---
title: "Upload Employee Photo"
method: POST
path: "/api/v1/employees/{employeeId}/photo"
tags: ["Photos", "Public API"]
---

# Upload Employee Photo

`POST /api/v1/employees/{employeeId}/photo`

Uploads a new photo for an employee. Accepts a `multipart/form-data` POST with a `file` field carrying raw binary image bytes (typical browser and SDK usage). An `application/json` POST with a `fileBase64` property is also accepted, but it is not recommended for AI connector use. The base64 payload is too large for an AI model to produce reliably in a single tool call. Supported formats: JPEG, PNG, BMP, GIF. Other formats (HEIC, SVG, AVIF, WebP) are rejected with 415. TIFF is accepted by the format gate but some variants may fail downstream. The image must be square within 1 pixel and at least 150×150 pixels. This endpoint does not perform cropping, so if your source image is not square, you must crop it before uploading. Photo upload through this endpoint is not a viable AI connector workflow. For interactive cropping or any AI-initiated photo change, redirect the user to the BambooHR web UI. Maximum file size is 20MB (applies to the decoded bytes for the JSON variant). The photo replaces the employee's current photo for all size variants. Employees may upload their own photo if the company has self-photo uploads enabled.

OAuth Scopes: employee:photo.write

## Path parameters

- `employeeId` integer, required

## Request body

- object
  - `fileBase64` string, byte, required — Base64-encoded image bytes. Same format, size, and dimension rules as the multipart `file` field. Supported formats: JPEG, PNG, BMP, GIF. Image must be square within 1 pixel and at least 150×150 pixels. Decoded payload must be no larger than 20MB. This endpoint does not perform cropping, so non-square sources must be cropped before upload. Not recommended for AI connector use, since the base64 payload is too large for an AI model to produce reliably in a single tool call. For AI-initiated photo upload, redirect the user to the BambooHR web UI. Whitespace inside the base64 string is tolerated and stripped before decoding.

## Response `201`

The photo was uploaded and processed successfully. No response body is returned.

## Other responses

- `400` — The request is invalid: no file provided, zero-byte file, or the maximum number of photo uploads (32767) has been exceeded.
- `402` — The photo could not be processed: the image crop failed, or the file contents could not be read.
- `403` — The authenticated user does not have permission to upload photos for this employee.
- `404` — The employee does not exist.
- `413` — The uploaded file exceeds the 20MB size limit.
- `415` — The image does not meet requirements: not square (width and height differ by more than one pixel), smaller than 150×150 pixels, or the file could not be read as a supported image format.

---

[API](https://skmtc.net/bamboohr/apis/bamboohr-api.md) · [All operations](https://skmtc.net/bamboohr/apis/bamboohr-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/bamboohr/bamboohr-api/revisions/19ebf391a399/schema)
