> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://help.moveworks.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://help.moveworks.com/_mcp/server.

# Upload file

POST https://api.moveworks.ai/rest/v1alpha1/files
Content-Type: multipart/form-data

Uploads a single file and creates a File resource, returning its stable `id`.

The request is `multipart/form-data`, not JSON. The `file` part must come last: the upload is streamed, so send `purpose` (and any other field) **before** it. A part that arrives after `file`, or a second `file` part, is rejected with `400`.

Moveworks determines `content_type` by inspecting the bytes. A declared media type or a filename extension is not trusted, and the detected type is what the response reports.

A `201` is returned only after the bytes are stored and the file has passed its security checks, so a successful response always describes a file that is ready to reference.

Uploaded files are retained for 24 hours. After `expire_time`, both the file and its metadata are removed, and the `id` no longer resolves. Reference the `id` from a downstream API before then.

There is no `GET`, `LIST`, download, or `DELETE` operation in `v1alpha1`. A file is reached only by passing its `id` to an API that accepts one.

Reference: https://help.moveworks.com/api-reference/alpha-files-api/files/upload-file

## Authentication

- `Authorization` header (bearer token, required) — JWT bearer token authentication. Obtain an access token from the Moveworks auth endpoint and include it in the Authorization header as 'Bearer \<token>'.

## Request

### Body (multipart/form-data)

This endpoint expects a multipart form containing a file.

- `purpose` (enum, required) — What the file is for. Must be sent before the `file` part.
- `file` (file, required) — The file to upload, sent as raw bytes rather than base64. The part's `filename` parameter supplies the response `name` and is required; `curl -F "file=@./screenshot.png"` sets both. Maximum 100 MB. The filename must be 1-255 characters after Unicode NFC normalization. It cannot be `.` or `..`, contain `/`, `\`, control characters, or bidirectional formatting characters, or be empty once trimmed.

## Response

### 201

File uploaded and File resource created

- `id` (string, required) — Opaque, stable identifier for the File resource. Pass it to other Moveworks APIs; do not parse it.
- `purpose` (enum, required) — The purpose the file was uploaded with.
  - Allowed values: `CONVERSATIONS_ATTACHMENT`
- `name` (string, required) — The filename from the uploaded `file` part, after Unicode normalization.
- `content_type` (string, required) — IANA media type detected by Moveworks from the file's bytes. This is authoritative over anything the request declared.
- `size_bytes` (long, required) — Exact number of bytes stored.
- `create_time` (datetime, required) — RFC 3339 UTC timestamp of when the File resource was created.
- `expire_time` (datetime, required, nullable) — RFC 3339 UTC timestamp of when the file and its metadata are removed, 24 hours after `create_time`. Once it passes, the `id` no longer resolves. The field is nullable for forward compatibility with a non-expiring purpose, but `CONVERSATIONS_ATTACHMENT` always expires, so it is never `null` today.

## Errors

### 400 Bad Request Error

Bad request - the body is not valid multipart, the `file` part is missing or carries no filename, the filename is invalid, `purpose` is missing, unrecognized, or sent after the `file` part, or the file is empty

- `error` (BadRequestErrorResponseError, required)

### 401 Unauthorized Error

Unauthorized - Invalid or missing authentication

- `error` (UnauthorizedErrorResponseError, required)

### 403 Forbidden Error

Forbidden - the credential is not permitted to upload files

- `error` (ForbiddenErrorResponseError, required)

### 413 Content Too Large Error

Payload too large - the file exceeds the 100 MB limit

- `error` (PayloadTooLargeErrorResponseError, required)

### 422 Unprocessable Entity Error

Unprocessable entity - the file was read but its content failed validation

- `error` (UnprocessableEntityErrorResponseError, required)

### 429 Too Many Requests Error

Rate limit exceeded

- `error` (RateLimitExceededErrorResponseError, required)

### 500 Internal Server Error

Internal server error

- `error` (InternalErrorResponseError, required)

## Types

### BadRequestErrorResponseError

- `code` (enum, required)
  - Allowed values: `BAD_REQUEST`
- `message` (string, required)

### UnauthorizedErrorResponseError

- `code` (enum, required)
  - Allowed values: `UNAUTHORIZED`
- `message` (string, required)

### ForbiddenErrorResponseError

- `code` (enum, required)
  - Allowed values: `FORBIDDEN`
- `message` (string, required)

### PayloadTooLargeErrorResponseError

- `code` (enum, required)
  - Allowed values: `PAYLOAD_TOO_LARGE`
- `message` (string, required)

### UnprocessableEntityErrorResponseError

- `code` (enum, required)
  - Allowed values: `UNPROCESSABLE_ENTITY`
- `message` (string, required)

