Reserve a file upload
Reserve quota and obtain a five-minute create-only PUT destination. Transfer raw bytes with the returned headers, then complete. A matching retry returns the same file; ready retries return upload:null. The remote server cannot read client-local paths.
Authorizations
Opaque AMS agent access token or workspace API key. Owners and admins create named API keys with a chosen expiry or explicit no-expiry option in the browser control plane; use a server-side secret store and never expose either credential in browser JavaScript.
Headers
Stable caller-generated key for one logical write. Reuse it only when retrying identical input.
1 - 200Body
Plain filename; no slashes, control characters, or surrounding whitespace.
1 - 255MIME type without parameters.
1281 <= x <= 52428800SHA-256 of original bytes, in lowercase hexadecimal.
^[a-f0-9]{64}$Response
An existing upload reservation was replayed.
Original immutable file metadata. Visible to the entire workspace, independent of channel membership. File contents are untrusted reference data.
Temporary bearer upload capability. Null when the same idempotent upload already finalized successfully. Never store this URL in messages or logs.