Skip to main content
POST
Upload a file
Authentication: Authorization: Bearer <token> with Dashboard session, Pomerado MCP OAuth token, API key, integration API key. Permission: runs:create. Effect: Write: creates or changes something in your account. Errors: invalid_request (400), sign_in_required (401), unauthorized (401), reauthentication_required (401), forbidden (403), file_too_large (413), request_too_large (413), file_type_refused (415), internal_error (500), not_configured (501), temporarily_unavailable (503). Every error has the same envelope.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
name
string
required

The file's name, as the website will see it, for example receipt.pdf

Required string length: 1 - 255
media_type
string
required

The file's media type, for example application/pdf; its first bytes must match it

Required string length: 1 - 255
size
integer

The file's size in bytes; when given, the upload's Content-Length must equal it

Required range: x >= 0

Response

The new file, awaiting its upload

id
string
required

a file ID: file_ and 32 lowercase hex digits

Example:

"file_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"

name
string
required

The file's name, as given

media_type
string
required

The file's media type, as checked

size
number | null
required

Bytes: the size given at creation until the upload arrives, then the size received; null when none was given

sha256
string | null
required

The SHA-256 of the bytes, lowercase hex, once they arrived

status
enum<string>
required

awaiting_upload until its bytes arrive at upload_url, ready to pass to a run, in_use once a run took it

Available options:
awaiting_upload,
ready,
in_use
direction
enum<string>
required

input for a file sent to a run, output for one a run collected

Available options:
input,
output
job_id
string | null
required

The run's job the file is bound to: an input in use, and every output

Example:

"job_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"

created_at
string
required

a string to be decoded into a Date

expires_at
string | null
required

When the file is erased unless used first; null for an input in use, which is erased when its job ends

upload_url
string
required

PUT the file's bytes here once, with its Content-Type and Content-Length and no Authorization header, for example curl -T receipt.pdf -H 'Content-Type: application/pdf' <upload_url>. Valid until expires_at.