curl --request POST \
--url https://app.base44.com/api/apps/{app_id}/assets/upload \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: multipart/form-data' \
--form file=@example-fileimport requests
url = "https://app.base44.com/api/apps/{app_id}/assets/upload"
files = { "file": ("example-file", open("example-file", "rb")) }
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, files=files, headers=headers)
print(response.text)const form = new FormData();
form.append('file', '<string>');
const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
options.body = form;
fetch('https://app.base44.com/api/apps/{app_id}/assets/upload', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/{app_id}/assets/upload",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"example-file\"\r\nContent-Type: application/octet-stream\r\n\r\n<string>\r\n-----011000010111000001101001--",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: multipart/form-data"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/{app_id}/assets/upload"
payload := strings.NewReader("-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"example-file\"\r\nContent-Type: application/octet-stream\r\n\r\n<string>\r\n-----011000010111000001101001--")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.base44.com/api/apps/{app_id}/assets/upload")
.header("Authorization", "Bearer <token>")
.body("-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"example-file\"\r\nContent-Type: application/octet-stream\r\n\r\n<string>\r\n-----011000010111000001101001--")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/{app_id}/assets/upload")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request.body = "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"example-file\"\r\nContent-Type: application/octet-stream\r\n\r\n<string>\r\n-----011000010111000001101001--"
response = http.request(request)
puts response.read_body{
"id": "68b0e1f2a3c4d5e6f7a8b9c0",
"app_id": "6820f3a4e7b91d003c45a1f2",
"file_name": "Logo-dark.png",
"file_url": "https://media.base44.com/files/public/6820f3a4e7b91d003c45a1f2/Logo-dark.png",
"source_type": "upload",
"file_type": "png",
"created_date": "2026-01-15T09:23:41",
"updated_date": "2026-01-15T09:31:07"
}Upload asset
Uploads a file to the app’s media library. Send it as multipart/form-data in a field named file.
The file name decides what’s accepted. It must end in one of these extensions: 3g2, 3gp, avi, csv, docx, fbx, gif, glb, gltf, ico, jpeg, jpg, json, m4v, md, mkv, mov, mp3, mp4, mtl, obj, ogv, pdf, png, svg, txt, wav, webm, webp, wmv, xlsx, zip. HTML files aren’t accepted. The size limit depends on the type, from 1 MB for ico to 100 MB for audio and video. Most images can be up to 40 MB. The asset’s file_name is the uploaded file’s name with the same character rules as Create asset, and its file_type is the extension, in lowercase.
The file is stored at a public URL, returned in file_url, so anyone with the URL can open it.
In this response, created_date and updated_date include a +00:00 offset. List assets returns them without one.
This endpoint is limited to 60 requests per minute. Some workspaces have a different limit.
curl --request POST \
--url https://app.base44.com/api/apps/{app_id}/assets/upload \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: multipart/form-data' \
--form file=@example-fileimport requests
url = "https://app.base44.com/api/apps/{app_id}/assets/upload"
files = { "file": ("example-file", open("example-file", "rb")) }
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, files=files, headers=headers)
print(response.text)const form = new FormData();
form.append('file', '<string>');
const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
options.body = form;
fetch('https://app.base44.com/api/apps/{app_id}/assets/upload', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/{app_id}/assets/upload",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"example-file\"\r\nContent-Type: application/octet-stream\r\n\r\n<string>\r\n-----011000010111000001101001--",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: multipart/form-data"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/{app_id}/assets/upload"
payload := strings.NewReader("-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"example-file\"\r\nContent-Type: application/octet-stream\r\n\r\n<string>\r\n-----011000010111000001101001--")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.base44.com/api/apps/{app_id}/assets/upload")
.header("Authorization", "Bearer <token>")
.body("-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"example-file\"\r\nContent-Type: application/octet-stream\r\n\r\n<string>\r\n-----011000010111000001101001--")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/{app_id}/assets/upload")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request.body = "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"file\"; filename=\"example-file\"\r\nContent-Type: application/octet-stream\r\n\r\n<string>\r\n-----011000010111000001101001--"
response = http.request(request)
puts response.read_body{
"id": "68b0e1f2a3c4d5e6f7a8b9c0",
"app_id": "6820f3a4e7b91d003c45a1f2",
"file_name": "Logo-dark.png",
"file_url": "https://media.base44.com/files/public/6820f3a4e7b91d003c45a1f2/Logo-dark.png",
"source_type": "upload",
"file_type": "png",
"created_date": "2026-01-15T09:23:41",
"updated_date": "2026-01-15T09:31:07"
}Authorizations
Personal access token, sent as Authorization: Bearer <token>.
Path Parameters
ID of the app whose media library to change.
Body
The file to upload. Its name must end in one of the supported extensions.
Response
The new asset.
A file in the app's media library.
ID of the asset.
"68b0e1f2a3c4d5e6f7a8b9c0"
ID of the app the asset belongs to.
"6820f3a4e7b91d003c45a1f2"
Name of the file.
"Logo-dark.png"
URL of the file.
"https://media.base44.com/files/public/6820f3a4e7b91d003c45a1f2/Logo-dark.png"
How the file got into the library. upload for a file someone uploaded, and generated for most files Base44 created for the app, such as AI-generated images and videos or a Figma import.
upload, generated "upload"
File extension without the dot, usually lowercase, such as png or mp4. The value is null when the file was added without one.
"png"
When the asset was added to the library, as a UTC timestamp in ISO 8601 format.
"2026-01-15T09:23:41"
When the asset was last changed, such as renamed, as a UTC timestamp in ISO 8601 format.
"2026-01-15T09:31:07"
Was this page helpful?