# Identity: media

> Send a file to a contact (SPEC §7.4)

## Send a file to a contact (SPEC §7.4)

`POST /v1/identities/{slug}/media` · operation `sendMedia`

Requires the `batondeck:messages:send` permission (action `message:send`).

Refused while the workspace is suspended or on deletion hold.

Accepts an `Idempotency-Key` header. A repeat within 24 hours returns the first answer; the same key with different arguments is refused with `idempotency_mismatch`.

**Parameters**

| Name | In | Type | Required | Notes |
|---|---|---|---|---|
| `slug` | path | string | yes |  |
| `Idempotency-Key` | header | string |  | Repeat this value to retry the call without repeating its effect. |

**Request body** (`application/json`)

| Field | Type | Required | Notes |
|---|---|---|---|
| `fingerprint` | string | yes | ≥ 1 chars |
| `data` | string | yes | ≥ 1 chars |
| `filename` | string | yes | ≤ 256 chars, default "" |
| `mime` | string | yes | ≤ 128 chars, default "application/octet-stream" |
| `thread_id` | string |  | ≤ 128 chars |
| `msg_id` | string |  | ≤ 128 chars |

<details>
<summary>Request schema</summary>

```json
{
  "type": "object",
  "properties": {
    "fingerprint": {
      "type": "string",
      "minLength": 1
    },
    "data": {
      "type": "string",
      "minLength": 1
    },
    "filename": {
      "default": "",
      "type": "string",
      "maxLength": 256
    },
    "mime": {
      "default": "application/octet-stream",
      "type": "string",
      "maxLength": 128
    },
    "thread_id": {
      "type": "string",
      "maxLength": 128
    },
    "msg_id": {
      "type": "string",
      "maxLength": 128
    }
  },
  "required": [
    "fingerprint",
    "data",
    "filename",
    "mime"
  ],
  "additionalProperties": false
}
```

</details>

**Responses**

| Status | Meaning |
|---|---|
| 201 | Send a file to a contact (SPEC §7.4) |
| 400 | The arguments did not validate. |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |
| 422 | That Idempotency-Key was used with different arguments. |
| 429 | This identity's outbound budget (HDTP §12: 1 call a second per contact with a burst of 10, the identity's aggregate, 20 an hour to strangers), or the peer's own, refused the call; `retry_after` and Retry-After say when to try again. |

<details>
<summary>201 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "status": {
      "type": "string"
    },
    "message_id": {
      "type": "string"
    },
    "thread_id": {
      "type": "string"
    },
    "hash": {
      "type": "string"
    }
  },
  "required": [
    "status",
    "message_id",
    "thread_id",
    "hash"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X POST 'https://api.batondeck.com/v1/identities/:slug/media' \
  -H "Authorization: Bearer $BATONDECK_API_KEY" \
  -H 'content-type: application/json' \
  -d @body.json
```
