Get upload URL(s) for a file field
post
https://api.expiryedge.com/v1/getCollectionUploadUrlPublic - no API key60/minAny method
Request
curl -X POST 'https://api.expiryedge.com/v1/getCollectionUploadUrl' \
-H "Content-Type: application/json" \
-d '{
"token": "3f9a1c7e5b2d4f6a8c0e1b3d5f7a9c2e4b6d8f0a1c3e5b7d9f2a4c6e8b0d1f3a",
"fieldId": "fld_insurance",
"filename": "liability-certificate-2026.pdf",
"contentType": "application/pdf",
"sizeBytes": 482113
}'Response
{
"chunked": false,
"uploadUrl": "https://storage.googleapis.com/stylingsphere.appspot.com/organizations/org_northwind/collection-submissions/req_9WkT/fld_insurance-6c1e-liability-certificate-2026.pdf?X-Goog-Algorithm=GOOG4-RSA-SHA256&X-Goog-Expires=900&X-Goog-Signature=...",
"storagePath": "organizations/org_northwind/collection-submissions/req_9WkT/fld_insurance-6c1e-liability-certificate-2026.pdf",
"uploadHeaders": {
"Content-Type": "application/pdf"
}
}Files up to 20MB get one signed PUT URL (15 minutes, bound to contentType). Larger files (up to the field limit, max 500MB) get one signed PUT URL per 20MB chunk (24 hours, Content-Type: application/octet-stream); upload every chunk, then call composeCollectionUpload. Send every header in uploadHeaders with each PUT. Use the returned storagePath in submit/save calls. The handler does not check the HTTP method.
X-Collection-PasswordstringRequest password, when the sender set one.
tokenstringrequiredThe token from the request link.pattern: ^[a-f0-9]{64}$fieldIdstringrequiredAfile_uploadorsignaturefield.filenamestringrequiredcontentTypestringrequiredMust match one of the field'sallowed_types.sizeBytesintegerrequiredDeclared size; must not exceed the field'smax_size_bytes.passwordstringRequest password, when set (or use theX-Collection-Passwordheader).
200
Upload instructions.
(body)one ofOne ofchunkedbooleanrequiredAllowedfalseuploadUrlstringrequiredPUT the file here with every header inuploadHeaders(15 minutes).format: uristoragePathstringrequireduploadHeadersmap of stringHeaders to send, unchanged, with the PUT to a Document Collection signed URL.
400 | Malformed token ( Invalid link) or invalid input. |
401 | The request has a password and it is missing ( {"requiresPassword": true}) or wrong. |
403 | The sender paused this request. |
404 | Unknown token (link rotated, deleted or mistyped), or the template no longer exists. |
410 | The request was cancelled, already completed ( alreadySubmitted: true) or has expired. |
429 | Password locked out after 5 wrong attempts (15 minutes, per request). |
500 | Unexpected server error. |
