Update access and the link
PATCH/api/v1/content/{id}
- Access
- API key
- Permission
content:write
Update title, access, password, one-time opening, expiry, view limit or download UI
Example request
curl -X PATCH "https://lac.pics/api/v1/content/Xq3u9RkT0bLmA7cV2pWz1eFy" \
-H "Authorization: Bearer lac_api_YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{
"visibility": "unlisted",
"password": "correct-horse-7",
"ttl": "week"
}'Parameters
Path
idstringrequiredThe file or note id.
Request body
application/jsonrequired
tagsarray of stringNFKC, trim, collapse spaces and lowercase; deduplicated after normalization. Raw controls are invalid. Omission preserves tags on update; an empty array clears them.
up to 10 items · unique
titlestringTitle, up to 180 characters.
up to 180 characters
visibilitystringprivate is owner-only. unlisted is accessible by link. public also appears in the authenticated feed and profile. public cannot be combined with oneTime (400 ONE_TIME_NOT_PUBLIC). Omitted on creation: use the account default (private or unlisted). Omitted on update: retain current access.
values:
"private""unlisted""public"ttlstringRelative to this request; forever clears expiry. Access stops at expiry; encrypted objects are removed asynchronously through a persistent retry queue.
values:
"forever""day""week""month"passwordstringrequest only8–128 characters. Empty string removes the password; omission retains it on update. Stored as Argon2id, never returned. Changing it revokes previous viewer access. Other accounts see protected content in the feed, favorites, profiles and albums only as a locked card (id, type, author, lock flags): title, tags, file name, size, dimensions, dates and previews stay hidden.
up to 128 characters · pattern
^(?:[\s\S]{8,128})?$oneTimebooleanOnly the first guest browser to explicitly open the share page receives access, for at most 10 minutes (including video Range requests). Owner previews and GET/HEAD do not consume the link. Omission retains the setting on update. Cannot be combined with visibility public: the resulting state is checked on creation and update (400 ONE_TIME_NOT_PUBLIC). Other accounts never see one-time content in the feed, profiles or albums.
default false
allowDownloadbooleanDisables the explicit download action; not DRM
expiresAtstring · date-timeLink control (Pro, plan feature link_expiry): the exact end of the file and its link, 5 minutes to 10 years ahead (400 LINK_EXPIRY_INVALID), instead of a ttl preset — sending both is 400 VALIDATION_FAILED. Like ttl, the file is removed at that time.
up to 40 characters
viewLimitintegeror nullLink control (Pro, plan feature view_limit): counted views after which the link answers like an expired one. A limit at or below the views so far ends the link at once; raising or removing it (null, allowed on any plan) opens it again. Existing limits keep working after a plan ends.
1–1,000,000
Responses
200Success
ContentidstringrequiredThe file id.
titlestringrequiredTitle, up to 180 characters.
tagsarray of stringrequiredNFKC, trim, collapse spaces and lowercase; deduplicated after normalization. Raw controls are invalid. Omission preserves tags on update; an empty array clears them.
up to 10 items · unique
originalNamestringThe original file name.
typestringrequiredIMAGE,VIDEO,PASTEorFOLDER(a folder of code).values:
"IMAGE""VIDEO""PASTE""FOLDER"mimestringrequiredThe MIME type of the stored file.
pasteFormatstringor nullvalues:
"plain""markdown""code"pasteLanguagestringor nullfolderFilesintegeror nullA code folder (type FOLDER): files in its archive. Null for other kinds. The archive itself is the media: GET /api/media/{id} serves it (Range requests read one file by the ZIP central directory), ?download=1 as an attachment.
at least 1
revisionintegerrequiredOptimistic revision for editing saved paste text; distinct from share access version.
at least 1
accessVersionintegerrequiredShare access version: 1 for a new file, raised by every change of visibility, password or one-time. From 2 on,
urlcarries it as ?v= so messengers build a fresh link card instead of the one they kept for the previous access.at least 1
sizeinteger · int64requiredSize in bytes.
visibilitystringrequiredprivate is owner-only. unlisted is accessible by link. public also appears in the authenticated feed and profile. public cannot be combined with oneTime (400 ONE_TIME_NOT_PUBLIC). Omitted on creation: use the account default (private or unlisted). Omitted on update: retain current access.
values:
"private""unlisted""public"allowDownloadbooleanrequiredpasswordProtectedbooleanrequiredoneTimebooleanrequiredconsumedAtstring · date-timeor nullreadExpiresAtstring · date-timeor nullreadMaxExpiresAtstring · date-timeor nullhasVideoTextbooleanvideoTextRevisioninteger0–2,147,483,647
viewsintegerrequiredExplicit guest opens, deduplicated during the viewer grant (normally 24 hours). Owner previews are excluded.
at least 0
viewLimitintegeror nullLink control (Pro, plan feature view_limit): after this many counted views the link answers like an expired one (404 SHARE_UNAVAILABLE) to everyone but the owner and viewers still holding the grant of their counted open. Media of a limited file is served only after an explicit open (POST /api/share/{id}/open), so direct media links and link cards cannot bypass the count. Null: no limit.
