> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pomerado.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Upload a file

> Start an upload for a run's file input: answers the file's ID and a one-time upload_url. PUT the bytes there (at most 25 MiB unless the deployment says otherwise; executables are refused and the first bytes must match media_type), then pass the ID as the file field's value in a run's input. A file serves one run, is erased when that run's job ends, and is erased after an hour if unused. A run's file field also takes an https URL or a data: URI of at most 512 KB instead.

**Authentication:** `Authorization: Bearer <token>` with Dashboard session, Pomerado MCP OAuth token, API key, integration API key.

**Permission:** `runs:create`.

**Effect:** Write: creates or changes something in your account.

**Errors:** [`invalid_request`](/errors#invalid_request) (400), [`sign_in_required`](/errors#sign_in_required) (401), [`unauthorized`](/errors#unauthorized) (401), [`reauthentication_required`](/errors#reauthentication_required) (401), [`forbidden`](/errors#forbidden) (403), [`file_too_large`](/errors#file_too_large) (413), [`request_too_large`](/errors#request_too_large) (413), [`file_type_refused`](/errors#file_type_refused) (415), [`internal_error`](/errors#internal_error) (500), [`not_configured`](/errors#not_configured) (501), [`temporarily_unavailable`](/errors#temporarily_unavailable) (503). Every error has the same [envelope](/errors).


## OpenAPI

````yaml /api-reference/openapi.json post /v1/files
openapi: 3.1.0
info:
  title: Pomerado API
  version: '1'
  description: >-
    Run and build website tools, follow their jobs, and manage logins, API keys
    and webhooks. Authenticate with a Pomerado API key (pom_…), an MCP OAuth
    token or a Dashboard session as a Bearer token.
servers:
  - url: https://api.pomerado.ai
security: []
tags:
  - name: account
    x-group: Account
  - name: api_keys
    x-group: API keys
  - name: connected_apps
    x-group: Connected apps
  - name: usage
    x-group: Usage
  - name: quota
    x-group: Quota
  - name: billing
    x-group: Billing
  - name: integrations
    x-group: Integrations
  - name: connect
    x-group: Connect
  - name: logins
    x-group: Logins
  - name: tools
    x-group: Tools
  - name: webhooks
    x-group: Webhooks
  - name: runs
    x-group: Runs
  - name: builds
    x-group: Builds
  - name: jobs
    x-group: Jobs
  - name: files
    x-group: Files
  - name: support
    x-group: Support
  - name: team
    x-group: Team
paths:
  /v1/files:
    post:
      tags:
        - files
      summary: Upload a file
      description: >-
        Start an upload for a run's file input: answers the file's ID and a
        one-time upload_url. PUT the bytes there (at most 25 MiB unless the
        deployment says otherwise; executables are refused and the first bytes
        must match media_type), then pass the ID as the file field's value in a
        run's input. A file serves one run, is erased when that run's job ends,
        and is erased after an hour if unused. A run's file field also takes an
        https URL or a data: URI of at most 512 KB instead.
      operationId: files.create
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - name
                - media_type
              properties:
                name:
                  type: string
                  description: >-
                    The file's name, as the website will see it, for example
                    receipt.pdf
                  minLength: 1
                  maxLength: 255
                media_type:
                  type: string
                  description: >-
                    The file's media type, for example application/pdf; its
                    first bytes must match it
                  minLength: 1
                  maxLength: 255
                size:
                  allOf:
                    - $ref: '#/components/schemas/Int'
                      description: a non-negative number
                      minimum: 0
                  description: >-
                    The file's size in bytes; when given, the upload's
                    Content-Length must equal it
              additionalProperties: false
      responses:
        '201':
          description: The new file, awaiting its upload
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/FileUpload'
        '400':
          description: invalid_request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: sign_in_required, unauthorized, reauthentication_required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '413':
          description: file_too_large, request_too_large
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '415':
          description: file_type_refused
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: internal_error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '501':
          description: not_configured
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: temporarily_unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - bearer: []
components:
  schemas:
    Int:
      type: integer
      description: an integer
    FileUpload:
      type: object
      required:
        - id
        - name
        - media_type
        - size
        - sha256
        - status
        - direction
        - job_id
        - created_at
        - expires_at
        - upload_url
      properties:
        id:
          $ref: '#/components/schemas/file_id'
        name:
          type: string
          description: The file's name, as given
        media_type:
          type: string
          description: The file's media type, as checked
        size:
          anyOf:
            - type: number
            - type: 'null'
          description: >-
            Bytes: the size given at creation until the upload arrives, then the
            size received; null when none was given
        sha256:
          anyOf:
            - type: string
            - type: 'null'
          description: The SHA-256 of the bytes, lowercase hex, once they arrived
        status:
          type: string
          enum:
            - awaiting_upload
            - ready
            - in_use
          description: >-
            awaiting_upload until its bytes arrive at upload_url, ready to pass
            to a run, in_use once a run took it
        direction:
          type: string
          enum:
            - input
            - output
          description: input for a file sent to a run, output for one a run collected
        job_id:
          anyOf:
            - $ref: '#/components/schemas/job_id'
            - type: 'null'
          description: >-
            The run's job the file is bound to: an input in use, and every
            output
        created_at:
          $ref: '#/components/schemas/Date'
        expires_at:
          anyOf:
            - $ref: '#/components/schemas/Date'
            - type: 'null'
          description: >-
            When the file is erased unless used first; null for an input in use,
            which is erased when its job ends
        upload_url:
          type: string
          description: >-
            PUT the file's bytes here once, with its Content-Type and
            Content-Length and no Authorization header, for example curl -T
            receipt.pdf -H 'Content-Type: application/pdf' <upload_url>. Valid
            until expires_at.
      additionalProperties: false
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
            - retryable
            - docs_url
          properties:
            code:
              type: string
            message:
              type: string
            retryable:
              type: boolean
            docs_url:
              type: string
            details:
              type: object
              required: []
              properties: {}
              additionalProperties:
                $id: /schemas/unknown
          additionalProperties: false
      additionalProperties: false
    file_id:
      type: string
      description: 'a file ID: file_ and 32 lowercase hex digits'
      examples:
        - file_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190
    job_id:
      type: string
      description: 'a job ID: job_ and 32 lowercase hex digits'
      examples:
        - job_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190
    Date:
      type: string
      description: a string to be decoded into a Date
  securitySchemes:
    bearer:
      type: http
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.