All integrations

cloudlayer.io

DOCS & KNOWLEDGE · FILES & DOCS

PDF and image generation jobs, their assets, and storage configuration on their own key.

Acts as the person, not as itself

Each user connects their own account. Every call carries both identities — the agent and the person it is acting for — so the agent can never reach past what that individual can already do.

Credentials never touch the agent

Tokens live in the vault and attach server-side at call time. The agent holds a session, not a secret, and revoking access does not mean rotating a key.

Every call on the record

Who asked, which agent acted, which action ran, and the verdict that let it through — one audit trail across every integration, not one per vendor.

What an agent can do

Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.

cloudlayer_delete_storage_by_idWRITE

Delete an S3 delivery configuration and fall back to cloudlayer.io's own storage, via DELETE /v2/storage/{id}. THE ONE DESTRUCTIVE TOOL ON THIS PROVIDER, and what it destroys is the ROUTE rather than the files: cloudlayer.io answers `{"message": "Storage configuration deleted. Reverting to default cloud storage."}` and every file generated afterwards lands in cloudlayer.io's own storage instead of your bucket. Files ALREADY delivered to your bucket are yours and are untouched. WHAT IT REALLY COSTS is that the stored bucket credentials are gone -- restoring delivery means running 'Configure S3 storage delivery' again with the access key and secret, which cloudlayer.io will not give back (it returns them masked). It is marked destructive for that reason: nothing else on this surface removes stored configuration, and every downstream automation expecting files in that bucket stops getting them silently, because generation keeps succeeding.

api
cloudlayer_get_accountREAD

Read the account this connection authenticates as, with its plan and usage, via GET /v2/account. THE CALL TO MAKE BEFORE A BULK GENERATION, and this provider's health check -- it is the probe the hosted key-connect page uses. It reports `email`, `uid`, the `subscription` price id, whether it is `subActive`, and the usage that decides whether the next job will run: `calls`/`callsLimit`, `bytesTotal`/`bytesLimit`, `computeTimeTotal`/`computeTimeLimit`, `storageUsed`/`storageLimit`, and `totalJobs`/`successJobs`/`errorJobs`. `-1` in any limit means unlimited. THE SHAPE DEPENDS ON `subType`: a `limit` plan counts calls against `callsLimit`; a `usage` plan carries a `credit` balance instead and leaves the limits at -1. WHY IT IS WORTH CHECKING: cloudlayer answers 401 both for a bad key AND for an account that has exhausted its plan, so a connection that starts failing has two possible causes and this tool tells them apart -- a 200 here with `calls == callsLimit` is quota, not credentials.

api
cloudlayer_get_assetsREAD

List the files cloudlayer.io has generated and stored, newest first, via GET /v2/assets. An asset is a generated file. Each entry carries `id`, the `jobId` that produced it, `ext`, `type`, `size`, a `timestamp` and -- the field you usually want -- `url`, a PRE-AUTHENTICATED download link that works with no API key, whose lifetime depends on the account's storage configuration. THE REPLY IS A BARE JSON ARRAY, not an object wrapping one: there is no envelope and no `meta` page block. HOW MANY COME BACK IS UNSETTLED and this build will not pretend otherwise -- cloudlayer.io's endpoint reference documents `limit` (1-100) and `startAfterId`, while its API overview says these listings take no pagination parameters and always return the 10 most recent. Both were re-read 2026-09-25 and no cloudlayer.io key existed to test either. Send `limit` if you want more than 10, then CHECK how many arrived rather than assuming.

api
cloudlayer_get_assets_by_idREAD

Read one generated file's metadata, via GET /v2/assets/{id}. HOW YOU COLLECT AN ASYNCHRONOUS RESULT. A generation call returns a job id; once 'Get a job' reports `status: "success"`, this tool hands you the asset's `url` -- a pre-authenticated download link that needs no API key -- along with its `ext`, `type` and `size`. The link expires according to the account's storage configuration, so fetch it rather than storing it. This returns the asset's METADATA, never its bytes: a file is downloaded from `url`, not through this integration.

