# Freaking Fast File Drive > A private file drive with fast links. Public files are served from the closest of 11 regions, > stream in any player, and carry no download or streaming fees. Files can be up to 2 TB. Files upload directly to object storage under a presigned policy, so throughput is not bounded by the API. Private files are shared with time-limited links; public files get a permanent URL. ## For agents - [MCP server](https://www.npmjs.com/package/freaking-fast-mcp): `npx -y freaking-fast-mcp`. Tools to upload, find, organize and share, collect files and feedback from other people, and make images: upload_file, get_download_url, read_file, list_files, search_files, get_file_views, set_file_visibility, tag_files, move_files, list_collections, create_playlist, add_to_playlist, create_gallery, add_to_gallery, create_file_request, list_file_requests, close_file_request, generate_image, get_generated_image, set_cover, create_review_link, get_review_notes, reply_to_note, resolve_note, import_from_url, delete_files, restore_files, get_storage_usage, get_changes. - Hosted MCP server: `https://mcp.freakingfast.io/mcp`, Streamable HTTP with OAuth sign-in. The same tools except upload_file, held to what the person allowed: read, organize (nothing made public or sent out), share (nothing deleted), or full, across the drive or in one folder. - [A2A 1.0 agent](https://freakingfast.io/.well-known/agent-card.json) at `https://mcp.freakingfast.io/a2a` (JSON-RPC, `A2A-Version: 1.0`): hand it a task and it does it in the drive with those tools. Skills for saving, sharing, finding and organizing, looking at photos, frames and documents, collecting files and reviews, and making images. A task can wait for files, notes, views or an image and pick up when they come, and it posts each change to a webhook given as its taskPushNotificationConfig. - [OpenAPI spec](https://freakingfast.io/openapi.yaml): the underlying HTTP API. ## Authentication The hosted server signs people in with OAuth 2.1: discovery at `https://mcp.freakingfast.io/.well-known/oauth-authorization-server`, dynamic client registration, PKCE (S256), and scopes `files:read`, `files:organize`, `files:share` and `files:full`. The person picks the limits on a consent page, never past the scope the app asked for. For the local MCP server, set `FREAKING_FAST_API_TOKEN` to an API token from account settings. It exchanges it for a short-lived session token automatically and re-mints before expiry. No browser flow, so it works in headless and containerised environments. A token made with limits only works as a bearer token at the hosted server. ## Limits - Maximum file size: 2 TB per file - Total storage: set by the account's subscription tier - Presigned upload policies expire 2 days after issue - Private download links expire 6 hours after issue ## Uploading without the MCP server Three calls. Get a presigned form from `POST /generate-file-urls`, `POST` the file as multipart/form-data to the returned `uploadUrl` including every `uploadForm` field verbatim, then record it with `POST /insert-file`. The final call re-reads the stored object's length and rejects the insert if it disagrees with the submitted `fileSize`, so send the exact byte count. Files over 64 MiB can go up in parts instead: `POST /create-multipart-upload`, send each part to its signed URL, then `POST /complete-multipart-upload` and `POST /insert-file`. Calling create again with the same `objectKey` resumes an upload that stopped.