Auth
If you are an agent, the llms.txt quickstart covers this page in machine-readable form.
Every request carries your API key in a header:
Authorization: Bearer vlf_...
Keys start with vlf_ and are shown once at creation. Keep the key in an environment variable (VEILFILE_API_KEY) or a secret manager. Never put it in a prompt, a chat message, or a repo.
The veilfile command-line client gets you a key without pasting secrets: pip install veilfile, then veilfile login (browser approval flow), veilfile logout, and veilfile status. The full reference is in the API docs source.
Upload
POST /api/v1/artifacts
Multipart form:
| Field | Required | Notes |
|---|---|---|
file |
yes | The file bytes. Max 25 MiB. |
ttl_days |
no | Days until expiry. Defaults to the plan max. Clamped to the plan max. |
Allowed types: png, jpg, jpeg, webp, gif, txt, md, log, json, har, pdf.
curl -X POST https://veilfile.com/api/v1/artifacts \
-H "Authorization: Bearer $VEILFILE_API_KEY" \
-F "file=@screenshot.png" \
-F "ttl_days=7"
A 201 comes back:
{
"id": "b3f7c2a1-...",
"url": "https://veilfile.com/a/4fK9vX2qZt8sW...",
"expires_at": "2026-10-12T00:25:00Z",
"size_bytes": 184320,
"secret_flags": []
}
ttl_adjusted: true appears when your ttl_days was clamped to the plan max. A warning string appears when secret_flags is non-empty: ask the user whether to keep or revoke the upload before sharing the link.
List
GET /api/v1/artifacts
Returns your workspace's artifacts, newest first.
Revoke
DELETE /api/v1/artifacts/<id>
Deletes the artifact at once. Its URL returns 404 immediately. Success is a 204 with an empty body. Unknown ids return 404.
Download
GET /a/<token>
Public. No auth. The token in the URL is the auth. Images, PDFs, and text are served inline. Everything else downloads as an attachment. Served with Cache-Control: no-store and X-Robots-Tag: noindex, nofollow.
Errors
Errors are JSON: {"error": "<code>", "message": "<detail>"}.
| HTTP | Code | Meaning |
|---|---|---|
| 400 | file_type_not_allowed |
Type not in the allowlist |
| 401 | unauthorized |
Missing or invalid API key |
| 402 | storage_cap_reached |
Plan storage cap hit |
| 404 | artifact_not_found |
Unknown, revoked, or expired |
| 413 | file_too_large |
Over 25 MiB |
| 429 | monthly_cap_reached |
Monthly upload quota hit |
| 429 | rate_limited |
Too many requests. Back off. |
Rate limit: 100 uploads per hour per API key.
The full technical reference, including MCP and billing endpoints, is API.md.