> ## Documentation Index
> Fetch the complete documentation index at: https://docs.azalt.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Create presigned URL for file upload

> Get a secure upload URL for sending files directly to cloud storage, avoiding server bandwidth limits.

**Required parameters**:
- `fileName`: Your file name with extension (e.g., "report.pdf")
- `contentType`: File type (e.g., "image/jpeg", "application/pdf")
- `entityType`: What this file relates to (e.g., "form-submission", "organization")
- `entityId`: ID of the related item

**Security features**:
- Upload URLs expire in 15 minutes for security
- Files go to your organization's private storage area
- Only allowed file types can be uploaded
- Files are automatically organized by what they relate to

**How to upload**:
1. Call this endpoint to get your secure upload URL
2. Upload your file directly to that URL (from your app/browser)
3. File becomes available in the system immediately

**Supported files**: Images, PDFs, spreadsheets, and documents as configured by your system admin.



## OpenAPI

````yaml https://app.azalt.co/api/v1/openapi.json post /media/presigned-url
openapi: 3.0.3
info:
  title: Erguvan Public API
  version: 1.0.0
servers:
  - url: https://app.azalt.co/api/v1
security: []
paths:
  /media/presigned-url:
    post:
      tags:
        - File
      summary: Create presigned URL for file upload
      description: >-
        Get a secure upload URL for sending files directly to cloud storage,
        avoiding server bandwidth limits.


        **Required parameters**:

        - `fileName`: Your file name with extension (e.g., "report.pdf")

        - `contentType`: File type (e.g., "image/jpeg", "application/pdf")

        - `entityType`: What this file relates to (e.g., "form-submission",
        "organization")

        - `entityId`: ID of the related item


        **Security features**:

        - Upload URLs expire in 15 minutes for security

        - Files go to your organization's private storage area

        - Only allowed file types can be uploaded

        - Files are automatically organized by what they relate to


        **How to upload**:

        1. Call this endpoint to get your secure upload URL

        2. Upload your file directly to that URL (from your app/browser)

        3. File becomes available in the system immediately


        **Supported files**: Images, PDFs, spreadsheets, and documents as
        configured by your system admin.
      operationId: createPresignedUrl
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                fileName:
                  type: string
                fileSize:
                  type: number
                entityType:
                  type: string
                  enum:
                    - Organization
                    - User
                    - FormSubmission
                    - FormElementSubmission
                    - ReportTemplate
                    - ComplianceCheck
                    - Activity
                    - FormElement
                    - FormSite
                    - ReportSection
                    - Report
                    - ReportSectionTemplateExample
                    - AiConversation
                entityId:
                  type: string
                fieldName:
                  type: string
              required:
                - fileName
                - entityType
                - entityId
                - fieldName
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  url:
                    type: string
                  fields:
                    type: object
                    additionalProperties:
                      type: string
                  mediaId:
                    type: string
                  mediaKey:
                    type: string
                required:
                  - url
                  - fields
                  - mediaId
                  - mediaKey
        '400':
          description: Invalid input data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.BAD_REQUEST'
        '401':
          description: Authorization not provided
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.UNAUTHORIZED'
        '403':
          description: Insufficient access
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.FORBIDDEN'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.INTERNAL_SERVER_ERROR'
      security:
        - Authorization: []
components:
  schemas:
    error.BAD_REQUEST:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Invalid input data
        code:
          type: string
          description: The error code
          example: BAD_REQUEST
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Invalid input data error (400)
      description: The error information
      example:
        code: BAD_REQUEST
        message: Invalid input data
        issues: []
    error.UNAUTHORIZED:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Authorization not provided
        code:
          type: string
          description: The error code
          example: UNAUTHORIZED
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Authorization not provided error (401)
      description: The error information
      example:
        code: UNAUTHORIZED
        message: Authorization not provided
        issues: []
    error.FORBIDDEN:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Insufficient access
        code:
          type: string
          description: The error code
          example: FORBIDDEN
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Insufficient access error (403)
      description: The error information
      example:
        code: FORBIDDEN
        message: Insufficient access
        issues: []
    error.INTERNAL_SERVER_ERROR:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Internal server error
        code:
          type: string
          description: The error code
          example: INTERNAL_SERVER_ERROR
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Internal server error error (500)
      description: The error information
      example:
        code: INTERNAL_SERVER_ERROR
        message: Internal server error
        issues: []
  securitySchemes:
    Authorization:
      type: http
      scheme: bearer

````