Receive links.
A receive link lets someone without an account send files into a folder you can write. These calls manage the link. The sender's page is not called with an API key.
Receive links need the portal feature. Custom questions on a link need the automation feature. See the API reference for the key and for errors.
The link
GET /api/v1/receive-links
Your receive links, and the limits that apply to a new one.
Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.
A receive link is an address you give to people who have no account, so they can send files straight into one of your folders. Receive links are part of the portal feature. An administrator sees every link on the server; everyone else sees their own, newest first. policy says whether a link may never expire, how many days a new one lasts by default, and whether this license includes custom form fields.
Success. 200.
| Field | Type | Meaning | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
links | array of objects | required | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Each item is an object:
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
policy | object | required | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
It is an object:
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"links": [
{
"id": "k7Qm2sLp9vX4aB1c",
"name": "Rush delivery",
"message": "The cut is in the folder.",
"rootId": "k7Qm2sLp9vX4aB1c",
"rootName": "example",
"path": "projects/rush",
"spaceName": "example",
"spacePath": "projects/rush",
"hasPasscode": true,
"requireEmail": true,
"verifyEmail": true,
"allowedTypes": "example",
"oneTime": true,
"subfolder": true,
"subfolderTemplate": "example",
"notifyOwner": true,
"formFields": [
{
"id": "k7Qm2sLp9vX4aB1c",
"label": "example",
"kind": {},
"required": true,
"choices": [
"example"
]
}
],
"state": "active",
"bytesReceived": 1,
"submissionCount": 1,
"ownerId": "k7Qm2sLp9vX4aB1c",
"ownerEmail": "[email protected]",
"createdAt": "2026-10-05T18:00:00Z"
}
],
"policy": {
"allowNeverExpires": true,
"defaultExpiryDays": 1,
"formFieldsIncluded": true
}
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "unauthenticated",
"message": "sign in to continue"
}
}
POST /api/v1/receive-links
Make a receive link.
Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API. This call can also answer 402 when form fields were sent and this server's license does not include automation.
The reply is the only time the link's address is shown, in url: only a hash of the token is kept, so a lost address means making a new link. The destination must be a folder that already exists and that the owner may write to; the link acts with its owner's rights. Leaving out expiresInDays uses the administrator's default, and null means never, which the administrator has to allow. Custom form fields need the automation feature.
Request body. JSON.
A field the server does not know is refused with 400.
| Field | Type | Meaning | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
name | string | optional | The name. | ||||||||||||||||||||||||
message | string | optional | |||||||||||||||||||||||||
rootId | string | optional | A storage location. Kept for older callers. A person picks a space. | ||||||||||||||||||||||||
spaceId | string | optional | A space. The path is then relative to that space, not the location. | ||||||||||||||||||||||||
path | string | optional | A path relative to the space or the storage location, with / between folders and no leading slash. | ||||||||||||||||||||||||
expiresInDays | integer | optional | |||||||||||||||||||||||||
passcode | string | optional | |||||||||||||||||||||||||
requireEmail | boolean | optional | An email address. | ||||||||||||||||||||||||
verifyEmail | boolean | optional | An email address. | ||||||||||||||||||||||||
maxBytesPerSubmission | integer | optional | |||||||||||||||||||||||||
maxFiles | integer | optional | |||||||||||||||||||||||||
allowedTypes | string | optional | |||||||||||||||||||||||||
maxBytesTotal | integer | optional | |||||||||||||||||||||||||
oneTime | boolean | optional | |||||||||||||||||||||||||
subfolder | boolean | optional | |||||||||||||||||||||||||
subfolderTemplate | string | optional | |||||||||||||||||||||||||
notifyOwner | boolean | optional | |||||||||||||||||||||||||
formFields | array of FormField | optional | |||||||||||||||||||||||||
Each item is an object:
| |||||||||||||||||||||||||||
state | string | optional | Where this record is in its life. | ||||||||||||||||||||||||
{
"name": "Rush delivery",
"message": "The cut is in the folder.",
"rootId": "k7Qm2sLp9vX4aB1c",
"spaceId": "k7Qm2sLp9vX4aB1c",
"path": "projects/rush",
"expiresInDays": 1,
"passcode": "example",
"requireEmail": true
}
Success. 200.
