---
title: "POST /v1/uploads"
method: POST
path: "/v1/uploads"
tags: ["Workflows"]
---

# POST /v1/uploads

`POST /v1/uploads`

Issues a presigned S3 upload URL for a file. When `encrypted` is true, a per-upload RSA public key is also returned (SPKI DER, base64) for the client to encrypt to; `workspaceId` is required in that case. The matching private key is wrapped under the workspace data key and stored against the upload, never returned.

## Headers

- `Authorization` string

## Request body

- object
  - `contentType` string, required
  - `filename` string, required
  - `workspaceId` string, uuid
  - `encrypted` boolean

## Response `200`

Default Response

- object
  - `presignedUrl` string, uri, required
  - `expiresIn` number, required
  - `key` string, required
  - `publicKey` string

## Other responses

- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found
- `500` — Internal Server Error

---

[API](https://skmtc.net/tessl/apis/tessl-api.md) · [All operations](https://skmtc.net/tessl/apis/tessl-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/tessl/tessl-api/versions/fbb186825642/schema)
