Skip to main content
POST
Upload the policy document
Uploads the policy document for a filing belonging to the authenticated upstream entity. Returns the filing with the policy document in place. Send it as multipart/form-data: exactly one file part.

Replacing a policy document

Exactly one file is accepted, and uploading again replaces the existing policy document rather than adding a second one. The previous file is soft-deleted at the moment the new one is stored. There is no way to hold two policy documents on the same filing at once. This matters if a request times out on your side: retry it with the same file. The retry either lands as the original upload (nothing was stored yet) or as a replacement of what your first attempt already stored, and both outcomes leave the filing with exactly the one document you sent. It never creates a duplicate.

Limits

Allowed types

PDF, DOC, DOCX, JPEG, PNG. Anything else is rejected with 400 before the body is buffered.

10 MB per file

A file larger than that returns 413.
This endpoint supports idempotency. If you include an idempotency-key header, duplicate requests within 1 hour return the original response without reprocessing. See Idempotency.

Error Scenarios

Bad Request (400)

Returned when filingId is not a valid MongoDB ObjectId, no file is attached, more than one file is attached, or the file’s type is not on the allowed list.

Filing Not Found (404)

Returned when filingId does not exist or belongs to a different upstream entity.

Payload Too Large (413)

Returned when the attached file exceeds 10 MB.

Unauthorized (401)

Missing or invalid authentication token. See Authentication.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Headers

idempotency-key
string

UUID to ensure idempotent request processing

Example:

"550e8400-e29b-41d4-a716-446655440000"

x-idempotency-key
string

Alternative UUID header for idempotent request processing

Example:

"550e8400-e29b-41d4-a716-446655440000"

Path Parameters

filingId
string
required

Unique identifier of the surplus-lines filing

Example:

"6650a1b2c3d4e5f6a7b8c9d0"

Body

multipart/form-data
file
file
required

The policy document to upload. Maximum 10MB.

Response

Filing with the policy document in place

data
object
required
requestId
string
required

Unique request identifier

Example:

"dev-2c5e7cf2-9acf-4c8c-ab2f-b81f39d775a8"

timestamp
string
required

Response timestamp

Example:

"2025-11-12T20:49:03.293Z"