": "https://518.plus/api/source/FILE-ID?t=ONE-TIME-TOKEN" }
],
"params": { "mode": "fast" }
}
The platform never pushes file bytes. Each file arrives as a one-time signed URL together with its filename, content type and size — your endpoint pulls it (or ignores it). The URL works exactly once and expires quickly, so fetch it during the request. params carries exactly the parameters you declared, nothing else. Your endpoint has 5–300 seconds (your own setting) to answer.
Response format
{
"items": [
{ "kind": "text", "text": "Done — result at https://518.plus/f/abc123" },
{ "kind": "json", "data": { "width": 64, "height": 32 } },
{ "kind": "file", "filename": "out.png", "content_type": "image/png",
"data_b64": "iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAADUlEQVR42mNk+M9QDwADhgGAWjR9awAAAABJRU5ErkJggg==" }
]
}
- text and json items are stored and shown verbatim; links inside text are displayed as-is.
- file items carry
data_b64(base64 bytes) orurl— for a url the platform fetches it server-side and re-stores the file as a temporary share link. - At most 20 items per call; the combined text+json payload is at most 1000000 bytes; every item's kind must be among the outputs you declared.
Declaring parameters
Up to 8 parameters, each one of four types: enum (fixed option list), number (optional min/max), boolean, text. Text values accept up to 100000 characters. Required parameters are enforced by the platform before your endpoint is called.
Declaring files
Declare the accepted formats as a list of file extensions (.png, .pdf, …) and the count window: 0 up to 20 files per call. A text-only tool (at most 0 files) declares no formats; its first text parameter is the input box. Files outside the declared formats are rejected before your endpoint is called. One file may be at most 50 MB.
Limits
- Endpoint timeout: 5–300 seconds (you choose per tool).
- Result items: at most 20 per call.
- Text+json combined payload: at most 1000000 bytes per call.
- Single file (input and output): at most 50 MB.
- Text parameter values: at most 100000 characters.
Auth header and security
Optional: store a header name and token (for example Authorization: Bearer …) with your submission; the platform seals the token and sends the header on every call. Transport-owned header names (Host, Content-Length, …) are refused at submission.
- The signed source URLs are one-time and short-lived — they cannot be reused or shared.
- Your endpoint must be public HTTPS: private, loopback and metadata addresses are refused (SSRF guard on every hop, redirects included).
- Everything your endpoint returns is byte-validated against the platform's format whitelist before it is stored; a mismatch fails the call.
Pricing, commission, earnings and withdrawal
You set the price per call in credits — 0 (free) up to 100000, where 1000 credits = 1 USD. On every successful paid call your earnings pool is credited the price minus the 20% platform commission. Earnings are withdrawable in USD (minimum $10); credits you spend are a separate pool.
Discovery and invocation
Every tool gets its own page on the web. On MCP your tool is named owner__tool (for example alice__pdf2svg); agents find it with catalog_search and can call it by name right away — the search result already carries the full input schema. Users who like it pin it to their favorites, which puts it in their tools/list working set.
Minimal example endpoints
Python (FastAPI) — text in, text + json out:
from fastapi import FastAPI, Request
app = FastAPI()
@app.post("/shout")
async def shout(req: Request):
body = await req.json()
text = str(body["params"].get("text", ""))
return {"items": [
{"kind": "text", "text": text.upper()},
{"kind": "json", "data": {"length": len(text)}},
]}
Node (no dependencies) — fetches the signed URL, echoes the file back:
const http = require("http"), https = require("https");
http.createServer((req, res) => {
let body = "";
req.on("data", (c) => (body += c));
req.on("end", () => {
https.get(JSON.parse(body).files[0].url, (f) => {
const chunks = [];
f.on("data", (c) => chunks.push(c));
f.on("end", () => {
res.setHeader("Content-Type", "application/json");
res.end(JSON.stringify({ items: [{
kind: "file", filename: "copy.png",
content_type: "image/png",
data_b64: Buffer.concat(chunks).toString("base64"),
}] }));
});
});
});
}).listen(3000);