Hugging Face integration for AI agents.
Hugging Face integration for AI agents with secure authentication and server-side credential injection. Open Connector runs the OAuth, seals the token in an encrypted vault, and serves Hugging Face tools to your agent over MCP or a typed API — credentials injected server-side, every call audited, nothing leaving your infrastructure. Open source (AGPL-3.0) and self-hostable.
Real Hugging Face actions, managed and audited.
Your user connects Hugging Face once; your agent can then we’re on a journey to advance and democratize artificial intelligence through open source and open science — scoped to the OAuth permissions you grant and the tool allowlist you configure. Every action is least-privilege and written to a tamper-evident audit trail.
- 1
Your user grants Hugging Face access once (OAuth) — the token lands in the vault.
- 2
Your agent calls a tool over MCP or the typed API; Open Connector injects the credential server-side.
- 3
Every routed call appends a hash-chained audit record — nothing leaves your infra.
Supported Hugging Face tools.
314 tools are generated from the published Hugging Face catalog. Descriptions are plain text; each action remains subject to its configured authentication and tool allowlist.
Showing 314 tools. All published catalog entries are included in this page's server-rendered HTML.
- Delete bucket
- Delete bucket
- buckets
- Delete a collection
- Delete a collection
- collections
- Delete a collection
- Delete a collection
- collections
- Delete item
- Delete an item from a collection
- collections
- Delete item
- Delete an item from a collection
- collections
- Delete a branch
- Delete a branch
- datasets
- Delete Large file
- Delete a Xet/LFS file
- datasets
- Delete a tag
- Delete a tag
- datasets
- Delete a branch
- Delete a branch
- models
- Delete Large file
- Delete a Xet/LFS file
- models
- Delete a tag
- Delete a tag
- models
- Delete notifications
- Delete notifications, either by specifying discussionIds or by applying to all notifications with search parameters
- notifications
- Delete resource group
- Delete a resource group from the organization. Requires the org to have a Team plan or higher.
- resource-groups
- Remove user
- Remove a user from a resource group, revoking the access granted through it. Requires the org to have a Team plan or higher.
- resource-groups
- Delete a SCIM group
- Delete a SCIM group
- scim
- Delete SCIM user
- Removes a user from the organization and deletes any pending invitations for non-managed organizations.
- scim
- Delete a SCIM group
- Delete a SCIM group
- scim
- Delete a SCIM user
- Delete a SCIM user
- scim
- Delete service account
- Delete a service account and all its tokens. This action cannot be undone.
- service-accounts
- Delete service-account token
- Delete an access token from a service account. This action cannot be undone.
- service-accounts
- Delete a discussion
- Delete a discussion
- discussions
- Delete a discussion
- Delete a discussion
- discussions
- Delete PR ref
- Deletes the git ref for a closed/merged pull request to free up storage. LFS files unique to this PR will be garbage collected. The PR page and diff will still be viewable using stored commit data.
- discussions
- Delete embed
- Delete SQL Console embed
- sql-console
- Delete a scheduled job
- Delete a scheduled job
- jobs
- Delete webhook
- Delete webhook
- webhooks
- Delete a branch
- Delete a branch
- spaces
- Delete Large file
- Delete a Xet/LFS file
- spaces
- Delete secret
- Delete Spaces's secret
- spaces
- Delete a tag
- Delete a tag
- spaces
- Delete variable
- Delete Spaces's variable
- spaces
- Delete Space volumes
- Delete Space volumes
- spaces
- Get agent harnesses
- Get the registry of AI agents / harnesses known to the Hub, along with the standard environment variables used to detect them. Clients use this registry to identify which agent they are running in when reporting Hub activity.
- agents
- Get health
- Get health
- agentic-provisioning
- Get a resource by ID
- Get a resource by ID
- agentic-provisioning
- Get services
- Get services
- agentic-provisioning
- Get avatar
- Display the avatar for any user or organization. This endpoint redirects to the avatar URL for either a user or an organization
- usersorgs
- List namespace buckets
- List namespace buckets
- buckets
- Get bucket details
- Get bucket details
- buckets
- Get resource group
- Get resource group
- buckets
- List files
- List files
- buckets
- Xet read token
- Get a read short-lived access token for XET
- buckets
- Xet write token
- Get a write short-lived access token for XET upload
- buckets
- Get collections
- Get collections
- collections
- Get a collection
- Get a collection
- collections
- Get a collection
- Get a collection
- collections
- Get collection resource group
- Get collection resource group
- collections
- Get collection resource group
- Get collection resource group
- collections
- Get Daily Papers
- Get Daily Papers
- papers
- List commits
- List commits
- datasets
- Get a compare rev
- Get a compare rev
- datasets
- Generate JWT
- Generate a JWT token for accessing a repository. Supports optional write access for spaces in dev mode, custom expiration, and encryption.
