> ## Documentation Index
> Fetch the complete documentation index at: https://developers.investorlift.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get an upload ticket for a draft file

> Answers a presigned form post for one file.



## OpenAPI

````yaml POST /sell/drafts/{draft_id}/media/uploads
openapi: 3.1.0
info:
  title: Investorlift Marketplace API
  version: '2026-09-18'
  summary: List, publish and trade wholesale real estate deals on Investorlift.
  description: >-
    The Marketplace API gives a seller organization and a buyer account the same
    actions the Investorlift application gives them. A seller creates a draft,
    publishes a deal, reads its leads and answers offers. A buyer searches
    deals, asks for an address, makes an offer and keeps a buy box. Every answer
    carries a request id, and every refusal carries a problem code with one
    recovery sentence.
  contact:
    name: Investorlift support
    email: support@investorlift.com
servers:
  - url: https://api.investorlift.com/marketplace/v1
    description: Production
security:
  - oauth2: []
tags:
  - name: sell
    description: What a seller organization does with its drafts and deals.
  - name: buy
    description: What a buyer account does with deals, offers and buy boxes.
  - name: me
    description: What this token can do right now.
  - name: events
    description: >-
      What Investorlift sends to a webhook endpoint, one entry for each event
      type.
paths:
  /sell/drafts/{draft_id}/media/uploads:
    post:
      tags:
        - sell
      summary: Get an upload ticket for a draft file
      description: >-
        Answers a presigned form post for one file. The caller posts the file
        with every field of the ticket, then registers the staged key. The API
        reads no URL the caller supplies.
      operationId: createSellDraftUpload
      parameters:
        - name: draft_id
          in: path
          required: true
          description: The public id in the path, for example draft_id as mdl_a1b2c3d4e5f6.
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                kind:
                  type: string
                  enum:
                    - image
                    - video
                    - contract
                    - document
                  description: >-
                    What the file is. The draft has one upload door for all
                    four.
                filename:
                  type: string
                  minLength: 1
                  maxLength: 255
                content_type:
                  type: string
                  minLength: 1
                  maxLength: 255
                  description: The media type of the file.
                size_bytes:
                  type: integer
                  minimum: 1
                  maximum: 9007199254740991
                  description: The size of the file in bytes.
              required:
                - kind
                - filename
                - content_type
                - size_bytes
              additionalProperties: false
      responses:
        '201':
          description: Created
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/UploadTicket'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                  - data
                  - meta
                additionalProperties: false
        '400':
          description: Body unusable, Identifier malformed, Parameter unknown
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/problem+json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/Problem.invalid_body'
                  - $ref: '#/components/schemas/Problem.invalid_id'
                  - $ref: '#/components/schemas/Problem.unknown_parameter'
        '401':
          description: Not authenticated
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem.unauthorized'
        '403':
          description: >-
            Designation missing, Refused, Scope missing, No organization, Terms
            not accepted
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/problem+json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/Problem.designation_required'
                  - $ref: '#/components/schemas/Problem.forbidden'
                  - $ref: '#/components/schemas/Problem.insufficient_scope'
                  - $ref: '#/components/schemas/Problem.no_organization'
                  - $ref: '#/components/schemas/Problem.terms_required'
        '404':
          description: Not found
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem.not_found'
        '405':
          description: Method not allowed
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem.method_not_allowed'
        '409':
          description: Draft under review
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem.draft_under_review'
        '422':
          description: Body failed validation
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem.validation_failed'
        '503':
          description: Service unavailable
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem.origin_error'
      security:
        - oauth2:
            - deals:write
components:
  headers:
    XRequestId:
      description: The id this answer shares with the Investorlift request log.
      schema:
        type: string
  schemas:
    UploadTicket:
      type: object
      properties:
        method:
          type: string
          const: POST
          description: Send the file as a multipart POST, never as a PUT.
        url:
          type: string
          description: The object store URL the multipart POST goes to.
