# Show HN: Artbucket – OSS brand assets and portals for humans and AI agents

> Source: <https://github.com/pwnera/artbucket>
> Published: 2026-10-04 07:49:50+00:00

**Your brand's source of truth, open source.**

Which logo is current? What colors should an agent use? Is this photo cleared for paid social in Germany?

Artbucket keeps a brand's assets, rules, rights and releases together, and gives the same answer to people, AI agents and code. People read it in the web app and on portals, agents query it over MCP, code consumes it through the API, the CLI and Git.

**Web app · MCP · REST API · CLI · Git**

[Try Artbucket Cloud](https://artbucket.io) · [Live brand page](https://brand.artbucket.io/) · [Docs](https://docs.artbucket.io) · [Run it yourself](#run-it-yourself)

Find the asset, ask whether it may run, get it at the size you need:

``` bash
$ npx artbucket search primary logo
{id}  logo-primary.svg  #logo #primary

$ npx artbucket check {spring-hero} --channel paid-social --territory DE
refused  Spring hero
  x Replaced by Summer hero
  x License expired after 2026-03-12
  → Summer hero  https://assets.example.com/a/{summer-hero}  (Its replacement)

$ npx artbucket url {id} --width 1200 --format webp
https://assets.example.com/a/{id}/w_1200,f_webp
```

Agents make the same calls over MCP (`search_assets`, `check_use`,
`rendition_url`), and code over the [REST API](https://docs.artbucket.io/developers/api) (`/api/v1`, with an OpenAPI
spec). The web app is a client of that API, with zero private endpoints, so
everything it does, you can script. See [May I use this?](https://docs.artbucket.io/guides/check) and the [CLI](https://docs.artbucket.io/developers/cli).

`/api/v1/mcp` is an MCP server. Give the URL to any agent: it opens a consent
screen where you pick what it may do (Suggest, Read or Edit), and the agent
gets a key bound to you, never more than you can do.

```
claude mcp add --transport http artbucket https://app.artbucket.io/api/v1/mcp
```

That is [Artbucket Cloud](https://artbucket.io); on your own server, use its URL. Then ask: *"Give me
the approved logo for a dark background."* The agent checks the use and gets
the brand's dark-background variant, as a URL at the size it needs.

The Claude Code plugin adds a skill that teaches the workflow (brand rules
first, a use check before publishing, provenance on anything generated):
`/plugin marketplace add pwnera/artbucket`, then
`/plugin install artbucket@artbucket`. Other agents: `npx skills add pwnera/artbucket`.
See [MCP](https://docs.artbucket.io/developers/mcp).

The whole core is here, free to self-host on Postgres and an S3-compatible bucket. Nothing held back, nothing to unlock, no telemetry. You need Node 22+, pnpm and Docker:

```
git clone https://github.com/pwnera/artbucket.git
cd artbucket
pnpm install
cp .env.example .env
docker compose up -d      # Postgres and S3-compatible storage
pnpm dev                  # migrates the database, then serves
```

Open [http://localhost:3000](http://localhost:3000) and make the first account: it is the admin of
everything. No Node on the machine? Set `BETTER_AUTH_SECRET` in `.env`
(`openssl rand -base64 32`) and run the published image with
`docker compose --profile app up -d`. The [quick start](https://docs.artbucket.io/quickstart) takes it from there.

To put it on a server, follow the guide for [Render](https://docs.artbucket.io/installation/render), [Docker Compose](https://docs.artbucket.io/installation/docker-compose),
[Docker](https://docs.artbucket.io/installation/docker), [Fly](https://docs.artbucket.io/installation/fly), [Kubernetes](https://docs.artbucket.io/installation/kubernetes), [Coolify](https://docs.artbucket.io/installation/coolify) or a [plain VPS](https://docs.artbucket.io/installation/vps). Any S3-compatible
storage works: AWS S3, Cloudflare R2, Backblaze B2, MinIO, Garage, SeaweedFS.

- **Assets: what exists.** The library: search in milliseconds at 100,000
assets, and any size or format from one original as a URL,`/a/{id}/w_1200,f_webp` , with no export and no duplicate.
- **Rules: how to use it.** Colors, type, logo rules and don'ts as typed
records with history, tied to the assets; guideline pages and design tokens
are drawn from them.
- **Rights: where it may run.** License, channels, territories, embargo and
last day of use on each asset. Ask before it runs: yes, or why not and what
to use instead.
- **Releases: what is current.** Release the brand like software, pin a
release, roll back. Portals and BrandHub show the release.
- **Access: who may use it.** Grants down to one asset, so an agency sees its
slice. Single sign-on in every install, and viewers are never counted.
- **Portals.** A press kit, partner hub or retailer portal on your own domain,
plus share and upload links for people without an account.
- **Review.** Uploads, tags and agent suggestions wait for a person's yes.
- **Provenance.** C2PA Content Credentials read on ingest and kept, IPTC/XMP
written back into the file on download. Your files leave with their metadata.
- **Brand as code.** The brand as YAML in a Git repository, changed on either
side and merged a rule at a time ([brand as code](https://docs.artbucket.io/guides/brand-as-code) ).
- **Insights.** What gets used, by whom, on which release, counted without
cookies.

Read [CONTRIBUTING.md](https://github.com/pwnera/artbucket/blob/main/CONTRIBUTING.md) first. Bug fixes go straight to a pull request; for
anything larger, open an issue before writing the code, since the roadmap is
opinionated on purpose. The load-bearing choices, and why, are in the
[decision records](https://github.com/pwnera/artbucket/blob/main/docs/decisions/index.mdx).

Built with Next.js, React, Postgres and Drizzle, sharp, better-auth and Tailwind. No monorepo, no job queue, no Redis, no search cluster.

```
pnpm test
pnpm typecheck
pnpm lint
```

Start with the [documentation](https://docs.artbucket.io). Questions and bugs go to
[GitHub issues](https://github.com/pwnera/artbucket/issues), with the version you run, what you did and what you expected.
Security reports never go in a public issue: see [SECURITY.md](https://github.com/pwnera/artbucket/blob/main/SECURITY.md).

[ROADMAP.md](https://github.com/pwnera/artbucket/blob/main/ROADMAP.md) has what shipped, what is in progress and what is deferred on
purpose. Artbucket is at v1: `/api/v1` and the MCP tools are frozen, and what
works against them keeps working on every 1.x release ([stability](https://docs.artbucket.io/developers/stability)).

[AGPL-3.0](https://github.com/pwnera/artbucket/blob/main/LICENSE), copyright Pwnera SAS. Run it, change it, self-host it, for
any purpose. If you offer a changed version as a network service, publish your
changes. Building a product on Artbucket, or need your own terms? Pwnera SAS
also licenses it commercially: [open an issue](https://github.com/pwnera/artbucket/issues) and ask. `ee/` is
reserved for commercial code. See [decision 0013](https://github.com/pwnera/artbucket/blob/main/docs/decisions/0013-agpl-and-cla.mdx).