- datasets
- Get dataset leaderboard
- Returns the evaluation results ranked by score for a dataset/task
- datasets
- List Large files
- List Xet/LFS files for a repo
- datasets
- Get notebook URL
- Get a jupyter notebook URL for the requested file
- datasets
- List references
- List references
- datasets
- Get resource group
- Get resource group
- datasets
- Get security status
- Get the security status of a repo
- datasets
- List folder content
- List the content of a repository tree, with pagination support.
- datasets
- Get folder size
- Get the total size of a repository at a given revision, optionally under a specific subpath. Returns the total size in bytes of all files under the specified path (recursively). If a file is stored via Xet/LFS, the LFS file size is used.
- datasets
- List access requests
- List access requests for a gated repository
- datasets
- Xet read token
- Get a read short-lived access token for XET
- datasets
- Xet write token
- Get a write short-lived access token for XET upload
- datasets
- Get dataset tags
- Get all possible tags used for datasets, grouped by tag type. Optionally restrict to only one tag type
- datasets
- List docs
- Get list of available documentation
- docs
- Search docs
- Search any Hugging Face documentation
- docs
- Full-text search docs
- Full-text search across Hugging Face documentation
- docs
- Get job hardware
- Get available job hardware
- jobs
- List jobs
- List of jobs for an entity
- jobs
- Count jobs
- Count the number of jobs for an entity with optional status stage filter
- jobs
- Get a job
- Get a job
- jobs
- Stream job events
- Stream the events of a job, using SSE
- jobs
- Stream job logs
- Stream the logs of a job, using SSE
- jobs
- Stream job metrics
- Stream the metrics of a job, using SSE
- jobs
- List kernels
- List kernels with optional filtering, sorting, and pagination
- kernels
- Get kernel
- Get kernel
- kernels
- Get kernel
- Get kernel
- kernels
- List commits
- List commits
- models
- Get a compare rev
- Get a compare rev
- models
- Generate JWT
- Generate a JWT token for accessing a repository. Supports optional write access for spaces in dev mode, custom expiration, and encryption.
- models
- List Large files
- List Xet/LFS files for a repo
- models
- Get notebook URL
- Get a jupyter notebook URL for the requested file
- models
- List references
- List references
- models
- Get resource group
- Get resource group
- models
- Get security status
- Get the security status of a repo
- models
- List folder content
- List the content of a repository tree, with pagination support.
- models
- Get folder size
- Get the total size of a repository at a given revision, optionally under a specific subpath. Returns the total size in bytes of all files under the specified path (recursively). If a file is stored via Xet/LFS, the LFS file size is used.
- models
- List access requests
- List access requests for a gated repository
- models
- Xet read token
- Get a read short-lived access token for XET
- models
- Xet write token
- Get a write short-lived access token for XET upload
- models
- Get model tags
- Get all possible tags used for models, grouped by tag type. Optionally restrict to only one tag type
- models
- List notifications
- List notifications for the user
- notifications
- Export the audit log
- Export the audit log events in JSON format for a Team or Enterprise organization. The export is limited to the last 100,000 events.
- orgs
- Get avatar
- Retrieve organization avatar. This endpoint returns a JSON with the avatar URL for the organization. If called with the `Sec-Fetch-Dest: image` header, it instead redirects to the avatar URL
- orgs
- Get org usage
- Get org usage for a given period
- orgs
- Get session inference usage
- Get org inference-provider usage broken down per session id, as a time-series of monthly periods.
- orgs
- Get resource group usage
- Get org usage breakdown per resource group, returned as a time-series of monthly periods. Window is [startDate, endDate], defaults to the current month. Both dates must fall within the last 12 months. Storage values are the peak observed within each monthly period.
- orgs
- Stream usage
- Get live usage for org
- orgs
- Get org usage
- Get org usage for a given period
- orgs
- Get organization members
- Get a list of members for the organization with optional search and pagination.
