# Upload media > Markdown version of https://docs.postlake.dev/api/post-media . The canonical page for humans. > PostLake is the social media API for AI agents: https://postlake.dev/llms.txt `POST /v1/media` Upload media, either as raw binary with Content-Type set, or as multipart/form-data with a file part. For images the response includes the pixel dimensions, which are checked against each network's limits at publish time. ## Request Authenticate with a bearer API key. Agents calling over MCP authorise with OAuth instead and never handle the key. ```bash curl -X POST https://api.postlake.dev/v1/media \ -H "Authorization: Bearer $POSTLAKE_API_KEY" ``` ## Response Created (`201`). ### Example ```json "…" ``` ## Calling this from an agent Agents do not call REST. They call tools. Over the hosted MCP server this operation is `upload_media`, and the agent authorises with OAuth so your API key is never pasted into a chat or seen by the model. You control what any one agent may do: which brands it may act for, which networks it may reach, how much a day, and whether it may spend credits bought up front. ## Errors Every failure uses one shape: a stable `type`, a granular `code`, the field at fault in `param`, and a plain-language `fix`. See https://docs.postlake.dev/errors.md . Retries are safe: send the same `Idempotency-Key` and a call that already succeeded returns its original result rather than repeating it. ## Common questions **Can an AI agent do this without the REST API?** Yes. Over MCP the same job is the upload_media tool. The agent authorises with OAuth, so no API key is pasted into a chat or seen by the model, and the answer comes back in the same normalised shape. **Is it safe to retry this call?** Yes. Send the same Idempotency-Key and a call that already succeeded returns its original result instead of repeating the work. That is what makes it safe to hand to an agent that retries on its own. **What happens when it fails?** You get one error shape: a stable type, a granular code you can branch on, the offending field in param, and a fix written so an agent can correct itself rather than stop. Full list on Errors and retries. ## Related - [Upload or prepare several media items](https://docs.postlake.dev/api/post-media-batch.md) `POST /v1/media/batch` - [Complete an MCP local-file upload](https://docs.postlake.dev/api/put-media-upload.md) `PUT /media/upload`