---
title: "save_project"
description: "Keep the strip: save it as an editable ShotOps project with a URL to hand back."
canonical: "https://shotops.dev/docs/mcp/reference/save_project"
last_updated: "2026-09-07"
shotops_mcp_version: "0.9.6"
result_contract_version: "2.0.0"
---
# save_project

Keep the strip: save it as an editable ShotOps project with a URL to hand back.

## What it does

- Writes
- Destructive
- Account required

The persistence step, and it happens when the user asks for it. It builds a structure and look record rather than pixels, so it is fast and never hits a render timeout, and it returns a URL the user opens in the web app. Omitting the project id creates a new project; passing one updates that project in place. Reach for it once someone wants the work preserved, shared, reused or kept editable — a request for images or a bundle is not that, and a render already told them nothing was saved and offered this call.

You can ask: “Save this Tidebook strip as a new project I can reopen later.”

Annotated destructive because passing an existing project id overwrites that project’s structure. Creating a new one is not destructive; the annotation covers the worst case, as the MCP spec asks.

## Input

- `screenshots`arrayrequiredat least 1 itemat most 10 items Screenshots in App Store display order (1–10). Preferred common form: a FLAT array, where each entry becomes its own App Store panel, e.g. [{ "ref": "first" }, { "ref": "second" }]. Advanced multi-phone form: a NESTED array of slots, where several entries inside one slot are composited into that single panel, e.g. [[{ "ref": "left" }, { "ref": "right" }], [{ "ref": "third" }]]. Each screenshot entry is EITHER an inline base64 PNG string (capped at 3MB of image data — a full-resolution screenshot is 3-4MB and will NOT fit; use a ref for anything real), OR { "ref": "..." } from request_screenshot_upload, OR { "url": "https://..." }, OR (local stdio mode only) { "path": "/abs/or/relative/path.png" } to read a file straight off disk, OR { "locales": { "<locale>": <any of those> } } to vary that screenshot per App Store locale (missing locales fall back to the en-US variant). Prefer ref/url for real screenshots so the bytes never transit this conversation. NOTE: save_project does not render — it uses only each slot's SHAPE (phones per panel) and each entry's `name` (source filename, for re-load matching). The image bytes are never fetched or stored, so pass the same entries you rendered with (esp. their `name`s). each item any The published schema does not constrain this element, on purpose — a malformed entry comes back as a sentence instead of a stacked union error. What the server re-validates against is below.
- `panelPresetId`stringoptional App Store screenshot size. Default r69 (6.9″ iPhone, 1290×2796). iPhone sizes only — iPad is not rendered yet. one of`r69``r65``r55`
- `outputs`arrayoptionalat least 1 itemat most 2 items The target DEVICES this project is for — iphone-6-9 (1290×2796) and/or iphone-6-5 (1242×2688), in the order they should be offered. On save_project this is saved ON the project (the same Output list the web app shows) and the first entry becomes the previewed size unless `panelPresetId` says otherwise; on render_project it OVERRIDES the saved set for this call. Omit it and the project's saved outputs are used unchanged. each item string one of`iphone-6-9``iphone-6-5`
- `look`objectoptional A ShotOps "look" — per-DEVICE styling + background, exactly as read_look returns it. Its shots[] give every screenshot/phone its own styling (including multiple phones in one panel); style.shotLook is one shared style for all. COMPOSES with `style`: pass a look for the devices + `style.captions` for the words in ONE render. Validated — unknown keys are rejected (call describe_look for the full field catalog).
  - `schema`numberoptional Look schema version. The server stamps it on every save (save_look); read_look returns it. Any input value is ignored — never set it yourself.
  - `panelPresetId`stringoptional Canvas size preset, e.g. r69 = 1290×2796. Default r69.
  - `bgMode`stringoptional One gradient across the strip, or a flat colour per panel. Default gradient. one of`gradient``perPanel`
  - `gradientStops`arrayoptionalat least 1 item Canonical gradient stops — { color (hex), at (0–1 position) } — wins over gradientFrom/gradientTo/gradientDir when present. Read this back for the full stop list a Studio-authored look may carry; the trio below is only ever a two-stop summary. each item object - `color`stringrequired - `at`numberrequiredmin 0max 1
  - `gradientAngle`numberoptional Canonical gradient angle in degrees, clockwise from "to top" (CSS convention: 90 = right, 180 = down, the gradientDir:"vertical" equivalent). Paired with gradientStops.
  - `gradientFrom`stringoptional Gradient start (hex) — a DERIVED mirror of gradientStops[0], re-derived from the stops on every render and reload. Setting it ALONE changes nothing: set gradientStops to change the backdrop. Default #1b1b2e.