        fields:
          type: object
          propertyNames:
            type: string
          additionalProperties:
            type: string
          description: Every form field the multipart POST carries beside the file.
        key:
          type: string
          description: The staged key you send back to register the file.
        content_type:
          type: string
          description: The media type the ticket allows.
        max_bytes:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
          description: The largest file the ticket takes, in bytes.
        expires_in:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
          description: The life of the ticket in seconds.
      required:
        - method
        - url
        - fields
        - key
        - content_type
        - max_bytes
        - expires_in
      additionalProperties: false
    Meta:
      type: object
      properties:
        request_id:
          type: string
          description: The id this answer shares with the log.
        api_version:
          type: string
          description: The contract version the body is rendered at.
      required:
        - request_id
        - api_version
      additionalProperties: false
    Problem.invalid_body:
      allOf:
        - $ref: '#/components/schemas/Problem'
      description: Body unusable. Send a JSON body with the content type application/json.
      properties:
        type:
          const: https://developers.investorlift.com/marketplace/errors#invalid_body
        title:
          const: Body unusable
        status:
          const: 400
        code:
          const: invalid_body
        recovery:
          const: Send a JSON body with the content type application/json.
    Problem.invalid_id:
      allOf:
        - $ref: '#/components/schemas/Problem'
      description: >-
        Identifier malformed. Send the public id with its type prefix, for
        example mdl_a1b2c3d4e5f6.
      properties:
        type:
          const: https://developers.investorlift.com/marketplace/errors#invalid_id
        title:
          const: Identifier malformed
        status:
          const: 400
        code:
          const: invalid_id
        recovery:
          const: >-
            Send the public id with its type prefix, for example
            mdl_a1b2c3d4e5f6.
    Problem.unknown_parameter:
      allOf:
        - $ref: '#/components/schemas/Problem'
      description: >-
        Parameter unknown. Remove the parameter the detail names, because this
        operation reads no such field.
      properties:
        type:
          const: >-
            https://developers.investorlift.com/marketplace/errors#unknown_parameter
        title:
          const: Parameter unknown
        status:
          const: 400
        code:
          const: unknown_parameter
        recovery:
          const: >-
            Remove the parameter the detail names, because this operation reads
            no such field.
        unknown_parameters:
          type: array
          items:
            type: string
          description: Every field of the request this operation does not read.
      required:
        - unknown_parameters
    Problem.unauthorized:
      allOf:
        - $ref: '#/components/schemas/Problem'
      description: >-
        Not authenticated. Send a current access token for this API, and start a
        new authorization when the token is expired.
      properties:
        type:
          const: https://developers.investorlift.com/marketplace/errors#unauthorized
        title:
          const: Not authenticated
        status:
          const: 401
        code:
          const: unauthorized
        recovery:
          const: >-
            Send a current access token for this API, and start a new
            authorization when the token is expired.
    Problem.designation_required:
      allOf:
        - $ref: '#/components/schemas/Problem'
      description: >-
        Designation missing. Finish the onboarding of the side you call, then
        repeat the call.
      properties:
        type:
          const: >-
            https://developers.investorlift.com/marketplace/errors#designation_required
        title:
          const: Designation missing
        status:
          const: 403
        code:
          const: designation_required
        recovery:
          const: Finish the onboarding of the side you call, then repeat the call.
        designation:
          description: The designation the side of this operation needs.
          type: string
          enum:
            - seller
            - buyer
    Problem.forbidden:
      allOf:
        - $ref: '#/components/schemas/Problem'
      description: >-
        Refused. Ask Investorlift support why the account, the client or the
        organization is stopped.
      properties:
        type:
          const: https://developers.investorlift.com/marketplace/errors#forbidden
        title:
          const: Refused
        status:
          const: 403
        code:
          const: forbidden
        recovery:
          const: >-
            Ask Investorlift support why the account, the client or the
            organization is stopped.
