API

Files and spaces.

Spaces are how people open storage. A path is relative to the space, uses /, and has no leading slash. kind on a space is shared or personal. level is view, edit, or full. icon is folder, home, users, film, image, music, or briefcase. The older root-and-path calls still work.

Authentication, errors, and paging are in the API reference. Sending the key is described once there.

Spaces

GET /api/v1/home

The spaces this caller can open. Personal spaces come first.

Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Success. 200.

FieldTypeMeaning
spacesarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
iconstringrequiredfolder, home, users, film, image, music, or briefcase.
kindstringrequired
levelstringrequiredview, edit or full. The best access this person has anywhere in the space.
anySpacesbooleanrequiredWhether this server has any space at all. An empty list means "nothing has been set up yet" when this is false and "none of it is yours" when it is true, and the two need different words.
{
  "spaces": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "name": "Rush delivery",
      "icon": "folder",
      "kind": "shared",
      "level": "edit"
    }
  ],
  "anySpaces": true
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}
Personal spaces are listed first. This is the call to make before you browse files.

GET /api/v1/spaces/{id}

One space: name, icon, kind and the caller's level. An administrator also gets the location's name.

Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
iconstringrequiredfolder, home, users, film, image, music, or briefcase.
kindstringrequired
levelstringrequired
locationNamestringoptional, left out when empty
{
  "id": "k7Qm2sLp9vX4aB1c",
  "name": "Rush delivery",
  "icon": "folder",
  "kind": "shared",
  "level": "edit",
  "locationName": "example"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
404not_foundnot there, or not visible to this caller
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "not_found",
    "message": "not found"
  }
}

GET /api/v1/spaces/{id}/files

One folder inside a space. Each entry has a level: view, edit, full, or traverse when the folder is only on the way to a grant.

Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe space.
pathquerystringoptionalFolder, relative to the space.

Encode the query value. A slash in a path may stay as / or be written %2F; the server reads the decoded value. Do not put a leading slash on the path.

Success. 200.

FieldTypeMeaning
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
levelstringrequired
itemsarray of objectsrequiredThe records in this reply.

Each item is an object:

FieldTypeMeaning
namestringrequiredThe name.
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
kindstringrequired
sizeintegerrequiredSize in bytes.
modifiedstringoptional
levelstringrequiredview, edit, full, or traverse when the folder is only on the way to a grant further down.
{
  "path": "projects/rush",
  "level": "edit",
  "items": [
    {
      "name": "Rush delivery",
      "path": "projects/rush",
      "kind": "file",
      "size": 1048576,
      "modified": "example",
      "level": "edit"
    }
  ]
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestthe request is not valid
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "the request is not valid"
  }
}

DELETE /api/v1/spaces/{id}/files

Delete a file or a folder inside a space.

Who. Any user with a key that has the delete scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe space.
pathquerystringoptionalWhat to delete, relative to the space.

Encode the query value. A slash in a path may stay as / or be written %2F; the server reads the decoded value. Do not put a leading slash on the path.

Success. 200.

The reply has no body.

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestname a file or a folder
404not_foundnot there, or not visible to this caller
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "name a file or a folder"
  }
}

POST /api/v1/spaces/{id}/folder

Make a folder inside a space. Body: {path}.

Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
pathstringoptionalA path relative to the space or the storage location, with / between folders and no leading slash.
{
  "path": "projects/rush"
}

Success. 200.

FieldTypeMeaning
namestringrequiredThe name.
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
kindstringrequired
sizeintegerrequiredSize in bytes.
modifiedstringoptional, left out when empty
{
  "name": "Rush delivery",
  "path": "projects/rush",
  "kind": "file",
  "size": 1048576,
  "modified": "example"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestname the folder
409conflictsomething is already there
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "name the folder"
  }
}

POST /api/v1/spaces/{id}/rename

Rename or move inside a space. Body: {from, to}.

Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
fromstringoptional
tostringrequired
{
  "from": "projects/rush",
  "to": "projects/rush"
}

Success. 200.

