EvidenceUpload evidence attachments

Upload evidence attachments

Uploads one or more files to an evidence record. Maximum 5 files per request. Combined size must not exceed 100 MB. evidenceDate is Unix epoch milliseconds and cannot be in the future. Idempotency-Key is required. The same key and payload replays the stored 2xx for 24 hours. Requires scope evidence:write.

One or more files in a supported format. See Supported file types in this operation description. Use the multipart field files for every attachment (same field name for each file, up to 5 per request). Example: -F "files=@access-review.pdf" -F "files=@appendix.pdf".

Example request (cURL)

For file uploads, copy this command (includes -F "files=@…"). The auto-generated cURL tab may show a text placeholder for files until you choose a file in the playground.

curl -X POST "https://api.scrut.io/v1/evidence/92af7e7f-b18e-495b-bf92-61c23ebd34a7/attachments" \
  -H "Authorization: Bearer $SCRUT_ACCESS_TOKEN" \
  -H "Idempotency-Key: 7c9e6679-7425-40de-944b-e07fc1f90ae7" \
  -F "evidenceDate=1715904000000" \
  -F "note=Q2 access review — identity verification records" \
  -F "files=@access-review.pdf"

Supported file types

Same list as Upload Evidence — Supported File Types.

TypeExtensions
PDF.pdf
Word.doc, .docx, .dotx
Excel.xls, .xlsx, .xlsm
PowerPoint.ppt, .pptx
Text.txt, .log, .html
Markdown.md
YAML.yaml, .yml
CSV.csv
JSON.json
XML.xml
ImagesAny image type, such as PNG, JPG, GIF, SVG
Video.mp4, .avi
Audio.mp3, .wav
Archives.zip, .rar
Apple iWork.numbers, .pages
Email.eml, .msg
Other.dwf, .evtx

Note: Scrut accepts Apple iWork files (.numbers, .pages) only when it detects them as zip packages. If Scrut rejects an iWork file, export it to PDF, Excel, or Word and upload it again.

curl -X POST "https://api.scrut.io/v1/evidence/92af7e7f-b18e-495b-bf92-61c23ebd34a7/attachments" \
  -H "Idempotency-Key: 7c9e6679-7425-40de-944b-e07fc1f90ae7" \
  -H "Authorization: Bearer YOUR_API_TOKEN (JWT)" \
  --form evidenceDate=1715904000000 \
  --form note=Q2 access review — identity verification records \
  --form files=@access-review.pdf
{
  "data": {
    "evidenceId": "92af7e7f-b18e-495b-bf92-61c23ebd34a7",
    "modifiedOn": 1711929600000
  },
  "meta": {
    "requestId": "550e8400-e29b-41d4-a716-446655440000"
  }
}
POST
/v1/evidence/{evidenceId}/attachments
POST
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token (JWT)
Bearer Tokenstring
Required

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
path
evidenceIdstring
Required

Evidence identifier returned by list and get endpoints.

Content-Typestring
Required

The media type of the request body

Options: multipart/form-data
header
Idempotency-Keystring
Required

Client-generated key identifying one logical write. 1–128 characters; letters, numbers, and . _ ~ - only. Reuse the same key and body to retry safely. Reusing a key with a different body returns 409 idempotency_key_reused. Successful 2xx responses are replayed for 24 hours.

Min length: 1 • Max length: 128 • Pattern: ^[A-Za-z0-9._~-]{1,128}$
evidenceDatestring
Required

Unix epoch milliseconds (number or numeric string). Must not be in the future.

notestring

Optional note stored with the upload.

filesfile
Required
Format: binary
Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Path Parameters

evidenceIdstring
Required

Evidence identifier returned by list and get endpoints.

Example:
92af7e7f-b18e-495b-bf92-61c23ebd34a7

Headers

Idempotency-Keystring
Required

Client-generated key identifying one logical write. 1–128 characters; letters, numbers, and . _ ~ - only. Reuse the same key and body to retry safely. Reusing a key with a different body returns 409 idempotency_key_reused. Successful 2xx responses are replayed for 24 hours.

Example:
7c9e6679-7425-40de-944b-e07fc1f90ae7

Body

multipart/form-data
evidenceDatestring
Required

Unix epoch milliseconds (number or numeric string). Must not be in the future.

Example:
1715904000000
notestring

Optional note stored with the upload.

Example:
Q2 access review — identity verification records
filesfile
Required
Example:
@access-review.pdf

Responses