- orgs
- Get resource groups
- Retrieve accessible resource groups. Get all resource groups the user has access to. Requires the org to have a Team plan or higher.
- resource-groups
- Get resource group
- Retrieve a single resource group by id. Requires the org to have a Team plan or higher.
- resource-groups
- List SCIM groups
- Get a list of SCIM groups. Retrieves a paginated list of all organization groups. If you provide the filter parameter, the resources for all matching groups are returned.
- scim
- Get a SCIM group
- Retrieves a group by its ID. If you provide the `excludedAttributes` parameter, the `members` attribute is not returned.
- scim
- List SCIM-managed users
- Retrieves a paginated list of organization members and pending invitations managed by SCIM for non-managed organizations.
- scim
- Get a SCIM provisioning user
- Retrieves a SCIM user by their ID for non-managed organizations.
- scim
- List SCIM groups
- Get a list of SCIM groups. Retrieves a paginated list of all organization groups. If you provide the filter parameter, the resources for all matching groups are returned.
- scim
- Get a SCIM group
- Retrieves a group by its ID. If you provide the `excludedAttributes` parameter, the `members` attribute is not returned.
- scim
- Get SCIM Resource Types
- Returns the list of SCIM 2.0 resource types supported by this server (User and Group).
- scim
- Get SCIM Schemas
- Returns the SCIM 2.0 schema definitions for User and Group resources.
- scim
- Get SCIM Schema by ID
- Returns a single SCIM 2.0 schema definition by its schema URI.
- scim
- Get SCIM Configuration
- Returns the SCIM 2.0 Service Provider configuration, describing the server's capabilities and supported authentication schemes.
- scim
- List SCIM users
- Retrieves a paginated list of all organization members who have been set up, including disabled users. If you provide the filter parameter, the resources for all matching members are returned.
- scim
- Get a SCIM user
- Retrieves a SCIM user by their ID.
- scim
- List service accounts
- List all service accounts for the organization.
- service-accounts
- Get service account
- Retrieve a single service account and its access token metadata. Token secrets are never returned.
- service-accounts
- Get network security settings
- Get the network security settings for an organization.
- orgs
- List organization repositories
- List organization repositories
- orgs
- Get social handles
- Get an organization's social media handles
- orgs
- List papers
- List arXiv papers sorted by published date
- papers
- Get a paper
- Get a paper
- papers
- Search papers
- Perform a hybrid semantic / full-text-search on papers
- papers
- Quick search
- Quick search for models, datasets, spaces, orgs, users, papers, collections, and buckets
- repo-search
- Registry token
- Mints a short-lived EdDSA JWT for the HuggingFace container registry, verifiable via the JWK at `/api/keys/jwt`.
- container
- List discussions
- Get discussions for a repo
- discussions
- Get discussion details
- Get discussion details
- discussions
- PR storage estimate
- Estimates the LFS storage used by a PR that could be freed if the ref is deleted.
- discussions
- Resolve a file
- This endpoint requires to follow redirection
- datasets
- Resolve a file
- This endpoint requires to follow redirection
- models
- Resolve a file
- This endpoint requires to follow redirection
- spaces
- List scheduled jobs
- List scheduled jobs for an entity
- jobs
- Get a scheduled job
- Get a scheduled job
- jobs
- Get user usage
- Get user usage for a given period
- users
- Get session inference usage
- Get user inference-provider usage broken down per session id
- users
- Get jobs usage
- Get user Jobs usage for current subscription period
- users
- Stream usage
- Get live usage for user
- users
- Get user usage
- Get user usage for a given period
- users
- Get MCP tools
- Get the MCP tools for the current user
- users
- Stream metrics
- Get live usage and running jobs count for the logged-in user, over a single SSE connection
- users
- List user repositories
- List user repositories
- users
- List webhooks
- List webhooks
- webhooks
- Get webhook
- Get webhook
- webhooks
- List space hardware
- Get available space hardware
- spaces
- List commits
- List commits
- spaces
- Get a compare rev
- Get a compare rev
- spaces
- Stream events
- Get status updates for a specific Space in a streaming fashion, with SSE protocol
- spaces
- Generate JWT
- Generate a JWT token for accessing a repository. Supports optional write access for spaces in dev mode, custom expiration, and encryption.
