curl --request POST \
--url https://app.sahlfinancial.com/api/v1/documents \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: multipart/form-data' \
--form file=@example-file \
--form 'document_type_hint=<string>' \
--form 'external_reference=<string>' \
--form 'ocr_language=<string>' \
--form case_id=3c90c3cc-0d44-4b50-8888-8dd25736052aconst form = new FormData();
form.append('file', '<string>');
form.append('document_type_hint', '<string>');
form.append('external_reference', '<string>');
form.append('ocr_language', '<string>');
form.append('case_id', '3c90c3cc-0d44-4b50-8888-8dd25736052a');
const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
options.body = form;
fetch('https://app.sahlfinancial.com/api/v1/documents', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.sahlfinancial.com/api/v1/documents"
files = { "file": ("example-file", open("example-file", "rb")) }
payload = {
"document_type_hint": "<string>",
"external_reference": "<string>",
"ocr_language": "<string>",
"case_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, data=payload, files=files, headers=headers)
print(response.text){
"document_id": "a8f1c3e5-6b2d-4974-8e0a-1d5c7b9f3e26",
"job_id": "3c9d7b1f-5e2a-4a86-9f4c-8b0e6d2a1c75",
"status": "queued",
"message": "Document accepted for processing"
}{
"detail": "Unsupported file type 'text/plain'. Allowed types: application/pdf, image/jpeg, image/png, image/tiff, image/webp"
}{
"detail": "Invalid or expired token"
}{
"detail": "Insufficient permissions"
}{
"detail": "Case not found"
}{
"detail": "File too large. Maximum allowed size is 30 MB."
}{
"detail": [
{
"type": "missing",
"loc": [
"body",
"bank_code"
],
"msg": "Field required",
"input": {}
}
]
}{
"code": "rate_limit_exceeded",
"message": "Too many requests. Please slow down."
}Upload a document
Who can call it: tenant_admin, tenant_reviewer, tenant_api_manager or platform_admin. A tenant_viewer is read-only and gets 403.
multipart/form-data. Processing is asynchronous: poll GET /v1/documents/{document_id}/status, or subscribe to the document.completed webhook. Send X-Sahl-Environment: sandbox or production (or the environment query parameter) to choose the workspace. Without it, no environment filter is applied. production is refused with 403 production_requires_paid_plan when the subscription is cancelled or suspended. Needs a verified email when the workspace requires it.
Auth: dashboard session (Authorization: Bearer <access token>). Not available with a partner API key.
curl --request POST \
--url https://app.sahlfinancial.com/api/v1/documents \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: multipart/form-data' \
--form file=@example-file \
--form 'document_type_hint=<string>' \
--form 'external_reference=<string>' \
--form 'ocr_language=<string>' \
--form case_id=3c90c3cc-0d44-4b50-8888-8dd25736052aconst form = new FormData();
form.append('file', '<string>');
form.append('document_type_hint', '<string>');
form.append('external_reference', '<string>');
form.append('ocr_language', '<string>');
form.append('case_id', '3c90c3cc-0d44-4b50-8888-8dd25736052a');
const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
options.body = form;
fetch('https://app.sahlfinancial.com/api/v1/documents', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.sahlfinancial.com/api/v1/documents"
files = { "file": ("example-file", open("example-file", "rb")) }
payload = {
"document_type_hint": "<string>",
"external_reference": "<string>",
"ocr_language": "<string>",
"case_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, data=payload, files=files, headers=headers)
print(response.text){
"document_id": "a8f1c3e5-6b2d-4974-8e0a-1d5c7b9f3e26",
"job_id": "3c9d7b1f-5e2a-4a86-9f4c-8b0e6d2a1c75",
"status": "queued",
"message": "Document accepted for processing"
}{
"detail": "Unsupported file type 'text/plain'. Allowed types: application/pdf, image/jpeg, image/png, image/tiff, image/webp"
}{
"detail": "Invalid or expired token"
}{
"detail": "Insufficient permissions"
}{
"detail": "Case not found"
}{
"detail": "File too large. Maximum allowed size is 30 MB."
}{
"detail": [
{
"type": "missing",
"loc": [
"body",
"bank_code"
],
"msg": "Field required",
"input": {}
}
]
}{
"code": "rate_limit_exceeded",
"message": "Too many requests. Please slow down."
}Authorizations
The access token (JWT) of a signed-in console user, from POST /v1/auth/login. It lasts 30 minutes. It is not an API key: a partner API key is refused here. There is no cookie.