| Field | Type | Meaning | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
id | string | required | The id. | ||||||||||||||||||||||||
name | string | required | The name. | ||||||||||||||||||||||||
message | string | required | |||||||||||||||||||||||||
rootId | string | required | The id. | ||||||||||||||||||||||||
rootName | string | required | The storage location's name. | ||||||||||||||||||||||||
path | string | required | Where the files land, relative to the storage location. | ||||||||||||||||||||||||
spaceId | string | optional, left out when empty | The space the owner picked. Absent on a link made before spaces. | ||||||||||||||||||||||||
spaceName | string | required | The space's name. Empty, and left out, when there is no space. | ||||||||||||||||||||||||
spacePath | string | required | path as it reads inside the space. This is what the owner picks. | ||||||||||||||||||||||||
expiresAt | string | optional | A time, as RFC 3339. | ||||||||||||||||||||||||
hasPasscode | boolean | required | |||||||||||||||||||||||||
requireEmail | boolean | required | An email address. | ||||||||||||||||||||||||
verifyEmail | boolean | required | An email address. | ||||||||||||||||||||||||
maxBytesPerSubmission | integer | optional | |||||||||||||||||||||||||
maxFiles | integer | optional | |||||||||||||||||||||||||
allowedTypes | string | required | |||||||||||||||||||||||||
maxBytesTotal | integer | optional | |||||||||||||||||||||||||
oneTime | boolean | required | |||||||||||||||||||||||||
subfolder | boolean | required | |||||||||||||||||||||||||
subfolderTemplate | string | required | |||||||||||||||||||||||||
notifyOwner | boolean | required | |||||||||||||||||||||||||
formFields | array of objects | required | |||||||||||||||||||||||||
Each item is an object:
| |||||||||||||||||||||||||||
state | string | required | Where this record is in its life. | ||||||||||||||||||||||||
bytesReceived | integer | required | |||||||||||||||||||||||||
submissionCount | integer | required | |||||||||||||||||||||||||
ownerId | string | required | The id. | ||||||||||||||||||||||||
ownerEmail | string | required | An email address. | ||||||||||||||||||||||||
createdAt | string | required | A time, as RFC 3339. | ||||||||||||||||||||||||
url | string | optional, left out when empty | The address to give out, present only in the reply that creates the link. Only a hash of the token is kept, so it cannot be shown again. | ||||||||||||||||||||||||
{
"id": "k7Qm2sLp9vX4aB1c",
"name": "Rush delivery",
"message": "The cut is in the folder.",
"rootId": "k7Qm2sLp9vX4aB1c",
"rootName": "example",
"path": "projects/rush",
"spaceName": "example",
"spacePath": "projects/rush",
"hasPasscode": true,
"requireEmail": true,
"verifyEmail": true,
"allowedTypes": "example",
"oneTime": true,
"subfolder": true,
"subfolderTemplate": "example",
"notifyOwner": true,
"formFields": [
{
"id": "k7Qm2sLp9vX4aB1c",
"label": "example",
"kind": {},
"required": true,
"choices": [
"example"
]
}
],
"state": "active",
"bytesReceived": 1,
"submissionCount": 1,
"ownerId": "k7Qm2sLp9vX4aB1c",
"ownerEmail": "[email protected]",
"createdAt": "2026-10-05T18:00:00Z"
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 400 | bad_request | no name, no folder, or a folder that is not there; a passcode under 6 characters; a limit below 1; a file type that is not one; more than 20 questions; a link that never expires when the administrator requires an expiry; or a `state`, which a new link cannot have |
| 402 | licence_required | form fields were sent and this server's license does not include automation |
| 404 | not_found | no such storage location, or a folder the owner may not write to |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
{
"error": {
"code": "bad_request",
"message": "no name, no folder, or a folder that is not there; a passcode under 6 characters; a limit below 1; a file type that is not one; more than 20 questions; a link that never expires when the administrator requires an expiry; or a `state`, which a new link cannot have"
}
}
PATCH /api/v1/receive-links/{id}
Change a receive link, or switch it off and on.
Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API. This call can also answer 402 when form fields were sent and this server's license does not include automation.
Send only what changes. Pointing the link at another folder checks the owner's rights there again. state may be active or disabled; to end a link, delete it. A link that has ended cannot be switched back on. The address is not shown again. Custom form fields need the automation feature. Anyone but the owner or an administrator is answered as if the link did not exist.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Request body. JSON.
