---
title: "Upload an attachment"
method: POST
path: "/attachments/"
tags: ["Attachments"]
---

# Upload an attachment

`POST /attachments/`

Upload an attachment. An API attachment key must be created first. Must be submitted using multipart/form-data encoding.

## Response `200`

OK

- object
  - `attachment` Attachment
    - `filename` string
    - `file_size` integer
    - `height` integer
    - `width` integer
    - `thumbnail_url` string
    - `retina_thumbnail_url` string
    - `direct_url` string
    - `is_video` boolean
    - `is_audio` boolean
    - `attachment_id` integer
    - `content_type` string
    - `content_id` integer
    - `attach_date` integer
    - `view_count` integer

## Other responses

- `default` — Error

## Changes

- **2026-03-18** `e271d0e41f6d` — 3 breaking, 7 info
  - request body became required
  - removed the media type `application/json` from the request body
  - removed the media type `application/x-www-form-urlencoded` from the request body
  - api operation id `post_attachments_` removed and replaced with `postAttachments`
  - …6 more
- **2026-02-03** `fc0a40f3b859` — 1 breaking, 4 warning, 7 info
  - removed the media type `multipart/form-data` from the request body
  - the optional response header `XF-Latest-Api-Version` removed for the status `200`
  - the optional response header `XF-Request-User` removed for the status `200`
  - the optional response header `XF-Request-User-Extras` removed for the status `200`
  - …8 more

[Change history](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/changes/attachments/post.md)

---

[API](https://skmtc.dev/xenforo-ltd/apis/xenforo-api.md) · [All operations](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/xenforo-ltd/xenforo-api/revisions/b15eba33657a/schema)
