openapi: 3.2.0 info: title: Taskfolk Attachments API version: 1.0.0 description: Public REST API for Taskfolk (taskfolk.ai). All endpoints require a workspace-scoped bearer API key. Paths are nested under `/v1/workspaces/{slug}/…`. servers: - url: https://taskfolk.ai/api security: - bearerAuth: [] tags: - name: Attachments paths: /v1/workspaces/{slug}/projects/{key}/issues/{issueKey}/attachments: get: summary: List attachments. tags: - Attachments security: - bearerAuth: - attachments:read parameters: - schema: type: string example: taskfolk description: Workspace slug. required: true description: Workspace slug. name: slug in: path - schema: type: string example: web description: Project key. required: true description: Project key. name: key in: path - schema: type: string example: WEB-39 description: Issue key (KEY-N). required: true description: Issue key (KEY-N). name: issueKey in: path - schema: type: string required: false name: cursor in: query - schema: type: - integer - 'null' required: false name: limit in: query responses: '200': description: Success. content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/Attachment' pagination: $ref: '#/components/schemas/Pagination' required: - data - pagination '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '401': description: Missing / invalid API key. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '403': description: Key lacks the required scope. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '404': description: Resource not found (or cross-workspace — never leaked). content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '429': description: Rate limited. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' post: summary: Create a pre-signed upload intent. tags: - Attachments security: - bearerAuth: - attachments:write parameters: - schema: type: string example: taskfolk description: Workspace slug. required: true description: Workspace slug. name: slug in: path - schema: type: string example: web description: Project key. required: true description: Project key. name: key in: path - schema: type: string example: WEB-39 description: Issue key (KEY-N). required: true description: Issue key (KEY-N). name: issueKey in: path requestBody: content: application/json: schema: $ref: '#/components/schemas/AttachmentIntentInput' responses: '201': description: Success. content: application/json: schema: type: object properties: data: $ref: '#/components/schemas/UploadIntent' required: - data '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '401': description: Missing / invalid API key. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '403': description: Key lacks the required scope. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '404': description: Resource not found (or cross-workspace — never leaked). content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '429': description: Rate limited. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' /v1/workspaces/{slug}/projects/{key}/issues/{issueKey}/attachments/commit: post: summary: Finalize an upload after the R2 PUT. tags: - Attachments security: - bearerAuth: - attachments:write parameters: - schema: type: string example: taskfolk description: Workspace slug. required: true description: Workspace slug. name: slug in: path - schema: type: string example: web description: Project key. required: true description: Project key. name: key in: path - schema: type: string example: WEB-39 description: Issue key (KEY-N). required: true description: Issue key (KEY-N). name: issueKey in: path requestBody: content: application/json: schema: $ref: '#/components/schemas/AttachmentCommitInput' responses: '201': description: Success. content: application/json: schema: type: object properties: data: $ref: '#/components/schemas/Attachment' required: - data '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '401': description: Missing / invalid API key. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '403': description: Key lacks the required scope. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '404': description: Resource not found (or cross-workspace — never leaked). content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '429': description: Rate limited. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' /v1/workspaces/{slug}/projects/{key}/issues/{issueKey}/attachments/{id}: delete: summary: Delete an attachment. tags: - Attachments security: - bearerAuth: - attachments:write parameters: - schema: type: string example: taskfolk description: Workspace slug. required: true description: Workspace slug. name: slug in: path - schema: type: string example: web description: Project key. required: true description: Project key. name: key in: path - schema: type: string example: WEB-39 description: Issue key (KEY-N). required: true description: Issue key (KEY-N). name: issueKey in: path - schema: type: string example: 019e6f12-… required: true name: id in: path responses: '200': description: Success. content: application/json: schema: type: object properties: data: type: object properties: id: type: string deleted: type: boolean enum: - true required: - id - deleted required: - data '400': description: Validation error. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '401': description: Missing / invalid API key. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '403': description: Key lacks the required scope. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '404': description: Resource not found (or cross-workspace — never leaked). content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' '429': description: Rate limited. content: application/json: schema: $ref: '#/components/schemas/ErrorEnvelope' components: schemas: Pagination: type: object properties: next_cursor: type: - string - 'null' example: null required: - next_cursor AttachmentCommitInput: type: object properties: r2_key: type: string description: The exact r2_key returned by the intent call. file_name: type: string mime: type: string byte_size: type: integer comment_id: type: string required: - r2_key - file_name - mime - byte_size AttachmentIntentInput: type: object properties: file_name: type: string mime: type: string byte_size: type: integer comment_id: type: string required: - file_name - mime - byte_size UploadIntent: type: object properties: r2_key: type: string url: type: string description: Pre-signed R2 PUT URL. relay_url: type: string description: Same-origin fallback PUT path for networks that block the storage domain. PUT the same bytes here if the direct URL is unreachable. headers: type: object additionalProperties: type: string expires_at: type: string format: date-time example: '2026-05-28T14:30:00Z' required: - r2_key - url - relay_url - headers - expires_at ErrorEnvelope: type: object properties: error: type: object properties: code: type: string enum: - unauthorized - forbidden - not_found - validation - rate_limited - conflict - idempotency_violation - internal_error example: validation message: type: string example: Label "foo" does not exist on this project. details: type: object additionalProperties: {} required: - code - message required: - error Attachment: type: object properties: id: type: string issue_id: type: string comment_id: type: - string - 'null' file_name: type: string mime: type: string byte_size: type: integer uploader_id: type: string url: type: - string - 'null' created_at: type: string format: date-time example: '2026-05-28T14:30:00Z' required: - id - issue_id - comment_id - file_name - mime - byte_size - uploader_id - url - created_at securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: API key description: 'Workspace API key. Send as `Authorization: Bearer tfk_live_…`. Each key is bound to exactly one workspace and carries a set of scopes.'