Files
Confirm direct upload (scan + finalize metadata)
After a client uploads directly to object storage using the presigned PUT URL, call this endpoint to have the server scan the object, create the File record, and optionally quarantine if infected.
POST
/api/files/upload/confirmSDK setup
Create a client and set credentials (JWT and/or API key) before calling the API. Match the authentication type shown above.
import { Configuration, FilesApi } from 'mudbase-sdk';
const configuration = new Configuration({
basePath: 'https://cloud.mudbase.dev',
apiKey: 'sk_live_mudbase_doc_Xk9mP2qR7vN4wL8jH3tY6uE',
accessToken: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfbW9yZ2FuX2RlIiwiZW1haWwiOiJtb3JnYW4uY2hlbkBub3J0aHdpbmQuZGV2IiwiZXhwIjoxODI1MTI5NjAwfQ.doc_preview_sig',
});
// This endpoint accepts either credential - apiKey or accessToken alone is enough.
const files = new FilesApi(configuration);import { Configuration, FilesApi } from 'mudbase-sdk';
const configuration = new Configuration({
basePath: 'https://cloud.mudbase.dev',
apiKey: 'sk_live_mudbase_doc_Xk9mP2qR7vN4wL8jH3tY6uE',
accessToken: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfbW9yZ2FuX2RlIiwiZW1haWwiOiJtb3JnYW4uY2hlbkBub3J0aHdpbmQuZGV2IiwiZXhwIjoxODI1MTI5NjAwfQ.doc_preview_sig',
});
// This endpoint accepts either credential - apiKey or accessToken alone is enough.
const files = new FilesApi(configuration);Example request
Call this endpoint using the client from SDK setup. Use View HTTP for a raw cURL example.
const { data: result } = await files.confirmDirectUpload(
{
key: "card index",
projectId: "proj_lpa0fco0yjT6",
originalName: "Marsha Stehr",
contentType: "port bypass",
size: 88756,
bucket: "interface transmit",
isPublic: false
}
);const { data: result } = await files.confirmDirectUpload(
{
key: "card index",
projectId: "proj_lpa0fco0yjT6",
originalName: "Marsha Stehr",
contentType: "port bypass",
size: 88756,
bucket: "interface transmit",
isPublic: false
}
);Playground
liveTest this endpoint with your own credentials. Your requests will be sent to the live API.
Get your API key from the console
Use the auth endpoints to obtain a JWT.
No Request Yet
Send a request to see the full inspector
Authentication
Requires JWT Requires API Key JWT or API Key
Note
This endpoint accepts either JWT Bearer token or API Key. Use
Authorization: Bearer YOUR_TOKEN for user context, or X-API-Key: YOUR_KEY for server-to-server. View authentication guide →Include your JWT in the Authorization: Bearer YOUR_TOKEN header (user-facing apps, RBAC). View authentication guide →Include your API key in the X-API-Key: YOUR_KEY header (server-to-server, SDKs). View authentication guide →Request Body
json
{
"key": "interface generate",
"projectId": "proj_qh5hFHNT70YZ",
"originalName": "Ms. Freda Romaguera III",
"contentType": "sensor program",
"size": 1002,
"bucket": "interface calculate",
"isPublic": false
}{
"key": "interface generate",
"projectId": "proj_qh5hFHNT70YZ",
"originalName": "Ms. Freda Romaguera III",
"contentType": "sensor program",
"size": 1002,
"bucket": "interface calculate",
"isPublic": false
}Responses
201File confirmed and metadata stored
json
{
"fileId": "abcd1234ef567890",
"status": "ok",
"scan": {
"status": "clean",
"provider": "virustotal",
"detections": 0
}
}{
"fileId": "abcd1234ef567890",
"status": "ok",
"scan": {
"status": "clean",
"provider": "virustotal",
"detections": 0
}
}400Bad request or file quarantined
json
{
"message": "File quarantined",
"details": {
"fileId": "abcd1234ef567890",
"status": "quarantined",
"threat": "EICAR-Test-Signature"
}
}{
"message": "File quarantined",
"details": {
"fileId": "abcd1234ef567890",
"status": "quarantined",
"threat": "EICAR-Test-Signature"
}
}401-
403-
413-
429-
500-
Errors
| Code | Meaning |
|---|---|
400 | Bad request or file quarantined |
401 | - |
403 | - |
413 | - |
429 | - |
500 | - |