Signal Attachments API

Attachment handling endpoints for uploading and downloading media files associated with messages.

OpenAPI Specification

signal-attachments-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Signal Server Accounts Attachments API
  description: The Signal Server API is the backend REST API that supports the Signal Private Messenger applications on Android, Desktop, and iOS. Built as a Dropwizard application, it provides REST controllers for account registration and management, message delivery, pre-key bundle distribution, device provisioning, profile management, and attachment handling. The server handles user registration via phone number verification, encrypted message routing, push notification delivery, and pre-key bundle management. While Signal does not offer an official public REST API for third-party use, the server source code is available for inspection and self-hosting. All communication is end-to-end encrypted using the Signal Protocol.
  version: '2.0'
  contact:
    name: Signal Support
    url: https://support.signal.org/
  termsOfService: https://signal.org/legal/
  license:
    name: AGPL-3.0
    url: https://github.com/signalapp/Signal-Server/blob/main/LICENSE
servers:
- url: https://chat.signal.org
  description: Signal Production Server
security:
- basicAuth: []
tags:
- name: Attachments
  description: Attachment handling endpoints for uploading and downloading media files associated with messages.
paths:
  /v4/attachments/form/upload:
    get:
      operationId: getAttachmentUploadForm
      summary: Get attachment upload form
      description: Returns a pre-signed upload form that clients use to upload attachment data directly to the storage service. The form includes the upload URL, headers, and the attachment identifier.
      tags:
      - Attachments
      responses:
        '200':
          description: Upload form returned successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AttachmentUploadForm'
        '401':
          description: Authentication required
components:
  schemas:
    AttachmentUploadForm:
      type: object
      properties:
        cdn:
          type: integer
          description: The CDN number to use for the upload.
        key:
          type: string
          description: The object key for the attachment.
        headers:
          type: object
          description: HTTP headers to include in the upload request.
          additionalProperties:
            type: string
        signedUploadLocation:
          type: string
          format: uri
          description: The pre-signed URL for uploading the attachment data.
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
      description: HTTP Basic authentication using the account UUID (or phone number) and password. The password is established during account registration.
    bearerAuth:
      type: http
      scheme: bearer
      description: Bearer token authentication used for certain provisioning and registration flows.
externalDocs:
  description: Signal Server Source Code
  url: https://github.com/signalapp/Signal-Server