Upload file

View as Markdown
Uploads a single file and creates a File resource, returning its stable `id`. The request is `multipart/form-data`, not JSON. The `file` part must come last: the upload is streamed, so send `purpose` (and any other field) **before** it. A part that arrives after `file`, or a second `file` part, is rejected with `400`. Moveworks determines `content_type` by inspecting the bytes. A declared media type or a filename extension is not trusted, and the detected type is what the response reports. A `201` is returned only after the bytes are stored and the file has passed its security checks, so a successful response always describes a file that is ready to reference. Uploaded files are retained for 24 hours. After `expire_time`, both the file and its metadata are removed, and the `id` no longer resolves. Reference the `id` from a downstream API before then. There is no `GET`, `LIST`, download, or `DELETE` operation in `v1alpha1`. A file is reached only by passing its `id` to an API that accepts one.

Authentication

AuthorizationBearer

JWT bearer token authentication. Obtain an access token from the Moveworks auth endpoint and include it in the Authorization header as ‘Bearer <token>’.

Request

This endpoint expects a multipart form containing a file.
purposeenumRequired

What the file is for. Must be sent before the file part.

Allowed values:
filefileRequired
The file to upload, sent as raw bytes rather than base64. The part's `filename` parameter supplies the response `name` and is required; `curl -F "file=@./screenshot.png"` sets both. Maximum 100 MB. The filename must be 1-255 characters after Unicode NFC normalization. It cannot be `.` or `..`, contain `/`, `\`, control characters, or bidirectional formatting characters, or be empty once trimmed.

Response headers

x-trace-idstringOptional
A unique identifier used to trace your request within the Moveworks system

Response

File uploaded and File resource created
idstring

Opaque, stable identifier for the File resource. Pass it to other Moveworks APIs; do not parse it.

purposeenum
The purpose the file was uploaded with.
Allowed values:
namestring

The filename from the uploaded file part, after Unicode normalization.

content_typestring
IANA media type detected by Moveworks from the file's bytes. This is authoritative over anything the request declared.
size_byteslong
Exact number of bytes stored.
create_timedatetime
RFC 3339 UTC timestamp of when the File resource was created.
expire_timedatetime or null

RFC 3339 UTC timestamp of when the file and its metadata are removed, 24 hours after create_time. Once it passes, the id no longer resolves. The field is nullable for forward compatibility with a non-expiring purpose, but CONVERSATIONS_ATTACHMENT always expires, so it is never null today.

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
413
Content Too Large Error
422
Unprocessable Entity Error
429
Too Many Requests Error
500
Internal Server Error