# Upload a media

> Upload a file to create a media.
{/* generated:versioned-pages - edit _pm-authored, not this file */}

`POST /api/medias`

Creates a Media resource.

Creates a media by uploading a file. This endpoint takes a `multipart/form-data` body (not JSON): send the binary in a `file` field. The response describes the stored media - its `contentUrl`, `mimeType`, derived `type`, `hash` and, for images, `dimensions`.

> **File size limits**
>
> Up to 5 MB for general files and 100 MB for videos. The `mimeType`, `type` and `hash` are derived from the uploaded file.

## Request body

| Property | Type     | Required | Description                                                   |
| -------- | -------- | -------- | ------------------------------------------------------------- |
| `file`   | `string` | -        | Upload file (max size: 5M for general files, 100M for videos) |

## Response

**201** - Media resource created

| Property     | Type                                     | Required | Description                                                                  |
| ------------ | ---------------------------------------- | -------- | ---------------------------------------------------------------------------- |
| `@context`   | `string \| object`                       | -        |                                                                              |
| `@id`        | `string`                                 | Yes      |                                                                              |
| `@type`      | `string`                                 | Yes      |                                                                              |
| `contentUrl` | `string \| null`                         | -        | The URL to fetch the uploaded file.                                          |
| `createdAt`  | `string \| null`                         | -        |                                                                              |
| `dimensions` | `EmbeddedImageDimensionResource \| null` | -        | Image dimensions (width and height in pixels). Only present for image files. |
| `hash`       | `string \| null`                         | -        | SHA256 hash of the file                                                      |
| `id`         | `string`                                 | -        | The resource's unique identifier (UUID).                                     |
| `mimeType`   | `string \| null`                         | -        | MIME type of the file                                                        |
| `type`       | `"image" \| "video" \| "file"`           | -        | Media type based on MIME type (image, video, or file)                        |
| `updatedAt`  | `string \| null`                         | -        |                                                                              |

## Errors

**400** - Invalid input

| Property      | Type               | Required | Description                                                                                                                          |
| ------------- | ------------------ | -------- | ------------------------------------------------------------------------------------------------------------------------------------ |
| `@context`    | `string \| object` | -        |                                                                                                                                      |
| `@id`         | `string`           | Yes      |                                                                                                                                      |
| `@type`       | `string`           | Yes      |                                                                                                                                      |
| `code`        | `string`           | -        | Stable identifier of the error in the error code catalogue (see /api/error-codes). Present on catalogued errors only.                |
| `description` | `string \| null`   | -        |                                                                                                                                      |
| `detail`      | `string \| null`   | -        | A human-readable explanation specific to this occurrence of the problem.                                                             |
| `instance`    | `string \| null`   | -        | A URI reference that identifies the specific occurrence of the problem. It may or may not yield further information if dereferenced. |
| `message`     | `string`           | -        | End-user message localized in the request locale, with this occurrence's values substituted. Present on catalogued errors only.      |
| `slug`        | `string`           | -        | Stable, readable key of the error in the error code catalogue. Present on catalogued errors only.                                    |
| `status`      | `integer \| null`  | -        |                                                                                                                                      |
| `title`       | `string \| null`   | -        | A short, human-readable summary of the problem. For a catalogued error it repeats the `slug`.                                        |
| `type`        | `string`           | -        | A URI reference that identifies the problem type. For a catalogued error it is the error code resource, `/api/error-codes/{code}`.   |

**403** - Access denied. The caller is missing one or more permissions required for this operation.

| Property             | Type               | Required | Description                                                                                                            |
| -------------------- | ------------------ | -------- | ---------------------------------------------------------------------------------------------------------------------- |
| `@context`           | `string \| object` | -        |                                                                                                                        |
| `@id`                | `string`           | Yes      |                                                                                                                        |
| `@type`              | `string`           | Yes      |                                                                                                                        |
| `detail`             | `string`           | -        |                                                                                                                        |
| `missingPermissions` | `string[]`         | -        | Permissions that the caller is missing for this operation. Present only when the 403 is caused by a denied permission. |
| `status`             | `integer`          | -        |                                                                                                                        |
| `title`              | `string`           | -        |                                                                                                                        |
| `type`               | `string`           | -        |                                                                                                                        |

**422** - An error occurred

| Property      | Type               | Required | Description |
| ------------- | ------------------ | -------- | ----------- |
| `@context`    | `string \| object` | -        |             |
| `@id`         | `string`           | Yes      |             |
| `@type`       | `string`           | Yes      |             |
| `description` | `string`           | -        |             |
| `detail`      | `string`           | -        |             |
| `instance`    | `string \| null`   | -        |             |
| `status`      | `integer`          | -        |             |
| `title`       | `string \| null`   | -        |             |
| `type`        | `string`           | -        |             |
| `violations`  | `object[]`         | -        |             |

## Examples

### Example request

```bash
curl -X POST 'https://<tenant>.product-management.flowkiwi.net/api/medias' \
  -H 'Authorization: Bearer {access_token}' \
  -H 'Flowkiwi-Api-Version: unstable' \
  -H 'Accept: application/ld+json' \
  -F 'file=@/path/to/photo.jpg'
```

### Example response

```json
{
  "@context": "/api/contexts/Media",
  "@id": "/api/medias/01234567-89ab-cdef-0123-456789abcdef",
  "@type": "https://schema.org/MediaObject",
  "contentUrl": "/uploads/medias/tshirt-red-front.jpg",
  "createdAt": "2026-01-15T09:30:00+00:00",
  "dimensions": {
    "@type": "EmbeddedImageDimensionResource",
    "height": 1200,
    "width": 1200
  },
  "hash": "9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08",
  "id": "01234567-89ab-cdef-0123-456789abcdef",
  "mimeType": "image/jpeg",
  "type": "image",
  "updatedAt": "2026-02-03T14:45:12+00:00"
}
```
