> ## Documentation Index
> Fetch the complete documentation index at: https://docs.slash.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Upload a document

> Upload a PDF, PNG or JPEG of up to 25 MB as `multipart/form-data`, then attach it to a bill or accounting entry by id. Until it's attached, only the uploading user can read the document.



## OpenAPI

````yaml /openapi-v2.json post /v2/documents
openapi: 3.1.0
info:
  title: Slash Public API V2
  description: >-
    Send money for a Slash legal entity. Every request uses an API key. Transfer
    creation returns a Transfer that links its resulting transactions.
  version: 0.0.1
servers:
  - url: https://api.slash.com
    description: production
security:
  - api_key: []
paths:
  /v2/documents:
    parameters:
      - name: x-legal-entity
        in: header
        required: true
        description: >-
          The legal entity to act on. Required on every request; a user API key
          can act on any legal entity its user has access to.
        schema:
          type: string
          pattern: ^le_[a-zA-Z0-9]+$
    post:
      summary: Upload a document
      description: >-
        Upload a PDF, PNG or JPEG of up to 25 MB as `multipart/form-data`, then
        attach it to a bill or accounting entry by id. Until it's attached, only
        the uploading user can read the document.
      requestBody:
        required: true
        content:
          multipart/form-data:
            schema:
              type: object
              properties:
                purpose:
                  type: string
                  enum:
                    - bill_invoice
                    - accounting_receipt
                  description: >-
                    What the file is for: `bill_invoice` for bills,
                    `accounting_receipt` for accounting entries. Send it before
                    `file`.
                file:
                  type: string
                  format: binary
                  description: >-
                    The file to upload. PDF, PNG, or JPEG (HEIC is converted to
                    JPEG). Required; a request without a `file` part is rejected
                    with `file_required`.
              required:
                - purpose
              additionalProperties: false
            encoding:
              file:
                contentType: '*/*'
      responses:
        '200':
          description: The uploaded document, with a `downloadUrl` for the stored file.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/document'
        '400':
          $ref: '#/components/responses/PublicApiV2Error400DocumentsUpload'
        '401':
          $ref: '#/components/responses/PublicApiV2Error401Unauthorized'
        '403':
          $ref: >-
            #/components/responses/PublicApiV2Error403ForbiddenForbiddenLegalEntityNotAvailableUserApiKeyRequired
        '429':
          $ref: '#/components/responses/PublicApiV2RateLimited'
        '500':
          $ref: '#/components/responses/PublicApiV2Error500Internal'
      security:
        - api_key: []
components:
  schemas:
    document:
      title: Document
      description: >-
        A file uploaded to Slash, owned by the user whose API key uploaded it.
        Until it's attached, only that user can read it; once attached to a bill
        or accounting entry, anyone who can see that bill or entry can. Attach
        it by id where its `purpose` is accepted; the file itself is fetched
        through `downloadUrl`.
      type: object
      properties:
        id:
          type: string
          description: Document id with the `st_` prefix.
          example: st_2rj4l7hmrrrcv
        filename:
          type: string
          description: The filename supplied at upload.
          example: invoice-4471.pdf
        purpose:
          type: string
          enum:
            - bill_invoice
            - accounting_receipt
          description: >-
            What the document was uploaded for. Absent on files Slash stored for
            something else.
          example: bill_invoice
        contentType:
          type: string
          description: MIME type detected from the file's bytes.
          example: application/pdf
        sizeBytes:
          type: integer
          description: Size of the stored file in bytes.
          example: 48213
        downloadUrl:
          type: string
          format: uri
          description: >-
            Presigned URL for the file. Valid for about 15 minutes; fetch the
            document again for a fresh one.
        createdAt:
          type: string
          format: date-time
          description: When the document was uploaded.
      required:
        - id
        - filename
        - contentType
        - sizeBytes
        - downloadUrl
        - createdAt
      additionalProperties: false
    PublicApiV2ErrorFileRequired:
      title: PublicApiV2ErrorFileRequired
      description: The `multipart/form-data` body ended without a `file` part.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - file_required
            details:
              type: object
              properties:
                field:
                  type: string
                  description: Dot path of the request field at fault.
                id:
                  type: string
                  description: The identifier that field carried, when it is one.
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorFileSizeLimit:
      title: PublicApiV2ErrorFileSizeLimit
      description: Files can be up to 25 MB.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - file_too_large
            details:
              type: object
              properties:
                field:
                  type: string
                  description: Dot path of the request field at fault.
                id:
                  type: string
                  description: The identifier that field carried, when it is one.
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorPdfPageLimit:
      title: PublicApiV2ErrorPdfPageLimit
      description: PDFs can have up to 100 pages.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - pdf_too_many_pages
            details:
              type: object
              properties:
                field:
                  type: string
                  description: Dot path of the request field at fault.
                id:
                  type: string
                  description: The identifier that field carried, when it is one.
