GitHub’s 2015 extension for storing large files outside a Git repository, with an HTTP Batch API that is the cleanest published version of the metadata-first upload — the client POSTs object IDs and sizes, the server replies per object with an upload or download action carrying a URL, the headers to send and an expiry, the client transfers bytes to that URL, and an optional verify step closes the loop. Implemented by GitHub, GitLab, Gitea, Bitbucket and Hugging Face.
Git LFS
Git LFS replaces large files in a repository with small pointer files and keeps the real bytes on an HTTP server. The interesting part is not the pointer; it is the Batch API that moves the bytes, because it separates three things most upload APIs tangle together: deciding what needs to transfer, deciding where and how, and the transfer itself.
- Batch first -
POST /objects/batchwith an operation (uploadordownload) and a list of object IDs and sizes. The server answers for each object individually. - Actions with everything the client needs - Each object comes back with an
upload,downloadorverifyaction: anhref, aheadermap to attach, andexpires_in. The server, not the client, decides what credential travels with the bytes. - Content-addressed - Objects are named by SHA-256, so existence checks are cheap, duplicates are free, and the server can refuse what it already has.
- Transfer adapters -
basicis onePUTper object;multipartand vendor adapters are negotiated so large objects can go in parts without changing the batch step.
Git LFS answers a question the Model Context Protocol Files Working Group left open in October 2026: on the data plane, bearer token or pre-signed URL? The LFS answer is neither and both. The server hands back the URL and the headers, which can be a bearer token, a signature in the query string, or nothing; the client follows instructions, and the credential never originated with the client. For an agent-facing design where the model must never see a credential, that is the right shape, and it has been in production at every major Git host for a decade. Alongside the OCI Distribution Specification, it is the content-addressed branch of the “metadata first, then bytes” family that AtomPub started.