- spaces
- List Large files
- List Xet/LFS files for a repo
- spaces
- Stream logs
- Get logs for a specific Space in a streaming fashion, with SSE protocol
- spaces
- Stream metrics
- Get live metrics for a specific Space in a streaming fashion, with SSE protocol, such as current Zero-GPU usage
- spaces
- Get notebook URL
- Get a jupyter notebook URL for the requested file
- spaces
- List references
- List references
- spaces
- Get resource group
- Get resource group
- spaces
- Get security status
- Get the security status of a repo
- spaces
- List secrets
- List a Space's secret keys. Values are never returned.
- spaces
- List folder content
- List the content of a repository tree, with pagination support.
- spaces
- Get folder size
- Get the total size of a repository at a given revision, optionally under a specific subpath. Returns the total size in bytes of all files under the specified path (recursively). If a file is stored via Xet/LFS, the LFS file size is used.
- spaces
- List variables
- List a Space's variables with their values.
- spaces
- Xet read token
- Get a read short-lived access token for XET
- spaces
- Xet write token
- Get a write short-lived access token for XET upload
- spaces
- List Space templates
- Returns the catalog of official Space templates. The `repoId` of a template can be passed as `template` when creating a Space through the create-repo endpoint.
- spaces
- Get ZeroGPU quota
- Get the authenticated user's current ZeroGPU quota usage and limits
- spaces
- Get trending
- Get the trending repositories
- modelsspacesdatasets
- Retrieve user avatar
- This endpoint returns a JSON with the avatar URL for the user. If called with the `Sec-Fetch-Dest: image` header, it instead redirects to the avatar URL
- users
- Stream usage
- Get live usage for user
- users
- List user likes
- List public repos liked by a user
- users
- User overview
- User overview
- users
- Get social handles
- Get a user's social media handles
- users
- Get user info
- Get information about the user and auth method used
- auth
- Get file metadata
- Returns file metadata including size, hash, and links to XET authentication
- buckets
- Resolve a file
- This endpoint requires to follow redirection
- datasets
- Export access report
- Export a report of all access requests for a gated repository
- datasets
- Resolve a file
- This endpoint requires to follow redirection
- models
- Export access report
- Export a report of all access requests for a gated repository
- models
- Get user info
- Get information about the user. Only available through oauth access tokens. Information varies depending on the scope of the oauth app and what permissions the user granted to the oauth app.
- oauth
- Resolve a file
- This endpoint requires to follow redirection
- spaces
- Update a collection
- Update a collection
- collections
- Update a collection
- Update a collection
- collections
- Update resource group
- Update the name and/or description of a resource group. Requires the org to have a Team plan or higher.
- resource-groups
- Change user role
- Change the role of a user in a resource group. Requires the org to have a Team plan or higher.
- resource-groups
- Update SCIM group
- Update attributes of a SCIM group. Updates individual attributes using Operations format. Just provide the changes you want to make using add, remove (only `members` is supported), or replace operations.
- scim
- Update SCIM user
- Modify individual attributes for non-managed organizations. Only the `active` field can be modified. User profile fields are not editable via SCIM.
- scim
- Update SCIM group
- Update attributes of a SCIM group. Updates individual attributes using Operations format. Just provide the changes you want to make using add, remove (only `members` is supported), or replace operations.
- scim
- Update SCIM user
- Update an attribute of a SCIM user. Modify individual attributes using Operations format. Just provide the changes you want to make using add, remove (only `externalId` is supported), or replace operations. If you set `active` to `false`, the user will be deprovisioned from the organization. Complicated SCIM `path` values are not supported like `emails[type eq 'work'].value`.
- scim
- Update service-account token
- Update the name and/or permissions of an existing service account token.
- service-accounts
- Update network security
- Update the network security settings for an organization.
- orgs
- Update embed
- Update SQL Console embed
- sql-console
- Update notification settings
- Update notification settings for the user
- notifications
- Update watch settings
- Update watch settings for the user. Get notified when discussions happen on your watched items.