  - `gradientTo`stringoptional Gradient end (hex) — a DERIVED mirror of the last gradientStops entry, re-derived from the stops on every render and reload. Setting it ALONE changes nothing: set gradientStops to change the backdrop. Default #0a0a14.
  - `gradientDir`stringoptional A DERIVED mirror of gradientAngle (nearest axis), re-derived on every render and reload. Setting it ALONE changes nothing: set gradientAngle to turn the gradient. Default vertical. one of`horizontal``vertical`
  - `panelColors`objectoptional Per-panel flat colours (mode perPanel), keyed by panel id.
  - `shadow`booleanoptional Drop shadow under the phones. Default true.
  - `floorReflection`booleanoptional Flipped, faded floor reflection under each phone. Default false.
  - `panelBackgrounds`objectoptional Per-frame background overrides keyed by panel id (web-authored; agents rarely set these).
  - `captionStyles`objectoptional Per-panel caption STYLE arrays keyed by panel id (styling only, no words — for caption text pass style.captions).
  - `shots`arrayoptionalat most 60 items One entry per SCREENSHOT/DEVICE, flattened in panel order. Each entry has its OWN `look`. For screenshots:[[left,right]], pass two shots with the SAME panelId ("panel-1") to give the two devices different colours/materials/angles. This is how a look varies devices; style.shotLook cannot. each item object - `panelId`stringoptional Panel containing this screenshot/device. Panels are panel-1…panel-N in slot order; REPEAT the same panelId for multiple devices in one panel. A saved look’s own ids are remapped by ordinal. - `look`objectoptional This individual screenshot/device’s styling — the SAME fields as style.shotLook. - `angle`stringoptional Camera preset. Default front. one of`front``left``right` - `cameraPos`one of 2 shapesoptional Manual camera position override; null/omit = use the angle preset. 1`x` - `x`numberrequired - `y`numberrequired - `z`numberrequired 2`null` - `roll`string or numberoptional -45–45° clock-hand tilt. Default 0. - `phoneHeight`string or numberoptional -45–45° clock-hand tilt. Default 0. - `hOffset`string or numberoptional -45–45° clock-hand tilt. Default 0. - `vOffset`string or numberoptional -45–45° clock-hand tilt. Default 0. - `material`stringoptional Device body. Default real. one of`real``clay` - `colorway`stringoptional Body colour (material "real"). Default silver. These are finish SLOTS — each device binds its own real finish (silver = iPhone Silver / Pixel Moonstone). "green" is Pixel-only (Jade); other devices fall back to their first finish. one of`orange``blue``silver``green``custom` - `customColor`stringoptional Hex body colour when colorway is "custom". - `finish`string or numberoptional -45–45° clock-hand tilt. Default 0. - `clearcoat`string or numberoptional -45–45° clock-hand tilt. Default 0. - `clayTone`stringoptional Clay tone (material "clay"). Default grey. one of`grey``white``charcoal``custom` - `clayCustom`stringoptional Hex clay colour when clayTone is "custom". - `flatScreen`booleanoptional Render the screen flat (no curvature). Default false. - `glare`booleanoptional Screen glare. Default false. - `lighting`booleanoptional Scene lighting. Default true. - `reflections`booleanoptional Body reflections. Default false. - `clipToFrame`booleanoptional Clip this complete device composite to its owning frame. Default false (overflow allowed).
- `style`objectoptional Structured styling — the discoverable path (call describe_look for the full field catalog + defaults). `layout` is the fastest way in: one named composition that settles the headline region and the device placement together, with your explicit fields still winning over it. COMPOSES with `look`: pass BOTH to get per-device styling from the `look` AND captions from `style.captions` in ONE render (every real App Store strip). When a `look` is also given it supplies the devices + background, so `style.shotLook`/`style.background` are ignored (a note says so) — use `style` for `captions` then. Alone, `style` styles every phone identically + captions. Also composes with `useSavedLook`/`version`.
  - `layout`stringoptional Panel COMPOSITION template — sets the headline’s reserved region and the device’s placement, camera pose, and roll in one choice. "standard" — Headline on top, whole device below it, nothing cropped. The safe default. Reserves 2 headline lines (~36 characters). Character: [safe]. "bleed" — Room for a longer headline, device running off the bottom edge. What the market looks like. Reserves 4 headline lines (~72 characters). Character: [conventional]. "top-bleed" — Device running off the TOP edge, headline underneath it. Inverts the usual reading order. Reserves 4 headline lines (~72 characters). Character: [expressive]. PRECEDENCE: the template expands FIRST into shotLook.phoneHeight/shotLook.hOffset/shotLook.vOffset/shotLook.angle/shotLook.cameraPos/shotLook.roll and captions[].sizePt/captions[].maxWidth/captions[].reserveLines/captions[].band, and THEN any of those fields you pass EXPLICITLY overrides it — so { layout: "bleed", shotLook: { vOffset: "45" } } renders bleed seated at 45, not at the template’s 38. That is how you say "bleed, but a bit lower" without the template silently winning. The reserved region is held at FULL SIZE whether or not the headline fills it, which is what makes every panel in a swiped set land on the same line. Nothing stores the template id: it is discarded at expansion, so a saved project and read_look carry only the expanded values. one of`standard``bleed``top-bleed`
