> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hifi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Upload a file

> Upload a file for use in KYC and other verification flows. The file is sent as
`multipart/form-data` with a single field named `file`.

Constraints:
  - Maximum file size is 20 MB.
  - Only the following MIME types are accepted: `application/pdf`, `image/jpeg`,
    `image/png`, `image/heic`, `image/tiff`.
  - Exactly one file may be uploaded per request, in a field named `file`.

The response returns a public file identifier (`file_...`) that can be referenced
in subsequent requests.




## OpenAPI

````yaml https://production.hifi.com/api/v3/openapi.json post /v3/files
openapi: 3.0.0
info:
  title: Hifi API
  version: 3.0.0
  description: API documentation for HIFI
servers:
  - url: https://production.hifi.com
    description: Production server
  - url: https://sandbox.hifi.com
    description: Sandbox server
security:
  - bearerAuth: []
tags:
  - name: Common
    description: Common endpoints
  - name: User
    description: User endpoints
  - name: Counter Party
    description: Counter party endpoints
  - name: Crypto Transfer
    description: Crypto transfer and batch transfer endpoints
  - name: Wallet
    description: Wallet and wallet offer endpoints
  - name: External Account
    description: External bank account endpoints (under a counter party)
  - name: External Wallet
    description: External wallet endpoints (under a counter party)
  - name: External Card
    description: External card endpoints (under a counter party)
  - name: Token Swap
    description: Token swap endpoints
  - name: Bridge
    description: Bridge endpoints
  - name: Virtual Account
    description: Virtual account endpoints
  - name: Compliance
    description: Compliance and compliance link endpoints
  - name: Webhook Endpoint
    description: Webhook endpoint endpoints
  - name: File
    description: File upload endpoints
  - name: Onramp
    description: Onramp (fiat to crypto) endpoints
  - name: Offramp
    description: Offramp (crypto to fiat) endpoints
  - name: Orchestration Address
    description: Orchestration (liquidation) address endpoints
  - name: KYC Link
    description: Hosted and custom KYC/KYB link endpoints
  - name: Transfer Approval
    description: Transfer approval endpoints
  - name: Corridor
    description: Supported fiat/crypto transfer corridor endpoints
  - name: Migration
    description: v2-to-v3 ID mapping endpoints
paths:
  /v3/files:
    post:
      tags:
        - File
      summary: Upload a file
      description: >
        Upload a file for use in KYC and other verification flows. The file is
        sent as

        `multipart/form-data` with a single field named `file`.


        Constraints:
          - Maximum file size is 20 MB.
          - Only the following MIME types are accepted: `application/pdf`, `image/jpeg`,
            `image/png`, `image/heic`, `image/tiff`.
          - Exactly one file may be uploaded per request, in a field named `file`.

        The response returns a public file identifier (`file_...`) that can be
        referenced

        in subsequent requests.
      operationId: v3UploadFile
      requestBody:
        $ref: '#/components/requestBodies/UploadFileBody'
      responses:
        '200':
          $ref: '#/components/responses/UploadFileResponse'
        '400':
          $ref: '#/components/responses/BadRequestResponse'
        '401':
          $ref: '#/components/responses/UnauthorizedResponse'
        '500':
          $ref: '#/components/responses/InternalServerErrorResponse'
components:
  requestBodies:
    UploadFileBody:
      required: true
      description: >
        The file to upload, sent as `multipart/form-data` with a single field
        named `file`.

        Maximum size is 20 MB. Accepted MIME types are `application/pdf`,
        `image/jpeg`,

        `image/png`, `image/heic`, `image/tiff`.
      content:
        multipart/form-data:
          schema:
            $ref: '#/components/schemas/FileUploadRequest'
          encoding:
            file:
              contentType: application/pdf, image/jpeg, image/png, image/heic, image/tiff
  responses:
    UploadFileResponse:
      description: File uploaded successfully.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/FileObject'
          example:
            id: file_9aB0xY4mNpXwZ7bV1aLdt
            createdAt: '2026-07-01T10:30:00.000Z'
            fileName: passport.pdf
            size: 245760
            mimeType: application/pdf
    BadRequestResponse:
      description: Bad Request — the request was malformed or failed validation.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          example:
            type: VALIDATION_ERROR
            message: One or more fields are invalid or missing.
            fields:
              - code: invalid_value
                message: Must be a valid email address
                field: email
    UnauthorizedResponse:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Unauthorized'
    InternalServerErrorResponse:
      description: Internal Server Error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/InternalServerError'
  schemas:
    FileUploadRequest:
      type: object
      required:
        - file
      properties:
        file:
          type: string
          format: binary
          description: >
            The file to upload. Maximum size is 20 MB. Accepted MIME types are

            `application/pdf`, `image/jpeg`, `image/png`, `image/heic`,
            `image/tiff`.
    FileObject:
      type: object
      description: A file that has been uploaded to HIFI.
      properties:
        id:
          type: string
          description: Public file identifier.
          example: file_9aB0xY4mNpXwZ7bV1aLdt
        createdAt:
          type: string
          format: date-time
          description: Timestamp when the file was uploaded, in ISO 8601 format.
          example: '2026-07-01T10:30:00.000Z'
        fileName:
          type: string
          description: Original name of the uploaded file.
          example: passport.pdf
        size:
          type: integer
          description: Size of the file in bytes.
          example: 245760
        mimeType:
          type: string
          description: MIME type of the uploaded file.
          enum:
            - application/pdf
            - image/jpeg
            - image/png
            - image/heic
            - image/tiff
          example: application/pdf
    ApiError:
      type: object
      description: >-
        Standard v3 error shape, returned by validation failures and
        business-logic errors alike.
      properties:
        type:
          type: string
          description: >-
            Machine-readable error type, e.g. VALIDATION_ERROR,
            ACTION_NOT_ALLOWED, RESOURCE_CONFLICT.
          example: VALIDATION_ERROR
        message:
          type: string
          description: Human-readable error message.
          example: One or more fields are invalid or missing.
        fields:
          type: array
          description: >-
            Present on field-level validation errors. One entry per problem
            field.
          items:
            type: object
            properties:
              code:
                type: string
                description: Error code related to the field issue.
              message:
                type: string
                description: Error message for the specific issue.
              field:
                type: string
                description: The name of the field that has an issue.
    Unauthorized:
      type: object
      properties:
        type:
          type: string
          description: Unauthorized enum
          example: UNAUTHORIZED
        message:
          type: string
          description: Unauthorized message
          example: Authentication required
    InternalServerError:
      type: object
      properties:
        type:
          type: string
          example: INTERNAL_SERVER_ERROR
          description: Internal server error enum
        message:
          type: string
          example: An internal server error occurred
          description: Internal server error message
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````