> ## Documentation Index
> Fetch the complete documentation index at: https://docs.synack.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Upload Attachment

> Uploads an evidence file of up to 300 MB. Reference the returned `id` and `secureHash` from a validation step when submitting a vulnerability.




## OpenAPI

````yaml /researcher-v1-openapi.yaml post /v1/attachments
openapi: 3.1.0
info:
  title: Synack Researcher API
  version: 1.0.0
  description: >
    API for Synack Red Team researchers to submit vulnerabilities and upload
    evidence.

    Requests must be sent from a LaunchPoint+ workspace.


    To submit a vulnerability:


    1. Upload each evidence file with `POST /v1/attachments`, which accepts
    files up to
       300 MB, and keep the returned `id` and `secureHash`. Files up to 5 MB can instead
       be sent inline, base64-encoded, in the submission itself.
    2. Submit the vulnerability with `POST /v1/vulnerabilities`, listing the
    attachments
       in its validation steps. At least one validation step must include an attachment,
       and a submission can include at most 50 attachments.

    Errors are returned as `application/problem+json`

    ([RFC 9457](https://datatracker.ietf.org/doc/html/rfc9457)).
  contact:
    name: Synack Engineering
    email: engineering@synack.com
servers:
  - url: https://platform.synack.com/api
    description: Commercial
  - url: https://platform.synack.us/api
    description: FedRAMP (Medium)
security:
  - bearerAuth: []
tags:
  - name: Vulnerabilities
    description: Submit vulnerabilities.
  - name: Attachments
    description: Upload evidence for validation steps.
paths:
  /v1/attachments:
    post:
      tags:
        - Attachments
      summary: Upload an attachment
      description: >
        Uploads an evidence file of up to 300 MB. Reference the returned `id`
        and `secureHash` from a validation step when submitting a vulnerability.
      operationId: createAttachment
      requestBody:
        required: true
        content:
          multipart/form-data:
            schema:
              type: object
              required:
                - file
              properties:
                file:
                  type: string
                  format: binary
                  description: >
                    The file to upload. Its extension must match its content.
                    Accepted files:


                    | Type | Extensions |

                    |---|---|

                    | Image | `.png`, `.jpg`, `.jpeg`, `.tif`, `.tiff` |

                    | Video | `.mp4`, `.m4v`, `.mov`, `.webm`, `.mpg`, `.mpeg`,
                    `.avi` |

                    | Document | `.pdf`, `.docx`, `.xls`, `.xlsx`, `.ppt` |

                    | Text | `.txt`, `.csv`, `.html`, `.htm` |

                    | Archive | `.zip`, `.tar` |
      responses:
        '201':
          description: The attachment was uploaded.
          content:
            application/json:
              schema:
                type: object
                properties:
                  attachment:
                    $ref: '#/components/schemas/Attachment'
        '401':
          $ref: '#/components/responses/401Unauthorized'
        '403':
          $ref: '#/components/responses/403UploadForbidden'
        '422':
          $ref: '#/components/responses/422UploadUnprocessableContent'
components:
  schemas:
    Attachment:
      type: object
      properties:
        id:
          type: integer
          example: 8412773
        fileName:
          type: string
          example: login-bypass.png
        fileSize:
          type: integer
          description: Size in bytes.
          example: 184320
        contentType:
          type: string
          example: image/png
        secureHash:
          type: string
          description: Must be sent with `id` when referencing this attachment.
          example: 6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d
        url:
          type: string
          format: uri
          description: Pre-signed download URL.
          example: https://storage.googleapis.com/example-bucket/cat.jpeg?X-Goog-Algo
    Problem:
      type: object
      required:
        - type
        - title
      properties:
        type:
          type: string
          format: uri
          description: URI identifying the problem type.
        title:
          type: string
          description: Short summary of the problem type.
        detail:
          type: string
          description: Explanation specific to this occurrence.
        invalidParams:
          type: array
          description: The fields that failed validation.
          items:
            type: object
            required:
              - name
              - reason
            properties:
              name:
                type: string
                description: >
                  Name of the field that failed. Most match the request field
                  names; some errors found while saving the submission, and
                  attachment file errors (`gcs_file`), use internal names.
                example: cvssVector
              reason:
                type: string
                example: is invalid
  responses:
    401Unauthorized:
      description: The bearer token is missing, invalid or expired.
      headers:
        WWW-Authenticate:
          schema:
            type: string
          example: Bearer realm="Synack Platform API"
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Problem'
          example:
            type: https://synack.com/probs/unauthenticated
            title: Authentication required
            detail: >-
              This endpoint requires a bearer token issued for the Synack
              Platform API.
    403UploadForbidden:
      description: |
        The request was refused for one of these reasons:

        - It was not sent from a LaunchPoint+ workspace.
        - The token was not issued for this API.
        - You have not completed ID verification or signed the current terms.
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Problem'
          examples:
            workspaceConnectionRequired:
              summary: Not sent from LaunchPoint+
              value:
                type: https://synack.com/probs/workspace_connection_required
                title: LaunchPoint+ connection required
                detail: >-
                  Requests to this endpoint must originate from a LaunchPoint+
                  workspace gateway.
            forbiddenScope:
              summary: Token not issued for this API
              value:
                type: https://synack.com/probs/forbidden_scope
                title: Token not valid for this API
                detail: The supplied token was not issued for the Synack Platform API.
            researcherNotEligible:
              summary: Researcher not eligible
              value:
                type: https://synack.com/probs/researcher_not_eligible
                title: Researcher not eligible
                detail: >-
                  The researcher must have completed identity verification and
                  signed the current terms.
    422UploadUnprocessableContent:
      description: No file was sent, or the file is too large or not a supported type.
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Problem'
          examples:
            missingFile:
              summary: No file
              value:
                type: https://synack.com/probs/missing_required_parameters
                title: Missing required parameters
                invalidParams:
                  - name: file
                    reason: is required
            unsupportedFile:
              summary: Unsupported file
              value:
                type: https://synack.com/probs/invalid_parameters
                title: Your parameters did not validate
                invalidParams:
                  - name: gcs_file
                    reason: file extension does not match content type
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >
        API token generated in the researcher portal under your profile menu,
        API, Tokens.

````