DEVELOPER GUIDE
Upload and download media through the API
Upload prepared files and use short-lived tickets for private MCP transfers.
Prepare the file
API uploads accept prepared JPEGs or unchanged H.264 MP4 videos. MP4 size must be strictly below 10,000,000 bytes. Read GET /capabilities for current image defaults, platform constraints and storage limits. Use those settings when preparing images.
Use the Node upload helper with Node 22.14 or newer. It prepares images with the supported settings, corrects orientation, removes source metadata and keeps proportions without enlargement. Transparent areas become white.
# Run from the unzipped helper directory.
npm install sharp@0.35.4
# Set CRICKETS_API_TOKEN securely in your environment.
export CRICKETS_WORKSPACE_ID='WORKSPACE_ID'
node --experimental-strip-types scripts/api-upload.mjs '/path/to/photo.png'Use the multipart flow
- Call
POST /media/uploadswithname,type(image/jpegorvideo/mp4) and bytesize. Save its media ID and part size. - Upload sequential binary parts with
PUT /media/{id}/parts/{number}. Retain the returned part number and ETag for each part. - Call
POST /media/{id}/completewith the orderedpartsarray. - Wait for confirmed
readystatus before using the media ID in a post. Save alt text withPATCH /media/{id}and analtfield.
Completion validates type, dimensions, metadata, actual size and storage allowance. Invalid completion removes the invalid item; correct the source and start again. Referenced attachments are protected from library deletion.
Private downloads and MCP
REST downloads require authentication through GET /media/{id}/file. Media stays private.
MCP upload and download tools return a resource URL, a 15-minute ticket, the required header and HTTP instructions. Send bytes through HTTP rather than embedding them in model arguments.
A ticket works only for its specified resource. It stops working if the integration is revoked or loses account access. Upload tickets also stop working after completion.
Follow the returned instructions. Keep private ticket URLs and tokens out of public logs.
Something unclear? Tell us what would help.