# Upload a file

Uploads a file that can be used as supporting documentation for cases.
All files are scanned for malware before being accepted.

Endpoint: POST /cases/files
Version: 2026Q4
Security: ClientCredentialsToken

## Security:

  - `ClientCredentialsToken` (unknown)
    http bearer JWT

## Header parameters:

  - `X-External-Correlation-Id` (string)
    Optional UUID for correlating requests across systems. If provided, Wise echoes it back in the response. Maximum 36 characters. [Learn more](/guides/developer/headers/correlation-id).

## Request fields (multipart/form-data):

  - `file` (string, required)
    The file to upload. Do not include personally identifying information in the file name. Must be one of the supported content types
(`application/pdf`, `image/jpeg`, `image/png`) and must not exceed 15 MB.
File name must not exceed 128 characters and the file extension must match the content type
(e.g. `.pdf` for `application/pdf`).

  - `submissionData` (object, required)
    Metadata for the file upload, sent as the `submissionData` part of the multipart request.
    Example: {"profileId":14556049,"purpose":"GENERAL"}

  - `submissionData.profileId` (integer, required)
    The ID of the profile you are providing the file for. If you are set up only with your own profile and do not have them for end customers you must use your own profileId.
    Example: 14556049

  - `submissionData.purpose` (string, required)
    The purpose of the file upload.
    Enum: "GENERAL"

## Response 201:

  - `201` (unknown)
    File uploaded successfully

## Response 201 fields (application/json):

  - `profileId` (integer, required)
    The ID of the profile this file belongs to.
    Example: 14556049

  - `fileId` (string, required)
    Unique identifier of the uploaded file (UUID v4).
    Example: a1b2c3d4-e5f6-7890-abcd-ef1234567890

  - `fileName` (string, required)
    The original name of the uploaded file.
    Example: company-registration.pdf

## Response 201 headers (application/json):

  - `X-External-Correlation-Id` (string)
    Echoed back when `X-External-Correlation-Id` was included in the request. [Learn more](/guides/developer/headers/correlation-id).
    Example: f47ac10b-58cc-4372-a567-0e02b2c3d479

  - `x-trace-id` (string)
    Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.
    Example: fba501b6d453b96789f52338f019341f

## Response 400:

  - `400` (unknown)
    Bad request - validation failed

## Response 400 fields (application/json):

  - `type` (any, required)
    Example: /errors/types/validation

  - `title` (any, required)
    Example: Validation Error

  - `status` (any, required)
    Example: 400

  - `detail` (string)
    A human-readable explanation specific to this occurrence of the error.
    Example: Unauthorized

  - `instance` (any)
    Example: /cases/files

  - `code` (string)
    A machine-readable error code for domain errors.
    Example: forbidden

  - `errors` (array)
    List of field-level validation errors.

  - `errors.code` (string, required)
    Machine-readable validation error code.
Possible codes:
- `parameter_missing` - A required parameter was not provided
- `parameter_invalid` - A parameter value is invalid
- `invalid_file_extension` - File type or extension is not allowed
- `file_size_exceeds_max_limit` - File exceeds the maximum allowed size
    Example: parameter_invalid

  - `errors.ref` (string, required)
    The field that caused the validation error.
    Example: purpose

  - `errors.detail` (string, required)
    A human-readable description of the validation failure.
    Example: Invalid purpose

## Response 400 headers (application/json):

  - `X-External-Correlation-Id` (string)
    Echoed back when `X-External-Correlation-Id` was included in the request. [Learn more](/guides/developer/headers/correlation-id).
    Example: f47ac10b-58cc-4372-a567-0e02b2c3d479

  - `x-trace-id` (string)
    Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.
    Example: fba501b6d453b96789f52338f019341f

## Response 401:

  - `401` (unknown)
    Unauthorized - missing or invalid authentication

## Response 401 fields (application/json):

  - `type` (any, required)
    Example: /errors/types/access

  - `title` (any, required)
    Example: Unauthorized

  - `status` (any, required)
    Example: 401

  - `detail` (string)
    A human-readable explanation specific to this occurrence of the error.
    Example: Unauthorized

  - `instance` (string)
    The request path that caused the error.
    Example: /cases/files

