Skip to main content
View as MarkdownOpenAPI spec

Files

List files​

GET/api/v1/files

The organization's unexpired files, newest first. Any role.

Query parameters
sha256string
Only the file with this lowercase hex SHA-256.
appstring · uuid
Only files of this app.
platformstring
Only files for this platform.
bundleIdstring
Only files with this bundle id.
branchstring
Only files whose build.branch equals this.
commitstring
Only files whose build.commit equals this.
statusstring
Only files in this status. Without it, ready and processing files are listed; pendingUpload and failed are for debugging.
qstring
Case-insensitive substring of the name, filename or bundle id.
limitinteger
Page size, 1 to 100. Default 25.
cursorstring
`nextCursor` from the previous page. Opaque.
Header parameters
X-Organization-Idstring
Selects which of the caller's organizations the request acts on. When omitted, the caller's default organization is used.
Returns
objectstringrequired
dataarrayrequired
Show child attributes
idstring · uuidrequired
statusstringrequired
pendingUpload: bytes not verified yet. processing: verification running (seen only by a concurrent caller). ready: installable. failed: see failureReason; creating the same sha256 again resets it.
appstring · uuidrequirednullable
The app this file belongs to, once metadata is extracted.
platformstringrequirednullable
Known once metadata is extracted.
filenamestringrequired
filesizeinteger · int64required
sha256stringrequired
namestringrequired
Display name. Defaults to the filename until metadata is extracted.
bundleIdstringrequirednullable
Android package name or iOS bundle identifier.
versionstringrequirednullable
Version name (Android) or CFBundleShortVersionString (iOS).
buildNumberstringrequirednullable
Version code (Android) or CFBundleVersion (iOS).
minOsVersionstringrequirednullable
Minimum OS version the build supports.
isSimulatorbooleanrequired
True for an iOS simulator build.
buildobjectrequirednullable
Show child attributes
branchstring
commitstring
ciRunUrlstring · uri
https only. Stored and displayed, never fetched.
sourcestringrequired
How the file was created, derived from the credential.
organizationstringrequired
Organization that owns the file.
userstringrequirednullable
Uploader; null if the user was deleted.
failureReasonstringrequirednullable
Why the file failed; null otherwise.
createdAtstring · date-timerequired
lastUsedAtstring · date-timerequirednullable
Last dedup hit or install.
expiresAtstring · date-timerequired
The file and its bytes are deleted after this.
nextCursorstring
Pass as `cursor` for the next page. Absent on the last page.

Create a file​

POST/api/v1/files

Declares a file by its SHA-256. If the organization already stores that hash, the stored file is returned instead of a new one.

PUT the bytes if and only if the response contains upload. Do not branch on the status code. Then call completeFile unless the file is already ready.

Stored file with this sha256Responseupload
none201, pendingUploadyes
pendingUpload or failed200, same id, reset to pendingUploadyes, fresh URL
processing200no
ready200, expiry extended, lastUsedAt setno

A dedup hit keeps the first create's filename, name, build and user, and never shortens the expiry. Rate limited to 100 creates per 15 minutes per organization.

Header parameters
X-Organization-Idstring
Selects which of the caller's organizations the request acts on. When omitted, the caller's default organization is used.
Body parameters
filenamestringrequired
Must end in .apk or .ipa.
filesizeinteger · int64required
Bytes. At most the plan's per-file cap: hobby 250 MB, starter 1 GB, team and enterprise 2 GB.
sha256stringrequired
Lowercase hex SHA-256 of the file.
expiresIninteger · int64
Seconds until the file expires: 10 minutes to 90 days, default 30 days. A dedup hit only ever extends the expiry.
namestring
Display name. Kept from the first create on a dedup hit.
buildobject
Where the build came from. Every field is optional; CI clients fill it from their environment.
Show child attributes
branchstring
commitstring
ciRunUrlstring · uri
https only. Stored and displayed, never fetched.
Returns
idstring · uuidrequired
statusstringrequired
pendingUpload: bytes not verified yet. processing: verification running (seen only by a concurrent caller). ready: installable. failed: see failureReason; creating the same sha256 again resets it.
appstring · uuidrequirednullable
The app this file belongs to, once metadata is extracted.
platformstringrequirednullable
Known once metadata is extracted.
filenamestringrequired
filesizeinteger · int64required
sha256stringrequired
namestringrequired
Display name. Defaults to the filename until metadata is extracted.
bundleIdstringrequirednullable
Android package name or iOS bundle identifier.
versionstringrequirednullable
Version name (Android) or CFBundleShortVersionString (iOS).
buildNumberstringrequirednullable
Version code (Android) or CFBundleVersion (iOS).
minOsVersionstringrequirednullable
Minimum OS version the build supports.
isSimulatorbooleanrequired
True for an iOS simulator build.
buildobjectrequirednullable
Show child attributes
branchstring
commitstring
ciRunUrlstring · uri
https only. Stored and displayed, never fetched.
sourcestringrequired
How the file was created, derived from the credential.
organizationstringrequired
Organization that owns the file.
userstringrequirednullable
Uploader; null if the user was deleted.
failureReasonstringrequirednullable
Why the file failed; null otherwise.
createdAtstring · date-timerequired
lastUsedAtstring · date-timerequirednullable
Last dedup hit or install.
expiresAtstring · date-timerequired
The file and its bytes are deleted after this.
uploadobject
Present only while the caller is expected to upload the bytes. Send exactly these headers; the URL is signed for the declared size and SHA-256, so any other bytes are rejected by storage.
Show child attributes
methodstringrequired
urlstring · urirequired
headersobjectrequired
expiresAtstring · date-timerequired
When the URL stops working. Calling create again returns a fresh one.