  - `shotLook`objectoptional This individual screenshot/device’s styling — the SAME fields as style.shotLook.
    - `angle`stringoptional Camera preset. Default front. one of`front``left``right`
    - `cameraPos`one of 2 shapesoptional Manual camera position override; null/omit = use the angle preset. 1`x` - `x`numberrequired - `y`numberrequired - `z`numberrequired 2`null`
    - `roll`string or numberoptional -45–45° clock-hand tilt. Default 0.
    - `phoneHeight`string or numberoptional -45–45° clock-hand tilt. Default 0.
    - `hOffset`string or numberoptional -45–45° clock-hand tilt. Default 0.
    - `vOffset`string or numberoptional -45–45° clock-hand tilt. Default 0.
    - `material`stringoptional Device body. Default real. one of`real``clay`
    - `colorway`stringoptional Body colour (material "real"). Default silver. These are finish SLOTS — each device binds its own real finish (silver = iPhone Silver / Pixel Moonstone). "green" is Pixel-only (Jade); other devices fall back to their first finish. one of`orange``blue``silver``green``custom`
    - `customColor`stringoptional Hex body colour when colorway is "custom".
    - `finish`string or numberoptional -45–45° clock-hand tilt. Default 0.
    - `clearcoat`string or numberoptional -45–45° clock-hand tilt. Default 0.
    - `clayTone`stringoptional Clay tone (material "clay"). Default grey. one of`grey``white``charcoal``custom`
    - `clayCustom`stringoptional Hex clay colour when clayTone is "custom".
    - `flatScreen`booleanoptional Render the screen flat (no curvature). Default false.
    - `glare`booleanoptional Screen glare. Default false.
    - `lighting`booleanoptional Scene lighting. Default true.
    - `reflections`booleanoptional Body reflections. Default false.
    - `clipToFrame`booleanoptional Clip this complete device composite to its owning frame. Default false (overflow allowed).
  - `background`objectoptional
    - `mode`stringoptional One gradient across the strip, or a flat colour per panel. one of`gradient``perPanel`
    - `stops`arrayoptionalat least 1 item Gradient colour stops, in order along the gradient line — { color (hex), at (0–1 position; 0 = line start, 1 = line end) }. Two stops is the classic top/bottom gradient, more make a multi-colour sweep, one stop is a solid fill. Default a two-stop navy gradient: [{color:"#1b1b2e",at:0},{color:"#0a0a14",at:1}]. each item object - `color`stringrequired - `at`numberrequiredmin 0max 1
    - `angle`numberoptional Gradient angle in degrees, clockwise from "to top" — CSS `linear-gradient()` convention: 90 = to right, 180 = to bottom (the old "vertical" default, and this field’s own default), 270 = to left. Any value folds into 0–360.
    - `panelColors`arrayoptionalat most 10 items Per-panel flat colours (mode "perPanel"), one entry per slot in order; null = default. each item string or null
    - `shadow`booleanoptional Drop shadow under the phones. Default true.
    - `floorReflection`booleanoptional Flipped, faded floor reflection under each phone. Default false.
  - `captions`arrayoptionalat most 10 items One entry PER PANEL in slot order; null = no caption on that panel. An entry is EITHER a single caption object OR an array of caption layers (stacked, in order) on that panel. Alongside a `look`, an entry is a DELTA: every style field you set wins, every field you leave out keeps the look’s styling for that panel and layer — which is what lets you re-render a `layout.correctedLook` without restating your captions. each item one of 2 shapes 1`one of 2 shapes` 1`object` - `fontId`stringoptional Bundled font. Default inter. one of`inter``manrope``poppins``fraunces``space-grotesk` - `sizePt`numberoptionalgreater than 0 Font size in iOS points (preset-independent), 20–120. Default 32. Outside that range it is clamped to it and the response says so. - `color`stringoptional Text colour (hex). Default FFFFFF. - `align`stringoptional Default center. one of`left``center``right` - `anchor`objectoptional Normalized 0–1 position of the caption on the panel. Default {x:0.5, y:0.06}. - `x`numberoptionalmin 0max 1 - `y`numberoptionalmin 0max 1 - `maxWidth`numberoptionalgreater than 0 Wrap width as a fraction of the panel, 0.1–1. Default 0.86. Outside that range it is clamped to it and the response says so. - `reserveLines`integeroptionalmin 1max 8 How many lines of headline room to HOLD, whether or not the text fills it. A shorter headline is