Fastio
by VividEngine, LLC HTTP API in File storage & sharing
Hosted Local
VividEngine, LLC · fast.io · who's behind it
Fastio is hosted file storage with workspaces, share links and document search for teams and AI agents, from VividEngine, LLC. Agents reach it through a REST API, a hosted MCP server and an open-source CLI.
Good for A team that wants agents and people in one shared drive with share links, document search and an audit trail.
Is this your product? Claim this listing or verify it
Assessment. OAuth with PKCE, scoped API keys with read, write and admin modes, and separate read and write MCP tools limit what an agent can touch. There is no free tier, the 30-day trial needs a card, and no status page, SLA, OpenAPI file or public changelog was found.
Facts
- Transport
- HTTP, Streamable HTTP, stdio
- Endpoint
https://mcp.fast.io/mcp/tools- Auth
- OAuth or key
- Pricing
- Paid · $9.99 / mo
- x402
- No
- Licence
- Proprietary service under Fast's terms of service. The CLI, which includes a local MCP server, is Apache-2.0
- Tools exposed
- 35
- Packages
npm@vividengine/fastio-cli- Docs
- docs.fast.io/
- llms.txt
- published
- Last release
- GitHub stars
- 1
- npm / week
- 653
- Surfaces
- REST API at https://api.fast.io/current/ (version 1.0, form-encoded requests, JSON responses), hosted MCP server over Streamable HTTP, and the
fastioCLI with a local stdio MCP server - MCP endpoints
https://mcp.fast.io/mcp/tools(35 named tools),/mcp/code(8 tools),/mcp/operations(one tool per operation). The earlier/mcpand/sseaddresses still work- Credentials
- OAuth 2.0 with PKCE and dynamic client registration, or API keys scoped by entity with
r,rworrwaaccess and optional expiry - Plans
- Starter $9.99 a month or $99 a year, Business $49.99 or $499, Enterprise $199.99 or $1,999. 250 GB, 5 TB and 25 TB of storage, and 3, 10 and 30 seats
- Credits
- Storage 150 a GB, bandwidth 400 a GB, AI chat 1 per 100 tokens, document indexing 10 a page, file conversion 25 each. Overage $0.0001 a credit
- Rate limits
- Reported in
x-ve-limit-avail,x-ve-limit-maxandx-ve-limit-expiresheaders. 429 with error code 10368. No numbers published - Uploads
- Single request under 4 MB, chunked above, 3 chunks in parallel, CRC-32C recommended, maximum file size 25, 50 or 100 GB by plan
- Sharing
- Send, Receive and Exchange shares with password, expiry and download controls, and single-file links with optional
expires - Audit
- Activity log on every plan, kept 30, 180 or 365 days. CSV or JSONL export and a signed SIEM stream on Enterprise
- Deletion
- Grace periods of 15 days for shares, 30 for workspaces, 60 for organisations and 90 for user accounts, 180 days where an organisation had a subscription
- Certifications
- Google CASA Assurance Level 1. No SOC 2 report. The data centre provider holds SOC 2 Type II and ISO 27001 per the Trust Centre
- CLI
@vividengine/fastio-cli0.2.93 (8 October 2026), Rust, Apache-2.0, for macOS, Linux and Windows- Capabilities
- storage.drive storage.share knowledge.search
Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- OAuth 2.0 with PKCE and dynamic client registration, plus API keys scoped as
entity_type:entity_id:access_modewithr,rwandrwamodes and optional expiry - Named MCP mode splits each area into a read tool and a
_managewrite tool, and a read-only key hides the write tools - Shares take a password, an expiry date and a
download_securitylevel, and file links can carryexpires - Sub-processor list with locations and 15 days' notice, and deletion periods of 15, 30, 60 and 90 days stated alike in the terms and privacy policy
- The CLI is Apache-2.0 on GitHub with CI, and shipped v0.2.93 on 8 October 2026
Weaknesses
- No free tier. A new organisation answers HTTP 402 until a paid plan is chosen, and the 30-day trial needs a credit card
- No status page, incident history or SLA found. The terms give no guarantee of API availability or backward compatibility
- No OpenAPI file.
