Upload incident attachments
Adds image or PDF attachments to an editable completed employee incident. With dryRun=true, the API validates the files without storing them.
At a glance
Operational behavior
Adds image or PDF attachments to an editable completed employee incident. WithdryRun=true, the API validates the files without storing them.
- Use multipart field uploads with 1 to 5 image or PDF files.
- The complete encoded multipart body must not exceed 5 MiB.
- The incident must be an editable completed incident.
Common errors
Before implementation
- Generate and log a new
X-Request-IDfor the attempt. - Handle every documented response status.
- Do not log
X-API-Keyor unnecessary personal data. - Reconcile current resource state before replaying an ambiguous write.
Related integration guidance
Authorizations
JobHandy integration API key. Send the credential in the X-API-Key header. Treat the key as a secret and use it only from trusted server-side environments.
Headers
Narrows the operation to one tenant in the API key's scope. Any referenced or target resource must be accessible through that tenant. In interactive clients, use the {{tenantId}} variable when a tenant must be selected. Keep the header disabled when tenant selection is not required.
^[0-9a-fA-F]{24}$Optional request identifier. If supplied, it must be a UUID v4 or v7 and is returned unchanged in every response. If omitted, the API generates one. Invalid values return 400 INVALID_REQUEST_ID. If your client uses a {{requestId}} variable, refresh it with a new UUID version 4 or 7 for every HTTP request attempt. Keep the header disabled to let the API generate the request identifier.
^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[47][0-9a-fA-F]{3}-[89aAbB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}$Path Parameters
Incident ID.
^[0-9a-fA-F]{24}$"730000000000000000000001"
Query Parameters
When true, the API validates the request without applying the change. The operation's responses specify the returned representation. When omitted, the server uses false.
true
Body
The complete request body, including multipart framing where applicable, must not exceed 5 MiB (5,242,880 bytes).
One to five files. Each file must be a PDF (application/pdf) or an image (image/*).
1 - 5 elementsResponse
Returns the incident after upload, or the current incident after successful dry-run validation.
Employee incident details.
Unique incident identifier.
1^[0-9a-fA-F]{24}$"730000000000000000000001"
Tenant-facing numeric incident number assigned by the server.
137
Incident type. Values are case-sensitive.
temporary, permanent 1"temporary"
Server-managed incident lifecycle status.
reported, in_progress, completed, archived 1"reported"
Identifier of the affected employee.
^[0-9a-fA-F]{24}$"68a000000000000000000001"
Actor category that originally reported the incident.
user, api_key 1"api_key"
UTC timestamp at which the incident was reported.
1Z$"2026-07-21T07:30:00.000Z"
UTC timestamp from which the incident applies.
1Z$"2026-07-21T00:00:00.000Z"
UTC timestamp until which the incident applies, or null while no end is set.
1Z$null
UTC timestamp at which the incident record was created.
1Z$"2026-07-21T07:30:00.000Z"
UTC timestamp of the latest incident update.
1Z$"2026-07-21T07:30:00.000Z"
