PreviewRustaBase OSS is in public preview. Build on managed PostgreSQL with APIs, authentication, storage, realtime, and server-side functions.Read the product direction

APIs and SDKs

File uploads and downloads

Files belong to records. You upload them with the record as multipart form data, and you read them back through the Project file endpoint.

Upload with a record

curl -X POST $PROJECT_URL/api/v1/collections/posts/records \
  -H "Authorization: $TOKEN" \
  -F "title=Launch notes" \
  -F "cover=@./cover.png"
// files can be passed directly; the SDK sends multipart for you
const record = await rb.from("posts").create({
  title: "Launch notes",
  cover: fileInput.files[0],
});

Download a file

PathPurpose
GET /api/v1/files/{table}/{recordId}/{filename}Fetch a stored file
?thumb=100x100Request a generated image thumbnail
?token={fileToken}Access a file on a protected table
POST /api/v1/files/tokenIssue a short-lived file token for the current session
const url = rb.files.url(record, record.cover, { thumb: "300x200" });

// protected tables need a short-lived token
const token = await rb.files.token();
const privateURL = rb.files.url(record, record.cover, { token });

Replace and remove files

Sending a new file for a single-file field replaces the stored file. To clear a field, send an empty value for it; to remove one file from a multiple-file field, send the remaining filenames.

Production guidance

  • Validate type and size before uploading from a client.
  • Keep private files on tables whose access rules require a signed-in owner.
  • Delete files that no longer belong to a live record.
  • Include file storage in your backup and restore planning.

Common workflows

Found something wrong on this page?

Fix it yourself. The link below opens this file in GitHub's editor and forks the repository for you if you need one, and your change becomes a pull request without leaving the browser.