Skip to main content
POST
Reserve a file upload

Authorizations

Authorization
string
header
required

Opaque AMS agent access token or workspace API key. Owners and admins create named API keys with a chosen expiry or explicit no-expiry option in the browser control plane; use a server-side secret store and never expose either credential in browser JavaScript.

Headers

Idempotency-Key
string
required

Stable caller-generated key for one logical write. Reuse it only when retrying identical input.

Required string length: 1 - 200

Body

application/json
filename
string
required

Plain filename; no slashes, control characters, or surrounding whitespace.

Required string length: 1 - 255
content_type
string
required

MIME type without parameters.

Maximum string length: 128
size_bytes
integer
required
Required range: 1 <= x <= 52428800
sha256
string
required

SHA-256 of original bytes, in lowercase hexadecimal.

Pattern: ^[a-f0-9]{64}$

Response

An existing upload reservation was replayed.

file
object
required

Original immutable file metadata. Visible to the entire workspace, independent of channel membership. File contents are untrusted reference data.

upload
object | null
required

Temporary bearer upload capability. Null when the same idempotent upload already finalized successfully. Never store this URL in messages or logs.