Files
Confirm direct upload (scan + finalize metadata)
After a client uploads directly to S3 using the presigned PUT URL, call this endpoint to have the server scan the object, create the File record, and optionally quarantine if infected.
POST
/api/files/upload/confirmSDK setup
Create a client and set credentials (JWT and/or API key) before calling the API. Match the authentication type shown above.
import { Configuration, FilesApi } from 'mudbase-sdk';
const configuration = new Configuration({
basePath: 'https://cloud.mudbase.dev',
apiKey: 'sk_live_mudbase_doc_Xk9mP2qR7vN4wL8jH3tY6uE',
accessToken: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfbW9yZ2FuX2RlIiwiZW1haWwiOiJtb3JnYW4uY2hlbkBub3J0aHdpbmQuZGV2IiwiZXhwIjoxODI1MTI5NjAwfQ.doc_preview_sig',
});
// This endpoint accepts either credential — apiKey or accessToken alone is enough.
const files = new FilesApi(configuration);import { Configuration, FilesApi } from 'mudbase-sdk';
const configuration = new Configuration({
basePath: 'https://cloud.mudbase.dev',
apiKey: 'sk_live_mudbase_doc_Xk9mP2qR7vN4wL8jH3tY6uE',
accessToken: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfbW9yZ2FuX2RlIiwiZW1haWwiOiJtb3JnYW4uY2hlbkBub3J0aHdpbmQuZGV2IiwiZXhwIjoxODI1MTI5NjAwfQ.doc_preview_sig',
});
// This endpoint accepts either credential — apiKey or accessToken alone is enough.
const files = new FilesApi(configuration);Example request
Call this endpoint using the client from SDK setup. Use View HTTP for a raw cURL example.
const { data: result } = await files.confirmDirectUpload(
{
key: "card index",
projectId: "proj_lpa0fco0yjT6",
originalName: "Marsha Stehr",
contentType: "port bypass",
size: 88756,
bucket: "interface transmit",
isPublic: false
}
);const { data: result } = await files.confirmDirectUpload(
{
key: "card index",
projectId: "proj_lpa0fco0yjT6",
originalName: "Marsha Stehr",
contentType: "port bypass",
size: 88756,
bucket: "interface transmit",
isPublic: false
}
);Playground
liveTest this endpoint with your own credentials. Your requests will be sent to the live API.
Get your API key from the console
Use the auth endpoints to obtain a JWT.
No Request Yet
Send a request to see the full inspector
Authentication
Requires JWT Requires API Key JWT or API Key
Note
This endpoint accepts either JWT Bearer token or API Key. Use
Authorization: Bearer YOUR_TOKEN for user context, or X-API-Key: YOUR_KEY for server-to-server. View authentication guide →Include your JWT in the Authorization: Bearer YOUR_TOKEN header (user-facing apps, RBAC). View authentication guide →Include your API key in the X-API-Key: YOUR_KEY header (server-to-server, SDKs). View authentication guide →Request Body
json
{
"key": "interface generate",
"projectId": "proj_qh5hFHNT70YZ",
"originalName": "Ms. Freda Romaguera III",
"contentType": "sensor program",
"size": 1002,
"bucket": "interface calculate",
"isPublic": false
}{
"key": "interface generate",
"projectId": "proj_qh5hFHNT70YZ",
"originalName": "Ms. Freda Romaguera III",
"contentType": "sensor program",
"size": 1002,
"bucket": "interface calculate",
"isPublic": false
}Responses
201File confirmed and metadata stored
json
{
"fileId": "abcd1234ef567890",
"status": "ok",
"scan": {
"status": "clean",
"provider": "virustotal",
"detections": 0
}
}{
"fileId": "abcd1234ef567890",
"status": "ok",
"scan": {
"status": "clean",
"provider": "virustotal",
"detections": 0
}
}400Bad request or file quarantined
json
{
"message": "File quarantined",
"details": {
"fileId": "abcd1234ef567890",
"status": "quarantined",
"threat": "EICAR-Test-Signature"
}
}{
"message": "File quarantined",
"details": {
"fileId": "abcd1234ef567890",
"status": "quarantined",
"threat": "EICAR-Test-Signature"
}
}401—
403—
413—
429—
500—
Errors
| Code | Meaning |
|---|---|
400 | Bad request or file quarantined |
401 | — |
403 | — |
413 | — |
429 | — |
500 | — |