A field the server does not know is refused with 400.
| Field | Type | Meaning | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
name | string | optional | The name. | ||||||||||||||||||||||||
message | string | optional | |||||||||||||||||||||||||
rootId | string | optional | A storage location. Kept for older callers. A person picks a space. | ||||||||||||||||||||||||
spaceId | string | optional | A space. The path is then relative to that space, not the location. | ||||||||||||||||||||||||
path | string | optional | A path relative to the space or the storage location, with / between folders and no leading slash. | ||||||||||||||||||||||||
expiresInDays | integer | optional | |||||||||||||||||||||||||
passcode | string | optional | |||||||||||||||||||||||||
requireEmail | boolean | optional | An email address. | ||||||||||||||||||||||||
verifyEmail | boolean | optional | An email address. | ||||||||||||||||||||||||
maxBytesPerSubmission | integer | optional | |||||||||||||||||||||||||
maxFiles | integer | optional | |||||||||||||||||||||||||
allowedTypes | string | optional | |||||||||||||||||||||||||
maxBytesTotal | integer | optional | |||||||||||||||||||||||||
oneTime | boolean | optional | |||||||||||||||||||||||||
subfolder | boolean | optional | |||||||||||||||||||||||||
subfolderTemplate | string | optional | |||||||||||||||||||||||||
notifyOwner | boolean | optional | |||||||||||||||||||||||||
formFields | array of FormField | optional | |||||||||||||||||||||||||
Each item is an object:
| |||||||||||||||||||||||||||
state | string | optional | Where this record is in its life. | ||||||||||||||||||||||||
{
"name": "Rush delivery",
"message": "The cut is in the folder.",
"rootId": "k7Qm2sLp9vX4aB1c",
"spaceId": "k7Qm2sLp9vX4aB1c",
"path": "projects/rush",
"expiresInDays": 1,
"passcode": "example",
"requireEmail": true
}
Success. 200.
| Field | Type | Meaning | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
id | string | required | The id. | ||||||||||||||||||||||||
name | string | required | The name. | ||||||||||||||||||||||||
message | string | required | |||||||||||||||||||||||||
rootId | string | required | The id. | ||||||||||||||||||||||||
rootName | string | required | The storage location's name. | ||||||||||||||||||||||||
path | string | required | Where the files land, relative to the storage location. | ||||||||||||||||||||||||
spaceId | string | optional, left out when empty | The space the owner picked. Absent on a link made before spaces. | ||||||||||||||||||||||||
spaceName | string | required | The space's name. Empty, and left out, when there is no space. | ||||||||||||||||||||||||
spacePath | string | required | path as it reads inside the space. This is what the owner picks. | ||||||||||||||||||||||||
expiresAt | string | optional | A time, as RFC 3339. | ||||||||||||||||||||||||
hasPasscode | boolean | required | |||||||||||||||||||||||||
requireEmail | boolean | required | An email address. | ||||||||||||||||||||||||
verifyEmail | boolean | required | An email address. | ||||||||||||||||||||||||
maxBytesPerSubmission | integer | optional | |||||||||||||||||||||||||
maxFiles | integer | optional | |||||||||||||||||||||||||
allowedTypes | string | required | |||||||||||||||||||||||||
maxBytesTotal | integer | optional | |||||||||||||||||||||||||
oneTime | boolean | required | |||||||||||||||||||||||||
subfolder | boolean | required | |||||||||||||||||||||||||
subfolderTemplate | string | required | |||||||||||||||||||||||||
notifyOwner | boolean | required | |||||||||||||||||||||||||
formFields | array of objects | required | |||||||||||||||||||||||||
Each item is an object:
| |||||||||||||||||||||||||||
state | string | required | Where this record is in its life. | ||||||||||||||||||||||||
bytesReceived | integer | required | |||||||||||||||||||||||||
submissionCount | integer | required | |||||||||||||||||||||||||
ownerId | string | required | The id. | ||||||||||||||||||||||||
ownerEmail | string | required | An email address. | ||||||||||||||||||||||||
createdAt | string | required | A time, as RFC 3339. | ||||||||||||||||||||||||
url | string | optional, left out when empty | The address to give out, present only in the reply that creates the link. Only a hash of the token is kept, so it cannot be shown again. | ||||||||||||||||||||||||
{
"id": "k7Qm2sLp9vX4aB1c",
"name": "Rush delivery",
"message": "The cut is in the folder.",
"rootId": "k7Qm2sLp9vX4aB1c",
"rootName": "example",
"path": "projects/rush",
"spaceName": "example",
"spacePath": "projects/rush",
"hasPasscode": true,
"requireEmail": true,
"verifyEmail": true,
"allowedTypes": "example",
"oneTime": true,
"subfolder": true,
"subfolderTemplate": "example",
"notifyOwner": true,
"formFields": [
{
"id": "k7Qm2sLp9vX4aB1c",
"label": "example",
"kind": {},
"required": true,
"choices": [
"example"
]
}
],
"state": "active",
"bytesReceived": 1,
"submissionCount": 1,
"ownerId": "k7Qm2sLp9vX4aB1c",
"ownerEmail": "[email protected]",
"createdAt": "2026-10-05T18:00:00Z"
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 400 | bad_request | a value that is not allowed, `state` set to `ended`, or a folder that is not there |
| 402 | licence_required | form fields were sent and this server's license does not include automation |
| 404 | not_found | no such link, or it is not this caller's, or a folder the owner may not write to |
| 409 | conflict | the link has ended; make a new one |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
{
"error": {
"code": "bad_request",
"message": "a value that is not allowed, `state` set to `ended`, or a folder that is not there"
}
}
DELETE /api/v1/receive-links/{id}
End a receive link.