centred in the reserved space rather than leaving all the slack beneath it, and the space is held so every panel in the strip lands on the same line. Omit to let the caption be exactly as tall as its text. Set for you by style.layout. - `band`stringoptional Put this caption in the BOTTOM band, growing upward from the lower margin, instead of the default top band. This is how a headline sits UNDER the device (see the top-bleed layout). The caption stays auto-placed — it still reflows and still stacks; use this rather than pinning an anchor, which would freeze it. one of`bottom` - `bandInset`numberoptionalmin 0max 0.5 Inset of the auto caption band from its own panel edge, as a 0–0.5 fraction of panel height. The top band measures down; the bottom band mirrors it upward. Default 0.06. - `lineHeight`numberoptionalmin 0.5max 3 Line spacing as a multiple of font size, 0.5–3. Default 1.2. - `bandCenter`numberoptionalmin 0max 1 Horizontal reference of the auto caption block as a 0–1 fraction of panel width. Text alignment decides which edge sits there. Default 0.5. - `text`stringoptionalat most 200 characters The headline — per-RENDER input, never stored in a look. - `subtitle`stringoptionalat most 300 characters Optional subtitle under the headline — also per-render input. 2`array` each item object - `fontId`stringoptional Bundled font. Default inter. one of`inter``manrope``poppins``fraunces``space-grotesk` - `sizePt`numberoptionalgreater than 0 Font size in iOS points (preset-independent), 20–120. Default 32. Outside that range it is clamped to it and the response says so. - `color`stringoptional Text colour (hex). Default FFFFFF. - `align`stringoptional Default center. one of`left``center``right` - `anchor`objectoptional Normalized 0–1 position of the caption on the panel. Default {x:0.5, y:0.06}. - `x`numberoptionalmin 0max 1 - `y`numberoptionalmin 0max 1 - `maxWidth`numberoptionalgreater than 0 Wrap width as a fraction of the panel, 0.1–1. Default 0.86. Outside that range it is clamped to it and the response says so. - `reserveLines`integeroptionalmin 1max 8 How many lines of headline room to HOLD, whether or not the text fills it. A shorter headline is centred in the reserved space rather than leaving all the slack beneath it, and the space is held so every panel in the strip lands on the same line. Omit to let the caption be exactly as tall as its text. Set for you by style.layout. - `band`stringoptional Put this caption in the BOTTOM band, growing upward from the lower margin, instead of the default top band. This is how a headline sits UNDER the device (see the top-bleed layout). The caption stays auto-placed — it still reflows and still stacks; use this rather than pinning an anchor, which would freeze it. one of`bottom` - `bandInset`numberoptionalmin 0max 0.5 Inset of the auto caption band from its own panel edge, as a 0–0.5 fraction of panel height. The top band measures down; the bottom band mirrors it upward. Default 0.06. - `lineHeight`numberoptionalmin 0.5max 3 Line spacing as a multiple of font size, 0.5–3. Default 1.2. - `bandCenter`numberoptionalmin 0max 1 Horizontal reference of the auto caption block as a 0–1 fraction of panel width. Text alignment decides which edge sits there. Default 0.5. - `text`stringoptionalat most 200 characters The headline — per-RENDER input, never stored in a look. - `subtitle`stringoptionalat most 300 characters Optional subtitle under the headline — also per-render input. 2`null`
- `useSavedLook`booleanoptional If true, style the strip with the project's saved look (ignored when `look`/`style` is given).
- `project`stringoptionalat least 1 character Which ShotOps project to target: its id (as returned by read_look/save_project), OR its NAME as the user says it — matched exactly, ignoring case and surrounding spaces. Omit = your most recently edited project. A name that matches none or several is refused with the account's projects listed, never resolved by guessing.
- `version`integeroptionalmin 1 Render a specific saved look version of the project (implies the saved look). Omit = the project's HELD version if one is held (hold_look), else the latest saved look.
- `locale`stringoptional App Store locale, e.g. "de-DE" (default en-US). Labels the render, selects which { "locales": … } screenshot variants render, and, for emit_bundle, selects the fastlane screenshots folder. Does not select caption text — pass the copy for this locale yourself via `style.captions[].text` (see the README's `captions.<locale>.json` convention).
- `projectName`stringoptional Name for the created project (when createProject makes a new one). Default "ShotOps render".
- `sourceDir`stringoptional Advanced: the on-disk folder these screenshots were read from (only meaningful when they came from local { path } entries on the SAME machine). When set, the saved project remembers this folder as its screen source (kind: "local-path") instead of just filenames. Used by the local stdio bridge — most callers should omit it.

