> ## Documentation Index
> Fetch the complete documentation index at: https://docs.uplint.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# List Files

> List uploaded files for the current tenant with pagination. Optionally filter by context or uploader.



## OpenAPI

````yaml GET /api/v1/files
openapi: 3.0.3
info:
  title: Uplint API
  version: 0.1.0
  description: >-
    Uplint is a file safety and integrity platform. Upload files through
    context-aware pipelines that automatically validate integrity, detect blank
    or placeholder content, and scan for viruses — all behind a single API.


    This specification covers the core Uplint REST API:


    - **API Keys** — Create and manage scoped API keys for programmatic access.

    - **File Contexts** — Define upload pipelines with per-context rules
    (allowed extensions, size limits, blank/corrupt rejection, virus scanning,
    rate limits, and storage quotas).

    - **Files** — Upload, list, download, inspect, and delete files. Every
    upload runs through the validation pipeline configured on its context.


    All endpoints are tenant-scoped. Authenticate with an API key or JWT token
    via the `Authorization` header.
  contact:
    name: Uplint Team
    url: https://uplint.dev
  license:
    name: MIT
    url: https://opensource.org/licenses/MIT
servers:
  - url: https://api.uplint.dev
    description: Production
  - url: http://localhost:8000
    description: Local development
security:
  - BearerAuth: []
tags:
  - name: API Keys
    description: >-
      Create, list, inspect, update, and revoke API keys. Each key carries
      scoped permissions (`upload`, `download`, `metadata`, `delete`, `admin`)
      and is bound to the authenticated tenant.
  - name: File Contexts
    description: >-
      File contexts define upload pipelines. Each context specifies allowed
      extensions, max file size, whether to reject blank or corrupt files, virus
      scanning, rate limits, and storage quotas. Files are always uploaded into
      a context.
  - name: Files
    description: >-
      Upload, list, download, inspect metadata, and delete files. Every upload
      is validated against its context rules before storage.
  - name: Storage Buckets
    description: >-
      Manage the S3 buckets a tenant stores files in. Each tenant can register
      multiple buckets (bring-your-own S3 credentials); one is the **default**
      (fallback) bucket, and file contexts can be routed to any active bucket.
      All storage endpoints require an `admin`-scoped API key.
paths:
  /api/v1/files:
    get:
      tags:
        - Files
      summary: List files
      description: >-
        List uploaded files for the current tenant with pagination. Optionally
        filter by context or uploader.
      operationId: listFiles
      parameters:
        - name: context
          in: query
          schema:
            type: string
          description: Filter by context key.
        - name: uploaded_by
          in: query
          schema:
            type: string
          description: Filter by API key ID or user ID.
        - name: page
          in: query
          schema:
            type: integer
            minimum: 1
            default: 1
          description: Page number.
        - name: page_size
          in: query
          schema:
            type: integer
            minimum: 1
            maximum: 100
            default: 20
          description: Items per page.
      responses:
        '200':
          description: Paginated list of files.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuccessResponse_FileList'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    SuccessResponse_FileList:
      type: object
      properties:
        status:
          type: string
          enum:
            - SUCCESS
        message:
          type: string
        data:
          type: array
          items:
            $ref: '#/components/schemas/FileListItemResponse'
        pagination:
          $ref: '#/components/schemas/PaginationMeta'
        timestamp:
          type: string
          format: date-time
    FileListItemResponse:
      type: object
      properties:
        file_id:
          type: string
        original_filename:
          type: string
        content_type:
          type: string
        size_bytes:
          type: integer
        context_key:
          type: string
        uploaded_by:
          type: string
          description: API key ID or user ID of the uploader.
        uploaded_by_name:
          type: string
          nullable: true
          description: Name of the API key used.
        metadata:
          type: object
          additionalProperties: true
        download_count:
          type: integer
          default: 0
        last_downloaded_at:
          type: string
          format: date-time
          nullable: true
        created_at:
          type: string
          format: date-time
    PaginationMeta:
      type: object
      properties:
        page:
          type: integer
        page_size:
          type: integer
        total:
          type: integer
        total_pages:
          type: integer
    ErrorResponse:
      type: object
      properties:
        status:
          type: string
          enum:
            - ERROR
        message:
          type: string
        errors:
          type: array
          items:
            type: string
        timestamp:
          type: string
          format: date-time
  responses:
    Unauthorized:
      description: Missing, invalid, or expired authentication credentials.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            status: ERROR
            message: Invalid or missing API key
            errors:
              - Authentication required
            timestamp: '2026-02-10T12:00:00Z'
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        Pass an API key or JWT token. API keys can be sent as `Authorization:
        Bearer <key>` or `Authorization: <key>`.

````