FieldTypeMeaning
namestringrequiredThe name.
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
kindstringrequired
sizeintegerrequiredSize in bytes.
modifiedstringoptional, left out when empty
{
  "name": "Rush delivery",
  "path": "projects/rush",
  "kind": "file",
  "size": 1048576,
  "modified": "example"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestname a file or a folder
409conflictsomething is already there
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "name a file or a folder"
  }
}

Managing spaces

GET /api/v1/admin/spaces

Every space, and storage locations that are not shared yet.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Success. 200.

FieldTypeMeaning
spacesarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
iconstringrequiredfolder, home, users, film, image, music, or briefcase.
kindstringrequired
rootIdstringrequiredThe id.
basePathstringrequired
templatestringoptional
forGroupstringoptional
positionintegerrequired
createdAtstringrequiredA time, as RFC 3339.
locationNamestringrequired
locationKindstringrequired
locationPathstringrequired
unsharedarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
kindstringrequired
{
  "spaces": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "name": "Rush delivery",
      "icon": "folder",
      "kind": "shared",
      "rootId": "k7Qm2sLp9vX4aB1c",
      "basePath": "projects/rush",
      "position": 1,
      "createdAt": "2026-10-05T18:00:00Z",
      "locationName": "example",
      "locationKind": "example",
      "locationPath": "projects/rush"
    }
  ],
  "unshared": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "name": "Rush delivery",
      "kind": "shared"
    }
  ]
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

POST /api/v1/admin/spaces

Create a space. Body: {name, icon, rootId, basePath, kind: shared|personal, template, forGroup}.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
namestringrequiredThe name.
iconstringoptionalfolder, home, users, film, image, music, or briefcase.
rootIdstringrequiredThe id.
basePathstringoptional
kindstringrequired
templatestringoptional
forGroupstringoptional
{
  "name": "Rush delivery",
  "icon": "folder",
  "rootId": "k7Qm2sLp9vX4aB1c",
  "basePath": "projects/rush",
  "kind": "shared",
  "template": "example",
  "forGroup": "example"
}

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
iconstringrequiredfolder, home, users, film, image, music, or briefcase.
kindstringrequired
rootIdstringrequiredThe id.
basePathstringrequired
templatestringoptional
forGroupstringoptional
positionintegerrequired
createdAtstringrequiredA time, as RFC 3339.
locationNamestringrequired
locationKindstringrequired
locationPathstringrequired
{
  "id": "k7Qm2sLp9vX4aB1c",
  "name": "Rush delivery",
  "icon": "folder",
  "kind": "shared",
  "rootId": "k7Qm2sLp9vX4aB1c",
  "basePath": "projects/rush",
  "position": 1,
  "createdAt": "2026-10-05T18:00:00Z",
  "locationName": "example",
  "locationKind": "example",
  "locationPath": "projects/rush"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestthe name, kind or template is not usable
409conflictthe name is taken
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "the name, kind or template is not usable"
  }
}

POST /api/v1/admin/spaces/preview

The warnings a new space would raise, without saving it. Same body as creating one.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
namestringrequiredThe name.
iconstringoptionalfolder, home, users, film, image, music, or briefcase.
rootIdstringrequiredThe id.
basePathstringoptional
kindstringrequired
templatestringoptional
forGroupstringoptional
{
  "name": "Rush delivery",
  "icon": "folder",
  "rootId": "k7Qm2sLp9vX4aB1c",
  "basePath": "projects/rush",
  "kind": "shared",
  "template": "example",
  "forGroup": "example"
}

Success. 200.

FieldTypeMeaning
warningsarray of stringrequired
{
  "warnings": [
    "example"
  ]
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

GET /api/v1/admin/spaces/{id}

One space, including the location path. A personal space includes the people who have opened their folder.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Success. 200.

FieldTypeMeaning
spaceobjectrequired

It is an object:

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
iconstringrequiredfolder, home, users, film, image, music, or briefcase.
kindstringrequired
rootIdstringrequiredThe id.
basePathstringrequired
templatestringoptional
forGroupstringoptional
positionintegerrequired
createdAtstringrequiredA time, as RFC 3339.
locationNamestringrequired
locationKindstringrequired
locationPathstringrequired
peoplearray of objectsrequired

Each item is an object:

