Workspace media
Upload inputs, inspect the library, and download generated files.
Upload an input file
Use the selected workspace's media library as the source of file inputs. Upload the file first with the media:write scope:
curl --fail-with-body 'https://api.ndnci.com/v1/media/upload' \
-H "Authorization: Bearer $NDNCI_KEY" \
-H "X-Ndnci-Workspace: $NDNCI_WORKSPACE" \
-F 'file=@./sample.png'The backend applies the same content, MIME, size and storage quota checks as the workspace library. A successful response returns the media UUID and its metadata.
Use that UUID in the discovered Tool operation's public media fields, such as referenceMediaIds. Each reference must still be visible within the selected workspace. Raw filesystem paths and provider upload objects are not valid public inputs.
For a small MCP upload, call ndnci_media_upload with workspaceId, name,
mimeType, and dataBase64. The encoded content is bounded at 60,000 characters
and the complete JSON request remains subject to the public input-size limit.
For larger files, use REST multipart upload with a REST-enabled key, then pass
the resulting media UUID to the MCP Tool call.
Browse and inspect
GET https://api.ndnci.com/v1/media returns a bounded, cursor-paginated page. GET https://api.ndnci.com/v1/media/{mediaId} retrieves one permitted item. Use the returned cursor for subsequent pages rather than increasing the response size without bound.
The same key cannot read another workspace's media by changing an identifier or the workspace header.
Download a file
GET https://api.ndnci.com/v1/media/{mediaId}/download returns a temporary download URL and its expiration timestamp. Request a new URL when necessary. Treat signed URLs as secrets while valid and keep them out of public logs.
Generated files become available through job output and the workspace library. Jobs describes the completion workflow.
Media lifecycle
The public API supports upload and read access. Direct media deletion is not an automation permission; use the normal authorized Tool lifecycle for removal. Uploading does not bypass the workspace's storage limits or grant broader access to a referenced file.