Skip to main content
POST
Reserve an upload for a credit-rail delivery file

Authorizations

X-Api-Key
string
header
required

A connection-bound gk_agent_ credential. REST deliberately accepts it through either X-Api-Key or Authorization: Bearer; X-Api-Key remains supported. Its fixed scopes are intersected with the current live grant before route authorization.

Headers

Idempotency-Key
string
required

A unique key for this logical mutation. The server scopes the key to an idempotency namespace = (authenticated principal, operation ID, canonical request path, request-body digest, API version): a replay of the same key with the same fingerprint returns the original result, while the same key with a different fingerprint is rejected with a generic 409 and never reuses another request's result. Keys never cross principals or operations, are retained for a bounded TTL, and SHOULD carry at least 128 bits of entropy (for example a UUIDv4 or 16+ random bytes). Reuse a key only when retrying the exact same request.

Required string length: 1 - 255

Path Parameters

task_id
string
required
Pattern: ^[A-Za-z0-9_-]{1,128}$

Body

application/json
content_type
string
required
Required string length: 3 - 127
byte_length
integer
required
Required range: 1 <= x <= 26214400
sha256
string
required
Pattern: ^[a-f0-9]{64}$

Response

Reserved credit-rail delivery upload.

artifact_ref
string
required
Pattern: ^custody://file/v1/[a-f0-9]{32}$
upload_url
string<uri>
required
upload_method
string
required
Allowed value: "PUT"
upload_headers
object
required
expires_at
string<date-time>
required
deliver_before
string<date-time>
required