0.x — pre-release, no compatibility promise yet.What this means
Upload an attachment to a task (multipart)
Upload a file to storage and create an attachment row.
Enforces per-task limit. S.10: the file passes upload_guard first (type from its bytes, size cap, name cleaned);
a refusal is a 413 / 415 / 422 problem and an upload.rejected event on the task.
Upload limits: up to 25 MB. Allowed: csv, docx, gif, heic, jpg, json, log, m4a, md, mov, mp3, mp4, ods, odt, pdf, png, pptx, txt, wav, webm, webp, xlsx, zip. The type is read from the file’s bytes, and the extension must match it. Executables, scripts, HTML, SVG, XML and macro-enabled Office files are refused. Refusals: 413 upload-too-large, 415 upload-type-not-allowed / upload-type-mismatch, 422 upload-rejected (the malware scan).
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”Responses
Section titled “ Responses ”Successful Response
Returned by task-attachments.create, task-attachments.read and task-attachments.update.
object
Task ID (text)
Example
{ "task_id": "task-1234", "title": "Design Doc", "name": "design.pdf", "url": "https://example.com/design.pdf", "uploaded_by": "string", "uploaded_at": "2026-09-25T12:00:00Z", "deleted_at": "2026-09-25T12:00:00Z", "deleted_by": "string", "is_inline": false, "attachment_id": "string", "url_expires_at": "2026-09-25T12:00:00Z", "content_type": "string"}Bad request - a query parameter outside what the operation accepts (invalid-parameter)
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Bad request", "status": 400, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}Missing or invalid bearer token
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Missing or invalid bearer token", "status": 401, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}Authenticated, but not allowed
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Authenticated, but not allowed", "status": 403, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}Not found
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Not found", "status": 404, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}Conflict (a duplicate, or an Idempotency-Key still in flight)
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Conflict (a duplicate, or an `Idempotency-Key` still in flight)", "status": 409, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}If-Match does not match the current ETag
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "`If-Match` does not match the current `ETag`", "status": 412, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}The file is over the size limit (upload-too-large)
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "The file is over the size limit (`upload-too-large`)", "status": 413, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}The file type is not allowed (upload-type-not-allowed), or its contents do not match its name (upload-type-mismatch)
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "The file type is not allowed (`upload-type-not-allowed`), or its contents do not match its name (`upload-type-mismatch`)", "status": 415, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}The body or query did not validate (validation), or an Idempotency-Key was reused; or the malware scan refused the file (upload-rejected)
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "The body or query did not validate (`validation`), or an `Idempotency-Key` was reused; or the malware scan refused the file (`upload-rejected`)", "status": 422, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}An access token, or a signed-in user, or an address over its limit (rate-limit; see Retry-After)
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "An access token, or a signed-in user, or an address over its limit (`rate-limit`; see `Retry-After`)", "status": 429, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}Unexpected server error - quote request_id
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Unexpected server error", "status": 500, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}The malware scan could not run (upload-rejected); retry later
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "The malware scan could not run (`upload-rejected`); retry later", "status": 503, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}