Documents and signing

documents.assets.prepare

Start uploading an image for agreements, such as a logo, a diagram or a signature stamp: PNG or JPEG up to 10 MB and 6,000 pixels on a side, with its SHA-256. Pass saved: true to keep it in the library to reuse. Returns the image and, unless the organization already has this exact image, a private upload link: PUT the bytes there with their content type, then call documents.assets.confirm. Place a confirmed image in a template with a line ![Alt text](asset:<id>?width=50&align=center); width is 10–100 percent of the text width (default 100) and align is left, center or right (default center).

POST/api/v1/accounting/documents.assets.prepare

Permissions

accounting:readaccounting:write

Who can call it

admin, finance

Retries

Idempotency key required

MCP

accounting_documents_assets_prepare

Fields

  • filenamestringRequired

    The file's name, including its extension.

    1–200 characters

  • mimeTypeenumRequired

    The file's type, such as image/jpeg or application/pdf.

    image/pngimage/jpeg
  • sizeBytesintegerRequired

    The file's size in bytes.

    1 to 10485760

  • sha256stringRequired

    The SHA-256 hash of the file's exact bytes, as 64 lowercase hex characters.

    SHA-256 hash as 64 lowercase hex characters

  • titlestring

    A short title.

    at most 120 characters

  • savedboolean

    Default false

  • idempotencyKeystringRequired

    Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.

    8–200 characters

Example

curl https://app.getoatmilk.com/api/v1/accounting/documents.assets.prepare \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "filename": "receipt.png",
  "mimeType": "image/png",
  "sizeBytes": 1,
  "sha256": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8f0a2b4c"
}'
Response
{
  "data": { … }
}

Try it

Try it

Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.

POST/api/v1/accounting/documents.assets.prepare
curl https://app.getoatmilk.com/api/v1/accounting/documents.assets.prepare \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "filename": "receipt.png",
  "mimeType": "image/png",
  "sizeBytes": 1,
  "sha256": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8f0a2b4c"
}'

More in Documents and signing.