  - `code` (string)
    A machine-readable error code for domain errors.
    Example: forbidden

## Response 401 headers (application/json):

  - `X-External-Correlation-Id` (string)
    Echoed back when `X-External-Correlation-Id` was included in the request. [Learn more](/guides/developer/headers/correlation-id).
    Example: f47ac10b-58cc-4372-a567-0e02b2c3d479

  - `x-trace-id` (string)
    Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.
    Example: fba501b6d453b96789f52338f019341f

## Response 403:

  - `403` (unknown)
    Forbidden - insufficient permissions

## Response 403 fields (application/json):

  - `type` (any, required)
    Example: /errors/types/access

  - `title` (any, required)
    Example: Forbidden

  - `status` (any, required)
    Example: 403

  - `detail` (string)
    A human-readable explanation specific to this occurrence of the error.
    Example: Unauthorized

  - `instance` (string)
    The request path that caused the error.
    Example: /cases/files

  - `code` (any)
    Example: forbidden

## Response 403 headers (application/json):

  - `X-External-Correlation-Id` (string)
    Echoed back when `X-External-Correlation-Id` was included in the request. [Learn more](/guides/developer/headers/correlation-id).
    Example: f47ac10b-58cc-4372-a567-0e02b2c3d479

  - `x-trace-id` (string)
    Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.
    Example: fba501b6d453b96789f52338f019341f

## Response 429:

  - `429` (unknown)
    Too many requests - rate limit exceeded

## Response 429 fields (application/json):

  - `type` (any, required)
    Example: /errors/types/domain

  - `title` (any, required)
    Example: Too Many Requests

  - `status` (any, required)
    Example: 429

  - `detail` (string)
    A human-readable explanation specific to this occurrence of the error.
    Example: Unauthorized

  - `instance` (string)
    The request path that caused the error.
    Example: /cases/files

  - `code` (any)
    Example: rate_limit_exceeded

## Response 429 headers (application/json):

  - `X-External-Correlation-Id` (string)
    Echoed back when `X-External-Correlation-Id` was included in the request. [Learn more](/guides/developer/headers/correlation-id).
    Example: f47ac10b-58cc-4372-a567-0e02b2c3d479

  - `x-trace-id` (string)
    Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.
    Example: fba501b6d453b96789f52338f019341f

## Response 500:

  - `500` (unknown)
    Internal server error

## Response 500 fields (application/json):

  - `type` (string, required)
    A URI reference that identifies the error type.
Common types:
- `/errors/types/validation` - Request validation failed
- `/errors/types/access` - Authentication or authorization error
- `/errors/types/domain` - Domain-specific business rule violation
    Example: /errors/types/validation

  - `title` (string, required)
    A short, human-readable summary of the error type.
    Example: Validation Error

  - `status` (integer, required)
    The HTTP status code.
    Example: 400

  - `detail` (string)
    A human-readable explanation specific to this occurrence of the error.
    Example: Unauthorized

  - `instance` (string)
    The request path that caused the error.
    Example: /cases/files

  - `code` (string)
    A machine-readable error code for domain errors.
    Example: forbidden

## Response 500 headers (application/json):

  - `X-External-Correlation-Id` (string)
    Echoed back when `X-External-Correlation-Id` was included in the request. [Learn more](/guides/developer/headers/correlation-id).
    Example: f47ac10b-58cc-4372-a567-0e02b2c3d479

  - `x-trace-id` (string)
    Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.
    Example: fba501b6d453b96789f52338f019341f

## Response 201 examples:

  - `PDF file uploaded` (unknown)

  - `PNG image uploaded` (unknown)

  - `JPEG image uploaded` (unknown)

## Response 400 examples:

  - `Missing profileId` (unknown)

  - `Missing purpose` (unknown)

  - `Invalid purpose value` (unknown)

  - `File is empty` (unknown)

  - `File name is missing` (unknown)

  - `File name exceeds 128 characters` (unknown)

  - `File exceeds 15 MB size limit` (unknown)

  - `File content type is missing` (unknown)

  - `File content type not allowed` (unknown)

  - `File name has no valid extension` (unknown)

  - `File extension does not match content type` (unknown)

  - `You do not own this profile` (unknown)

  - `File failed security scan` (unknown)

