> ## Documentation Index
> Fetch the complete documentation index at: https://docs.moonup.gg/llms.txt
> Use this file to discover all available pages before exploring further.

# Get an upload URL for a picture

> Mints a presigned `PUT` — the bytes go from your process straight to
storage, never through this API. Send the same `Content-Type` and
`Content-Length` on the PUT as you declared here, or it is refused.

There is no confirm step: sending the returned public URL in `images[]`
on create or patch is what attaches it.




## OpenAPI

````yaml /openapi.yaml post /v1/offers/images/upload-url
openapi: 3.1.0
info:
  title: MoonUP Seller API
  version: 1.0.0
  summary: List and manage your offers from your own tools.
  description: |
    Everything a seller's bot needs to keep a catalogue of listings up to date:
    create a listing, restock it, pause it, archive it.

    Each category has its own paths — `/v1/offers/accounts`,
    `/v1/offers/currency` and so on — with its own fields. You integrate with
    the categories you sell in, and a category added to the platform later
    leaves yours untouched.

    This is the public surface. The cabinet's own screens — payouts, disputes,
    account settings — are not part of it and an API key does not reach them.

    ## Authentication

    Create a key in the cabinet under **Seller → API keys**. It is shown once.
    Send it on every request:

    ```
    Authorization: Bearer moonup_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
    ```

    There is nothing to exchange it for — no short-lived token sits in between.
    HTTPS only. Keep the key in an environment variable or your CI's secret
    store, never in a repository.

    A key may be pinned to a list of addresses when you create it (up to 16
    addresses or subnets). An empty list means any address.

    ## Creating a listing

    Categories do not sell the same thing, so they do not ask for the same
    fields, and each one's create call takes only its own. An accounts listing
    has a price and a picture; a currency listing has a product, a price per
    unit and a stock, and no picture at all; a gift card is a code, so it has
    no manual handover time to promise.

    What every category does share is `attributes` — its own field list, which
    varies by game and is versioned. That one you read at runtime:

        GET /v1/offers/games/{game}/categories/{category_slug}/schema

    A full pass looks like this:

    1. `GET /v1/offers/games` — pick a game, keep its `slug`.
    2. `GET /v1/offers/games/{game}/categories` — pick a category.
    3. `GET /v1/offers/games/{game}/categories/{category_slug}/schema` — read
       `attributes`.
    4. `POST /v1/offers/images/upload-url`, then PUT the bytes to the URL it
       returns. Repeat per picture, collect the public URLs. Skip it for a
       category with no gallery.
    5. `POST /v1/offers/{category}` — the listing goes straight to moderation.

    ## Statuses

    A new listing is `pending_moderation`. Moderation makes it `active`, or
    `rejected` with a `rejection_reason_code` and a note. Editing a rejected
    listing is how you resubmit it — there is no separate call. Editing an
    `active` one sends it back to moderation too, unless all you changed was
    the price or the stock.

    `paused` is yours, through pause and unpause. `archived` is the end of the
    line: `DELETE` retires a listing for good and keeps it readable to you.
    `reserved` and `sold` follow orders, not calls.

    ## Rate limits

    | | Budget |
    |---|---|
    | Reads | 500 requests per minute |
    | Writes | 250 requests per minute |
    | Writes to one offer | 5 per minute and 10 per hour |

    Going over answers `429`. It is temporary: wait and retry, the key stays
    valid. Up to 5 keys per account — create the second one ahead of time so
    you can rotate without downtime.

    ## Errors

    Every failure answers with the same body, a stable snake_case code:

    ```json
    { "error": "delivery_instructions_required" }
    ```

    Branch on `error`, not on the message — there is no message.
servers:
  - url: https://api.moonup.gg
    description: Production
security:
  - api_key: []
tags:
  - name: Catalog
    description: |
      What can be listed, and what each category's fields are. Public: these
      read without a key, so you can explore before you have one.
  - name: Accounts
    description: Game accounts, sold whole — one price, one picture.
  - name: Items
    description: In-game items, sold whole.
  - name: Boosting
    description: Boosting services, sold whole.
  - name: Top-ups
    description: Top-up packs, handed over by one of the platform's delivery methods.
  - name: Gift cards
    description: Fixed-denomination codes, handed over instantly.
  - name: Currency
    description: In-game currency, priced per unit out of a stock you keep.
  - name: Pictures
    description: Where an offer's images come from.
paths:
  /v1/offers/images/upload-url:
    post:
      tags:
        - Pictures
      summary: Get an upload URL for a picture
      description: |
        Mints a presigned `PUT` — the bytes go from your process straight to
        storage, never through this API. Send the same `Content-Type` and
        `Content-Length` on the PUT as you declared here, or it is refused.

        There is no confirm step: sending the returned public URL in `images[]`
        on create or patch is what attaches it.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - content_type
                - content_length
              properties:
                content_type:
                  type: string
                  enum:
                    - image/jpeg
                    - image/png
                    - image/webp
                content_length:
                  type: integer
                  format: int64
                  description: Bytes. Bound into the signature, so storage enforces it too.
            examples:
              jpeg:
                value:
                  content_type: image/jpeg
                  content_length: 184320
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  upload_url:
                    type: string
                    format: uri
                  expires_in:
                    type: integer
                    description: Seconds the URL stays usable.
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  responses:
    BadRequest:
      description: |
        The body or a parameter is wrong. `error` names which rule — e.g.
        `delivery_instructions_required`, `bulk_fields_required`,
        `instant_requires_activation_code`, `title_too_short`,
        `invalid_attributes`, `invalid_image`.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            missing_field:
              value:
                error: delivery_instructions_required
    Unauthorized:
      description: |
        The key is unknown, revoked, or the request came from an address
        outside the key's list. Which check failed is not disclosed.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            unauthorized:
              value:
                error: unauthorized
  schemas:
    Error:
      type: object
      description: The one failure shape this API answers with.
      properties:
        error:
          type: string
          description: A stable snake_case code. Branch on this.
          examples:
            - delivery_instructions_required
      required:
        - error
  securitySchemes:
    api_key:
      type: http
      scheme: bearer
      description: Your API key, from the cabinet under **Seller → API keys**.

````