Skip to the page
Chapters

Attachments

Upload a document

POST/api/v1/attachments/{id}/documents

Adds an image to an open attachment, as multipart/form-data: the JPEG or PNG in the field "file", and its document type (and, for an X-ray or a photo, its date and orientation). A PNG is converted to a JPEG at upload (transparency on white; its header is checked before it is decoded. A PNG may have sides of at most 20,000 pixels and at most 20 megapixels in all (160 MB once decoded), or 4 megapixels if it is interlaced, and may not be animated. One PNG is converted at a time per server, and one that waits too long is answered 429 TOO_MANY_REQUESTS), and the document says converted_from: "png". PDF and every other format are refused (export a PDF page as an image first). The image is checked and rewritten before it is stored: metadata (EXIF with its GPS and device data, the EXIF orientation flag, thumbnails, XMP, color profiles, PNG text), comments and anything after the image are removed, so rotate a photo before uploading it. The size and MD5 are those of the stored JPEG. An attachment holds at most 127 documents and 15 MB of images in all. The same image uploaded again (a retry, or the same file chosen twice) is answered with the document the attachment has already: an attachment never holds one image twice. The body may be up to 15 MB and 64 KiB for the form's own parts; one declared larger is refused before it is read, one streamed without a length is read up to that and refused. At most 2 uploads of one key are taken at once, and each server instance processes at most 6 that have arrived: another is answered 429 TOO_MANY_REQUESTS (send it again when one has finished). A body that stops arriving for 15 seconds is answered 408 REQUEST_TIMEOUT. Needs an Idempotency-Key header and a key with the submit permission.

Needs a key with submit permission.

Request

Headers

Headers
NameTypeRequiredDescription
Idempotency-KeystringrequiredMakes the request safe to repeat: a request with the same key and body returns the first answer (the reply has an idempotent-replayed header), and the same key with a different request is refused. 1 to 255 printable characters; a UUID is a good choice.At least 1 character.At most 255 characters.Matches `^[\x21-\x7e]{1,255}$`.

Path parameters

Path parameters
NameTypeRequiredDescription
idstringrequiredAn attachment ID (att_...).

Body

Body
NameTypeRequiredDescription
filestring (binary)requiredThe image: a JPEG or a PNG, at most what the attachment has left of its 15 MB.
document_typestringrequiredA document type code (GET /attachments/document_types).
image_datestring (date)optionalThe date the image was taken: required for a film type (an X-ray or a photo).
orientationstringoptionalleft or right: required for a film type.One of: `left`, `right`.

Response

The attachment, with the document. Status 201.

Response fields
NameTypeDescription
idstringAn ID that starts with att_.
objectstringAlways `attachment`.
statestringopen while documents can be added; closed once sent, with its number. Nothing changes after closing.One of: `open`, `closed`.
kindstringunsolicited (sent with a claim); solicited (answering a payer request: never on a claim file).One of: `unsolicited`, `solicited`.
claim_idstring or nullThe claim it was made for, if any. Which claims carry it is the claim's attachments field.
office_idstringAn ID that starts with off_.
payerobject
payer.idstringAn ID that starts with pyr_.
payer.payer_idstringThe payer's own payer ID.
payer.namestring
payer_request_idstring or nullAn ID that starts with prq_.
payer_referencevalueThe payer's reference number, for a solicited attachment.
narrativestringWhat the documents show, in words: at most 2000 characters.
documentsarray of object
documents[].idstringAn ID that starts with doc_.
documents[].objectstringAlways `attachment_document`.
documents[].document_typestringThe document type code (GET /attachments/document_types).
documents[].mediumstringfilm (an X-ray or a photo: has an image date and an orientation) or paper.One of: `film`, `paper`.
documents[].image_datestring (date) or null
documents[].orientationstring or nullOne of: `left`, `right`.
documents[].file_namestringThe name the file was sent with, for display: the last part of it, without control characters. The stored file is named by the document ID.
documents[].converted_fromstring or nullpng when the upload was a PNG, converted to the JPEG that is stored and sent; null when it was a JPEG.One of: `png`.
documents[].sizeintegerThe size in bytes of the image as stored and sent: the upload rewritten without its metadata (a PNG converted to a JPEG first).At least -9007199254740991.
documents[].md5stringThe MD5 of the stored image (the JPEG), lower-case hex.
documents[].sent_to_networkbooleanTrue once the document has been sent to the attachment network (closing sends it).
documents[].created_atstring (date-time)
attachment_numbervalueThe number the attachment network gave when it closed; null while open.
claim_fileobject or nullHow a claim carrying it refers to it; null while open.
claim_file.pwkstringWhat the claim file carries in PWK06 (loop 2300).
claim_file.ntestringThe note the claim file carries for it (NTE, loop 2300).
request_idstring or nullThe API request that made it; null for one made in the dashboard.
created_atstring (date-time)
updated_atstring (date-time)
closed_atstring (date-time) or null