FieldTypeMeaning
userIdstringrequiredThe id.
emailstringrequiredAn email address.
displayNamestringrequired
{
  "space": {
    "id": "k7Qm2sLp9vX4aB1c",
    "name": "Rush delivery",
    "icon": "folder",
    "kind": "shared",
    "rootId": "k7Qm2sLp9vX4aB1c",
    "basePath": "projects/rush",
    "position": 1,
    "createdAt": "2026-10-05T18:00:00Z",
    "locationName": "example",
    "locationKind": "example",
    "locationPath": "projects/rush"
  },
  "people": [
    {
      "userId": "k7Qm2sLp9vX4aB1c",
      "email": "[email protected]",
      "displayName": "example"
    }
  ]
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

PATCH /api/v1/admin/spaces/{id}

Rename a space, change its icon or position, or change which group a personal space is for.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
namestringoptionalThe name.
iconstringoptionalfolder, home, users, film, image, music, or briefcase.
positionintegeroptional
forGroupstringoptional
{
  "name": "Rush delivery",
  "icon": "folder",
  "position": 1,
  "forGroup": "example"
}

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
iconstringrequiredfolder, home, users, film, image, music, or briefcase.
kindstringrequired
rootIdstringrequiredThe id.
basePathstringrequired
templatestringoptional
forGroupstringoptional
positionintegerrequired
createdAtstringrequiredA time, as RFC 3339.
locationNamestringrequired
locationKindstringrequired
locationPathstringrequired
{
  "id": "k7Qm2sLp9vX4aB1c",
  "name": "Rush delivery",
  "icon": "folder",
  "kind": "shared",
  "rootId": "k7Qm2sLp9vX4aB1c",
  "basePath": "projects/rush",
  "position": 1,
  "createdAt": "2026-10-05T18:00:00Z",
  "locationName": "example",
  "locationKind": "example",
  "locationPath": "projects/rush"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

DELETE /api/v1/admin/spaces/{id}

Remove a space.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Access another shared space also holds moves to the innermost such space; all other access on the space is removed, and one space.deleted audit entry lists both. The files stay on the storage location. Jobs keep their location and path.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Success. 200.

The reply has no body.

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
409conflicta personal space whose private folders shared access on the location would then reach
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "conflict",
    "message": "a personal space whose private folders shared access on the location would then reach"
  }
}

GET /api/v1/admin/spaces/{id}/removal

What removing the space would do, without doing it: {name, kind, locationName, lose, keep, exposes}.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

lose is the access that would be removed, keep the access that would move to another space (with spaceId and spaceName), and exposes the shared access that stops a personal space from being removed.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Success. 200.

FieldTypeMeaning
namestringrequiredThe name.
kindstringrequired
locationNamestringrequired
losearray of objectsrequiredAccess that goes with the space, because no other space holds its folder. Paths are relative to the space.

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
kindstringrequired
principalIdstringrequiredThe id.
principalNamestringrequired
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
levelstringrequired
keeparray of objectsrequiredAccess another shared space also holds. It moves there and keeps working.

Each item is an object:

FieldTypeMeaning
accessobjectrequired

It is an object:

FieldTypeMeaning
idstringrequiredThe id.
kindstringrequired
principalIdstringrequiredThe id.
principalNamestringrequired
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
levelstringrequired
spaceIdstringrequiredThe id.
spaceNamestringrequired
exposesarray of objectsrequiredShared access on the location that would reach into this personal space's private folders once the space no longer marks them as private. Paths are relative to the location. While there is any, the space is not removed.

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
kindstringrequired
principalIdstringrequiredThe id.
principalNamestringrequired
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
levelstringrequired
{
  "name": "Rush delivery",
  "kind": "shared",
  "locationName": "example",
  "lose": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "kind": "shared",
      "principalId": "k7Qm2sLp9vX4aB1c",
      "principalName": "example",
      "path": "projects/rush",
      "level": "edit"
    }
  ],
  "keep": [
    {
      "access": {
        "id": "k7Qm2sLp9vX4aB1c",
        "kind": "shared",
        "principalId": "k7Qm2sLp9vX4aB1c",
        "principalName": "example",
        "path": "projects/rush",
        "level": "edit"
      },
      "spaceId": "k7Qm2sLp9vX4aB1c",
      "spaceName": "example"
    }
  ],
  "exposes": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "kind": "shared",
      "principalId": "k7Qm2sLp9vX4aB1c",
      "principalName": "example",
      "path": "projects/rush",
      "level": "edit"
    }
  ]
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

GET /api/v1/admin/spaces/{id}/access

Grants on this space, paths relative to the space.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Success. 200.