Who. Any user with a key that has the delete scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.
The link stops taking files at once and cannot be turned back on. The record stays, so what it received still has a name and a folder. Ending a link that has already ended is not an error.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Success. 200.
| Field | Type | Meaning | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
id | string | required | The id. | ||||||||||||||||||||||||
name | string | required | The name. | ||||||||||||||||||||||||
message | string | required | |||||||||||||||||||||||||
rootId | string | required | The id. | ||||||||||||||||||||||||
rootName | string | required | The storage location's name. | ||||||||||||||||||||||||
path | string | required | Where the files land, relative to the storage location. | ||||||||||||||||||||||||
spaceId | string | optional, left out when empty | The space the owner picked. Absent on a link made before spaces. | ||||||||||||||||||||||||
spaceName | string | required | The space's name. Empty, and left out, when there is no space. | ||||||||||||||||||||||||
spacePath | string | required | path as it reads inside the space. This is what the owner picks. | ||||||||||||||||||||||||
expiresAt | string | optional | A time, as RFC 3339. | ||||||||||||||||||||||||
hasPasscode | boolean | required | |||||||||||||||||||||||||
requireEmail | boolean | required | An email address. | ||||||||||||||||||||||||
verifyEmail | boolean | required | An email address. | ||||||||||||||||||||||||
maxBytesPerSubmission | integer | optional | |||||||||||||||||||||||||
maxFiles | integer | optional | |||||||||||||||||||||||||
allowedTypes | string | required | |||||||||||||||||||||||||
maxBytesTotal | integer | optional | |||||||||||||||||||||||||
oneTime | boolean | required | |||||||||||||||||||||||||
subfolder | boolean | required | |||||||||||||||||||||||||
subfolderTemplate | string | required | |||||||||||||||||||||||||
notifyOwner | boolean | required | |||||||||||||||||||||||||
formFields | array of objects | required | |||||||||||||||||||||||||
Each item is an object:
| |||||||||||||||||||||||||||
state | string | required | Where this record is in its life. | ||||||||||||||||||||||||
bytesReceived | integer | required | |||||||||||||||||||||||||
submissionCount | integer | required | |||||||||||||||||||||||||
ownerId | string | required | The id. | ||||||||||||||||||||||||
ownerEmail | string | required | An email address. | ||||||||||||||||||||||||
createdAt | string | required | A time, as RFC 3339. | ||||||||||||||||||||||||
url | string | optional, left out when empty | The address to give out, present only in the reply that creates the link. Only a hash of the token is kept, so it cannot be shown again. | ||||||||||||||||||||||||
{
"id": "k7Qm2sLp9vX4aB1c",
"name": "Rush delivery",
"message": "The cut is in the folder.",
"rootId": "k7Qm2sLp9vX4aB1c",
"rootName": "example",
"path": "projects/rush",
"spaceName": "example",
"spacePath": "projects/rush",
"hasPasscode": true,
"requireEmail": true,
"verifyEmail": true,
"allowedTypes": "example",
"oneTime": true,
"subfolder": true,
"subfolderTemplate": "example",
"notifyOwner": true,
"formFields": [
{
"id": "k7Qm2sLp9vX4aB1c",
"label": "example",
"kind": {},
"required": true,
"choices": [
"example"
]
}
],
"state": "active",
"bytesReceived": 1,
"submissionCount": 1,
"ownerId": "k7Qm2sLp9vX4aB1c",
"ownerEmail": "[email protected]",
"createdAt": "2026-10-05T18:00:00Z"
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 404 | not_found | no such link, or it is not this caller's |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "not_found",
"message": "not found"
}
}
What a link has received
GET /api/v1/receive-links/{id}/submissions
What a receive link has received, newest first.
Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.
