openapi: 3.2.0 info: title: Pipeshub Internal Storage API version: 1.0.0 contact: name: API Support email: support@pipeshub.com description: 'Operations tagged Internal Storage across 2 of this provider''s published API definitions: pipeshub-openapi.yaml, pipeshub-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL security: - bearerAuth: [] - oauth2: [] tags: - name: Internal Storage description: 'Service-to-service storage endpoints, authenticated with the storage scoped token rather than a signed-in user''s session, so these are **not** callable by API clients or the browser. Storage checks only the org, not record permissions; read and write files through the Knowledge Base routes (for example `GET /knowledgeBase/stream/record/{recordId}`).' paths: /document/internal/upload: post: tags: - Internal Storage summary: Upload a file (service-to-service) description: 'Store one file and create its document record. Mirrors `POST /document/upload`, but authenticated with the storage scoped token rather than a signed-in user.' operationId: internalUploadDocument security: - scopedToken: [] requestBody: description: The file to store. required: true content: multipart/form-data: schema: type: object required: - file properties: file: type: string format: binary description: The file to store. One file per request. responses: '200': description: The file was stored and its document record created. '400': description: The request was missing the file, or the file was rejected. '401': description: The storage scoped token was missing or invalid. '503': description: The file could not be saved. Safe to retry. servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /document/internal/placeholder: post: tags: - Internal Storage summary: Create a document record with no file yet (service-to-service) description: 'Create the document record that a direct upload will later fill. Mirrors `POST /document/placeholder`.' operationId: internalCreatePlaceholderDocument security: - scopedToken: [] requestBody: description: Where the file will live and what to call it. required: true content: application/json: schema: type: object required: - documentName - documentPath - extension properties: documentName: type: string alternateDocumentName: type: string documentPath: type: string extension: type: string permissions: type: string metaData: {} isVersionedFile: type: boolean customMetadata: type: array items: type: object required: - key - value properties: key: type: string value: {} responses: '200': description: The document record was created. '400': description: The request body was incomplete. '401': description: The storage scoped token was missing or invalid. servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /document/internal/{documentId}: get: tags: - Internal Storage summary: Read a document record (service-to-service) description: Mirrors `GET /document/{documentId}`. operationId: internalGetDocumentById security: - scopedToken: [] parameters: - $ref: '#/components/parameters/InternalDocumentId' responses: '200': description: The document record. '401': description: The storage scoped token was missing or invalid. '404': description: No such document. servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /document/internal/{documentId}/: delete: tags: - Internal Storage summary: Delete a document record (service-to-service) description: 'Mark the document deleted. Mirrors `DELETE /document/{documentId}/`. The stored file itself is handled by the caller.' operationId: internalDeleteDocumentById security: - scopedToken: [] parameters: - $ref: '#/components/parameters/InternalDocumentId' responses: '200': description: The document was marked deleted. '401': description: The storage scoped token was missing or invalid. '404': description: No such document. servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /document/internal/{documentId}/download: get: tags: - Internal Storage summary: Download a document (service-to-service) description: 'Returns a time-limited link for S3 or Azure, or the file itself for local storage. Mirrors `GET /document/{documentId}/download`.' operationId: internalDownloadDocument security: - scopedToken: [] parameters: - $ref: '#/components/parameters/InternalDocumentId' - name: version in: query required: false description: A past version to download. Defaults to the current one. schema: type: integer minimum: 0 - name: expirationTimeInSeconds in: query required: false description: How long the download link stays valid. schema: type: integer minimum: 1 responses: '200': description: A download link, or the file itself for local storage. '401': description: The storage scoped token was missing or invalid. '404': description: No such document, or no such version. servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /document/internal/{documentId}/buffer: get: tags: - Internal Storage summary: Read a document's bytes (service-to-service) description: Mirrors `GET /document/{documentId}/buffer`. operationId: internalGetDocumentBuffer security: - scopedToken: [] parameters: - $ref: '#/components/parameters/InternalDocumentId' - name: version in: query required: false description: A past version to read. Defaults to the current one. schema: type: integer minimum: 0 responses: '200': description: The document's bytes. content: application/octet-stream: schema: type: string format: binary '401': description: The storage scoped token was missing or invalid. '404': description: No such document, or no such version. put: tags: - Internal Storage summary: Replace a document's bytes (service-to-service) description: Mirrors `PUT /document/{documentId}/buffer`. operationId: internalUpdateDocumentBuffer security: - scopedToken: [] parameters: - $ref: '#/components/parameters/InternalDocumentId' requestBody: description: The bytes that replace the document's current contents. required: true content: multipart/form-data: schema: type: object properties: file: type: string format: binary responses: '200': description: The document's bytes were replaced. '401': description: The storage scoped token was missing or invalid. '404': description: No such document. '503': description: The file could not be saved. Safe to retry. servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /document/internal/{documentId}/uploadNextVersion: post: tags: - Internal Storage summary: Add a new version of a document (service-to-service) description: Mirrors `POST /document/{documentId}/uploadNextVersion`. operationId: internalUploadNextVersion security: - scopedToken: [] parameters: - $ref: '#/components/parameters/InternalDocumentId' requestBody: description: The new version's bytes, and optional notes for this and the previous version. required: true content: multipart/form-data: schema: type: object properties: file: type: string format: binary currentVersionNote: type: string nextVersionNote: type: string responses: '200': description: The new version was stored. '401': description: The