### RateLimitExceededErrorResponseError

- `code` (enum, required)
  - Allowed values: `RATE_LIMIT_EXCEEDED`
- `message` (string, required)

### InternalErrorResponseError

- `code` (enum, required)
  - Allowed values: `INTERNAL_SERVER_ERROR`
- `message` (string, required)

## Examples

**Request**

```json
{
  "file": "<file: string>",
  "purpose": "CONVERSATIONS_ATTACHMENT"
}
```

**Response**

```json
{
  "id": "file_2yE5b2NC3Ypa2FszHbkh7",
  "purpose": "CONVERSATIONS_ATTACHMENT",
  "name": "screenshot.png",
  "content_type": "image/png",
  "size_bytes": 482133,
  "create_time": "2026-08-26T05:11:00Z",
  "expire_time": "2026-08-27T05:11:00Z"
}
```

**SDK Code**

```python Files_uploadFile_example
import requests

url = "https://api.moveworks.ai/rest/v1alpha1/files"

files = { "file": "open('string', 'rb')" }
payload = { "purpose": "CONVERSATIONS_ATTACHMENT" }
headers = {"Authorization": "Bearer <token>"}

response = requests.post(url, data=payload, files=files, headers=headers)

print(response.json())
```

```javascript Files_uploadFile_example
const url = 'https://api.moveworks.ai/rest/v1alpha1/files';
const form = new FormData();
form.append('file', 'string');
form.append('purpose', 'CONVERSATIONS_ATTACHMENT');

const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};

options.body = form;

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Files_uploadFile_example
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.moveworks.ai/rest/v1alpha1/files"

	payload := strings.NewReader("-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"string\"\r\nContent-Type: application/octet-stream\r\n\r\n\r\n-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"purpose\"\r\n\r\nCONVERSATIONS_ATTACHMENT\r\n-----011000010111000001101001--\r\n")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Files_uploadFile_example
require 'uri'
require 'net/http'

url = URI("https://api.moveworks.ai/rest/v1alpha1/files")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request.body = "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"string\"\r\nContent-Type: application/octet-stream\r\n\r\n\r\n-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"purpose\"\r\n\r\nCONVERSATIONS_ATTACHMENT\r\n-----011000010111000001101001--\r\n"

response = http.request(request)
puts response.read_body
```

```java Files_uploadFile_example
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.moveworks.ai/rest/v1alpha1/files")
  .header("Authorization", "Bearer <token>")
  .body("-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"string\"\r\nContent-Type: application/octet-stream\r\n\r\n\r\n-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"purpose\"\r\n\r\nCONVERSATIONS_ATTACHMENT\r\n-----011000010111000001101001--\r\n")
  .asString();
```

```php Files_uploadFile_example
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.moveworks.ai/rest/v1alpha1/files', [
  'multipart' => [
    [
        'name' => 'file',
        'filename' => 'string',
        'contents' => null
    ],
    [
        'name' => 'purpose',
        'contents' => 'CONVERSATIONS_ATTACHMENT'
    ]
  ]
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

```csharp Files_uploadFile_example
using RestSharp;

var client = new RestClient("https://api.moveworks.ai/rest/v1alpha1/files");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddParameter("undefined", "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"string\"\r\nContent-Type: application/octet-stream\r\n\r\n\r\n-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"purpose\"\r\n\r\nCONVERSATIONS_ATTACHMENT\r\n-----011000010111000001101001--\r\n", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift Files_uploadFile_example
import Foundation

let headers = ["Authorization": "Bearer <token>"]
let parameters = [
  [
    "name": "file",
    "fileName": "string"
  ],
  [
    "name": "purpose",
    "value": "CONVERSATIONS_ATTACHMENT"
  ]
]

let boundary = "---011000010111000001101001"

var body = ""
var error: NSError? = nil
for param in parameters {
  let paramName = param["name"]!
  body += "--\(boundary)\r\n"
  body += "Content-Disposition:form-data; name=\"\(paramName)\""
  if let filename = param["fileName"] {
    let contentType = param["content-type"]!
    let fileContent = String(contentsOfFile: filename, encoding: String.Encoding.utf8)
    if (error != nil) {
      print(error as Any)
    }
    body += "; filename=\"\(filename)\"\r\n"
    body += "Content-Type: \(contentType)\r\n\r\n"
    body += fileContent
  } else if let paramValue = param["value"] {
    body += "\r\n\r\n\(paramValue)"
  }
}

let request = NSMutableURLRequest(url: NSURL(string: "https://api.moveworks.ai/rest/v1alpha1/files")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```