- notifications
- Create account request
- Create account request
- agentic-provisioning
- Create deep link
- Create deep link
- agentic-provisioning
- Provision a resource
- Provision a resource
- agentic-provisioning
- Remove resource
- Remove resource
- agentic-provisioning
- Rotate resource credentials
- Rotate resource credentials
- agentic-provisioning
- Update resource service
- Update resource service
- agentic-provisioning
- Create a new comment
- Create a new comment
- discussions
- Create a new comment
- Create a new comment
- discussions
- Create a new comment
- Create a new comment
- discussions
- Create a new comment
- Create a new comment
- discussions
- Create bucket
- Create bucket
- buckets
- Batch file operations
- Accepts NDJSON (newline-delimited JSON) where each line is an addFile, copyFile, or deleteFile instruction. All add/copy operations must come before all delete operations. JSON-lines payload: ```json '{"type":"addFile","path":"...","xetHash":"...","mtime":...,"mtimeNanos":...,"contentType":"..."}' + '{"type":"copyFile","path":"...","xetHash":"...","sourceRepoType":"...","sourceRepoId":"...","mtime":...,"mtimeNanos":...,"contentType":"..."}' + '{"type":"deleteFile","path":"..."}' ```
- buckets
- Duplicate xet files
- Duplicate xet-stored files from this repo (source) into another repo (target) by xet hash, without re-uploading file bytes. The caller must then commit the files with their sha256/size as usual.
- buckets
- List paths info
- List paths info
- buckets
- Add resource group
- Add the repository to a resource group
- buckets
- Create a collection
- Create a collection
- collections
- Add item
- Add an item to a collection
- collections
- Batch update items
- Batch update items in a collection
- collections
- Set collection resource group
- Assign, move, or unassign an organization-owned collection to a resource group. Pass null to unassign. User-owned collections are not eligible.
- collections
- Add item
- Add an item to a collection
- collections
- Batch update items
- Batch update items in a collection
- collections
- Set collection resource group
- Assign, move, or unassign an organization-owned collection to a resource group. Pass null to unassign. User-owned collections are not eligible.
- collections
- Revoke leaked tokens
- Publicly invalidate leaked Hugging Face access tokens. Possession of the raw token value is the only proof required: no authentication is needed, and no rights over the owning account or org are necessary. Each raw token is fully invalidated, the owning user is notified by email. Always returns 202, whether or not any of the provided tokens existed, so the response cannot be used to probe token validity.
- tokens
- Create branch
- Create branch
- datasets
- Commit
- For legacy reason, we support both `application/json` and `application/x-ndjson` but we recommend using `application/x-ndjson` to create a commit. JSON-lines payload: ```json { "key": "header", "value": { "summary": "string (REQUIRED)", "description": "string (OPTIONAL - defaults to empty string)", "parentCommit": "string (OPTIONAL - 40-character hex SHA)" } } { "key": "file", "value": { "path": "string (REQUIRED)", "content": "string (OPTIONAL - required if oldPath not set)", "encoding": "utf-8 | base64 (OPTIONAL - defaults to utf-8)", "oldPath": "string (OPTIONAL - for move/rename operations)" } } { "key": "deletedEntry", "value": { "path": "string (REQUIRED)" } } { "key": "lfsFile", "value": { "path": "string (REQUIRED - max 1000 chars)", "oid": "string (OPTIONAL - required if oldPath not set, 64 hex chars)", "algo": "sha256 (OPTIONAL - only sha256 supported)", "size": "number (OPTIONAL - required if oldPath is set)", "oldPath": "string (OPTIONAL - for move/rename operations)" } } ``` JSON payload: ```json { "summary": "string (REQUIRED)", "description": "string (OPTIONAL - defaults to empty string)", "parentCommit": "string (OPTIONAL - 40-character hex SHA)" "files": [ { "path": "string (REQUIRED)", "content": "string (OPTIONAL - required if oldPath not set)", "encoding": "utf-8 | base64 (OPTIONAL - defaults to utf-8)", "oldPath": "string (OPTIONAL - for move/rename operations)" } ], "deletedEntries": [ { "path": "string (REQUIRED)" } ], "lfsFiles": [ { "path": "string (REQUIRED - max 1000 chars)", "oid": "string (OPTIONAL - required if oldPath not set, 64 hex chars)", "algo": "sha256 (OPTIONAL - only sha256 supported)", "size": "number (OPTIONAL - required if oldPath is set)", "oldPath": "string (OPTIONAL - for move/rename operations)" } ] } ```
- datasets
- Delete Large files
- Delete Xet/LFS files in batch
- datasets
- Duplicate xet files
- Duplicate xet-stored files from this repo (source) into another repo (target) by xet hash, without re-uploading file bytes. The caller must then commit the files with their sha256/size as usual.
- datasets
- List paths info
- List paths info
- datasets
- Check upload method
- Check if a file should be uploaded through the Large File mechanism or directly.