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorUnreadablePdf:
      title: PublicApiV2ErrorUnreadablePdf
      description: The file is not a valid PDF, or it is damaged or encrypted.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - unreadable_pdf
            details:
              type: object
              properties:
                field:
                  type: string
                  description: Dot path of the request field at fault.
                id:
                  type: string
                  description: The identifier that field carried, when it is one.
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorUnsupportedFileType:
      title: PublicApiV2ErrorUnsupportedFileType
      description: >-
        Only PDF, PNG and JPEG files are accepted. HEIC photos are converted to
        JPEG on upload.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - unsupported_file_type
            details:
              type: object
              properties:
                field:
                  type: string
                  description: Dot path of the request field at fault.
                id:
                  type: string
                  description: The identifier that field carried, when it is one.
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorInvalidRequestShape:
      title: PublicApiV2ErrorInvalidRequestShape
      description: >-
        The body, query, or headers failed validation, or a required header is
        missing. `details` has one entry per failing location, keyed by JSON
        pointer or header name.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - invalid_request
            details:
              type: object
              properties: {}
              additionalProperties:
                type: string
          required:
            - code
            - details
    PublicApiV2ErrorUnauthorized:
      title: PublicApiV2ErrorUnauthorized
      description: API key authentication is missing or invalid.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - unauthorized
            details:
              type: object
              properties: {}
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorForbidden:
      title: PublicApiV2ErrorForbidden
      description: >-
        The credential is not permitted to perform this action on the resource.
        When the resource is a field of the request, `details` names that
        `field` and the `id` it received.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - forbidden
            details:
              type: object
              properties:
                field:
                  type: string
                  description: Dot path of the request field at fault.
                id:
                  type: string
                  description: The identifier that field carried, when it is one.
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorForbiddenLegalEntity:
      title: PublicApiV2ErrorForbiddenLegalEntity
      description: The credential is not permitted to act for the selected legal entity.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - forbidden
            details:
              type: object
              properties: {}
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorNotAvailable:
      title: PublicApiV2ErrorNotAvailable
      description: >-
        Public API v2 is not yet available. Use [Public API
        v1](https://docs.slash.com/introduction) in the meantime.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - not_available
            details:
              type: object
              properties: {}
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorUserApiKeyRequired:
      title: PublicApiV2ErrorUserApiKeyRequired
      description: >-
        The API key is scoped to a legal entity rather than a user. Every v2
        request needs a user API key, created under Settings → API keys in the
        Slash dashboard, together with the `x-legal-entity` header.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - user_api_key_required
            details:
              type: object
              properties: {}
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorInternal:
      title: PublicApiV2ErrorInternal
      description: >-
        Slash could not complete the request. Quote `referenceId` when
        contacting Slash support.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - internal
            details:
              type: object
              properties: {}
              additionalProperties: false
          required:
            - code
            - details
    Error:
      type: object
      properties:
        code:
          type: string
          description: >-
            Machine-readable reason; branch on this, not on `message`. Every
            code an endpoint can return is listed on its reference page; the
            ones shared by all endpoints are explained in the Errors guide.
          example: invalid_request
        message:
          type: string
          description: >-
            Human-readable explanation, safe to show to an operator. Wording may
            change; use `code` and `details` programmatically.
        details:
          type: object
          description: >-
            The values behind `message`, keyed per `code`. For example
            `insufficient_funds` carries `available` and `requested`;
            `invalid_request` from contract validation carries one entry per
            failing field, keyed by JSON pointer. Empty when the code has no
            variable data.
          additionalProperties:
            type: string
          example:
            available: $120.00
            requested: $500.00
        referenceId:
          type: string
          description: Unique id of this failure. Quote it when contacting Slash support.
          example: 4001-2alj5if
      required:
        - code
        - message
        - details
        - referenceId
      additionalProperties: false
      title: Error
  responses:
    PublicApiV2Error400DocumentsUpload:
      description: >-
        - `file_required` — The `multipart/form-data` body ended without a
        `file` part.

        - `file_too_large` — Files can be up to 25 MB.

        - `pdf_too_many_pages` — PDFs can have up to 100 pages.

        - `unreadable_pdf` — The file is not a valid PDF, or it is damaged or
        encrypted.

        - `unsupported_file_type` — Only PDF, PNG and JPEG files are accepted.
        HEIC photos are converted to JPEG on upload.

