> ## Documentation Index
> Fetch the complete documentation index at: https://www.carstoragesoftware.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Upload car photo

> Requires `write:cars`. Attach one image to a car event session (JSON body — MCP-compatible). Provide `dataBase64` or `sourceUrl` (SSRF-guarded), plus `filename` and `contentType`. Prefer `sessionId` from create-event; if omitted, an open session is reused or a documentation session is created. Max ~3MB decoded per request; loop for multiple chat images. Do not use marketing asset upload for car gallery photos.



## OpenAPI

````yaml /api-reference/openapi.json post /api/v1/cars/{id}/photos
openapi: 3.0.0
info:
  title: Car Storage Software API
  version: 1.1.0
  description: >-
    Team-scoped REST API for Car Storage Software. Authenticate with a team API
    key (`Authorization: Bearer <key>` or `x-api-key: <key>`) created under
    Settings → Integrations → API. Keys carry granular `read:*` / `write:*`
    scopes; read never implies write.
servers:
  - url: https://www.carstoragesoftware.com
security: []
paths:
  /api/v1/cars/{id}/photos:
    post:
      tags:
        - Cars
      summary: Upload car photo
      description: >-
        Requires `write:cars`. Attach one image to a car event session (JSON
        body — MCP-compatible). Provide `dataBase64` or `sourceUrl`
        (SSRF-guarded), plus `filename` and `contentType`. Prefer `sessionId`
        from create-event; if omitted, an open session is reused or a
        documentation session is created. Max ~3MB decoded per request; loop for
        multiple chat images. Do not use marketing asset upload for car gallery
        photos.
      parameters:
        - schema:
            type: string
            format: uuid
          required: true
          name: id
          in: path
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/V1CarPhotoCreate'
      responses:
        '201':
          description: Photo attached.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/V1CarPhotoResponse'
        '401':
          description: Missing, invalid, revoked, or expired API key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '403':
          description: API key missing required scope, or API disabled for team.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '404':
          description: Resource not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '422':
          description: Request validation failed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
      security:
        - ApiKeyAuth: []
components:
  schemas:
    V1CarPhotoCreate:
      type: object
      properties:
        sessionId:
          type: string
          format: uuid
        filename:
          type: string
          minLength: 1
          maxLength: 255
        contentType:
          type: string
          minLength: 1
        dataBase64:
          type: string
          minLength: 1
        sourceUrl:
          type: string
          format: uri
        photoRuleLocation:
          type: string
          nullable: true
        photoRuleNotes:
          type: string
          nullable: true
      required:
        - filename
        - contentType
    V1CarPhotoResponse:
      type: object
      properties:
        data:
          $ref: '#/components/schemas/V1CarPhoto'
      required:
        - data
    ApiError:
      type: object
      properties:
        error:
          type: string
        code:
          type: string
        details:
          nullable: true
      required:
        - error
    V1CarPhoto:
      type: object
      properties:
        id:
          type: string
          format: uuid
        sessionId:
          type: string
          format: uuid
        blobUrl:
          type: string
        filename:
          type: string
          nullable: true
        contentType:
          type: string
          nullable: true
        size:
          type: integer
          nullable: true
        photoRuleLocation:
          type: string
          nullable: true
        photoRuleNotes:
          type: string
          nullable: true
        createdAt:
          type: string
          nullable: true
          format: date-time
      required:
        - id
        - sessionId
        - blobUrl
        - filename
        - contentType
        - size
        - photoRuleLocation
        - photoRuleNotes
        - createdAt
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key
      description: >-
        Team API key from Settings → Integrations. Use `Authorization: Bearer
        <key>` or `x-api-key`.

````

## Related topics

- [Car intake workflow](/docs/api-reference/car-intake-workflow.md)
- [Review car activity, notes, and photos](/docs/cars/review-car-activity-notes-and-photos.md)
- [Import customers, cars, events, and photos](/docs/contacts/import-customers-and-cars.md)
- [Manage vehicle photos](/docs/cars/manage-vehicle-photos.md)
- [Organize your marketing photos and files](/docs/marketing-events/organize-your-marketing-assets.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.