Get upload URL(s) for a file field

posthttps://api.expiryedge.com/v1/getCollectionUploadUrl
Public - no API key60/minAny method
Request
curl -X POST 'https://api.expiryedge.com/v1/getCollectionUploadUrl' \
  -H "Content-Type: application/json" \
  -d '{
  "token": "3f9a1c7e5b2d4f6a8c0e1b3d5f7a9c2e4b6d8f0a1c3e5b7d9f2a4c6e8b0d1f3a",
  "fieldId": "fld_insurance",
  "filename": "liability-certificate-2026.pdf",
  "contentType": "application/pdf",
  "sizeBytes": 482113
}'
Response
{
  "chunked": false,
  "uploadUrl": "https://storage.googleapis.com/stylingsphere.appspot.com/organizations/org_northwind/collection-submissions/req_9WkT/fld_insurance-6c1e-liability-certificate-2026.pdf?X-Goog-Algorithm=GOOG4-RSA-SHA256&X-Goog-Expires=900&X-Goog-Signature=...",
  "storagePath": "organizations/org_northwind/collection-submissions/req_9WkT/fld_insurance-6c1e-liability-certificate-2026.pdf",
  "uploadHeaders": {
    "Content-Type": "application/pdf"
  }
}

Files up to 20MB get one signed PUT URL (15 minutes, bound to contentType). Larger files (up to the field limit, max 500MB) get one signed PUT URL per 20MB chunk (24 hours, Content-Type: application/octet-stream); upload every chunk, then call composeCollectionUpload. Send every header in uploadHeaders with each PUT. Use the returned storagePath in submit/save calls. The handler does not check the HTTP method.

Headers

  • X-Collection-Passwordstring
    Request password, when the sender set one.

Body parameters

application/json
  • tokenstringrequired
    The token from the request link.
    pattern: ^[a-f0-9]{64}$
  • fieldIdstringrequired
    A file_upload or signature field.
  • filenamestringrequired
  • contentTypestringrequired
    Must match one of the field's allowed_types.
  • sizeBytesintegerrequired
    Declared size; must not exceed the field's max_size_bytes.
  • passwordstring
    Request password, when set (or use the X-Collection-Password header).

Returns

200
Upload instructions.
  • (body)one of
    One of
    • chunkedbooleanrequired
      Allowedfalse
    • uploadUrlstringrequired
      PUT the file here with every header in uploadHeaders (15 minutes).
      format: uri
    • storagePathstringrequired
    • uploadHeadersmap of string
      Headers to send, unchanged, with the PUT to a Document Collection signed URL.

Errors

400
Malformed token (Invalid link) or invalid input.
401
The request has a password and it is missing ({"requiresPassword": true}) or wrong.
403
The sender paused this request.
404
Unknown token (link rotated, deleted or mistyped), or the template no longer exists.
410
The request was cancelled, already completed (alreadySubmitted: true) or has expired.
429
Password locked out after 5 wrong attempts (15 minutes, per request).
500
Unexpected server error.