        - `invalid_request (request shape)` — The body, query, or headers failed
        validation, or a required header is missing. `details` has one entry per
        failing location, keyed by JSON pointer or header name.
      content:
        application/json:
          schema:
            anyOf:
              - title: file_required
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorFileRequired'
              - title: file_too_large
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorFileSizeLimit'
              - title: pdf_too_many_pages
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorPdfPageLimit'
              - title: unreadable_pdf
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorUnreadablePdf'
              - title: unsupported_file_type
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorUnsupportedFileType'
              - title: invalid_request (request shape)
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorInvalidRequestShape'
          examples:
            file_required_file:
              summary: file_required (file)
              value:
                code: file_required
                message: A `file` part is required.
                details:
                  field: file
                referenceId: 4001-2alj5if
            file_too_large_file:
              summary: file_too_large (file)
              value:
                code: file_too_large
                message: The file exceeds 25 MB.
                details:
                  field: file
                referenceId: 4001-2alj5if
            pdf_too_many_pages_file:
              summary: pdf_too_many_pages (file)
              value:
                code: pdf_too_many_pages
                message: The PDF has more than 100 pages.
                details:
                  field: file
                referenceId: 4001-2alj5if
            unreadable_pdf_file:
              summary: unreadable_pdf (file)
              value:
                code: unreadable_pdf
                message: The PDF could not be read.
                details:
                  field: file
                referenceId: 4001-2alj5if
            unsupported_file_type_file:
              summary: unsupported_file_type (file)
              value:
                code: unsupported_file_type
                message: The file must be a PDF, PNG or JPEG.
                details:
                  field: file
                referenceId: 4001-2alj5if
            invalid_request_request_shape:
              summary: invalid_request (request shape)
              value:
                code: invalid_request
                message: >-
                  Invalid `purpose`: Invalid option: expected one of
                  "bill_invoice"|"accounting_receipt"
                details:
                  /purpose: >-
                    Invalid option: expected one of
                    "bill_invoice"|"accounting_receipt"
                referenceId: 4001-2alj5if
    PublicApiV2Error401Unauthorized:
      description: '- `unauthorized` — API key authentication is missing or invalid.'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PublicApiV2ErrorUnauthorized'
          examples:
            unauthorized:
              summary: unauthorized
              value:
                code: unauthorized
                message: API key authentication is missing or invalid.
                details: {}
                referenceId: 4011-2alj5if
    PublicApiV2Error403ForbiddenForbiddenLegalEntityNotAvailableUserApiKeyRequired:
      description: >-
        - `forbidden` — The credential is not permitted to perform this action
        on the resource. When the resource is a field of the request, `details`
        names that `field` and the `id` it received.

        - `forbidden (legal entity)` — The credential is not permitted to act
        for the selected legal entity.

        - `not_available` — Public API v2 is not yet available. Use [Public API
        v1](https://docs.slash.com/introduction) in the meantime.

        - `user_api_key_required` — The API key is scoped to a legal entity
        rather than a user. Every v2 request needs a user API key, created under
        Settings → API keys in the Slash dashboard, together with the
        `x-legal-entity` header.
      content:
        application/json:
          schema:
            anyOf:
              - title: forbidden
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorForbidden'
              - title: forbidden (legal entity)
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorForbiddenLegalEntity'
              - title: not_available
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorNotAvailable'
              - title: user_api_key_required
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorUserApiKeyRequired'
          examples:
            forbidden:
              summary: forbidden
              value:
                code: forbidden
                message: This credential is not permitted to do that.
                details: {}
                referenceId: 4031-2alj5if
            forbidden_legal_entity:
              summary: forbidden (legal entity)
              value:
                code: forbidden
                message: This credential is not permitted to do that.
                details: {}
                referenceId: 4031-2alj5if
            not_available:
              summary: not_available
              value:
                code: not_available
                message: >-
                  Public API v2 is not yet available. Use Public API v1
                  (https://docs.slash.com/introduction) in the meantime.
                details: {}
                referenceId: 4031-2alj5if
            user_api_key_required:
              summary: user_api_key_required
              value:
                code: user_api_key_required
                message: >-
                  Public API v2 requires a user API key. Create one under
                  Settings → API keys in the Slash dashboard.
                details: {}
                referenceId: 4031-2alj5if
    PublicApiV2RateLimited:
      description: >-
        The request exceeded the applicable rate limit. The response body is
        plain text, not the error object; clients must not depend on its
        wording.
      content:
        text/plain:
          schema:
            type: string
          example: You are rate limited
    PublicApiV2Error500Internal:
      description: >-
        - `internal` — Slash could not complete the request. Quote `referenceId`
        when contacting Slash support.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PublicApiV2ErrorInternal'
          examples:
            internal:
              summary: internal
              value:
                code: internal
                message: >-
                  An unexpected error occurred. If this keeps happening, contact
                  Slash support with the reference id below.
                details: {}
                referenceId: 5001-2alj5if
  securitySchemes:
    api_key:
      type: apiKey
      name: X-API-Key
      in: header
      description: >-
        User API key authentication. Create a key under Settings → API keys in
        the Slash dashboard (https://app.slash.com/global-settings/api-keys) and
        send the `x-legal-entity` header naming the legal entity to act on with
        every request. Keys scoped to a legal entity are rejected with `403
        user_api_key_required`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.