Media API
5 operations. Authentication, errors and pagination work as described in the REST API overview.
Get a media item
GET/api/v1/media/{id}Token optional
The owner sees every status. Others see only ready, scan-clean media attached to something they can read. URLs point at media.incantory.ai.
| Name | Type | Description |
|---|---|---|
id pathrequired | string | Media id |
Responses: 200 OK304, 400, 404, 429
Response fields
| Name | Type | Description |
|---|---|---|
idrequired | string | |
kindrequired | "image" | "video" | "file" | |
mimerequired | string | |
bytesrequired | integer (-9007199254740991–9007199254740991) | |
statusrequired | "uploading" | "processing" | "ready" | "failed" | "quarantined" | |
scanStatusrequired | "pending" | "clean" | "infected" | "error" | null | |
urlrequired | string | null | |
widthrequired | integer (-9007199254740991–9007199254740991) | null | |
heightrequired | integer (-9007199254740991–9007199254740991) | null | |
durationSrequired | number | null | |
blurhashrequired | string | null | |
posterUrlrequired | string | null | |
variantsrequired | object[] | |
altrequired | string | null | |
filenamerequired | string | null |
curl 'https://incantory.ai/api/v1/media/{id}' \
-H "Authorization: Bearer $INCANTORY_TOKEN"Open a resumable upload
POST/api/v1/uploadsToken required
Declares the file (filename, mime, bytes, purpose) and returns a session with partSize and partCount. Limits per purpose: images 20 MB (avatars 5 MB), video mp4/webm 200 MB, files 100 MB. SVG and HTML are refused; types are checked by magic bytes when the bytes arrive. Sessions expire after 24 hours. Session (browser) auth only: API tokens cannot upload media.
Request body
| Name | Type | Description |
|---|---|---|
filenamerequired | string | |
mimerequired | string | |
bytesrequired | integer (…–2147483647) | |
sha256 | string | |
purposerequired | "make" | "example" | "post" | "avatar" | "prompt_file" | "make_file" | |
alt | string | |
contentRating | "general" | "mature" |
Responses: 201 OK400, 401, 403, 404, 413, 415, 429
Response fields
| Name | Type | Description |
|---|---|---|
idrequired | string | |
mediaIdrequired | string | |
partSizerequired | integer (-9007199254740991–9007199254740991) | |
partCountrequired | integer (-9007199254740991–9007199254740991) | |
presignedParts | object[] | |
expiresAtrequired | string |
curl -X POST 'https://incantory.ai/api/v1/uploads' \
-H "Authorization: Bearer $INCANTORY_TOKEN" \
-H 'Content-Type: application/json' \
-d '{"filename":"filename","mime":"mime","bytes":1,"purpose":"make"}'Cancel an upload
DELETE/api/v1/uploads/{id}Token required
Aborts the multipart upload and discards the stored parts.
| Name | Type | Description |
|---|---|---|
id pathrequired | string | Upload session id (= the media id) |
Responses: 204 OK400, 401, 403, 404, 409, 429
curl -X DELETE 'https://incantory.ai/api/v1/uploads/{id}' \
-H "Authorization: Bearer $INCANTORY_TOKEN"Finish an upload
POST/api/v1/uploads/{id}/completeToken required
Assembles the parts and returns the MediaView with status processing; the worker makes variants (images/video) and scans it, then status becomes ready (files: only once the malware scan is clean). Idempotent.
| Name | Type | Description |
|---|---|---|
id pathrequired | string | Upload session id (= the media id) |
Responses: 200 OK400, 401, 403, 404, 409, 410, 415, 429
Response fields
| Name | Type | Description |
|---|---|---|
idrequired | string | |
kindrequired | "image" | "video" | "file" | |
mimerequired | string | |
bytesrequired | integer (-9007199254740991–9007199254740991) | |
statusrequired | "uploading" | "processing" | "ready" | "failed" | "quarantined" | |
scanStatusrequired | "pending" | "clean" | "infected" | "error" | null | |
urlrequired | string | null | |
widthrequired | integer (-9007199254740991–9007199254740991) | null | |
heightrequired | integer (-9007199254740991–9007199254740991) | null | |
durationSrequired | number | null | |
blurhashrequired | string | null | |
posterUrlrequired | string | null | |
variantsrequired | object[] | |
altrequired | string | null | |
filenamerequired | string | null |
curl -X POST 'https://incantory.ai/api/v1/uploads/{id}/complete' \
-H "Authorization: Bearer $INCANTORY_TOKEN"Upload one part (raw bytes)
PUT/api/v1/uploads/{id}/parts/{n}Token required
Body: application/octet-stream, exactly partSize bytes except the last part. Re-sending a part number replaces it, so a client resumes by re-sending the parts it is unsure of. Part 1 is magic-byte checked: a mismatching, markup or executable file fails the upload with 415.
| Name | Type | Description |
|---|---|---|
id pathrequired | string | Upload session id |
n pathrequired | string | Part number, 1-based |
Responses: 200 OK400, 401, 403, 404, 409, 410, 413, 415, 429
Response fields
| Name | Type | Description |
|---|---|---|
nrequired | integer (-9007199254740991–9007199254740991) | |
sizerequired | integer (-9007199254740991–9007199254740991) | |
etagrequired | string |
curl -X PUT 'https://incantory.ai/api/v1/uploads/{id}/parts/{n}' \
-H "Authorization: Bearer $INCANTORY_TOKEN"