Endpoint
Authentication
This endpoint requires an OAuth access token. Send it as a bearer token:tasks:write
The document is uploaded as the access token’s user. The
user_email field on the request body is
ignored.Path Parameters
Request Body
The request body must be a JSON object with the following fields:Required Fields
File Object Fields
Request Example
Response
Success Response
Status Code:200 OK
Response Fields
Error Responses
400 Bad Request
Returned when the access token has no user behind it.client_credentials tokens act as the admin who created the application, so this applies only to
tokens issued before application creators were recorded.
401 Unauthorized
Returned when the access token is missing, unknown, revoked, or expired, or when anX-API-Key was
sent instead of a bearer token. See OAuth error responses.
403 Forbidden
Returned when the token lacks the required scope:404 Not Found
Returned when the task does not exist.409 Conflict
Returned when the task is not at a signature step or the document cannot be attached in the current state.422 Validation Error
Returned when the request body is invalid.429 Too Many Requests
Returned when your organization exceeds its per-minute request limit.500 Internal Server Error
Returned when the upload fails due to a server error.Notes
Use this endpoint when a document is signed outside Chamelio (for example, a manually signed PDF) and
you need to attach the executed copy to the signature step.
Use Cases
This endpoint is useful for:- Manual signing flows - Attach wet-signed or externally signed documents to a task
- Third-party signature providers - Record the executed document from a provider not integrated with Chamelio
- Audit completeness - Ensure the final signed copy is stored against the workflow step, attributed to the person who uploaded it