Skip to the page
Chapters

SFTP account

Set up the SFTP account

POST/api/v1/sftp-account

Makes the organization's SFTP account: a user name chosen from the organization's name and a generated password. An organization has one account, for test and live files; setting up again is refused with CONFLICT: rotate the password instead. If a request is lost after the account was made, rotate the password to get one. Send an empty JSON object as the body. The response carries the password (password). It is shown only in this response and cannot be read again: store it now. A request repeated with the same Idempotency-Key gets the stored reply without the password (password_available is false): rotate the password to get a new one. Needs an Idempotency-Key header and a key with the submit permission.

Needs a key with submit permission.

Request

Headers

Headers
NameTypeRequiredDescription
Idempotency-KeystringrequiredMakes the request safe to repeat: a request with the same key and body returns the first answer (the reply has an idempotent-replayed header), and the same key with a different request is refused. 1 to 255 printable characters; a UUID is a good choice.At least 1 character.At most 255 characters.Matches `^[\x21-\x7e]{1,255}$`.

Response

The account, with its password. Status 201.

Response fields
NameTypeDescription
idstringAn ID that starts with sftp_.
objectstringAlways `sftp_account`.
statusstringA disabled account is refused at login; its files stay where they are.One of: `active`, `disabled`.
usernamestringThe user name to log in with.
hostvalueThe host to connect to; null in an environment that has no SFTP host.
portinteger or nullThe port to connect to; null in an environment that has no SFTP host.At least -9007199254740991.
host_key_fingerprintvalueThe SHA256 fingerprint of the server's host key: check it the first time you connect. Null in an environment that has no SFTP host.
foldersobjectThe folders of the account. A file dropped in a folder under TEST is a test file; the folder is the mode.
folders.testobject
folders.test.instringAlways `TEST/IN`.
folders.test.outstringAlways `TEST/OUT`.
folders.liveobject
folders.live.instringAlways `IN`.
folders.live.outstringAlways `OUT`.
keysarray of objectThe public keys that may log in, at most 5.At most 5 items.
keys[].idstringAn ID that starts with sfk_.
keys[].objectstringAlways `sftp_key`.
keys[].labelstringThe name you gave the key.At most 64 characters.
keys[].fingerprintstringThe key's SHA256 fingerprint, as ssh-keygen -l shows it.
keys[].added_atstring (date-time)
last_login_atstring (date-time) or null
last_file_atstring (date-time) or nullWhen the last file dropped on the account was taken.
created_atstring (date-time)
passwordstringThe password to log in with. Shown only in the response that made it: store it now. Absent when password_available is false.
password_availablebooleanFalse in the stored reply an Idempotency-Key replay returns: the password is never stored for replay. Rotate the password to get a new one.

Errors

Errors
HTTP statusCodeWhat it means
401UNAUTHORIZEDA valid API key is required. Send it as "Authorization: Bearer <key>".
403PERMISSION_DENIEDThis API key is not allowed to do that.
422INVALID_REQUESTThe request is not valid.
400IDEMPOTENCY_KEY_REQUIREDPOST and PATCH requests need an Idempotency-Key header.
422IDEMPOTENCY_KEY_REUSEDThat Idempotency-Key was already used with a different request.
409IDEMPOTENCY_KEY_IN_USEA request with that Idempotency-Key is still running. Retry shortly.
413PAYLOAD_TOO_LARGEThe request body is larger than 1 MB.
504TIMEOUTThe request took too long to finish. It may still have taken effect: look it up before sending it again with a new Idempotency-Key. What it made is found with GET /api/v1/eligibility?request_id=<this request_id>, and the same filter on /api/v1/claims and /api/v1/attachments (a key with read permission).
409CONFLICTThe resource is not in a state that allows this, or it changed while the request was handled. Read it, then decide whether to send the request again.
500INTERNALSomething went wrong on our side. Quote the request ID if you contact us.

Example

Example request

Shell
curl -X POST "https://sandbox.myclaimhouse.com/api/v1/sftp-account" \
  -H "Authorization: Bearer $CLAIMHOUSE_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{}'

Example response: 201

JSON
{
  "id": "sftp_01JM000000E00800000000008G",
  "object": "sftp_account",
  "status": "active",
  "username": "example-dental-group",
  "host": "sftp.example.com",
  "port": 22,
  "host_key_fingerprint": "SHA256:3rJq0nX1m2Yw8dVf5uQ7bT9kLz4cE6hA1sPoGvNxYdI",
  "folders": {
    "test": {
      "in": "TEST/IN",
      "out": "TEST/OUT"
    },
    "live": {
      "in": "IN",
      "out": "OUT"
    }
  },
  "keys": [],
  "last_login_at": null,
  "last_file_at": null,
  "created_at": "2026-09-24T15:00:00+00:00",
  "password": "k3Vq9xT1mZ8wRb4nJc7YdLfH2sGpA6uE",
  "password_available": true
}