Skip to main content
Version: v3

Upload file attachments

POST 

/conversations/messages/upload

Post the necessary fields for the API to upload files. The files need to be a buffer with the key "fileAttachment".

Note: One of conversationId or contactId must be provided.

File Size Limits:

  • Maximum file size: 5 MB
  • Maximum files per upload: 5

Allowed file types:

Images: JPG, JPEG, PNG, GIF, SVG, HEIC, AI

Videos: MP4, MPEG, 3GP

Audio: MP3, WAV, WAVE, AIFF, AIF, AIFC, GSM, ULAW, OGG, AAC, M4A, AMR

Documents: PDF, DOC, DOCX, TXT, CSV, XLS, XLSX, PPT, PPTX, ODT

Archives: ZIP, RAR

Other: VCF, VCARD (contact files), ICS (calendar files)

The API will return an object with the URLs

Secure attachments: Set isSecureAttachment to true to upload the file as a secure attachment. This is currently supported for the email channel only; support for the remaining conversation channels is coming.

A secure attachment is returned with a /files/d/{slug} URL that is publicly accessible for one hour after upload. After that window the attachment becomes private — to render, download, or retry access, extract the {slug} from the returned URL and call GET /files/d/{slug} with a bearer token carrying the files.readonly OAuth scope, which returns a short-lived signed download URL. A file uploaded without this flag keeps its existing permanently accessible URL.

Note: From 30 November 2026 every file uploaded through this endpoint is stored as a secure attachment, and the isSecureAttachment field is ignored.

Request​

Version stringrequired

API Version

Available optionsv3
multipart/form-data

Bodyrequired

    conversationIdstring

    Conversation Id

    contactIdstring

    Contact Id

    workflowIdstring

    Workflow Id

    campaignIdstring

    Campaign Id

    locationIdstringrequired
    attachmentUrlsstring[]required
    isSecureAttachmentstring

    Set to true to upload the file as a secure attachment. Defaults to false. Currently supported for the email channel only; support for the remaining conversation channels is coming. A secure attachment URL is publicly accessible for one hour after upload, after which the file must be fetched with GET /files/d/{slug} using the files.readonly OAuth scope. Considered only until 30 November 2026; from that date every upload is stored as a secure attachment and this field is ignored.

    Default value: false
application/json

Uploaded the file successfully

Schema
    uploadedFilesobjectrequired