api
cloudlayer_get_jobsREAD

List recent generation jobs with their status and cost, newest first, via GET /v2/jobs. Every API call creates a job, so this is the audit and debugging view: `type` (`html-pdf`, `url-image`, ...), `status` (`pending`, `success`, `error`), `params` (what was sent, minus the html/template body), `size`, `processTime`, `apiCreditCost` and `workerName`. THE REPLY IS A BARE JSON ARRAY with no envelope and no `meta` block, and the same unsettled pagination applies as on 'List assets' -- `limit` and `startAfterId` are documented on the endpoint page and denied on the API overview, neither testable without a key, so check how many records actually came back. THE `apiKeyUsed` FIELD IS REMOVED BEFORE YOU SEE IT, and that is this integration's doing rather than cloudlayer.io's: the provider documents the field as carrying the API key that made the call, which is the same credential this connection authenticates with, so the connector replaces it with a marker. Nothing here can hand back the credential. Use `id` and `uid` to correlate jobs instead.

api
cloudlayer_get_jobs_by_idREAD

Read one generation job's status and cost, via GET /v2/jobs/{id}. THE POLLING TOOL. Every generation call on this provider is asynchronous by default and answers a job id; call this with that id until `status` leaves `pending`. `success` means the file exists -- go to 'Get an asset' for its download `url`. `error` means it does not, and `params`, `processTime` and `workerName` are what you debug with. The id is a millisecond epoch as a STRING (`"1705312200000"`). `apiCreditCost` says what the job actually cost. LIKE THE LISTING, this reply has its `apiKeyUsed` field replaced by a marker before it reaches you: cloudlayer.io documents that field as the API key the job was created with.

api
cloudlayer_get_storageREAD

Read the account's current S3 delivery configuration, via GET /v2/storage. Returns `title`, `bucket`, `region`, `endpoint` and the credentials in masked form -- cloudlayer.io truncates `accessKeyId` to `AKIA...MPLE` and replaces `secretAccessKey` with `****`, and this integration replaces the secret's value again on the way out. Use it to confirm WHICH bucket generated files are being delivered to before a bulk run; the vendor notes that a failing upload does not fail the generation -- the file silently falls back to cloudlayer.io's own cloud storage -- so 'my files are not in my bucket' is a configuration question this tool answers. An account with no user storage configured is on the default cloud storage.

api
cloudlayer_get_storage_by_idREAD

Read one S3 delivery configuration by its id, via GET /v2/storage/{id}. The same record 'Get the storage configuration' returns, addressed by the `id` that 'Configure S3 storage delivery' answered with -- which is also the id 'Remove the storage configuration' needs. Credentials come back masked by cloudlayer.io and the secret is replaced again by this integration. An id that does not exist answers 404 rather than an empty record.

api
cloudlayer_get_url_imageWRITE

Screenshot a web page with only its address, via GET /v2/url/image?url=... THE CONVENIENCE FORM of 'Generate an image from a URL': the URL and a timeout, nothing else -- no `imageType`, no viewport, no wait condition, no cookies. Use the POST tool when any of those matter; this one always renders cloudlayer.io's defaults. A GET that WRITES: it creates a job, spends plan credits and stores an asset, which is why it is grouped with the writes. Asynchronous by default -- poll 'Get a job', then read the download `url` from 'Get an asset'.

api
cloudlayer_get_url_pdfWRITE

Capture a web page as a PDF with only its address, via GET /v2/url/pdf?url=... THE CONVENIENCE FORM of 'Generate a PDF from a URL': it takes the URL and a timeout and nothing else. Use the POST tool when you need a page size, margins, a wait condition, cookies or HTTP Basic credentials -- none of which can be expressed here. It is still a GENERATION call despite being a GET: it creates a job, spends plan credits and stores an asset, which is why it is grouped with the writes. Asynchronous by default, answering `{"id": ..., "status": "pending"}`; poll 'Get a job', then read the file's download `url` from 'Get an asset'.

api
cloudlayer_post_html_imageWRITE

Render base64-encoded HTML into a PNG, JPEG, WebP or SVG, via POST /v2/html/image. The image sibling of 'Generate a PDF from HTML', with the same asynchronous contract: it answers `{"id": ..., "status": "pending"}`, you poll 'Get a job', then 'Get an asset' hands you the file's pre-authenticated download `url`. `html` MUST BE BASE64. The image options replace the PDF ones: `imageType` (`png` by default), `quality` for the lossy formats, `transparent` (PNG and WebP only) and `trim` to crop surrounding whitespace. Spends plan credits and, by default, account storage.