## What the server actually accepts

The published schema above deliberately accepts a wider shape for `screenshots`, so a malformed entry comes back as a sentence rather than a stack of union errors. The server re-validates against these shapes and refuses anything else.

- `screenshots`one of 2 shapesrequired Screenshots in App Store display order (1–10). Preferred common form: a FLAT array, where each entry becomes its own App Store panel, e.g. [{ "ref": "first" }, { "ref": "second" }]. Advanced multi-phone form: a NESTED array of slots, where several entries inside one slot are composited into that single panel, e.g. [[{ "ref": "left" }, { "ref": "right" }], [{ "ref": "third" }]]. Each screenshot entry is EITHER an inline base64 PNG string (capped at 3MB of image data — a full-resolution screenshot is 3-4MB and will NOT fit; use a ref for anything real), OR { "ref": "..." } from request_screenshot_upload, OR { "url": "https://..." }, OR (local stdio mode only) { "path": "/abs/or/relative/path.png" } to read a file straight off disk, OR { "locales": { "<locale>": <any of those> } } to vary that screenshot per App Store locale (missing locales fall back to the en-US variant). Prefer ref/url for real screenshots so the bytes never transit this conversation. NOTE: save_project does not render — it uses only each slot's SHAPE (phones per panel) and each entry's `name` (source filename, for re-load matching). The image bytes are never fetched or stored, so pass the same entries you rendered with (esp. their `name`s). 1`array` Preferred: one screenshot entry per App Store panel, in display order. each item one of 5 shapes 1`string` Inline base64-encoded PNG (no "data:" prefix). Capped at 3MB of image data — a real full-resolution screenshot is 3-4MB and will NOT fit. Use request_screenshot_upload and pass { ref } instead; inline is for thumbnails and tests. 2`ref` A ref returned by request_screenshot_upload — resolved server-side, never re-sent inline. - `ref`stringrequiredat least 1 character - `name`stringoptionalat most 200 characters The screenshot's original filename (e.g. "03_statistics.png"). Pass it so that, if this render is saved as a project, the user's own screenshots folder re-loads exactly this file by name. Optional if the ref already carries a name (from request_screenshot_upload({ names })); omit entirely and the record falls back to a positional name (screen-N.png). 3`url` An https URL to a PNG or JPEG — fetched server-side, converted to PNG when needed (no redirects, ~20MB cap). - `url`stringrequiredat least 1 character - `name`stringoptionalat most 200 characters The screenshot's original filename (e.g. "03_statistics.png"). Pass it so that, if this render is saved as a project, the user's own screenshots folder re-loads exactly this file by name. Optional if the ref already carries a name (from request_screenshot_upload({ names })); omit entirely and the record falls back to a positional name (screen-N.png). 4`path` A local filesystem path to a PNG, read straight off disk — ONLY available over the local stdio server (npx shotops-mcp); the hosted server rejects this entry shape. - `path`stringrequiredat least 1 character - `name`stringoptionalat most 200 characters The screenshot's original filename (e.g. "03_statistics.png"). Pass it so that, if this render is saved as a project, the user's own screenshots folder re-loads exactly this file by name. Optional if the ref already carries a name (from request_screenshot_upload({ names })); omit entirely and the record falls back to a positional name (screen-N.png). 5`locales` Per-locale variants of ONE screenshot: { "locales": { "en-US": <entry>, "de-DE": <entry> } } (each variant is an inline base64 / ref / url / path entry). render_strip picks the top-level `locale`'s variant; emit_bundle with `locales` renders/packages every listed locale. A locale with no variant of its own falls back to the en-US variant (else the first declared), so you can localize only some screenshots. - `locales`objectrequired 2`array` Advanced: one nested slot per panel; put several screenshot entries in a slot for a multi-phone panel. each item array One App Store slot: 1–6 screenshots. Several entries = several phones composited into that one slot. each item one of 5 shapes 1`string` Inline base64-encoded PNG (no "data:" prefix). Capped at 3MB of image data — a real full-resolution screenshot is 3-4MB and will NOT fit. Use request_screenshot_upload and pass { ref } instead; inline is for thumbnails and tests. 2`ref` A ref returned by request_screenshot_upload — resolved server-side, never re-sent inline. - `ref`stringrequiredat least 1 character - `name`stringoptionalat most 200 characters The screenshot's original filename (e.g. "03_statistics.png"). Pass it so that, if this render is saved as a project, the user's own screenshots folder re-loads exactly this file by name. Optional if the ref already carries a name (from request_screenshot_upload({ names })); omit entirely and the record falls back to a positional name (screen-N.png). 3`url` An https URL to a PNG or JPEG — fetched server-side, converted to PNG when needed (no redirects, ~20MB cap). - `url`stringrequiredat least 1 character - `name`stringoptionalat most 200 characters The screenshot's original filename (e.g. "03_statistics.png"). Pass it so that, if this render is saved as a project, the user's own screenshots folder re-loads exactly this file by name. Optional if the ref already carries a name (from request_screenshot_upload({ names })); omit entirely and the record falls back to a positional name (screen-N.png). 4`path` A local filesystem path to a PNG, read straight off disk — ONLY available over the local stdio server (npx shotops-mcp); the hosted server rejects this entry shape. - `path`stringrequiredat least 1 character - `name`stringoptionalat most 200 characters The screenshot's original filename (e.g. "03_statistics.png"). Pass it so that, if this render is saved as a project, the user's own screenshots folder re-loads exactly this file by name. Optional if the ref already carries a name (from request_screenshot_upload({ names })); omit entirely and the record falls back to a positional name (screen-N.png). 5`locales` Per-locale variants of ONE screenshot: { "locales": { "en-US": <entry>, "de-DE": <entry> } } (each variant is an inline base64 / ref / url / path entry). render_strip picks the top-level `locale`'s variant; emit_bundle with `locales` renders/packages every listed locale. A locale with no variant of its own falls back to the en-US variant (else the first declared), so you can localize only some screenshots. - `locales`objectrequired