The body is an array.

FieldTypeMeaning
idstringrequiredThe id.
kindstringrequired
principalIdstringrequiredThe id.
principalNamestringrequired
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
levelstringrequired
[
  {
    "id": "k7Qm2sLp9vX4aB1c",
    "kind": "shared",
    "principalId": "k7Qm2sLp9vX4aB1c",
    "principalName": "example",
    "path": "projects/rush",
    "level": "edit"
  }
]

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

PUT /api/v1/admin/spaces/{id}/access

Give a person or a group view, edit or full access on the space or a folder in it.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
userIdstringoptionalThe id.
groupIdstringoptionalThe id.
pathstringoptionalA path relative to the space or the storage location, with / between folders and no leading slash.
accessstringrequired
{
  "userId": "k7Qm2sLp9vX4aB1c",
  "groupId": "k7Qm2sLp9vX4aB1c",
  "path": "projects/rush",
  "access": "edit"
}

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
kindstringrequired
principalIdstringrequiredThe id.
principalNamestringrequired
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
levelstringrequired
{
  "id": "k7Qm2sLp9vX4aB1c",
  "kind": "shared",
  "principalId": "k7Qm2sLp9vX4aB1c",
  "principalName": "example",
  "path": "projects/rush",
  "level": "edit"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestneither or both of userId and groupId, or a personal space
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "neither or both of userId and groupId, or a personal space"
  }
}

DELETE /api/v1/admin/spaces/{id}/access/{grant_id}

Take one space grant away.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe space.
grant_idpathstringrequiredThe grant.

Success. 200.

The reply has no body.

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

GET /api/v1/admin/spaces/{id}/personal/{user_id}/files

Open one person's personal folder. Writes space.personal.opened to the audit log.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe space.
user_idpathstringrequiredThe person.
pathquerystringoptionalFolder, relative to their folder.

Encode the query value. A slash in a path may stay as / or be written %2F; the server reads the decoded value. Do not put a leading slash on the path.

Success. 200.

FieldTypeMeaning
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
levelstringrequired
itemsarray of objectsrequiredThe records in this reply.

Each item is an object:

FieldTypeMeaning
namestringrequiredThe name.
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
kindstringrequired
sizeintegerrequiredSize in bytes.
modifiedstringoptional
levelstringrequiredview, edit, full, or traverse when the folder is only on the way to a grant further down.
{
  "path": "projects/rush",
  "level": "edit",
  "items": [
    {
      "name": "Rush delivery",
      "path": "projects/rush",
      "kind": "file",
      "size": 1048576,
      "modified": "example",
      "level": "edit"
    }
  ]
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestthe request is not valid
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "the request is not valid"
  }
}

GET /api/v1/admin/access/folder

Who can reach this folder, and why.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
spacequerystringrequiredThe space.
pathquerystringoptionalFolder, relative to the space.

Encode the query value. A slash in a path may stay as / or be written %2F; the server reads the decoded value. Do not put a leading slash on the path.

Success. 200.

The body is an array.

FieldTypeMeaning
kindstringrequired
namestringrequiredThe name.
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
levelstringrequired
whystringrequired
[
  {
    "kind": "shared",
    "name": "Rush delivery",
    "path": "projects/rush",
    "level": "edit",
    "why": "example"
  }
]

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestthe request is not valid
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "the request is not valid"
  }
}

GET /api/v1/admin/users/{id}/access

Every space and folder one person can reach, and why.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Success. 200.

The body is an array.

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
kindstringrequired
pathsarray of objectsrequired

Each item is an object:

FieldTypeMeaning
kindstringrequired
namestringrequiredThe name.
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
levelstringrequired
whystringrequired
[
  {
    "id": "k7Qm2sLp9vX4aB1c",
    "name": "Rush delivery",
    "kind": "shared",
    "paths": [
      {
        "kind": "shared",
        "name": "Rush delivery",
        "path": "projects/rush",
        "level": "edit",
        "why": "example"
      }
    ]
  }
]

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

Files and folders

GET /api/v1/roots

The storage locations this caller may see. Prefer GET /api/v1/home.

