Skip to main content
POST
Open a folder of attachments

Behavior

Upload each member’s bytes to its upload_url, then finalize each member. The folder becomes ready when every member is finalized. A folder already open and ready with the same roster (member paths and declared sizes; contents are not compared) answers 200 with reused: true and nothing to upload; otherwise a new folder answers 201. Files the instance will not read are listed in skipped. See Attachments.

Authorizations

Authorization
string
header
required

Send the key as Authorization: Bearer <key>. Two kinds of key exist.

Organization keys are issued in the portal (Settings, then API keys), each bound to one environment, shaped nx_<environment slug>_<64 hex>. They carry no capabilities and pass every capability check, with one exception: routes under /api/v1/records, /api/v1/engines/{id}/opportunities, /api/v1/graph and /api/v1/catalog/documents accept an organization key only when its environment is live, and refuse any other with 403 scoped_key_required. Revocation takes effect within 60 seconds.

Scoped keys are issued by Nexio on request, shaped nxsk_v1_<24 hex key id>_<43 character secret>. Each is bound to one org, one environment, a set of engines and a set of capabilities. A malformed, unknown or revoked nxsk_ key fails with 401 and is never retried as an organization key. Revocation takes effect on the next request. A scoped key without a route's capability gets 403 insufficient_capability; a scoped key not bound to the engine gets 403 engine_binding_forbidden.

Key-grantable capabilities: engines:read, runs:write, runs:read, runs:defensibility:read, runs:test, catalog:read, catalog:documents:read, webhooks:manage, conversations:use, conversations:export, records:read, records:opportunities:run, actions:write, actions:read, graph:read, records:analyze.

Routes that accept organization keys only (every scoped key gets 403 insufficient_capability): environment management, engine create, update, configuration and publish, and conversation instance authoring. Each operation description names the capability a scoped key needs.

Path Parameters

instance_slug
string
required

Conversation instance identifier slug (e.g. platform-assistant).

conversation_id
string<uuid>
required

Body

application/json
end_user
string
required

The asserted end-user identity the conversation must belong to.

name
string
required

Folder name.

files
object[]
required
Maximum array length: 25

Response

The same folder was already open and ready; it is returned with reused true and no members to upload.

An opened folder container with one reservation per readable file.

container
object
required

One file attached to a conversation. There is no text field: the platform does not parse the document, it hands the bytes to the model.

reused
boolean
required

True when a folder with the same roster (member paths and declared sizes; contents are not compared) was already open and ready and is handed back; members is empty and nothing needs uploading.

members
object[]
required
skipped
object[]
required

Files the instance will not read. Always present; empty when nothing was skipped.

Last modified on September 25, 2026