---
title: "Upload one evidence file, link token in a header (public; multipart, one part named file)"
method: POST
path: "/shared/supplier-request/files"
tags: ["Supplier portal"]
---

# Upload one evidence file, link token in a header (public; multipart, one part named file)

`POST /shared/supplier-request/files`

The token travels in the X-Greentally-Share-Token header. Rules: the evidenceFiles section (409 SECTION_NOT_REQUESTED), a request open for answers (409 INVALID_STATE), one upload or delete at a time per link (409 UPLOAD_IN_PROGRESS), at most 20 files (409 TOO_MANY_FILES) of 10 MiB (413 FILE_TOO_LARGE), .pdf, .png, .jpg, .jpeg, .csv or .xlsx with matching content (415 UNSUPPORTED_MEDIA_TYPE), 503 OBJECT_STORE_UNAVAILABLE when no file store is configured or it fails.

## Headers

- `X-Greentally-Share-Token` string, required

## Response `201`

The stored file

- SupplierPortalFileResponse
  - `data` SupplierPortalFile, required
    - `contentType` string, required
    - `fileName` string, required
    - `id` string, required
    - `sizeBytes` integer, required
    - `uploadedAt` string, date-time, required

## Other responses

- `400` — Bad Request
- `404` — Not Found
- `409` — Conflict
- `410` — Gone
- `413` — Payload Too Large
- `415` — Unsupported Media Type
- `429` — Too Many Requests
- `503` — OBJECT_STORE_UNAVAILABLE: no file store is configured, or it failed

## Changes

- **2026-10-06** `461a0ebc7731` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/greentally/apis/esgai-api/changes/shared/supplier-request/files/post.md)

---

[API](https://skmtc.dev/greentally/apis/esgai-api.md) · [All operations](https://skmtc.dev/greentally/apis/esgai-api/llms.txt) · [OpenAPI document](https://skmtc.dev/greentally/apis/esgai-api/revisions/461a0ebc7731?raw)
