Skip to main content
TempCDN logo
TempCDN
reference

File upload API docs

Everything you need to upload, look up, and delete files through the free TempCDN REST API. No authentication, no API keys — just a base url and standard HTTP requests.

base url
https://srv1.tempcdn.eu.cc/api/v1

All endpoints below are relative to this base url. Only one node is currently configured or reachable, so there's nothing to round-robin against right now.

Upload config

GET/api/v1/config

Returns the server's current upload constraints — max file size, allowed MIME types, blocked extensions, and retention TTL. The front-end fetches this once per session to size-check files client-side before uploading, so limits shown in the UI always reflect the server's actual configuration.

request
curl https://srv1.tempcdn.eu.cc/api/v1/config
200 OK
{
  "max_upload_size_bytes": 134217728,
  "max_upload_size_mb": 128,
  "allowed_mime_types": [
    "image/*",
    "video/*",
    "application/pdf",
    "application/zip",
    "text/plain"
  ],
  "blocked_extensions": [
    ".exe",
    ".bat",
    ".sh",
    ".msi",
    ".dll",
    ".scr"
  ],
  "file_ttl_hours": 24
}
error responses
500

Unexpected server-side failure.

Upload a file

POST/api/v1/upload

Accepts multipart/form-data with a single file field. No authentication required.

FieldTypeRequiredDescription
filefileYesThe file to upload.
validation rules
  • File must not be empty and must not exceed the server's max upload size.
  • File extension must not be on the blocked-extension list.
  • Content type is detected by sniffing the file's magic bytes (not the client-supplied Content-Type) and must match an allowed MIME pattern.
  • If the file's SHA-256 checksum matches an existing, non-expired file, no new object is stored — the existing record is returned with duplicate: true.
request
curl -X POST https://srv1.tempcdn.eu.cc/api/v1/upload \
  -F "file=@photo.png;type=image/png"
200 OK
{
  "id": "b6b3f6d2-9b1a-4e8b-8a7a-2e6c9e6b0a11",
  "original_name": "photo.png",
  "content_type": "image/png",
  "size_bytes": 20481,
  "checksum_sha256": "e3b0c442...b7852b85",
  "object_key": "2026/08/09/b6b3f6d2-....png",
  "cdn_url": "https://files.tempcdn.eu.cc/2026/08/09/b6b3f6d2-....png",
  "created_at": "2026-08-09T10:15:00Z",
  "expires_at": "2026-08-10T10:15:00Z",
  "duplicate": false,
  "delete_token": "dt_9f2c1a7e4b3d8f6a0c5e2b7d1a4f8c3e"
}

delete_token is only ever returned here, in the upload response. Save it alongside the id — it's required to delete this file later, and it cannot be retrieved again afterwards (including from GET /api/v1/files/{id}).

error responses
400

Missing file field, invalid multipart data, empty or oversized file, blocked extension, or disallowed content type.

503

Server reached its concurrent-upload limit. Retry shortly.

504

Upload processing exceeded the request deadline.

500

Unexpected server-side failure.

Get file info

GET/api/v1/files/{id}

Retrieves metadata for a previously uploaded file, identified by the id returned from the upload response.

request
curl https://srv1.tempcdn.eu.cc/api/v1/files/b6b3f6d2-9b1a-4e8b-8a7a-2e6c9e6b0a11
200 OK
{
  "id": "b6b3f6d2-9b1a-4e8b-8a7a-2e6c9e6b0a11",
  "original_name": "photo.png",
  "content_type": "image/png",
  "size_bytes": 20481,
  "checksum_sha256": "e3b0c442...b7852b85",
  "object_key": "2026/08/09/b6b3f6d2-....png",
  "cdn_url": "https://files.tempcdn.eu.cc/2026/08/09/b6b3f6d2-....png",
  "created_at": "2026-08-09T10:15:00Z",
  "expires_at": "2026-08-10T10:15:00Z",
  "expired": false
}
error responses
404

No file exists with the given ID.

410

File record exists but has already expired. The body still includes the metadata, with expired: true.

500

Unexpected server-side failure.

Delete a file

DELETE/api/v1/files/{id}

Deletes a file before its TTL expires. Requires the delete_token issued in the original /upload response — pass it as the X-Delete-Token header, or as a delete_token query parameter if setting a custom header isn't practical for your client. Knowing the file's id alone is no longer enough to delete it.

Knowing a file's id alone is not enough to delete it — you must have the matching delete_token. Files with no token on record (e.g. shared links you don't own) can't be deleted this way; they're still removed automatically once their TTL expires.

request (header)
curl -X DELETE https://srv1.tempcdn.eu.cc/api/v1/files/b6b3f6d2-9b1a-4e8b-8a7a-2e6c9e6b0a11 \
  -H "X-Delete-Token: dt_9f2c1a7e4b3d8f6a0c5e2b7d1a4f8c3e"
request (query param alternative)
curl -X DELETE "https://srv1.tempcdn.eu.cc/api/v1/files/b6b3f6d2-9b1a-4e8b-8a7a-2e6c9e6b0a11?delete_token=dt_9f2c1a7e4b3d8f6a0c5e2b7d1a4f8c3e"
200 OK
{ "deleted": true }
error responses
403

Missing, invalid, or already-blank X-Delete-Token / delete_token. This includes files that predate delete-token support — they have no token to check against and can no longer be deleted this way.

404

No file exists with the given ID.

410

File exists but has already expired.

500

Unexpected server-side failure.