Errors

Errors
HTTP statusCodeWhat it means
401UNAUTHORIZEDA valid API key is required. Send it as "Authorization: Bearer <key>".
403PERMISSION_DENIEDThis API key is not allowed to do that.
404NOT_FOUNDNot found.
422INVALID_REQUESTThe request is not valid.
400IDEMPOTENCY_KEY_REQUIREDPOST and PATCH requests need an Idempotency-Key header.
422IDEMPOTENCY_KEY_REUSEDThat Idempotency-Key was already used with a different request.
409IDEMPOTENCY_KEY_IN_USEA request with that Idempotency-Key is still running. Retry shortly.
429TOO_MANY_REQUESTSToo many requests of this kind lately. Wait, then try again.
408REQUEST_TIMEOUTThe request body stopped arriving, so the request was stopped. Send it again.
413PAYLOAD_TOO_LARGEThe request body is larger than 1 MB.
504TIMEOUTThe request took too long to finish. It may still have taken effect: look it up before sending it again with a new Idempotency-Key. What it made is found with GET /api/v1/eligibility?request_id=<this request_id>, and the same filter on /api/v1/claims and /api/v1/attachments (a key with read permission).
503ATTACHMENTS_UNAVAILABLEAttachments are not available in live mode yet. Use a test key.
409CONFLICTThe resource is not in a state that allows this, or it changed while the request was handled. Read it, then decide whether to send the request again.
500INTERNALSomething went wrong on our side. Quote the request ID if you contact us.

Example

Example request

Shell
curl -X POST "https://sandbox.myclaimhouse.com/api/v1/attachments/att_01JM000000E00800000000003G/documents" \
  -H "Authorization: Bearer $CLAIMHOUSE_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -F '[email protected];type=image/jpeg' \
  -F 'document_type=bitewing_xray' \
  -F 'image_date=2026-09-24' \
  -F 'orientation=right'

Example response: 201

JSON
{
  "id": "att_01JM000000E00800000000003G",
  "object": "attachment",
  "state": "open",
  "kind": "unsolicited",
  "claim_id": "clm_01JM000000E00800000000002G",
  "office_id": "off_01JM000000E008000000000003",
  "payer": {
    "id": "pyr_01JM000000E008000000000004",
    "payer_id": "00000",
    "name": "Example Dental Plan"
  },
  "payer_request_id": null,
  "payer_reference": null,
  "narrative": "Fractured distal cusp on tooth 3, shown on the bitewing.",
  "documents": [
    {
      "id": "doc_01JM000000E00800000000003H",
      "object": "attachment_document",
      "document_type": "bitewing_xray",
      "medium": "film",
      "image_date": "2026-09-24",
      "orientation": "right",
      "file_name": "bitewing-right.jpg",
      "converted_from": null,
      "size": 184211,
      "md5": "3f2a9c1e5b7d4f60a8c2e1d3b5f7a9c0",
      "sent_to_network": false,
      "created_at": "2026-09-24T20:57:20.000000+00:00"
    }
  ],
  "attachment_number": null,
  "claim_file": null,
  "request_id": "req_01JM000000E00800000000003K",
  "created_at": "2026-09-24T20:57:00.000000+00:00",
  "updated_at": "2026-09-24T20:57:00.000000+00:00",
  "closed_at": null
}