> ## Documentation Index
> Fetch the complete documentation index at: https://docs.quivr.thevibecompany.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Create upload

> Create a transfer session with a single presigned PUT URL, required headers and expiry. Initial limits: 1 GiB Blob, configurable; oversized uploads are rejected before a session is issued.



## OpenAPI

````yaml /openapi.yaml post /v0/uploads
openapi: 3.1.0
info:
  title: Quivr V2 public text foundation contract
  version: 0.0.0-draft
  description: >-
    THE-543 and THE-547 evaluation contracts; endpoint implementations are
    separate work. Matching criterion is plugin-owned and deferred. One
    configured webhook destination, immutable Matches, independent at-least-once
    Delivery and reference-only notifications. OpenAPI is authoritative for
    transport shapes. THE-640 adds text search and asynchronous Corpus
    projection rebuild initiation.
servers: []
security:
  - ApiKey: []
paths:
  /v0/uploads:
    post:
      tags:
        - Uploads
      summary: Create upload
      description: >-
        Create a transfer session with a single presigned PUT URL, required
        headers and expiry. Initial limits: 1 GiB Blob, configurable; oversized
        uploads are rejected before a session is issued.
      operationId: createUpload
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UploadRequest'
      responses:
        '201':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Upload'
        default:
          description: >-
            Structured error. 400 malformed; 401 unauthenticated; 403 forbidden
            action; 404 absent or inaccessible; 409 conflict; 413 oversized; 422
            invalid input; 429 throttled; 503 temporary failure.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    UploadRequest:
      type: object
      additionalProperties: false
      properties:
        size_bytes:
          type: integer
          minimum: 1
          maximum: 1073741824
        sha256:
          type: string
          pattern: ^[a-f0-9]{64}$
        media_type:
          type: string
          minLength: 1
      required:
        - size_bytes
        - sha256
        - media_type
    Upload:
      type: object
      additionalProperties: false
      properties:
        upload_id:
          type: string
          minLength: 1
        state:
          type: string
          enum:
            - awaiting_upload
            - verifying
            - verified
            - rejected
            - expired
        upload_url:
          type: string
          format: uri
        upload_headers:
          type: object
          additionalProperties:
            type: string
        expires_at:
          type: string
          format: date-time
        blob_id:
          type: string
          minLength: 1
        error:
          $ref: '#/components/schemas/Error'
        upload_method:
          type: string
          enum:
            - PUT
      required:
        - upload_id
        - state
      description: >-
        Upload URL and headers are transfer capabilities. Only verified uploads
        expose a usable Blob ID. Repeated confirmation of the same session
        observes the same verification, never a second upload.
      allOf:
        - if:
            properties:
              state:
                const: verified
          then:
            required:
              - blob_id
          else:
            not:
              required:
                - blob_id
    Error:
      type: object
      additionalProperties: false
      properties:
        code:
          type: string
          minLength: 1
        message:
          type: string
          minLength: 1
        retryable:
          type: boolean
        field:
          type: string
          minLength: 1
          description: >-
            JSON Pointer (RFC 6901) to the request member that caused a 422,
            when known (for example /config/url or /credential/secret/token on
            connector commands).
        resync_url:
          type: string
          format: uri-reference
      required:
        - code
        - message
        - retryable
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      description: >-
        API key, not necessarily a JWT. Server derives Organization, permitted
        actions and Corpus scope; every resource access is authorized.

````