    Problem.insufficient_scope:
      allOf:
        - $ref: '#/components/schemas/Problem'
      description: >-
        Scope missing. Start a new authorization that asks for the scope named
        in the detail.
      properties:
        type:
          const: >-
            https://developers.investorlift.com/marketplace/errors#insufficient_scope
        title:
          const: Scope missing
        status:
          const: 403
        code:
          const: insufficient_scope
        recovery:
          const: >-
            Start a new authorization that asks for the scope named in the
            detail.
        scope:
          type: string
          enum:
            - marketplace:profile
            - deals:read
            - deals:write
            - offers:read
            - offers:write
            - inquiries:read
            - inquiries:write
            - leads:read
            - leads:write
            - contacts:read
            - reviews:read
            - buy_boxes:manage
            - webhooks:manage
            - events:read
          description: The scope this operation needs.
      required:
        - scope
    Problem.no_organization:
      allOf:
        - $ref: '#/components/schemas/Problem'
      description: >-
        No organization. Create an organization on Investorlift, then repeat the
        call.
      properties:
        type:
          const: >-
            https://developers.investorlift.com/marketplace/errors#no_organization
        title:
          const: No organization
        status:
          const: 403
        code:
          const: no_organization
        recovery:
          const: Create an organization on Investorlift, then repeat the call.
    Problem.terms_required:
      allOf:
        - $ref: '#/components/schemas/Problem'
      description: >-
        Terms not accepted. Accept the Marketplace API Terms on the consent
        page, then start a new authorization.
      properties:
        type:
          const: >-
            https://developers.investorlift.com/marketplace/errors#terms_required
        title:
          const: Terms not accepted
        status:
          const: 403
        code:
          const: terms_required
        recovery:
          const: >-
            Accept the Marketplace API Terms on the consent page, then start a
            new authorization.
        agreement_id:
          type: string
          description: The version of the Marketplace API Terms to accept.
      required:
        - agreement_id
    Problem.not_found:
      allOf:
        - $ref: '#/components/schemas/Problem'
      description: >-
        Not found. Check the id, and check that the account you call with owns
        the resource.
      properties:
        type:
          const: https://developers.investorlift.com/marketplace/errors#not_found
        title:
          const: Not found
        status:
          const: 404
        code:
          const: not_found
        recovery:
          const: >-
            Check the id, and check that the account you call with owns the
            resource.
    Problem.method_not_allowed:
      allOf:
        - $ref: '#/components/schemas/Problem'
      description: >-
        Method not allowed. Use one of the methods the documentation lists for
        this path.
      properties:
        type:
          const: >-
            https://developers.investorlift.com/marketplace/errors#method_not_allowed
        title:
          const: Method not allowed
        status:
          const: 405
        code:
          const: method_not_allowed
        recovery:
          const: Use one of the methods the documentation lists for this path.
    Problem.draft_under_review:
      allOf:
        - $ref: '#/components/schemas/Problem'
      description: >-
        Draft under review. Wait for the Deal Desk to finish its review of this
        draft, then repeat the call.
      properties:
        type:
          const: >-
            https://developers.investorlift.com/marketplace/errors#draft_under_review
        title:
          const: Draft under review
        status:
          const: 409
        code:
          const: draft_under_review
        recovery:
          const: >-
            Wait for the Deal Desk to finish its review of this draft, then
            repeat the call.
    Problem.validation_failed:
      allOf:
        - $ref: '#/components/schemas/Problem'
      description: >-
        Body failed validation. Correct each field the detail names, then repeat
        the call.
      properties:
        type:
          const: >-
            https://developers.investorlift.com/marketplace/errors#validation_failed
        title:
          const: Body failed validation
        status:
          const: 422
        code:
          const: validation_failed
        recovery:
          const: Correct each field the detail names, then repeat the call.
    Problem.origin_error:
      allOf:
        - $ref: '#/components/schemas/Problem'
      description: >-
        Service unavailable. Repeat the call in a minute, and tell Investorlift
        support when the answer stays the same.
      properties:
        type:
          const: https://developers.investorlift.com/marketplace/errors#origin_error
        title:
          const: Service unavailable
        status:
          const: 503
        code:
          const: origin_error
        recovery:
          const: >-
            Repeat the call in a minute, and tell Investorlift support when the
            answer stays the same.