storage scoped token was missing or invalid. '404': description: No such document. '503': description: The file could not be saved. Safe to retry. servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /document/internal/{documentId}/rollBack: post: tags: - Internal Storage summary: Roll a document back to an earlier version (service-to-service) description: Mirrors `POST /document/{documentId}/rollBack`. operationId: internalRollBackToPreviousVersion security: - scopedToken: [] parameters: - $ref: '#/components/parameters/InternalDocumentId' requestBody: description: The version to return to, and why. required: true content: application/json: schema: type: object required: - note properties: note: type: string description: Why the document was rolled back. version: type: integer minimum: 0 description: The version to return to. responses: '200': description: The document was rolled back. '400': description: The note was missing, or the version was not a whole number. '401': description: The storage scoped token was missing or invalid. '404': description: No such document, or no such version. servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /document/internal/{documentId}/directUpload: post: tags: - Internal Storage summary: Get a link to upload straight to storage (service-to-service) description: 'Returns a time-limited link the caller uses to send the file directly to S3 or Azure. Mirrors `POST /document/{documentId}/directUpload`.' operationId: internalDirectUpload security: - scopedToken: [] parameters: - $ref: '#/components/parameters/InternalDocumentId' responses: '200': description: A time-limited upload link. '401': description: The storage scoped token was missing or invalid. '404': description: No such document. '503': description: The upload link could not be issued. Safe to retry. servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /document/internal/{documentId}/isModified: get: tags: - Internal Storage summary: Has this document changed? (service-to-service) description: Mirrors `GET /document/{documentId}/isModified`. operationId: internalIsDocumentModified security: - scopedToken: [] parameters: - $ref: '#/components/parameters/InternalDocumentId' responses: '200': description: Whether the document has changed since it was stored. '401': description: The storage scoped token was missing or invalid. '404': description: No such document. servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL components: parameters: InternalDocumentId: name: documentId in: path required: true description: The document's id. schema: type: string securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: 'JWT Bearer token for authenticated requests. A personal access token (see the **Personal Access Tokens** tag) is a `phpat_`-prefixed variant of this same JWT — e.g. `phpat_eyJhbGci...`. The prefix is display-only, added for secret-scanner detectability; the gateway strips it before verifying the token, so send it exactly as issued, prefix included. ' scopedToken: type: http scheme: bearer bearerFormat: JWT description: 'Scoped JWT token for service-to-service authentication. Format: "Bearer {scoped_token}" Required scopes vary by endpoint. ' oauth2: type: oauth2 description: 'OAuth 2.0 authentication with fine-grained scopes. Supports authorization_code (with PKCE) and client_credentials flows. OAuth tokens are Bearer JWTs — use the same Authorization header as regular tokens. For **client_credentials**, machine JWTs may use `userId === client_id`; the Node gateway resolves the OAuth app creator — see **OAuth Provider** tag. ' flows: authorizationCode: authorizationUrl: /api/v1/oauth2/authorize tokenUrl: /api/v1/oauth2/token refreshUrl: /api/v1/oauth2/token scopes: openid: OpenID Connect authentication profile: User profile information email: User email address offline_access: Offline access (refresh tokens) org:read: Read organization information org:write: Update organization settings org:admin: Full organization administration user:read: Read user profiles user:write: Update user profiles user:invite: Invite new users user:delete: Delete users usergroup:read: Read user groups usergroup:write: Create and manage user groups team:read: Read team information team:write: Create and manage teams kb:read: Read knowledge bases and records kb:write: Create and update knowledge bases kb:delete: Delete knowledge bases and records kb:upload: Upload files to knowledge bases semantic:read: Read semantic search results and history semantic:write: Execute semantic search semantic:delete: Delete semantic search history conversation:read: Read conversations conversation:write: Create and manage conversations conversation:chat: Send messages in conversations project:read: Read projects and their conversations project:write: Create and manage projects project:delete: Delete projects agent:read: Read AI agents agent:write: Create and manage AI agents agent:execute: Execute AI agents connector:read: Read connector configurations connector:write: Create and update connectors connector:sync: Trigger connector synchronization connector:delete: Delete connectors config:read: Read system configuration config:write: Update system configuration crawl:read: Read crawling jobs crawl:write: Create and manage crawling jobs crawl:delete: Delete crawling jobs clientCredentials: tokenUrl: /api/v1/oauth2/token scopes: openid: OpenID Connect authentication profile: User profile information email: User email address offline_access: Offline access (refresh tokens) org:read: Read organization information org:write: Update organization settings org:admin: Full organization administration user:read: Read user profiles user:write: Update user profiles user:invite: Invite new users user:delete: Delete users usergroup:read: Read user groups usergroup:write: Create and manage user groups team:read: Read team information team:write: Create and manage teams kb:read: Read knowledge bases and records kb:write: Create and update knowledge bases kb:delete: Delete knowledge bases and records kb:upload: Upload files to knowledge bases semantic:write: Execute semantic search semantic:read: Read semantic search results and history semantic:delete: Delete semantic search history conversation:read: Read conversations conversation:write: Create and manage conversations conversation:chat: Send messages in conversations project:read: Read projects and their conversations project:write: Create and manage projects project:delete: Delete projects agent:read: Read AI agents agent:write: Create and manage AI agents agent:execute: Execute AI agents connector:read: Read connector configurations connector:write: Create and update connectors connector:sync: Trigger connector synchronization connector:delete: Delete connectors config:read: Read system configuration config:write: Update system configuration crawl:read: Read crawling jobs crawl:write: Create and manage crawling jobs x-refined-from: - pipeshub-openapi.yaml - pipeshub-openapi.yml