# Short links for AI agents: a shortener built for the way agents work

> AI agents create and share links all day. Here is how Blinkhop serves them: no account, three MCP tools, idempotent shortening, safety checks and clear limits.

Source: https://blinkhop.com/blog/short-links-for-ai-agents · 2026-10-11

AI agents produce a lot of links. They draft newsletters, write release notes, answer support tickets, post updates and summarize research, and almost everything they write points somewhere. We built Blinkhop so that short links for AI agents are as easy as short links for people: no account, no key, no captcha, and a native MCP server.

## Why AI agents need short links

Long URLs cause the same problems for agents as they do for people, only more often. Tracking parameters make links hard to read. Character limits in text messages and social posts leave little room for them. And a person reading what an agent wrote should be able to check a link before trusting it.

A short link fixes the length. A short link you can inspect fixes the trust problem: add `+` to any zou.sh link, as in `https://zou.sh/launch+`, and you see where it goes before you click.

## What breaks when an agent uses a shortener built for humans

Most shorteners were designed for a person in a browser. Agents run into that design quickly:

- **Sign-ups and API keys.** An agent usually can't sign up for an account on its own, and pasting an API key into a chat or a prompt puts that key at risk.
- **Captchas and bot checks.** They exist to stop automated clients, so they stop agents too, especially agents running on cloud servers or behind shared IP addresses.
- **Vague errors.** An HTML error page gives an agent nothing to act on.
- **Duplicates.** Agents retry. A shortener that creates a new link on every call leaves you with several links for one page and clicks split between them.

## Anonymous by design

The Blinkhop API and MCP server need no account and no key. Abuse is handled with per-IP rate limits, a destination blocklist and reports, not with identity checks. When a link is created, we store the destination URL, the code, the creation time and how it was created (web, API or MCP). We don't store the IP address.

Because there is no key to manage, any agent that can make an HTTP request can shorten a link:

```bash
curl -d url=https://example.com https://api.blinkhop.com/v1/links
```

## Three MCP tools

For assistants that support the Model Context Protocol, the remote MCP server at `https://mcp.blinkhop.com/mcp` uses the Streamable HTTP transport and exposes three tools:

| Tool | What it does |
| --- | --- |
| `shorten_link` | Shortens one URL, with an optional custom ending (alias) |
| `shorten_links` | Shortens up to 50 URLs in one call |
| `expand_link` | Shows where a zou.sh link goes, its clicks and its creation date |

Setup is one URL. In Claude Code:

```bash
claude mcp add --transport http blinkhop https://mcp.blinkhop.com/mcp
```

In Claude on desktop and web, add it as a custom connector under Settings → Connectors. ChatGPT supports it through developer mode connectors, and Cursor, VS Code and Windsurf take a short JSON entry. The [setup guide in our help center](https://blinkhop.com/help/connect-claude-chatgpt-cursor) has every snippet.

## Prompts that work

Once the server is connected, plain requests are enough:

- "Shorten `https://example.com/blog/fall-update?utm_source=newsletter&utm_medium=email` and use the ending `fall-update`."
- "Here is my newsletter draft. Shorten every link in it and give me the draft back with the short links."
- "Write a post for each of our three social accounts about the webinar. Give each one the registration link with its own `utm_source`, then shorten all three."
- "Where does `zou.sh/launch` go? Check it before you open it."
- "Make a short link for our meetup page with the ending `spring-meetup`, and give me its QR code address for the poster."

Your assistant picks the tool: `shorten_link` for one URL, `shorten_links` for a batch, `expand_link` to check a link. For the last prompt, every zou.sh link has a QR code at the same address plus `/qr`, such as `https://zou.sh/spring-meetup/qr`.

## Idempotent by default

Agents retry. A request times out, a step is re-run, or the model calls the same tool twice in one conversation. Blinkhop is built for that: shortening the same URL again, without a custom ending, returns the existing link instead of creating a new one. Through the REST API, a new link comes back with HTTP 201 and an existing one with HTTP 200, so your code can tell the difference.

The result is one URL, one short link and one click count, however many times an agent asks. That's also why the third prompt above adds a different `utm_source` to each post: different URLs give you separate links, and separate counts, for each channel.

## Safety checks agents can rely on

An agent that shares links on your behalf shouldn't spread phishing or leak internal addresses. Every destination is checked when the link is created:

- The domain is compared against a blocklist of about 390,000 phishing and malware domains, refreshed every night from URLhaus (abuse.ch) and the Phishing.Database project.
- URLs with embedded credentials (`user:pass@`) are refused, so a password can't end up in a public link.
- Private and local addresses are refused, so an internal URL can't become a public short link.
- zou.sh links are refused, so links don't get shortened twice.

When something is refused, the API returns a JSON error with a code an agent can act on, such as `unsafe_destination`, `alias_taken` or `rate_limited`.

Checks work in the other direction too. `expand_link` tells an agent where a zou.sh link goes before anyone follows it. The API's `/expand` endpoint follows short links from zou.sh and other services, including bit.ly, tinyurl.com and t.co, for up to 10 hops, then returns the chain, the final destination and a safety verdict.

## Limits, stated up front

The limits are public, per IP address and the same for everyone:

- MCP server: 120 calls per minute and 5,000 per day.
- REST API without a key: 20 new links per minute and 300 per day. In a bulk request, each URL counts.

Every API response carries `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`, and a 429 response adds `Retry-After`, so an agent knows when to try again instead of guessing. Higher limits will come with API keys, which are part of accounts (early access). And because there are no captchas or bot walls, agents behind Tor, VPNs or cloud IP addresses get the same service as everyone else.

## Get started

Connect your assistant from the [MCP page](https://blinkhop.com/mcp), or see how Blinkhop fits agent workflows on the [AI agents page](https://blinkhop.com/solutions/ai-agents). Building your own agent? Start with the [API reference](https://blinkhop.com/docs/api).