- datasets
- Add resource group
- Add the repository to a resource group
- datasets
- Squash ref
- Squash all commits in the current ref into a single commit with the given message. Action is irreversible.
- datasets
- Create tag
- Create tag
- datasets
- Batch handle access requests
- Accept, reject or reset to pending up to 100 access requests for a single gated repository in one call. The same `status` (and optional `rejectionReason`) is applied to every request in the list.
- datasets
- Cancel access request
- Cancel the current user's access request to a gated repository
- datasets
- Grant access
- Grant access to a user for a gated repository
- datasets
- Handle access request
- Handle a user's access request to a gated repository
- datasets
- Check access
- Check if the user has access to the inference endpoint
- inference-endpoints
- Check access
- Check if the user has access to the inference endpoint
- inference-endpoints
- Start a job
- Start a job
- jobs
- Check access
- Check if the user has access to jobs in the namespace
- jobs
- Check access
- Check if the user has access to jobs in the namespace
- jobs
- Cancel a job
- Cancel a job
- jobs
- Duplicate a job
- Duplicate an existing job, re-using its spec
- jobs
- Duplicate xet files
- Duplicate xet-stored files from this repo (source) into another repo (target) by xet hash, without re-uploading file bytes. The caller must then commit the files with their sha256/size as usual.
- kernels
- Create branch
- Create branch
- models
- Commit
- For legacy reason, we support both `application/json` and `application/x-ndjson` but we recommend using `application/x-ndjson` to create a commit. JSON-lines payload: ```json { "key": "header", "value": { "summary": "string (REQUIRED)", "description": "string (OPTIONAL - defaults to empty string)", "parentCommit": "string (OPTIONAL - 40-character hex SHA)" } } { "key": "file", "value": { "path": "string (REQUIRED)", "content": "string (OPTIONAL - required if oldPath not set)", "encoding": "utf-8 | base64 (OPTIONAL - defaults to utf-8)", "oldPath": "string (OPTIONAL - for move/rename operations)" } } { "key": "deletedEntry", "value": { "path": "string (REQUIRED)" } } { "key": "lfsFile", "value": { "path": "string (REQUIRED - max 1000 chars)", "oid": "string (OPTIONAL - required if oldPath not set, 64 hex chars)", "algo": "sha256 (OPTIONAL - only sha256 supported)", "size": "number (OPTIONAL - required if oldPath is set)", "oldPath": "string (OPTIONAL - for move/rename operations)" } } ``` JSON payload: ```json { "summary": "string (REQUIRED)", "description": "string (OPTIONAL - defaults to empty string)", "parentCommit": "string (OPTIONAL - 40-character hex SHA)" "files": [ { "path": "string (REQUIRED)", "content": "string (OPTIONAL - required if oldPath not set)", "encoding": "utf-8 | base64 (OPTIONAL - defaults to utf-8)", "oldPath": "string (OPTIONAL - for move/rename operations)" } ], "deletedEntries": [ { "path": "string (REQUIRED)" } ], "lfsFiles": [ { "path": "string (REQUIRED - max 1000 chars)", "oid": "string (OPTIONAL - required if oldPath not set, 64 hex chars)", "algo": "sha256 (OPTIONAL - only sha256 supported)", "size": "number (OPTIONAL - required if oldPath is set)", "oldPath": "string (OPTIONAL - for move/rename operations)" } ] } ```
- models
- Delete Large files
- Delete Xet/LFS files in batch
- models
- Duplicate xet files
- Duplicate xet-stored files from this repo (source) into another repo (target) by xet hash, without re-uploading file bytes. The caller must then commit the files with their sha256/size as usual.
- models
- List paths info
- List paths info
- models
- Check upload method
- Check if a file should be uploaded through the Large File mechanism or directly.
- models
- Add resource group
- Add the repository to a resource group
- models
- Squash ref
- Squash all commits in the current ref into a single commit with the given message. Action is irreversible.
- models
- Create tag
- Create tag
- models
- Batch handle access requests
- Accept, reject or reset to pending up to 100 access requests for a single gated repository in one call. The same `status` (and optional `rejectionReason`) is applied to every request in the list.
- models
- Cancel access request
- Cancel the current user's access request to a gated repository
- models
- Grant access
- Grant access to a user for a gated repository
- models
- Handle access request
- Handle a user's access request to a gated repository
- models
- Change read status
- Mark discussions as read or unread. If `applyToAll` is true, all notifications for the user matching the search parameters will be marked as read or unread.