    Problem:
      type: object
      description: >-
        One refusal, as RFC 9457 application/problem+json. The code picks the
        status, the title and the recovery sentence.
      properties:
        type:
          type: string
          format: uri
          description: The errors page anchor of the code.
        title:
          type: string
          description: The short title of the code.
        status:
          type: integer
          description: The HTTP status of this answer.
        code:
          type: string
          enum:
            - address_unavailable
            - agreement_required
            - api_offers_disabled
            - below_floor
            - cap_reached
            - client_limit
            - daily_cap_reached
            - deal_changed
            - deal_closed
            - deal_incomplete
            - designation_required
            - draft_under_review
            - duplicate_inquiry
            - forbidden
            - idempotency_conflict
            - idempotency_in_progress
            - idv_required
            - insufficient_balance
            - insufficient_role
            - insufficient_scope
            - invalid_body
            - invalid_id
            - invalid_parameter
            - invalid_transition
            - lead_locked
            - method_not_allowed
            - no_organization
            - not_a_member
            - not_found
            - offer_exists
            - offer_required
            - offer_superseded
            - organization_required
            - origin_error
            - person_exists
            - preview_expired
            - preview_mismatch
            - proof_of_funds_expired
            - proof_of_funds_missing
            - rate_limited
            - requirement_unmet
            - resource_exists
            - resource_limit
            - strike_exists
            - strike_window_closed
            - terms_required
            - unauthorized
            - unknown_parameter
            - validation_failed
            - webhook_limit
            - webhook_url_refused
            - wrong_side
          description: The problem code. Read this, never the title.
        detail:
          type: string
          description: What happened for this one request.
        recovery:
          type: string
          description: One sentence that says what to do next.
        request_id:
          type: string
          description: The id this answer shares with the log.
      required:
        - type
        - title
        - status
        - code
        - detail
        - recovery
        - request_id
  securitySchemes:
    oauth2:
      type: oauth2
      description: >-
        Authorization code with PKCE. The person grants the scopes on the
        Investorlift consent page and accepts the Marketplace API Terms there.
      flows:
        authorizationCode:
          authorizationUrl: https://mogul.investorlift.com/api/auth/oauth2/authorize
          tokenUrl: https://mogul.investorlift.com/api/auth/oauth2/token
          refreshUrl: https://mogul.investorlift.com/api/auth/oauth2/token
          scopes:
            marketplace:profile: Read your account, your organization and your trust tier.
            deals:read: Read your deals as a seller, and the deals you see as a buyer.
            deals:write: >-
              Create drafts, add media and documents, publish deals and change
              their status.
            offers:read: >-
              Read the offers on your deals as a seller, and your own offers as
              a buyer.
            offers:write: Make, counter, accept, decline and withdraw offers.
            inquiries:read: >-
              Read the inquiries and address requests on your deals, and your
              own.
            inquiries:write: Send inquiries and address requests, and answer address requests.
            leads:read: Read the leads on your deals with their history.
            leads:write: Set a lead status, add a lead and file a strike.
            contacts:read: >-
              Read the email address and the phone number of a buyer on your
              deals.
            reviews:read: Read a seller public profile and the reviews of that seller.
            buy_boxes:manage: Read and change your buy boxes and their alerts.
            webhooks:manage: Create, read and delete the webhook endpoints of your side.
            events:read: Read the event feed of your side.

````

## Related topics

- [Get an upload ticket for a draft file](/api-reference/sell/get-an-upload-ticket-for-a-draft-file.md)
- [Register an uploaded file on a draft](/api-reference/sell/register-an-uploaded-file-on-a-draft.md)
- [Quickstart for sellers](/marketplace/quickstart-seller.md)
- [Ask for a proof of funds upload slot](/api-reference/buy/ask-for-a-proof-of-funds-upload-slot.md)