OPTIONSintrospection covers about 40 per cent of endpoints, and rate limits are published as headers without numbers - fast.io/llms.txt gives 100 credits a GB for storage and 212 for bandwidth. The pricing page and agent guide give 150 and 400
- No SOC 2 report yet (the Trust Centre says an audit is being prepared), no bug bounty, and
/.well-known/security.txtanswers 404 - The terms forbid robots and spiders outside the programmatic access of Section 12. This matters before any probe is run
Before you call it notes for agents
- Connect to
https://mcp.fast.io/mcp/toolsfor named tools orhttps://mcp.fast.io/mcp/codefor the 8-tool code mode. The URL fixes the tool set for the session - Call
action="describe"on a tool before first use. Parameters live there, not in the tool list - To update a file, upload again with the same parent folder and filename. Deleting first loses the version history
- On 429 wait until
x-ve-limit-expiresor theRetry-Aftervalue. On 402 the organisation has no plan or no credits, so stop and tell the owner - Ask the owner for a key scoped to one workspace with
rorrw. A key made without scopes carriesuser:*:rwacross the account
Who's behind it provenance 51/100
- Legal entity namedVividEngine, LLC (doing business as Fast Technologies)20/20
- Domain agefast.io, no registry record we could read0/15
- Endpoint on the vendor's domainmcp.fast.io15/15
- Terms of serviceread, states 7 of the 7 things a reader expects, and has 2 clauses that cost points6/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagenot found0/10
- Changelognot found0/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2026-10-02, states 7 of 7, 4 to know
TL;DR Dated 2026-10-02. States all 7 things a reader expects. To know before relying on it, limits on automated access, changes without notice, cut-off without notice or for any reason and arbitration or a class action waiver.
Restricts automated accesscosts points
Prohibited Activities: Agent Accounts may not be used to circumvent account limits, create fake or fraudulent accounts, engage in automated abuse, scraping beyond authorized use, spam, or any activity that violates these Terms or the Fair Use Policy.
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Says the terms or the service can change without noticecosts points
Fast may change, suspend or discontinue all or any aspect of the Services at any time, including the availability of any feature, database, or Content, without prior notice or liability.
A customer may not hear about a change before it applies.
Says access can be ended without notice or for any reason
Fast reserves the right to terminate your access to any and/or all parts of the Services at any time for any reason without prior notice or liability.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
YOU AND FAST AGREE THAT EACH MAY BRING CLAIMS AGAINST THE OTHER ONLY IN AN INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, COLLECTIVE, CONSOLIDATED, OR REPRESENTATIVE PROCEEDING.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2026-10-02
Last updated on October 2nd, 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of Texas
The Agreement shall be construed in accordance with the laws of the State of Texas, without reference to principles of choice of law.
Says where a dispute would be heard and under whose law.
States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
IN STATES, COUNTRIES OR TERRITORIES NOT ALLOWING EXCLUSION OF IMPLIED WARRANTIES OR LIMITATION OF LIABILITY FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES, FAST AND ANY THIRD PARTY PROVIDER SHALL BE LIMITED TO THE GREATEST EXTENT PERMITTED BY LAW.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Fast may change, suspend or discontinue all or any aspect of the Services at any time, including the availability of any feature, database, or Content, without prior notice or liability.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
Users will be notified of significant changes to the Services or Terms via email or through the platform.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
You agree, while using Fast Services, that you may not:
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
The warranty disclaimers and "as is" language in this Section are subject to any express warranties, service level commitments, availability guarantees, or uptime obligations that Fast undertakes in a valid Enterprise Agreement between you and Fast.
Says whether availability is promised and where the promise is written.
Fast's total liability is zero dollars for a customer who paid no fees in the twelve months before the event behind the claim.
