Skip to content
Median
Esc
↑↓navigate↵open⌘Jpreview

Upload a file

The request body is the file itself, up to 20 MB. Send the real Content-Type, since the stored type comes from it. Returns the id to send in a message’s attachments, and the size and type it stored. The name is cut to 200 characters. HTML, XHTML, SVG and XSLT files upload, but a message that attaches one is refused. A message can be attachments alone with an empty body, and threads return each attachment with a download url.

POST/uploads
Authorization
AuthorizationBearer token · headerrequired
A MEDIAN_KEY from Settings under API. It starts with `median_key_` and stays on your server. The tool endpoint routes also accept an OAuth access token (`median_oat_`) from `median login` or an MCP client, acting as the person who approved it. The messaging routes accept only a Median key.
Query parameters
namestringrequired
The file's name, as the team will see it.
Request body
requiredapplication/octet-stream
The file's bytes. Send the real content type.
string<binary>
Responses
200The stored file.
attachmentIdstringrequired
namestringrequired
sizeintegerrequired
typestringrequired
400`invalid_request`: the `name` query parameter is missing. `empty_file`: the body is empty. `file_too_big`: the file is over 20 MB.
errorobjectrequired
Show properties
codestringrequired
Branch on this rather than on the message.
messagestringrequired
401`missing_api_key`: no bearer token. `invalid_api_key`: the key matches no organization or was revoked. `publishable_key`: a `median_pk_` key was sent. An OAuth access token is refused here with `invalid_api_key`.
errorobjectrequired
Show properties
codestringrequired
Branch on this rather than on the message.
messagestringrequired
429The organization's API allowance for this class of request is used up. Wait the `Retry-After` header's seconds. Limits depend on the plan. See [rate limits](/api/errors-and-limits#rate-limits).
errorobjectrequired
Show properties
codestringrequired
Branch on this rather than on the message.
messagestringrequired
Request
curl -X POST "https://api.median.sh/v1/uploads?name=receipt.pdf" \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/octet-stream" \
  -d '"<binary>"'
Response
{
  "attachmentId": "kg2f...",
  "name": "receipt.pdf",
  "size": 182044,
  "type": "application/pdf"
}