> ## Documentation Index
> Fetch the complete documentation index at: https://docs.energy.nayax.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Request an upload URL for a comment attachment

> Returns a presigned POST policy for uploading one attachment (max 25MB) directly to storage. POST the file to the returned url with the returned fields, then reference the storageKey when adding the comment.



## OpenAPI

````yaml /api/specs/incident-management-api.json post /incident-management/v1/incidents/{id}/comments/upload-url
openapi: 3.0.0
info:
  title: Lynkwell API
  version: 1.377.0
  description: API Documentation for the Incident Management Service
servers:
  - url: https://api.lynkwell.com
security: []
tags: []
paths:
  /incident-management/v1/incidents/{id}/comments/upload-url:
    post:
      tags:
        - Incidents
      summary: Request an upload URL for a comment attachment
      description: >-
        Returns a presigned POST policy for uploading one attachment (max 25MB)
        directly to storage. POST the file to the returned url with the returned
        fields, then reference the storageKey when adding the comment.
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UploadUrlParams'
      responses:
        '200':
          description: A presigned upload policy.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/IncidentUploadUrl'
        '400':
          description: Bad Request (e.g. an unsupported content type)
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IncidentBadRequestError'
        '401':
          description: Missing or invalid token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IncidentUnauthorizedError'
        '403':
          description: Insufficient scope. The body is a plain-text message, not JSON.
          content:
            text/plain:
              schema:
                type: string
        '404':
          description: Incident not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IncidentNotFoundError'
        '409':
          description: The incident was merged away
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IncidentConflictError'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IncidentInternalServerError'
      security:
        - oauth2:
            - write:incident
components:
  schemas:
    UploadUrlParams:
      type: object
      description: Request a presigned upload for a comment attachment.
      properties:
        filename:
          type: string
        contentType:
          type: string
          description: >-
            One of: image/png, image/jpeg, image/heic, image/webp,
            application/pdf, text/plain, text/csv.
        networkId:
          type: string
          description: >-
            Network id. Required for machine (M2M) callers whose token carries
            no network claim; ignored when the token has one.
      required:
        - filename
        - contentType
    IncidentUploadUrl:
      type: object
      description: >-
        A presigned POST policy for uploading a comment attachment directly to
        storage.
      properties:
        url:
          type: string
          description: The URL to POST the multipart form to.
        fields:
          type: object
          description: Form fields that must be included in the multipart POST, verbatim.
          additionalProperties:
            type: string
        storageKey:
          type: string
          description: >-
            Reference this key as the attachment storageKey when posting the
            comment.
        expiresAt:
          type: string
          format: date-time
      required:
        - url
        - fields
        - storageKey
        - expiresAt
    IncidentBadRequestError:
      type: object
      description: The response body for a 400 request.
      properties:
        type:
          type: string
          enum:
            - BAD_REQUEST
        code:
          type: string
          description: >-
            A stable machine-readable error code identifying the specific
            validation failure.
        message:
          type: string
      required:
        - type
        - code
        - message
    IncidentUnauthorizedError:
      type: object
      description: The response body for a 401 request (missing or invalid token).
      properties:
        message:
          type: string
      required:
        - message
    IncidentNotFoundError:
      type: object
      description: The response body for a 404 request.
      properties:
        type:
          type: string
          enum:
            - NOT_FOUND
        code:
          type: string
        message:
          type: string
      required:
        - type
        - code
        - message
    IncidentConflictError:
      type: object
      description: >-
        The response body for a 409 request. Some conflicts carry an extra id
        field naming the conflicting resource.
      properties:
        type:
          type: string
          enum:
            - CONFLICT
        code:
          type: string
        message:
          type: string
      required:
        - type
        - code
        - message
    IncidentInternalServerError:
      type: object
      description: The response body for a 500 request.
      properties:
        type:
          type: string
          enum:
            - INTERNAL_ERROR
        message:
          type: string
      required:
        - type
        - message
  securitySchemes:
    oauth2:
      type: oauth2
      description: OAuth2 Client Credentials Flow
      flows:
        clientCredentials:
          tokenUrl: https://lynkwell-prod.us.auth0.com/oauth/token
          scopes:
            read:asset: Retrieve assets
            write:asset: Create and update assets
            read:assetgroup: Retrieve asset groups
            write:assetgroup: Create and update asset groups
            read:assetstatus: Retrieve asset statuses
            read:chargingstationmodel: Retrieve charging station models
            write:chargingstationmodel: Create and update charging station models
            write:network: Create and update networks
            write:sitepartner: Create and update site partners
            read:sitepartner: Retrieve site partners
            write:sitepartneruser: Create and update site partner users
            read:sitepartneruser: Retrieve site partner users
            read:networkaccessprofile: Retrieve network access profiles
            write:paymentprofile: Create payment profile
            write:onboardinglink: Create an onboarding link
            read:invoice: Retrieve an invoice
            write:session: Create or update a session
            read:session: Retrieve a session
            write:ticket: Create a ticket
            write:verificationcode: Send and confirm verification codes
            write:driver: Create and update drivers
            read:driver: Retrieve drivers
            write:token: Create and update tokens
            read:token: Retrieve tokens
            read:tokenvalue: Retrieve token by ID including its value
            write:invitecode: Create and update invite codes
            write:invitation: Create and update invitations
            read:invitation: Retrieve invitations
            read:payment_terminals_payment: Read payments from payment terminal
            abort:session: Abruptly end session
            read:paymentprofile: Retrieve payment profile from payment terminal
            write:ocpp: Sends request over OCPP
            write:ocpp.raw_request: Sends raw request over OCPP
            write:notification.email: Create and update email
            read:invoiceitem: Retrieve invoice item
            read:subscription: Retrieve subscription
            write:plugandcharge_enrollment: Update Plug and Charge enrollment status
            write:projects: Create and update projects
            read:projects: Retrieve projects
            write:project_stations: Create and update project stations
            write:panel: Create and update panels.
            read:panel: Retrieve panels.
            write:webhooks: Create, update, and delete webhooks
            read:webhooks: Retrieve webhooks
            read:incident: Retrieve incidents and their sub-resources
            write:incident: Create, update, comment on, merge, split, and link incidents

````