IF YOU HAVE NOT PAID ANY FEES TO FAST DURING SUCH PERIOD, FAST'S MAXIMUM AGGREGATE LIABILITY TO YOU SHALL BE ZERO DOLLARS ($0).
Noted by a second reader on 2026-10-08.
The customer is responsible for every action taken through programmatic access or by an agent account it creates, controls or authorises.
You are fully responsible for all actions taken through Programmatic Access or by any Agent Account you create, control, or authorize, including any content uploaded, downloaded, modified, or shared.
Noted by a second reader on 2026-10-08.
After an account is deleted, closed or terminated, content is permanently purged after 15 days for shares, 30 for workspaces, 60 for organisations and 90 for user accounts.
When a share, workspace, organization, or user account is deleted, closed, or terminated, its Content is permanently purged after a grace period of 15 days for shares, 30 days for workspaces, 60 days for organizations, and 90 days for user accounts.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 8,432 words
Privacy policy dated 2026-10-02, states 8 of 8
TL;DR Dated 2026-10-02. States all 8 things a reader expects. The rules found no clause to flag.
Gives the date it was last updated Last updated 2026-10-02
Last updated on October 2nd, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
We collect minimal information necessary to enable our services, monitor stability and performance, and improve our offerings.
The basic statement a privacy policy exists to make.
Says how long data is kept Names a period of 15 days
After a share, workspace, organization, or user account is closed or deleted, its data is kept for a recovery period before it is permanently purged: 15 days for shares, 30 days for workspaces, 60 days for organizations, and 90 days for user accounts.
Says when data sent to the service is deleted.
Says who else receives the data
When Fast processes personal data contained in a business customer's Content, it acts as that customer's service provider or processor under the Service Provider and Processor Terms in our Terms of Service and, where one has been executed, the DPA.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
In the United States you can opt out at any time with the "Do Not Sell or Share My Personal Information" link or the cookie banner, and we honor Global Privacy Control signals.
A plain statement either way.
Says what rights people have over their data
Under the EU General Data Protection Regulation (GDPR), UK GDPR, California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), and other applicable privacy laws, you have the right to access, rectify, delete, restrict processing of, and object to the processing of your PII.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@fast.io
If you have questions, please contact us at privacy@fast.io.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
Where you have executed a DPA with Fast, the Standard Contractual Clauses it incorporates apply to transfers of the personal data it covers.
The countries data goes to and the safeguard used.
PostHog product analytics and session replay run in the web application and cannot be turned off there.
Our web application uses PostHog product analytics and session replay as part of operating and improving the Service; they cannot be turned off within the application.
Noted by a second reader on 2026-10-08.
Data from API, MCP and agent account access may be kept longer than standard user data.
Data from programmatic access may be retained longer than standard user data for security analysis, abuse prevention, and legal compliance purposes.
Noted by a second reader on 2026-10-08.
LangSmith records AI requests and responses, which may include prompts, AI answers and file excerpts.
LangChain, Inc. (LangSmith): Monitoring and debugging of AI features; records AI requests and responses, which may include prompts, AI answers, and file excerpts
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 4,051 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms of service (effective 2 October 2026) name VividEngine, LLC, doing business as Fast Technologies, 4747 Research Forest Dr., Ste 180-265, The Woodlands, TX 77381-4902.
The API answers at api.fast.io and the MCP server at mcp.fast.io, both on the vendor's domain.
fast.io/.well-known/security.txt returns 404, although fast.io/llms.txt lists it as the security contact.
No status page or changelog is linked from the home page, the developer hub, the docs or the Trust Centre.
rdap.org answered that no RDAP service is available for fast.io, so the registration date is blank.
The DPA binds only when signed by both parties, and the Trust Centre says it is executed with Enterprise Plus customers and on request.
Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-10 00:51 UTC
Probed every five minutes at https://mcp.fast.io/mcp/tools. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- github
MediaFire/fastio_cliv0.2.93, released 2026-10-08 - npm
@vividengine/fastio-cli0.2.93 - GitHub stars 1
- npm downloads a week 653
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| fast.io/pricing | pricing | 6 hours ago · 200 | no change seen |
| fast.io/privacy | privacy | 6 hours ago · 200 | no change seen |
| fast.io/terms | terms | 6 hours ago · 200 | no change seen |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/fast-io.json
Notable
- Three hosted MCP addresses fix the tool set.
/mcp/toolshas 35 named tools (39 with import and signing),/mcp/codehas 8 and/mcp/operationshas one tool per operation source - A new organisation must choose a paid plan before it can work, and until then resource endpoints answer HTTP 402 source
- Shares take a password of 4 to 128 characters, an
expiresdate and adownload_securitylevel of off, medium or high source - Uploads under 4 MB go in one request. Larger files are chunked with up to 3 chunks in parallel and CRC-32C checks, to a plan limit of 25, 50 or 100 GB source
- Content is stored in the United States on servers the vendor owns. Files uploaded through MCP are staged on Cloudflare, and AI functions send content to Google Cloud, Voyage AI and LangSmith source
- The Trust Centre lists Google CASA Assurance Level 1 and says a SOC 2 Type II audit is being prepared source
- Section 12 of the terms lets the vendor suspend programmatic access without notice and gives no guarantee of API availability, response times or backward compatibility source
- fast.io/llms.txt gives storage at 100 credits a GB and bandwidth at 212. The pricing page and agent guide give 150 and 400 source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 6.6 | |
No status page or incident history found on fast.io, the docs or the Trust Centre (0 + 5 for no readable history). An unauthenticated GET /current/system/status/ reports scheduled maintenance only. Rate limits are exposed in x-ve-limit-avail, x-ve-limit-max and x-ve-limit-expires headers, with no published numbers (5). 429 handling is documented with Retry-After, backoff, a retryable 503 and if_version_id compare-and-swap on uploads. Idempotency keys exist only on bug reports (13). No SLA. Section 12 of the terms gives no guarantee of API availability (0). The API and MCP server are sold as generally available (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 10.6 | |
No OpenAPI file. OPTIONS introspection returns parameter types and constraints on about 40 per cent of endpoints, and MCP tools answer action="describe". The hosted tool definitions were not read, because mcp.fast.io's robots.txt disallows /mcp (10). llms.txt on fast.io and api.fast.io, a Markdown twin for each reference section, agents.md and skill.md (10). Descriptions say when to use each tool and name the traps (17). Constraint tables and enums are documented, but MCP inputs route through one action parameter (9). Request and response examples and per-endpoint error tables (13). The API is version 1.0 under /current/, guides carry version numbers and dates, and no changelog was found (6). | |||
| Agent ergonomics | 13%16.2 | 11.9 | |
35 tools in named mode, 39 with import and signing (5). Added back 10 for the 8-tool code mode, read-only sessions that list no write tools and the CLI's --tools filter (15). Offset and cursor pagination, page_size of 100 to 500, filters and output=terse or markdown (20). Errors carry an HTTP status, a code, per-parameter messages and a recovery hint (18). The docs say every tool sets readOnlyHint, destructiveHint and idempotentHint, and uploads accept if_version_id. No general idempotency key (14). No SDK in any language, only the CLI, and workspace creation needs four required fields with literal permission strings (6). | |||
| Security & auth | 14%17.5 | 12.9 | |
OAuth 2.0 with PKCE (S256), dynamic client registration and consent to scopes, or revocable API keys scoped by entity and access mode with optional expiry (30). Read-only scopes, read and write tools kept apart, and confirm='true' on irreversible actions (18). Stored files are untrusted content. The docs flag intent text as untrusted and say AI works within the caller's permissions, with no wider guidance (6). An activity log on every plan, kept 30 to 365 days, with an actor on each record. CSV export and SIEM streaming are Enterprise only (13). security@fast.io, a SECURITY.md for the CLI and Google CASA Assurance Level 1. No SOC 2 report, no bug bounty and no security.txt (7). | |||
