Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

A staff session token, uk_st_…. Minted by sign-up, sign-in or the two-factor exchange.

Headers

X-Organization-Id
string

The organization the caller is acting on — the org_… code that appears in the panel URL. It identifies; the membership JOIN is what authorizes, so a forged code reads nothing. Absent, the session's default organization answers.

Body

application/json
content_type
enum<string>
required
Available options:
image/jpeg,
image/png,
image/webp,
image/gif
size_bytes
integer
required

Up to 5 MiB.

Required range: 1 <= x <= 5242880

Response

The presigned upload.

Everything the browser needs to PUT the file straight into the bucket, and everything the caller needs to reference it afterwards.

upload_url
string
headers
object

Send these with the PUT — they are part of the signature.

public_url
string

Where the object will be readable. Save this on the profile or the organization.