Get file storage usage​

GET/api/v1/files/usage

Stored bytes against the plan's quota, for display. The quota is not enforced yet; the only enforced limit is a safety ceiling (403 storage_quota_exceeded on create).

Header parameters
X-Organization-Idstring
Selects which of the caller's organizations the request acts on. When omitted, the caller's default organization is used.
Returns
usedBytesinteger · int64required
Sum of the organization's stored files, failed files excluded.
quotaBytesinteger · int64requirednullable
The plan's storage quota; null when unlimited. Shown, not enforced yet.

Get a file​

GET/api/v1/files/{fileId}

Returns a file in any status. A missing, expired or other organization's file is 404.

Path parameters
fileIdstring · uuidrequired
File UUID
Header parameters
X-Organization-Idstring
Selects which of the caller's organizations the request acts on. When omitted, the caller's default organization is used.
Returns

One stored app binary. Immutable bytes, unique per organization by SHA-256.

idstring · uuidrequired
statusstringrequired
pendingUpload: bytes not verified yet. processing: verification running (seen only by a concurrent caller). ready: installable. failed: see failureReason; creating the same sha256 again resets it.
appstring · uuidrequirednullable
The app this file belongs to, once metadata is extracted.
platformstringrequirednullable
Known once metadata is extracted.
filenamestringrequired
filesizeinteger · int64required
sha256stringrequired
namestringrequired
Display name. Defaults to the filename until metadata is extracted.
bundleIdstringrequirednullable
Android package name or iOS bundle identifier.
versionstringrequirednullable
Version name (Android) or CFBundleShortVersionString (iOS).
buildNumberstringrequirednullable
Version code (Android) or CFBundleVersion (iOS).
minOsVersionstringrequirednullable
Minimum OS version the build supports.
isSimulatorbooleanrequired
True for an iOS simulator build.
buildobjectrequirednullable
Show child attributes
branchstring
commitstring
ciRunUrlstring · uri
https only. Stored and displayed, never fetched.
sourcestringrequired
How the file was created, derived from the credential.
organizationstringrequired
Organization that owns the file.
userstringrequirednullable
Uploader; null if the user was deleted.
failureReasonstringrequirednullable
Why the file failed; null otherwise.
createdAtstring · date-timerequired
lastUsedAtstring · date-timerequirednullable
Last dedup hit or install.
expiresAtstring · date-timerequired
The file and its bytes are deleted after this.

Update a file​

PATCH/api/v1/files/{fileId}

Changes a file's expiry or display name. The bytes are immutable.

