Files
You upload documents in three steps. Bodo checks type, size, checksum and file signature before a document becomes visible.
Upload in three steps
- 11. Create an upload session
POST /v1/uploadswith name, type, size and SHA-256. The answer names method, address and headers for the file; the target is valid for 15 minutes, the session for 24 hours. - 22. Send the raw bytes
Exactly with method, address and headers from the answer, without
Authorizationand without multipart. Ignore the answer of the store. - 33. Create the document
POST /v1/documentswith theuploadIdanswers 202 with an operation. Once the check passes, the document is in the operation and the eventdocument.createdgoes out.
With the SDK
The SDK walks all three steps and waits for the operation.
// Portal D3 · Files and upload — session, raw bytes, document; the SDK follows method, URL and
// headers of the session (no Authorization to the storage) and waits for the operation.
// Run: BODO_API_KEY=bodo_uk_test_… bun examples/upload-document.ts ./vertrag.pdf
import { readFile } from "node:fs/promises";
import { basename } from "node:path";
import { Bodo } from "@bodo/api";
const bodo = new Bodo({ apiKey: process.env.BODO_API_KEY, preview: true });
const path = process.argv[2] ?? "vertrag.pdf";
const operation = await bodo.uploads.uploadDocument({
bytes: await readFile(path),
fileName: basename(path),
contentType: "application/pdf",
});
const done = await bodo.operations.wait(operation.id); // throws BodoApiError when the check fails
console.log(done.status, done.result);What gets rejected
| Case | Answer |
|---|---|
| Type not allowed or file larger than 50 MB | 422 VALIDATION_FAILED with a field error, already when creating the session |
| Document created before the file is complete | 409 UPLOAD_INCOMPLETE |
| Size or SHA-256 do not match the session | 422 UPLOAD_CHECKSUM_MISMATCH |
| File signature does not match the type | 422 UPLOAD_REJECTED, no document is created |
Download
GET /v1/documents/{id}/content answers 302 with a signed address valid for 5 minutes. Follow the redirect without Authorization; do not pass the address on.