Still served, so an older script keeps working. New scripts should use spaces.

Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Success. 200.

The body is an array.

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
kindstringrequired
canWritebooleanrequiredWhat this caller may do anywhere in the storage location. The portal uses these to decide which buttons to draw; the server checks again per path, because a grant can cover one folder and not another.
canDeletebooleanrequired
[
  {
    "id": "k7Qm2sLp9vX4aB1c",
    "name": "Rush delivery",
    "kind": "shared",
    "canWrite": true,
    "canDelete": true
  }
]

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

GET /api/v1/files

One folder's contents: {items, total, nextCursor}. Prefer a space.

Still served, so an older script keeps working. New scripts should use spaces.

Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
rootquerystringrequiredWhich storage location.
pathquerystringoptionalFolder, relative to the storage location. / separated, no leading slash.
sortquerystringoptionalname, size or modified. Defaults to name.
dirquerystringoptionalasc or desc. Defaults to asc.
filterquerystringoptionalNarrow the listing. Matched against the name, ignoring case.
cursorquerystringoptionalWhere to resume: the previous reply's nextCursor. Omit to start.
limitqueryintegeroptionalHow many entries, from 1 to 1000. Defaults to 200.

Encode the query value. A slash in a path may stay as / or be written %2F; the server reads the decoded value. Do not put a leading slash on the path.

Success. 200.

FieldTypeMeaning
itemsarray of objectsrequiredThe records in this reply.

Each item is an object:

FieldTypeMeaning
namestringrequiredThe name.
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
kindstringrequired
sizeintegerrequiredSize in bytes.
modifiedstringoptional
totalintegerrequiredHow many matched, including ones not on this page.
nextCursorstringoptionalSend this back as cursor to get the next page. Left out when this is the last page.
{
  "items": [
    {
      "name": "Rush delivery",
      "path": "projects/rush",
      "kind": "file",
      "size": 1048576,
      "modified": "example"
    }
  ],
  "total": 1,
  "nextCursor": "example"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestthe request is not valid
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "the request is not valid"
  }
}
The cursor is how many entries to skip after sorting, from the previous nextCursor. limit defaults to 200 and must be from 1 to 1000. A folder this caller may not see is 404, the same answer as a folder that is not there.

DELETE /api/v1/files

Delete a file or a folder. Body: {root, path}.

Who. Any user with a key that has the delete scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Request body. JSON.

FieldTypeMeaning
rootstringrequired
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
{
  "root": "k7Qm2sLp9vX4aB1c",
  "path": "projects/rush"
}

Success. 200.

The reply has no body.

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestthe request is not valid
404not_foundnot there, or this caller may not delete it
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "the request is not valid"
  }
}

POST /api/v1/files/folder

Make a folder.

Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Request body. JSON.

FieldTypeMeaning
rootstringrequired
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
{
  "root": "k7Qm2sLp9vX4aB1c",
  "path": "projects/rush"
}

Success. 200.

FieldTypeMeaning
namestringrequiredThe name.
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
kindstringrequired
sizeintegerrequiredSize in bytes.
modifiedstringoptional, left out when empty
{
  "name": "Rush delivery",
  "path": "projects/rush",
  "kind": "file",
  "size": 1048576,
  "modified": "example"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestthe request is not valid
409conflictsomething is already there
404not_foundnot there, or not visible to this caller
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "the request is not valid"
  }
}

POST /api/v1/files/rename

Rename or move within a storage location.

Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Request body. JSON.

FieldTypeMeaning
rootstringrequired
fromstringrequired
tostringrequired
{
  "root": "k7Qm2sLp9vX4aB1c",
  "from": "projects/rush",
  "to": "projects/rush"
}

Success. 200.

FieldTypeMeaning
namestringrequiredThe name.
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
kindstringrequired
sizeintegerrequiredSize in bytes.
modifiedstringoptional, left out when empty
{
  "name": "Rush delivery",
  "path": "projects/rush",
  "kind": "file",
  "size": 1048576,
  "modified": "example"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestthe request is not valid
409conflictsomething is already there
404not_foundnot there, or not visible to this caller
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "the request is not valid"
  }
}