## Result

- `ok`booleanoptional
- `projectId`stringoptional
- `status`stringoptionalalways "pending_claim"
- `ownership`stringoptionalalways "pending"
- `claimId`stringoptional
- `openUrl`stringoptionalformat uri
- `count`numberoptional
- `panelPresetId`stringoptional
- `locale`stringoptional
- `message`stringoptional
- `outputs`arrayoptional each item string
- `note`stringoptional Free-text advisories about THIS call, joined into one string. Written when the server did something you did not literally ask for or could not have known: a look/version fallback, an output-mode downgrade, a device this server cannot render, a `style.shotLook` a `look` overrode, or placement set by hand where a `style.layout` template would have produced the same composition. Never an error — the call succeeded. Read it, and act on it next call.
- `disclosure`objectoptional Stated because this call moved caller bytes into ShotOps storage. Relay it before or with the result; do not paraphrase the retention window.
  - `moves`stringrequired The bytes that left the caller’s control, in plain words.
  - `why`stringrequired What the move buys — never a restatement of the mechanism.
  - `retentionDays`integerrequiredgreater than 0 How long ShotOps keeps it without an explicit retaining action. Read from the retention policy, never typed.
  - `retainedBy`stringrequired The explicit action that keeps it past that window.
  - `statement`stringrequired The same four facts as one sentence, safe to relay verbatim.
- `contract`objectoptional The versioned ShotOps result contract (#662): what ran, where, what it changed, what it cost, what it produced and — on a refusal — a typed failure over a closed code catalog. Structured content is authoritative; the prose beside it is a rendering of this block.
  - `contractVersion`stringrequired The version of THIS envelope, REPORTED. Compare it against the version you were written for. There is no version negotiation: no tool accepts a requested version, so this is never a refusal — it moves only when a field changes meaning, and additive fields never move it.
  - `status`stringrequired one of`succeeded``partial``failed``refused``accepted``queued``running``cancel_requested``cancelled`
  - `terminal`booleanrequired false ⟹ this operation is still running and will be reported again (#666).
  - `operation`objectrequired
    - `id`stringrequired Identity for THIS call, unique per invocation. Quote it in a bug report.
    - `tool`stringrequired The registered tool name that produced this result.
    - `kind`stringrequired one of`render``bundle``read``mutate``upload``delete``status`
    - `durable`objectoptional #666 domain handle for addressable long-running work. Absent from synchronous calls.
      - `operationId`stringrequired
      - `pollWith`stringoptional
  - `execution`objectrequired
    - `location`stringrequired Where the work RAN. `local` is the caller’s own machine over stdio. one of`local``hosted`
    - `inputModes`arrayrequired Every way this door accepts screenshots and assets. each item string one of`inline_base64``stored_ref``remote_url``local_path``project_stored`
    - `deliveryModes`arrayrequired Every way this door can hand a result back. each item string one of`inline_base64``signed_url``local_path``share_link`
  - `effects`objectrequired What this call DID to the world, independent of what it returned. Every flag is stated on every result, false included: an absent flag would be indistinguishable from an effect nobody thought to declare.
    - `networkFetch`booleanrequired This call fetched bytes from a host neither ShotOps nor the caller controls.
    - `upload`booleanrequired Caller bytes were uploaded into ShotOps storage.
    - `retainedStorage`booleanrequired Something survives this call in ShotOps storage.
    - `projectMutation`booleanrequired A saved project or its look history changed.
    - `publication`booleanrequired Something became reachable outside the account — a share link.
    - `deletion`booleanrequired Something was permanently removed.
  - `cost`objectrequired
    - `unit`stringrequiredalways "credit" Public cloud credits — the same unit every ShotOps surface quotes.
    - `model`stringrequired How this connection pays. `unmetered` is local stdio, which renders on the caller’s own machine; `anonymous_allowance` is the unsigned hosted taste. one of`metered``anonymous_allowance``unmetered`
    - `estimated`numberoptional What the call was expected to cost, before it ran.
    - `reserved`numberoptional Held against the wallet for the duration of the call (#666).
    - `released`numberoptional Given back — an unused reservation or a refund after a post-charge failure (#666).
    - `settled`numberoptional Actually taken. Absent when nothing was charged.
    - `balanceAfter`numberoptional The wallet’s public cloud credit balance once this call settled.
    - `refillAt`stringoptional ISO 8601. When the wallet is next topped up; absent when none is scheduled.
  - `progress`objectoptional Persisted monotonic durable-operation progress. Never inferred from transient render metadata. Relay `panelsCompleted`/`panelsTotal` and the estimate to the waiting user; the item counters are internal bookkeeping and do not match what they asked for.
    - `completed`integerrequiredmin 0 Internal scheduling items done — panels PLUS the bundle and result items. Do not quote this to a person.
    - `total`integerrequiredmin 0 Internal scheduling items in total. Larger than the panel count.
    - `panelsCompleted`integeroptionalmin 0 Panels finished, in the unit the caller asked in. THIS is the number to report.
