Skip to content
Documentation/Documents

Upload a public URL

Store the original bytes of a publicly accessible HTTPS file for review or extraction.

Markdown
POST/api/v1/upload/urlhttps://api.webcite.co

URL and file limits

Send a public HTTPS URL, not a local file path or a private chat attachment. The fetch forwards no caller credentials or headers and checks every redirect for unsafe addresses. Private, loopback, link-local, metadata and reserved addresses are refused. The streamed body is limited to 100 MB and the fetch deadline is 30 seconds.

Supported bytes: PDF, PNG, JPEG, WebP, DOCX, PPTX, XLSX, XLSM, XLSB, XLS, ODS, CSV, TSV, TXT and MD. An optional display filename must have an extension matching the fetched bytes. Hosted MCP upload_url uses this workflow; hosted base64 upload_file retains its separate 20 MB limit.

Request

1 credit, charged only when the file is stored.

Examples run on your server. Set WEBCITE_API_KEY first. Python examples use the requests package.

curl
curl --fail-with-body -X POST 'https://api.webcite.co/api/v1/upload/url' \
  -H "x-api-key: $WEBCITE_API_KEY" \
  -H 'Content-Type: application/json' \
  -d '{
  "url": "https://example.com/report.pdf"
}'

Request body

filenamestring

Display filename. Its extension must match the fetched bytes.

urlstringrequired

Public HTTPS URL of the file. Fetched server-side with no caller credentials or headers; private, loopback, link-local and metadata addresses are refused on every redirect.

Response

HTTP 200 returns asset_id and source_version_id. Keep these owned identifiers for later review and extraction. The public OpenAPI does not define the complete response schema.

200 response

See the response guidance above. A complete JSON schema is not published for this response.

Errors

400: unsafe or invalid URL or redirect. 413: more than 100 MB. 415: unsupported bytes or filename mismatch. 422: upstream non-2xx or empty body. 504: fetch timeout. An uncertain outcome is not proof that no upload occurred; retain any operation receipt before retrying.

400
URL not allowed (non-https, private address, credentials, bad redirect)
413
File larger than 100 MB
415
Bytes are not a supported format
422
URL returned a non-2xx status or an empty body
504
Fetch timed out
Error handling and retry guidance