Skip to main content
POST
Upload File

Authorizations

Authorization
string
header
required

API key from Settings > Developer > REST API

Headers

Moda-Version
enum<string>
default:2026-05-01

Calendar-dated API version pin. New integrations should pin 2026-05-01 to opt into the newest response shapes. For back-compat the server also accepts requests with no header and resolves them to the current default (today: 2026-04-12); that default advances on each sunset date. Any unsupported value returns 400 unsupported_version.

Available options:
2026-04-12,
2026-05-01
Example:

"2026-05-01"

Body

multipart/form-data
file
file
required
folder_id
string | null

Destination drive folder (fld_... or a bare folder UUID). The file adopts the folder's visibility, exactly like an in-app upload into that folder. An unknown or inaccessible folder is a 404 folder_not_found; a folder you can see but not edit, or a read-only namespace (Skills, Brand Kits), is a 403 folder_write_denied; brand-kit-managed folders are a 403 brand_kit_folder_protected. Omit to land unfiled (library root).

Response

Successful Response

id
string
required

Unique file identifier (prefixed file_...).

Pattern: ^file_[0-9A-HJKMNP-TV-Za-hjkmnp-tv-z]{26}$
Example:

"file_01HT9WK8N3M2J4A5Z6P7Q8R9TV"

url
string
required

Stable proxy URL for the uploaded file. Use this in attachment URLs.

filename
string
required

Filename of the uploaded file.

mime_type
string
required

MIME type of the file.

size_bytes
integer | null

File size in bytes.

was_duplicate
boolean
default:false

True if an identical file already existed (deduplicated).

folder_id
string | null

Prefixed fld_ wire ID (Crockford base32 body) — the canonical, recommended form. For back-compat, a bare UUID string is also accepted in both path parameters and JSON request bodies (older integrations that stored raw UUIDs keep working). Both are permanent, supported inputs.

Pattern: ^fld_[0-9A-HJKMNP-TV-Za-hjkmnp-tv-z]{26}$
Example:

"fld_01HT9WK8N3M2J4A5Z6P7Q8R9TV"