    - `panelsTotal`integeroptionalmin 0 Panels this operation will produce — the count the user asked for.
    - `attempt`integerrequiredmin 0
    - `heartbeatAt`string or nulloptional
    - `estimatedRemainingSeconds`numberoptionalmin 0 Rough seconds of rendering left, from this operation’s own measured pace once a panel has landed. An estimate, not a deadline — say “about”. Absent when nothing is left to render.
  - `resolvedInput`objectoptional #661 — what the server actually resolved the request to, before any pixel was produced.
    - `snapshotId`stringoptional `psi_` + the first 32 hex of the fingerprint. Quote it in a bug report.
    - `fingerprint`stringoptional sha256 over every resolved fact. Equal fingerprints ⟹ equal production input.
    - `sources`arrayoptional One entry per source cell, resolved or not. `slot` is the cell the bytes came FROM — a shot id and coordinate on a saved project, an ordered slot label on a direct render. Never a filename, a ref or a URL. `origin` is absent exactly when `status` is not `resolved`: there is nothing the cell came from. each item object - `slot`stringrequired - `status`stringrequired one of`resolved``missing``ambiguous` - `origin`stringoptional one of`inline_base64``stored_ref``remote_url``local_path``project_stored`
    - `defaultsApplied`arrayoptional What the server chose because the caller said nothing. each item string
    - `overrides`arrayoptional What the caller said that changed the outcome. each item string
  - `readiness`objectoptional #665 — the readiness verdict and any waiver receipt.
    - `state`stringoptional `blocked` ⟹ nothing was delivered. `ready_with_findings` ⟹ delivered, and here is what to know. one of`ready``ready_with_findings``waived``blocked`
    - `policyVersion`stringoptional The readiness policy this verdict was computed under. A waiver granted under another one is rejected.
    - `findings`arrayoptional Every finding, with `code`, `waivable` and `digest`. A waiver names one id AND its digest; there is no wildcard and no code-level waiver. each item object - `id`stringrequired `rf_` + 24 hex. Quote it in a waiver. - `severity`stringrequired one of`info``warn``block` - `message`stringrequired - `target`objectrequired The exact shot, panel, locale, output or frames this finding is about. - `shotId`stringoptional - `panelIndex`numberoptional - `locale`stringoptional - `output`stringoptional - `captionLayer`numberoptional - `frames`arrayoptional each item number - `evidence`objectrequired Bounded redacted facts used to derive the finding and its digest.
    - `waivers`arrayoptional The waivers this call ACCEPTED. Pass these objects back verbatim to reuse them; a rebuilt one is rejected. each item object - `findingId`stringrequired - `findingDigest`stringrequired - `policyVersion`stringrequired - `waivedBy`stringrequired - `waivedAt`stringrequired - `code`stringrequired one of`source_identity_ambiguous``output_unsupported``output_omitted``look_exact_unavailable``no_panels``panel_invalid_png``panel_dimensions_invalid``renderer_failed``input_changed_during_run``panel_source_empty``locale_source_fallback``device_source_fallback``caption_inherited``caption_locale_fallback``look_source_fallback``caption_device_collision``caption_caption_collision``device_device_collision``caption_legibility_unresolved``scope_filtered``locale_not_live_on_apple``look_hold_inactive``caption_text_empty` - `reason`stringoptional
  - `artifacts`arrayoptional each item object - `id`stringrequired The opaque asset id from the custody registry (#663) — or, for `kind: "share"`, the link’s own token. Never a storage path, and never a signed URL. - `kind`stringrequired one of`panel``bundle``screenshot``share``project` - `delivery`objectrequired - `mode`stringrequired one of`inline_base64``signed_url``local_path``share_link` - `url`stringoptional THE ONE FIELD a signed URL may appear in. Nothing else in this envelope carries one. - `expiresAt`stringoptional ISO 8601, when the grant above stops working. - `bytes`numberoptional - `retainedUntil`stringoptional ISO 8601, when ShotOps stops keeping the artifact itself.
  - `failure`objectoptional Present exactly when `status` is `failed` or `refused`.
    - `code`stringrequired The closed failure code. Branch on this, never on the sentence. one of`invalid_input``unsupported_input``project_not_found``project_ambiguous``no_projects``version_not_found``resolution_incomplete``readiness_required``readiness_unmet``asset_not_found``asset_in_use``authentication_required``plan_required``trial_choice_required``quota_exhausted``anonymous_limit_reached``capability_denied``billing_unavailable``render_failed``storage_failed``persistence_failed``upstream_unavailable``payload_too_large``rate_limited``operation_not_found``idempotency_conflict``operation_unavailable``operation_not_ready``contract_version_unsupported``internal_error`
    - `phase`stringrequired How far the call got. `input` and `authorization` guarantee nothing was rendered, stored, written or charged. one of`input``authorization``resolution``reservation``execution``delivery``persistence`
    - `retryable`booleanrequired true ⟹ the identical call may succeed later with nothing changed.
    - `nextAction`stringrequired The one move that resolves this, machine-readable. one of`none``fix_input``choose_project``upload_assets``reduce_scope``sign_in``choose_plan``upgrade_plan``retry``wait_and_retry``poll_operation``upgrade_client``contact_support`
    - `details`objectoptional Bounded, redacted, code-specific facts (the offending field name, the candidate project ids, the required plan). Never a credential, a signed URL or screenshot bytes.

