Docs

Register a file upload

Preview· P9
POST/files

Registers a file and returns a presigned URL to upload it to. Files never pass through the API: send the bytes with PUT to upload.url, with exactly the headers in upload.headers, within five minutes. Then use the file's ID where a record takes one, for example selfie_file_id on a clock-in.

kindContent typesUp to
visitor_photoimage/jpeg, image/png, image/webp5 MB
id_imageimage/jpeg, image/png, image/webp10 MB
signatureimage/png1 MB
selfieimage/jpeg, image/webp5 MB
delivery_photoimage/jpeg, image/png, image/webp10 MB
documentapplication/pdf20 MB
badgeapplication/pdf, image/png5 MB
  • The storage refuses an upload of another type or size, or after the link expires. Register the file again to get a new link.
  • After the upload, Agoo removes the photo's metadata (EXIF, including any GPS location), checks that the content matches its type and makes a thumbnail for photos. The file's status then changes from pending to ready, usually within seconds. A file whose content doesn't match its type is deleted.
  • A file that is never uploaded is deleted after a day. ID images, visitor photos and selfies are deleted on your organisation's retention schedule.
  • selfie needs selfie evidence switched on in your attendance settings; otherwise you get validation_failed at body.kind.

Scope: files:write · Plan: Pro and Enterprise in live mode; every plan in test mode.

Authorization

AuthorizationBearer <token>

Send Authorization: Bearer <token> on every request. The token is one of:

PrefixWhat it isWhere it may be used
agoo_sk_live_Secret key, live modeYour servers only
agoo_sk_test_Secret key, test modeYour servers only
agoo_pk_live_Publishable key, live modeBrowsers and apps: create pre-registrations and bookings, read public booking types (with their intake questions) and their free slots, read the visit types open for pre-registration with their public forms. Never lists people.
agoo_pk_test_Publishable key, test modeAs above, in test mode

Admins create keys in Console → Developers → API keys and choose each key's scopes. A key is shown once. Never put a secret key in a URL, a browser or a mobile app.

In: header

Scope: files:write

Header Parameters

Idempotency-Key*string

A UUID you generate for this operation. If you retry with the same key within 24 hours, Agoo returns the original response instead of acting twice. While the first request is still running, a retry returns conflict. Reusing a key with a different request returns idempotency_key_reused. Responses with rate_limited, internal_error or unavailable aren't stored, so retry those with the same key.

Formatuuid

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

curl -X POST "https://example.com/files" \  -H "Idempotency-Key: 3f6b2a1e-8c4d-4f7a-9b2e-5d1c0a7e9f64" \  -H "Content-Type: application/json" \  -d '{    "kind": "selfie",    "content_type": "image/jpeg",    "byte_size": 184320  }'
{  "id": "file_01m4z8vge0fkktt139dhkf42gw",  "kind": "selfie",  "status": "pending",  "content_type": "image/jpeg",  "byte_size": 184320,  "sha256": null,  "has_thumbnail": false,  "created_at": "2026-10-15T07:54:00Z",  "ready_at": null,  "deleted_at": null,  "upload": {    "url": "https://files.example.com/f/7Kq2Xp4Lm9Rt?expires=1791230400&signature=8b2e7d",    "method": "PUT",    "headers": {      "Content-Type": "image/jpeg",      "Content-Length": "184320"    },    "expires_at": "2026-10-15T07:59:00Z"  }}