Skip to main content
POST
Attach files to a checklist item
Uploads one or more files to a public checklist item on a filing belonging to the authenticated upstream entity. Returns the filing with the new attachments in place. Send it as multipart/form-data: sourceCategoryId and sourceTaskId as form fields, plus one or more files parts.

Identifying the checklist item

sourceCategoryId and sourceTaskId come from the filing’s own checklist, returned by Get a Surplus Lines Filing. That pair identifies an item within one filing only: both ids come from the state template a filing is built from, so the same pair appears on every filing in that state, across every tenant. Always resolve them against the checklist of the specific filingId you are posting to, never a cached checklist from a different filing. Checklist content Turris keeps internal is excluded from the checklist response entirely, so there is no id to obtain for it. That applies at two levels: a whole category can be internal, and so can an individual item inside an otherwise-visible category. Posting to a private or unknown item returns 404, the same response as an unrecognized filingId, so a caller cannot distinguish “does not exist” from “not yours to see”.

Limits

Allowed types

PDF, DOC, DOCX, JPEG, PNG. Anything else is rejected with 400 before the body is buffered.

10 MB per file

A file larger than that returns 413.
This endpoint supports idempotency. If you include an idempotency-key header, duplicate requests within 1 hour return the original response without reprocessing. See Idempotency.

Error Scenarios

Bad Request (400)

Returned when filingId is not a valid MongoDB ObjectId, no files are attached, or a file’s type is not on the allowed list.

Filing or Checklist Item Not Found (404)

Returned when filingId does not exist, belongs to a different upstream entity, or the checklist item identified by sourceCategoryId / sourceTaskId is private or unknown.

Payload Too Large (413)

Returned when any attached file exceeds 10 MB.

Unauthorized (401)

Missing or invalid authentication token. See Authentication.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Headers

idempotency-key
string

UUID to ensure idempotent request processing

Example:

"550e8400-e29b-41d4-a716-446655440000"

x-idempotency-key
string

Alternative UUID header for idempotent request processing

Example:

"550e8400-e29b-41d4-a716-446655440000"

Path Parameters

filingId
string
required

Unique identifier of the surplus-lines filing

Example:

"6650a1b2c3d4e5f6a7b8c9d0"

Body

multipart/form-data
sourceCategoryId
string
required

sourceCategoryId of the checklist item, from the filing checklist response

Example:

"6650a1b2c3d4e5f6a7b8c9d0"

sourceTaskId
string
required

sourceTaskId of the checklist item, from the filing checklist response

Example:

"6650a1b2c3d4e5f6a7b8c9d1"

files
file[]
required

One or more files to attach. Maximum 10MB per file.

Response

Filing with the new attachments

data
object
required
requestId
string
required

Unique request identifier

Example:

"dev-2c5e7cf2-9acf-4c8c-ab2f-b81f39d775a8"

timestamp
string
required

Response timestamp

Example:

"2025-11-12T20:49:03.293Z"