- notifications
- Create resource group
- Create a new resource group in the organization. Requires the org to have a Team plan or higher.
- resource-groups
- Configure auto-join
- Configure the auto-join settings of a resource group. Requires the org to have a Team plan or higher.
- resource-groups
- Add users
- Add one or more organization members to a resource group. Requires the org to have a Team plan or higher.
- resource-groups
- Create a SCIM group
- Creates a new group in the organization. The group name must be unique within the organization.
- scim
- Create SCIM invitation
- Creates an invitation for a user to join the organization. The user must have an existing Hugging Face account.
- scim
- Create a SCIM group
- Creates a new group in the organization. The group name must be unique within the organization.
- scim
- Create a SCIM user
- Creates a new user in the organization. If the user already exists, only `active` field will be updated to provision the user.
- scim
- Create service account
- Create a new service account for the organization.
- service-accounts
- Create service-account token
- Create a new access token for a service account. Store the token securely - it cannot be retrieved later.
- service-accounts
- Rotate service-account token
- Invalidate an existing token and generate a new one with the same permissions. The old token will stop working immediately.
- service-accounts
- Revoke member token
- An org admin can revoke a token's access to the org. The token itself isn't deleted, it still works outside the org. Requires the raw token value. Enterprise only.
- orgs
- Index a paper
- Index a paper from arXiv by its ID. If the paper is already indexed, only its authors can re-index it.
- papers
- Create a new comment
- Create a new comment
- discussions
- Create a new comment
- Create a new comment
- discussions
- Update paper links
- Update the project page, GitHub repository, or submitting organization for a paper. Requires the requester to be the paper author, the Daily Papers submitter, or a papers admin.
- papers
- Create a new comment
- Create a new comment
- discussions
- Create a new comment
- Create a new comment
- discussions
- Quick search
- Quick search for models, datasets, spaces, orgs, users, papers, collections, and buckets
- repo-search
- Create a new discussion
- Create a new discussion
- discussions
- Create a new comment
- Create a new comment
- discussions
- Merge a pull request
- Merge a pull request
- discussions
- Pin a discussion
- Pin a discussion
- discussions
- Change status
- Change the status of a discussion
- discussions
- Change title
- Change the title of a discussion
- discussions
- Duplicate a repository
- Duplicate a repository
- repos
- Create embed
- Create SQL Console embed
- sql-console
- Create a new repository
- Create a new repository
- repos
- Move repo
- Move or rename a repo
- repos
- Create a scheduled job
- Create a scheduled job
- jobs
- Resume a scheduled job
- Resume a scheduled job
- jobs
- Run job
- Trigger a scheduled job run. Trigger a scheduled job to run immediately. Throws an error if an instance is already running and job spec does not allow concurrent runs.
- jobs
- Update job schedule
- Update job schedule
- jobs
- Suspend a scheduled job
- Suspend a scheduled job
- jobs
- Claim paper authorship
- Claim paper authorship
- papers
- Create webhook
- Create webhook
- webhooks
- Update webhook
- Update webhook
- webhooks
- Enable/disable webhook
- Enable/disable webhook
- webhooks
- Replay webhook log
- Replay webhook log
- webhooks
- Create branch
- Create branch
- spaces
- Commit
- For legacy reason, we support both `application/json` and `application/x-ndjson` but we recommend using `application/x-ndjson` to create a commit. JSON-lines payload: ```json { "key": "header", "value": { "summary": "string (REQUIRED)", "description": "string (OPTIONAL - defaults to empty string)", "parentCommit": "string (OPTIONAL - 40-character hex SHA)" } } { "key": "file", "value": { "path": "string (REQUIRED)", "content": "string (OPTIONAL - required if oldPath not set)", "encoding": "utf-8 | base64 (OPTIONAL - defaults to utf-8)", "oldPath": "string (OPTIONAL - for move/rename operations)" } } { "key": "deletedEntry", "value": { "path": "string (REQUIRED)" } } { "key": "lfsFile", "value": { "path": "string (REQUIRED - max 1000 chars)", "oid": "string (OPTIONAL - required if oldPath not set, 64 hex chars)", "algo": "sha256 (OPTIONAL - only sha256 supported)", "size": "number (OPTIONAL - required if oldPath is set)", "oldPath": "string (OPTIONAL - for move/rename operations)" } } ``` JSON payload: ```json { "summary": "string (REQUIRED)", "description": "string (OPTIONAL - defaults to empty string)", "parentCommit": "string (OPTIONAL - 40-character hex SHA)" "files": [ { "path": "string (REQUIRED)", "content": "string (OPTIONAL - required if oldPath not set)", "encoding": "utf-8 | base64 (OPTIONAL - defaults to utf-8)", "oldPath": "string (OPTIONAL - for move/rename operations)" } ], "deletedEntries": [ { "path": "string (REQUIRED)" } ], "lfsFiles": [ { "path": "string (REQUIRED - max 1000 chars)", "oid": "string (OPTIONAL - required if oldPath not set, 64 hex chars)", "algo": "sha256 (OPTIONAL - only sha256 supported)", "size": "number (OPTIONAL - required if oldPath is set)", "oldPath": "string (OPTIONAL - for move/rename operations)" } ] } ```
- spaces
- Delete Large files
- Delete Xet/LFS files in batch
- spaces
- Duplicate xet files
- Duplicate xet-stored files from this repo (source) into another repo (target) by xet hash, without re-uploading file bytes. The caller must then commit the files with their sha256/size as usual.