api
cloudlayer_post_html_pdfWRITE

Render base64-encoded HTML into a PDF, via POST /v2/html/pdf. ASYNCHRONOUS BY DEFAULT: it answers `{"id": "1705312200000", "status": "pending"}` straight away and the file appears later. Poll 'Get a job' with that id until `status` is `success` (or `error`), then 'List assets' / 'Get an asset' gives you the file's `url`, which is a pre-authenticated download link that needs no API key. Supply a `webhook` instead if you would rather be told than poll. `html` MUST BE BASE64 -- raw HTML answers 400 naming the field, which reads like you omitted it. Every capture and PDF option (`format`, `margin`, `waitUntil`, `printBackground`, header and footer templates) rides on the same JSON object; the research ledger splits them into several bodies, which are documentation tables rather than alternatives. This call SPENDS PLAN CREDITS and, with the default `storage: true`, consumes account storage.

api
cloudlayer_post_storageWRITE

Point cloudlayer.io at your own S3-compatible bucket for generated files, via POST /v2/storage. CREATE OR REPLACE, not create-only: cloudlayer.io's own reference titles this 'Create or Update Storage Configuration', so sending it again with new credentials is how a key rotation is applied -- and how an existing configuration is overwritten by accident. THIS TOOL TAKES YOUR CLOUD CREDENTIALS IN ITS BODY: `accessKeyId` and `secretAccessKey` for the bucket, which cloudlayer.io then holds in order to write to it. Grant the narrowest IAM policy that works -- the vendor's own example is `s3:PutObject` and `s3:PutObjectAcl` on one bucket ARN -- and use a dedicated user, never root credentials. Works with AWS S3 (omit `endpoint`), and with Google Cloud Storage, DigitalOcean Spaces, Backblaze B2, MinIO, Wasabi and Cloudflare R2 by naming their `endpoint`. PLAN GATED: cloudlayer.io offers user storage on its Growth and Business plans, so a smaller account gets a refusal from the provider rather than from this integration. The reply is just `{"title": ..., "id": ...}`; read it back with 'Get the storage configuration'.

api
cloudlayer_post_template_imageWRITE

Render a saved or inline Nunjucks template into an image, via POST /v2/template/image. The image sibling of 'Generate a PDF from a template', for repeatable graphics -- social cards, badges, certificates -- where the layout is fixed and only `data` changes. Give EITHER `templateId` OR `template` (base64), never both. The multipart file-upload variant cloudlayer.io also accepts is not offered here; base64 reaches the same result. Image options apply (`imageType`, `quality`, `transparent`, `trim`). Asynchronous by default; poll 'Get a job', then read the file's `url` from 'Get an asset'.

api
cloudlayer_post_template_pdfWRITE

Render a saved or inline Nunjucks template into a PDF, via POST /v2/template/pdf. THE TOOL FOR REPEATABLE DOCUMENTS -- invoices, certificates, statements: the layout lives in the template and only `data` changes per document. Give EITHER `templateId` (a template saved in your cloudlayer.io gallery) OR `template` (the template inline as a base64 string), never both. `data` is a JSON OBJECT of the values the template renders. cloudlayer.io also accepts a template as an uploaded FILE on a multipart body; that variant is not offered here -- a native tool's body is JSON and this platform has no file channel on this surface -- and base64 reaches the same result. Asynchronous by default; poll 'Get a job' and read the file's `url` from 'Get an asset'.

api
cloudlayer_post_url_imageWRITE

Screenshot a web page with the full option set, via POST /v2/url/image. The full form: `imageType`, `quality`, `transparent`, `trim`, a `viewPort` to emulate a device, `waitUntil`/`waitForSelector` and `autoScroll` for lazy-loaded content. THE SAME TWO FIELDS CARRY SOMEBODY ELSE'S SECRETS as on the PDF sibling: `authentication` (HTTP Basic credentials for the target site) and `cookies` (a live session) travel to cloudlayer.io in this body so its browser can reach a page behind a login. Asynchronous by default -- poll 'Get a job', then 'Get an asset' for the download `url`. There is no `batch` here; combining several captures into one file is a PDF-only feature.

api
cloudlayer_post_url_pdfWRITE

Capture a web page as a PDF with the full option set, via POST /v2/url/pdf. The full form: page size, margins, header and footer templates, `waitUntil`/`waitForSelector`, `autoScroll` for lazy-loaded content, and `batch` to fold several URLs into ONE multi-page PDF. TWO FIELDS CARRY SOMEBODY ELSE'S SECRETS and are worth a second thought before you send them: `authentication` (HTTP Basic credentials for the target site) and `cookies` (a live session) both travel to cloudlayer.io in this body so its browser can reach a page behind a login. Asynchronous by default -- poll 'Get a job', then take the download `url` from 'Get an asset'. Spends plan credits and, by default, account storage.

api

Put cloudlayer.io behind one governed endpoint.

Same permissions, same audit trail, whatever else you connect next.