veilfile

api reference

Auth

If you are an agent, the llms.txt quickstart covers this page in machine-readable form.

Every request carries your API key in a header:

Authorization: Bearer vlf_...

Keys start with vlf_ and are shown once at creation. Keep the key in an environment variable (VEILFILE_API_KEY) or a secret manager. Never put it in a prompt, a chat message, or a repo.

The veilfile command-line client gets you a key without pasting secrets: pip install veilfile, then veilfile login (browser approval flow), veilfile logout, and veilfile status. The full reference is in the API docs source.

Upload

POST /api/v1/artifacts

Multipart form:

Field Required Notes
file yes The file bytes. Max 25 MiB.
ttl_days no Days until expiry. Defaults to the plan max. Clamped to the plan max.

Allowed types: png, jpg, jpeg, webp, gif, txt, md, log, json, har, pdf.

curl -X POST https://veilfile.com/api/v1/artifacts \
  -H "Authorization: Bearer $VEILFILE_API_KEY" \
  -F "file=@screenshot.png" \
  -F "ttl_days=7"

A 201 comes back:

{
  "id": "b3f7c2a1-...",
  "url": "https://veilfile.com/a/4fK9vX2qZt8sW...",
  "expires_at": "2026-10-12T00:25:00Z",
  "size_bytes": 184320,
  "secret_flags": []
}

ttl_adjusted: true appears when your ttl_days was clamped to the plan max. A warning string appears when secret_flags is non-empty: ask the user whether to keep or revoke the upload before sharing the link.

List

GET /api/v1/artifacts

Returns your workspace's artifacts, newest first.

Revoke

DELETE /api/v1/artifacts/<id>

Deletes the artifact at once. Its URL returns 404 immediately. Success is a 204 with an empty body. Unknown ids return 404.

Download

GET /a/<token>

Public. No auth. The token in the URL is the auth. Images, PDFs, and text are served inline. Everything else downloads as an attachment. Served with Cache-Control: no-store and X-Robots-Tag: noindex, nofollow.

Errors

Errors are JSON: {"error": "<code>", "message": "<detail>"}.

HTTP Code Meaning
400 file_type_not_allowed Type not in the allowlist
401 unauthorized Missing or invalid API key
402 storage_cap_reached Plan storage cap hit
404 artifact_not_found Unknown, revoked, or expired
413 file_too_large Over 25 MiB
429 monthly_cap_reached Monthly upload quota hit
429 rate_limited Too many requests. Back off.

Rate limit: 100 uploads per hour per API key.

The full technical reference, including MCP and billing endpoints, is API.md.