- spaces
- List paths info
- List paths info
- spaces
- Check upload method
- Check if a file should be uploaded through the Large File mechanism or directly.
- spaces
- Add resource group
- Add the repository to a resource group
- spaces
- Upsert secret
- Upsert Spaces's secret
- spaces
- Squash ref
- Squash all commits in the current ref into a single commit with the given message. Action is irreversible.
- spaces
- Create tag
- Create tag
- spaces
- Upsert variable
- Upsert Spaces's variable
- spaces
- Request access
- Request access to a gated repository. The fields requested by repository card metadata (https://huggingface.co/docs/hub/en/models-gated#customize-requested-information)
- datasets
- Request access
- Request access to a gated repository. The fields requested by repository card metadata (https://huggingface.co/docs/hub/en/models-gated#customize-requested-information)
- models
- Initiate device authorization
- Initiate device authorization
- oauth
- Register a new OAuth app
- Register a new OAuth app
- oauth
- Get user info
- Get information about the user. Only available through oauth access tokens. Information varies depending on the scope of the oauth app and what permissions the user granted to the oauth app.
- oauth
- Update bucket settings
- Update bucket settings
- buckets
- Update repo settings
- Update the settings of a repo
- datasets
- Update job exposed ports
- Replace the exposed ports of a running job, applied live (no re-run). Ports listed in `portsPublic` are reachable without any authentication.
- jobs
- Update job labels
- Replace user-provided labels on a job
- jobs
- Update repo settings
- Update the settings of a repo
- models
- Change member role
- Change the role of a member in the organization. Need a paid plan.
- orgs
- Update a SCIM group
- Updates a group by its ID. The group name must be unique within the organization.
- scim
- Update a SCIM user
- Updates a provisioned user's invitation for non-managed organizations. User profile fields are not editable via SCIM for non-managed organizations.
- scim
- Update a SCIM group
- Updates a group by its ID. The group name must be unique within the organization.
- scim
- Update a SCIM user
- Updates a provisioned user, you'll need to provide all their information fresh - just like setting them up for the first time. Any details you don't include will be automatically removed, so make sure to include everything they need to keep their account running smoothly. Setting `active` to `false` will deprovision the user from the organization.
- scim
- Update scheduled job labels
- Replace user-provided labels on a scheduled job
- jobs
- Update repo settings
- Update the settings of a repo
- spaces
- Set Space volumes
- Set Space volumes
- spaces
Hugging Face integration, answered
- How do AI agents use Hugging Face through Open Connector?
- Your user connects Hugging Face once with one of its cataloged authentication methods. Open Connector stores the credential in an encrypted vault and exposes Hugging Face tools to your agent over MCP or a typed API, with credentials injected server-side on each call.
- Is this a Hugging Face MCP server?
- Yes. Open Connector can serve Hugging Face as a named MCP server with a scoped allowlist and a per-user connection URL, so any MCP client can call Hugging Face actions with credentials injected server-side.
- Where do Hugging Face credentials live?
- In your own infrastructure. Open Connector keeps credentials in its own vault and injects them at call time, so they never leave your environment.
Give your agents Hugging Face — keep the keys.
Open source, self-hostable, with Hugging Face credentials that never leave your infrastructure. Run it from source today.