| Payments & pricing | 10%12.5 | 3.8 | |
No x402, MPP or L402. HTTP 402 signals a missing plan or spent credits and carries no payment terms (0). Plan prices and per-unit rates are public, $0.0001 a credit, 1.5 cents a GB-month of extra storage and 4 cents a GB of extra bandwidth (20). No free tier, and the 30-day trial needs a credit card (0). An agent can create an account with POST /current/user/ and no browser, but must verify an email address and select a paid plan before any work (10). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.1 | |
| CLI v0.2.93 on 8 October 2026 and MCP guide 2.92 on 7 October (30). Twelve CLI tags between 1 September and 8 October 2026 (20). No public changelog. Support runs through a contact page, Discord and a bug-report endpoint, and the CLI repository has no open issues and one star (7). The official CLI is current, there are no SDKs, and a search of the MCP registry for fastio and fast.io returned nothing (5). CI runs check, format and clippy, and Cargo.lock is committed (8). | |||
| Transparency & trusteditorial 70, provenance 51 | 7%8.8 | 5.3 | |
| Closed service under clear terms dated 2 October 2026. The CLI is Apache-2.0 (18). Privacy policy, a published DPA and a deletion policy with matching periods of 15, 30, 60 and 90 days, and a no-training statement. The DPA binds only once signed (26). Deprecations are flagged in the docs (Basic sign-in, QuickShare, 410 Gone for retired paths) without dates, and the terms disclaim backward compatibility (6). Sub-processor list with purposes and locations, and 15 days' notice of additions (20). | |||
| Negative events | ≤15 |
| -2 |
| Total | 55.2 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 22 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Fastio, or have the agent fetch /fixes/fast-io.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Fastio From Anchor Terminal's listing at https://www.anchorterminal.com/tools/fast-io, the October 2026 research run, assessed 9 October 2026. Grade C, 55.2 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Fastio: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Reliability, 33 out of 100, up to 13.4 more on the total Why it scored 33: No status page or incident history found on fast.io, the docs or the Trust Centre (0 + 5 for no readable history). An unauthenticated `GET /current/system/status/` reports scheduled maintenance only. Rate limits are exposed in `x-ve-limit-avail`, `x-ve-limit-max` and `x-ve-limit-expires` headers, with no published numbers (5). 429 handling is documented with `Retry-After`, backoff, a retryable 503 and `if_version_id` compare-and-swap on uploads. Idempotency keys exist only on bug reports (13). No SLA. Section 12 of the terms gives no guarantee of API availability (0). The API and MCP server are sold as generally available (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 2. Payments & pricing, 30 out of 100, up to 8.8 more on the total Why it scored 30: No x402, MPP or L402. HTTP 402 signals a missing plan or spent credits and carries no payment terms (0). Plan prices and per-unit rates are public, $0.0001 a credit, 1.5 cents a GB-month of extra storage and 4 cents a GB of extra bandwidth (20). No free tier, and the 30-day trial needs a credit card (0). An agent can create an account with `POST /current/user/` and no browser, but must verify an email address and select a paid plan before any work (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Schema & documentation, 65 out of 100, up to 5.7 more on the total Why it scored 65: No OpenAPI file. `OPTIONS` introspection returns parameter types and constraints on about 40 per cent of endpoints, and MCP tools answer `action="describe"`. The hosted tool definitions were not read, because mcp.fast.io's robots.txt disallows `/mcp` (10). llms.txt on fast.io and api.fast.io, a Markdown twin for each reference section, agents.md and skill.md (10). Descriptions say when to use each tool and name the traps (17). Constraint tables and enums are documented, but MCP inputs route through one `action` parameter (9). Request and response examples and per-endpoint error tables (13). The API is version 1.0 under `/current/`, guides carry version numbers and dates, and no changelog was found (6). