---
title: "Upload an attachment to any supported entity"
method: POST
path: "/v1/attachments"
tags: ["Attachments"]
---

# Upload an attachment to any supported entity

`POST /v1/attachments`

Upload a base64-encoded file and attach it to a task, vendor, risk, comment, or other supported entity type. The file is uploaded to S3 and a database record is created.

## Request body

- CreateAttachmentDto
  - `fileName` string, required — Name of the file
  - `fileType` string, required — MIME type of the file
  - `fileData` string — Base64-encoded file contents. For the web UI / direct callers. AI/MCP clients should instead upload via /v1/uploads/presign (purpose=attachment) and pass `s3Key` — base64 through an LLM is impractically slow and times out. Provide exactly one of fileData or s3Key.
  - `s3Key` string — Key of a file already uploaded via /v1/uploads/presign (purpose=attachment). The server fetches the bytes from storage — no base64 needed. Provide exactly one of fileData or s3Key.
  - `description` string — Description of the attachment
  - `userId` string — User ID of the user uploading the attachment (required for API key auth, ignored for JWT auth)
  - `entityId` string, required — ID of the entity to attach the file to
  - `entityType` 'task' | 'vendor' | 'risk' | 'comment' | 'trust_nda' | 'task_item' | 'background_check' | 'employment_onboard' | 'employment_offboard' | 'offboarding_checklist', required — Type of entity the attachment belongs to

## Response `201`

Attachment uploaded successfully

- AttachmentResponseDto
  - `id` string, required — Unique identifier for the attachment
  - `name` string, required — Original filename
  - `type` string, required — File type/MIME type
  - `size` number, required — File size in bytes
  - `downloadUrl` string, required — Signed URL for downloading the file (temporary)
  - `createdAt` string, date-time, required — Upload timestamp

## Other responses

- `400` — Invalid file data, unsupported file type, or file too large
- `401` — Unauthorized - Invalid authentication

---

[API](https://skmtc.net/trycompai/apis/comp-ai-api.md) · [All operations](https://skmtc.net/trycompai/apis/comp-ai-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/trycompai/comp-ai-api/revisions/726b9523fb22/schema)
