> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Internal links on these pages omit the .md extension. Append .md to a docs page URL, or send an Accept: text/markdown header, to get that page as markdown.

# Upload asset

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Uploads a file to the app's media library. Send it as `multipart/form-data` in a field named `file`.

The file name decides what's accepted. It must end in one of these extensions: `3g2`, `3gp`, `avi`, `csv`, `docx`, `fbx`, `gif`, `glb`, `gltf`, `ico`, `jpeg`, `jpg`, `json`, `m4v`, `md`, `mkv`, `mov`, `mp3`, `mp4`, `mtl`, `obj`, `ogv`, `pdf`, `png`, `svg`, `txt`, `wav`, `webm`, `webp`, `wmv`, `xlsx`, `zip`. HTML files aren't accepted. The size limit depends on the type, from 1 MB for `ico` to 100 MB for audio and video. Most images can be up to 40 MB. The asset's `file_name` is the uploaded file's name with the same character rules as [Create asset](/api-reference/create-asset), and its `file_type` is the extension, in lowercase.

The file is stored at a public URL, returned in `file_url`, so anyone with the URL can open it.

In this response, `created_date` and `updated_date` include a `+00:00` offset. [List assets](/api-reference/list-assets) returns them without one.

This endpoint is limited to 60 requests per minute. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>

<Warning>The response includes fields beyond the ones documented here. Don't rely on undocumented response fields, as they can change at any time.</Warning>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json post /api/apps/{app_id}/assets/upload
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/assets/upload:
    post:
      summary: Upload asset
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Uploads a file to the app's media library. Send it as
        `multipart/form-data` in a field named `file`.


        The file name decides what's accepted. It must end in one of these
        extensions: `3g2`, `3gp`, `avi`, `csv`, `docx`, `fbx`, `gif`, `glb`,
        `gltf`, `ico`, `jpeg`, `jpg`, `json`, `m4v`, `md`, `mkv`, `mov`, `mp3`,
        `mp4`, `mtl`, `obj`, `ogv`, `pdf`, `png`, `svg`, `txt`, `wav`, `webm`,
        `webp`, `wmv`, `xlsx`, `zip`. HTML files aren't accepted. The size limit
        depends on the type, from 1 MB for `ico` to 100 MB for audio and video.
        Most images can be up to 40 MB. The asset's `file_name` is the uploaded
        file's name with the same character rules as [Create
        asset](/api-reference/create-asset), and its `file_type` is the
        extension, in lowercase.


        The file is stored at a public URL, returned in `file_url`, so anyone
        with the URL can open it.


        In this response, `created_date` and `updated_date` include a `+00:00`
        offset. [List assets](/api-reference/list-assets) returns them without
        one.


        This endpoint is limited to 60 requests per minute. Some workspaces have
        a different limit.


        <Note>This endpoint accepts a personal API key belonging to a user with
        editor access to the app. A read-only key is refused, and workspace API
        keys are not accepted.</Note>


        <Warning>The response includes fields beyond the ones documented here.
        Don't rely on undocumented response fields, as they can change at any
        time.</Warning>
      operationId: upload_to_assets_api_apps__app_id__assets_upload_post
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app whose media library to change.
            title: App Id
          description: ID of the app whose media library to change.
          example: 6820f3a4e7b91d003c45a1f2
      requestBody:
        required: true
        content:
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/UploadAsset'
      responses:
        '200':
          description: The new asset.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AssetSummary'
        '400':
          description: >-
            The file name has no supported extension, or the file is over the
            size limit for its type.
        '401':
          description: Missing or invalid credentials.
        '403':
          description: >-
            You don't have editor access to this app, the app is blocked, your
            API key is read-only, or you used a workspace API key.
        '404':
          description: App not found.
        '422':
          description: '`file` is missing.'
        '429':
          description: >-
            Rate limit exceeded. The base limit is 60 requests per minute. See
            [Rate
            limits](/developers/references/apps-api/get-started/rate-limits) for
            the multiplier your plan gets.
components:
  schemas:
    UploadAsset:
      properties:
        file:
          type: string
          format: binary
          title: File
          description: >-
            The file to upload. Its name must end in one of the supported
            extensions.
      type: object
      required:
        - file
      title: UploadAsset
    AssetSummary:
      properties:
        id:
          type: string
          title: Id
          description: ID of the asset.
          example: 68b0e1f2a3c4d5e6f7a8b9c0
        app_id:
          type: string
          title: App Id
          description: ID of the app the asset belongs to.
          example: 6820f3a4e7b91d003c45a1f2
        file_name:
          type: string
          title: File Name
          description: Name of the file.
          example: Logo-dark.png
        file_url:
          type: string
          title: File Url
          description: URL of the file.
          example: >-
            https://media.base44.com/files/public/6820f3a4e7b91d003c45a1f2/Logo-dark.png
        source_type:
          type: string
          enum:
            - upload
            - generated
          title: Source Type
          description: >-
            How the file got into the library. `upload` for a file someone
            uploaded, and `generated` for most files Base44 created for the app,
            such as AI-generated images and videos or a Figma import.
          example: upload
        file_type:
          anyOf:
            - type: string
            - type: 'null'
          title: File Type
          description: >-
            File extension without the dot, usually lowercase, such as `png` or
            `mp4`. The value is `null` when the file was added without one.
          example: png
        created_date:
          type: string
          title: Created Date
          description: >-
            When the asset was added to the library, as a UTC timestamp in ISO
            8601 format.
          example: '2026-01-15T09:23:41'
        updated_date:
          type: string
          title: Updated Date
          description: >-
            When the asset was last changed, such as renamed, as a UTC timestamp
            in ISO 8601 format.
          example: '2026-01-15T09:31:07'
      type: object
      required:
        - id
        - app_id
        - file_name
        - file_url
        - source_type
        - file_type
        - created_date
        - updated_date
      title: AssetSummary
      description: A file in the app's media library.
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.