Authorize a document upload
curl --request POST \
--url http://localhost:3500/v1/documents/upload \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"file_name": "invoice-2026-001.pdf",
"mime_type": "application/pdf",
"file_size": 48321
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
file_name: 'invoice-2026-001.pdf',
mime_type: 'application/pdf',
file_size: 48321
})
};
fetch('http://localhost:3500/v1/documents/upload', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "http://localhost:3500/v1/documents/upload"
payload = {
"file_name": "invoice-2026-001.pdf",
"mime_type": "application/pdf",
"file_size": 48321
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"document_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"upload_url": "<string>",
"headers": {},
"expires_at": "2023-11-07T05:31:56Z"
}{
"error": {
"code": "validation_error",
"message": "Invalid request format, parameters, or body. Details contain up to 20 actionable field errors; the complete encoded request body must be at most 2 MiB (2,097,152 bytes).",
"request_id": "req_example"
}
}{
"error": {
"code": "invalid_token",
"message": "Missing or invalid bearer credential.",
"request_id": "req_example"
}
}{
"error": {
"code": "forbidden",
"message": "Access denied: forbidden, token_disabled, organization_required, insufficient_role, or mfa_required. Check the error code and effective permissions.",
"request_id": "req_example"
}
}{
"error": {
"code": "rate_limit_exceeded",
"message": "The IP or authenticated credential exceeded its request limit.",
"request_id": "req_example"
}
}{
"error": {
"code": "internal_error",
"message": "Unexpected server failure. Include the request ID when contacting support.",
"request_id": "req_example"
}
}{
"error": {
"code": "service_unavailable",
"message": "Authentication or upload signing is temporarily unavailable. Honor Retry-After when provided.",
"request_id": "req_example"
}
}Documents
Authorize a document upload
Creates a Document placeholder and a short-lived upload capability. PUT the bytes directly to upload_url with all returned headers before expires_at. Then pass document_id to an invoice import, invoice attachment, or agreement document link; there is no upload completion endpoint.
Authorize a document upload
curl --request POST \
--url http://localhost:3500/v1/documents/upload \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"file_name": "invoice-2026-001.pdf",
"mime_type": "application/pdf",
"file_size": 48321
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
file_name: 'invoice-2026-001.pdf',
mime_type: 'application/pdf',
file_size: 48321
})
};
fetch('http://localhost:3500/v1/documents/upload', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "http://localhost:3500/v1/documents/upload"
payload = {
"file_name": "invoice-2026-001.pdf",
"mime_type": "application/pdf",
"file_size": 48321
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"document_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"upload_url": "<string>",
"headers": {},
"expires_at": "2023-11-07T05:31:56Z"
}{
"error": {
"code": "validation_error",
"message": "Invalid request format, parameters, or body. Details contain up to 20 actionable field errors; the complete encoded request body must be at most 2 MiB (2,097,152 bytes).",
"request_id": "req_example"
}
}{
"error": {
"code": "invalid_token",
"message": "Missing or invalid bearer credential.",
"request_id": "req_example"
}
}{
"error": {
"code": "forbidden",
"message": "Access denied: forbidden, token_disabled, organization_required, insufficient_role, or mfa_required. Check the error code and effective permissions.",
"request_id": "req_example"
}
}{
"error": {
"code": "rate_limit_exceeded",
"message": "The IP or authenticated credential exceeded its request limit.",
"request_id": "req_example"
}
}{
"error": {
"code": "internal_error",
"message": "Unexpected server failure. Include the request ID when contacting support.",
"request_id": "req_example"
}
}{
"error": {
"code": "service_unavailable",
"message": "Authentication or upload signing is temporarily unavailable. Honor Retry-After when provided.",
"request_id": "req_example"
}
}Authorizations
ApiKeyBearerClerkSessionBearer
Personal API key. Send X-Organization-Id. The required cumulative level is listed in x-watchdog-permission.
Headers
Required for personal API keys. Target one organization you have access to. Migrated keys may omit it to use their original organization. For Clerk sessions, it must match the active organization.
Body
application/json