1–1,000,000
viewLimitReachedAtstring · date-timeor nullWhen the view limit was used up; null while views remain or without a limit.
mediaStatusstringNew videos are processed asynchronously. Playback and previews require READY. The owner may explicitly download the original with ?download=1 while PROCESSING or FAILED; it is returned as an application/octet-stream attachment.
values:
"PROCESSING""READY""FAILED"mediaErrorstringor nullThe reason when processing failed.
widthintegeror nullWidth in pixels.
heightintegeror nullHeight in pixels.
durationMsintegeror nullVideo duration in milliseconds.
videoCodecstringor nullhasAudiobooleanpreviewUrlstringor nullEncrypted derived preview served with the same access checks as the source.
expiresAtstring · date-timeor nullcreatedAtstring · date-timerequiredWhen it was created.
urlstring · urirequiredThe file page to share: {WEB_ORIGIN}/s/{id}, with ?v={accessVersion} once access changed (the page ignores the parameter; older links keep working).
mediaUrlstringrequiredThe address of the file itself.
moderationHoldstringor nullAutomatic check:
review— hidden from everyone but the owner until a moderator decides;blocked— kept hidden by a moderator. Others get such a file exactly like a private one, so only the owner ever sees a non-null value.values:
"review""blocked"favoritebooleanPresent in list responses
ownedbooleanPresent in list responses
authorobject3 fields
idstringThe author’s id.
usernamestringnamestring
- 401Authentication required
- 403SCOPE_REQUIRED, or PLAN_FEATURE_REQUIRED with params.feature (link_expiry, view_limit) when the plan in force lacks it.PLAN_FEATURE_REQUIRED
- 404Content unavailable
- 409Media processing, upload idempotency or paste revision conflict
- 410Previously uploaded content was deleted or expired
- 413Size or quota limit
- 429Rate limit, or the account already uses all its upload slots
- 503Upload or password verification capacity reached
Example response
{
"id": "Xq3u9RkT0bLmA7cV2pWz1eFy",
"title": "capture",
"tags": [
"release"
],
"originalName": "capture.png",
"type": "IMAGE",
"mime": "image/png",
"pasteFormat": null,
"pasteLanguage": null,
"folderFiles": 1,
"revision": 1,
"accessVersion": 1,
"size": 482133,
"visibility": "unlisted",
"allowDownload": true,
"passwordProtected": false,
"oneTime": false,
"consumedAt": null,
"readExpiresAt": null,
"readMaxExpiresAt": null,
"hasVideoText": false,
"videoTextRevision": 0,
"views": 3,
"viewLimit": null,
"viewLimitReachedAt": null,
"mediaStatus": "READY",
"mediaError": null,
"width": 1920,
"height": 1080,
"durationMs": null,
"videoCodec": null,
"hasAudio": false,
"previewUrl": null,
"expiresAt": null,
"createdAt": "2026-09-27T09:30:00.000Z",
"url": "https://lac.pics/s/Xq3u9RkT0bLmA7cV2pWz1eFy",
"mediaUrl": "/api/media/Xq3u9RkT0bLmA7cV2pWz1eFy",
"moderationHold": null,
"favorite": false,
"owned": true,
"author": {
"id": "cmf8a1x2k0000q7lh3v9w2e4d",
"username": "alex",
"name": "Alex"
}
}Error codes
| Code | Status | Message |
|---|---|---|
LINK_EXPIRY_INVALID | 400 | Pick a date and time at least 5 minutes and at most 10 years ahead. |
ONE_TIME_NOT_PUBLIC | 400 | A one-time file cannot be published in the feed and profile. Choose link access or turn off the one-time link. |
PLAN_FEATURE_REQUIRED | 403 | This is available in Pro. |
Answers of any method with a key (an invalid or expired key, a missing permission, too many requests) are in Errors.