agency-board

POST /v1/agency/boards/{boardId}/cards/{cardId}/attachments

Attach a file to a card.

Alle agency-board-eindpunten

Authenticatie

Stuur een API-sleutel mee als bearer token. Dit eindpunt vermeldt geen specifieke toestemming in de specificatie, dus geef uw sleutel de minimale rechten die nodig zijn en controleer het antwoord in plaats van zomaar wat aan te nemen.

Dit eindpunt vereist geen organisatie-id. Uw sleutel identificeert al de organisatie waartoe deze behoort, en het antwoord is hierop afgestemd.

Probeer het

Vervang alles tussen punthaakjes door uw eigen waarden en de sleutelplaatsvervanger door een sleutel uit uw dashboard.

curl -X POST https://api.zinndigital.com/v1/agency/boards/{boardId}/cards/{cardId}/attachments \
  -H "Authorization: Bearer zdk_live_…"

Ingelogd? De API-console in je dashboard vult je echte organisatie-id en je eigen sleutel in, en voert het verzoek uit tegen de live API zodat je de daadwerkelijke respons kunt zien. Open dit eindpunt in de API-console

Details

⚖️ 25 MB per file and 2 GB per organisation, owner-ruled 2026-09-03. The organisation quota is counted across every board it owns, because a per-board cap is escaped by making another board. ⛔⛔ A stored file is `pending` and **not downloadable by anybody, including the agency's own staff**, until a malware scan has passed it. A client's upload is the best phishing route into an agency there is, and the person opening it has production access to that client's sites. `pending`, `infected` and `error` all refuse — an unscannable file is not a clean file. Accepted types are PNG, JPEG, GIF, WebP, PDF, plain text and CSV, each validated by its magic bytes rather than by the declared content type. No archives (a way to smuggle every format not on the list), no Office documents (macros), no SVG (a script container browsers execute).

Parameters

NaamTypeVerplichtWat dit is
boardId (path)UuidJaProject board ID (UUIDv7).
cardId (path)UuidJaBoard card ID (UUIDv7).

Reactie

NaamTypeVerplichtWat dit is
idUuidJaUUIDv7 identifier — sortable by creation time (docs/02 §8).
card_idUuidJaUUIDv7 identifier — sortable by creation time (docs/02 §8).
filenamestringJa
content_typestringNee
size_bytesintegerJa
visibilityAgencyBoardVisibilityNeeWho may see this object. `internal` is always the default. A **card** reaches the client only when it is `client` **and its column is too** — an AND, not inheritance, because th…
scan_stateAgencyBoardAttachmentScanStateJaWhere an uploaded file is in the malware pipeline. ⛔ `clean` is the ONLY state the bytes are ever served in — `pending`, `infected` and `error` all refuse, including to the agen…
downloadablebooleanJa⭐ Whether these bytes may be fetched right now. Computed from the scan state by the engine rather than derived by a caller — two copies of "may this leave the building" is how t…
uploaded_byAgencyBoardActorNee
created_atstringNee

Fouten die dit eindpunt kan retourneren

401 · 403 · 404 · 422