---
title: "Upload app file"
method: POST
path: "/api/files/apps/{app_id}/upload"
---

# Upload app file

`POST /api/files/apps/{app_id}/upload`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Uploads a file to the app's storage and returns a link to it.

Send the file as `multipart/form-data`. Use the public link of an uploaded image as `logo_url` in [Set app logo](/api-reference/set-app-logo) or as `social_image_url` in [Set social image](/api-reference/set-social-image).

A public file gets a permanent link that anyone can open. A private file gets a signed link that expires after `expires_in` seconds, one hour at most, and this API has no way to get a new link for it. Upload a private file only when you use its link right away.

The size limit depends on the extension in the file name. For example, it's 40 MB for JPEG, PNG, GIF and WebP images, 5 MB for SVG, 100 MB for video and MP3 or WAV audio, and 10 MB for PDF and for any extension without its own limit. Executable and script files such as `.exe`, `.bat`, `.jar` and `.apk` are refused. Files are scanned for malware after the upload returns.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>

## Path parameters

- `app_id` string, required — ID of the app to upload the file to.

## Response `200`

The stored file and its link.

- UploadedAppFile — Doc-only: the handler returns a plain dict with exactly these keys.
  - `file_uri` string, required — Storage URI of the file. `mp/public/` or `mp/private/` shows its visibility.
  - `url` string, required — Link to the file. For a public file it's permanent and anyone with it can open the file. For a private file it's a signed link that stops working after `expires_in` seconds.

## Other responses

- `400` — The file is empty, too large for its extension, of a refused type, or its size couldn't be determined.
- `401` — Missing or invalid credentials.
- `403` — You don't have editor access to this app, or your API key is read-only.
- `404` — App not found.
- `422` — `file` is missing, `visibility` isn't `public` or `private`, or `expires_in` is outside 60 to 3600.

## Changes

> 18 revisions in range; 1 not diffed.

- **2026-09-28** `28fc82924122` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/adexad/apis/base44-app-management-api/changes/api/files/apps/:app_id/upload/post.md)

---

[API](https://skmtc.dev/adexad/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/adexad/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/adexad/apis/base44-app-management-api/revisions/28fc82924122?raw)