Path parameters
fileIdstring · uuidrequired
File UUID
Header parameters
X-Organization-Idstring
Selects which of the caller's organizations the request acts on. When omitted, the caller's default organization is used.
Body parameters
expiresIninteger · int64
Seconds from now: 10 minutes to 90 days. Restarts the clock and may shorten the expiry (a create never does).
namestring
Display name. An empty string clears it, so the file shows its filename again.
Returns

One stored app binary. Immutable bytes, unique per organization by SHA-256.

idstring · uuidrequired
statusstringrequired
pendingUpload: bytes not verified yet. processing: verification running (seen only by a concurrent caller). ready: installable. failed: see failureReason; creating the same sha256 again resets it.
appstring · uuidrequirednullable
The app this file belongs to, once metadata is extracted.
platformstringrequirednullable
Known once metadata is extracted.
filenamestringrequired
filesizeinteger · int64required
sha256stringrequired
namestringrequired
Display name. Defaults to the filename until metadata is extracted.
bundleIdstringrequirednullable
Android package name or iOS bundle identifier.
versionstringrequirednullable
Version name (Android) or CFBundleShortVersionString (iOS).
buildNumberstringrequirednullable
Version code (Android) or CFBundleVersion (iOS).
minOsVersionstringrequirednullable
Minimum OS version the build supports.
isSimulatorbooleanrequired
True for an iOS simulator build.
buildobjectrequirednullable
Show child attributes
branchstring
commitstring
ciRunUrlstring · uri
https only. Stored and displayed, never fetched.
sourcestringrequired
How the file was created, derived from the credential.
organizationstringrequired
Organization that owns the file.
userstringrequirednullable
Uploader; null if the user was deleted.
failureReasonstringrequirednullable
Why the file failed; null otherwise.
createdAtstring · date-timerequired
lastUsedAtstring · date-timerequirednullable
Last dedup hit or install.
expiresAtstring · date-timerequired
The file and its bytes are deleted after this.

Delete a file​

DELETE/api/v1/files/{fileId}

Deletes the file immediately: it no longer appears in lists, cannot be fetched or downloaded, and stops counting as usage. Download URLs already issued keep working until they expire.

Path parameters
fileIdstring · uuidrequired
File UUID
Header parameters
X-Organization-Idstring
Selects which of the caller's organizations the request acts on. When omitted, the caller's default organization is used.

Complete a file upload​

POST/api/v1/files/{fileId}/complete

Call after the PUT. Verifies the stored bytes against the declared size and SHA-256 and returns the file as ready or failed. Synchronous; there is nothing to poll. Idempotent: a ready or failed file is returned unchanged.

Path parameters
fileIdstring · uuidrequired
File UUID
Header parameters
X-Organization-Idstring
Selects which of the caller's organizations the request acts on. When omitted, the caller's default organization is used.
Returns

One stored app binary. Immutable bytes, unique per organization by SHA-256.

idstring · uuidrequired
statusstringrequired
pendingUpload: bytes not verified yet. processing: verification running (seen only by a concurrent caller). ready: installable. failed: see failureReason; creating the same sha256 again resets it.
appstring · uuidrequirednullable
The app this file belongs to, once metadata is extracted.
platformstringrequirednullable
Known once metadata is extracted.
filenamestringrequired
filesizeinteger · int64required
sha256stringrequired
namestringrequired
Display name. Defaults to the filename until metadata is extracted.
bundleIdstringrequirednullable
Android package name or iOS bundle identifier.
versionstringrequirednullable
Version name (Android) or CFBundleShortVersionString (iOS).
buildNumberstringrequirednullable
Version code (Android) or CFBundleVersion (iOS).
minOsVersionstringrequirednullable
Minimum OS version the build supports.
isSimulatorbooleanrequired
True for an iOS simulator build.
buildobjectrequirednullable
Show child attributes
branchstring
commitstring
ciRunUrlstring · uri
https only. Stored and displayed, never fetched.
sourcestringrequired
How the file was created, derived from the credential.
organizationstringrequired
Organization that owns the file.
userstringrequirednullable
Uploader; null if the user was deleted.
failureReasonstringrequirednullable
Why the file failed; null otherwise.
createdAtstring · date-timerequired
lastUsedAtstring · date-timerequirednullable
Last dedup hit or install.
expiresAtstring · date-timerequired
The file and its bytes are deleted after this.

Download a file​

GET/api/v1/files/{fileId}/download

Returns a presigned download URL valid for 5 minutes; it saves under the file's original filename. Any role. Does not change lastUsedAt. Returns JSON rather than redirecting, so the route itself cannot be shared as a download link.

Path parameters
fileIdstring · uuidrequired
File UUID
Header parameters
X-Organization-Idstring
Selects which of the caller's organizations the request acts on. When omitted, the caller's default organization is used.
Returns
urlstring · urirequired
Presigned download URL; the browser saves it under the file's original filename.
expiresAtstring · date-timerequired
When the URL stops working (5 minutes).