tax.sources.prepare
Prepare an immutable private PDF or photo company/tax source upload. Returns a signed upload URL; this does not create an expense or run AI.
/api/v1/accounting/tax.sources.preparePermissions
Who can call it
Retries
MCP
Fields
filenamestringRequiredThe file's name, including its extension.
1–180 characters
mimeTypeenumRequiredThe file's type, such as image/jpeg or application/pdf.
application/pdfimage/jpegimage/pngimage/webpimage/heicimage/heifsizeBytesintegerRequiredThe file's size in bytes.
1 to 52428800
sha256stringRequiredThe SHA-256 hash of the file's exact bytes, as 64 lowercase hex characters.
SHA-256 hash as 64 lowercase hex characters
idempotencyKeystringRequiredAny unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.
8–200 characters
Example
curl https://app.getoatmilk.com/api/v1/accounting/tax.sources.prepare \
-H "Authorization: Bearer $OATMILK_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"filename": "receipt.pdf",
"mimeType": "application/pdf",
"sizeBytes": 1,
"sha256": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8f0a2b4c"
}'{
"data": { … }
}Try it
Try it
Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.
curl https://app.getoatmilk.com/api/v1/accounting/tax.sources.prepare \
-H "Authorization: Bearer $OATMILK_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"filename": "receipt.pdf",
"mimeType": "application/pdf",
"sizeBytes": 1,
"sha256": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8f0a2b4c"
}'More in Reports and tax.