API reference · Media
Complete an MCP local-file upload
PUT /media/upload
Upload raw file bytes to the short-lived target returned by the MCP upload_media tool when called without a URL. Send the returned upload token as `Authorization: Bearer …` and the exact returned Content-Type. This endpoint does not accept a PostLake API key and is not called until upload_media has prepared a media id and target.
Request
Authenticate with a bearer API key. Agents calling over MCP authorise with OAuth instead and never handle the key.
curl -X PUT https://api.postlake.dev/media/upload \
-H "Authorization: Bearer $POSTLAKE_API_KEY"Response
Uploaded; returns the MediaAsset whose id is ready for create_post (201).
Example
"…"Limits
Write operations are limited per account, and every response carries X-RateLimit-Remaining and X-RateLimit-Reset. A 429 includes Retry-After. Send an Idempotency-Key so a retry after a timeout cannot duplicate the work.
Calling this from an agent
Agents do not call REST. They call tools. Over the hosted MCP server this operation is upload_media, and the agent authorises with OAuth so your API key is never pasted into a chat or seen by the model. The reply comes back in the same normalised shape you see above, which is what lets an agent reason about it without a per-network branch.
You control what any one agent may do with it: which brands it may act for, which networks it may reach, how much it may do in a day, and whether it may spend credits you bought up front. See the MCP server.
Errors
Every failure uses one shape: a stable type, a granular code, the field at fault in param, and a plain-language fix. An agent can act on it without a person reading the message. See Errors and retries.
Idempotency-Key and a call that already succeeded returns its original result rather than repeating it.Common questions
Can an AI agent do this without the REST API?
Yes. Over MCP the same job is the upload_media tool. The agent authorises with OAuth, so no API key is pasted into a chat or seen by the model, and the answer comes back in the same normalised shape.
How often can I call this?
Reads are rate limited per account and every response carries X-RateLimit-Remaining and X-RateLimit-Reset. On a 429 the Retry-After header tells you how long to wait.
What happens when it fails?
You get one error shape: a stable type, a granular code you can branch on, the offending field in param, and a fix written so an agent can correct itself rather than stop. Full list on Errors and retries.