## Example

That request maps to this call:

```
{
  "name": "save_project",
  "arguments": {
    "screenshots": [
      {
        "ref": "uploads/you/tidebook/01-today.png",
        "name": "01-today.png"
      },
      {
        "ref": "uploads/you/tidebook/02-forecast.png",
        "name": "02-forecast.png"
      },
      {
        "ref": "uploads/you/tidebook/03-spots.png",
        "name": "03-spots.png"
      }
    ],
    "projectName": "Tidebook 2.4 launch"
  }
}
```

A project id and an openUrl to give the user. From an unsigned local server it returns an explicit seven-day pending claim instead — the user owns the project once they open the URL and sign in.

## Access and cost

- Needs an account on the hosted server. On local stdio an unsigned save is allowed and becomes a pending claim.
- Free, on both doors. Saving spends no cloud credits and renders nothing.
- An unsigned local save is the one local path that uploads pixels — the raw PNGs go to temporary private claim storage so the user can claim them. Ordinary local rendering and exporting upload nothing.
- A Free account may own 2 projects. Pro is unlimited.

## When it refuses

- **The reply says the project allowance is used up.**
  Delete a project in the web app, or upgrade. Nothing was saved.

- **A pending claim expires unclaimed.**
  The seven-day window closed and the temporary upload is gone. Save again and open the URL this time.

- **You passed a project id and it updated something the user did not expect.**
  Only pass an id when the user explicitly says the work belongs in that project. Omit it and a new project is created instead.

## Where this fits

- [Saving, claiming and reopening a project](https://shotops.dev/docs/mcp/workflows/saved-project)
- [Where saving falls in a first run](https://shotops.dev/docs/mcp/workflows/first-strip)

## What the agent is told

The title and description the server publishes on `tools/list` — this is the copy a model chooses between, reproduced verbatim.

Save as editable project

Let the user keep the strip: save it as an editable ShotOps project they can open in the web app, refine by hand, and have re-rendered later by render_project. Returns an openUrl to hand back and, when already authenticated, a projectId. Unsigned local stdio instead returns an explicit pending claim; the user owns it after opening the URL and signing in. No panel PNGs are returned. Fast, and it does NOT render: it builds a byte-free structure + look record, so no panel bytes are returned and it never hits the render timeout. `outputs` names the device sizes the project targets; an existing `project` id updates that project in place, omitting it creates a new one. CALL IT WHEN THE USER ASKS FOR PERSISTENCE, not as the closing step of every job: this is the door for someone who said they want to keep, share, reuse or keep editing the work. A request for images, full-resolution panels or a bundle is not that, and neither is silence — a render already told them nothing was saved and offered this call. Pass `project` only when they named an existing project as the target; never infer one from the most recently edited. An UNSIGNED local save is the one local path that moves bytes: it stages the raw PNGs in private claim storage so the claimed project reopens whole, and its result carries a `disclosure` block naming what moved, why, how long it is kept and what retains it. Ordinary local render/export never uploads.