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 4. Security & auth, 74 out of 100, up to 4.6 more on the total Why it scored 74: OAuth 2.0 with PKCE (S256), dynamic client registration and consent to scopes, or revocable API keys scoped by entity and access mode with optional expiry (30). Read-only scopes, read and write tools kept apart, and `confirm='true'` on irreversible actions (18). Stored files are untrusted content. The docs flag intent text as untrusted and say AI works within the caller's permissions, with no wider guidance (6). An activity log on every plan, kept 30 to 365 days, with an actor on each record. CSV export and SIEM streaming are Enterprise only (13). security@fast.io, a SECURITY.md for the CLI and Google CASA Assurance Level 1. No SOC 2 report, no bug bounty and no security.txt (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 5. Agent ergonomics, 73 out of 100, up to 4.4 more on the total Why it scored 73: 35 tools in named mode, 39 with import and signing (5). Added back 10 for the 8-tool code mode, read-only sessions that list no write tools and the CLI's `--tools` filter (15). Offset and cursor pagination, `page_size` of 100 to 500, filters and `output=terse` or `markdown` (20). Errors carry an HTTP status, a code, per-parameter messages and a recovery hint (18). The docs say every tool sets readOnlyHint, destructiveHint and idempotentHint, and uploads accept `if_version_id`. No general idempotency key (14). No SDK in any language, only the CLI, and workspace creation needs four required fields with literal permission strings (6). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 6. Transparency & trust, 61 out of 100, up to 3.4 more on the total Made of editorial 70, provenance 51. Why it scored 61: Closed service under clear terms dated 2 October 2026. The CLI is Apache-2.0 (18). Privacy policy, a published DPA and a deletion policy with matching periods of 15, 30, 60 and 90 days, and a no-training statement. The DPA binds only once signed (26). Deprecations are flagged in the docs (Basic sign-in, QuickShare, 410 Gone for retired paths) without dates, and the terms disclaim backward compatibility (6). Sub-processor list with purposes and locations, and 15 days' notice of additions (20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: fast.io, no registry record we could read (0 of 15) - Terms of service: read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points (6 of 10) - Status page: not found (0 of 10) - Changelog: not found (0 of 10) - security.txt: not found (0 of 10) ## 7. Maintenance & community, 70 out of 100, up to 2.6 more on the total Why it scored 70: CLI v0.2.93 on 8 October 2026 and MCP guide 2.92 on 7 October (30). Twelve CLI tags between 1 September and 8 October 2026 (20). No public changelog. Support runs through a contact page, Discord and a bug-report endpoint, and the CLI repository has no open issues and one star (7). The official CLI is current, there are no SDKs, and a search of the MCP registry for fastio and fast.io returned nothing (5). CI runs check, format and clippy, and Cargo.lock is committed (8). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - 2026-10-09. fast.io/llms.txt states storage at 100 credits a GB and bandwidth at 212, while the pricing page and the agent guide (version 1.40.0, 2 October 2026) give 150 and 400. The same file points to a security.txt that answers 404. An agent reading only llms.txt would understate cost by a third or more (-2). https://fast.io/llms.txt ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the hosted MCP server's tool definitions, input schemas and annotations. mcp.fast.io/robots.txt disallows `/mcp`, so no `initialize` or `tools/list` was sent, and the tool count and annotations come from skill.md and agents.md - unchecked: the domain registration date. rdap.org answered that no RDAP service exists for fast.io - unchecked: the auth, OAuth, storage and organisations reference pages, the data deletion policy page and the help centre, left unread to keep to the page budget - The terms (Section 3) forbid any robot or spider retrieving the Services except through the programmatic access of Section 12 or by public search engines. Recorded as a fact with no deduction. It matters before any probe is run - robots.txt answers. fast.io 200 and allows all, mcp.fast.io 200 and disallows `/mcp`, `/sse`, `/blob`, `/file`, api.fast.io 404, docs.fast.io 404, registry.npmjs.org and api.npmjs.org no rules, registry.modelcontextprotocol.io 404, rdap.org 400 - fast.io/llms.txt and api.fast.io/llms.txt carry lines addressed to AI models (read in full, do not summarise). They were treated as data - The lead was wrong on three points. The product is now written Fastio, the vendor is VividEngine, LLC (doing business as Fast Technologies), and the trial needs a card. The price of $9.99 a month and the MCP address were right - Whether the billing API lets an agent select a plan and pay with no browser was not established. The Trust Centre says payment runs on a Stripe-hosted checkout - The CLI repository sits under the MediaFire organisation on GitHub and was created on 5 September 2026. The Trust Centre describes the parent company as founded in 2006 with MediaFire users ## Weaknesses - No free tier. A new organisation answers HTTP 402 until a paid plan is chosen, and the 30-day trial needs a credit card - No status page, incident history or SLA found. The terms give no guarantee of API availability or backward compatibility - No OpenAPI file. `OPTIONS` introspection covers about 40 per cent of endpoints, and rate limits are published as headers without numbers - fast.io/llms.txt gives 100 credits a GB for storage and 212 for bandwidth. The pricing page and agent guide give 150 and 400 - No SOC 2 report yet (the Trust Centre says an audit is being prepared), no bug bounty, and `/.well-known/security.txt` answers 404 - The terms forbid robots and spiders outside the programmatic access of Section 12. This matters before any probe is run ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Connect to `https://mcp.fast.io/mcp/tools` for named tools or `https://mcp.fast.io/mcp/code` for the 8-tool code mode. The URL fixes the tool set for the session - Call `action="describe"` on a tool before first use. Parameters live there, not in the tool list - To update a file, upload again with the same parent folder and filename. Deleting first loses the version history - On 429 wait until `x-ve-limit-expires` or the `Retry-After` value. On 402 the organisation has no plan or no credits, so stop and tell the owner - Ask the owner for a key scoped to one workspace with `r` or `rw`. A key made without scopes carries `user:*:rw` across the account ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the hosted MCP server's tool definitions, input schemas and annotations. mcp.fast.io/robots.txt disallows
/mcp, so noinitializeortools/listwas sent, and the tool count and annotations come from skill.md and agents.md - unchecked: the domain registration date. rdap.org answered that no RDAP service exists for fast.io
- unchecked: the auth, OAuth, storage and organisations reference pages, the data deletion policy page and the help centre, left unread to keep to the page budget
- The terms (Section 3) forbid any robot or spider retrieving the Services except through the programmatic access of Section 12 or by public search engines. Recorded as a fact with no deduction. It matters before any probe is run
- robots.txt answers. fast.io 200 and allows all, mcp.fast.io 200 and disallows
/mcp,/sse,/blob,/file, api.fast.io 404, docs.fast.io 404, registry.npmjs.org and api.npmjs.org no rules, registry.modelcontextprotocol.io 404, rdap.org 400 - fast.io/llms.txt and api.fast.io/llms.txt carry lines addressed to AI models (read in full, do not summarise). They were treated as data
- The lead was wrong on three points. The product is now written Fastio, the vendor is VividEngine, LLC (doing business as Fast Technologies), and the trial needs a card. The price of $9.99 a month and the MCP address were right
- Whether the billing API lets an agent select a plan and pay with no browser was not established. The Trust Centre says payment runs on a Stripe-hosted checkout
- The CLI repository sits under the MediaFire organisation on GitHub and was created on 5 September 2026. The Trust Centre describes the parent company as founded in 2006 with MediaFire users