Up to 500 sends, each with its files, the sender's answers and the folder it was put in. scanState is pending, scanning, clean, blocked or notScanned.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Success. 200.
| Field | Type | Meaning | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
submissions | array of objects | required | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Each item is an object:
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
{
"submissions": [
{
"id": "k7Qm2sLp9vX4aB1c",
"linkId": "k7Qm2sLp9vX4aB1c",
"senderEmail": "[email protected]",
"senderName": "example",
"emailVerified": true,
"formValues": {},
"folder": "example",
"bytes": 1048576,
"fileCount": 1,
"state": "active",
"scanState": "example",
"startedAt": "2026-10-05T18:00:00Z",
"files": [
{
"id": "k7Qm2sLp9vX4aB1c",
"path": "projects/rush",
"finalPath": "projects/rush",
"bytes": 1048576,
"checksum": "example",
"scanResult": "example",
"scanDetail": "example"
}
]
}
]
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 404 | not_found | no such link, or it is not this caller's |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "not_found",
"message": "not found"
}
}
POST /api/v1/receive-links/{id}/submissions/{submission_id}/receipt
Email a sender their receipt again.
Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.
Built from what is stored, for a send that is complete or blocked. Unlike the receipt at the end of a send, a failure here is the answer: the caller asked for the mail and is told why it did not go.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The receive link. |
submission_id | path | string | required | The send. |
Request body. None.
Success. 200.
| Field | Type | Meaning | |
|---|---|---|---|
sentTo | string | required |
{
"sentTo": "example"
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 400 | bad_request | the sender gave no email address |
| 404 | not_found | no such link, or it has no such finished send |
| 409 | conflict | email is not switched on or its settings are not complete, or the mail server refused the message; the message says why |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "bad_request",
"message": "the sender gave no email address"
}
}
POST /api/v1/receive-links/{id}/block
Stop one email address sending through a link.
Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.
The address is lowercased and refused from then on. Any send it has open on this link is abandoned, so a sender found halfway through an upload cannot finish. Other links are not affected.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Request body. JSON.
A field the server does not know is refused with 400.
| Field | Type | Meaning | |
|---|---|---|---|
email | string | required | An email address. |
{
"email": "[email protected]"
}
Success. 200.
| Field | Type | Meaning | |
|---|---|---|---|
blocked | string | required |
{
"blocked": "example"
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 400 | bad_request | not an email address |
| 404 | not_found | no such link, or it is not this caller's |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "bad_request",
"message": "not an email address"
}
}
Invitations
GET /api/v1/receive-links/{id}/invites
Who a receive link was emailed to, and whether they opened it.
Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Success. 200.
| Field | Type | Meaning | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
invites | array of objects | required | |||||||||||||||||||||||||||||||||
Each item is an object:
| |||||||||||||||||||||||||||||||||||
{
"invites": [
{
"id": "k7Qm2sLp9vX4aB1c",
"email": "[email protected]",
"createdAt": "2026-10-05T18:00:00Z",
"sentAt": "2026-10-05T18:00:00Z",
"openedAt": "2026-10-05T18:00:00Z",
"openCount": 1,
"revoked": true
}
]
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 404 | not_found | no such link, or it is not this caller's |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "not_found",
"message": "not found"
}
}
POST /api/v1/receive-links/{id}/invites
Email a receive link to people, each with a link of their own.
Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.
Each address gets a personal link. Opening it proves the address the way a sign-in link does, so the person is not asked for their address or a code, and what they send is put under their name. The personal token is random, only its hash is kept, and it stops working when the link ends or the invitation is withdrawn. Uses the receive.invite email template; the optional note is kept to its first 1,000 characters. Up to 50 addresses a call and 200 an hour per owner. Each address is answered on its own, so one that is not valid, is blocked on this link, or could not be emailed does not stop the rest.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Request body. JSON.
A field the server does not know is refused with 400.
| Field | Type | Meaning | |
|---|---|---|---|
emails | array of string | required | |
note | string | optional |
{
"emails": [
"[email protected]"
],
"note": "The cut is in the folder."
}
Success. 200.
| Field | Type | Meaning | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
invites | array of objects | required | |||||||||||||||||
Each item is an object:
| |||||||||||||||||||
{
"invites": [
{
"email": "[email protected]",
"sent": true,
"error": "example"
}
]
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 400 | bad_request | no addresses, or more than 50 |
| 404 | not_found | no such link, or it is not this caller's |
| 409 | conflict | the link has ended or is switched off, this server has no hostname, email is not set up, or too many invitations were sent this hour |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "bad_request",
"message": "no addresses, or more than 50"
}
}
DELETE /api/v1/receive-links/{id}/invites/{invite_id}
Withdraw one person's invitation.
Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.
Their personal link stops working at once. The receive link itself, and everyone else's invitation, are untouched. Answers 204.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The receive link. |
invite_id | path | string | required | The invitation. |
Success. 204.
The reply has no body.
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 404 | not_found | no such link or invitation, or it is not this caller's |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "not_found",
"message": "not found"
}
}