API and MCP reference

Files

5 operations. Each REST operation is also an MCP tool of the same name. REST https://tlntconnect.com/api/v1

GET/api/v1/filesThe workspace's files (contracts, briefs, W-9s…), newest first; filter by campaign, creator, brand or category.

Agency files as the app's Files page lists them (admin members only, like the app): id, name, campaign_id, creator_id, brand_id, category, status, mime_type, file_size, version, notes, uploaded_by, created_at, updated_at — never the storage path. Paged with page/limit (limit ≤ 100, default 50).

MCP tool
list_files
Scopes
tasks:read
Members
admin
Idempotency-Key
Ignored (read)
Rate weight
1

Input

limit queryinteger — Page size, default 50.
page queryinteger — 1-based page, default 1.
brand_id querystring (uuid)
campaign_id querystring (uuid)
category query"contract" | "amendment" | "w9" | "usage_rights" | "nda" | "brand_brief" | "invoice_doc" | "other"
creator_id querystring (uuid)

Responses

200Success
400invalid_input / invalid_json / invalid_id
401missing_token / invalid_token / revoked_token / expired_token
403missing_scope / actor_unavailable / plan_upgrade_required / role_forbidden
404not_found (unknown, cross-workspace or not visible to the key's member)
429rate_limited (honour Retry-After)
500internal_error
GET/api/v1/files/{file_id}One file's metadata (download it with get_file_download_url).

One agency file's metadata. Unknown or cross-workspace ids return 404.

MCP tool
get_file
Scopes
tasks:read
Members
admin
Idempotency-Key
Ignored (read)
Rate weight
1

Input

file_id path, requiredstring (uuid) — File id in this workspace.

Responses

200Success
400invalid_input / invalid_json / invalid_id
401missing_token / invalid_token / revoked_token / expired_token
403missing_scope / actor_unavailable / plan_upgrade_required / role_forbidden
404not_found (unknown, cross-workspace or not visible to the key's member)
429rate_limited (honour Retry-After)
500internal_error
POST/api/v1/files/uploadsReserve a file on a campaign and get a short-lived signed URL to PUT its bytes to; then call complete_file_upload.

The app's signed-upload flow, step 1 (admin members only). Reserves a file record (status needed) on a campaign of this workspace (404 otherwise) and returns upload { url, token, expires_in_seconds }: PUT the bytes to url with the same Content-Type within two hours (Supabase Storage signed upload URL, one object under this agency's own path), then POST /files/{id}/complete. content_type: PDF, Word, plain text, JPEG, PNG or WebP; file_size ≤ 50 MB. Returns 201. If Storage cannot sign the upload the reservation is undone and the answer is 503 service_unavailable; that outcome is kept for the Idempotency-Key, so retry with a new Idempotency-Key.

MCP tool
create_file_upload
Scopes
tasks:write
Members
admin
Idempotency-Key
optional
Rate weight
1

Input

Idempotency-Key headerstring — Retry-safe key (1-255 printable ASCII; a UUID is recommended; an RFC 8941 quoted string is accepted). The same key with the same request within 24h replays the stored response byte for byte (Idempotent-Replayed: true) without running again; the replay still consumes the operation's rate weight.
campaign_id body, requiredstring (uuid) — Campaign in this workspace the file belongs to.
category body, required"contract" | "amendment" | "w9" | "usage_rights" | "nda" | "brand_brief" | "invoice_doc" | "other"
content_type body, requiredstring — One of application/pdf, application/msword, application/vnd.openxmlformats-officedocument.wordprocessingml.document, text/plain, image/jpeg, image/png, image/webp.
file_name body, requiredstring
file_size body, requiredinteger — Bytes; at most 52,428,800 (50 MB).

Responses

201Success
400invalid_input / invalid_json / invalid_id
401missing_token / invalid_token / revoked_token / expired_token
403missing_scope / actor_unavailable / plan_upgrade_required / role_forbidden
404not_found (unknown, cross-workspace or not visible to the key's member)
409idempotency_key_reused / idempotency_in_progress / idempotency_context_changed / idempotency_response_too_large
429rate_limited (honour Retry-After)
500internal_error / idempotent_replay_of_failure
503service_unavailable
POST/api/v1/files/{file_id}/completeMark a reserved file as uploaded after PUTting its bytes to the signed URL.

The app's signed-upload flow, step 3: a reserved file (status needed) becomes uploaded, once its object is in Storage at the reserved path. Completing before the PUT landed (or with an empty object, one over 50 MB, or an object whose type is not the content_type declared when the upload was reserved) is 409 upload_incomplete and nothing changes — PUT the bytes with the declared Content-Type, then retry (the same Idempotency-Key is fine); a wrong type needs a new reservation. If Storage itself cannot be checked the answer is 503 and nothing changes. The stored file_size becomes the object's real size. Any other status is 409 conflict; unknown or cross-workspace ids are 404.

MCP tool
complete_file_upload
Scopes
tasks:write
Members
admin
Idempotency-Key
optional
Rate weight
1

Input

file_id path, requiredstring (uuid) — File id in this workspace.
Idempotency-Key headerstring — Retry-safe key (1-255 printable ASCII; a UUID is recommended; an RFC 8941 quoted string is accepted). The same key with the same request within 24h replays the stored response byte for byte (Idempotent-Replayed: true) without running again; the replay still consumes the operation's rate weight.

Responses

200Success
400invalid_input / invalid_json / invalid_id
401missing_token / invalid_token / revoked_token / expired_token
403missing_scope / actor_unavailable / plan_upgrade_required / role_forbidden
404not_found (unknown, cross-workspace or not visible to the key's member)
409conflict / upload_incomplete / idempotency_key_reused / idempotency_in_progress / idempotency_context_changed / idempotency_response_too_large
429rate_limited (honour Retry-After)
500internal_error / idempotent_replay_of_failure
503service_unavailable
GET/api/v1/files/{file_id}/downloadA signed download URL for a stored file, valid for five minutes.

A five-minute signed Storage URL for one uploaded file of this workspace (admin members only). Unknown, cross-workspace or never-uploaded files — and a record whose object is no longer in Storage — are 404.

MCP tool
get_file_download_url
Scopes
tasks:read
Members
admin
Idempotency-Key
Ignored (read)
Rate weight
1

Input

file_id path, requiredstring (uuid) — File id in this workspace.

Responses

200Success
400invalid_input / invalid_json / invalid_id
401missing_token / invalid_token / revoked_token / expired_token
403missing_scope / actor_unavailable / plan_upgrade_required / role_forbidden
404not_found (unknown, cross-workspace or not visible to the key's member)
429rate_limited (honour Retry-After)
500internal_error