runs:create permission (the default permissions include it). A file belongs to you alone; another member’s file, or a file in another account, answers not_found.
Send a file to a run
A tool’s file field is a string. Give it one of:- A file ID (
file_…) from an upload. Use this for any file larger than a few hundred kilobytes. - An https URL. Pomerado fetches it when you start the run. The URL must be https on the default port, with no username or password, and must resolve to a public address. It may redirect at most three times, must answer within 20 seconds and must send a
Content-Length. - A
data:URI of at most 512 KB, such asdata:application/pdf;base64,JVBERi0….
Upload a file
Create the upload withPOST /v1/files, or from an MCP client with call_pomerado_api and the operation files.create:
size is optional; when you give it, the upload must be exactly that long. The answer is 201:
upload_url once, with no Authorization header:
200 with the file, now ready, with its size and sha256. If an upload fails, PUT it again until the file expires. Pass the file’s ID as the field’s value when you start the run:
GET /v1/files/{id} reads a file’s metadata, never its bytes; DELETE /v1/files/{id} erases it now.
Get a file from a run
A run that collects a file returns it in its result as a$file object:
download_url works once, with no Authorization header: curl -o statement.pdf "<download_url>". The file is erased as soon as one download finishes, which means Pomerado handed its last byte to the network, not that your client saved it; save the body before anything else, and check it against sha256. A download that breaks off before its last byte may start again until expires_at. Compare the bytes with sha256 if you need proof they are complete.
Limits
Pomerado accepts PDF, common image, audio and video types, ZIP and office documents, and plain text, CSV, Markdown, calendar, XML and JSON files;
application/octet-stream takes any other bytes. A file’s first bytes must match its media type. Programs and scripts (.exe, .sh, .js, .dmg and others) are refused by name, type and content. Files are not scanned for malware, so open a downloaded file with the care you would give any other.
Errors
See Errors for every code.