Sources 21
- home page fast.io · seen 2026-10-09
- llms.txt fast.io · seen 2026-10-09
- pricing fast.io · seen 2026-10-09
- terms of service fast.io · seen 2026-10-09
- privacy policy fast.io · seen 2026-10-09
- DPA fast.io · seen 2026-10-09
- sub-processors fast.io · seen 2026-10-09
- security page fast.io · seen 2026-10-09
- Trust Centre fast.io · seen 2026-10-09
- fair use policy fast.io · seen 2026-10-09
- developer hub fast.io · seen 2026-10-09
- agent guide fast.io · seen 2026-10-09
- API docs home docs.fast.io · seen 2026-10-09
- API reference (llms.txt) api.fast.io · seen 2026-10-09
- shares reference api.fast.io · seen 2026-10-09
- upload reference api.fast.io · seen 2026-10-09
- MCP server guide mcp.fast.io · seen 2026-10-09
- mcp.fast.io robots.txt, which disallows /mcp mcp.fast.io · seen 2026-10-09
- CLI repository, tags, CI and SECURITY.md (shallow clone) github.com · seen 2026-10-09
- npm package registry.npmjs.org · seen 2026-10-09
- MCP registry search registry.modelcontextprotocol.io · seen 2026-10-09
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Paid $9.99 / mo From $9.99 a month (Starter, 250 GB, 100,000 credits, 3 seats). Business is $49.99 and Enterprise $199.99. No free tier. Monthly plans start with a 30-day trial that needs a credit card and converts when the trial or its credits end. Usage past the allowance is billed at $0.0001 a credit, extra storage at 1.5 cents a GB-month and extra bandwidth at 4 cents a GB (https://fast.io/pricing/).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Starter plan | $9.99 | per month (plan) | 250 GB, 100,000 credits, 3 seats |
| Business plan | $49.99 | per month (plan) | 5 TB, 600,000 credits, 10 seats |
| Enterprise plan | $199.99 | per month (plan) | 25 TB, 3,000,000 credits, 30 seats |
| Additional storage | $0.015 | per GB per month | |
| Additional bandwidth | $0.04 | per GB of traffic | |
| Credit overage | $0.0001 | per credit | $10 per 100,000 credits |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/fast-io.xml, or this listing's score history at history.json.
Connect
Install
npm install -g @vividengine/fastio-cli
MCP client configuration
{
"mcpServers": {
"fastio": {
"args": [
"mcp"
],
"command": "fastio"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/fast-io
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Alternatives to Fastio
#13 of 14 in Best file storage and sharing APIs for AI agents · All 75 storage comparisons
Google Drive API + MCP ABox API + MCP BDropbox API + MCP BOneDrive and SharePoint files (Microsoft Graph) BAmazon S3 BBCloudflare R2 BB
Head to head Amazon S3 vs Fastio · Azure Blob Storage vs Fastio · Backblaze B2 vs Fastio · Cloudflare R2 vs Fastio · DigitalOcean Spaces vs Fastio · Fastio vs Tigris · Box API + MCP vs Fastio · Dropbox API + MCP vs Fastio · Fastio vs Google Drive API + MCP · Fastio vs OneDrive and SharePoint files (Microsoft Graph)
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Google Drive API + MCP Google | A | 79.6 | storage.drive storage.share | no |
| Box API + MCP Box | B | 69.4 | storage.drive storage.share | no |
| Dropbox API + MCP Dropbox | B | 68.2 | storage.drive storage.share | no |
| OneDrive and SharePoint files (Microsoft Graph) Microsoft | B | 65.3 | storage.drive storage.share | no |
| Amazon S3 Amazon Web Services | BB | 77.9 | storage.share | no |
| Cloudflare R2 Cloudflare | BB | 77.1 | storage.share | no |
Machine-readable
- JSON
/api/v1/tools/fast-io.json· historyhistory.json· badge/badges/fast-io.svg· changes feed/feeds/tools/fast-io.xml - Markdown
/tools/fast-io.md· slim/tools/fast-io.min.md(or sendAccept: text/markdown) - Fix list
/fixes/fast-io.md·/fixes/fast-io.json - From a terminal
anchor tool fast-io --md(the CLI) · over MCPget_tool {"slug": "fast-io"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/fast-io"><img src="https://www.anchorterminal.com/badges/fast-io.svg" alt="Fastio on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/fast-io)<a href="https://www.anchorterminal.com/tools/fast-io">Fastio on Anchor Terminal</a>It counts on a page on fast.io or one of its subdomains, or the README of github.com/MediaFire/fastio_cli.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "fast-io", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


