> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lala.ist/llms.txt
> Use this file to discover all available pages before exploring further.

# Start an upload

> Reserves a media id and returns a signed URL for the bytes. Upload in three steps:

1. `POST /api/media` with the mime type. You get back a `Media` and an `upload`.
2. `PUT` the raw bytes to `upload.url`. No `Authorization` header — the URL is signed.
3. Send the message with the media id in `mediaIds`.

The media stays `pending` until the bytes are in storage. `POST /api/chat/send`
confirms them for you, so step 3 needs no extra call. Pending media that is never
uploaded is dropped from the message instead of failing the send.

`upload.url` expires in 15 minutes. Start again if it does.



## OpenAPI

````yaml /api-reference/openapi.json post /api/media
openapi: 3.1.0
info:
  title: Lala Client API
  description: >-
    The HTTP API behind Lala, the AI study companion for Turkish YKS and LGS
    students. This document is generated from the Zod schemas that validate each
    request at runtime. Do not hand-edit openapi.json. Student-visible text is
    Turkish. All identifiers are English.
  version: 1.0.0
servers:
  - url: https://client-api.lala.ist
    description: production
  - url: http://localhost:3000
    description: local dev
security:
  - supabaseJwt: []
tags:
  - name: chat
    description: The chat stream, the message history, and reactions
  - name: media
    description: Upload and read message attachments
  - name: plan
    description: The study planner — blocks of work on a day
  - name: journey
    description: Deneme results, topic performance, study-hours stats, and the streak
  - name: profile
    description: The student profile and onboarding
  - name: devices
    description: Push notification devices
  - name: system
    description: Health check
paths:
  /api/media:
    post:
      tags:
        - media
      summary: Start an upload
      description: >-
        Reserves a media id and returns a signed URL for the bytes. Upload in
        three steps:


        1. `POST /api/media` with the mime type. You get back a `Media` and an
        `upload`.

        2. `PUT` the raw bytes to `upload.url`. No `Authorization` header — the
        URL is signed.

        3. Send the message with the media id in `mediaIds`.


        The media stays `pending` until the bytes are in storage. `POST
        /api/chat/send`

        confirms them for you, so step 3 needs no extra call. Pending media that
        is never

        uploaded is dropped from the message instead of failing the send.


        `upload.url` expires in 15 minutes. Start again if it does.
      operationId: postApiMedia
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MediaCreateBody'
      responses:
        '200':
          description: The media row and where to put the bytes
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MediaCreateResponse'
        '400':
          description: The media is larger than the limit
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: The token is missing, expired, or invalid
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '503':
          description: Media storage is not configured
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
components:
  schemas:
    MediaCreateBody:
      type: object
      properties:
        mimeType:
          type: string
          minLength: 1
          maxLength: 255
        sizeBytes:
          type: integer
          minimum: 1
          maximum: 9007199254740991
        width:
          type: integer
          minimum: 1
          maximum: 9007199254740991
        height:
          type: integer
          minimum: 1
          maximum: 9007199254740991
        durationMs:
          type: integer
          minimum: 0
          maximum: 9007199254740991
        fileName:
          type: string
          maxLength: 255
      required:
        - mimeType
    MediaCreateResponse:
      type: object
      properties:
        media:
          $ref: '#/components/schemas/Media'
        upload:
          $ref: '#/components/schemas/MediaUpload'
      required:
        - media
        - upload
    ErrorResponse:
      type: object
      properties:
        error:
          type: string
        issues:
          description: >-
            Present only on a 400 raised by request validation, capped at 10
            entries. Every other error carries `error` alone.
          type: array
          items:
            $ref: '#/components/schemas/ValidationIssue'
      required:
        - error
      description: Error body. `error` is a short English string.
    Media:
      type: object
      properties:
        id:
          type: string
          format: uuid
          pattern: >-
            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
        kind:
          $ref: '#/components/schemas/MediaKind'
        mimeType:
          type: string
        sizeBytes:
          anyOf:
            - type: integer
              minimum: -9007199254740991
              maximum: 9007199254740991
            - type: 'null'
        width:
          anyOf:
            - type: integer
              minimum: -9007199254740991
              maximum: 9007199254740991
            - type: 'null'
        height:
          anyOf:
            - type: integer
              minimum: -9007199254740991
              maximum: 9007199254740991
            - type: 'null'
        durationMs:
          anyOf:
            - type: integer
              minimum: -9007199254740991
              maximum: 9007199254740991
            - type: 'null'
        fileName:
          anyOf:
            - type: string
            - type: 'null'
        status:
          type: string
          enum:
            - pending
            - ready
          description: '`ready` when the bytes are in storage. Only ready media can be sent.'
        url:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Short-lived signed URL, null while the media is pending. It expires
            — read the media or the message again for a new one. Do not cache
            it.
        urlExpiresAt:
          anyOf:
            - type: string
              format: date-time
              pattern: >-
                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
            - type: 'null'
        createdAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
      required:
        - id
        - kind
        - mimeType
        - sizeBytes
        - width
        - height
        - durationMs
        - fileName
        - status
        - url
        - urlExpiresAt
        - createdAt
    MediaUpload:
      type: object
      properties:
        url:
          type: string
          description: Absolute URL. Send the raw bytes here.
        method:
          type: string
          const: PUT
        expiresAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
      required:
        - url
        - method
        - expiresAt
    ValidationIssue:
      type: object
      properties:
        path:
          type: string
          description: Dotted path to the offending field, empty at the root.
        message:
          type: string
      required:
        - path
        - message
    MediaKind:
      type: string
      enum:
        - image
        - audio
        - video
        - file
  securitySchemes:
    supabaseJwt:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'Supabase access token: `Authorization: Bearer <token>`'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.