# Attach a file to a record

Declares a file on one record and answers the file row plus a signed PUT `uploadUrl` the client sends the bytes to — this route never carries the file itself. `name` is required and `sizeBytes` must not be negative; `contentType`, `documentType` and `periodStart`/`periodEnd` type the file so the statements and processing reads can find it. Refused when file storage is not configured for this workspace.

Access class: `def:read`.

## Endpoint

`POST /v1/definitions/{key}/rows/{rowId}/files`

## Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| key | path | string | Yes |
| rowId | path | string | Yes |

## Request body

Content type: `application/json`.

```json
{
  "body": {
    "contentType": "string",
    "documentType": "string",
    "name": "string",
    "periodEnd": "string",
    "periodStart": "string",
    "sizeBytes": 1
  },
  "params": {
    ":key": "string",
    ":rowId": ""
  },
  "query": {}
}
```

## Responses

### 201

the action's answer

Content type: `application/json`.

```json
{}
```

### default

a refusal: `{"error": "<what a person needs to read>"}`. 401 no credential, 402 the plan does not include this, 403 the seat does not, 404 the thing does not exist or is not yours to see.

Content type: `application/json`.

```json
{
  "error": "string"
}
```
