# signing.files.prepare

Prepare a private upload for an agreement original: filename, mimeType (PDF, Word .docx, PNG, JPEG, text, Markdown; legacy .doc, .odt and .rtf are kept as records only), sizeBytes up to 25 MB, sha256, idempotencyKey. Returns fileId and uploadUrl; if alreadyUploaded is true skip the upload and confirm.

`POST /api/v1/accounting/signing.files.prepare`

Permissions: `accounting:read`, `accounting:write` · Roles: admin, finance · Idempotency key required

MCP tool: `accounting_signing_files_prepare`

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `filename` | string | Yes | The file's name, including its extension. 1–255 characters. |
| `mimeType` | enum | Yes | The file's type, such as image/jpeg or application/pdf. One of: `application/pdf`, `application/vnd.openxmlformats-officedocument.wordprocessingml.document`, `application/msword`, `application/vnd.oasis.opendocument.text`, `application/rtf`, `image/png`, `image/jpeg`, `text/plain`, `text/markdown`. |
| `sizeBytes` | integer | Yes | The file's size in bytes. 1 to 26214400. |
| `sha256` | string | Yes | The SHA-256 hash of the file's exact bytes, as 64 lowercase hex characters. SHA-256 hash as 64 lowercase hex characters. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/signing.files.prepare \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "filename": "receipt.pdf",
  "mimeType": "application/pdf",
  "sizeBytes": 1,
  "sha256": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8f0a2b4c"
}'
```

Reference page: https://app.getoatmilk.com/docs/api/signing.files.prepare
