Paperclip’s Hugging Face MCP connector gives your AI agents tools to search repositories and inspect their metadata. Each tool can be Allowed, Ask first or Off.
Agents can reach public Hub content. Private or gated repositories require the authorizing account’s existing access.
What agents can do with Hugging Face
- Find models and inspect repository details
hub_repo_search·hub_repo_details - Compare dataset repository metadata
hub_repo_search·hub_repo_details - Find repositories for further evaluation
hub_repo_search·hub_repo_details
How to connect Hugging Face
- In Paperclip, open Connectors and select Hugging Face.
- On the Access step, choose the identity and which agents may use the connection.
- Select Sign in with Hugging Face and complete browser sign-in.
Hugging Face tools for agents5
Read 3
hf_fsWhen to use: Hugging Face Hub models, datasets, Spaces, collections, papers, daily papers, today's trending models, current paper leaderboard, docs, and repository files.
Full description
When to use: Hugging Face Hub models, datasets, Spaces, collections, papers, daily papers, today's trending models, current paper leaderboard, docs, and repository files. Examples: {"operations":[{"cmd":"ls","args":["hf://models/trending","--limit","10"]}]} {"operations":[{"cmd":"ls","args":["hf://papers/trending"]}]} {"operations":[{"cmd":"ls","args":["hf://papers/daily/latest"]}]} {"operations":[{"cmd":"cat","args":["hf://papers/2501.00001/paper.md"]}]} Use hf_fs for Hugging Face Hub filesystem operations. Call it with operations, an array of {cmd, args} items; multiple operations may be submitted together. Usage: {"operations":[{"cmd":"ls","args":["hf://models/org/repo"]}]} Grammar; each string below is one args array item: ls URI [--recursive] [--glob GLOB] [--type TYPE] [--sort SORT] [--limit N] cat URI [--offset N] [--max-bytes N] attach URI [--max-bytes N] stat URI find URI [--name GLOB] [--path GLOB] [--type TYPE] [--limit N] search URI [QUERY] [--type TYPE] [--sort SORT] [--tag TAG] [--kind mcp] [--limit N] COMMAND = ls|cat|attach|stat|find|search. TYPE = file|dir|repo|bucket|collection|paper|link. SORT = createdAt|downloads|likes|lastModified|likes30d|trendingScore|mainSize|id|trending|upvotes. URI is a canonical hf:// URI. QUERY and GLOB are each one string. Use search for resource discovery, not repository-content search; ls for a known directory, find for recursive file discovery by name/path (not file contents), stat for filesystem metadata or an uncertain target type, cat for text contents, and attach for a complete JPEG, PNG, or WebP image. When the request gives an exact text-file URI, use cat directly; do not add ls or stat first. stat does not read the contents of JSON, Markdown, or other text files. Search scopes: hf://models[/OWNER], hf://datasets[/OWNER], hf://spaces[/OWNER], hf://collections[/OWNER], hf://papers, and hf://docs[/...]. Repository and repository-file scopes are not supported: search a resource root or owner scope to discover resources; use find for file discovery within a repository or cat for a known text file. Paper and documentation search require QUERY. --tag (repeatable) and --kind are supported only on exactly hf://spaces, not owner scopes or other roots. The only valid --kind value is mcp, which selects MCP Spaces. Use ls hf://models/trending, hf://datasets/trending, hf://spaces/trending, or hf://papers/trending for trending listings. hf://papers/ID is a paper directory, not paper text. Use cat hf://papers/ID/paper.md for paper text and cat hf://papers/ID/metadata.json for metadata. No preliminary listing is needed for these known paths. Use ls hf://papers/ID to discover other resources. Omit --limit, --sort, and --type unless the request requires them. Limits and path-specific behavior are documented at hf://README.md. Issue one hf_fs call.
hub_repo_detailsGet details for one or more Hugging Face repos (model, dataset, or space).
Full description
Get details for one or more Hugging Face repos (model, dataset, or space). Auto-detects type unless specified. For datasets, use operations: overview, dataset_structure, dataset_preview. Use dataset_structure first to discover configs, splits, sizes, and schema. Use dataset_preview only when config and split are known, unless the dataset has a single config/split.
hub_repo_searchSearch Hugging Face repositories with a shared query interface.
Full description
Search Hugging Face repositories with a shared query interface. You can target models, datasets, spaces, or aggregate across multiple repo types in one call. Include links to repositories in your response.
Write 2
create_repoCreate a Hugging Face model, dataset, Space, or bucket repository using an hf:// destination URI.
Full description
Create a Hugging Face model, dataset, Space, or bucket repository using an hf:// destination URI. Set source_uri to duplicate an existing model, dataset, or Space server-side.
hf_jobsRemote compute for Hugging Face workflows.
Full description
Remote compute for Hugging Face workflows. Run Python/UV or Docker jobs to deeply analyze Hub datasets, repos, traces, models, and large files; compute trends/statistics; run batch inference/evaluation; or perform long-running work with installed libraries. Use for dataset/repo analysis prompts when local chat inspection is insufficient. Includes submit, logs, inspect, cancel, schedule, labels/names, and volume mounting. Minimal run: {"operation":"run","args":{"image":"python:3.12","command":["python","-c","print(123)"]}}. Command arrays are literal argv; strings tokenize quotes and escaping, not shell execution. For pipes, chaining, redirections, or variable expansion, explicitly use ["/bin/sh", "-lc", "..."] only if the image provides that shell. Help: {"operation":"run","args":{"help":true}}; full usage: {}. Follow up with logs or inspect using args: {"job_id":"<returned job ID>"}.
Tool availability and permissions
This list describes the reviewed tools. Your selected method, provider access and action permissions determine what agents can use.
These lists use a conservative permission policy. Read requires a provider read-only hint or a reviewed Paperclip read rule. Evidence that an action changes data or submits information elsewhere puts it in Write. Write also includes actions we cannot verify as read-only. Read describes the reviewed evidence; it does not guarantee that an action has no side effects. A connected account can group actions differently.
This list covers the built-in tools with dynamic Space tools turned off. Sandbox and optional write tools are excluded. Your selected tools, preferences and read-mcp scope can further limit availability. Published source code does not authorize an account.
Connection policies
Discovered actions follow the connection’s policies. Review their permissions. Set create_repo and hf_jobs to Ask first or Off unless agents need them; the requested read-mcp scope may further limit what your account exposes.
Hugging Face connector FAQ
Can I require approval for actions?
Set an action to Ask first to require human approval of each call or Off to prevent calls. Allowed actions run without approval. Read and Write grouping is separate from these settings.
What can agents reach in Hugging Face?
Agents can reach public Hub content. Private or gated repositories require the authorizing account’s existing access.
What do I need before connecting?
Use a Hugging Face account. Private organization repositories require membership and access.