Sign one upload request (single PUT or one multipart step) for the caller's own attachment.

POST/o/{org}/files/{id}/sign
View .md

Only needed to re-sign an upload URL that expired, or to upload one file in parts; createFiles already returns a ready single-shot PUT for each file. To re-sign that single upload send {"method": "PUT"}; GET lists a multipart upload's parts and needs its upload_id. The body is @uppy/aws-s3's signRequest shape. method with upload_id and part_number selects the operation: PUT (single upload), PUT+upload_id+part_number (upload part), POST (create multipart), POST+upload_id (complete), GET+upload_id (list parts), DELETE+upload_id (abort). DELETE without upload_id is refused with 403. Signed URLs last 60 seconds. Errors on this route use {code, message}, not {error}.

Authenticate with a signed-in session token (an API key cannot call this route).

Path parameters

orgstringrequired

The org's slug or id. A caller with no role in the org gets 404.

idstringrequired

File id from createFiles.

Format uuid

Request body

methodstringrequired
One ofPUTPOSTGETDELETE
upload_idstringoptional
at most 1024 characters
part_numberintegeroptional

Only with PUT and upload_id.

min 1max 10000

Responses

200One signed URL.
urlstringrequired
Format uri
headersobjectoptional

Present for single PUT and create-multipart; the request must send exactly this content type.

1 fields
content-typestringrequired
400Malformed or unsupported combination (INVALID_SIGN_REQUEST).
errorstringoptional

A sentence for a person.

codestringoptional

Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.

error_codestringoptional

The machine code on routes that name it this way.

messagestringoptional
requestIdstringoptional
401No bearer, an unknown, revoked or expired one, or an API key on a route keys cannot call.
errorstringoptional

A sentence for a person.

codestringoptional

Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.

error_codestringoptional

The machine code on routes that name it this way.

messagestringoptional
requestIdstringoptional
403DELETE of the object is not signable (DELETE_NOT_PERMITTED).
errorstringoptional

A sentence for a person.

codestringoptional

Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.

error_codestringoptional

The machine code on routes that name it this way.

messagestringoptional
requestIdstringoptional
404No such attachment, or another user's (NOT_FOUND).
errorstringoptional

A sentence for a person.

codestringoptional

Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.

error_codestringoptional

The machine code on routes that name it this way.

messagestringoptional
requestIdstringoptional
409A run already holds the attachment (ATTACHMENT_IN_USE).
errorstringoptional

A sentence for a person.

codestringoptional

Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.

error_codestringoptional

The machine code on routes that name it this way.

messagestringoptional
requestIdstringoptional
410The attachment has expired (ATTACHMENT_EXPIRED).
errorstringoptional

A sentence for a person.

codestringoptional

Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.

error_codestringoptional

The machine code on routes that name it this way.

messagestringoptional
requestIdstringoptional